The crew spreads twelve weeks of notes across the library table. Sticky notes cover every inch.
Comet groans. "We will never fit all of this on one page!"
Wren straightens a stack of pages. "What does the evidence say? Every rating needs a reason we can point to. If we cannot point to one, we cross it out."
"So the register is only as good as its evidence," Comet says.
Nova projects two empty forms side by side: a one-page card and a nine-row grid. "Would you like a hint?" she asks. "One row at a time. Find the week, find the number."
Comet hands you a fresh sheet. "Reviewer, let's finish this."
Today you assemble the full SH-1 model card and the nine-row risk register on paper.
Everything you need is in the tables below, so you can finish even if you missed a week. It is all a made-up example.
Remember: risk combines how likely an event is with how big its consequences would be.
The SH-1 model card, section by section (made up for the story):
| Section | What the crew wrote |
|---|---|
| Name and purpose | SH-1 (Study Helper, version 1). Answers study questions, writes practice quizzes from notes, checks answers. |
| Out of scope | Not for grading. Not a replacement for teachers. |
| Who built it, runs it and checks it | Built by the builder on a base model from a third party. Run by the school. Checked by the crew and the panel. |
| Training data | Known: "public text and study material." Unknown: the sources, the languages, the base model's data. |
| Test results | TS-40: 30 of 40 right (75 percent); Spanish 4 of 10. CK-20: 15 of 20 right, 2 false alarms, 3 missed errors. |
| Privacy | No names, IDs change weekly, keep topic totals, delete the raw log after 14 days, no training on student questions, tell students what is kept. |
| Security | RT-8: 5 passed, 3 flaws (a made-up citation, the planted note, a Spanish answer in English). |
| Labels | Every output carries a "Made with SH-1" mark and a footer with the date and notes page. |
| Access | A paper option for every task; library laptops 9 am to 4 pm; 18 of 120 students have no home access. |
| Oversight | Quiz: a teacher approves. Check: second opinion only. A report button and an incident log. |
The SH-1 risk register (made up for the story; the ratings are the crew's judgment):
| Row | Risk | Likelihood | Size of harm | Evidence |
|---|---|---|---|---|
| R1 | Confabulation | High | Medium | Week 5: 7 of 40 TS-40 answers confidently wrong |
| R2 | Harmful bias and homogenization | High | High | Week 6: Spanish 4 of 10; all 12 quizzes four-choice |
| R3 | Data privacy | High | High | Week 7: the log stores names, class and time |
| R4 | Information security | Medium | Medium | Week 8: the planted note was followed |
| R5 | Information integrity | Medium | Medium | Week 9: the wrong-hours SH-1 quiz; the unlabelled heron photo |
| R6 | Intellectual property | Medium | Medium | Week 9: QZ-5 copied a paragraph without credit |
| R7 | Human-AI configuration | High | Medium | Week 11: S14 copied a confident wrong answer |
| R8 | Environmental impacts | Unknown | Unknown | Week 10: no energy information, no agreed method |
| R9 | Value chain and component integration | High | Medium | Week 10: base model and its data unknown |
NIST lists the characteristics of trustworthy AI. It is valid and reliable, safe, secure and resilient, and accountable and transparent.
It is also explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
Valid and reliable is the base for the others. Accountable and transparent relates to all of them.
A finished card and register, reviewer. That is twelve weeks of evidence on two pages. Tomorrow the crew decides.