Law / Frameworks / NIST AI RMF / Govern
NIST AI RMF, GovernGOVERN 1.1
Legal and regulatory requirements involving AI are understood, managed, and documented.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), GOVERN 1.1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 30
- laws
- 22
- places
- 0
- with court rulings behind them
- 8
- not yet in force
- 2
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.2 Risk Disclosure
- MIT mitigations1.1 Board Structure & Oversight
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI risk obligations
10 laws, 7 places| Place | Law | What it asks, as read here |
|---|---|---|
| Resolución ANIA 0001/2025, registro obligatorio para decisiones consecuenciales |
If your AI system is the controlling factor in a decision that materially affects a person's legal status, rights, or access to essential goods, services or opportunities, and it operates in a registrable sector (primary health diagnosis or treatment, creditworthiness or insurance and loan decisions, real-time biometric identification in public spaces, the exercise of government authority or public benefits, unsupervised hiring or compensation decisions, or academic admission or grading), register with ANIA. |
|
| AI Act, Article 111(2) (2030 compliance deadline for public-authority-intended systems) from , in 3.8 years |
If you are a provider or deployer of a high-risk AI system intended to be used by public authorities, and the system was placed on the market or put into service before Chapter III applies to it, take the necessary steps to comply with the Regulation's requirements and obligations by , regardless of whether the system is later significantly redesigned. |
|
| AI Act, Article 26(10) (post-remote biometric identification authorisation) from , in 14 months |
If you are a law enforcement deployer using a high-risk AI system for post-remote biometric identification in a targeted search for a suspected or convicted person, request authorisation from a judicial authority or a binding, judicially reviewable administrative authority, in advance or without undue delay and no later than 48 hours, unless you are using the system only for the initial identification of a potential suspect on objective and verifiable facts directly linked to the offence. Submit annual reports to the relevant market surveillance and data protection authorities on your use of post-remote biometric identification systems. |
|
| AI Act, Article 27 (fundamental rights impact assessment) from , in 14 months |
Once you have performed the assessment, notify the market surveillance authority of its results using the AI Office's template, unless you are exempt as a real-world testing participant under Article 46(1). |
|
| AI Act, Article 6(3) and (4) (narrow-task derogation from Annex III high-risk classification) from , in 14 months |
You are subject to the Article 49(2) EU database registration obligation. Provide the documentation of your assessment to national competent authorities on request. |
|
| Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025) |
Obtain prior authorisation from a Magistrate before deploying a real-time or post-remote biometric identification system in a publicly accessible space in Malta for law enforcement purposes, and notify the Commissioner with the Regulation (EU) 2024/1689 Article 5(6) information excluding sensitive operational data, under Legal Notice 227 of 2025. |
|
| HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review |
Make the tool available for audit or compliance review by the Insurance Commissioner, and review its performance, use, and outcomes at least quarterly. |
|
| Ensuring Transparency in Prior Authorization Act, artificial-intelligence utilization review restriction |
Make your automated utilization management system available for audit by the department, which may perform the audit itself or through a third-party entity. |
|
| Norwegian Artificial Intelligence Act (KI-loven) proposed |
Comply with Regulation (EU) 2024/1689's requirements for high-risk AI systems, including conformity assessment and human oversight, once the Regulation is incorporated into the EEA Agreement and the Norwegian Act is adopted. |
|
| Law on Artificial Intelligence, risk classification and conformity assessment |
For a medium-risk or high-risk AI system, prepare a classification dossier and notify the classification result to the Ministry of Science and Technology through the one-stop AI portal before putting the system into service. For a high-risk AI system, complete a conformity assessment before putting it into service or after a significant change, and maintain that conformity throughout operation. |
AI governance
8 laws, 7 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 21(2) (competent authority access to automatically generated logs) from , in 14 months |
Give a competent authority access to the automatically generated logs of your high-risk AI system, to the extent they are under your control, when it makes a reasoned request, if you are the system's provider. |
|
| AI Act, Article 26(8) (public-authority deployer registration) from , in 14 months |
If you are a public authority, or a Union institution, body, office or agency, deploying a high-risk AI system, comply with the Article 49 registration obligations. |
|
| Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act |
Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines. |
|
| Act LXXV of 2025 on the Domestic Implementation of the EU AI Regulation |
