Law / Frameworks / NIST AI RMF / Manage

NIST AI RMF, ManageMANAGE 4.1

Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MANAGE 4.1

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

17
laws
14
places
1
with court rulings behind it
3
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Algeria
  • California
  • Chile
  • China
  • Connecticut
  • Ethiopia
  • European Union
  • Florida
  • Illinois
  • Monaco
  • Texas
  • Utah
  • Vermont
  • Vietnam

AI prohibited practices

6 laws, 6 places
PlaceLawWhat it asks, as read here
Connecticut Civil Action and Platform Takedown Duty for Synthetically Created Intimate Images from , in 2 days

On receiving a valid removal request, remove the image and make reasonable efforts to remove copies within forty-eight hours.

Florida Promotion of an Altered Sexual Depiction; Brooke's Law platform takedown duty

Remove a validly requested altered sexual depiction, and make reasonable efforts to remove known identical copies, within 48 hours of receiving the request.

Monaco Code Pénal Arts. 294-3 to 294-4, Child Sexual Abuse Material Including Realistic and AI-Generated Depictions

As a telecommunications or electronic communications network operator or service provider, act to bar public access to such an image once you become aware of it through your professional activity, and make it available to the judicial authority.

Texas S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications

If you own a website, application, or social media platform on which such material is disclosed, you are liable for damages if the depicted person requests removal and you fail to remove it, and known identical copies, within 72 hours.

Utah Digital Voyeurism Prevention Act (HB 276, 2026 General Session), Utah Code Title 13 Chapter 72b from , in 3 months

Give users a clear way to report a non-consensual counterfeit intimate image and remove a reported image within 48 hours of notice, if you operate a covered platform

Vermont Disclosure of sexually explicit images without consent, digitized and computer-generated images

An operator of a website, online service, or application may not accept a fee or other consideration to remove, delete, or refrain from posting such an image when the depicted person requests it.

AI risk obligations

4 laws, 4 places
PlaceLawWhat it asks, as read here
California CCPA Automated Decisionmaking Technology Regulations

Let a consumer opt out of your use of ADMT to make a significant decision about them, unless you offer an appeal to a human reviewer with authority to overturn the decision or another exception listed in the regulation applies

Chile Boletín 16.821-19, obligaciones para sistemas de IA de alto riesgo proposed

If passed as introduced, an operator of a high-risk AI system would need a risk-management system, data governance conforming to recognized standards, technical documentation, usage logs, transparency and human-oversight mechanisms, accuracy and cybersecurity standards, contingency measures to disable or recall the system, and post-market monitoring.

European Union AI Act, Article 14 (human oversight) from , in 14 months

Provide the system so the assigned overseers can decide, in a particular situation, not to use it, or can disregard, override or reverse its output.

Vietnam Law on Artificial Intelligence, incident management and reporting obligation

Continuously keep your AI system safe, secure, and reliable, and promptly detect and remedy any incident capable of harming people, property, data, or social order, regardless of the system's risk tier.

AI governance

3 laws, 2 places
PlaceLawWhat it asks, as read here
China Interim Measures for the Management of Generative AI Services, Article 14

If you discover a user has used the service to engage in illegal activity, warn the user, restrict their access to features, or suspend or terminate their access, in accordance with law and your service agreement.

China Provisions on the Administration of Deep Synthesis Internet Information Services, Article 10

Separately take measures against the responsible user, such as warning, restricting features, suspending the service, or closing the account, in accordance with law and your service agreement.

Texas H.B. 3133 (2025), social media platform complaint system for explicit deep fake material

On receiving a report of explicit deep fake material, immediately confirm to the user that you are aware of it, remove the reported content and any identical known copies, and provide the user a written status update within seven days.

If you determine reported content is explicit deep fake material, take measures to keep the same material from being posted again.

Computer misuse

2 laws, 2 places
PlaceLawWhat it asks, as read here
Algeria Loi n° 09-04 relative à la prévention et à la lutte contre les infractions liées aux technologies de l'information et de la communication

As an internet access provider, remove or block access to illicit content as soon as you become aware of it, directly or indirectly (not only on judicial order), and assist the competent judicial authorities in an investigation.

Ethiopia Computer Crime Proclamation

As a service provider, remove or disable access to illegal content data disseminated by a third party through your systems once you obtain actual knowledge of it or a notice from a competent authority.

AI transparency

1 law, 1 place
PlaceLawWhat it asks, as read here
Illinois Artificial Intelligence Video Interview Act

Delete an applicant's interview video, and instruct anyone else who received a copy to do the same, within 30 days of the applicant's request.

Personal data

1 law, 1 place
PlaceLawWhat it asks, as read here
China Personal Information Protection Law, Arts. 13(6) and 27 (processing already-public personal information)

Stop processing an individual's already-public personal information once they expressly decline, even though no prior consent was required.

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.