Law / Frameworks / NIST AI RMF / Manage

NIST AI RMF, ManageMANAGE 4.3

Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MANAGE 4.3

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

10
laws
7
places
0
with court rulings behind them
2
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • California
  • China
  • European Union
  • Illinois
  • New York
  • South Korea
  • Vietnam

AI governance

7 laws, 6 places
PlaceLawWhat it asks, as read here
California Transparency in Frontier Artificial Intelligence Act (SB 53)

Report a critical safety incident to the Office of Emergency Services within 15 days of discovering it, or within 24 hours if it poses an imminent risk of death or serious injury

China Interim Measures for the Management of Generative AI Services, Article 14

Upon discovering illegal content your generative AI service has produced, promptly stop generating it, stop transmitting it, eliminate it, carry out rectification such as retraining the model, and report it to the relevant competent authority, all under the same 'promptly' standard the text sets from the moment of discovery.

Preserve records of that user's illegal activity and report it to the relevant competent authority. The text sets no promptness standard or deadline for this second reporting duty, stating only that it follows discovery.

China Provisions on the Administration of Deep Synthesis Internet Information Services, Article 10

Upon discovering illegal or undesirable information, take disposal measures and preserve relevant records in accordance with law, and promptly report the discovery to the cyberspace administration department and the relevant competent authority. The text marks only this reporting step as prompt, counted from the moment of discovery, and states no separate promptness standard for the disposal and record-keeping steps that precede it.

European Union AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk)

Keep track of, document, and report to the AI Office, and as appropriate to national competent authorities, without undue delay, relevant information about serious incidents involving your model and any corrective measures you have taken or plan to take. The Regulation states no fixed number of days for this report and no explicit moment its clock starts from, only that it must be made without undue delay.

Illinois Artificial Intelligence Safety Measures Act from , in 3 months

Report a critical safety incident to the Agency, the Illinois Emergency Management Agency and Office of Homeland Security, and to the Attorney General within 72 hours of learning facts sufficient to establish a reasonable belief that a critical safety incident has occurred.

Within 24 hours of discovering that a critical safety incident poses an imminent risk of death or serious physical injury, disclose it to an appropriate authority, including a law enforcement or public safety agency with jurisdiction over it.

New York Responsible AI Safety and Education Act (RAISE Act)

Disclose each safety incident affecting a frontier model to the Attorney General within 72 hours of learning of it.

South Korea AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems)

Build a risk-management system that monitors and responds to AI-related safety accidents involving your system.

AI risk obligations

3 laws, 2 places
PlaceLawWhat it asks, as read here
European Union AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring) from , in 14 months

Where you have reason to consider that using the system per its instructions may present a risk to health, safety or fundamental rights, inform the provider or distributor and the relevant market surveillance authority without undue delay, and suspend use of the system.

Where you have identified a serious incident, immediately inform first the provider, then the importer or distributor and the relevant market surveillance authorities; if you cannot reach the provider, report the incident yourself as Article 73 requires of a provider.

European Union AI Act, Article 73 (reporting of serious incidents)

If your high-risk AI system is placed on the EU market and you are its provider, report any serious incident to the market surveillance authority of the Member State where the incident occurred.

Report a serious incident not later than 15 days after you become aware of it, or immediately once you establish a causal link between your AI system and the incident, or the reasonable likelihood of one, whichever is sooner.

+6 more
Vietnam Law on Artificial Intelligence, incident management and reporting obligation

If a serious incident occurs in your AI system and you are its developer or provider, urgently apply technical measures to remedy, suspend, or recall the system, and at the same time notify the competent state authority of the incident.

If a serious incident occurs in your AI system and you are its deployer or user, record the incident, notify it promptly, and coordinate with the other parties during the remediation process.

+1 more

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.