🛠️ Lab 11 — Governance Plan, Risk Classification & Framework Crosswalk (50 pts)

Goal: Apply NIST AI RMF, the EU AI Act's risk tiers, and ISO/IEC 42001 to a real (or realistic) AI system, using only free, publicly available official texts — no paid tools required. Steps:

  1. Choose your AI system. Pick one AI system you've built in this program (e.g., your AIINFRA 301 RAG app) or a realistic one you invent (e.g., "AI resume screener," "AI customer chatbot," "AI medical triage assistant"). Write 2–3 sentences describing its purpose, users, and data inputs.
  2. Build a NIST AI RMF governance plan. Download the free NIST AI RMF 1.0 (NIST AI 100-1) PDF and the companion online Playbook. For your chosen system, select at least 2 relevant suggested actions under each of the four functions (GOVERN, MAP, MEASURE, MANAGE) — 8 actions total — and write one sentence per action explaining how you would actually implement it for your system.
  3. Classify five AI systems under the EU AI Act. Using the free official EU AI Act text (Article 5 for prohibited practices, Annex III for high-risk domains) or the EU AI Act Service Desk timeline page, classify the following five example systems as prohibited, high-risk, limited-risk, or minimal-risk, with one sentence of justification for each: (a) a social scoring system used by a government agency, (b) an AI system used to screen job applicants, (c) a chatbot that discloses it is an AI system to consumers, (d) a spam filter, (e) a real-time remote biometric identification system used by law enforcement in public spaces.
  4. Build a crosswalk table. Using the free public texts plus the EC-Council plain-English comparison article, create a table with columns: NIST Function/Action, Corresponding ISO/IEC 42001 Clause (approximate is fine — cite the clause number or theme), and Corresponding EU AI Act Obligation (if any). Include at least 5 rows, and explicitly note in at least one row where there is no corresponding obligation in one of the other two frameworks (to reinforce that the three regimes don't map 1:1).
  5. Write a 150–250 word reflection on where the three frameworks overlapped most and where the biggest gap was — i.e., where being compliant with one framework would NOT automatically make you compliant with another.

Deliverables: One document (PDF or shared doc link) containing your system description, 8-action governance plan, five-system risk classification with justifications, crosswalk table, and reflection. Submit via online upload or paste as text entry.