Law / Frameworks / NIST AI RMF / Measure
NIST AI RMF, MeasureMEASURE 3.3
Feedback processes for end users and impacted communities to report problems and appeal system outcomes are established and integrated into AI system evaluation metrics.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MEASURE 3.3
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 17
- laws
- 15
- places
- 0
- with court rulings behind them
- 2
- not yet in force
- 5
- proposed, not law
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-04 Data Privacy
- MIT mitigations3.2 Data Governance
- MIT mitigations4.6 User Rights & Recourse
- NIST Privacy FrameworkCT.PO-P3 Policies, processes, and procedures for enabling individuals’ data processing...
- NIST Privacy FrameworkCT.DM-P1 Data elements can be accessed for review.
A law in force is unmarked; the rest wear their state: not yet in force proposed
AI governance
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Andorra proposed |
It would also require giving notice that a person is interacting with an AI system rather than a human being, and providing an effective means to challenge a decision made through, or substantially based on, such a system. |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Armenia proposed |
It would also require giving notice that a person is interacting with an AI system rather than a human being, and providing an effective means to challenge a decision made through, or substantially based on, such a system. |
|
| Council of Europe Framework Convention on Artificial Intelligence, signed by Moldova proposed |
It would also require giving notice that a person is interacting with an AI system rather than a human being, and providing an effective means to challenge a decision made through, or substantially based on, such a system. |
|
| H.B. 3133 (2025), social media platform complaint system for explicit deep fake material |
If you operate a social media platform, provide an easily accessible complaint system letting a user report explicit deep fake material, alongside illegal content and content-removal decisions. Give clear, conspicuous, plain-language notice of that complaint system and how to use it. |
AI prohibited practices
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Civil Action and Platform Takedown Duty for Synthetically Created Intimate Images from , in 2 days |
If you operate a covered platform under 47 U.S.C. Sec. 223a, set up a process letting a harmed individual or the Attorney General notify you of such an image and request its removal. Post a clear and conspicuous notice describing that removal process in plain language. |
|
| Promotion of an Altered Sexual Depiction; Brooke's Law platform takedown duty |
If you operate a covered platform, one that primarily hosts user-generated content or that in the regular course of business publishes, hosts, or makes available nonconsensual altered sexual depictions, establish a process for a depicted person to request removal and post a clear and conspicuous notice describing it. |
|
| S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications |
You must provide an easily accessible system for a depicted person to request removal, and a clear, plain-language notice describing that process and your responsibilities under it. |
|
| Digital Voyeurism Prevention Act (HB 276, 2026 General Session), Utah Code Title 13 Chapter 72b from , in 3 months |
Give users a clear way to report a non-consensual counterfeit intimate image and remove a reported image within 48 hours of notice, if you operate a covered platform |
AI transparency
4 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Ley de Fomento a la Inteligencia Artificial y Tecnologías, decisiones de la IA o impulsadas por IA |
Give the person a way to challenge the decision before a competent natural person who can confirm, modify or revoke it. |
|
| Resolución ANIA 0001/2025, derecho a notificación ante decisiones automatizadas |
In that notification, confirm that AI was involved, explain the role it played, and give the person a way to challenge the decision. |
|
| Digital Services Act, Article 35(1)(k) (systemic risk mitigation, synthetic media marking) |
Offer an easy-to-use function for flagging that content |
|
| Digital Code, algorithmic decision-making rights |
Allow the person to demand review of the decision by an authorised specialist where it carries legal consequences or can affect their rights and legitimate interests. |
AI risk obligations
3 laws, 3 places| Place | Law | What it asks, as read here |
|---|---|---|
| Council of Europe Framework Convention on AI, Georgia's signature proposed |
Document information about an AI system and its usage, make it available to affected persons so they can challenge a decision made through or substantially based on the system, and provide an effective way to complain to a competent authority. |
|
| New Jersey Disparate Impact Discrimination Rules, Automated Employment Decision Tools |
Provide a mechanism for an applicant to request a reasonable accommodation where an automated tool screens applicants based on a schedule requirement. |
|
| New York Artificial Intelligence Act proposed |
Preserve the individual's option to request human review of the decision. |
AI sector rules
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| Healthcare AI Patient-Communication Disclosure Act (AB 3030) |
In each such communication, give clear instructions describing how the patient can reach a human health care provider or other appropriate person |
|
| Qatar Central Bank Artificial Intelligence Guideline |
A QCB-regulated entity must give a customer a mechanism to raise inquiries about an AI-driven decision affecting them and request a review of it. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.