TC260 AI Safety Governance Framework 3.0: operators' guidelines §5.3 (voluntary; 2026-09-14)
A three-block risk taxonomy (inherent, application, secondary), technological and governance countermeasures and role-based guidelines; operators keep logs for at least six months and audit them, monitor risk in real time, keep a traceable chain of responsibility and assess resilience (§5.3)
AIGE-OBL-CN-TC260-OPS. Drawn from chapter 08.
Text alternative
- Clause: TC260 Framework 3.0, Framework 3.0 §5.3.
- Duty holder: Not stated.
- Applies from: No date, Voluntary.
- Artefact: Risk register keyed….
- Layers: Layer 01, Layer 04, Layer 05.
- Evidence record: Evidence record v1.
- Record schema: Evidence record.
- The same topic in 27 other frameworks; the crosswalk section below links each clause.
- Id
AIGE-OBL-CN-TC260-OPS- Instrument
- TC260 AI Safety Governance Framework 3.0 framework
- Clause
- Framework 3.0 §5.3
- Applies from
- No date Voluntary · published 2026-09-14, building on 1.0 (2024) and 2.0 (2025)
The artefact that evidences it
Risk register keyed to the framework's taxonomy; log-retention policy (six months) with audit; real-time risk monitoring; resilience assessment.
Patterns that build it
No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.
The same topic in other frameworks
From the topic crosswalk: the clauses filed under the same topics as this one. Mappings are illustrative, not a claim of conformity.
Risk management
- EU AI Act Art. 9 Risk management system (core)
- ISO 42001 6.1.2 AI risk assessment (core)
- ISO 42001 6.1.3 AI risk treatment (core)
- ISO 42001 8.2 AI risk assessment (operation) (core)
- ISO 42001 8.3 AI risk treatment (operation) (core)
- NIST AI RMF MAP 1 MAP 1: Context is established and understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- NIST AI RMF MANAGE 1 MANAGE 1: AI risks based on assessments and other analytical output are prioritized, responded to, and managed (core)
- ISO 23894 23894 6.4 Risk assessment (core) (clause not verified)
- ISO 23894 23894 6.5 Risk treatment (core) (clause not verified)
- NIST AI RMF GOVERN 1.3 GOVERN 1.3: Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance (core)
- NIST AI RMF MAP 1.5 MAP 1.5: Organizational risk tolerances are determined and documented (core)
- NIST AI RMF MANAGE 1.3 MANAGE 1.3: Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented (core)
- NIST AI RMF MANAGE 1.4 MANAGE 1.4: Negative residual risks to both downstream acquirers of AI systems and end users are documented (core)
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place (core)
- CSA AICM GRC-02 Risk Management Program (core)
- Korea AI Act Art. 34(1)(1) Risk management plan for high-impact AI (core)
- UK ATRS ATRS 2.5.2 Risks and mitigations (core)
- Singapore Agentic Agentic 2.1 Assess and bound the risks upfront (core)
- CoE Convention CoE Art. 16 Risk and impact management framework (core)
- prEN 18228 prEN 18228 AI risk management (draft; supports Art. 9) (core) (clause not verified)
- GAO AI Accountability 1.6 Risk management: implement an AI-specific risk management plan to systematically identify, analyze, and mitigate risks (core)
- ISO 42001 A.6 AI system life cycle
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics
- China GenAI Measures GenAI Art. 17 Security assessment and algorithm filing
- China Algo. Rec. AlgoRec Art. 27 Security assessment
- EU AI Act Art. 3 Definitions
- ISO 42001 6.1.4 AI system impact assessment
- ISO 23894 23894 6.6 Monitoring and review (clause not verified)
- GPAI Code Safety C1 Commitment 1: Safety and Security Framework
- GPAI Code Safety C3 Commitment 3: Systemic risk analysis
- CSA AICM MDS-12 Open Model Risk Assessment
- OECD AI Principles OECD 1.5(c) Systematic risk management at each lifecycle phase
