Law / Frameworks / NIST AI RMF / Measure
NIST AI RMF, MeasureMEASURE 2.9
The AI model is explained, validated, and documented, and AI system output is interpreted within its context – as identified in the MAP function – to inform responsible use and governance.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 2.9
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 10
- laws
- 9
- places
- 0
- with court rulings behind them
- 1
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations3.2 Data Governance
- MIT mitigations4.6 User Rights & Recourse
- NIST Privacy FrameworkCT.PO-P3 Policies, processes, and procedures for enabling individuals’ data processing...
- NIST Privacy FrameworkCT.DM-P1 Data elements can be accessed for review.
A law in force is unmarked; the rest wear their state: not yet in force
AI risk obligations
6 laws, 5 places| Place | Law | What it asks, as read here |
|---|---|---|
| CCPA Automated Decisionmaking Technology Regulations |
When a consumer requests access to your use of ADMT to make a significant decision, respond with a plain-language explanation of the specified information about that use |
|
| AI Act, Article 14 (human oversight) from , in 14 months |
Provide the system so the assigned overseers can correctly interpret its output. |
|
| AI Act, Article 86 (right to explanation of individual decision-making) |
If you are the deployer of a high-risk AI system listed in Annex III, other than the Annex III point 2 critical-infrastructure use case, and your decision based on the system's output produces a legal effect, or similarly significantly affects a person in a way they consider to adversely impact their health, safety or fundamental rights, give that person, on request, a clear and meaningful explanation of the AI system's role in the decision-making procedure and the main elements of the decision. |
|
| Digital Code, Chapter 23: AI system design and risk-management obligations |
Where such a system's output feeds a decision that could affect a person's rights, the user must publish or otherwise supply plain-language information about the system and, on request from an affected person, explain free of charge how that person's result was reached. |
|
| Reglamento de la Ley 31814, high-risk AI system duties |
Where a high-risk AI system's decision affects a person's human rights, explain the result to the affected user in accessible language, covering the criteria and factors the decision relied on. |
|
| AI Framework Act, Article 34 (business-operator duties for high-impact AI) |
Establish and carry out a plan to explain, so far as technically feasible, your AI's final output, the main criteria it used to reach that output, and an overview of the training data you used to develop or use it. |
AI governance
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), AI Market Surveillance and Innovation Promotion Act |
Provide any information or documentation a market surveillance or notifying authority requests under Article 21 or Article 45, carry out or update the fundamental rights impact assessment Article 27 requires, and give an affected person the explanation Article 86 requires when you operate a high-risk AI system for one of the purposes Annex III lists: failing to do so can carry a German administrative fine of up to 50,000 euros, separate from the Regulation's own fines. |
AI sector rules
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Estatuto de los Trabajadores Article 64.4.d), Algorithmic Management Works Council Information Right |
Inform the works council of the parameters, rules, and instructions on which any algorithm or AI system that affects decisions on working conditions, access to employment, or continued employment is based, including any profiling, per Estatuto de los Trabajadores Article 64.4.d). |
AI transparency
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Digital Code, algorithmic decision-making rights |
Give the person an explanation of the key factors and criteria that influenced the decision, without disclosing the algorithm, source code or a legally protected secret. |
Personal data
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Minnesota Consumer Data Privacy Act (MCDPA), publicly available information exemption and profiling explanation right |
If you profile a Minnesota consumer's data for a decision with legal or similarly significant effect, be prepared to answer the consumer's questions about why the profiling reached that result and what they could have done differently, not merely to honor an opt-out request. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.