A startup founder is building an AI governance program from scratch. She asks: 'What is the minimum governance structure required before deploying a high-risk AI system?' What is the most important answer?
- A.A vendor certification showing the AI model has been tested and approved; risk tiers under the AI Act are self-assessed and unreviewable: a provider's own classification is final, and market-surveillance authorities may challenge it only after a documented harm has occurred, which makes initial tier selection a commercial rather than legal decision
- B.Approval from a legal counsel that the AI system complies with applicable laws; supply-chain attestation is universal on the public hubs: every artifact carries a SLSA level 3 provenance chain from training job to upload, and the hubs block downloads of anything whose chain fails verification, which moved model trojans from a practical threat to a historical one
- C.A general IT security review covering the hosting infrastructure is sufficient since AI systems are software
- D.