Law / Frameworks / MIT mitigations / Operational Process Controls

MIT mitigations 3.6Incident Response & Recovery

Protocols and technical systems that respond to security incidents, safety failures, or capability misuse to contain harm and restore safe operations.MIT AI Risk Mitigation Taxonomy, preliminary taxonomy, July 2025, 3.6

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

The kinds of duty that reach it: breach notice, security.

2
laws
2
places
0
with court rulings behind them
1
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • European Union
  • Vietnam

AI risk obligations

2 laws, 2 places
PlaceLawHow it reaches this control
European Union AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months

Through its security duty. What it requires

Vietnam Law on Artificial Intelligence, incident management and reporting obligation

Through its breach notice duty. What it requires

Full text of the MIT AI Risk Mitigation Taxonomy, CC BY 4.0. MIT AI Risk Initiative (MIT FutureTech), AI Risk Mitigation Taxonomy, https://airisk.mit.edu/ai-risk-mitigations. Data from the MIT AI Risk Initiative is licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Cite as: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy, https://airisk.mit.edu/blog/mapping-ai-risk-mitigations Every control of the framework.