Law / Frameworks / NIST AI RMF / Manage
NIST AI RMF, ManageMANAGE 4.3
Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MANAGE 4.3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 10
- laws
- 7
- places
- 0
- with court rulings behind them
- 2
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-09 Information Security
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations4.3 Incident Reporting
- MIT mitigations3.6 Incident Response & Recovery
- NIST Privacy FrameworkCM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event.
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
A law in force is unmarked; the rest wear their state: not yet in force
AI governance
7 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| Transparency in Frontier Artificial Intelligence Act (SB 53) |
Report a critical safety incident to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious injury |
|
| Interim Measures for the Management of Generative AI Services, Article 14 |
Upon discovering illegal content your generative AI service has produced, promptly stop generating it, stop transmitting it, eliminate it, carry out rectification such as retraining the model, and report it to the relevant competent authority, all under the same 'promptly' standard the text sets from the moment of discovery. Preserve records of that user's illegal activity and report it to the relevant competent authority. The text sets no promptness standard or deadline for this second reporting duty, stating only that it follows discovery. |
|
| Provisions on the Administration of Deep Synthesis Internet Information Services, Article 10 |
Upon discovering illegal or undesirable information, take disposal measures and preserve relevant records in accordance with law, and promptly report the discovery to the cyberspace administration department and the relevant competent authority. The text marks only this reporting step as prompt, counted from the moment of discovery, and states no separate promptness standard for the disposal and record-keeping steps that precede it. |
|
| AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk) |
Keep track of, document, and report to the AI Office, and as appropriate to national competent authorities, without undue delay, relevant information about serious incidents involving your model and any corrective measures you have taken or plan to take. The Regulation states no fixed number of days for this report and no explicit moment its clock starts from, only that it must be made without undue delay. |
|
| Artificial Intelligence Safety Measures Act from , in 3 months |
Report a critical safety incident to the Agency, the Illinois Emergency Management Agency and Office of Homeland Security, and to the Attorney General within 72 hours of learning facts sufficient to establish a reasonable belief that a critical safety incident has occurred. Within 24 hours of discovering that a critical safety incident poses an imminent risk of death or serious physical injury, disclose it to an appropriate authority, including a law enforcement or public safety agency with jurisdiction over it. |
|
| Responsible AI Safety and Education Act (RAISE Act) |
Disclose each safety incident affecting a frontier model to the Attorney General within 72 hours of learning of it. |
|
| AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems) |
Build a risk-management system that monitors and responds to AI-related safety accidents involving your system. |
AI risk obligations
3 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring) from , in 14 months |
Where you have reason to consider that using the system per its instructions may present a risk to health, safety or fundamental rights, inform the provider or distributor and the relevant market surveillance authority without undue delay, and suspend use of the system. Where you have identified a serious incident, immediately inform first the provider, then the importer or distributor and the relevant market surveillance authorities; if you cannot reach the provider, report the incident yourself as Article 73 requires of a provider. |
|
| AI Act, Article 73 (reporting of serious incidents) |
If your high-risk AI system is placed on the EU market and you are its provider, report any serious incident to the market surveillance authority of the Member State where the incident occurred. Report a serious incident not later than 15 days after you become aware of it, or immediately once you establish a causal link between your AI system and the incident, or the reasonable likelihood of one, whichever is sooner. +6 more |
|
| Law on Artificial Intelligence, incident management and reporting obligation |
If a serious incident occurs in your AI system and you are its developer or provider, urgently apply technical measures to remedy, suspend, or recall the system, and at the same time notify the competent state authority of the incident. If a serious incident occurs in your AI system and you are its deployer or user, record the incident, notify it promptly, and coordinate with the other parties during the remediation process. +1 more |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.