Law / Frameworks / NIST AI RMF / Measure

NIST AI RMF, MeasureMEASURE 2.4

The functionality and behavior of the AI system and its components – as identified in the MAP function – are monitored when in production.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.4

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

9
laws
5
places
0
with court rulings behind them
5
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • China
  • European Union
  • Kenya
  • Kyrgyzstan
  • Maryland

AI risk obligations

5 laws, 4 places
PlaceLawWhat it asks, as read here
European Union AI Act, Article 26(1) to (5) (deployer use, human oversight, input data and monitoring) from , in 14 months

If you are the deployer of a high-risk AI system, monitor its operation on the basis of the provider's instructions for use, and inform the provider where relevant.

European Union AI Act, Article 26(10) (post-remote biometric identification authorisation) from , in 14 months

Document every use in the relevant police file, and make it available to the market surveillance authority and the national data protection authority on request, excluding sensitive operational data.

Kenya Artificial Intelligence Bill, 2026, high-risk system obligations proposed

Keep records of data inputs, training datasets, outputs and performance metrics for at least five years.

Kyrgyzstan Digital Code, Chapter 23: AI system design and risk-management obligations

An owner of such a heightened-risk system must meet the Cabinet of Ministers' risk-management, transparency, accuracy, reliability, data-quality and technical-documentation requirements, keep operating logs, and declare conformity in a signed digital document published on the owner's site before the system is deployed.

Maryland HB 820 / Ch. 747 (2025), Artificial Intelligence in Health Insurance Utilization Review

Make the tool available for audit or compliance review by the Insurance Commissioner, and review its performance, use, and outcomes at least quarterly.

AI governance

4 laws, 2 places
PlaceLawWhat it asks, as read here
China Provisions on the Administration of Deep Synthesis Internet Information Services, Article 10

Strengthen your management of deep synthesis content: review your users' input data and synthesis output by technical or manual means, and record and retain the related network logs, if you provide a deep synthesis service.

Build and maintain a feature database for identifying illegal and undesirable information, with entry standards, rules, and procedures.

European Union AI Act, Article 12 (record-keeping) from , in 14 months

Build automatic event logging into a high-risk AI system so it can record events over the system's lifetime, if you are its provider.

Design the logging capability to support identifying an emerging risk or a substantial modification, post-market monitoring, and a deployer's monitoring of the system's operation.

+1 more
European Union AI Act, Article 19 (automatically generated logs) from , in 14 months

Keep the logs your high-risk AI system automatically generates under Article 12, to the extent they are under your control, if you are its provider.

European Union AI Act, Article 26(6) (deployer log-keeping) from , in 14 months

Keep the logs your high-risk AI system automatically generates, to the extent they are under your control, if you are its deployer.

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.