Law / Frameworks / MIT mitigations / Governance & Oversight Controls
MIT mitigations 1.2Risk Management
Systematic methods that identify, evaluate, and manage AI risks for comprehensive risk governance across organizations.MIT AI Risk Mitigation Taxonomy, preliminary taxonomy, July 2025, 1.2
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: DPIA, governance.
- 41
- laws
- 27
- places
- 0
- with court rulings behind them
- 20
- not yet in force
- 3
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 1.4 The risk management process and its outcomes are established through transparent...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkID.IM-P8 Data processing is mapped, illustrating the data actions and associated data elements...
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI governance
16 laws, 12 placesShow the other 6 laws
| Act LXXV of 2025 on the Domestic Implementation of the EU AI Regulation |
Through its governance duty. What it requires |
|
| Artificial Intelligence Safety Measures Act from , in 3 months |
Through its governance duty. What it requires |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
Through its DPIA duty. What it requires |
|
| Federal Law No. 243-FZ, Article 8, Duties of Sovereign and National Foundation Model Developers from , in 5 months |
Through its governance duty. What it requires |
|
| Digital Transformation Act 2025, ICT service permit for AI and AI-related data services |
Through its governance duty. What it requires |
|
| Guidelines on Artificial Intelligence of Vatican City State (Decree No. DCCII) |
Through its governance duty. What it requires |
AI risk obligations
15 laws, 8 placesShow the other 5 laws
| Digital Code, Chapter 23: AI system design and risk-management obligations |
Through its DPIA, governance duties. What it requires |
|
| Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025) |
Through its governance duty. What it requires |
|
| Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty |
Through its governance duty. What it requires |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Through its governance duty. What it requires |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
Through its governance duty. What it requires |
AI sector rules
7 laws, 7 placesAI prohibited practices
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement |
Through its governance duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its governance duty. What it requires |
AI transparency
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Practice Direction No. 1 of 2025, Use of Generative Artificial Intelligence in Court Proceedings |
Through its governance duty. What it requires |
Full text of the MIT AI Risk Mitigation Taxonomy, CC BY 4.0. MIT AI Risk Initiative (MIT FutureTech), AI Risk Mitigation Taxonomy, https://airisk.mit.edu/ai-risk-mitigations. Data from the MIT AI Risk Initiative is licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Cite as: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy, https://airisk.mit.edu/blog/mapping-ai-risk-mitigations Every control of the framework.