Law / Frameworks / MIT mitigations
MIT AI Risk Mitigation Taxonomy
Below are its 23 controls in the framework's own order, and under each one the laws we track that bear on it. Each mapping is our reading that a law bears on a control, never a finding that running the control meets the law.
Where the law lands in the framework
18of 23 controls have law366laws158places
Of these laws, 314 are in force, 40 not yet in force, 1 blocked by a court, and 11 proposed and not law.
3 of the 7 controls under Governance & Oversight Controls have no law we track under them.
- in force
- not yet in force
- blocked by a court
- proposed
- no law we track
Read through the kinds of duty each AI and scraping law we track carries, counting a kind of duty only where the law's own requirement lines, as read against the NIST AI Risk Management Framework, bear it out.
Governance & Oversight Controls
4 of 7 controls with lawFormal organizational structures and policy frameworks that establish human oversight mechanisms and decision protocols to ensure human accountability, ethical conduct, and risk management throughout AI development and deployment.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| 1.1 | Board Structure & Oversight 35 laws, 18 not yet in force | 35 | 24 | 18 | 0 | 0 | |
| 1.2 | Risk Management 41 laws, 20 not yet in force, 3 proposed | 41 | 27 | 20 | 0 | 3 | |
| 1.3 | Conflict of Interest Protections no law we track | no law we track | |||||
| 1.4 | Whistleblower Reporting & Protection no law we track | no law we track | |||||
| 1.5 | Safety Decision Frameworks 118 laws, 4 not yet in force, 1 blocked, 2 proposed | 118 | 77 | 4 | 1 | 2 | |
| 1.6 | Environmental Impact Management no law we track | no law we track | |||||
| 1.7 | Societal Impact Assessment 7 laws, 2 not yet in force, 3 proposed | 7 | 6 | 2 | 0 | 3 | |
Technical & Security Controls
3 of 4 controls with lawTechnical, physical, and engineering safeguards that secure AI systems and constrain model behaviors to ensure security, safety, alignment with human values, and content integrity.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| 2.1 | Model & Infrastructure Security 130 laws, 4 not yet in force | 130 | 103 | 4 | 0 | 0 | |
| 2.2 | Model Alignment no law we track | no law we track | |||||
| 2.3 | Model Safety Engineering 5 laws, 5 not yet in force | 5 | 5 | 5 | 0 | 0 | |
| 2.4 | Content Safety Controls 36 laws, 8 not yet in force, 1 blocked, 3 proposed | 36 | 28 | 8 | 1 | 3 | |
Operational Process Controls
5 of 6 controls with lawProcesses and management frameworks governing AI system deployment, usage, monitoring, incident handling, and validation, which promote safety, security, and accountability throughout the system lifecycle.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| 3.1 | Testing & Auditing 8 laws, 3 not yet in force, 3 proposed | 8 | 6 | 3 | 0 | 3 | |
| 3.2 | Data Governance 164 laws, 8 not yet in force | 164 | 115 | 8 | 0 | 0 | |
| 3.3 | Access Management 122 laws, 7 not yet in force, 1 blocked, 2 proposed | 122 | 78 | 7 | 1 | 2 | |
| 3.4 | Staged Deployment no law we track | no law we track | |||||
| 3.5 | Post-deployment Monitoring 35 laws, 18 not yet in force | 35 | 24 | 18 | 0 | 0 | |
| 3.6 | Incident Response & Recovery 2 laws, 1 not yet in force | 2 | 2 | 1 | 0 | 0 | |
Transparency & Accountability Controls
6 of 6 controls with lawFormal disclosure practices and verification mechanisms that communicate AI system information and enable external scrutiny to build trust, facilitate oversight, and ensure accountability to users, regulators, and the public.
| Control | What it says | Laws, by state | Laws | Places | Not yet in force | Blocked | Proposed |
|---|---|---|---|---|---|---|---|
| 4.1 | System Documentation 91 laws, 24 not yet in force, 9 proposed | 91 | 60 | 24 | 0 | 9 | |
| 4.2 | Risk Disclosure 61 laws, 12 not yet in force, 9 proposed | 61 | 40 | 12 | 0 | 9 | |
| 4.3 | Incident Reporting 18 laws, 6 not yet in force | 18 | 12 | 6 | 0 | 0 | |
| 4.4 | Governance Disclosure 2 laws, 1 not yet in force | 2 | 2 | 1 | 0 | 0 | |
| 4.5 | Third-Party System Access 17 laws, 6 not yet in force | 17 | 12 | 6 | 0 | 0 | |
| 4.6 | User Rights & Recourse 66 laws, 13 not yet in force, 1 blocked, 9 proposed | 66 | 42 | 13 | 1 | 9 |
Where the law and the framework part
5 of the 23 controls have no law we track under them.
The framework's text
Full text of the MIT AI Risk Mitigation Taxonomy, CC BY 4.0. MIT AI Risk Initiative (MIT FutureTech), AI Risk Mitigation Taxonomy, https://airisk.mit.edu/ai-risk-mitigations. Data from the MIT AI Risk Initiative is licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Cite as: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy, https://airisk.mit.edu/blog/mapping-ai-risk-mitigations
Read it from the publisher: airisk.mit.edu