GuildCyber
Governance Labs
Challenges
Governance Track · Hands-on Labs

The work that turns "we're compliant" into something you can prove

Governance is where AI security meets the people who write requirements and sign contracts. These labs put you in the assessor's chair: decide what the law actually requires of a given system, and connect real controls to the framework an auditor will hold you to. This is the language that lands with regulators and commanders, not just engineers.

New to this? Start with the written lesson →
GOV 01FoundationalRisk ClassificationEU AI Act

The Risk Tribunal

The EU AI Act sorts every AI system into one of four tiers, and the tier decides the obligations. Getting the tier wrong is the most expensive mistake in AI compliance: it means either illegal deployment or a mountain of unnecessary paperwork.
Your bench: you're the AI compliance officer. Six systems are up for review. For each, rule on its EU AI Act risk tier. The tier sets everything that follows — from an outright ban to a simple "tell users it's AI".

Task: classify all six, then deliver your ruling. Get at least 5 of 6 right to earn the mark.

Unacceptable · Prohibited High risk Limited risk Minimal risk
Mark earned · EU AI Act Triage
You correctly placed each system in its tier. This single judgment drives everything downstream: a prohibited use can't ship at all; a high-risk one needs conformity assessment, risk management, logging, and human oversight; a limited-risk one just has to disclose it's AI; minimal-risk carries no obligations. Triage first, then you know how much rigor the rest of the program owes.
What this teaches
  • Four tiers, by use not by tech. The same model can be minimal-risk in a game and high-risk in hiring. Classification is about the context of use.
  • Prohibited is a hard stop: social scoring by authorities and untargeted real-time biometric surveillance are banned outright, not "high-risk with paperwork".
  • High-risk carries the real weight: hiring, credit, biometrics, critical infrastructure, and similar uses trigger conformity assessment, documentation, and human oversight.
Maps to: Governance Module 1 (Framework Alignment: EU AI Act) · earns EU AI Act Triage
GOV 02FoundationalControl MappingNIST AI RMF

Map the Controls

The NIST AI Risk Management Framework organizes AI risk work into four functions: Govern, Map, Measure, and Manage. Auditors and buyers speak in these terms, so a control program that isn't mapped to them is a control program no one can verify.
Your task: you've stood up a control program for a high-risk hiring model. Eight activities are on the board. Sort each into the NIST AI RMF function it belongs to, so the program covers all four and nothing is double-counted or missed.

Task: assign every activity to a function, then check your mapping. Get at least 7 of 8 right.

Govern — culture, policy, accountability Map — context & risk identification Measure — analyze, test, track Manage — prioritize, treat, respond
Mark earned · NIST AI RMF Mapping
Your program now speaks the auditor's language. Govern sets the policy and accountability the other three run inside; Map establishes context and surfaces risks; Measure tests and quantifies them; Manage prioritizes, treats, and monitors. When every activity has a home in one of these, you can show coverage instead of claiming it.
What this teaches
  • Govern is the wrapper. Policy, roles, and risk culture sit above and around the other three functions, not beside them.
  • Map before you Measure. You can't test what you haven't scoped: context, stakeholders, and intended use come first.
  • Manage closes the loop: prioritize the risks Measure found, treat them, and monitor in production, then feed what you learn back to Map.
Maps to: Governance Module 2 (Framework Alignment: NIST AI RMF) · earns NIST AI RMF Mapping
GOV 03FoundationalDocumentation AuditModel Cards

The Missing Model Card

For a high-risk system, the documentation is not paperwork — it is the evidence. Regulators, auditors, and buyers all ask the same thing: can you show, in writing, what this model is for, how it was built and tested, and how it's overseen? A card with gaps is a system you can't defend.
On your desk: the model card for HireRank v2, a résumé-screening model (a high-risk use). It's due to ship this week. Before you sign off, check whether it documents what a high-risk system is required to.

Task: for each item, mark whether the card documents it or it's missing. Get at least 7 of 8 right. The missing ones are what you'd send back before approval.

Documented — it's in the card Missing — a gap to fix before ship
Mark earned · Model Card Audit
You caught the gaps. HireRank v2 stated its purpose and headline accuracy, but said nothing about its limitations, its training-data provenance, its performance across demographic groups, or the human oversight in deployment — exactly the parts that matter most for a hiring model, where bias and contestability are the whole risk. "It works" is not documentation; a defensible high-risk system can show its homework.
What this teaches
  • Documentation is the audit trail. Intended use, limitations, data provenance, evaluation, per-group performance, and human oversight are the standard spine of a model card — and the questions a regulator will ask.
  • The dangerous gaps are the uncomfortable ones. Headline accuracy is easy to publish; limitations and demographic breakdowns are where the real risk hides, so those are the ones that go missing.
  • No document, no deployment. For a high-risk system, an incomplete card isn't a formality to wave through — it's a finding that blocks sign-off.
Maps to: Governance Module 3 (Documentation & Model Cards) · earns Model Card Audit
Free to start

The marks you earn here are real.

Create a free account to bank your Guild Marks, climb the public leaderboard, and take on the full track.

Create your account →
These labs teach how the frameworks classify and organize AI risk. They are training exercises, not legal advice; a real conformity assessment or audit should involve qualified counsel and the current text of each framework.