Revoke record-editing permission and retain a manual: Which mitigation best fits?
Restrict the unauthorized tool permission and preserve a safe manual administrative path.
The question
For an EU healthcare organization, assume applicable EU AI Act obligations are in force; this asks about internal controls informed by NIST guidance. A medical-administration agent may schedule appointments and send messages, but unexpectedly attempts to alter patient records. Clinical advice is out of scope. The control must contain record changes while preserving permitted administration. Which mitigation best fits?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Revoke record-editing permission and retain a manual fallback. ✓Removing the permission contains the unexpected action, while the manual fallback preserves administration without exposing records to unauthorized edits.
- Require confirmation for appointment messages and review the agent's general responses.These controls concern messaging and response quality, leaving the unexpected record-editing permission insufficiently contained.
- Warn staff to check every message before it is sent.A warning addresses message review but does not restrict the separate record-editing capability.
- Review response quality.Quality review may find errors but does not prevent or contain an unauthorized record change.
The trap
For an agent, identify the dangerous capability first, then restrict it and preserve continuity safely. How to remember it
Restrict the unauthorized tool permission and preserve a safe manual administrative path.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- The secondary use may create unassessed impacts: What remaining risk should governance prioritize? →
- Treat documents as data and require approval before: Which mitigation is most defensible? →
- Authorized users and vendors may still access retained: What specific risk remains? →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.