Governance and accountability
- EU AI Act Art. 17 Quality management system (core)
- ISO 42001 5.1 Leadership and commitment (core)
- ISO 42001 5.2 AI policy (core)
- ISO 42001 5.3 Roles, responsibilities and authorities (core)
- ISO 42001 A.2 Policies related to AI (core)
- ISO 42001 A.3 Internal organization (core)
- NIST AI RMF GOVERN 1 GOVERN 1: Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively (core)
- NIST AI RMF GOVERN 2 GOVERN 2: Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained (core)
- China GenAI Measures GenAI Art. 9 Provider responsibility as content producer (core)
- China Algo. Rec. AlgoRec Art. 7 Algorithm-security responsibility system (core)
- China Deep Synthesis DeepSyn Art. 7 Information-security responsibility system (core)
- GDPR Art. 5(2) Accountability (core)
- ISO 42001 9.3 Management review (core) (clause not verified)
- CSA AICM GRC-01 Governance Program Policy and Procedures (core)
- CSA AICM GRC-06 Governance Responsibility Model (core)
- UK ATRS ATRS 2.1 Owner and responsibility (core)
- Singapore GenAI GenAI 1 Accountability (core)
- Singapore Agentic Agentic 2.2.1 Clear allocation of responsibilities within and outside the organisation (core)
- OECD AI Principles OECD 1.5 Accountability (core)
- GAO AI Accountability 1.2 Roles and responsibilities: define clear roles, responsibilities, and delegation of authority for the AI system (core)
- EU AI Act Art. 4 AI literacy
- EU AI Act Art. 87 Reporting of infringements and protection of reporting persons
- ISO 42001 7.2 Competence (clause not verified)
- ISO 42001 9.2 Internal audit (clause not verified)
- ISO 42001 10.1 Continual improvement (clause not verified)
- NIST AI RMF GOVERN 4 GOVERN 4: Organizational teams are committed to a culture that considers and communicates AI risk
- NIST AI RMF GOVERN 5 GOVERN 5: Processes are in place for robust engagement with relevant AI actors
- GPAI Code Safety C8 Commitment 8: Systemic risk responsibility allocation
- Korea AI Act Art. 36 Domestic representative
- CoE Convention CoE Art. 9 Accountability and responsibility
- G7 Code G7 Action 5 Develop, implement and disclose AI governance and risk-management policies
- EN 18286 EN 18286 Quality management system for EU AI Act regulatory purposes
- GAO AI Accountability 1.1 Clear goals: define clear goals and objectives for the AI system
- GAO AI Accountability 1.3 Values: demonstrate a commitment to values and principles established by the entity
Impact assessment
- EU AI Act Art. 27 Fundamental rights impact assessment for high-risk AI systems (core)
- ISO 42001 6.1.4 AI system impact assessment (core)
- ISO 42001 8.4 AI system impact assessment (operation) (core)
- ISO 42001 A.5 Assessing impacts of AI systems (core)
- NIST AI RMF MAP 3 MAP 3: AI capabilities, targeted usage, goals, and expected benefits and costs are understood (core)
- NIST AI RMF MAP 5 MAP 5: Impacts to individuals, groups, communities, organizations, and society are characterized (core)
- China GenAI Measures GenAI Art. 17 Security assessment (core)
- GDPR Art. 35 Data protection impact assessment (core)
- ISO 42005 42005 5.8 Performing the AI system impact assessment (core) (clause not verified)
- ISO 42005 42005 6.8 Actual and reasonably foreseeable impacts (core) (clause not verified)
- CSA AICM GRC-10 AI Impact Assessment (core)
- Korea AI Act Art. 35 Impact assessment (best-effort duty) (core)
- UK ATRS ATRS 2.5.1 Impact assessments (core)
- EU AI Act Art. 9 Risk management system
- GDPR Art. 36 Prior consultation
- ISO 42005 42005 5.12 Monitoring and review (clause not verified)
- CSA AICM DSP-09 Data Protection Impact Assessment
- CoE Convention CoE Art. 16 Risk and impact management framework
