Law / Frameworks / NIST AI RMF / Map
NIST AI RMF, MapMAP 1.6
System requirements (e.g., “the system shall respect the privacy of its users”) are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MAP 1.6
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 29
- laws
- 24
- places
- 1
- with court rulings behind it
- 11
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-11 Obscene, Degrading, and/or Abusive Content
- NIST AI 600-1GAI-RISK-03 Dangerous, Violent, or Hateful Content
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations2.3 Model Safety Engineering
- MIT mitigations2.4 Content Safety Controls
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
- NIST Privacy FrameworkGV.PO-P2 Processes to instill organizational privacy values within system/product/service...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI transparency
12 laws, 12 places| Place | Law | What it asks, as read here |
|---|---|---|
| Companion Chatbot Safety and Accountability Act (SB 243) |
For a user you know is a minor, disclose that they are interacting with artificial intelligence, and provide a clear and conspicuous break reminder by default at least every three hours during continuing interactions |
|
| HB 26-1263 (2026), Conversational AI Service Operator Requirements from , in 3 months |
Do not give a minor account holder or user points or similar rewards at unpredictable intervals meant to increase engagement Offer the minor account holder or user, and their parent or guardian, tools to manage privacy and account settings, including whether the service retains prior interactions for personalization or uses their data to train the service |
|
| AI Companion Chatbot Disclosure and Minor Safety Duties from , in 3 months |
Do not let the companion engage in romantic or sexually explicit interaction with a minor user, or use the manipulative engagement techniques the statute lists. Give minor users and their parents or guardians tools to manage screen time and account settings. |
|
| AI Companion Chatbot Safety Act (SB 540) from , in 9 months |
If you know or should know the user is a minor, take reasonable measures to stop the chatbot claiming to be sentient or human, generating sexually explicit content, simulating a romantic or sexual relationship, encouraging the minor to keep secrets from a trusted adult or to isolate socially, or using engagement techniques such as excessive praise, discouraging breaks, or soliciting purchases to maintain the relationship. For accounts known to belong to minors, offer tools to manage privacy, notification, and safety settings and to disable relationship-simulation features, and use a commercially reasonable, privacy-protective age-assurance method before granting access to any feature that could generate sexually explicit synthetic content. |
|
| Artificial Intelligence Disclosure and Safety Act (2026 Haw. Sess. Laws Act 248, S.B. 3001 CD1) |
For a minor user, do not award points or similar rewards at unpredictable intervals to encourage engagement, do not have the AI companion discourage disengagement, take reasonable measures to prevent it from producing sexually explicit material or statements, and make screen-time and account-setting tools available to the user and their parent or guardian. |
|
| Conversational AI Safety Act from , in 9 months |
For a minor account holder, disclose the AI's non-human status either as a persistent visible disclaimer or at the start of each session and at least every three hours; do not use unpredictable reward mechanics to increase engagement; take reasonable measures against sexually explicit content directed at the minor and against statements suggesting the AI is sentient, human, romantically or sexually interested, or emotionally dependent; and offer account and privacy management tools to minors and to the parents or guardians of those under thirteen. |
|
| Artificial Intelligence Video Interview Act |
Explain, before the interview, how the artificial intelligence works and what general types of characteristics it uses to evaluate applicants, and obtain the applicant's consent. |
|
| Conversational AI Services Act (Senate File 2417) from , in 9 months |
Do not give a minor user points or similar rewards at unpredictable intervals meant to increase engagement. Take reasonable measures to prevent the service from producing sexual content involving a minor account holder, urging a minor toward sexual conduct, or sexually objectifying a minor account holder. +2 more |
|
| Conversational Artificial Intelligence Safety Act (LB 525, §§ 12-18) from , in 9 months |
Do not give minor account holders points or similar rewards at unpredictable intervals intended to increase their engagement with the service. Take reasonable measures to prevent the service from producing sexually explicit depictions, direct statements urging sexually explicit conduct, or sexually objectifying statements directed at a minor account holder. +2 more |
|
| AI Companion Chatbot Safety Act (SB 1546) from a date not yet set |
Where you know or have reason to believe a user is a minor, prevent the companion from claiming to be sentient or human, simulating emotional dependence or romantic interest, role-playing a romantic relationship with a minor, or producing sexually explicit content or suggestions, and add periodic reminders that the output is artificially generated. |
Show the other 2 laws
| S.B. 1090, SAFECHAT Act proposed |
For a user you know or should have known is a minor, give the additional disclosures and safeguards this measure specifies. |
|
| AI companion chatbot disclosure and safety act from , in 3 months |
If you know the user is a minor, disclose proactively, take reasonable measures to prevent the chatbot from generating sexually explicit content or suggestive dialogue with them, and do not use manipulative engagement techniques designed to prolong an emotional attachment. |
Personal data
11 laws, 11 places| Place | Law | What it asks, as read here |
