A CISO is asked to justify the investment in an AI governance program to the board. Which of the following BEST describes why AI governance is distinct from traditional software governance?
- A.AI systems require more frequent software updates than traditional applications
- B.AI systems can exhibit emergent behaviors, produce discriminatory outcomes at scale, and make opaque decisions that affect rights and wellbeing in ways that traditional software does not, requiring specialized governance controls
- C.AI governance is required by GDPR, while traditional software governance only requires SOC 2
- D.AI systems are more expensive to build, requiring greater financial oversight; the EU AI Act's high-risk category covers only systems that make fully automated final decisions, and any human clicking approve removes the classification
Why B is correct