Law / Frameworks / FINOS AIGF / Detective
FINOS AIGF AIR-DET-004AI System Observability
AI System Observability encompasses the comprehensive collection, analysis, and monitoring of data about AI system behavior, performance, interactions, and outcomes. This control is essential for maintaining operational awareness, detecting anomalies, ensuring performance standards, and supporting incident response for AI-driven applications and services within a financial institution.FINOS AI Governance Framework, version 2, as maintained on , AIR-DET-004
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: breach notice, governance, reporting, retention.
- 421
- laws
- 171
- places
- 2
- with court rulings behind them
- 53
- not yet in force
- 10
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 4.3 Organizational practices are in place to enable AI testing, identification of...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.1 System Documentation
- MIT mitigations4.3 Incident Reporting
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- CIS Controls8.2 Turning on and gathering logs from the enterprise's systems.
- CIS Controls17.2 A maintained list of who to contact about a security incident, inside and outside the...
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
86 laws, 83 placesShow the other 76 laws
Breach notification
71 laws, 70 placesShow the other 61 laws
Vulnerability and incident reporting
68 laws, 62 placesShow the other 58 laws
Enforcement supervision
66 laws, 66 placesShow the other 56 laws
Sector security regimes
45 laws, 43 placesShow the other 35 laws
Security baseline statutes
16 laws, 16 placesShow the other 6 laws
| Law on Information Security, General Security Measures |
Through its governance duty. What it requires |
|
| Cybersecurity Law, General Security Requirements for the Public Administration and the Private Sector |
Through its governance duty. What it requires |
|
| Identity Theft Protection Act, destruction of personal information records |
Through its retention duty. What it requires |
|
| Proyecto de Ley 9906/2024-CR, Ley de Seguridad Digital o Ciberseguridad proposed |
Through its governance duty. What it requires |
|
| Document Safe Destruction Act, safe destruction of records containing personal information |
Through its retention duty. What it requires |
|
| Cybersecurity Law, Information System Classification and Protection Measures |
Through its governance duty. What it requires |
AI risk obligations
15 laws, 8 placesShow the other 5 laws
| Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025) |
Through its governance duty. What it requires |
|
| Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty |
Through its governance duty. What it requires |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Through its governance duty. What it requires |
|
| Law on Artificial Intelligence, incident management and reporting obligation |
Through its breach notice duty. What it requires |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
Through its governance, reporting duties. What it requires |
AI governance
12 laws, 8 placesShow the other 2 laws
| Digital Transformation Act 2025, ICT service permit for AI and AI-related data services |
Through its governance duty. What it requires |
|
| Guidelines on Artificial Intelligence of Vatican City State (Decree No. DCCII) |
Through its governance duty. What it requires |
Adult content age verification (AV)
9 laws, 8 placesAI sector rules
7 laws, 7 placesAI transparency
6 laws, 6 places| Place | Law | How it reaches this control |
|---|---|---|
| Companion Chatbot Safety and Accountability Act (SB 243) |
Through its reporting duty. What it requires |
|
| HB 26-1263 (2026), Conversational AI Service Operator Requirements from , in 3 months |
Through its reporting duty. What it requires |
|
| Ordonnance n°0011/PR/2026, marquage des contenus générés par intelligence artificielle |
Through its reporting duty. What it requires |
|
| Artificial Intelligence Video Interview Act |
Through its reporting duty. What it requires |
|
| Practice Direction No. 1 of 2025, Use of Generative Artificial Intelligence in Court Proceedings |
Through its governance duty. What it requires |
|
| AI Companion Chatbot Safety Act (SB 1546) from a date not yet set |
Through its reporting duty. What it requires |
Sensitive categories
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Law No. 025/2023, sensitive categories of personal data and children's data |
Through its governance duty. What it requires |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares, sensitive personal data |
Through its retention duty. What it requires |
|
| Ley N° 6534/2020, de Protección de Datos Personales Crediticios |
Through its reporting duty. What it requires |
|
| Ley para la Protección de la Privacidad Cibernética de los Niños y Jóvenes (children's online privacy) |
Through its retention duty. What it requires |
|
| Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data |
Through its retention duty. What it requires |
Product security requirements
3 laws, 3 places| Place | Law | How it reaches this control |
|---|---|---|
| Security Standards for Smart Devices |
Through its governance duty. What it requires |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Through its governance, reporting duties. What it requires |
|
| Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience Act |
Through its reporting duty. What it requires |
Social media and minors
3 laws, 3 places| Place | Law | How it reaches this control |
|---|---|---|
| HB 3 (2024), social media use for minors |
Through its retention duty. What it requires |
|
| Ordonnance n°0011/PR/2026, protection des mineurs sur les réseaux sociaux |
Through its reporting duty. What it requires |
|
| Law 4779/2021 Article 32, Video-Sharing Platform and Social Network Minor Protection Duties |
Through its reporting duty. What it requires |
AI prohibited practices
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement |
Through its governance duty. What it requires |
|
| Code Pénal Arts. 294-3 to 294-4, Child Sexual Abuse Material Including Realistic and AI-Generated Depictions |
Through its reporting duty. What it requires |
Telephone contact
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Gesetz gegen den unlauteren Wettbewerb, Documentation of Consent to Telephone Advertising |
Through its reporting, retention duties. What it requires |
|
| Telemarketing Sales Rule |
Through its retention duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its governance duty. What it requires |
Biometric privacy
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Biometric Information Privacy Act (BIPA) |
Through its retention duty. What it requires |
Computer misuse
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Loi n° 09-04 relative à la prévention et à la lutte contre les infractions liées aux technologies de l'information et de la communication |
Through its reporting duty. What it requires |
Cross border transfer
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form |
Through its breach notice duty. What it requires |
Data subject rights
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| SPDP Norma General guaranteeing personal-data protection in the use of AI systems from a date not yet set |
Through its governance duty. What it requires |
Full text of the FINOS AI Governance Framework, CC BY 4.0. FINOS AI Governance Framework, https://air-governance-framework.finos.org/, copyright 2025 FINOS, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Titles and purpose text are quoted; markdown emphasis and links were removed. Every control of the framework.
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.