Law / Frameworks / NIST AI RMF / Measure

NIST AI RMF, MeasureMEASURE 2.6

The AI system is evaluated regularly for safety risks – as identified in the MAP function. The AI system to be deployed is demonstrated to be safe, its residual negative risk does not exceed the risk tolerance, and it can fail safely, particularly if made to operate beyond its knowledge limits. Safety metrics reflect system reliability and robustness, real-time monitoring, and response times for AI system failures.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.6

We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .

18
laws
18
places
0
with court rulings behind them
10
not yet in force
1
proposed, not law

The same ground elsewhere linked through the kinds of duty both controls are mapped from

A law in force is unmarked; the rest wear their state: not yet in force proposed

  • Arkansas
  • California
  • Colorado
  • Connecticut
  • Croatia
  • European Union
  • Georgia
  • Hawaii
  • Idaho
  • Iowa
  • Nebraska
  • New Hampshire
  • New York
  • Oregon
  • Pennsylvania
  • Rhode Island
  • South Korea
  • Washington

AI transparency

12 laws, 12 places
PlaceLawWhat it asks, as read here
California Companion Chatbot Safety and Accountability Act (SB 243)

Do not let a companion chatbot on your platform engage with users unless you maintain, and publish on your website, a protocol for preventing it from producing suicidal ideation, suicide, or self-harm content, including a notification referring the user to a crisis hotline or crisis text line

For a user you know is a minor, take reasonable measures to prevent your companion chatbot from producing visual sexually explicit material or directly telling the minor to engage in sexually explicit conduct

Colorado HB 26-1263 (2026), Conversational AI Service Operator Requirements from , in 3 months

Institute technically feasible measures preventing the service from producing explicit sexual content or intimate digital depictions involving a minor, or from engaging in or encouraging explicit sexual conduct with a minor, and reasonable measures preventing it from claiming to be human or sentient, simulating a romantic companionship, or role-playing an adult-minor romantic relationship

Starting , disclose to every user, not only minors, that the service is artificial intelligence, implement a protocol for responding to a user prompt about suicidal ideation or self-harm that refers the user to a crisis service provider rather than law enforcement, and do not represent the service's output as coming from a licensed health-care, legal, or mental-health professional or a qualified dietitian

Connecticut AI Companion Chatbot Disclosure and Minor Safety Duties from , in 3 months

If you know or have reason to believe a user is a minor, do not let the companion encourage self-harm, suicide, violence, disordered eating, or unlawful drug or alcohol use.

Georgia AI Companion Chatbot Safety Act (SB 540) from , in 9 months

Implement and publicly disclose a protocol for detecting and responding to expressions of severe harm, including self-harm and suicidal ideation, with referral to crisis resources, and publish an annual count of crisis referrals.

Hawaii Artificial Intelligence Disclosure and Safety Act (2026 Haw. Sess. Laws Act 248, S.B. 3001 CD1)

Adopt a protocol using evidence-based methods for the AI companion to respond to a user's prompts about suicidal ideation or self-harm, making reasonable efforts to refer the user to crisis-intervention services, and do not represent or program the AI companion to represent itself as providing professional mental or behavioral health care.

Idaho Conversational AI Safety Act from , in 9 months

Adopt a protocol for the service to respond to user prompts about suicidal ideation, including reasonable efforts to refer users to crisis services such as a suicide hotline or crisis text line, and do not cause the service to represent that it provides professional mental or behavioral health care.

Iowa Conversational AI Services Act (Senate File 2417) from , in 9 months

Adopt a protocol for responding to a user's expressions of suicidal ideation or self-harm, including referral to crisis services.

Nebraska Conversational Artificial Intelligence Safety Act (LB 525, §§ 12-18) from , in 9 months

Adopt a protocol for the service to respond to a user's suicidal-ideation or self-harm prompts, including reasonable efforts to refer the user to a crisis service.

New York Artificial Intelligence Companion Models safeguards

Implement a protocol to detect a user's expressions of suicidal ideation or self-harm and refer them to appropriate crisis services such as the 9-8-8 suicide prevention and behavioral health crisis hotline.

Oregon AI Companion Chatbot Safety Act (SB 1546) from a date not yet set

Maintain a protocol using evidence-based methods to detect suicidal or self-harm ideation, refer the user to the 988 crisis lifeline or to a youth-specific lifeline for a user you identify as under 25, and publish the details of that protocol.

Show the other 2 laws
Pennsylvania S.B. 1090, SAFECHAT Act proposed

Maintain, implement, and publicly publish a protocol to prevent the AI companion from producing suicidal ideation, suicide, or self-harm content, including referring a user who expresses such content to a crisis line.

Washington AI companion chatbot disclosure and safety act from , in 3 months

Maintain protocols to detect and respond to expressions of self-harm or suicidal ideation, including referral to crisis resources, and publicly report on those protocols annually.

AI prohibited practices

4 laws, 4 places
PlaceLawWhat it asks, as read here
Arkansas Act 827 of 2025 (HB 1529), Unlawful Creation or Distribution of Deepfake Visual Material

If you provide or develop prompt-based image-generation technology, put reasonable safeguards in place against its use to generate this kind of deepfake visual material; without them, the Attorney General may sue you directly over material it was used to create.

Croatia Kazneni zakon Article 215a, Endangering Life and Property by an Artificial Intelligence System

Do not develop, test, verify, oversee, manage, or otherwise use an artificial intelligence system in a way that creates a danger to a person's life or body, or to property on a large scale, in Croatia; this is a criminal offence carrying six months to five years' imprisonment for intentional conduct and up to three years for negligent conduct.

New Hampshire AI Chatbot Solicitation of Children

Do not operate an AI chatbot or other generative-communication application that, knowing it is directing a communication to a child, facilitates, encourages, offers, solicits, or recommends that the child imminently engage in sexually explicit conduct, illegal drug or alcohol use, self-harm or suicide, or violence against another person.

Rhode Island Artificial Intelligence Companion Models Act from , in 3 months

Do not operate or provide an AI companion unless it contains a protocol to address possible suicidal ideation or self-harm, physical harm to others, or financial harm to others expressed by a user, including a referral to crisis services.

AI risk obligations

2 laws, 2 places
PlaceLawWhat it asks, as read here
European Union AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months

Build your high-risk AI system to be as resilient as possible to errors, faults or inconsistencies, including those arising from its interaction with people or other systems, through technical and organisational measures.

South Korea AI Framework Act, Article 34 (business-operator duties for high-impact AI)

Prepare and keep documents that confirm the content of the measures you took to secure your AI's safety and reliability.

Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.