Law / Frameworks / NIST AI RMF / Measure

NIST AI RMF, MeasureMEASURE 2.5

The AI system to be deployed is demonstrated to be valid and reliable. Limitations of the generalizability beyond the conditions under which the technology was developed are documented.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.5

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

2
laws
2
places
0
with court rulings behind them
2
not yet in force

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force

  • Alabama
  • European Union

AI risk obligations

1 law, 1 place
PlaceLawWhat it asks, as read here
European Union AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months

If you are the provider of a high-risk AI system, design and develop it to achieve an appropriate level of accuracy, robustness and cybersecurity, held consistently throughout its lifecycle.

AI sector rules

1 law, 1 place
PlaceLawWhat it asks, as read here
Alabama SB 63 (2026), Artificial Intelligence in Health Insurance Prior Authorization from , in 2 days

Make prominent written disclosure of your use of artificial intelligence in utilization review in your policies and procedures, review its outcomes periodically for accuracy, and keep patient data used in that review within its stated purpose under HIPAA.

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.