Law / Frameworks

Governance frameworks, read against the law

A governance framework lists the controls to run. Each page here turns one around: under every control, the laws we track that bear on it and the places that made them.

AI governance

FrameworkWhere the law landsControls with lawLawsPlacesLaws naming itWhat we print
NIST AI Risk Management FrameworkNational Institute of Standards and Technology, version 1.0, January 2023 (NIST AI 100-1) 37 of 72 controls with law, 747 laws 37 of 72 747 257 2 Full text, public domain (a US government work)
NIST Generative AI ProfileNational Institute of Standards and Technology, July 2024 (NIST AI 600-1) 8 of 12 controls with law, 366 laws 8 of 12 366 158 none Full text, public domain (a US government work)
OWASP Top 10 for LLM ApplicationsOWASP GenAI Security Project, 2026 edition, August 2026 5 of 10 controls with law, 165 laws 5 of 10 165 115 none Excerpts, CC BY-SA 4.0
OWASP Top 10 for Agentic ApplicationsOWASP GenAI Security Project, 2026 edition, December 2025 4 of 10 controls with law, 200 laws 4 of 10 200 123 none Excerpts, CC BY-SA 4.0
MIT AI Risk Mitigation TaxonomyMIT AI Risk Initiative, preliminary taxonomy, July 2025 18 of 23 controls with law, 366 laws 18 of 23 366 158 none Full text, CC BY 4.0

Privacy

FrameworkWhere the law landsControls with lawLawsPlacesLaws naming itWhat we print
NIST Privacy FrameworkNational Institute of Standards and Technology, version 1.0, January 2020 62 of 100 controls with law, 1,212 laws 62 of 100 1,212 234 1 Full text, public domain (a US government work)

Security

FrameworkWhere the law landsControls with lawLawsPlacesLaws naming itWhat we print
NIST Cybersecurity FrameworkNational Institute of Standards and Technology, version 2.0, February 2024 (NIST CSWP 29) 61 of 106 controls with law, 225 laws 61 of 106 225 122 5 Full text, public domain (a US government work)

Laws that name a framework

15 laws we track name a framework in their own text. What following it does differs from law to law, and each law's page says on what terms.

PlaceLawWhat naming it doesFrameworks it names
A defence, or a limit on damages
Connecticut Adoption of cybersecurity controls by businesses, exemption from punitive damages a limit on damages
NIST CSFNIST SP 800-171NIST SP 800-53FedRAMPCIS ControlsISO/IEC 27000 seriesPCI DSS
Iowa Tort Liability for Cybersecurity Programs, affirmative defense for a reasonable security program a defence to a claim
NIST CSFNIST SP 800-171NIST SP 800-53FedRAMPCIS ControlsISO/IEC 27000 seriesPCI DSS
Ohio Ohio Data Protection Act, cybersecurity program safe harbor a defence to a claim
NIST CSFNIST SP 800-171NIST SP 800-53FedRAMPCIS ControlsISO/IEC 27000 seriesPCI DSS
Tennessee Tennessee Information Protection Act, Attorney General enforcement and NIST safe harbor a defence to a claim
NIST Privacy FrameworkAPEC CBPR and PRP
Texas Cybersecurity Program safe harbor from exemplary damages (S.B. 2610) a limit on damages
NIST CSFNIST SP 800-171NIST SP 800-53FedRAMPCIS ControlsISO/IEC 27000 seriesHITRUST CSFSecure Controls FrameworkSOC 2PCI DSS
or a comparable framework
Utah Cybersecurity Affirmative Defense Act a defence to a claim
NIST SP 800-171NIST SP 800-53FedRAMPCIS ControlsISO/IEC 27000 seriesPCI DSS
Presumed to conform
California Security of Connected Devices presumed to conform
NIST IoT labelling criteria
El Salvador Resolución ANIA 0001/2025, registro obligatorio para decisiones consecuenciales presumed to conform
ISO/IEC 42001ISO/IEC 23053ISO/IEC 23894ISO/IEC 38507NIST AI RMFIEEE 7000IEEE 7001IEEE 7010
or a comparable framework
Michigan Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty proposed presumed to conform
Required
Michigan Senate Bill 360 (2025-2026), Identity Theft Protection Act reasonable security procedures duty proposed required or a comparable framework
Montana Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty required
NIST AI RMFISO/IEC 42001
or a comparable framework
Montenegro Law on Information Security, Essential and Important Entities required
ISO/IEC 27001
Nevada Security measures for data collectors maintaining personal information from a date not yet set required
CIS Controlsthe corresponding NIST standards
United States Safeguarding Covered Defense Information and Cyber Incident Reporting (DFARS 252.204-7012) required
NIST SP 800-171FedRAMP
Named as one way to do it
Côte d'Ivoire RGSSI and PPIC Compliance Duty one accepted way
ISO/IEC 27001ISO/IEC 27002
Georgia SB 351 (2024), commercial entity age verification for material harmful to minors one accepted way
NIST identity assurance level 2

How we read a framework against the law

Three frameworks are read line by line: each requirement line of the laws in their field (the AI and scraping laws for the NIST AI RMF, the privacy and communications laws for the NIST Privacy Framework, the cybersecurity laws for the NIST CSF 2.0) was mapped on its own to the control it bears on most closely. The others are read through the kinds of duty a law carries, such as a ban, a disclosure or a security duty, counting a kind of duty only where the law's own lines, as read against the NIST AI RMF, bear it out.

Laws on age assurance and news aggregation are not read against these frameworks yet. Laws that are no longer in force are left out of every count.