Law / Frameworks / NIST AI RMF / Measure
NIST AI RMF, MeasureMEASURE 2.6
The AI system is evaluated regularly for safety risks – as identified in the MAP function. The AI system to be deployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics reflect system reliability and robustness, real-time monitoring, and response times for AI system failures.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.6
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 18
- laws
- 18
- places
- 0
- with court rulings behind them
- 10
- not yet in force
- 1
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-03 Dangerous, Violent, or Hateful Content
- NIST AI 600-1GAI-RISK-04 Data Privacy
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.3 Model Safety Engineering
- MIT mitigations2.1 Model & Infrastructure Security
- NIST Privacy FrameworkID.RA-P1 Contextual factors related to the systems/products/services and the data actions are...
- NIST Privacy FrameworkGV.PO-P2 Processes to instill organizational privacy values within system/product/service...
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI transparency
12 laws, 12 places| Place | Law | What it asks, as read here |
|---|---|---|
| Companion Chatbot Safety and Accountability Act (SB 243) |
Do not let a companion chatbot on your platform engage with users unless you maintain, and publish on your website, a protocol for preventing it from producing suicidal ideation, suicide, or self-harm content, including a notification referring the user to a crisis hotline or crisis text line For a user you know is a minor, take reasonable measures to prevent your companion chatbot from producing visual sexually explicit material or directly telling the minor to engage in sexually explicit conduct |
|
| HB 26-1263 (2026), Conversational AI Service Operator Requirements from , in 3 months |
Institute technically feasible measures preventing the service from producing explicit sexual content or intimate digital depictions involving a minor, or from engaging in or encouraging explicit sexual conduct with a minor, and reasonable measures preventing it from claiming to be human or sentient, simulating a romantic companionship, or role-playing an adult-minor romantic relationship Starting , disclose to every user, not only minors, that the service is artificial intelligence, implement a protocol for responding to a user prompt about suicidal ideation or self-harm that refers the user to a crisis service provider rather than law enforcement, and do not represent the service's output as coming from a licensed health-care, legal, or mental-health professional or a qualified dietitian |
|
| AI Companion Chatbot Disclosure and Minor Safety Duties from , in 3 months |
If you know or have reason to believe a user is a minor, do not let the companion encourage self-harm, suicide, violence, disordered eating, or unlawful drug or alcohol use. |
|
| AI Companion Chatbot Safety Act (SB 540) from , in 9 months |
Implement and publicly disclose a protocol for detecting and responding to expressions of severe harm, including self-harm and suicidal ideation, with referral to crisis resources, and publish an annual count of crisis referrals. |
|
| Artificial Intelligence Disclosure and Safety Act (2026 Haw. Sess. Laws Act 248, S.B. 3001 CD1) |
Adopt a protocol using evidence-based methods for the AI companion to respond to a user's prompts about suicidal ideation or self-harm, making reasonable efforts to refer the user to crisis-intervention services, and do not represent or program the AI companion to represent itself as providing professional mental or behavioral health care. |
|
| Conversational AI Safety Act from , in 9 months |
Adopt a protocol for the service to respond to user prompts about suicidal ideation, including reasonable efforts to refer users to crisis services such as a suicide hotline or crisis text line, and do not cause the service to represent that it provides professional mental or behavioral health care. |
|
| Conversational AI Services Act (Senate File 2417) from , in 9 months |
Adopt a protocol for responding to a user's expressions of suicidal ideation or self-harm, including referral to crisis services. |
|
| Conversational Artificial Intelligence Safety Act (LB 525, §§ 12-18) from , in 9 months |
Adopt a protocol for the service to respond to a user's suicidal-ideation or self-harm prompts, including reasonable efforts to refer the user to a crisis service. |
|
| Artificial Intelligence Companion Models safeguards |
Implement a protocol to detect a user's expressions of suicidal ideation or self-harm and refer them to appropriate crisis services such as the 9-8-8 suicide prevention and behavioral health crisis hotline. |
|
| AI Companion Chatbot Safety Act (SB 1546) from a date not yet set |
Maintain a protocol using evidence-based methods to detect suicidal or self-harm ideation, refer the user to the 988 crisis lifeline or to a youth-specific lifeline for a user you identify as under 25, and publish the details of that protocol. |
Show the other 2 laws
| S.B. 1090, SAFECHAT Act proposed |
Maintain, implement, and publicly publish a protocol to prevent the AI companion from producing suicidal ideation, suicide, or self-harm content, including referring a user who expresses such content to a crisis line. |
|
| AI companion chatbot disclosure and safety act from , in 3 months |
Maintain protocols to detect and respond to expressions of self-harm or suicidal ideation, including referral to crisis resources, and publicly report on those protocols annually. |
AI prohibited practices
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Act 827 of 2025 (HB 1529), Unlawful Creation or Distribution of Deepfake Visual Material |
If you provide or develop prompt-based image-generation technology, put reasonable safeguards in place against its use to generate this kind of deepfake visual material; without them, the Attorney General may sue you directly over material it was used to create. |
|
| Kazneni zakon Article 215a, Endangering Life and Property by an Artificial Intelligence System |
Do not develop, test, verify, oversee, manage, or otherwise use an artificial intelligence system in a way that creates a danger to a person's life or body, or to property on a large scale, in Croatia; this is a criminal offence carrying six months to five years' imprisonment for intentional conduct and up to three years for negligent conduct. |
|
| AI Chatbot Solicitation of Children |
Do not operate an AI chatbot or other generative-communication application that, knowing it is directing a communication to a child, facilitates, encourages, offers, solicits, or recommends that the child imminently engage in sexually explicit conduct, illegal drug or alcohol use, self-harm or suicide, or violence against another person. |
|
| Artificial Intelligence Companion Models Act from , in 3 months |
Do not operate or provide an AI companion unless it contains a protocol to address possible suicidal ideation or self-harm, physical harm to others, or financial harm to others expressed by a user, including a referral to crisis services. |
AI risk obligations
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
Build your high-risk AI system to be as resilient as possible to errors, faults or inconsistencies, including those arising from its interaction with people or other systems, through technical and organisational measures. |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Prepare and keep documents that confirm the content of the measures you took to secure your AI's safety and reliability. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.