NIST AI RMF
DATA
INFRASTRUCTURE
MODEL
Context establishment
Description
Legal, regulatory, and societal contexts of AI system deployment are identified and documented, including norms and expectations. You cannot manage risks you don't understand, and you cannot understand risks without understanding context.
Suggested Actions
1
Research and document all applicable AI regulations for your jurisdiction and use case: EU AI Act, state-level AI laws (Colorado, Illinois BIPA, NYC Local Law 144), sector-specific requirements (FDA for medical AI, SR 11-7 for banking), and emerging legislation2
Document societal norms and ethical expectations for the AI system's domain — what would a reasonable person expect about AI involvement in this context?3
Identify relevant industry standards and best practices (ISO 42001, NIST AI RMF, IEEE 7000 series, sector-specific guidance)4
Map organizational context including existing risk tolerance, corporate values, brand reputation considerations, and competitive landscape5
Assess the current state of public trust and awareness regarding AI in your domain — deploy into a context you understand, not one you assume6
Document deployment constraints: geographic scope, language requirements, cultural considerations, connectivity requirements, and accessibility needs