Law / Frameworks / NIST AI RMF / Govern
NIST AI RMF, GovernGOVERN 6.1
Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), GOVERN 6.1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 4
- laws
- 3
- places
- 0
- with court rulings behind them
- 3
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-10 Intellectual Property
- NIST AI 600-1GAI-RISK-12 Value Chain and Component Integration
- MIT mitigations3.2 Data Governance
- MIT mitigations3.3 Access Management
- NIST Privacy FrameworkID.DE-P2 Data processing ecosystem parties (e.g., service providers, customers, partners,...
- NIST Privacy FrameworkID.DE-P3 Contracts with data processing ecosystem parties are used to implement appropriate...
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are...
A law in force is unmarked; the rest wear their state: not yet in force
AI governance
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 26(8) (public-authority deployer registration) from , in 14 months |
If you find that the high-risk AI system you plan to use has not been registered in the EU database, do not use it, and inform the provider or the distributor. |
AI risk obligations
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 25 (responsibilities along the AI value chain) from , in 14 months |
If you are the initial provider and one of those events happens, closely cooperate with the new provider: make available technical documentation sufficient to assess compliance with Article 16, inform them of known limitations and failure modes, and give them targeted technical access, including for testing and validation, unless you clearly specified that your system was not to be changed into a high-risk one. If you are the provider of a high-risk AI system, or a third party supplying an AI system, AI model, tool, service, component, or process it integrates, specify by written agreement the necessary information, capabilities, technical access, and other assistance needed for the provider to comply with this Regulation, unless the third party makes the tool, service, process or component available to the public under a free and open-source licence; that exception never covers a general-purpose AI model. |
AI sector rules
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Reform to the Federal Labor Law and the Federal Copyright Law, AI Voice and Image Consent Regime for Performing Artists |
Specify in a performing artist's labor contract the conditions and remuneration for any use of their image or voice through AI systems or other technology. |
AI transparency
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| AI content provenance and disclosure act from , in 4 months |
If you license your generative AI system to a third party, require by contract that the licensee preserve this disclosure capability. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.