Law / Frameworks / NIST AI 600-1
NIST AI 600-1 GAI-RISK-07Human-AI Configuration
Arrangements of or interactions between a human and an AI system which can result in the human inappropriately anthropomorphizing GAI systems or experiencing algorithmic aversion, automation bias, over-reliance, or emotional entanglement with GAI systems.NIST Generative AI Profile, July 2024 (NIST AI 600-1), GAI-RISK-07
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
The kinds of duty that reach it: biometric, content labelling, design code, disclosure, governance.
- 93
- laws
- 53
- places
- 2
- with court rulings behind them
- 28
- not yet in force
- 1
- blocked by a court
- 9
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI RMFGOVERN 4.2 Organizational teams document the risks and potential impacts of the AI technology...
- NIST AI RMFMAP 3.5 Processes for human oversight are defined, assessed, and documented in accordance with...
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.6 User Rights & Recourse
- MIT mitigations2.4 Content Safety Controls
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkID.IM-P6 Data elements within the data actions are inventoried.
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force blocked by a court proposed
AI transparency
45 laws, 34 placesShow the other 35 laws
AI risk obligations
20 laws, 12 placesShow the other 10 laws
AI governance
14 laws, 11 placesShow the other 4 laws
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
Through its disclosure duty. What it requires |
|
| Federal Law No. 243-FZ, Article 8, Duties of Sovereign and National Foundation Model Developers from , in 5 months |
Through its governance duty. What it requires |
|
| Digital Transformation Act 2025, ICT service permit for AI and AI-related data services |
Through its governance duty. What it requires |
|
| Guidelines on Artificial Intelligence of Vatican City State (Decree No. DCCII) |
Through its content labelling, governance duties. What it requires |
AI sector rules
11 laws, 11 placesShow the other 1 law
| Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session) from , in 3 months |
Through its disclosure, governance duties. What it requires |
AI prohibited practices
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement |
Through its governance duty. What it requires |
AI training data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Through its governance duty. What it requires |
Personal data
1 law, 1 place| Place | Law | How it reaches this control |
|---|---|---|
| Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier |
Through its biometric duty. What it requires |
Full text of the NIST Generative AI Profile, public domain (a US government work). Every control of the framework.