If you have difficulty in submitting comments on draft standards you can use a commenting template and email it to admin.start@bsigroup.com. The commenting template can be found here.
This document specifies a framework for data elements of reports of AI incidents that have occurred. This document is applicable to all types of organizations (e.g., commercial enterprises, government agencies, not-for-profit organizations).
Establishing an international standard for AI incident reporting is crucial and urgent as AI use continues to grow rapidly across sectors. With regulations starting to mandate incident reporting, a cohesive framework is needed to ensure consistent data collection and sharing across countries. Otherwise, there is a significant risk that different countries will develop their own disparate frameworks, leading to a fragmented approach to AI incident reporting. This fragmentation could create confusion, hinder cross-border collaboration, and complicate compliance for businesses operating internationally.
Moreover, working retroactively to align these varied frameworks will be much more challenging and time-consuming. (Please use this field or attach an annex) The Common Reporting Framework for AI Incidents aims to establish a common reporting schema for AI-related incidents. Its primary objectives include:
- Data collection and sharing:
The framework facilitates the collection and sharing of AI incident-related data in a manner that is both comparable and interoperable across different countries.
- Flexible approach: It promotes a standardised reporting approach while allowing countries the flexibility to implement reporting requirements and respond to incident reports in ways that align with their domestic contexts and legal frameworks.
- Inform policy and support risk management:
The framework will facilitate the collection of comparable data, which will aid in informing and improving risk management frameworks, policies, and regulations.
Background:
- Work on the framework began in 2023, led by the GPAI Expert Group on AI Incidents, which includes over 60 experts from all stakeholder groups. The group was co-chaired by NIST, the European Commission, and the Jozef Stefan Institute (Slovenia). The framework has been approved and published by consensus among the 44 GPAI countries.
Considerations:
- The framework is not designed to function as a tool for post-market surveillance, evaluation, or monitoring, although it may provide valuable insights for these purposes.
- It does not provide specific implementation guidance or processes, as these should be tailored to fit the unique contexts of individual organisations or countries.
- The framework covers AI-related incidents across various fields, including cybersecurity. Its broader scope is designed to complement existing reporting frameworks across various domains while maintaining a focus on AI.
- The framework is designed to enable broad reporting of AI incidents by all stakeholders. However, it does not aim to prove a direct cause-and-effect relationship between an incident and the AI system involved. Proving such a link would require further investigation by the appropriate authority.
-The framework does not exclude incidents that have occurred but have not resulted in any harm
You are now following this standard. Weekly digest emails will be sent to update you on the following activities:
You can manage your follow preferences from your Account. Please check your mailbox junk folder if you don't receive the weekly email.
You have successfully unsubscribed from weekly updates for this standard.
Comment on proposal
Required form fields are indicated by an asterisk (*) character.