A startup founder is building an AI governance program from scratch. She asks: 'What is the minimum governance structure required before deploying a high-risk AI system?' What is the most important answer?
- A.At minimum: documented risk assessment of the AI system, a model card describing capabilities and limitations, a designated AI owner accountable for ongoing performance, a bias evaluation on the intended deployment population, a human oversight mechanism for decisions the AI influences, and a documented incident response plan for AI failures
- B.A general IT security review covering the hosting infrastructure is sufficient since AI systems are software
- C.Approval from a legal counsel that the AI system complies with applicable laws
- D.A vendor certification showing the AI model has been tested and approved
Why A is correct