- GAO AI Accountability 1.5 Stakeholder involvement: include diverse perspectives from a community of stakeholders throughout the AI life cycle
Data governance
- EU AI Act Art. 10 Data and data governance (core)
- ISO 42001 A.7 Data for AI systems (core)
- China GenAI Measures GenAI Art. 7 Training-data lawful sourcing (core)
- China GenAI Measures GenAI Art. 8 Data-annotation standards (core)
- China GenAI Measures GenAI Art. 11 Protection of user input and records (core)
- China Deep Synthesis DeepSyn Art. 14 Training-data management (core)
- GB/T 45654 GB/T 45654 Corpus security Training-corpus (data) security requirements (core) (clause not verified)
- EU AI Act Art. 10(2)(f)–(g) Examination for possible biases; measures to detect, prevent and mitigate them (core)
- GDPR Art. 5(1)(c) Data minimisation (core)
- GDPR Art. 25 Data protection by design and by default (core)
- ISO 42001 A.7.3 Acquisition of data (core) (clause not verified)
- CSA AICM DSP-20 Data Provenance and Transparency (core)
- UK ATRS ATRS 2.4.3 Development data specification (core)
- Singapore GenAI GenAI 2 Data (core)
- GAO AI Accountability 2.1 Sources: document sources and origins of data used to develop the models (core)
- GAO AI Accountability 2.2 Reliability: assess reliability of data used to develop the models (core)
- EU AI Act Art. 4a Special-category data for bias detection
- ISO 42001 A.4 Resources for AI systems
- NIST AI RMF MAP 2 MAP 2: Categorization of the AI system is performed
- NIST AI RMF MEASURE 2.10 MEASURE 2.10: Privacy risk of the AI system is examined and documented
- NIST AI RMF MEASURE 2.11 MEASURE 2.11: Fairness and bias are evaluated and results are documented
- EU AI Act Art. 53 Obligations for providers of general-purpose AI models
- EU AI Act Art. 53(1)(c) Copyright policy, including rights reservations
- EU AI Act Art. 5(1)(e) Prohibited: untargeted scraping of facial images
- GPAI Code Copyright 1.1–1.5 Commitment 1: Copyright policy (Measures 1.1 to 1.5)
- GDPR Art. 9 Processing of special categories of personal data
- CSA AICM DSP-21 Data Poisoning Prevention & Detection
- OWASP LLM LLM05:2026 Data and Model Poisoning
- GAO AI Accountability 2.4 Variable selection: assess data variables used in the AI component models
- GAO AI Accountability 2.5 Enhancement: assess the use of synthetic, imputed, and/or augmented data
Inventory and registration
- EU AI Act Art. 49 Registration (core)
- EU AI Act Art. 71 EU database for high-risk AI systems (core)
- ISO 42001 A.4 Resources for AI systems (core)
- NIST AI RMF GOVERN 1.6 GOVERN 1.6: Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities (core)
- China Algo. Rec. AlgoRec Art. 24 Algorithm filing (core)
- China Deep Synthesis DeepSyn Art. 19 Filing for public-opinion services (core)
- China GenAI Measures GenAI Art. 17 Algorithm filing (core)
- UK ATRS ATRS Tier 1 Summary information (the published record) (core)
- EU AI Act Art. 6 Classification rules for high-risk AI systems
- TC260 Framework 3.0 TC260 App. 2 II.2 Identity and access management
- EU AI Act Art. 3(1) Definition of an AI system
- EU AI Act Art. 52 Procedure
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness
- CSA AICM STA-08 Supply Chain Inventory
- CSA AICM IAM-03 Identity Inventory
- Korea AI Act Art. 33 Confirmation of high-impact AI
- GAO AI Accountability 3.1 Documentation: catalog model and non-model components, along with operating specifications and parameters
Logging and traceability
- EU AI Act Art. 12 Record-keeping (core)
- ISO 42001 A.6 AI system life cycle (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Continuous monitoring and auditing (core)
- EU AI Act Art. 26(6) Deployers keep the automatically generated logs (core)
- ISO 42001 A.6.2.8 AI system recording of event logs (core) (clause not verified)
