Testing, Securing, and Documenting the Prototype
BLD-F04 · Foundation level · ~150 min
Capabilities
- C5Evaluation and Quality Assurance
- C6Responsible, Secure, and Appropriate Use
Source
- NIST-GAI-PROFILE
Profiles: builder
Loading…
Activity: Three-Lens Classifier
Classify each system with the three lenses. When information is missing, choose "Cannot determine" and note what you would need. Then reveal the suggested answers and check your automation-vs-AI calls.
| System | How it operates | What it does | Where it sits |
|---|---|---|---|
| Mail merge | |||
| Spam filter | |||
| Recommendation engine | |||
| Chatbot | |||
| Rules-based approval | |||
| Tool-using agent |
Activity: AI Landscape Map
Pick one AI product you use or have observed. Fill in the eight dimensions. Then export your map — it becomes the core of your checkpoint submission.
Activity: Task Scorer
List up to ten recurring tasks. Score each 1–5 on potential value (would AI plausibly improve the net result?), risk (consequence of error, data sensitivity), and verification effort (cost to confirm the output is right). Reject at least two tasks — an honest rejection is part of the method, not a failure.
Scoring: 1 = very low · 3 = moderate · 5 = very high. For verification effort, 5 means it would cost a lot to check the output.
| Task | Value (1–5) | Risk (1–5) | Verification effort (1–5) | Decision |
|---|---|---|---|---|
The three lenses — look at any system through all three
How it operates
Rules someone wrote, patterns learned from data, or a hybrid.
What it does
The action: predict, classify, detect, recommend, generate, retrieve, act.
Where it sits
The layer: model, data source, application, connected tool, workflow, human checkpoint.
One chat box can hide all three at once. Separate them before judging the system.
Worked example — "The AI answered the ticket" is five components
Classify
request type
Retrieve
policy doc
Draft
reply
Route
rules
Human
checkpoint
Five different components, each a place where incorrect data or weak oversight can cause harm. The sentence hides all of them.
The equation that decides
Low verification cost → good first use
Summarizing your own notes. You already know what's right — checking is cheap.
High verification cost → avoid first
Summarizing unfamiliar legal terms. You'd have to verify every claim — the checking is the real work.
An unpleasant task is not automatically an AI-suitable task. Run the equation first.
Review · flashcard
Flip each card, say the answer out loud first, then check.
Your takeaway card — what to keep from this module
- 1create fixtures, test normal and failure cases, check instruction injection and data exposure, document limitations, and produce a safe handoff.
- 2Test representative, edge, invalid, unavailable, adversarial, and recovery cases.
- 3Include unsupported claims, conflicting sources, oversized input, malformed output, timeout, and untrusted text that attempts to override instructions.
- 4Document purpose, setup, architecture, data boundary, model and prompt version, expected behavior, known limitations, evaluation, manual fallback, and deletion.
- 5Deliverable: Test the prototype and create a Prototype Handoff Package.
Try it yourself · Apply BLD-F04 — do the real task
This experiment takes the BLD-F04 Apply step into your own work with the AI tools you actually have.
Pick your tool (to confirm what's available — the method works with any)
Tip: open ChatGPT (free) (chatgpt.com — free tier, no login needed for most use) in a new tab to begin.
Do the task the current way — no AI. Time it, and note errors or rework. This is your baseline.
Now produce the BLD-F04 deliverable with your AI tool. Use a real prompt with your goal, context, and constraints.
Here is my task: Test the prototype and create a Prototype Handoff Package.. My goal is [goal]. Context: [what the AI needs to know]. Constraints: [limits, format, tone, length]. Produce the deliverable, and tell me where you are not certain.
Verify the AI output using the module's evaluation criteria: Check test diversity, security boundaries, reproducibility, evidence, known limitations, and honest readiness status. Time the verification.
Compare baseline vs AI honestly. Run: net value = benefit − (setup + review + correction + tool + switching).
Record what you observed