Law / Frameworks / NIST AI RMF / Map
NIST AI RMF, MapMAP 5.1
Likelihood and magnitude of each identified impact (both potentially beneficial and harmful) based on expected use, past uses of AI systems in similar contexts, public incident reports, feedback from those external to the team that developed or deployed the AI system, or other data are identified and documented.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MAP 5.1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 11
- laws
- 9
- places
- 0
- with court rulings behind them
- 2
- not yet in force
- 5
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-03 Dangerous, Violent, or Hateful Content
- NIST AI 600-1GAI-RISK-04 Data Privacy
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.2 Risk Management
- MIT mitigations1.7 Societal Impact Assessment
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
- NIST Privacy FrameworkID.IM-P8 Data processing is mapped, illustrating the data actions and associated data elements...
- NIST CSF 2.0ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified...
- NIST CSF 2.0ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI governance
6 laws, 6 places| Place | Law | What it asks, as read here |
|---|---|---|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Andorra proposed |
If ratified and implemented, it would require carrying out risk and impact assessments of an AI system's actual and potential impact on human rights, democracy, and the rule of law, and establishing prevention and mitigation measures. |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Armenia proposed |
If ratified and implemented, it would require carrying out risk and impact assessments of an AI system's actual and potential impact on human rights, democracy, and the rule of law, and establishing prevention and mitigation measures. |
|
| AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk) |
Assess and mitigate the systemic risks your model may pose at Union level, including where those risks originate, whether in the model's development, its placing on the market, or its use. |
|
| Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act |
Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines. |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
If ratified and implemented, it would require carrying out risk and impact assessments of an AI system's actual and potential impact on human rights, democracy, and the rule of law, and establishing prevention and mitigation measures. |
|
| AI Framework Act, Article 32 (safety-assurance duty for high-compute AI systems) |
If your AI system was trained using cumulative compute of 10^26 floating-point operations or more, applies the most advanced AI technology currently in use, and could broadly and seriously affect people's life, physical safety or fundamental rights, identify, assess and mitigate risk across the system's full life cycle. |
AI risk obligations
5 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 27 (fundamental rights impact assessment) from , in 14 months |
If you are a body governed by public law, a private entity providing a public service, or a deployer of a credit-scoring or life-and-health-insurance-risk-pricing high-risk AI system (Annex III points 5(b) or (c)), assess the impact on fundamental rights of a high-risk AI system before its first use, unless the system is the Annex III point 2 critical-infrastructure use case. Update the assessment if any of those elements changes during use, rather than treating it as a one-time exercise. |
|
| AI Act, Article 9 (risk management system) from , in 14 months |
Identify and analyze the known and reasonably foreseeable risks the system can pose to health, safety, or fundamental rights under its intended use, and estimate and evaluate risks that may emerge under intended use and reasonably foreseeable misuse. Consider whether the system is likely to adversely affect persons under 18 or other vulnerable groups, given its intended purpose, when implementing your risk management system. |
|
| Council of Europe Framework Convention on AI, Georgia's signature proposed |
Carry out iterative risk and impact assessments of an AI system's actual and potential impacts on human rights, democracy, and the rule of law, with sufficient prevention and mitigation measures. |
|
| Artificial Intelligence Bill, 2026, high-risk system obligations proposed |
Conduct a risk assessment and a human-rights impact assessment before deploying a high-risk system, and maintain human oversight of it. |
|
| Digital Code, Chapter 23: AI system design and risk-management obligations |
An app whose AI system a hazard assessment finds poses increased danger to life, health, rights, the environment, defense, national security or public order must have its owner reassess that hazard at each design, development, deployment and material-change stage, and publish the assessment and its methodology on the owner's own website as open data. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.