Law / Frameworks / NIST AI RMF / Map
NIST AI RMF, MapMAP 1.1
Intended purposes, potentially beneficial uses, context-specific laws, norms and expectations, and prospective settings in which the AI system will be deployed are understood and documented. Considerations include: the specific set or types of users along with their expectations; potential positive and negative impacts of system uses to individuals, communities, organizations, society, and the planet; assumptions and related limitations about AI system purposes, uses, and risks across the development or product AI lifecycle; and related TEVV and system metrics.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MAP 1.1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 2
- laws
- 2
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations1.2 Risk Management
- MIT mitigations1.7 Societal Impact Assessment
- NIST Privacy FrameworkID.IM-P8 Data processing is mapped, illustrating the data actions and associated data elements...
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
- NIST CSF 2.0ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified...
- NIST CSF 2.0ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent...
A law in force is unmarked; the rest wear their state: not yet in force
AI risk obligations
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 27 (fundamental rights impact assessment) from , in 14 months |
Cover in that assessment: your intended process for using the system, the period and frequency of use, the categories of people likely affected, the specific risks of harm to them, your human oversight measures, and the steps you would take if those risks materialise, including complaint and internal-governance arrangements. |
Personal data
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Personal Information Protection Act, Art. 15(1)(vi), as applied by the PIPC's publicly-available-data AI guideline |
Specify a legitimate, defined purpose for the AI model before relying on this ground to process publicly available personal data. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.