0
Graphic depicting the three phases of analysis under NIST's AI RMF: map, measure, manage.

Creating trustworthy AI and reducing liability with NIST’s AI Risk Management Framework

On January 26, 2023, the National Institute of Standards and Technology (NIST) released the first version of the Artificial Intelligence Risk Management Framework (AI RMF).[1] The AI RMF is a voluntary resource meant to help organizations “manage the many risks of AI and promote trustworthy and responsible development and use of AI systems.”[2] To support the goal of the AI RMF, NIST supplemented its release with a companion NIST AI RMF Playbook,[3] AI RMF Explainer Video,[4] an AI RMF Roadmap,[5] AI RMF Crosswalk,[6] and statements from organization and individuals interested in the success of the AI RMF.[7] Together, these resources provide organizations with a comprehensive toolbox for identifying and managing AI risks. Given the growing regulatory interest in scrutinizing AI, these resources — although voluntary to use — provide important insights into what regulators may or may not want to see in AI products, services, and systems.

Background

The US Federal Government has long recognized the need for AI regulation. In 2016, the National Science and Technology Council produced a report stating that “the approach to regulation of AI-enabled products to protect public safety should be informed by assessment of the aspects of risk.”[8] In 2018, President Donald Trump signed a law establishing the National Security Commission on Artificial Intelligence to consider how to defend against AI threats and promote AI innovation.[9] In 2019, following Executive Order 13859,[10] the White House’s Office of Science and Technology Policy released guidance detailing the ten principles that Federal agencies should consider when determining how to regulate AI.[11] In response, NIST released a position paper, which called for US agencies to create globally relevant, non-discriminatory AI standards. Recognizing that AI has the potential to transform every sector of the US economy and society, Congress passed the National AI Initiative Act of 2020, which established the National Artificial Intelligence Initiative (NAIA), and directed NIST to “develop voluntary standards for artificial intelligence systems.”[12] On July 29, 2021, NIST issued a Request for Information to Help Develop an AI Risk Management Framework,[13] in which NIST asked individuals, groups, and organizations to submit comment on the goals of the AI RMF and on how those goals should be achieved. On October 15, 2021, NIST published a summary analysis of those comments,[14] and on December 13, 2021, the agency published a concept paper incorporating input from the initial Request for Information.[15] NIST released a draft AI RMF on March 17, 2022,[16] but, based on comments received during a NIST workshop held that same month,[17] the agency released a modified second draft on August 18, 2022,[18] and held another workshop in October 2022.[19] Four months later, NIST released the first version of the AI RMF.

