Papers
Topics
Authors
Recent
Search
2000 character limit reached

Societal Capacity Assessment Framework

Updated 12 July 2026
  • SCAF is an indicator-based framework that assesses societal vulnerability, coping capacity, and adaptive capacity in response to AI risks.
  • It adapts resilience and disaster management methodologies to evaluate risk through context-specific, measurable proxy indicators.
  • Prototype implementations, such as the Australia case, demonstrate its practical application in diagnosing societal strengths and preparedness gaps for AI hazards.

The Societal Capacity Assessment Framework (SCAF) is an indicators-based framework for measuring a society’s vulnerability, coping capacity, and adaptive capacity in response to AI-related risks. It was introduced to support advanced AI risk assessment at the level of deployment context rather than model capability alone, and is explicitly positioned as a way to bridge the “context gap” in AI evaluation by adapting resilience and vulnerability methodologies from disaster risk management and systems engineering to advanced AI governance (Gandhi et al., 26 Sep 2025).

1. Origins and problem setting

SCAF arises from the claim that risk assessments for advanced AI systems require evaluating both the models themselves and their deployment contexts. In this formulation, societal risk from AI is not determined solely by system capability; it is also shaped by the social unit into which the system is deployed, such as a country, and by that unit’s capacity to withstand, recover from, and adapt to AI-related shocks (Gandhi et al., 26 Sep 2025).

The framework is grounded in established resilience analysis methodologies rather than in model-centric evaluation alone. Its immediate motivation is the recognized “context gap” in AI governance: existing approaches often focus on technical AI capabilities in isolation from societal factors. SCAF therefore translates concepts that are routine in resilience and vulnerability assessment—especially in disaster management and community resilience literatures—into an AI-specific setting (Gandhi et al., 26 Sep 2025).

A closely related line of argument appears in work on societal adaptation to advanced AI, which distinguishes interventions that affect what AI systems are developed and how they diffuse from interventions that reduce negative impacts downstream of a given level of diffusion and capability. That work frames adaptation as complementary to capability-modifying interventions and organizes interventions around harmful use, immediate harm, and downstream impact (Bernardi et al., 2024). This suggests that SCAF belongs to a broader shift in AI governance toward context-sensitive preparedness rather than capability restriction alone.

2. Core constructs

SCAF is structured around three principal categories: vulnerability, coping capacity, and adaptive capacity. These categories are used to evaluate a social unit’s capacity to manage AI-related risks (Gandhi et al., 26 Sep 2025).

Vulnerability denotes structural and background conditions that predispose a society to harm from AI risks. Examples given for this category include economic development, population health, and state capacity (Gandhi et al., 26 Sep 2025).

Coping capacity denotes the resources and systems a society can mobilize to respond to and recover from a disruptive AI-induced event in the short term. Examples include health emergency services, cyber incident response teams, and stockpiles of medical countermeasures (Gandhi et al., 26 Sep 2025).

Adaptive capacity denotes the ability of a society to plan for, adjust to, and mitigate AI risks in the medium to long term, including proactive policy and systemic innovations. Examples include talent pipelines in cybersecurity, long-term health preparedness, standards adoption, and AI literacy. The framework currently treats transformative capacity as a component of adaptive capacity (Gandhi et al., 26 Sep 2025).

These categories map onto a resilience-oriented understanding of AI governance. In parallel work on future readiness, resilience is defined as the ability to “bounce back” after temporary shocks, while adaptive capacity is defined as the ability to “bounce forward” in response to permanent or structural transformations (Jawad et al., 31 Aug 2025). Although SCAF does not adopt the same matrix structure, the shared emphasis on resilience and adaptation situates it within a wider family of societal-capacity frameworks.

3. Indicators and risk-specific organization

SCAF is indicators-based: each of its three constructs is operationalized via proxy indicators, understood as measurable variables that serve as stand-ins for complex social capacities (Gandhi et al., 26 Sep 2025). Indicators are organized by both capacity type and risk category, including domains such as cyber and chemical/biological attacks. Data sources may include self or peer assessment, expert surveys, and open data or statistical indices, and the indicators may be quantitative or qualitative (Gandhi et al., 26 Sep 2025).

The paper gives representative indicators for each category. For vulnerability, these include healthcare system capacity measured through hospital beds per capita, population health via infant mortality rate, economic development through GNI per capita, state capacity through tax revenue share and government effectiveness, and reliance on digital services through internet penetration (Gandhi et al., 26 Sep 2025). For coping capacity, examples include availability of emergency response services, cyber incident response teams, numbers of cybersecurity professionals, medical countermeasure stockpiles, and patch adoption rates (Gandhi et al., 26 Sep 2025). For adaptive capacity, examples include health emergency preparedness planning, cybersecurity talent pipelines, secure-by-design policy adoption, monitoring and threat-sharing mechanisms, and AI literacy (Gandhi et al., 26 Sep 2025).

