Unassigned AI accountability and escalation: Which gap is most decisive?
Legacy security controls do not assign AI output validation or escalation responsibility amid supplier information limits.
The question
A public benefits agency’s legacy security policy requires access controls and breach reporting for databases. It is adopting a vendor chatbot that retrieves applicant records and generates eligibility explanations. The vendor will not disclose detailed model updates, while the agency has not defined who validates explanations or escalates harmful outputs. Which gap is most decisive?
Preparing for AIGP? Take the free 5-min readiness quiz →
- The absence of stronger database passwordsAccess controls matter, but stronger passwords do not resolve unassigned responsibility for generated explanations and supplier information gaps.
- Unassigned AI accountability and escalation ✓Existing database security does not assign responsibility for AI output validation, supplier changes, or harmful-output escalation in this new use.
- A requirement to archive every applicant conversationArchiving may support investigation, but records alone cannot establish validation ownership or escalation authority for harmful explanations.
- The vendor’s lack of a public benchmarkBenchmark evidence could inform evaluation, but the immediate decisive gap is who validates outputs and manages incidents.
The trap
For AI deployments, separate information security controls from accountability for outputs, supplier changes, and harmful incidents. How to remember it
Legacy security controls do not assign AI output validation or escalation responsibility amid supplier information limits.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- Require material-change notice: Before the supplier replaces the underlying model and adds an external data →
- Adding overnight routes: Which event satisfies that review trigger? →
- Inability to determine necessary safeguards: What specific residual risk remains after this internal →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.