Law / Frameworks / MIT mitigations / Operational Process Controls
MIT mitigations 3.1Testing & Auditing
Systematic internal and external evaluations that assess AI systems, infrastructure, and compliance processes to identify risks, verify safety, and ensure performance meets standards.MIT AI Risk Mitigation Taxonomy, preliminary taxonomy, July 2025, 3.1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: DPIA, security.
- 8
- laws
- 6
- places
- 0
- with court rulings behind them
- 3
- not yet in force
- 3
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMAP 1.1 Intended purposes, potentially beneficial uses, context-specific laws, norms and...
- NIST AI RMFMAP 5.1 Likelihood and magnitude of each identified impact (both potentially beneficial and...
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- NIST Privacy FrameworkID.IM-P8 Data processing is mapped, illustrating the data actions and associated data elements...
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI governance
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Andorra proposed |
Through its DPIA duty. What it requires |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Armenia proposed |
Through its DPIA duty. What it requires |
|
| Ley de Fomento a la Inteligencia Artificial y Tecnologías, marco institucional, registro y evaluación de riesgos |
Through its DPIA duty. What it requires |
|
| AI Act, Article 26(9) (using Article 13 information for a data protection impact assessment) from , in 14 months |
Through its DPIA duty. What it requires |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
Through its DPIA duty. What it requires |
AI risk obligations
3 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
Through its security duty. What it requires |
|
| AI Act, Article 27 (fundamental rights impact assessment) from , in 14 months |
Through its DPIA duty. What it requires |
|
| Digital Code, Chapter 23: AI system design and risk-management obligations |
Through its DPIA duty. What it requires |
Full text of the MIT AI Risk Mitigation Taxonomy, CC BY 4.0. MIT AI Risk Initiative (MIT FutureTech), AI Risk Mitigation Taxonomy, https://airisk.mit.edu/ai-risk-mitigations. Data from the MIT AI Risk Initiative is licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Cite as: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy, https://airisk.mit.edu/blog/mapping-ai-risk-mitigations Every control of the framework.