Law / Frameworks / MIT mitigations / Transparency & Accountability Controls
MIT mitigations 4.3Incident Reporting
Formal processes and protocols that document and share AI safety incidents, security breaches, near-misses, and relevant threat intelligence with appropriate stakeholders to enable coordinated responses and systemic improvements.MIT AI Risk Mitigation Taxonomy, preliminary taxonomy, July 2025, 4.3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: breach notice, reporting.
- 18
- laws
- 12
- places
- 1
- with court rulings behind it
- 6
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.3 Organizational practices are in place to enable AI testing, identification of...
- NIST AI RMFMANAGE 4.1 Post-deployment AI system monitoring plans are implemented, including mechanisms for...
- NIST AI 600-1GAI-RISK-09 Information Security
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST Privacy FrameworkCM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event.
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
A law in force is unmarked; the rest wear their state: not yet in force
AI governance
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Transparency in Frontier Artificial Intelligence Act (SB 53) |
Through its reporting duty. What it requires |
|
| Digital Services Act, Article 37 (independent audit of very large online platforms and search engines) |
Through its reporting duty. What it requires |
|
| Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act |
Through its reporting duty. What it requires |
|
| Artificial Intelligence Safety Measures Act from , in 3 months |
Through its reporting duty. What it requires |
|
| AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems) |
Through its reporting duty. What it requires |
AI transparency
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Companion Chatbot Safety and Accountability Act (SB 243) |
Through its reporting duty. What it requires |
|
| HB 26-1263 (2026), Conversational AI Service Operator Requirements from , in 3 months |
Through its reporting duty. What it requires |
|
| Ordonnance n°0011/PR/2026, marquage des contenus générés par intelligence artificielle |
Through its reporting duty. What it requires |
|
| Artificial Intelligence Video Interview Act |
Through its reporting duty. What it requires |
|
| AI Companion Chatbot Safety Act (SB 1546) from a date not yet set |
Through its reporting duty. What it requires |
AI risk obligations
4 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring) from , in 14 months |
Through its reporting duty. What it requires |
|
| AI Act, Article 26(10) (post-remote biometric identification authorisation) from , in 14 months |
Through its reporting duty. What it requires |
|
| Law on Artificial Intelligence, incident management and reporting obligation |
Through its breach notice duty. What it requires |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
Through its reporting duty. What it requires |
AI sector rules
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days |
Through its reporting duty. What it requires |
|
| Amended Regulation 10-1-1 (2025), Governance and Risk Management Framework for Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models |
Through its reporting duty. What it requires |
AI prohibited practices
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Code Pénal Arts. 294-3 to 294-4, Child Sexual Abuse Material Including Realistic and AI-Generated Depictions |
Through its reporting duty. What it requires |
Computer misuse
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Loi n° 09-04 relative à la prévention et à la lutte contre les infractions liées aux technologies de l'information et de la communication |
Through its reporting duty. What it requires |
Full text of the MIT AI Risk Mitigation Taxonomy, CC BY 4.0. MIT AI Risk Initiative (MIT FutureTech), AI Risk Mitigation Taxonomy, https://airisk.mit.edu/ai-risk-mitigations. Data from the MIT AI Risk Initiative is licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Cite as: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy, https://airisk.mit.edu/blog/mapping-ai-risk-mitigations Every control of the framework.