Law / Frameworks / NIST AI 600-1
NIST AI 600-1 GAI-RISK-04Data Privacy
Impacts due to leakage and unauthorized use, disclosure, or de-anonymization of biometric, health, location, or other personally identifiable information or sensitive data.NIST Generative AI Profile, July 2024 (NIST AI 600-1), GAI-RISK-04
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: DPIA, age verification, biometric, breach notice, consent, data subject rights, retention, security, transfer.
- 18
- laws
- 12
- places
- 1
- with court rulings behind it
- 7
- not yet in force
- 3
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFMEASURE 2.10 Privacy risk of the AI system – as identified in the MAP function – is examined and documented.
- NIST AI RMFMANAGE 4.1 Post-deployment AI system monitoring plans are implemented, including mechanisms for...
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations3.2 Data Governance
- MIT mitigations3.1 Testing & Auditing
- NIST Privacy FrameworkCT.PO-P1 Policies, processes, and procedures for authorizing data processing (e.g.,...
- NIST Privacy FrameworkCT.PO-P2 Policies, processes, and procedures for enabling data review, transfer, sharing or...
- NIST CSF 2.0ID.AM-07 Inventories of data and corresponding metadata for designated data types are maintained
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI risk obligations
8 laws, 4 placesAI governance
5 laws, 5 places| Place | Law | How it reaches this control |
|---|---|---|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Andorra proposed |
Through its DPIA duty. What it requires |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Armenia proposed |
Through its DPIA duty. What it requires |
|
| Ley de Fomento a la Inteligencia Artificial y Tecnologías, marco institucional, registro y evaluación de riesgos |
Through its DPIA duty. What it requires |
|
| AI Act, Article 26(9) (using Article 13 information for a data protection impact assessment) from , in 14 months |
Through its DPIA duty. What it requires |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
Through its DPIA duty. What it requires |
AI sector rules
2 laws, 2 places| Place | Law | How it reaches this control |
|---|---|---|
| Wellness and Oversight for Psychological Resources Act |
Through its consent duty. What it requires |
|
| Use of artificial intelligence in therapy or psychotherapy services from a date not yet set |
Through its consent duty. What it requires |
AI prohibited practices
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Digital Voyeurism Prevention Act (HB 276, 2026 General Session), Utah Code Title 13 Chapter 72b from , in 3 months |
Through its consent duty. What it requires |
AI transparency
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Artificial Intelligence Video Interview Act |
Through its consent duty. What it requires |
Personal data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier |
Through its biometric, consent duties. What it requires |
Full text of the NIST Generative AI Profile, public domain (a US government work). Every control of the framework.