NIST AI RMF DATA INFRASTRUCTURE MODEL

AI capabilities and limitations

Part of: MP: MAP — Context & Risk Identification

Description

AI system capabilities, intended purposes, context of use, and known limitations are documented. Every AI system has boundaries — the question is whether you discover them during testing or in production incidents.

Suggested Actions

1
Document technical capabilities with quantitative metrics: accuracy, precision, recall, F1 scores, latency, throughput — broken down by demographic group and use case segment where applicable
2
Define intended use cases explicitly and, critically, document out-of-scope uses — what the system should NOT be used for is as important as what it should
3
Identify and document system limitations, failure modes, and degradation patterns: What happens with out-of-distribution inputs? How does performance change under load? What are the known blind spots?
4
Create model cards following the Google Model Card framework or equivalent, including: training data description, evaluation methodology, ethical considerations, and caveats
5
Document human oversight mechanisms: At what confidence threshold should the system escalate to a human? What information does the human reviewer receive? Can the human override the AI decision?
6
Conduct and document stress testing results: How does the system behave at the boundaries of its capabilities? What is the graceful degradation pattern?