Skip to main content
v2026.11,858 entries · CC-BY 4.0
Frontier AI Safety & Governance

Incident Reporting & Governance

Statutory and voluntary incident-reporting duties, whistleblower protections, accountable-decision-maker sign-off, and the internal governance structures (boards, audit functions) frontier AI developers are building to meet them.

Guides

General Counsel’s Guide to Frontier-AI Litigation Exposure

Three genuinely checkable cases — a Canadian small-claims chatbot ruling, an active US federal age-discrimination collective action against an AI hiring vendor, and unresolved wrongful-death claims against a companion-AI company — read as illustrative of where frontier-AI liability exposure is being tested right now, not as settled law anywhere.

Board Oversight of Frontier AI: What Caremark Actually Requires

Delaware’s Caremark doctrine requires boards to attempt in good faith to ensure a reasonable information and reporting system exists. Firms are now extrapolating that duty to AI risk the way they did for cybersecurity a decade ago — but no Delaware court has yet applied Caremark to an AI-risk fact pattern. This is what the doctrine actually holds, what NACD’s new director certificate teaches, and where that leaves a board writing an AI-oversight charter today.

Incident Type: The Taxonomy No One Has Actually Published

SB 53, the EU GPAI Code, OpenAI, Anthropic, and the Frontier Model Forum each classify AI incidents differently — and only one of them names anything short of catastrophic. NIKOLAI’s own N7 element, opened up in full, with confidence flagged row by row.

AI Whistleblower Protections and the Right-to-Warn Movement

The cross-lab “right to warn” movement, the EU AI Act’s whistleblower provision, and New York’s September 2026 AI enforcement alert — and how they differ from CASRAI’s existing SB 53/RAISE Act incident-reporting coverage.

AI Accountability: Who’s Responsible When an AI System Causes Harm?

What AI accountability means as a general concept, the mechanisms (roles, sign-offs, audit trails, incident-reporting obligations) that implement it, and how SB 53, the NIST AI RMF, and the EU AI Act assign it differently.

The AI Incident Database: What It Is and How It Works

What the AI Incident Database is, who runs it (the Responsible AI Collaborative), how entries get in, and why it is a public catalogue of reported AI harms rather than a substitute for SB 53 or RAISE Act statutory incident reporting.

The SB 53 Material-Change Trigger: When a Frontier AI Framework Must Be Updated

SB 53 requires a large frontier developer to publish its modified Frontier AI Framework, with a justification, within 30 days of a material modification. This guide covers what counts as material and the process for complying.

Accountable Decision-Makers Under SB 53: What the Statute Actually Requires

SB 53 requires internal governance practices around deployment decisions, but the statute itself never names a required accountable-decision-maker role. Here is what it explicitly requires, what is implementation practice, and how NIKOLAIs N9 element proposes to fill the gap.

What Is a Frontier AI Framework? The SB 53 and RAISE Act Requirement, Explained

A Frontier AI Framework is a specific published document that SB 53 and the RAISE Act require large AI developers to maintain. Here is what each law requires, how the terms lined up in March 2026, and how it relates to a lab’s own voluntary safety policy.

Building an Internal AI Safety Incident Response Program

What an internal AI safety incident response program needs structurally: detection channels, triage against a severity taxonomy, escalation to a named accountable decision-maker, and the SB 53 and RAISE Act external reporting clocks.

New York RAISE Act: What It Requires

New York’s RAISE Act requires large frontier AI developers to publish a Frontier AI Framework and report Critical Safety Incidents to DFS within 72 hours — a much tighter window than California SB 53’s 15 days.

SB 53 Critical Safety Incident Reporting: What Counts, Deadlines, and Who to Notify

The statutory definition of a reportable incident under California SB 53, the 15-day versus 24-hour reporting clocks, who must be notified, what a compliant report must contain, and how the Attorney General enforces it.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →