A housing authority is establishing a data-sharing framework with health and social-service agencies feeding a shared AI risk model intended to identify residents at risk of housing instability. What should the authority require before the agencies begin pooling their data into the shared model?
Select an answer to reveal the explanation.
Short Explanation
Think about roommates who move in together without ever agreeing on whose name is on the lease or who's responsible for what: it works fine until something goes wrong, and then nobody agrees on the rules. Multiple agencies pooling sensitive resident data into one shared model need that agreement settled in writing, ownership, allowed uses, and limits, before the data ever gets combined, not after.
Full Explanation
A formal data-sharing agreement that defines data ownership, permitted uses, and limits across the participating agencies establishes clear accountability before sensitive information from housing, health, and social-service records gets combined into a single shared risk model, which matters because pooled data spanning multiple sensitive domains creates significant privacy exposure if usage boundaries aren't settled in advance. A verbal understanding among directors provides no enforceable accountability if an agency later uses the pooled data beyond what was informally discussed, and offers no documented record for oversight bodies or residents questioning how their information is being used. Letting only the largest data contributor approve the framework ignores that data ownership and governance concerns apply to every participating agency's residents, not just the agency contributing the most volume, and sidelines smaller contributors from a decision that affects their populations too. Beginning data pooling immediately and negotiating governance terms afterward reverses the necessary sequence, since once data has already been combined and used to train or run a shared model, retroactively imposing usage limits can't undo whatever happened during the ungoverned period. A scope caveat: the agreement should be revisited periodically as new agencies join or the model's scope expands, since governance terms negotiated for the original participants may not anticipate later additions. A concrete check: confirm a signed data-sharing agreement specifying ownership and use limits exists and is referenced in the model's documentation before any cross-agency data pooling begins.