Law / Frameworks / MIT mitigations / Transparency & Accountability Controls
MIT mitigations 4.5Third-Party System Access
Mechanisms granting controlled system access to vetted external parties to enable independent assessment, validation, and safety research of AI models and capabilities.MIT AI Risk Mitigation Taxonomy, preliminary taxonomy, July 2025, 4.5
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: reporting.
- 17
- laws
- 12
- places
- 1
- with court rulings behind it
- 6
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 1.1 Legal and regulatory requirements involving AI are understood, managed, and documented.
- NIST AI RMFGOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology...
- NIST AI 600-1GAI-RISK-09 Information Security
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST Privacy FrameworkGV.MT-P4 Policies, processes, and procedures for communicating progress on managing privacy...
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
A law in force is unmarked; the rest wear their state: not yet in force
AI governance
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Transparency in Frontier Artificial Intelligence Act (SB 53) |
Through its reporting duty. What it requires |
|
| Digital Services Act, Article 37 (independent audit of very large online platforms and search engines) |
Through its reporting duty. What it requires |
|
| Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act |
Through its reporting duty. What it requires |
|
| Artificial Intelligence Safety Measures Act from , in 3 months |
Through its reporting duty. What it requires |
|
| AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems) |
Through its reporting duty. What it requires |
AI transparency
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Companion Chatbot Safety and Accountability Act (SB 243) |
Through its reporting duty. What it requires |
|
| HB 26-1263 (2026), Conversational AI Service Operator Requirements from , in 3 months |
Through its reporting duty. What it requires |
|
| Ordonnance n°0011/PR/2026, marquage des contenus générés par intelligence artificielle |
Through its reporting duty. What it requires |
|
| Artificial Intelligence Video Interview Act |
Through its reporting duty. What it requires |
|
| AI Companion Chatbot Safety Act (SB 1546) from a date not yet set |
Through its reporting duty. What it requires |
AI risk obligations
3 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring) from , in 14 months |
Through its reporting duty. What it requires |
|
| AI Act, Article 26(10) (post-remote biometric identification authorisation) from , in 14 months |
Through its reporting duty. What it requires |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
Through its reporting duty. What it requires |
AI sector rules
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days |
Through its reporting duty. What it requires |
|
| Amended Regulation 10-1-1 (2025), Governance and Risk Management Framework for Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models |
Through its reporting duty. What it requires |
AI prohibited practices
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Code Pénal Arts. 294-3 to 294-4, Child Sexual Abuse Material Including Realistic and AI-Generated Depictions |
Through its reporting duty. What it requires |
Computer misuse
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Loi n° 09-04 relative à la prévention et à la lutte contre les infractions liées aux technologies de l'information et de la communication |
Through its reporting duty. What it requires |
Full text of the MIT AI Risk Mitigation Taxonomy, CC BY 4.0. MIT AI Risk Initiative (MIT FutureTech), AI Risk Mitigation Taxonomy, https://airisk.mit.edu/ai-risk-mitigations. Data from the MIT AI Risk Initiative is licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Cite as: Mapping AI Risk Mitigations: Evidence Scan & Draft Mitigation Taxonomy, https://airisk.mit.edu/blog/mapping-ai-risk-mitigations Every control of the framework.