Memory hook: Assign accountability before delegating a consequential decision.
Must remember
Responsible AI considers fairness, explainability, privacy, security, robustness, transparency and human oversight. The required safeguards depend on impact and context; an internal drafting assistant and an automated eligibility decision do not have identical risk profiles. Define prohibited uses and escalation criteria.
Governance assigns business ownership, technical responsibility, risk acceptance and independent review. Maintain an inventory of AI systems, intended uses, data/model dependencies, evaluation evidence and approvals. Embed review into procurement and delivery rather than creating a committee that only sees finished systems.
Assess data rights, consent, retention, residency and intellectual-property concerns with the responsible specialists. Supplier contracts should address security, data use, incident support, change notification and exit. A vendor assurance statement does not replace the organization’s own deployment assessment.
Common risks include hallucination, biased outcomes, privacy leakage, prompt injection, overreliance, unsafe tool actions and model/data drift. Mitigations include scoped access, authorized retrieval, output validation, human review, monitoring and restricted actions. Filters reduce some risks but cannot guarantee correctness. Provide an appeal/override path for consequential outcomes and a way to stop unsafe operation.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| High-impact automated decision | Risk-based approval, meaningful oversight and appeal mechanisms. |
| Agent can change business records | Authorize each action and constrain tool scope. |
| New model/provider version | Re-evaluate quality, risk and contractual implications. |
Traps
- Compliance is not proof of fairness or safety in every use case.
- A human nominally present is not meaningful oversight if they cannot understand or intervene.
Active recall
1. Why inventory AI systems?
To identify ownership, dependencies, risk and review obligations.
2. What is meaningful human oversight?
A capable authorized person can understand, challenge and stop or correct the outcome.
3. Why constrain agent tools?
Malicious or mistaken instructions can otherwise cause real external effects.
4. Why retain evaluation evidence?
To justify decisions and investigate changes or failures.
5. Who accepts residual risk?
The authorized accountable business/governance owner.