Legal requirement
public sector use
·
United States
EO 14179 · Section 5
Agency heads were directed to identify actions taken under Executive Order 14110 that are inconsistent with the policy of EO 14179 and to suspend, revise or rescind them, and OMB was directed to revise its federal AI use and procurement memoranda.
Source-linked
Legal requirement
risk management
·
United States
OMB M-25-21 · Section 4
For AI whose output serves as a principal basis for decisions with significant effects on rights, safety or access to services, agencies must complete pre-deployment testing, an AI impact assessment, ongoing monitoring, operator training, human oversight and a mechanism for affected people to seek remedy, or stop using the AI.
Source-linked
Legal requirement
transparency
·
United States
OMB M-25-21 · Section 3
Agencies must inventory their AI use cases annually and publish the inventory, identifying high-impact uses, with limited exclusions.
Source-linked
Voluntary guidance
governance accountability
·
United States
NIST AI RMF · GOVERN function
Govern covers policies and procedures for AI risk, roles and responsibilities, workforce diversity and training, organisational culture, stakeholder engagement, and third-party risk management. It is the cross-cutting function that supports the other three.
Source-linked
Voluntary guidance
impact assessment
·
United States
NIST AI RMF · MAP function
Map establishes the context: intended purposes, users, deployment settings, legal requirements, risk categorisation, benefits and costs, and impacts on individuals, groups, communities and society.
Source-linked
Voluntary guidance
risk management
·
United States
NIST AI RMF · MANAGE function
Manage allocates resources to mapped and measured risks, plans responses including decommissioning, manages third-party risks, and documents post-deployment monitoring, incident response and communication.
Source-linked
Voluntary guidance
safety testing
·
United States
NIST AI RMF · MEASURE function
Measure covers selecting metrics and test methods, evaluating validity, safety, security, resilience, explainability, privacy, fairness and bias, and monitoring these over time, including through independent review and red-teaming for generative AI.
Source-linked