Where you test an AI system under real-world conditions in Hungary, expect to do so through the AI regulatory sandbox the AI market surveillance authority operates under Section 10. |
|
| Regulation of Artificial Intelligence Act 2026 |
Comply with information requests, contravention notices and prohibition notices issued by an authorised officer of a relevant market surveillance authority in respect of an AI system you provide or deploy (Part 5). |
|
| Act on Promotion of Research and Development, and Utilization of Artificial Intelligence-related Technology (AI Promotion Act) |
A utilization business operator must cooperate with the AI-promotion measures the national government carries out under Article 4 and a local government carries out under Article 5. |
|
| Digital Transformation Act 2025, ICT service permit for AI and AI-related data services |
Before carrying on business as a provider of artificial intelligence or AI-related data services in Vanuatu, apply to the Director of the Department of Communications and Digital Transformation for an ICT service permit in that class, and pay the prescribed annual permit fee. Comply with any condition the Director imposes on the permit, and cooperate with an enforcement officer's inspection, information request, or search warrant, since a serious breach can suspend the permit and stop all operations, and providing the service without a valid permit is a criminal offence. |
|
| Proyecto de Ley de Inteligencia Artificial (National Artificial Intelligence Bill) proposed |
If enacted, register as an AI provider with the National Artificial Intelligence Agency the bill would create. |
AI sector rules
4 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days |
Certify annually to the Alabama Department of Insurance that the artificial intelligence does not rely on a group dataset, is applied fairly and equitably consistent with applicable federal guidance, and does not discriminate against any subscriber group or enrollee. |
|
| Amended Regulation 10-1-1 (2025), Governance and Risk Management Framework for Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models |
If you do not use an external consumer data and information source or an ECDIS-based algorithm or predictive model, file a signed officer attestation to that effect with the Division instead. File a compliance report with the Division on SERFF: annually by December 1 if you are a life insurer, and annually by July 1 if you are a private passenger automobile insurer or a health benefit plan insurer. +1 more |
|
| SB 21-169 (2021), Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models |
Cooperate with the Commissioner and the Division of Insurance in any examination or investigation of your use of an external consumer data and information source, algorithm, or predictive model. |
|
| Qatar Central Bank Artificial Intelligence Guideline |
A QCB-regulated financial entity must obtain QCB approval before launching a new AI system as a provider or making a material modification to one, and before signing a High-Risk AI purchase, licensing, or outsourcing agreement. |
AI transparency
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Companion Chatbot Safety and Accountability Act (SB 243) |
Beginning , report annually to the Office of Suicide Prevention on the crisis-referral notifications you issued and the protocols you have in place, without including user identifiers or personal information |
|
| HB 26-1263 (2026), Conversational AI Service Operator Requirements from , in 3 months |
Starting , report annually to the Attorney General on the number of crisis-service-provider referrals issued and the protocols used to detect, prevent, and respond to suicidal ideation or self-harm, without including any user-identifying information |
|
| Ordonnance n°0011/PR/2026, marquage des contenus générés par intelligence artificielle |
Preserve the origin metadata of AI-generated content under judicial or administrative investigation, and hand it to the Haute Autorité de la Communication within eight days of a request. |
AI prohibited practices
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Lov nr. 467 af 14. maj 2025, National Competent Authorities and Article 5 Enforcement |
Provide accurate, complete information to Digitaliseringsstyrelsen, Datatilsynet or Domstolsstyrelsen on request, and allow them to inspect your premises and technical systems, or risk a court-set fine with no statutory ceiling stated in Danish law. |
|
| Law on Artificial Intelligence, prohibited practices |
Do not create or distribute an AI-generated output that Kazakhstani law bans. |
Personal data
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Data Protection Law, reach over scraped public personal data |
A scraper collecting the personal data of an individual in Oman from a public page must confirm the data was made public in a manner not contrary to the Personal Data Protection Law before treating it as outside the Law's scope under Art. 3(j); a biometric identifier such as a faceprint or voiceprint derived from publicly posted photographs, video, or audio requires a Ministry permit under Art. 5 regardless of the recording's public availability. |
|
| Personal Data Protection Act, 2022, application to processing of personal data |
Register with the Personal Data Protection Commission and have a lawful basis before collecting or processing personal data through a crawler or data pipeline, whether or not the data was publicly accessible online. |
AI training data
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Keep technical documentation available for the AI Office |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.