Seven characteristics of trustworthy AI

As a flexible framework designed to adapt to a wide range of systems, products, and organizations, the AI RMF does not prescribe specific technical requirements that must be satisfied before an AI is considered trustworthy. Instead, the AI RMF provides a list of characteristics that must be balanced “based on the AI system’s context of use.”[20] These characteristics are:
  1. Valid and reliable
    1. Valid: Confirmation, though the provision of objective evidence, that the requirements for the AI’s specific intended use or application have been fulfilled. (ISO 9000:2015.)
    2. Reliable: The ability of AI system to perform as required, without failure, for a given time interval, under given conditions, including the entire lifetime of the system. (ISO/IEC TS 5723:2022.)
    3. Accurate: The closeness of the AI system’s results of observations, computations, or estimates to the true values or the values accepted as being true. (ISO/IEC TS 5723:2022.)
    4. Robust / Generalized: The ability of an AI system to maintain its level of performance under a variety of circumstances, which includes performing in ways that minimize potential harm to people if it is operating in an unexpecting setting. (ISO/IEC TS 5723:2022.)
  2. Safe
    1. AI systems should not, under defined conditions, lead to a state in which human life, health, property, or the environment is endangered. (ISO/IEC TS 5723:2022.)
  3. Secure and resilient
    1. Secure: AI systems should maintain confidentiality, integrity, and availability through protection mechanisms that prevent unauthorized access and use. (NIST Cybersecurity Framework and Risk Management Framework.)
    2. Resilient: AI systems, as well as the ecosystems in which they are deployed, should withstand unexpected adverse events or unexpected changes in their environment or use — or if they can maintain their functions and structure in the face of internal and external change and degrade safely and gracefully when this is necessary. (ISO/IEC TS 5723:2022.)
  4. Accountable and transparent
    1. Transparent: Information about an AI system and its outputs should be available to individuals interacting with such a system, regardless of whether they are even aware that they are doing so, and be tailored to the role or knowledge of AI actors or individuals interacting with or using the AI system.
    2. Accountable: AI systems should incorporate actionable redressability related to AI system outputs that are incorrect or otherwise lead to negative impacts.
  5. Explainable and interpretable
    1. Explainable: The AI system should describe how the AI system functions, with descriptions tailored to individual differences such as the user’s role, knowledge, and skill level.
    2. Interpretable: The AI system should communicate a description of why an AI system made a particular prediction or recommendation. (“Four Principles of Explainable Artificial Intelligence” and “Psychological Foundations of Explainability and Interpretability in Artificial Intelligence.”[21])
  6. Privacy-enhanced
    1. Privacy values such as anonymity, confidentiality, and control should guide choices for AI system design, development, and deployment, but privacy-enhancing technologies (PETs) may be needed to support privacy-enhanced AI design.
  7. Fair — with harmful bias managed
    1. Fair: AI systems should incorporate equality and equity by addressing issues such as harmful bias and discrimination, which includes taking into consideration cultural context and demographic differences.
    2. With harmful bias managed: AI systems should consider and manage three major categories of AI bias:
      1. Systemic: Bias found in the AI datasets, the organizational norms, practices, and processes across the AI lifecycle, and the broader society that uses the AI system.
