NIST AI RMF
DATA
INFRASTRUCTURE
MODEL
Impact assessment
Description
AI system impacts on individuals, groups, communities, organizations, and society are identified and assessed. Impact assessment goes beyond risk identification to consider who bears the burden of AI system errors and how that burden is distributed.
Suggested Actions
1
Assess impacts on individual rights: autonomy (does the system reduce human agency?), privacy (what personal data is collected, inferred, or exposed?), dignity (could system outputs be demeaning or dehumanizing?), and safety (could system errors cause physical harm?)2
Evaluate differential impacts on protected groups across race, gender, age, disability, and other protected attributes — aggregate performance metrics that look acceptable can mask severe disparities for specific populations3
Consider broader societal impacts: labor market effects (job displacement, skill degradation), environmental costs (energy consumption, carbon footprint), democratic implications (information manipulation, filter bubbles), and economic concentration (market power, digital divides)4
Engage affected communities in impact identification and assessment — communities often identify impacts that developers and executives miss because they understand the deployment context from the receiving end5
Assess cumulative impacts: How does this AI system interact with other AI systems and automated processes the same individuals encounter? A single system may be fair in isolation but contribute to cumulative disadvantage6
Document impact assessment methodology, findings, and mitigations with enough specificity to enable independent review and reproduce conclusions