Law / Frameworks / NIST AI RMF / Map

NIST AI RMF, MapMAP 3.5

Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MAP 3.5

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

22
laws
21
places
0
with court rulings behind them
8
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Alabama
  • Arizona
  • Belize
  • European Union
  • Georgia
  • Indiana
  • Jamaica
  • Kenya
  • Kyrgyzstan
  • Maine
  • Maryland
  • Minnesota
  • Nebraska
  • Nevada
  • Qatar
  • Rhode Island
  • South Korea
  • Texas
  • Utah
  • Uzbekistan
  • Vietnam

AI risk obligations

9 laws, 8 places
PlaceLawWhat it asks, as read here
European Union AI Act, Article 14 (human oversight) from , in 14 months

If you are the provider of a high-risk AI system, design and develop it, including its human-machine interface, so that a natural person can effectively oversee it while it is in use.

Build oversight measures proportionate to the system's risks, autonomy and context of use, either into the system itself before it is placed on the market or put into service, or as measures you identify for the deployer to implement.

+1 more
European Union AI Act, Article 26(10) (post-remote biometric identification authorisation) from , in 14 months

Do not take, or let a law enforcement authority take, any decision producing an adverse legal effect on a person based solely on the system's output.

Indiana Downcoding of Health Benefits Claims, automated and AI decision-making (House Enrolled Act 1271, 2026)

Do not use an automated process, system, or tool, including artificial intelligence, as the sole basis to downcode a health benefits claim based on medical necessity, unless an employee or contractor has first reviewed the covered individual's medical record

Kenya Artificial Intelligence Bill, 2026, high-risk system obligations proposed

Conduct a risk assessment and a human-rights impact assessment before deploying a high-risk system, and maintain human oversight of it.

Kyrgyzstan Digital Code, Chapter 23: AI system design and risk-management obligations

A user of such a heightened-risk system must operate it per its instructions, keep the data it processes relevant, maintain effective human oversight and resourcing, immediately suspend use and notify the owner once it has grounds to believe use as instructed could cause harm to a protected interest, keep operating logs, and comply with a regulator's suspension order or a final court order to stop using the system.

Maryland HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review

Keep a health care provider in the determination process; the tool may not replace that role.

Nebraska Ensuring Transparency in Prior Authorization Act, artificial-intelligence utilization review restriction

Do not let an artificial intelligence-based algorithm be the sole basis of a decision to deny, delay, or modify a health care service based, in whole or in part, on medical necessity.

South Korea AI Framework Act, Article 34 (business-operator duties for high-impact AI)

Provide human management and supervision of your high-impact AI.

Uzbekistan Law on Informatization, use of artificial intelligence in information resources and systems

Where the app's output feeds a legally significant decision affecting a person's rights or freedoms, the decision may not rest exclusively on the AI-based resource's or system's conclusions.

AI sector rules

9 laws, 9 places
PlaceLawWhat it asks, as read here
Alabama SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days

Have a licensed physician or other health care professional competent to evaluate the artificial intelligence's recommendation make the final determination to deny, delay, or modify a prior-authorization request based on medical necessity.

Arizona Denial of claims; individualized review requirement

If you are a health care insurer, do not deny a claim submitted by a provider on the basis of medical necessity without a medical director individually reviewing the denial and exercising independent medical judgment.

The reviewing medical director may not rely solely on recommendations from any other source, including an automated or AI-assisted recommendation, in making that individualized review.

Georgia Private Review Agent Artificial Intelligence Coverage Determinations Act (SB 444) from , in 3 months

Do not let such a system issue an adverse coverage determination on its own; have a natural person qualifying as a private review agent or utilization review entity conduct the utilization review, with a clinical peer participating, before any adverse determination issues.

Do not let the system supersede the clinical peer's judgment.

Maine Use of artificial intelligence in therapy or psychotherapy services from a date not yet set

If you are a Maine-licensed therapy professional using AI for supplementary support such as session notes, give the client written disclosure and get consent first, and never let AI make an independent therapeutic decision, interact directly with the client in therapeutic communication, or generate a treatment recommendation without your review and approval.

Minnesota Utilization Review, AI-Only Adverse Determination Prohibition from , in 3 months

If you are a utilization review organization, do not use automated processing alone, without a clinician review by an appropriate health professional, to make an adverse determination on a health care service, admission, or extension of stay.

Nevada AB 406 (2025), licensed provider restriction on direct clinical use of AI

Independently review the accuracy of any report, data or other information an AI system compiles, summarizes, analyzes or generates for those administrative purposes.

Qatar Qatar Central Bank Artificial Intelligence Guideline

A QCB-regulated entity deploying a High-Risk AI system must maintain an AI system register, adopt an AI governance policy, conduct risk and bias assessments, and provide human oversight of the system's decisions.

Texas S.B. 1188 (2025), AI diagnostic disclosure duty in electronic health records

If you are a health care practitioner using AI for diagnostic purposes, including AI-generated recommendations on a diagnosis or course of treatment, stay within the scope of your license, do not use AI in a way state or federal law otherwise restricts, and review all AI-created records consistent with Texas Medical Board standards.

Utah Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session) from , in 3 months

Base an adverse preauthorization determination on clinical or medical necessity on independent medical judgment, not solely on a recommendation from any other source

AI transparency

3 laws, 3 places
PlaceLawWhat it asks, as read here
Belize Practice Direction No. 18 of 2025, ethical use of generative AI in court proceedings

Disclose when AI-generated content is used in a court submission, and independently verify any AI-generated legal research before relying on it.

Jamaica Practice Direction No. 1 of 2025, Use of Generative Artificial Intelligence in Court Proceedings

Declare, in the prescribed form, whenever any part of a document submitted to a Jamaican court was prepared with the assistance of generative AI, and have that content thoroughly reviewed, verified, and approved before submission.

Do not rely on generative AI output without independently confirming the validity of any case law, statutory provision, or authority it cites.

Rhode Island Use of Artificial Intelligence by Healthcare Providers Notification Act from a date not yet set

Review AI-generated visit documentation for accuracy after the visit.

AI prohibited practices

1 law, 1 place
PlaceLawWhat it asks, as read here
Vietnam Law on Artificial Intelligence, prohibited practices

Do not obstruct, disable, or distort the human-oversight mechanisms this Law requires over your AI system.

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.