Law / Frameworks / FINOS AIGF / Detective
FINOS AIGF AIR-DET-021Agent Decision Audit and Explainability
Agent Decision Audit and Explainability implements comprehensive logging, documentation, and explainability mechanisms for agent decisions to support regulatory compliance, security incident investigation, and decision accountability. This detective control ensures that all agent actions, reasoning processes, and decision factors are captured in sufficient detail to meet regulatory requirements and enable effective forensic analysis when incidents occur.FINOS AI Governance Framework, version 2, as maintained on , AIR-DET-021
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: data subject rights, disclosure, governance, reporting, retention.
- 586
- laws
- 187
- places
- 2
- with court rulings behind them
- 63
- not yet in force
- 24
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.1 System Documentation
- MIT mitigations3.2 Data Governance
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- CIS Controls8.2 Turning on and gathering logs from the enterprise's systems.
- CIS Controls3.2 A maintained catalogue of the sensitive data the enterprise holds and where it sits.
A law in force is unmarked; the rest wear their state: not yet in force proposed
Data subject rights
99 laws, 87 placesShow the other 89 laws
Comprehensive regime
95 laws, 91 placesShow the other 85 laws
Enforcement supervision
67 laws, 67 placesShow the other 57 laws
Vulnerability and incident reporting
67 laws, 61 placesShow the other 57 laws
Breach notification
45 laws, 44 placesShow the other 35 laws
Sector security regimes
45 laws, 43 placesShow the other 35 laws
AI transparency
31 laws, 28 placesShow the other 21 laws
Telephone contact
30 laws, 22 placesShow the other 20 laws
AI risk obligations
21 laws, 12 placesShow the other 11 laws
Security baseline statutes
17 laws, 17 placesShow the other 7 laws
| Identity Theft Protection Act, destruction of data no longer needed |
Through its retention duty. What it requires |
|
| Law on Information Security, General Security Measures |
Through its governance duty. What it requires |
|
| Cybersecurity Law, General Security Requirements for the Public Administration and the Private Sector |
Through its governance duty. What it requires |
|
| Identity Theft Protection Act, destruction of personal information records |
Through its retention duty. What it requires |
|
| Proyecto de Ley 9906/2024-CR, Ley de Seguridad Digital o Ciberseguridad proposed |
Through its governance duty. What it requires |
|
| Document Safe Destruction Act, safe destruction of records containing personal information |
Through its retention duty. What it requires |
|
| Cybersecurity Law, Information System Classification and Protection Measures |
Through its governance duty. What it requires |
AI governance
15 laws, 11 placesShow the other 5 laws
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
Through its disclosure duty. What it requires |
|
| Federal Law No. 243-FZ, Article 8, Duties of Sovereign and National Foundation Model Developers from , in 5 months |
Through its governance duty. What it requires |
|
| AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems) |
Through its reporting duty. What it requires |
|
| Digital Transformation Act 2025, ICT service permit for AI and AI-related data services |
Through its governance duty. What it requires |
|
| Guidelines on Artificial Intelligence of Vatican City State (Decree No. DCCII) |
Through its governance duty. What it requires |
AI sector rules
11 laws, 11 placesShow the other 1 law
| Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session) from , in 3 months |
Through its disclosure, governance duties. What it requires |
Adult content age verification (AV)
10 laws, 8 placesCommercial messages
8 laws, 8 places| Place | Law | How it reaches this control |
|---|---|---|
| Spam Act 2003, Unsolicited Commercial Electronic Messages |
Through its disclosure duty. What it requires |
|
| Canada's Anti-Spam Legislation |
Through its disclosure duty. What it requires |
|
| Gesetz gegen den unlauteren Wettbewerb, Commercial Electronic Messages |
Through its disclosure duty. What it requires |
|
| Irish ePrivacy Regulations |
Through its disclosure duty. What it requires |
|
| Unsolicited Commercial E-mail Protection Act |
Through its disclosure duty. What it requires |
|
| Nevada Unsolicited Commercial Electronic Mail Liability Act |
Through its disclosure duty. What it requires |
|
| PECR, Electronic Mail for Direct Marketing Purposes |
Through its disclosure duty. What it requires |
|
| CAN-SPAM Act |
Through its disclosure duty. What it requires |
Sensitive categories
8 laws, 8 placesProduct security requirements
6 laws, 6 places| Place | Law | How it reaches this control |
|---|---|---|
| Security Standards for Smart Devices |
Through its governance duty. What it requires |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybersécurité), sécurité des réseaux et essai de vulnérabilité des produits |
Through its disclosure duty. What it requires |
|
| Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment) |
Through its disclosure duty. What it requires |
|
| Cybersecurity Law, Network Product and Service Security Duties |
Through its governance, reporting duties. What it requires |
|
| Digital Code, Livre IV: ICT Product and Service Vendor Security Certification |
Through its disclosure duty. What it requires |
|
| Kyberkestävyyslaki, National Enforcement and Market Surveillance for the Cyber Resilience Act |
Through its reporting duty. What it requires |
Social media and minors
3 laws, 3 places| Place | Law | How it reaches this control |
|---|---|---|
| HB 3 (2024), social media use for minors |
Through its retention duty. What it requires |
|
| Ordonnance n°0011/PR/2026, protection des mineurs sur les réseaux sociaux |
Through its reporting duty. What it requires |
|
| Law 4779/2021 Article 32, Video-Sharing Platform and Social Network Minor Protection Duties |
Through its reporting duty. What it requires |
AI prohibited practices
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement |
Through its governance duty. What it requires |
|
| Code Pénal Arts. 294-3 to 294-4, Child Sexual Abuse Material Including Realistic and AI-Generated Depictions |
Through its reporting duty. What it requires |
Cross border transfer
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Resolución 58/2022 (MINCOM), security and localization rules for personal data in electronic form |
Through its data subject rights, disclosure duties. What it requires |
|
| Ley Federal de Protección de Datos Personales en Posesión de los Particulares, transfer of personal data |
Through its disclosure duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its governance duty. What it requires |
Biometric privacy
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Biometric Information Privacy Act (BIPA) |
Through its disclosure, retention duties. What it requires |
Computer misuse
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Loi n° 09-04 relative à la prévention et à la lutte contre les infractions liées aux technologies de l'information et de la communication |
Through its reporting duty. What it requires |
Device storage and tracking consent
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Canada's Anti-Spam Legislation |
Through its disclosure duty. What it requires |
Full text of the FINOS AI Governance Framework, CC BY 4.0. FINOS AI Governance Framework, https://air-governance-framework.finos.org/, copyright 2025 FINOS, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Titles and purpose text are quoted; markdown emphasis and links were removed. Every control of the framework.
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.