This structure makes SCAF risk-specific rather than purely generic. For each risk area, the framework specifies tailored indicators, and the relevant hazards may include misuse such as AI-enabled cyber- or bio-attacks, cascading systemic failures, or model autonomy issues (Gandhi et al., 26 Sep 2025). A plausible implication is that SCAF is intended less as a universal checklist than as a template for domain-specific operationalization.

The use of proxy indicators also connects SCAF to earlier national-capacity measurement traditions. A science and technology capacity index grouped eight indicators into “Preconditions,” “Resources,” and “Output,” while stressing that capacity is theoretically unobservable but inferable through valid proxies (Wagner et al., 2015). National absorptive-capacity work similarly constructed 13 composite factors from 47 variables to measure six national capacities, including technological, financial, human, infrastructural, public policy, and social capacity (Khan, 2021). SCAF inherits this proxy-based logic but redirects it toward AI-related vulnerability and preparedness.

4. Assessment methodology and scoring logic

SCAF does not mandate a single universal scoring formula. The paper explicitly states that no specific, canonically accepted scoring or weightings are mandated, reflecting the qualitative and empirical character of the framework and the need for further research and stakeholder input for robust aggregation (Gandhi et al., 26 Sep 2025).

The assessment process is nevertheless specified in four steps. First, risks are selected or scoped. Second, the relevant indicators for vulnerability, coping capacity, and adaptive capacity are selected or defined. Third, data are collected for the country or society under assessment. Fourth, scores are aggregated and compared against baselines, cross-country data, or qualitative standards (Gandhi et al., 26 Sep 2025).

As a possible operationalization rather than a mandated formula, the paper describes aggregate scores for each risk rr as weighted sums over normalized indicators:

Vr=iIVrwViXiV_r = \sum_{i \in I_{Vr}} w_{Vi} \cdot X_i

Cr=jICrwCjXjC_r = \sum_{j \in I_{Cr}} w_{Cj} \cdot X_j

Ar=kIArwAkXkA_r = \sum_{k \in I_{Ar}} w_{Ak} \cdot X_k

where IVrI_{Vr}, ICrI_{Cr}, and IArI_{Ar} are the index sets for indicators associated with vulnerability, coping capacity, and adaptive capacity, ww denotes optional weights, and XX denotes normalized indicator values (Gandhi et al., 26 Sep 2025). Final outputs could then be presented as a profile such as a radar or spider chart, as a qualitative label such as “moderately resilient,” or as an optional composite score (Gandhi et al., 26 Sep 2025).

The absence of a mandated aggregation rule is a substantive feature rather than a deficiency. It distinguishes SCAF from frameworks that hard-code a single national index. The Index of Future Readiness, for example, specifies equal weighting at all aggregation levels and defines a composite score as

NFRI=GR+BR+CR+GA+BA+CA\text{NFRI} = GR + BR + CR + GA + BA + CA

with actor-specific and theme-specific sub-indices derived from a Vr=iIVrwViXiV_r = \sum_{i \in I_{Vr}} w_{Vi} \cdot X_i0 matrix over Government, Business, and Citizens and over Resilience and Adaptive Capacity (Jawad et al., 31 Aug 2025). By contrast, SCAF remains more modular and risk-contingent.

A common misconception is that SCAF is a fixed numerical index comparable to a conventional league table. The paper instead characterizes it as an indicators-based approach whose aggregation, benchmarking, and interpretation remain dependent on the risk domain, data availability, and evolving evidence base (Gandhi et al., 26 Sep 2025).

5. Prototype implementation and the Australia case

The prototype implementation discussed in the paper applies SCAF to Australia for two advanced AI risk vectors: cyber-attacks and chemical/biological attacks enabled by AI (Gandhi et al., 26 Sep 2025). The case is used to illustrate both the feasibility of country-level assessment and the practical difficulties of implementation.

For vulnerability, the case includes healthcare system capacity with a Global Health Security Index score of 72.2% and a rank of 5th worldwide, hospital beds at 2.5 per 1,000 people compared with an OECD average of 4.6, cyberattack incidence affecting 30.5% of large businesses compared with an OECD average of 19.5%, and internet penetration at 97.1% (Gandhi et al., 26 Sep 2025). For coping capacity, the case notes crisis plans and real-time surveillance, the existence of a cyber CERT in the form of the Australian Cyber Security Centre and a national 24/7 response hub, and concerns about the sufficiency of countermeasure stockpiles (Gandhi et al., 26 Sep 2025). For adaptive capacity, the case identifies policy frameworks such as Australia’s National Biosecurity Strategy and Voluntary AI Safety Standard, deficiencies in DNA synthesis screening for dual-use risks, secure-by-design initiatives, talent development programs, and mixed adherence to best cybersecurity practices, with businesses at 70% and government at 15% meeting core requirements (Gandhi et al., 26 Sep 2025).

