Law / Frameworks / MIT mitigations / Operational Process Controls
MIT mitigations 3.6Incident Response & Recovery
Protocols and technical systems that respond to security incidents, safety failures, or capability misuse to contain harm and restore safe operations.MIT AI Risk Mitigation Taxonomy, preliminary taxonomy, July 2025, 3.6
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: breach notice, security.
- 2
- laws
- 2
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.3 Organizational practices are in place to enable AI testing, identification of...
- NIST AI RMFMEASURE 2.5 The AI system to be deployed is demonstrated to be valid and reliable. Limitations of...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkCM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event.
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
- NIST CSF 2.0GV.SC-08 Relevant suppliers and other third parties are included in incident planning,...
A law in force is unmarked; the rest wear their state: not yet in force
AI risk obligations
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
Through its security duty. What it requires |
|
| Law on Artificial Intelligence, incident management and reporting obligation |
Through its breach notice duty. What it requires |
Full text of the MIT AI Risk Mitigation Taxonomy, CC BY 4.0. MIT AI Risk Initiative (MIT FutureTech), AI Risk Mitigation Taxonomy, https://airisk.mit.edu/ai-risk-mitigations. Data from the MIT AI Risk Initiative is licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Cite as: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy, https://airisk.mit.edu/blog/mapping-ai-risk-mitigations Every control of the framework.