Law / Frameworks / NIST AI RMF / Manage
NIST AI RMF, ManageMANAGE 1.3
Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented. Risk response options can include mitigating, transferring, avoiding, or accepting.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MANAGE 1.3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 8
- laws
- 5
- places
- 0
- with court rulings behind them
- 1
- not yet in force
- 3
- proposed, not law
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI governance
6 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Andorra proposed |
If ratified and implemented, it would require carrying out risk and impact assessments of an AI system's actual and potential impact on human rights, democracy, and the rule of law, and establishing prevention and mitigation measures. |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Armenia proposed |
If ratified and implemented, it would require carrying out risk and impact assessments of an AI system's actual and potential impact on human rights, democracy, and the rule of law, and establishing prevention and mitigation measures. |
|
| AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk) |
Assess and mitigate the systemic risks your model may pose at Union level, including where those risks originate, whether in the model's development, its placing on the market, or its use. |
|
| Digital Services Act, Article 37 (independent audit of very large online platforms and search engines) |
Where the audit report's opinion is not positive, adopt an audit implementation report within one month describing the measures you took, or explaining why you did not and what you did instead. |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
If ratified and implemented, it would require carrying out risk and impact assessments of an AI system's actual and potential impact on human rights, democracy, and the rule of law, and establishing prevention and mitigation measures. |
|
| AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems) |
If your AI system was trained using cumulative compute of 10^26 floating-point operations or more, applies the most advanced AI technology currently in use, and could broadly and seriously affect people's life, physical safety or fundamental rights, identify, assess and mitigate risk across the system's full life cycle. |
AI risk obligations
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 9 (risk management system) from , in 14 months |
Fold in other risks surfaced by your post-market monitoring data, and adopt targeted risk management measures for the risks you identified. Bring residual risk, per hazard and overall, down to an acceptable level: eliminate or reduce risk through design and development where technically feasible, then mitigate or control what cannot be eliminated, then provide required information and, where appropriate, deployer training, taking the deployer's likely expertise and context of use into account. |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Establish and operate a plan to protect the users of your high-impact AI. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.