- CSA AICM LOG-09 Log Records (core)
- Korea AI Act Art. 34(1)(5) Documents showing the measures taken (core)
- OECD AI Principles OECD 1.5(b) Traceability of datasets, processes and decisions (core)
- prEN 18229-1 prEN 18229-1 AI trustworthiness framework, Part 1: logging (draft; supports Art. 12) (core) (clause not verified)
- GAO AI Accountability 4.3 Traceability: document results of monitoring activities and any corrective actions taken (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored
- NIST AI RMF MEASURE 3 MEASURE 3: Mechanisms for tracking identified AI risks over time are in place
- China AI Labelling Label Art. 5 Implicit metadata labels
- EU AI Act Art. 19 Automatically generated logs
- CSA AICM LOG-12 Transaction/Activity Logging
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
Runtime guardrails
- ISO 42001 A.9 Use of AI systems (core)
- NIST AI RMF MANAGE 2 MANAGE 2: Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by relevant AI actors (core)
- TC260 Framework 3.0 TC260 App. 2 II.5 Dynamic runtime management (core)
- China GenAI Measures GenAI Art. 10 Guided, bounded use (core)
- China GenAI Measures GenAI Art. 14 Stop unlawful generation (core)
- China Deep Synthesis DeepSyn Art. 10 Input and output review (core)
- CSA AICM TVM-13 Guardrails (core)
- CSA AICM AIS-09 Input Validation (core)
- CSA AICM AIS-10 Output Validation (core)
- OWASP LLM LLM01:2026 Prompt Injection (core)
- OWASP LLM LLM10:2026 Improper Output Handling (core)
- Singapore Agentic Agentic 2.3.1 During design and development, use technical controls (core)
- EU AI Act Art. 5 Prohibited AI practices
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity
- ISO 42001 A.6 AI system life cycle
- China Algo. Rec. AlgoRec Art. 8 Periodic algorithm review
- China Algo. Rec. AlgoRec Art. 9 Feature database for unlawful content
- EU AI Act Art. 5(1)(a)–(b) Manipulative techniques; exploitation of vulnerabilities
- GPAI Code Safety C5 Commitment 5: Safety mitigations
- OWASP LLM LLM06:2026 Unbounded Consumption
Robustness, security and evaluations
- EU AI Act Art. 15 Accuracy, robustness and cybersecurity (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk (core)
- ISO 42001 A.6 AI system life cycle (core)
- NIST AI RMF MEASURE 2 MEASURE 2: AI systems are evaluated for trustworthy characteristics (core)
- TC260 Framework 3.0 TC260 App. 2 II.6 Sandbox validation and red teaming (core)
- China Deep Synthesis DeepSyn Art. 15 Technology management and algorithm verification (core)
- China Deep Synthesis DeepSyn Art. 20 Security assessment of new products (core)
- GB/T 45654 GB/T 45654 Security assessment Security-assessment requirements for generative AI services (core) (clause not verified)
- GPAI Code Safety 3.2 Measure 3.2: Model evaluations (core)
- NIST AI RMF MEASURE 2.7 MEASURE 2.7: AI system security and resilience as identified in the MAP function are evaluated and documented (core)
- CSA AICM MDS-06 Adversarial Attack Analysis (core)
- CSA AICM MDS-07 Robustness against Adversarial Attack / Model Hardening (core)
- Singapore GenAI GenAI 5 Testing and Assurance (core)
- Singapore GenAI GenAI 6 Security (core)
- Singapore Agentic Agentic 2.3.2 Before deploying, test agents (core)
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified (core)
- OECD AI Principles OECD 1.4 Robustness, security and safety (core)
- G7 Code G7 Action 1 Identify, evaluate and mitigate risks across the lifecycle, including testing (core)
- GAO AI Accountability 3.7 Assessment: assess performance against defined metrics to ensure the AI system functions as intended and is sufficiently robust (core)
- EU AI Act Art. 60 Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes
- ISO 42001 9.1 Monitoring, measurement, analysis and evaluation
