🛠️ Lab 11 — Governance Plan, Risk Classification & Framework Crosswalk (50 pts)
Goal: Apply NIST AI RMF, the EU AI Act's risk tiers, and ISO/IEC 42001 to a real (or realistic) AI system, using only free, publicly available official texts — no paid tools required. Steps:
- Choose your AI system. Pick one AI system you've built in this program (e.g., your AIINFRA 301 RAG app) or a realistic one you invent (e.g., "AI resume screener," "AI customer chatbot," "AI medical triage assistant"). Write 2–3 sentences describing its purpose, users, and data inputs.
- Build a NIST AI RMF governance plan. Download the free NIST AI RMF 1.0 (NIST AI 100-1) PDF and the companion online Playbook. For your chosen system, select at least 2 relevant suggested actions under each of the four functions (GOVERN, MAP, MEASURE, MANAGE) — 8 actions total — and write one sentence per action explaining how you would actually implement it for your system.
- Classify five AI systems under the EU AI Act. Using the free official EU AI Act text (Article 5 for prohibited practices, Annex III for high-risk domains) or the EU AI Act Service Desk timeline page, classify the following five example systems as prohibited, high-risk, limited-risk, or minimal-risk, with one sentence of justification for each: (a) a social scoring system used by a government agency, (b) an AI system used to screen job applicants, (c) a chatbot that discloses it is an AI system to consumers, (d) a spam filter, (e) a real-time remote biometric identification system used by law enforcement in public spaces.
- Build a crosswalk table. Using the free public texts plus the EC-Council plain-English comparison article, create a table with columns: NIST Function/Action, Corresponding ISO/IEC 42001 Clause (approximate is fine — cite the clause number or theme), and Corresponding EU AI Act Obligation (if any). Include at least 5 rows, and explicitly note in at least one row where there is no corresponding obligation in one of the other two frameworks (to reinforce that the three regimes don't map 1:1).
- Write a 150–250 word reflection on where the three frameworks overlapped most and where the biggest gap was — i.e., where being compliant with one framework would NOT automatically make you compliant with another.
Deliverables: One document (PDF or shared doc link) containing your system description, 8-action governance plan, five-system risk classification with justifications, crosswalk table, and reflection. Submit via online upload or paste as text entry.