Define AI artifact: Which addition most directly closes the AI-specific policy gap?
The policy should explicitly cover AI artifacts, provenance, version control, and supplier security responsibilities.
The question
A research institution’s legacy security policy covers access control, encryption, and incident handling for conventional software. Its AI research systems also depend on training data provenance, model versions, and supplier components. Owners, risk treatment, monitoring, and general data review are otherwise established. Which addition most directly closes the AI-specific policy gap?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Require independent penetration testing for every research model.Testing may identify selected vulnerabilities, but it does not establish broad policy requirements for provenance, versions, and suppliers.
- Add a separate annual security awareness course.Awareness may support culture, yet it does not establish controls for AI artifacts, lineage, versions, and supplier dependencies.
- Expand password rotation requirements for researchers.Password controls strengthen access security, but they do not address provenance, model-version dependencies, or supplier-specific AI risks.
- Define AI artifact, provenance, version, and supplier security requirements. ✓This directly extends legacy policy to the AI-specific assets and dependencies identified as missing from current security coverage.
The trap
Map the remedy to every stated gap: artifact, provenance, version, and supplier controls. How to remember it
The policy should explicitly cover AI artifacts, provenance, version control, and supplier security responsibilities.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- Require supplier change notification: What single contractual control is most direct? →
- Define event-based policy review triggers: What is the most direct missing control? →
- The inventory is incomplete: What does this evidence most directly support? →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.