GenAI Capabilities & Risks
Generative AI is like having a very capable assistant that can write, draw, and code. But this assistant sometimes states wrong information confidently, or accidentally generates harmful content. The AIF-C01 exam requires you to understand both the powers and the risks.
---
7 Core Capabilities of Generative AI
| Capability | Plain-English Explanation | |------------|--------------------------| | Adaptability | The same model answers cooking questions and legal questions — it adjusts to context. | | Responsiveness | Answers appear almost instantly, far faster than asking a human expert. | | Simplicity | Enormous complexity is hidden behind a simple chat interface. | | Creativity | It generates new ideas, slogans, code snippets, or story openings that never existed before. | | Data Efficiency | Works well even with smaller datasets, making it accessible to smaller organizations. | | Personalization | The same model can respond simply to a child and technically to an expert. | | Scalability | Handles millions of simultaneous users — traditional call centers cannot compete. |
---
Key Challenges Overview
Regulatory violations: unintentional breach of laws Social risks: amplified bias and misinformation Data security: leakage of sensitive information Toxic content: offensive or harmful outputs Hallucinations: confident but false statements Uninterpretability: black-box decision-making Non-determinism: same input, different outputs Plagiarism and cheating: ethical and legal concerns
---
Toxicity
Toxicity refers to AI outputs that are offensive, hateful, or inappropriate. Defining "toxic" is hard because standards vary by culture, audience, and context. AWS addresses this with Guardrails for Amazon Bedrock.
Mitigation strategies: Training data curation: filter harmful data before training Guardrails and moderation models: automatically detect and block harmful outputs Human-in-the-Loop (HITL): human reviewers handle ambiguous cases
---
Hallucinations
AI predicts the most probable next word — it does not truly "know" facts. This causes it to invent book titles, cite non-existent legal cases, or give wrong calculations confidently.
| Strategy | Description | |----------|-------------| | User education | Inform users that AI output is not guaranteed to be accurate | | Verification | Always cross-check with trusted sources | | Output labeling | Clearly mark AI-generated content as unverified | | RAG | Ground responses using real external documents retrieved at query time |
When the exam mentions hallucinations, think RAG first.
---
Prompt Misuses — 5 Types
Poisoning: injecting malicious or biased data into training data Hijacking / Prompt Injection: hiding override instructions inside user input Exposure of Sensitive Information: private data leaking through model outputs Prompt Leaking: the hidden system prompt becoming visible to users Jailbreaking: tricking the model into bypassing safety guardrails
---
Exam Quick Reference
7 capabilities: Adaptability, Responsiveness, Simplicity, Creativity, Data Efficiency, Personalization, Scalability Hallucination fix → RAG Toxicity fix → Guardrails + data curation + HITL Prompt misuses: 5 types — Poisoning, Injection, Exposure, Leaking, Jailbreaking Guardrails for Amazon Bedrock handles toxicity filtering, PII removal, and sensitive topic blocking