Law / Frameworks / NIST AI RMF / Map

NIST AI RMF, MapMAP 2.3

Scientific integrity and TEVV considerations are identified and documented, including those related to experimental design, data collection and selection (e.g., availability, representativeness, suitability), system trustworthiness, and construct validation.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MAP 2.3

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

9
laws
6
places
0
with court rulings behind them
3
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Alabama
  • California
  • European Union
  • Maryland
  • New York
  • Vatican City

AI risk obligations

3 laws, 2 places
PlaceLawWhat it asks, as read here
European Union AI Act, Article 10 (data and data governance) from , in 14 months

If you are the provider of a high-risk AI system that uses techniques involving the training of AI models, develop it on training, validation and testing data sets that meet the criteria below, whenever you use such data sets.

Apply data governance and management practices appropriate to the system's intended purpose, covering your design choices; how you collected the data and, for personal data, why you originally collected it; your data-preparation operations, such as annotation, labelling, cleaning, updating, enrichment and aggregation; the assumptions you made about what the data measures and represents; an assessment of whether the data sets you need are available, sufficient in quantity, and suitable; examination of the data for biases likely to affect health and safety, harm fundamental rights, or lead to discrimination prohibited under Union law, especially where one operation's data outputs become a later operation's inputs; and measures to detect, prevent and mitigate any bias you find.

+2 more
European Union AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring) from , in 14 months

If you are the deployer of a high-risk AI system and you exercise control over its input data, ensure that input data is relevant and sufficiently representative in view of the system's intended purpose.

Maryland HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review

Base any determination an AI, algorithm, or other software tool makes in utilization review on the enrollee's own medical or clinical history, individual clinical circumstances, or other relevant clinical information in the enrollee's record, never solely on a group dataset.

AI training data

3 laws, 3 places
PlaceLawWhat it asks, as read here
California Generative AI Training Data Transparency Act (AB 2013)

Post training-data documentation on your website before making a generative AI system publicly available to Californians, and again before any substantial modification

Cover the datasets and their sources and owners, an approximate count and description of the data points, whether the data includes copyrighted or personal information, and whether synthetic data generation was used

European Union AI Act, Article 53 (obligations for providers of general-purpose AI models)

Publish a training-content summary if you provide a general-purpose model

New York Artificial Intelligence Training Data Transparency Act proposed

Publicly post documentation describing the datasets used to train a generative AI model or service made available to New York users, including their sources, whether they contain copyrighted, personal or aggregate consumer information, the collection period, and whether synthetic data generation was used.

AI governance

1 law, 1 place
PlaceLawWhat it asks, as read here
Vatican City Guidelines on Artificial Intelligence of Vatican City State (Decree No. DCCII)

Verify and maintain oversight of the data your AI systems process so that outputs remain correct, reliable, and obtained transparently.

AI sector rules

1 law, 1 place
PlaceLawWhat it asks, as read here
Alabama SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days

If you are a health benefit plan provider using artificial intelligence to make medical-necessity determinations on prior-authorization requests, base each determination on the enrollee's own medical history, the clinical circumstances the treating provider presents, and other clinical information in the enrollee's record, not a group dataset.

Crawl signals

1 law, 1 place
PlaceLawWhat it asks, as read here
California AI Training Data Transparency Act (AB 2013)

If you develop a generative AI system made available to Californians, publicly post documentation of your training datasets before each release or substantial modification, starting .

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.