Scope the System Before You Attack the Model
Define a red-team scope by naming the AI system boundary, users, assets, and decisions before selecting attacks.
A red team without a system map is just prompt sampling. The NIST AI RMF Map function is the discipline that turns testing from entertainment into evidence. Start with the business workflow and name the actual system: model, prompts, retrieval, tools, data stores, human approvals, logging, and downstream decisions. Then name the exposure points. Can a user upload files? Can retrieved web pages change context? Can the model send messages, update records, call code, or reveal hidden instructions? Finally, name the protected assets and unacceptable outcomes. This is where vague safety language becomes test criteria: no public reply may include…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in