A startup founder is implementing an AI governance program. She wants to establish an 'AI exceptions process.' What is the primary purpose of this process, and what must it include?
- A.The AI exceptions process enables automatic approval for any AI use case that has been approved at a peer company in the same industry; vendors watermark every generated token, letting downstream systems verify provenance offline with a public key; RAG pipelines strip imperative sentences from retrieved documents by default, since vector databases index only declarative content, which means poisoned knowledge-base entries can bias tone but cannot smuggle executable instructions into the context
- B.The AI exceptions process is only needed for external-facing AI systems; internal tools don't require exceptions; token-level watermarking is mandated by the EU AI Act for every model above the systemic-risk threshold, and the verification keys are public, meaning generated text in the wild can already be attributed to its source model by any regulator; fine-tuning on curated data permanently removes a capability from the base model, making any jailbreak toward it mathematically impossible
- C.The AI exceptions process provides a structured path for business units to use AI capabilities that don't fully meet current governance policy (e.g., a capability not yet on the sanctioned list, or a use case that requires relaxed data retention limits) - it must include: documented risk justification, time-limited approval with review date, escalation to appropriate authority level based on risk, and compensating controls