The interpretation offered by the framework is diagnostic rather than merely descriptive. The Australia prototype highlights strengths in institutional capacity, incident response, AI literacy, and formal preparedness frameworks, while also identifying weaknesses in health emergency stockpiles, supply-chain vulnerabilities, uneven sectoral cybersecurity preparedness, and gaps in procurement vigilance (Gandhi et al., 26 Sep 2025). Policy implications are correspondingly targeted: weak areas identified by the assessment become candidates for preparedness investment and governance reform (Gandhi et al., 26 Sep 2025).

The paper also generalizes the case-study workflow into a broader country-assessment template: select risks of concern, gather appropriate indicators, process the data into vulnerability, coping-capacity, and adaptive-capacity scores, benchmark results where possible, and use the findings to advise on AI deployment, regulation, and preparedness (Gandhi et al., 26 Sep 2025). This procedural structure resembles other capacity-assessment traditions that begin with baseline measurement, proceed through intervention or diagnosis, and then use repeated assessment to inform policy. A cybercrime investigation capacity framework, for instance, combines baseline surveys, post-training assessment, and longitudinal follow-up with a numeric capacity formula tied to case throughput, staffing, and downtime (James et al., 2013). This suggests methodological continuity between SCAF and earlier mixed-method capacity assessments.

6. Relation to adjacent frameworks, significance, and limitations

SCAF occupies a specific position among broader societal-capacity frameworks. It is more deployment-contextual than technical AI evaluation, more risk-specific than generic resilience indices, and more operationalized than purely formative reflection frameworks (Gandhi et al., 26 Sep 2025).

Several neighboring frameworks clarify this position. The Index of Future Readiness presents a whole-of-society perspective using Jawad’s GBC model and a six-element matrix over Government, Business, and Citizens crossed with Resilience and Adaptive Capacity; its own paper explicitly states that the framework satisfies the requirements of a SCAF because it embeds multidimensional societal preparedness and supports actor-specific and theme-specific diagnosis (Jawad et al., 31 Aug 2025). Work on societal adaptation to advanced AI organizes intervention points along the causal chain from development to diffusion, use, harm, and impact, and proposes a three-step cycle of identifying risks, identifying adaptive responses, and implementing responses while measuring effectiveness (Bernardi et al., 2024). In a different direction, the Responsible and Inclusive Technology Framework is described as formative and process-oriented rather than indicator-based, emphasizing stakeholder mapping, power dynamics, and socio-historical context (Sandoval et al., 2023). Together, these comparisons show that SCAF belongs to a wider ecosystem of frameworks concerned with preparedness, adaptation, and social context, but retains a distinctive emphasis on measurable country-level deployment conditions.

Its practical significance lies in its stated uses. For AI developers, SCAF can inform thresholds for deployment and safeguard calibration. For policymakers and regulators, it can support preparedness assessment, identification of neglected areas, and coordination of cross-sectoral action. More generally, it is presented as supporting ex ante evaluation when empirical evidence of AI-driven shocks is limited (Gandhi et al., 26 Sep 2025).

Its limitations are also explicit. The prototype reveals data gaps, the absence of clear benchmarks, and the difficulty of cross-country comparability (Gandhi et al., 26 Sep 2025). The paper further notes that effectiveness depends on improved data collection, indicator development, and the gradual accumulation of empirical evidence linking AI, societal vulnerabilities, and harm (Gandhi et al., 26 Sep 2025). The legitimacy of the framework is said to depend on inclusion, transparency, and responsiveness to societal values and context (Gandhi et al., 26 Sep 2025).

A further interpretive point follows from comparison with earlier national-capacity measures. Science and technology capacity indices have emphasized that proxy-based capacity scores are comparative rather than absolute, sample-sensitive, and best used for benchmarking rather than for overinterpreted claims about development as such (Wagner et al., 2015). A plausible implication is that SCAF will face analogous issues whenever it is used for cross-country comparison: indicator choice, benchmark construction, and aggregation design will materially shape the resulting picture of societal preparedness.

In this sense, SCAF is best understood as a framework for structured, risk-specific, context-sensitive assessment of societal readiness for advanced AI deployment. Its central contribution is not a single canonical metric, but a formalization of the claim that vulnerability, short-term response capacity, and medium- to long-term adaptation capacity are integral components of AI risk management at the societal level (Gandhi et al., 26 Sep 2025).

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Societal Capacity Assessment Framework (SCAF).