Law / Frameworks / NIST AI RMF / Map
NIST AI RMF, MapMAP 3.5
Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MAP 3.5
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 22
- laws
- 21
- places
- 0
- with court rulings behind them
- 8
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- NIST AI 600-1GAI-RISK-04 Data Privacy
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkID.IM-P6 Data elements within the data actions are inventoried.
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI risk obligations
9 laws, 8 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 14 (human oversight) from , in 14 months |
If you are the provider of a high-risk AI system, design and develop it, including its human-machine interface, so that a natural person can effectively oversee it while it is in use. Build oversight measures proportionate to the system's risks, autonomy and context of use, either into the system itself before it is placed on the market or put into service, or as measures you identify for the deployer to implement. +1 more |
|
| AI Act, Article 26(10) (post-remote biometric identification authorisation) from , in 14 months |
Do not take, or let a law enforcement authority take, any decision producing an adverse legal effect on a person based solely on the system's output. |
|
| Downcoding of Health Benefits Claims, automated and AI decision-making (House Enrolled Act 1271, 2026) |
Do not use an automated process, system, or tool, including artificial intelligence, as the sole basis to downcode a health benefits claim based on medical necessity, unless an employee or contractor has first reviewed the covered individual's medical record |
|
| Artificial Intelligence Bill, 2026, high-risk system obligations proposed |
Conduct a risk assessment and a human-rights impact assessment before deploying a high-risk system, and maintain human oversight of it. |
|
| Digital Code, Chapter 23: AI system design and risk-management obligations |
A user of such a heightened-risk system must operate it per its instructions, keep the data it processes relevant, maintain effective human oversight and resourcing, immediately suspend use and notify the owner once it has grounds to believe use as instructed could cause harm to a protected interest, keep operating logs, and comply with a regulator's suspension order or a final court order to stop using the system. |
|
| HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review |
Keep a health care provider in the determination process; the tool may not replace that role. |
|
| Ensuring Transparency in Prior Authorization Act, artificial-intelligence utilization review restriction |
Do not let an artificial intelligence-based algorithm be the sole basis of a decision to deny, delay, or modify a health care service based, in whole or in part, on medical necessity. |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Provide human management and supervision of your high-impact AI. |
|
| Law on Informatization, use of artificial intelligence in information resources and systems |
Where the app's output feeds a legally significant decision affecting a person's rights or freedoms, the decision may not rest exclusively on the AI-based resource's or system's conclusions. |
AI sector rules
9 laws, 9 places| Place | Law | What it asks, as read here |
|---|---|---|
| SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days |
Have a licensed physician or other health care professional competent to evaluate the artificial intelligence's recommendation make the final determination to deny, delay, or modify a prior-authorization request based on medical necessity. |
|
| Denial of claims; individualized review requirement |
If you are a health care insurer, do not deny a claim submitted by a provider on the basis of medical necessity without a medical director individually reviewing the denial and exercising independent medical judgment. The reviewing medical director may not rely solely on recommendations from any other source, including an automated or AI-assisted recommendation, in making that individualized review. |
|
| Private Review Agent Artificial Intelligence Coverage Determinations Act (SB 444) from , in 3 months |
Do not let such a system issue an adverse coverage determination on its own; have a natural person qualifying as a private review agent or utilization review entity conduct the utilization review, with a clinical peer participating, before any adverse determination issues. Do not let the system supersede the clinical peer's judgment. |
|
| Use of artificial intelligence in therapy or psychotherapy services from a date not yet set |
If you are a Maine-licensed therapy professional using AI for supplementary support such as session notes, give the client written disclosure and get consent first, and never let AI make an independent therapeutic decision, interact directly with the client in therapeutic communication, or generate a treatment recommendation without your review and approval. |
|
| Utilization Review, AI-Only Adverse Determination Prohibition from , in 3 months |
If you are a utilization review organization, do not use automated processing alone, without a clinician review by an appropriate health professional, to make an adverse determination on a health care service, admission, or extension of stay. |
|
| AB 406 (2025), licensed provider restriction on direct clinical use of AI |
Independently review the accuracy of any report, data or other information an AI system compiles, summarizes, analyzes or generates for those administrative purposes. |
|
| Qatar Central Bank Artificial Intelligence Guideline |
A QCB-regulated entity deploying a High-Risk AI system must maintain an AI system register, adopt an AI governance policy, conduct risk and bias assessments, and provide human oversight of the system's decisions. |
|
| S.B. 1188 (2025), AI diagnostic disclosure duty in electronic health records |
If you are a health care practitioner using AI for diagnostic purposes, including AI-generated recommendations on a diagnosis or course of treatment, stay within the scope of your license, do not use AI in a way state or federal law otherwise restricts, and review all AI-created records consistent with Texas Medical Board standards. |
|
| Health Insurance Preauthorization AI Disclosure (SB 319, 2026 General Session) from , in 3 months |
Base an adverse preauthorization determination on clinical or medical necessity on independent medical judgment, not solely on a recommendation from any other source |
AI transparency
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Practice Direction No. 18 of 2025, ethical use of generative AI in court proceedings |
Disclose when AI-generated content is used in a court submission, and independently verify any AI-generated legal research before relying on it. |
|
| Practice Direction No. 1 of 2025, Use of Generative Artificial Intelligence in Court Proceedings |
Declare, in the prescribed form, whenever any part of a document submitted to a Jamaican court was prepared with the assistance of generative AI, and have that content thoroughly reviewed, verified, and approved before submission. Do not rely on generative AI output without independently confirming the validity of any case law, statutory provision, or authority it cites. |
|
| Use of Artificial Intelligence by Healthcare Providers Notification Act from a date not yet set |
Review AI-generated visit documentation for accuracy after the visit. |
AI prohibited practices
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Law on Artificial Intelligence, prohibited practices |
Do not obstruct, disable, or distort the human-oversight mechanisms this Law requires over your AI system. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.