AISI

[AI 안전 동향 분석 시리즈] (26-01) AI사고 정의 및 보고체계 국제동향
  • 분류
    보고서
  • 등록일
    2026-05-19 18:53:19
  • 작성자
    운영자
  • 조회수
    926
  • 인공지능안전연구소는 AI 안전 분야 중 특정 주제 또는 이슈를 선정하여 정리한 보고서 유형인 'AI 안전 동향 분석 시리즈'를 발간합니다.

    그 첫 번째로서 AI사고의 정의 및 AI사고 보고체계에 관한 국제적 동향을 정리했습니다.

    본 보고서는 주요국 및 국제기구의 AI사고 정의 및 보고체계 현황을 비교·분석하고, 국제적 논의 동향과 제도적 특징을 종합적으로 검토한다.

    AI사고 정의: 국제적으로 AI사고 개념은 OECD 프레임워크를 중심으로 형성되고 있다. OECD는 실제 피해 발생 여부를 기준으로 AI사고(AI Incident)와 AI위험원(AI Hazard)을 구분하고, 피해 수준에 따라 중대 AI사고(Serious AI Incident)와 AI재난(AI Disaster)으로 세분화한다. 이는 단순한 기술적 오류를 넘어, AI시스템이 인간의 생명·신체·재산·기본권 및 사회 전반에 미치는 영향을 포괄적으로 고려하려는 접근이라는 점에서 의미를 가진다. 또한 OECD는 국가 간 보고 기준의 정합성과 비교 가능성 확보를 위해 88개 후보 기준을 8개 차원으로 재구성한 후, 29개 공통 보고 기준과 7개 핵심 필수 기준으로 구성된 공통 보고 프레임워크를 구축하고 있다. 이러한 논의는 AI사고를 국제적으로 공유·비교 가능한 위험 관리 대상으로 체계화하려는 흐름으로 볼 수 있다.

    AI사고 보고체계: 주요국의 AI사고 보고체계는 크게 통합형 모델과 분산형 모델로 구분된다. EU는 AI사고 전용 의무 보고체계를 법제화한 대표적 사례로, 고위험 AI시스템 제공자에게 중대 사고 발생 시 일정 기간 내 시장감시당국(MSA)에 보고 의무를 부과하는 통합적 규제 체계를 운영하고 있다. 특히 사망 사고, 기본권 침해, 중요 인프라 교란 등 중대한 피해 유형에 대해서는 신속 보고 및 감독기관 간 정보 공유 체계를 마련하고 있다. 반면 영국·미국·캐나다 등은 기존 산업별 법체계에 기반한 분산형 접근을 유지하면서 AI사고 보고 의무와 중앙 관리 체계 도입을 검토하고 있다. 일본·싱가포르·호주는 가이드라인 중심의 연성규범(soft law) 접근 아래 자율적 위험 관리와 보완적 거버넌스 체계를 운영하고 있으며, 중앙 모니터링 및 정보 공유 체계 구축 가능성을 함께 논의하고 있다. 케냐는 AI 거버넌스 체계 구축 초기 단계로, 데이터보호 및 사이버보안 관련 기존 법률을 중심으로 제한적 대응 체계를 운영하고 있다.

    주요국 및 국제기구는 AI사고를 기존 산업별 규제체계만으로 관리하기 어렵다는 공통된 문제의식을 바탕으로, OECD 중심의 공통 정의 및 보고 기준 마련 논의를 확대하고 있다. 또한 각국은 위험 기반 접근(risk-based approach)을 토대로 의무 보고, 중앙 모니터링, 정보 공유 등 다양한 대응체계 정비를 추진하고 있으며, 이는 향후 국제 AI 거버넌스 체계 논의가 AI사고의 정의 및 보고체계 정립을 중심으로 전개될 가능성을 시사한다.

    This report provides a comparative analysis of AI incident definitions and reporting frameworks across major jurisdictions and international organizations, while examining international regulatory discussions and institutional approaches related to AI incident governance.

    Defining AI Incidents: Internationally, the OECD framework has emerged as the primary reference point for defining AI incidents. The OECD distinguishes between AI Incidents, where actual harm has occurred, and AI Hazards, where harm has not yet materialized but could plausibly occur. It further classifies incidents by severity into Serious AI Incidents and AI Disasters. This approach is significant in that it extends beyond technical malfunctions to encompass the broader impacts of AI systems on human life, bodily integrity, property, fundamental rights, and society as a whole. To improve consistency and comparability across jurisdictions, the OECD is also developing a common reporting framework consisting of 29 common reporting criteria and 7 core mandatory criteria refined from an initial set of 88 candidate criteria organized across eight dimensions. These developments reflect broader efforts to establish AI incidents as internationally comparable and shareable objects of risk management and governance.

    AI Incident Reporting Systems: National AI incident reporting systems can broadly be divided into integrated and decentralized models. The EU represents the most developed integrated model, having legislated a mandatory AI-specific reporting regime that requires providers of high-risk AI systems to report serious incidents to Market Surveillance Authorities (MSAs) within specified timeframes. In particular, the EU framework establishes expedited reporting and information-sharing mechanisms for incidents involving death, violations of fundamental rights, or serious disruptions to critical infrastructure. In contrast, the UK, the US, and Canada continue to rely primarily on decentralized approaches based on existing sector-specific legal frameworks while considering the introduction of mandatory reporting obligations and centralized oversight mechanisms. The United States manages AI-related risks through sectoral reporting systems operated by regulatory agencies in areas such as healthcare, transportation, data protection, and consumer protection. Similarly, the UK addresses AI-related incidents through existing reporting regimes in sectors including healthcare, telecommunications, finance, and data protection. Canada is currently considering the introduction of an AI regulatory and reporting framework centered on the concept of “harm” through the proposed Artificial Intelligence and Data Act(AIDA). Japan, Singapore, and Australia maintain soft law approaches centered on guidelines, voluntary risk management, and supplementary governance mechanisms, while also exploring centralized monitoring and information-sharing systems. Kenya remains at an early stage of developing its AI governance framework and currently relies on existing data protection and cybersecurity laws as limited regulatory mechanisms.

    Overall, major jurisdictions and international organizations share the view that AI incidents are difficult to manage solely through existing sector-specific regulatory systems. In response, discussions led by the OECD on common definitions and reporting standards for AI incidents continue to expand internationally. At the same time, jurisdictions are increasingly exploring policy measures such as mandatory reporting obligations, centralized monitoring systems, and information-sharing mechanisms based on risk-based approaches. These developments suggest that future international AI governance discussions are likely to place greater emphasis on establishing common frameworks for defining and reporting AI incidents.
  • 첨부파일