Law / Frameworks / NIST AI RMF / Manage
NIST AI RMF, ManageMANAGE 4.1
Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MANAGE 4.1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 17
- laws
- 14
- places
- 1
- with court rulings behind it
- 3
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- MIT mitigations4.3 Incident Reporting
- MIT mitigations3.2 Data Governance
- NIST Privacy FrameworkCM.AW-P7 Impacted individuals and organizations are notified about a privacy breach or event.
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST CSF 2.0ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are...
- NIST CSF 2.0RS.CO-02 Internal and external stakeholders are notified of incidents
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI prohibited practices
6 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| Civil Action and Platform Takedown Duty for Synthetically Created Intimate Images from , in 2 days |
On receiving a valid removal request, remove the image and make reasonable efforts to remove copies within forty-eight hours. |
|
| Promotion of an Altered Sexual Depiction; Brooke's Law platform takedown duty |
Remove a validly requested altered sexual depiction, and make reasonable efforts to remove known identical copies, within 48 hours of receiving the request. |
|
| Code Pénal Arts. 294-3 to 294-4, Child Sexual Abuse Material Including Realistic and AI-Generated Depictions |
As a telecommunications or electronic communications network operator or service provider, act to bar public access to such an image once you become aware of it through your professional activity, and make it available to the judicial authority. |
|
| S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications |
If you own a website, application, or social media platform on which such material is disclosed, you are liable for damages if the depicted person requests removal and you fail to remove it, and known identical copies, within 72 hours. |
|
| Digital Voyeurism Prevention Act (HB 276, 2026 General Session), Utah Code Title 13 Chapter 72b from , in 3 months |
Give users a clear way to report a non-consensual counterfeit intimate image and remove a reported image within 48 hours of notice, if you operate a covered platform |
|
| Disclosure of sexually explicit images without consent, digitized and computer-generated images |
An operator of a website, online service, or application may not accept a fee or other consideration to remove, delete, or refrain from posting such an image when the depicted person requests it. |
AI risk obligations
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| CCPA Automated Decisionmaking Technology Regulations |
Let a consumer opt out of your use of ADMT to make a significant decision about them, unless you offer an appeal to a human reviewer with authority to overturn the decision or another exception listed in the regulation applies |
|
| Boletín 16.821-19, obligaciones para sistemas de IA de alto riesgo proposed |
If passed as introduced, an operator of a high-risk AI system would need a risk-management system, data governance conforming to recognized standards, technical documentation, usage logs, transparency and human-oversight mechanisms, accuracy and cybersecurity standards, contingency measures to disable or recall the system, and post-market monitoring. |
|
| AI Act, Article 14 (human oversight) from , in 14 months |
Provide the system so the assigned overseers can decide, in a particular situation, not to use it, or can disregard, override or reverse its output. |
|
| Law on Artificial Intelligence, incident management and reporting obligation |
Continuously keep your AI system safe, secure, and reliable, and promptly detect and remedy any incident capable of harming people, property, data, or social order, regardless of the system's risk tier. |
AI governance
3 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Interim Measures for the Management of Generative AI Services, Article 14 |
If you discover a user has used the service to engage in illegal activity, warn the user, restrict their access to features, or suspend or terminate their access, in accordance with law and your service agreement. |
|
| Provisions on the Administration of Deep Synthesis Internet Information Services, Article 10 |
Separately take measures against the responsible user, such as warning, restricting features, suspending the service, or closing the account, in accordance with law and your service agreement. |
|
| H.B. 3133 (2025), social media platform complaint system for explicit deep fake material |
On receiving a report of explicit deep fake material, immediately confirm to the user that you are aware of it, remove the reported content and any identical known copies, and provide the user a written status update within seven days. If you determine reported content is explicit deep fake material, take measures to keep the same material from being posted again. |
Computer misuse
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Loi n° 09-04 relative à la prévention et à la lutte contre les infractions liées aux technologies de l'information et de la communication |
As an internet access provider, remove or block access to illicit content as soon as you become aware of it, directly or indirectly (not only on judicial order), and assist the competent judicial authorities in an investigation. |
|
| Computer Crime Proclamation |
As a service provider, remove or disable access to illegal content data disseminated by a third party through your systems once you obtain actual knowledge of it or a notice from a competent authority. |
AI transparency
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Artificial Intelligence Video Interview Act |
Delete an applicant's interview video, and instruct anyone else who received a copy to do the same, within 30 days of the applicant's request. |
Personal data
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Information Protection Law, Arts. 13(6) and 27 (processing already-public personal information) |
Stop processing an individual's already-public personal information once they expressly decline, even though no prior consent was required. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.