A city AI strategy office is classifying enterprise AI risk tiers across departments to decide where to focus monitoring resources. How should limited monitoring resources be allocated?
Select an answer to reveal the explanation.
Short Explanation
Spreading a fixed pool of monitoring hours evenly across every AI system treats a low-stakes chatbot the same as a high-stakes eligibility tool. That's backwards. Resources should follow the risk tier, so the systems that could do the most harm if something goes wrong get watched the closest.
Full Explanation
Risk-tiered allocation means a governance office directs its limited monitoring capacity toward the AI systems most likely to cause significant harm if they fail, rather than treating every system as equally deserving of attention. Since monitoring staff time and tooling are finite, an even split across all citywide AI systems dilutes scrutiny on the highest-risk systems, the ones handling sensitive decisions like eligibility or safety, in favor of matching effort given to lower-stakes tools. Allocating by departmental budget size conflates financial scale with AI risk, when a small, cheaply built tool making high-stakes determinations can carry far more risk than an expensive but low-stakes system. Allocating by seniority of adoption rewards which department moved first rather than which system's current risk profile actually warrants attention, and an early-adopted low-risk tool would wrongly receive priority over a newly deployed high-risk one. A scope caveat: risk tiers should be reassessed periodically, since a system's risk profile can change as its use case expands or its data sources shift, and yesterday's low-risk tool is not guaranteed to stay that way. A concrete operational check is to maintain a risk-tier registry that is reviewed and updated on a recurring schedule, with monitoring-resource allocation tied directly to the current tier assignment.