There should be transparency and responsible disclosure so that people can understand when they are significantly impacted by AI and can find out when an AI system is engaging with them. Disclosure serves each stakeholder differently: users (what the system does and why), creators and certifiers (processes and input data), deployers and operators, accident investigators, regulators in investigations, participants in legal processes, and the public (confidence in the technology). Disclosures should be timely and give reasonable justifications for outcomes, including the key factors used in decision making, and people should be able to learn that an AI system is engaging with them whatever the level of impact and obtain a reasonable disclosure about it.
This control maps to 9 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 9 it maps to, and the evidence behind each claim, over MCP and REST.