Law / Frameworks / FINOS AIGF / Preventative
FINOS AIGF AIR-PREV-007Legal and Contractual Frameworks for AI Systems
Robust legal and contractual agreements are essential for governing the development, procurement, deployment, and use of AI systems within a financial institution. This control ensures that comprehensive frameworks are established and maintained to manage risks, define responsibilities, protect data, and ensure compliance with legal and regulatory obligations when engaging with AI technology vendors, data providers, partners, and even in defining terms for end-users. These agreements must be thoroughly understood and actively managed to ensure adherence to all stipulated requirements.FINOS AI Governance Framework, version 2, as maintained on , AIR-PREV-007
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Law library as of .
The kinds of duty that reach it: TDM, attribution, contract terms, security, transfer.
- 283
- laws
- 146
- places
- 0
- with court rulings behind them
- 25
- not yet in force
- 7
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 6.1 Policies and procedures are in place that address AI risks associated with third-party...
- NIST AI RMFMAP 4.1 Approaches for mapping AI technology and legal risks of its components – including the...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-10 Intellectual Property
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations3.2 Data Governance
- MIT mitigations2.1 Model & Infrastructure Security
- NIST Privacy FrameworkID.DE-P2 Data processing ecosystem parties (e.g., service providers, customers, partners,...
- NIST Privacy FrameworkID.DE-P3 Contracts with data processing ecosystem parties are used to implement appropriate...
- NIST CSF 2.0GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are...
- NIST CSF 2.0GV.SC-05 Requirements to address cybersecurity risks in supply chains are established,...
- CIS Controls3.8 Recording how sensitive data moves between systems and parties.
- CIS Controls3.10 Encryption of sensitive data as it crosses networks.
A law in force is unmarked; the rest wear their state: not yet in force proposed
Comprehensive regime
83 laws, 81 placesShow the other 73 laws
Cross border transfer
76 laws, 76 placesShow the other 66 laws
Security baseline statutes
33 laws, 31 placesShow the other 23 laws
Copyright and text and data mining (TDM)
20 laws, 20 placesShow the other 10 laws
Snippet reproduction
17 laws, 17 placesShow the other 7 laws
| Copyright Act 2019, news and current-events exceptions to copyright |
Through its attribution duty. What it requires |
|
| Ley No. 312, quotation and press-reproduction limitations |
Through its attribution duty. What it requires |
|
| Ley de Derechos Morales de Autor de Puerto Rico, news and criticism exception |
Through its attribution duty. What it requires |
|
| Decreto-Lei n.º 02/2017, exclusão das notícias do dia, revista de imprensa e citação |
Through its attribution duty. What it requires |
|
| Copyright Act, news reproduction and press-article exceptions |
Through its attribution duty. What it requires |
|
| Copyright Act 2002, Reproduction of Newspaper Articles and Quotation Exceptions |
Through its attribution duty. What it requires |
|
| Copyright Act, Facts Exclusion and Quotation and Press-Review Exception |
Through its attribution duty. What it requires |
Sector security regimes
16 laws, 16 placesShow the other 6 laws
| FSM Telecommunications Act of 2014, Security Safeguards for Customer Information |
Through its security duty. What it requires |
|
| Law on Information Security, ICT Systems of Special Importance and Security Measures |
Through its security duty. What it requires |
|
| Telecommunications Act 2009, Security Safeguards for Consumer Information |
Through its security duty. What it requires |
|
| Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit |
Through its security duty. What it requires |
|
| Cybersecurity Act 2025, Critical Infrastructure Operator Obligations from a date not yet set |
Through its security duty. What it requires |
|
| Law on Communications, network and subscriber-information protection duties |
Through its security duty. What it requires |
Database right
8 laws, 8 placesProduct security requirements
8 laws, 8 placesVulnerability and incident reporting
8 laws, 8 placesSensitive categories
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Law on the Protection of Personal Data, sensitive data categories |
Through its security duty. What it requires |
|
| Law No. 133/V/2001 on the Protection of Personal Data, sensitive data categories |
Through its security duty. What it requires |
|
| Law No. 09-08, sensitive personal data and offense records |
Through its security duty. What it requires |
|
| Law relating to the Protection of Personal Data and Privacy, sensitive personal data and children's data |
Through its security duty. What it requires |
|
| Lei n.º 03/2016, sensitive categories and suspect records |
Through its security duty. What it requires |
AI risk obligations
2 laws, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
Through its security duty. What it requires |
|
| AI Act, Article 25 (responsibilities along the AI value chain) from , in 14 months |
Through its contract terms duty. What it requires |
Enforcement supervision
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Student Data Accessibility, Transparency and Accountability Act (SDATAA) from a date not yet set |
Through its transfer duty. What it requires |
|
| Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 |
Through its security duty. What it requires |
Press publishers' right
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Copyright and Neighbouring Rights Act (ZAPSP), Arts. 90d and 90zh, Press Publisher Right |
Through its attribution duty. What it requires |
|
| Legge sul Diritto d'Autore Art. 43-bis, Press Publisher Neighbouring Right |
Through its attribution duty. What it requires |
AI sector rules
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Reform to the Federal Labor Law and the Federal Copyright Law, AI Voice and Image Consent Regime for Performing Artists |
Through its contract terms duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its TDM duty. What it requires |
Breach notification
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| National Digital Identification Act 2024, personal data breach notification |
Through its security duty. What it requires |
Full text of the FINOS AI Governance Framework, CC BY 4.0. FINOS AI Governance Framework, https://air-governance-framework.finos.org/, copyright 2025 FINOS, licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Titles and purpose text are quoted; markdown emphasis and links were removed. Every control of the framework.
CIS Critical Security Controls® (CIS Controls®) v8.1 © Center for Internet Security, Inc. Safeguard numbers are used under a CIS Controls Supporter License; the one-line descriptions beside them are our own, not CIS text.