S0007RS1-T01-S0007-Z · Full risk code

Regulatory Gaps in Specific Sectors

特定產業監管空白

Inception
Risk Description

When an organization introducing an AI application in a regulated sector finds that the authority has not yet issued clear standards for that type of application; due to unmitigated control gaps, the organization implements controls based on its own judgment, but the authority later takes a different view and deems the existing approach non-compliant, resulting in remediation orders or sanctions, and casting doubt on the validity of past decisions, triggering compliance exposure and operational reputational costs.

Framework Mappings

EU AI ActArt.95
ISO/IEC 42001§4.2
NIST AI RMFGOVERN 1.1
ISO/IEC 5338啟動
MIT AI Risk RepositoryDomain 6

Risk Treatment & Implementation Guidance

Where standards are unclear, proactively seek the authority's views and retain the correspondence as evidence of good-faith compliance and due care; Adopt international standards and recognized industry practice as the internal control baseline, document the basis for adoption, and realign promptly once the authority takes a position