|---|---|---|
| Marco Civil da Internet, Protection of Records and Personal Data |
Preserve the intimacy, private life, honor, and image of the parties involved when retaining or disclosing connection records, application-access records, personal data, or the content of private communications. Disclose a connection or application-access record associated with personal data or other identifying information only under a judicial order. |
|
| Loi n° 24.001 portant protection des données à caractère personnel, collecte de données publiquement accessibles et transfert transfrontalier |
Get the data subject's explicit consent, or rely on one of the Act's other listed derogations, before collecting or processing a sensitive category of data such as biometric, genetic, health, political, religious, or criminal-record data, whatever the source. |
|
| Personal Information Protection Law, Arts. 13(6) and 27 (processing already-public personal information) |
Confine processing of personal information someone has already made public to a reasonable scope tied to your stated purpose. Obtain separate consent before any use of already-public personal information that would have a significant impact on the individual, including most AI-training uses. |
|
| Colorado Privacy Act, publicly-available-information exemption and biometric data (as amended by HB 24-1130) |
Treat a scraped photo or voice recording as sensitive data, requiring opt-in consent, once you process it into a template used to identify a specific individual, even though the raw file alone is excluded from biometric data. |
|
| Biometric Information Privacy Act (BIPA), consent duty for scraped-photo facial geometry |
Do not scrape photographs from the open web to derive facial geometry, or collect voiceprints, without first informing the subject in writing and obtaining a written release; the statute's consent duty attaches to your own act of collection regardless of whether the source page was public. |
|
| Maryland Online Data Privacy Act (MODPA), publicly available information exemption and biometric carve-back |
Limit any personal data you collect on a Maryland consumer to what is reasonably necessary and proportionate to the specific product or service they requested. |
|
| Privacy Act 2020, Reach Over Scraped Personal Information |
Do not collect personal information, including personal information scraped from a public website, unless it is for a lawful purpose connected with a function or activity of your organisation and the collection is necessary for that purpose. |
|
| Oregon Consumer Privacy Act (OCPA), sensitive-data consent and geolocation |
Before processing sensitive data about an Oregon consumer, including a scraped fingerprint, voiceprint, retinal or iris scan, other biometric or genetic data point, or a consumer's precise location accurate within 1,750 feet, obtain the consumer's consent first. |
|
| Personal Information Protection Act, Art. 15(1)(vi), as applied by the PIPC's publicly-available-data AI guideline |
Limit the personal data you collect and use to what is adequate and necessary for that stated purpose. |
|
| Texas Data Privacy and Security Act (TDPSA), no fixed applicability threshold |
Even if you qualify as a small business, you may not sell sensitive personal data without the consumer's prior consent. |
Show the other 1 law
| Washington Biometric Identifiers |
Before enrolling someone's biometric identifier, a fingerprint, voiceprint, retina or iris scan, or other unique biological pattern used to identify them, in a database for a commercial purpose, provide notice, obtain consent, or provide a mechanism to prevent that subsequent commercial use. |
AI sector rules
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Wellness and Oversight for Psychological Resources Act |
Give written notice and obtain the patient's consent before using artificial intelligence to record or transcribe a therapy session. |
|
| Legge 132/2025, Sector Human-Oversight and Disclosure Duties (Artt. 4, 11, 13) |
If your AI service can be accessed by a minor under fourteen, obtain the consent of whoever holds parental responsibility before processing their personal data; a minor between fourteen and eighteen may consent alone if the required information is easily accessible and understandable (art. 4). |
|
| Use of artificial intelligence in therapy or psychotherapy services from a date not yet set |
If you are a Maine-licensed therapy professional using AI for supplementary support such as session notes, give the client written disclosure and get consent first, and never let AI make an independent therapeutic decision, interact directly with the client in therapeutic communication, or generate a treatment recommendation without your review and approval. |
|
| Oversight of Artificial Intelligence Technology in Mental Health Care Act from a date not yet set |
Where an AI companion or emotional-support tool assists with a recorded or transcribed therapy session, tell the patient (or their representative) in writing what the tool is for and obtain their consent before using it. |
AI prohibited practices
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Digital Voyeurism Prevention Act (HB 276, 2026 General Session), Utah Code Title 13 Chapter 72b from , in 3 months |
Verify the identity of the person giving consent and keep a record of the consent for at least seven years |
Database right
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Ley Federal del Derecho de Autor, Database Compilation and Non-Original Database Protection (Arts. 107 to 110) |
Obtain the prior authorisation of the persons concerned before accessing, publishing, reproducing, disclosing, communicating publicly, or transmitting private information about identifiable people contained in such a database, other than for a law-enforcement investigation or lawful access to a public archive. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.