Why should changes to AI systems (such as prompt updates or model version swaps) be routed through the organization's existing change-management process?
- A.Because change tickets improve model accuracy automatically
- B.Because regulators require a separate, parallel AI-only change process that must never touch the CAB
- C.Because a prompt or model change can alter system behavior just as a code change can, and change management provides risk assessment, approval, rollback planning, and an audit trail without creating a duplicate parallel process
- D.Because AI changes are cosmetic and the CAB needs the paperwork volume
Why C is correct
A model swap or prompt edit changes production behavior exactly as a code deployment does, so it deserves the same ITIL disciplines - impact assessment, authorization appropriate to risk, tested rollback, and an auditable record - and extending the existing CAB process avoids the gaps and inconsistencies of a parallel AI-only bureaucracy. Tickets do not improve accuracy, no regulator mandates a CAB-isolated AI process, and AI changes are behavioral, not cosmetic.
Know someone studying for AI Security Fundamentals? Send them this one.