← Latest papers
💻 computer science

Post-Deployment Accountability in AI Governance: A Cross-Regulatory Empirical Analysis of AI Incidents

This empirical study analyzes AI incidents from 2020 to 2026 against major regulatory frameworks to reveal significant post-deployment accountability gaps, particularly in external detection and impact assessments, while proposing the Proactive AI Governance Compliance Framework (PAGCF) to address these systemic failures.

Original authors: Ummara Mumtaz, Rabi Noor, Summaya Mumtaz

Published 2026-08-19
📖 4 min read☕ Coffee break read

Original authors: Ummara Mumtaz, Rabi Noor, Summaya Mumtaz

Original paper licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine a world where the software making life-or-death decisions in hospitals, the algorithms deciding who gets a loan, and the systems sorting job applications are constantly watched. For years, the conversation about artificial intelligence has focused on how these systems are built and whether they are fair before they are turned on. But a new question has emerged that is just as critical: what happens after they are deployed? Once these systems are running in the real world, who is responsible for watching them, spotting when they go wrong, and fixing them before they hurt people? This is the realm of post-deployment accountability. It is not about the code itself, but about the human and organizational routines that keep the code in check. If a system starts making dangerous errors, does the company know immediately? Do they have a plan to stop it? Do they tell the people affected? Without these safety nets, even the most carefully designed technology can become a source of unmanaged harm.

A team of researchers set out to see if these safety nets actually exist in practice. They did not look at theoretical rules or company promises; instead, they examined the real-world failures of artificial intelligence systems. They gathered data on 480 specific incidents where AI systems caused harm between 2020 and 2026. These incidents ranged from medical errors to biased hiring decisions and were collected from a public database that tracks such events. The researchers then measured each incident against three major sets of rules designed to govern AI: the European Union's AI Act, a voluntary framework from the US National Institute of Standards and Technology, and the General Data Protection Regulation, which focuses on privacy. They were looking for concrete evidence that the companies involved were doing the things these rules require, such as continuously monitoring their systems, reporting serious accidents, or assessing risks before they happened.

The results revealed a stark reality: the safety nets are largely missing. When the researchers looked for proof that companies were watching their systems after they were launched, they found almost nothing. In nearly 80 percent of the cases, there was no evidence that the required continuous monitoring was taking place. For the rules regarding privacy and risk assessment, the gap was even wider; in more than 99 percent of the relevant cases, there was no public record showing that a formal risk assessment had been done. The picture was not one of companies breaking specific laws, but of a complete absence of the documentation and processes that would prove they were following any rules at all. The researchers found that when these systems failed, the public record rarely showed that anyone had been watching, that anyone had a plan to respond, or that anyone had been held accountable.

Perhaps the most revealing discovery was about how these failures were found. In the vast majority of cases, the problems were not spotted by the companies running the systems. Instead, they were uncovered by journalists, researchers, or the public after the damage was already done. The study found that when a company did have an internal system to watch for errors and catch them before they became public, the outcome was dramatically different. In the small number of cases where the company found the problem itself, they were far more likely to have followed the rules, responded quickly, and fixed the issue. This suggests that the ability to see a problem before it explodes is the single most important factor in whether a company can govern its technology effectively. It is not enough to have a policy on paper; the organization must have the capacity to actually see when things go wrong.

The researchers argue that the current approach to AI governance is too reactive. It waits for a disaster to happen and then tries to manage the fallout. They propose a new way of thinking that shifts the focus to the time before and during the operation of the system. This approach involves four steps: checking the system thoroughly before it launches, keeping a constant watch on its performance, having a clear plan ready for when things go wrong, and checking that all the rules are being followed across different standards. The study suggests that if companies could implement even one part of this plan—specifically, the ability to monitor their own systems internally—they would likely see a massive improvement in how they handle AI risks. The evidence shows that the tools and rules to manage these systems exist, but the daily habits and monitoring routines needed to make them work are missing. Until organizations build the capacity to watch their own creations, the responsibility for fixing AI failures will continue to fall on the public, rather than on the people who built them.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →