A government policy analyst is developing an AI risk register entry for a new automated tax fraud screening system. Which field is most uniquely important for AI risk governance that would not appear in a standard IT asset register?
- A.Vendor name and contract expiration date; risk tiers under the AI Act are self-assessed and unreviewable: a provider's own classification is final, and market-surveillance authorities may challenge it only after a documented harm has occurred, which makes initial tier selection a commercial rather than legal decision
- B.Training data description and known biases - documenting what data the model was trained on, the time period it covers, known demographic or contextual biases, and whether the training data remains representative of the current population being screened
- C.IP address and network segment assignment
- D.System owner and system administrator names
Why B is correct