Law / Frameworks / MIT mitigations / Technical & Security Controls
MIT mitigations 2.3Model Safety Engineering
Technical methods and safeguards that constrain model behaviors and protect against exploitation and vulnerabilities.MIT AI Risk Mitigation Taxonomy, preliminary taxonomy, July 2025, 2.3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: design code, security.
- 5
- laws
- 5
- places
- 0
- with court rulings behind them
- 5
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.6 The AI system is evaluated regularly for safety risks – as identified in the MAP...
- NIST AI RMFMAP 1.6 System requirements (e.g., “the system shall respect the privacy of its users”) are...
- NIST AI 600-1GAI-RISK-03 Dangerous, Violent, or Hateful Content
- NIST AI 600-1GAI-RISK-04 Data Privacy
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
- NIST Privacy FrameworkGV.PO-P2 Processes to instill organizational privacy values within system/product/service...
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
A law in force is unmarked; the rest wear their state: not yet in force
AI transparency
4 laws, 4 places| Place | Law | How it reaches this control |
|---|---|---|
| HB 26-1263 (2026), Conversational AI Service Operator Requirements from , in 3 months |
Through its design code duty. What it requires |
|
| Conversational AI Safety Act from , in 9 months |
Through its design code duty. What it requires |
|
| Conversational AI Services Act (Senate File 2417) from , in 9 months |
Through its design code duty. What it requires |
|
| AI Companion Chatbot Safety Act (SB 1546) from a date not yet set |
Through its design code duty. What it requires |
AI risk obligations
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
Through its security duty. What it requires |
Full text of the MIT AI Risk Mitigation Taxonomy, CC BY 4.0. MIT AI Risk Initiative (MIT FutureTech), AI Risk Mitigation Taxonomy, https://airisk.mit.edu/ai-risk-mitigations. Data from the MIT AI Risk Initiative is licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Cite as: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy, https://airisk.mit.edu/blog/mapping-ai-risk-mitigations Every control of the framework.