Law / Frameworks / NIST AI RMF / Measure
NIST AI RMF, MeasureMEASURE 2.4
The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.4
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 9
- laws
- 5
- places
- 0
- with court rulings behind them
- 5
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-07 Human-AI Configuration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI09 Human-Agent Trust Exploitation
- MIT mitigations1.1 Board Structure & Oversight
- MIT mitigations1.2 Risk Management
- NIST Privacy FrameworkID.IM-P4 Data actions of the systems/products/services are inventoried.
- NIST Privacy FrameworkGV.PO-P1 Organizational privacy values and policies (e.g., conditions on data processing such...
- NIST CSF 2.0GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including...
- NIST CSF 2.0GV.RR-01 Organizational leadership is responsible and accountable for cybersecurity risk and...
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI risk obligations
5 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring) from , in 14 months |
If you are the deployer of a high-risk AI system, monitor its operation on the basis of the provider's instructions for use, and inform the provider where relevant. |
|
| AI Act, Article 26(10) (post-remote biometric identification authorisation) from , in 14 months |
Document every use in the relevant police file, and make it available to the market surveillance authority and the national data protection authority on request, excluding sensitive operational data. |
|
| Artificial Intelligence Bill, 2026, high-risk system obligations proposed |
Keep records of data inputs, training datasets, outputs and performance metrics for at least five years. |
|
| Digital Code, Chapter 23: AI system design and risk-management obligations |
An owner of such a heightened-risk system must meet the Cabinet of Ministers' risk-management, transparency, accuracy, reliability, data-quality and technical-documentation requirements, keep operating logs, and declare conformity in a signed digital document published on the owner's site before the system is deployed. |
|
| HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review |
Make the tool available for audit or compliance review by the Insurance Commissioner, and review its performance, use, and outcomes at least quarterly. |
AI governance
4 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Provisions on the Administration of Deep Synthesis Internet Information Services, Article 10 |
Strengthen your management of deep synthesis content: review your users' input data and synthesis output by technical or manual means, and record and retain the related network logs, if you provide a deep synthesis service. Build and maintain a feature database for identifying illegal and undesirable information, with entry standards, rules, and procedures. |
|
| AI Act, Article 12 (record-keeping) from , in 14 months |
Build automatic event logging into a high-risk AI system so it can record events over the system's lifetime, if you are its provider. Design the logging capability to support identifying an emerging risk or a substantial modification, post-market monitoring, and a deployer's monitoring of the system's operation. +1 more |
|
| AI Act, Article 19 (automatically generated logs) from , in 14 months |
Keep the logs your high-risk AI system automatically generates under Article 12, to the extent they are under your control, if you are its provider. |
|
| AI Act, Article 26(6) (deployer log-keeping) from , in 14 months |
Keep the logs your high-risk AI system automatically generates, to the extent they are under your control, if you are its deployer. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.