OECD AI Principles
Incident Reporting, Compliance, International

OECD AI Principles OECDAI-8: AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation

Operate AI incident reporting + regulatory compliance + public reporting + international cooperation per OECD AI Principles + applicable regulation + voluntary commitment. AI incident reporting and response must (a) detect + assess + respond to AI incidents including model failure + bias incident + safety event + adversarial attack + privacy breach + misuse + emergent capability + agentic action gone wrong + (b) report incidents per applicable regulation (EU AI Act Article 73 serious incident reporting + sector-specific reporting + voluntary commitments) + (c) maintain incident learning loop feeding back to risk management + design + deployment. Regulatory compliance for AI must (a) maintain AI-regulatory inventory across applicable jurisdictions (EU AI Act + UK AI regulation + US federal + state + sectoral + Canada + Australia + Japan + similar) + (b) monitor for change + integrate new requirements into AI governance + (c) coordinate with broader compliance function including privacy + cyber + consumer protection + competition + employment. Public reporting and accountability to society must (a) maintain transparency about AI use + outcomes + harms + remediation per applicable expectation + (b) engage with civil society + academia + media + public per organisational AI strategy + (c) participate in industry voluntary commitments where appropriate (Frontier Model Forum + similar). International cooperation for trustworthy AI must (a) participate in international AI governance dialogues + (b) align cross-border AI deployment with applicable regulation in each jurisdiction + (c) coordinate cross-border AI incident response.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 25 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AIGE-NR-1 Nurture AI talent and upskill the workforce
  • AIGE-NR-2 Invest in AI research and development
  • AIGE-NR-3 Support the AI innovation ecosystem and investment
  • AIGE-RR-1 Establish an ASEAN Working Group on AI Governance
  • AIGE-RR-2 Foster regional alignment, cooperation and interoperability
  • CO-AIA-1702-5 Developer Disclosure of Algorithmic Discrimination
  • CO-AIA-1703-7 Deployer Disclosure of Algorithmic Discrimination to AG

Bahrain PDPL · 1 control

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution

NIST SP 800-190 · 1 control

  • NIST190-04 Regulatory compliance for cloud services
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • DSOMM-6 Metrics, Maturity Measurement, and Continuous Improvement
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training
  • AUPRV-8 OAIC Cooperation, Vendor Management, Training, Complaints, Enforcement

Privacy Act 2020 · 1 control

  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training
  • EHDSREG-5 Cross-Border Health Data Flows

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 25 it maps to, and the evidence behind each claim, over MCP and REST.