      2. Computational and statistical: Bias found in AI datasets and algorithmic processes, and often stems from systematic errors due to non-representative samples.
      3. Human-cognitive: Bias relating to how an individual or group perceives AI system information to make a decision or fill in missing information, or how humans think about purposes and functions of an AI system.

Practical benefit of complying with the AI RMF

As a voluntary framework, the AI RMF does not mandate compliance with its principles; however, as the NIST Cybersecurity Framework demonstrates, voluntary compliance may help shield an organization from legal risks. The NIST Cybersecurity Framework offers a risk-based approach to cybersecurity and a methodology for developing a comprehensive information security program. Like the AI RMF, the Cybersecurity Framework is voluntary, and therefore does not form the basis for any regulatory action. Yet, if a cybersecurity incident occurs, an organization that has implemented the Cybersecurity Framework can use their adherence in their favor. For example, if a regulator alleges the organization was negligent in its cybersecurity practices, the organization can rebut the allegations by demonstrating that its program was designed in accordance with the Cybersecurity Framework and therefore was reasonably designed to counter foreseeable risks. Compliance with the AI RMF may produce similar benefits, given that NIST created the AI RMF for AI industry stakeholders to “cultivate trust in the design, development, use, and evaluation of AI technologies and systems in ways that enhance economic security and improve qualify of life.”[22]
[1] https://www.nist.gov/itl/ai-risk-management-framework [2] https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf [3] https://pages.nist.gov/AIRMF/ [4] https://www.nist.gov/video/introduction-nist-ai-risk-management-framework-ai-rmf-10-explainer-video [5] https://www.nist.gov/itl/ai-risk-management-framework/roadmap-nist-artificial-intelligence-risk-management-framework-ai [6] https://www.nist.gov/itl/ai-risk-management-framework/crosswalks-nist-artificial-intelligence-risk-management-framework [7] https://www.nist.gov/itl/ai-risk-management-framework/perspectives-about-nist-artificial-intelligence-risk-management [8] https://obamawhitehouse.archives.gov/sites/default/files/whitehouse_files/microsites/ostp/NSTC/preparing_for_the_future_of_ai.pdf [9] https://www.govinfo.gov/content/pkg/COMPS-15483/uslm/COMPS-15483.xml; https://www.nscai.gov/ [10] https://trumpwhitehouse.archives.gov/presidential-actions/executive-order-maintaining-american-leadership-artificial-intelligence/ [11] https://www.whitehouse.gov/wp-content/uploads/2020/01/Draft-OMB-Memo-on-Regulation-of-AI-1-7-19.pdf [12] https://www.congress.gov/bill/116th-congress/house-bill/6216 [13] https://www.federalregister.gov/documents/2021/07/29/2021-16176/artificial-intelligence-risk-management-framework [14] https://www.nist.gov/system/files/documents/2021/10/15/AI%20RMF_RFI%20Summary%20Report.pdf [15] https://www.nist.gov/system/files/documents/2021/12/14/AI%20RMF%20Concept%20Paper_13Dec2021_posted.pdf [16] https://www.nist.gov/system/files/documents/2022/03/17/AI-RMF-1stdraft.pdf [17] https://www.nist.gov/news-events/events/2022/03/building-nist-ai-risk-management-framework-workshop-2 [18] https://www.nist.gov/system/files/documents/2022/08/18/AI_RMF_2nd_draft.pdf [19] https://www.nist.gov/news-events/events/2022/10/building-nist-ai-risk-management-framework-workshop-3 [20] https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf [21] https://www.nist.gov/artificial-intelligence/ai-fundamental-research-explainability [22] https://www.nist.gov/itl/ai-risk-management-framework/ai-risk-management-framework-faqs
0
Picture of the word "AI" surrounded by stars.

