Law / Frameworks / FINOS AIGF / Detective
FINOS AIGF AIR-DET-001AI Data Leakage Prevention and Detection
Data Leakage Prevention and Detection (DLP&D) for Artificial Intelligence (AI) systems encompasses a combination of proactive measures to prevent sensitive data from unauthorized egress or exposure through these systems, and detective measures to identify such incidents promptly if they occur. This control is critical for safeguarding various types of information associated with AI, including: Session Data; Training Data; Model Intellectual Property.FINOS AI Governance Framework, version 2, as maintained on , AIR-DET-001
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: breach notice, security.
- 229
- laws
- 132
- places
- 0
- with court rulings behind them
- 25
- not yet in force
- 8
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.3 Organizational practices are in place to enable AI testing, identification of...
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations3.6 Incident Response & Recovery
- MIT mitigations2.1 Model & Infrastructure Security
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkCM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event.
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
- NIST CSF 2.0GV.SC-08 Relevant suppliers and other third parties are included in incident planning,...
- CIS Controls3.10 Encryption of sensitive data as it crosses networks.
- CIS Controls3.11 Encryption of sensitive data where it is stored on servers and applications.
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
81 laws, 79 placesShow the other 71 laws
Breach notification
71 laws, 70 placesShow the other 61 laws
Security baseline statutes
33 laws, 31 placesShow the other 23 laws
Sector security regimes
16 laws, 16 placesShow the other 6 laws
| FSM Telecommunications Act of 2014, Security Safeguards for Customer Information |
Through its security duty. What it requires |
|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Through its security duty. What it requires |
|
| Telecommunications Act 2009, Security Safeguards for Consumer Information |
Through its security duty. What it requires |
|
| Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit |
Through its security duty. What it requires |
|
| Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set |
Through its security duty. What it requires |
|
| Law on Communications, network and subscriber-information protection duties |
Through its security duty. What it requires |
Vulnerability and incident reporting
9 laws, 9 placesProduct security requirements
8 laws, 8 placesSensitive categories
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Law on the Protection of Personal Data, sensitive data categories |
Through its security duty. What it requires |
|
| Law No. 133/V/2001 on the Protection of Personal Data, sensitive data categories |
Through its security duty. What it requires |
|
| Law No. 09-08, sensitive personal data and offense records |
Through its security duty. What it requires |
|
| Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data |
Through its security duty. What it requires |
|
| Lei n.º 03/2016, sensitive categories and suspect records |
Through its security duty. What it requires |
Cross border transfer
3 laws, 3 places| Place | Law | How it reaches this control |
|---|---|---|
| Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form |
Through its breach notice, security duties. What it requires |
|
| Loi n° 2022-59, transfert transfrontalier des données |
Through its security duty. What it requires |
|
| DOJ Data Security Program (Bulk Sensitive Personal Data Rule) |
Through its security duty. What it requires |
AI risk obligations
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
Through its security duty. What it requires |
|
| Law on Artificial Intelligence, incident management and reporting obligation |
Through its breach notice duty. What it requires |
Enforcement supervision
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 |
Through its security duty. What it requires |
Full text of the FINOS AI Governance Framework, CC BY 4.0. FINOS AI Governance Framework, https://air-governance-framework.finos.org/, copyright 2025 FINOS, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Titles and purpose text are quoted; markdown emphasis and links were removed. Every control of the framework.
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.