- China GenAI Measures GenAI Art. 17 Security assessment
- EU AI Act Art. 15(3) Declared accuracy levels and metrics
- EU AI Act Art. 9 Risk management system
- EU AI Act Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act)
- GPAI Code Safety C6 Commitment 6: Security mitigations
- GDPR Art. 32 Security of processing
- NIST AI RMF MEASURE 2.1 MEASURE 2.1: Test sets, metrics, and details about the tools used during TEVV are documented
- NIST AI RMF MEASURE 1 MEASURE 1: Appropriate methods and metrics are identified and applied
- CSA AICM AIS-05 Application Security Testing
- OWASP LLM LLM01:2026 Prompt Injection
- OWASP Agentic ASI05 Unexpected Code Execution (RCE)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold
- GAO AI Accountability 3.2 Metrics: define performance metrics that are precise, consistent, and reproducible
Incident response and monitoring
- EU AI Act Art. 72 Post-market monitoring by providers and post-market monitoring plan (core)
- EU AI Act Art. 73 Reporting of serious incidents (core)
- ISO 42001 A.8 Information for interested parties (core)
- ISO 42001 10.2 Nonconformity and corrective action (core)
- NIST AI RMF MANAGE 4 MANAGE 4: Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored (core)
- China GenAI Measures GenAI Art. 14 Handle and report unlawful content (core)
- China GenAI Measures GenAI Art. 15 Complaint and reporting mechanism (core)
- EU AI Act Art. 26(5) Deployer monitoring, informing the provider and suspending use (core)
- GPAI Code Safety C9 Commitment 9: Serious incident reporting (core)
- GDPR Arts. 33–34 Notification and communication of a personal data breach (core)
- NIST AI RMF MANAGE 4.3 MANAGE 4.3: Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented (core)
- CSA AICM SEF-07 Incident Management and Response (core)
- CSA AICM SEF-08 Security Breach Notification (core)
- Korea AI Act Art. 32(1) Safety duties for AI above the compute threshold (core)
- Singapore GenAI GenAI 4 Incident Reporting (core)
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test (core)
- G7 Code G7 Action 2 Identify and mitigate vulnerabilities, incidents and misuse after deployment (core)
- G7 Code G7 Action 4 Responsible information sharing and reporting of incidents (core)
- GAO AI Accountability 4.1 Planning: develop plans for continuous or routine monitoring of the AI system (core)
- GAO AI Accountability 4.2 Drift: establish the range of data and model drift that is acceptable (core)
- EU AI Act Art. 55 Obligations for providers of general-purpose AI models with systemic risk
- TC260 Framework 3.0 TC260 App. 2 II.6 Emergency plans
- China Algo. Rec. AlgoRec Art. 7 Security management and emergency response
- EU AI Act Art. 3(49) Definition of serious incident
- EU AI Act Art. 20 Corrective actions and duty of information
- GPAI Code Safety 3.5 Measure 3.5: Post-market monitoring
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use
- NIST AI RMF GOVERN 4.3 GOVERN 4.3: Organizational practices are in place to enable AI testing, identification of incidents, and information sharing
Supply chain and third parties
- EU AI Act Art. 25 Responsibilities along the AI value chain (core)
- ISO 42001 A.10 Third-party and customer relationships (core)
- NIST AI RMF GOVERN 6 GOVERN 6: Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues (core)
- NIST AI RMF MAP 4 MAP 4: Risks and benefits are mapped for all AI system components including third-party software and data (core)
- NIST AI RMF MANAGE 3 MANAGE 3: AI risks and benefits from third-party entities are managed (core)
- TC260 Framework 3.0 TC260 App. 2 II.4 Supply chain and tool management (core)
- EU AI Act Art. 25(4) Written agreement with third-party suppliers (core)
- GDPR Art. 28 Processor (core)