What the EU’s Artificial Intelligence Act will mean for the global AI industry

On April 21, 2021, the European Commission proposed the Artificial Intelligence Act (AIA), a regulatory and legal framework for artificial intelligence systems.[1] On December 5, 2022, the Council of the European Union adopted its general approach to the AIA, which incorporated changes to the regulation.[2][3] Germany announced support for the AIA, but “sees some need for improvements.”[4] In similar fashion, the Federal Trade Commission (FTC) published an article on April 19, 2021, calling for the integration of truth, fairness, and equity into the use of AI.[5] Later that year, the FTC announced its consideration to initiate rulemaking to, in part, ensure that algorithmic decision-making does not result in unlawful discrimination.[6] Given this growing international interest in regulating AI systems, it is important to note that the AIA was drafted to have an extraterritorial effect much like the EU’s General Data Protection Regulation (GDPR). The GDPR became a global model for data protection laws across the world, including the California Consumer Privacy Act (CCPA), and the AIA could similarly establish a worldwide standard for AI regulation – especially if the FTC is considering initiating rulemaking for algorithmic systems. So, while the draft AIA will likely see more changes, the proposed regulation appears sufficiently settled for analysis of its requirements and potential global effects. This article provides an overview of the major legal takeaways from the AIA, including which AI systems are outright prohibited and which are less regulated. Background As early as 2017, the European Council called for a “sense of urgency to address emerging trends,” including “issues such as artificial intelligence . . ., while at the same time ensuring a high level of data protection, digital rights and ethical standards.”[7] On July 16, 2019, Ursula von der Leyen, then-candidate for President of the European Commission, announced her political guidelines for the 2019-2024 Commission, in which she called for legislation for a coordinated EU approach on the human and ethical implications of AI. [8] Following this announcement, the Commission published a white paper on AI, “A European approach to excellence and trust.”[9] This paper sets out policy options for how to achieve the goal of promoting AI adoption while also addressing the risks associated with certain uses of AI. The AIA draft proposed on April 21, 2021, delivers on now-President von der Leyen’s political commitments announced in 2019 and the white paper’s stated objectives. The result is a legal framework presenting a balanced, proportionate regulatory approach that seeks to address the risks and problems with AI, without unduly constraining or hindering AI development on the market. To whom does the AIA apply? Like the GDPR’s territorial scope in Article 3, the AIA’s scope in Article 2 covers providers that place AI systems on the EU market, or put them into service in the EU, irrespective of whether those providers are established within the EU. A “provider” is any natural or legal person, public authority, agency, or other body that develops an AI system or that has an AI system developed. An AI is “put into service” by a provider when the provider supplies an AI system for first use directly to a user or for the provider’s own use on the EU market. An AI is placed “on the market” by a provider when the AI is distributed or used on the EU market in the course of a commercial activity, whether in return for payment or free of charge. Taken together, this means that the AIA does not apply to private, non-professional use, but anyone supplying, using, or distributing, AI systems on the EU market to users or for their own purposes may fall within the regulation’s scope. Can the EU’s proposed AI regulation apply to AI creators and companies outside of the EU? Yes. The AIA applies to AI systems used by natural or legal persons, including public authorities, agencies, or other bodies, who are physically present or established within the Union. However, the regulation’s reach extends beyond the EU’s borders. The AIA covers natural or legal persons, including public authorities, agencies, or other bodies, who are physically present or established “in a third country, where the output produced by the system is used in the Union.” The AIA also applies to any natural or legal person that makes an AI system available on the EU market. This extraterritorial scope, like the GDPR’s, means companies outside of the EU should take care in considering how and where their AI systems are used. Does the EU’s proposed AI regulation provide data subjects with additional rights? No. The AIA does not provide additional rights to data subjects. Instead, as a piece of product regulation, the AIA takes aim at the AI systems themselves, by either prohibiting a particular AI system or requiring it to conform to a list of obligations. That said, the AIA recognizes the need for new AI technologies to be “developed and functioning according to Union values, fundamental rights, and principles.” This includes rights provided under the GDPR, such as an individual’s right to restrict processing (Article 18) and the right of deletion / erasure (Article 17). Furthermore, a controller using an AIA-covered AI system must satisfy their GDPR notice obligations to data subjects (Articles 12 – 14). Does the EU’s proposed AI regulation cover all algorithm-based systems? No. The AIA draft proposed on April 21, 2021, defined “AI system” so broadly that it seemed to encompass most software, which prompted EU Member States to propose a narrower definition.[10] The version adopted by the Council of the EU on December 5, 2022, recognizes the need to more narrowly define “AI system” to “provide sufficiently clear criteria for distinguishing AI from more classical software systems.” Thus, the current AIA draft defines “AI system” to target systems developed through machine learning and logic- and knowledge-based approaches. In addition, an AI system using one of these approaches must operate with elements of autonomy and, based on machine and/or human-provided data and inputs, infer how to achieve a given set of objectives. This definition is recognized by the Council as a “compromise” between those calling for a broader definition and those calling for a narrower one, and as such, it remains subject to change. Does the proposed AI regulation treat all covered AI systems equally? No. The regulation uses a risk-based approach to separate covered AI systems into four categories: Unacceptable Risk The AIA contains a limited list of particularly harmful AI systems found to contravene EU values. Because the risk of harm is unacceptably high, these AI systems are prohibited under the regulation. This list includes:
