Responsible AI practice requires saying plainly where the museum falls short. These are the limitations of Halston Arthouse’s AI use as it stands today. Gaps that have since been closed in the build are removed from this list rather than left standing.
- Self-assessed, not certified
- Alignment with the NIST AI RMF, the EU AI Act, and ISO/IEC 42001 is the museum’s own assessment. No external audit, conformity assessment, notified-body review, or ISO certification has been carried out, and none is claimed.
- One-person oversight
- The accountable human reviewer is a single curator. There is no separate reviewer, no segregation of duties, and no independent appeal body inside the museum. A concern is reviewed by the same person who made the original decision.
- Third-party models are not fully explainable
- Curatorial text, safety screening, and narration rely on general-purpose models operated by external providers. Their training data, weights, and internal reasoning are not visible to the museum, so outputs cannot be fully explained, reproduced, or guaranteed free of bias or error.
- Automated safety screening is imperfect
- The content check can both miss prohibited material and wrongly flag legitimate art. It only ever flags — it never accepts or refuses a work on its own — but a wrong flag can delay a submission until a curator reads it.
- AI text may misread the work
- Machine-written wall text is interpretation, not fact. It can misidentify medium, period, or intent. It is labelled wherever it appears and an artist may ask for it to be corrected or removed.
- Adversarial defences are deterrents
- Prompt-injection, poisoning, extraction, and screen-capture protections reduce risk; they do not eliminate it. A determined attacker with device-level tools can still capture displayed images.
- Measurement is internal, not benchmarked
- Accuracy, cohort disparity, drift, reliability, and token consumption are measured continuously against written thresholds, with breaches raising alerts. But accuracy rests on one curator’s judgement rather than an independent ground truth, token figures are estimated because providers do not return usage, and there is no external benchmark suite or formal red-team programme.
- No provider-side obligations assumed
- The museum acts as a deployer of AI systems, not a provider. It does not train, fine-tune, or place models on the market, and it cannot fulfil provider duties such as technical documentation or post-market monitoring of the underlying models.
- Automated decision-making rights
- Because no legal or significant decision about a person is made by AI alone, GDPR Art. 22 safeguards are not engaged. Should that ever change, a documented human-review route would be published before the change took effect.
- Small team, quarterly cadence
- The AI programme is reviewed quarterly rather than continuously, and an overdue review raises its own alert. With a deliberately small team, remediation between reviews happens as capacity allows.
This statement is reviewed alongside the museum’s AI inventory. If you believe a limitation is missing or has been understated, the curator would rather hear it than not.