Law / Frameworks / NIST AI RMF / Govern
NIST AI RMF, GovernGOVERN 1.6
Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), GOVERN 1.6
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 1
- law
- 1
- place
- 0
- with court rulings behind them
- 0
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- NIST AI 600-1GAI-RISK-10 Intellectual Property
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
AI sector rules
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Qatar Central Bank Artificial Intelligence Guideline |
A QCB-regulated entity deploying a High-Risk AI system must maintain an AI system register, adopt an AI governance policy, conduct risk and bias assessments, and provide human oversight of the system's decisions. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.