Law / Frameworks / NIST AI RMF / Measure
NIST AI RMF, MeasureMEASURE 2.7
AI system security and resilience – as identified in the MAP function – are evaluated and documented.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.7
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 3
- laws
- 2
- places
- 0
- with court rulings behind them
- 2
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- NIST AI 600-1GAI-RISK-09 Information Security
- OWASP LLM Top 10LLM01:2026 Prompt Injection
- OWASP LLM Top 10LLM02:2026 Sensitive Information Disclosure
- OWASP Agentic Top 10ASI01 Agent Goal Hijack
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations2.1 Model & Infrastructure Security
- MIT mitigations2.3 Model Safety Engineering
- NIST Privacy FrameworkPR.PO-P7 Response plans (Incident Response and Business Continuity) and recovery plans...
- NIST Privacy FrameworkPR.PO-P10 A vulnerability management plan is developed and implemented.
- NIST CSF 2.0ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
- NIST CSF 2.0ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established
A law in force is unmarked; the rest wear their state: not yet in force
AI governance
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 55 (obligations for providers of general-purpose AI models with systemic risk) |
If the Commission has classified your general-purpose AI model as carrying systemic risk, in addition to your Article 53 duties, perform model evaluation using standardised, state-of-the-art protocols and tools, including conducting and documenting adversarial testing to identify and mitigate systemic risks. Ensure an adequate level of cybersecurity protection for your model and its physical infrastructure throughout the model's lifecycle. |
|
| Federal Law No. 243-FZ, Article 8, Duties of Sovereign and National Foundation Model Developers from , in 5 months |
Once Article 8 of Federal Law No. 243-FZ takes effect on : if you develop a sovereign or national large foundation AI model, take organizational and technical measures to secure it, define operating rules covering restrictions, conditions of use, updates, and decommissioning, and maintain technical documentation of its key parameters and limitations sufficient to assess the safety of its application. |
AI risk obligations
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 15 (accuracy, robustness and cybersecurity) from , in 14 months |
If you are the provider of a high-risk AI system, design and develop it to achieve an appropriate level of accuracy, robustness and cybersecurity, held consistently throughout its lifecycle. Make your high-risk AI system resilient against attempts by unauthorised third parties to alter its use, outputs or performance by exploiting vulnerabilities, with technical solutions appropriate to the circumstances and the risk. +1 more |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.