- NIST AI RMF MANAGE 3.1 MANAGE 3.1: AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented (core)
- CSA AICM STA-10 Supply Chain Risk Management (core)
- CSA AICM STA-09 Service Bill of Material (BOM) (core)
- OWASP LLM LLM04:2026 Supply Chain (core)
- OWASP Agentic ASI04 Agentic Supply Chain Vulnerabilities (core)
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems
- China GenAI Measures GenAI Art. 7 Lawful data and model sources
- China Deep Synthesis DeepSyn Art. 14 Providers and technical supporters
- EU AI Act Art. 22 Authorised representatives of providers of high-risk AI systems
- EU AI Act Art. 23 Obligations of importers
- EU AI Act Art. 24 Obligations of distributors
- EU AI Act Art. 54 Authorised representatives of providers of general-purpose AI models
- GPAI Code Transparency 1.2 Providing relevant information
- GDPR Arts. 44–46 Transfers to third countries
- NIST AI RMF GOVERN 6.2 GOVERN 6.2: Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk
- UK ATRS ATRS 2.1.4 Third party involvement
- G7 Code G7 Action 11 Implement data input measures and protect personal data and intellectual property
- GAO AI Accountability 2.6 Dependency: assess interconnectivities and dependencies of data streams that operationalize the AI system
Deployment, change and decommissioning
- EU AI Act Art. 26 Obligations of deployers of high-risk AI systems (core)
- ISO 42001 A.6.2.5 AI system deployment (core) (clause not verified)
- ISO 42001 A.6.2.6 AI system operation and monitoring (core) (clause not verified)
- NIST AI RMF MANAGE 2.4 MANAGE 2.4: Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use (core)
- NIST AI RMF MANAGE 4.1 MANAGE 4.1: Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management (core)
- NIST AI RMF GOVERN 1.7 GOVERN 1.7: Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness (core)
- CSA AICM AIS-06 Secure Application Deployment (core)
- EU AI Act Art. 25 Responsibilities along the AI value chain
- EU AI Act Art. 43(4) New conformity assessment on substantial modification
- EU AI Act Art. 20 Corrective actions and duty of information
- EU AI Act Art. 79 Procedure at national level for dealing with AI systems presenting a risk
- EU AI Act Art. 86 Right to explanation of individual decision-making
- ISO 42001 A.9 Use of AI systems
- CSA AICM CCC-01 Change Management Policy and Procedures
- CSA AICM DSP-02 Secure Disposal
- Singapore Agentic Agentic 2.3.3 When deploying, continuously monitor and test
- CoE Convention CoE Art. 16(2)(g) Testing before first use and when significantly modified
- OECD AI Principles OECD 1.4 Robustness, security and safety
- GAO AI Accountability 4.4 Ongoing assessment: assess the utility of the AI system to ensure its relevance to the current context
- GAO AI Accountability 4.5 Scaling: identify conditions, if any, under which the AI system may be scaled or expanded beyond its current use
Source
Chapter 08, section China, checked against its sources on the review date above.
Machine-readable
- This obligation:
/api/v1/obligations/aige-obl-cn-tc260-ops.json - The register:
/api/v1/obligations.json· CSV - Schema and stability promise: open data and API
Cite this obligation
García Aibar, J. (2026). TC260 AI Safety Governance Framework 3.0: operators' guidelines §5.3 (voluntary; 2026-09-14) (AIGE-OBL-CN-TC260-OPS). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-ops. CC BY 4.0
BibTeX
@misc{aige2026obligation,
author = {Jorge García Aibar},
title = {{TC260 AI Safety Governance Framework 3.0: operators' guidelines §5.3 (voluntary; 2026-09-14) (AIGE-OBL-CN-TC260-OPS)}},
howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
year = {2026},
version = {0.5.0},
doi = {10.5281/zenodo.22956197},
url = {https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-ops},
note = {Version 0.5.0}
}