Law / Frameworks / NIST AI RMF / Govern
NIST AI RMF, GovernGOVERN 4.3
Organizational practices are in place to enable AI testing, identification of incidents, and information sharing.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), GOVERN 4.3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 3
- laws
- 3
- places
- 0
- with court rulings behind them
- 2
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-09 Information Security
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations4.3 Incident Reporting
- MIT mitigations3.6 Incident Response & Recovery
- NIST Privacy FrameworkCM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event.
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
A law in force is unmarked; the rest wear their state: not yet in force
AI governance
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Transparency in Frontier Artificial Intelligence Act (SB 53) |
Do not retaliate against a covered employee who discloses, in good faith and with reasonable cause, that your activities pose a catastrophic-risk danger to public health or safety or that you violated this Act; if you are a large frontier developer, also provide an internal channel for anonymous disclosure of that kind |
|
| Frontier Developer Catastrophic-Risk Whistleblower Protections from , in 2 days |
If you are a large frontier developer with annual gross revenue over five hundred million dollars, establish by an internal process letting a covered employee anonymously report such a concern. |
|
| Artificial Intelligence Safety Measures Act from , in 3 months |
If you are a large frontier developer, provide a reasonable internal process through which a covered employee can disclose that kind of information to you anonymously, and give that employee a monthly update on your investigation and on what you did in response. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.