Law / Frameworks / NIST AI RMF / Govern

NIST AI RMF, GovernGOVERN 1.4

The risk management process and its outcomes are established through transparent policies, procedures, and other controls based on organizational risk priorities.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), GOVERN 1.4

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

10
laws
10
places
0
with court rulings behind them
3
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • California
  • Chile
  • Colorado
  • European Union
  • Illinois
  • Kyrgyzstan
  • Montana
  • New York
  • Russia
  • South Korea

AI risk obligations

5 laws, 5 places
PlaceLawWhat it asks, as read here
Chile Boletín 16.821-19, obligaciones para sistemas de IA de alto riesgo proposed

If passed as introduced, an operator of a high-risk AI system would need a risk-management system, data governance conforming to recognized standards, technical documentation, usage logs, transparency and human-oversight mechanisms, accuracy and cybersecurity standards, contingency measures to disable or recall the system, and post-market monitoring.

European Union AI Act, Article 9 (risk management system) from , in 14 months

If you are the provider of a high-risk AI system, establish, implement, document, and maintain a risk management system for it, run as a continuous process across its whole lifecycle with regular review and updates.

Kyrgyzstan Digital Code, Chapter 23: AI system design and risk-management obligations

An owner of such a heightened-risk system must meet the Cabinet of Ministers' risk-management, transparency, accuracy, reliability, data-quality and technical-documentation requirements, keep operating logs, and declare conformity in a signed digital document published on the owner's site before the system is deployed.

Montana Right to Compute Act (SB 212, 2025), critical AI infrastructure risk management duty

If a deployer of a critical artificial intelligence system controls, in whole or in part, a critical infrastructure facility, develop a risk management policy after deploying the system

The policy must be reasonable and consider a nationally or internationally recognized AI risk management framework, such as the NIST AI risk management framework

South Korea AI Framework Act, Article 34 (business-operator duties for high-impact AI)

If you provide high-impact AI, or a product or service that uses it, establish and operate a risk-management plan for it.

AI governance

4 laws, 4 places
PlaceLawWhat it asks, as read here
California Transparency in Frontier Artificial Intelligence Act (SB 53)

If you are a large frontier developer (a frontier developer whose group had annual gross revenues over $500,000,000 in the prior calendar year), write, implement and publish on your website a frontier AI framework describing how you define and assess catastrophic-risk thresholds for your frontier models and apply mitigations, and review that framework at least once a year

Illinois Artificial Intelligence Safety Measures Act from , in 3 months

If you are a large frontier developer, from write, implement, comply with and publish on your website a frontier AI framework covering catastrophic-risk assessment, mitigations, cybersecurity, internal governance, third-party evaluations, and risks from your own internal use of your frontier models.

New York Responsible AI Safety and Education Act (RAISE Act)

If you are a large developer of a frontier AI model, write a safety and security protocol addressing severe risks and conspicuously publish it, with appropriate redactions, transmitting an unredacted copy to the Attorney General on request.

Russia Federal Law No. 243-FZ, Article 8, Duties of Sovereign and National Foundation Model Developers from , in 5 months

Once Article 8 of Federal Law No. 243-FZ takes effect on : if you develop a sovereign or national large foundation AI model, take organizational and technical measures to secure it, define operating rules covering restrictions, conditions of use, updates, and decommissioning, and maintain technical documentation of its key parameters and limitations sufficient to assess the safety of its application.

AI sector rules

1 law, 1 place
PlaceLawWhat it asks, as read here
Colorado Amended Regulation 10-1-1 (2025), Governance and Risk Management Framework for Insurers' Use of External Consumer Data and Information Sources, Algorithms, and Predictive Models

Establish a documented, risk-based governance and risk management framework, including a cross-functional governance group drawing on legal, compliance, risk management, product development, underwriting, actuarial, data science, marketing, and customer service, designed to determine through quantitative testing whether your use of an external consumer data and information source, or an algorithm or predictive model that uses one, results in unfair discrimination with respect to race, and to remediate any discrimination detected.

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.