Law / Frameworks / NIST AI RMF / Govern
NIST AI RMF, GovernGOVERN 4.2
Organizational teams document the risks and potential impacts of the AI technology they design, develop, deploy, evaluate, and use, and they communicate about the impacts more broadly.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), GOVERN 4.2
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 13
- laws
- 11
- places
- 1
- with court rulings behind it
- 5
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- NIST AI 600-1GAI-RISK-08 Information Integrity
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations4.2 Risk Disclosure
- MIT mitigations4.6 User Rights & Recourse
- NIST Privacy FrameworkGV.PO-P5 Legal, regulatory, and contractual requirements regarding privacy are understood and managed.
- NIST Privacy FrameworkGV.MT-P4 Policies, processes, and procedures for communicating progress on managing privacy...
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI transparency
6 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Companion Chatbot Safety Act (SB 540) from , in 9 months |
Implement and publicly disclose a protocol for detecting and responding to expressions of severe harm, including self-harm and suicidal ideation, with referral to crisis resources, and publish an annual count of crisis referrals. |
|
| Artificial Intelligence Disclosure and Safety Act (2026 Haw. Sess. Laws Act 248, S.B. 3001 CD1) |
Beginning , submit an annual report to the Department of Health's Behavioral Health Administration on crisis-intervention referrals and protocols, containing no user-identifying information. |
|
| Artificial Intelligence Video Interview Act |
If you rely solely on AI analysis of a video interview to select applicants for an in-person interview, collect and report race and ethnicity data on applicants and hires to the Department of Commerce and Economic Opportunity every year by December 31. |
|
| AI Companion Chatbot Safety Act (SB 1546) from a date not yet set |
Maintain a protocol using evidence-based methods to detect suicidal or self-harm ideation, refer the user to the 988 crisis lifeline or to a youth-specific lifeline for a user you identify as under 25, and publish the details of that protocol. Post an annual public report disclosing how many times you referred a user to crisis resources and the details of your detection protocol, without including information that identifies an individual. |
|
| S.B. 1090, SAFECHAT Act proposed |
Maintain, implement, and publicly publish a protocol to prevent the AI companion from producing suicidal ideation, suicide, or self-harm content, including referring a user who expresses such content to a crisis line. |
|
| AI companion chatbot disclosure and safety act from , in 3 months |
Maintain protocols to detect and respond to expressions of self-harm or suicidal ideation, including referral to crisis resources, and publicly report on those protocols annually. |
AI governance
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Transparency in Frontier Artificial Intelligence Act (SB 53) |
If you are a large frontier developer, add to that transparency report summaries of your catastrophic-risk assessments, their results, and the extent of any third-party evaluator involvement If you are a large frontier developer, transmit summaries of catastrophic-risk assessments from your frontier models' internal use to the California Office of Emergency Services on a quarterly or agreed schedule +1 more |
|
| Digital Services Act, Article 37 (independent audit of very large online platforms and search engines) |
Transmit the audit report and the audit implementation report to your Digital Services Coordinator of establishment and the Commission without undue delay, and make them public, with confidential information removed where necessary, within three months of receiving the audit report. |
|
| Artificial Intelligence Safety Measures Act from , in 3 months |
If you are a large frontier developer, add to that transparency report summaries of your catastrophic-risk assessments for the model, their results, the extent of any third-party evaluator involvement, and the other steps you took to meet your frontier AI framework for it. |
|
| AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems) |
Submit the results of implementing those two measures to the Ministry of Science and ICT, in the form and manner the Ministry sets by public notice. |
AI risk obligations
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Digital Code, Chapter 23: AI system design and risk-management obligations |
An app whose AI system a hazard assessment finds poses increased danger to life, health, rights, the environment, defense, national security or public order must have its owner reassess that hazard at each design, development, deployment and material-change stage, and publish the assessment and its methodology on the owner's own website as open data. |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Post the main content of your risk-management plan, your explanation plan, and your user-protection plan, and the name and contact details of the person managing and supervising your high-impact AI, at your place of business or on your website. |
AI sector rules
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Employer AI-Related Layoff Disclosure to the Labor Department from , in 2 days |
If you serve a mass-layoff notice on the Connecticut Labor Department under the federal WARN Act, also disclose to the department whether the layoffs are related to your use of artificial intelligence or another technological change. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.