🤖 AI Summary
This study addresses the empirical gap in evaluating whether AI systems fulfill post-deployment regulatory obligations concerning monitoring, reporting, and impact assessment. Drawing on an AI incident database spanning 2020–2026, it presents the first systematic quantification of compliance gaps across nine post-deployment provisions of the EU AI Act, the NIST AI Risk Management Framework, and the GDPR. Employing a multi-regulatory coding scheme and statistical modeling of compliance, the analysis reveals that 77.1% of incidents lack evidence of post-market monitoring and 99.6% show no data protection impact assessments. Internal monitoring is found to significantly improve compliance rates. Building on these findings, the study proposes a four-stage Proactive AI Governance Compliance Framework (PAGCF), emphasizing continuous monitoring and cross-framework validation to establish an evidence-based foundation for post-deployment accountability and governance.
📝 Abstract
Artificial intelligence systems are increasingly deployed in high-stakes domains, yet it remains unclear whether existing governance frameworks ensure accountability after deployment. This study makes two contributions. First, it presents a cross-regulatory empirical analysis of 480 real-world AI incidents from the AI Incident Database (AIID), evaluating their alignment with post-deployment provisions in three major governance frameworks: the EU AI Act (Articles 72-73), the NIST AI Risk Management Framework (MANAGE and GOVERN functions), and the General Data Protection Regulation (GDPR Articles 22, 33-35). The results reveal substantial governance gaps across these frameworks, indicating persistent weaknesses in post-deployment accountability. Second, based on these findings, the study proposes the Proactive AI Governance Compliance Framework (PAGCF), a four-phase lifecycle methodology designed to shift governance from reactive incident response toward pre-deployment compliance assurance. The framework includes risk-stratified governance tiers, an implementation checklist linked to specific regulatory provisions, and a projected impact analysis that uses internal monitoring as a proxy for proactive governance capacity.