  1. An AI system that subliminally manipulates a person, thereby materially distorting the person’s behavior in a manner that causes or is reasonably likely to cause physical or psychological harm.
  2. An AI system that exploits the vulnerabilities of individuals due to age, disability, or socioeconomic status, resulting in physical or psychological harm.
  3. An AI system that analyzes individuals to create a social score, which leads to detrimental or unfavorable treatment unrelated to the contexts in which the data was originally generated or collected.
  4. Some uses of remote biometric identification for law enforcement purposes in publicly accessible spaces (e.g., facial recognition technology).
A full list of prohibited AI systems can be found in Article 5 of the AIA. High-Risk Most of the AIA’s legal obligations and burdens fall on AI systems deemed to be “high-risk” under the regulation. An AI system is considered “high-risk” under the AIA if the AI system is itself a product or is intended to be used as a safety component of a product, and the product is subject to an existing third-party conformity assessment (e.g., medical devices, machinery, engine-powered vehicles, certain stand-alone AI systems in employment, education, and immigration, etc.). A high-risk AI system can only be used in the EU or put on the EU market if the AI system complies with the AIA’s legal obligations. This includes:
  1. A risk management system (Article 9).
  2. Adherence of training, validation, and testing data to quality criteria (Article 10).
  3. Technical documentation describing how the AI system complies with applicable rules, including law enforcement purposes (Article 11).
  4. Record-keeping requirements to ensure traceability of the AI system’s functions (Article 12).
  5. Transparency requirements to enable users to understand the system’s output and use (Article 13).
  6. Providing adequate human oversight of the AI system’s operations (Article 14).
  7. Ensuring the AI system achieves appropriate levels of accuracy, robustness, and cybersecurity (Article 15).
The AIA provides further obligations on AI system developers, which include:
  1. Maintaining a quality management system (Article 17).
  2. Ensuring the system undergoes a conformity assessment procedure (Article 19).
  3. Maintaining automatically generated logs (Article 20).
  4. Taking corrective actions if the system is found not to conform with the AIA (Article 21).
  5. A duty to notify serious incidents or malfunctions to national competent authorities (Article 22).
Limited Risk Title IV of the AIA creates new transparency obligations for certain AI systems. For example, users of emotion recognition systems or biometric categorization systems must be informed of the operation of the system. In addition, users of an AI system that generates deep fake images or content must be informed that the content has been artificially generated or manipulated. Similar to the GDPR, these disclosures must be provided to the user in a clear and distinguishable manner no later than the user’s first interaction or exposure to the AI system. Minimal / No Risk If an AI system does not fall into one of the above categories, then it can be developed and used in the EU subject to existing regulation without any additional legal obligations under the AIA. That said, the Council encourages developers of AI systems in this category to “create codes of conduct intended to foster the voluntary application of the requirements applicable to high-risk AI systems, adapted in light of the intended purpose of the systems and the lower risk involved.”[11] Are the enforcement penalties harsher than the GDPR? Yes. Non-compliance with the AIA’s list of prohibited AI systems in Article 5 could be subject to an administrative fine of up to €30 million or, if the offender is a company, up to 6% of its worldwide annual turnover for the preceding financial year, whichever is higher. By contrast, serious GDPR violations can result in a fine of up to €20 million or 4% of a company’s worldwide annual revenue from the preceding financial year, whichever is higher. For less serious infringements under the AIA, the offender could be subject to administrative fines of up to €20 million or, if the offender is a company, up to 4% of its total worldwide annual turnover for the preceding financial year, whichever is higher. This too is higher than the GDPR’s fines for less severe infringements. What are the next steps for the AIA? The Parliament is scheduled to vote on the current draft of the AIA by the end of March 2023. After this, Member States, the Parliament, and the European Commission will begin discussions of the AIA in April 2023. This timeline could lead to an adoption of the AIA by the end of 2023.
[1] https://artificialintelligenceact.eu/wp-content/uploads/2022/05/AIA-COM-Proposal-21-April-21.pdf [2] https://www.consilium.europa.eu/en/press/press-releases/2022/12/06/artificial-intelligence-act-council-calls-for-promoting-safe-ai-that-respects-fundamental-rights/ [3] https://data.consilium.europa.eu/doc/document/ST-14954-2022-INIT/en/pdf [4] https://data.consilium.europa.eu/doc/document/ST-14954-2022-ADD-1/en/pdf [5] https://www.ftc.gov/business-guidance/blog/2021/04/aiming-truth-fairness-equity-your-companys-use-ai [6] https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202210&RIN=3084-AB69 [7] https://www.consilium.europa.eu/media/21620/19-euco-final-conclusions-en.pdf [8] https://op.europa.eu/en/publication-detail/-/publication/43a17056-ebf1-11e9-9c4e-01aa75ed71a1 [9] https://commission.europa.eu/publications/white-paper-artificial-intelligence-european-approach-excellence-and-trust_en [10] https://www.wired.com/story/artificial-intelligence-regulation-european-union [11] https://artificialintelligenceact.eu/wp-content/uploads/2022/05/AIA-COM-Proposal-21-April-21.pdf
1 2 3 4