A company's AI governance policy requires all AI systems to have documented 'intended use' and 'out-of-scope use' statements. A developer argues this is bureaucratic overhead since 'the AI will do what users tell it to do anyway.' What is the strongest governance argument against this view?
- A.Documented intended use and out-of-scope use establish the governance boundary for monitoring, testing, and liability: systems used outside their validated scope may fail in unexpected ways, and without documented scope, the organization cannot demonstrate governance due diligence to regulators or courts when AI-related harms occur
- B.Documentation is required by ISO standards and therefore cannot be eliminated regardless of perceived value
- C.The developer is correct for low-risk AI tools; documentation requirements should only apply to high-risk systems