A public library system completes an AI readiness self-assessment. Its cloud infrastructure is modern, scalable, and already supports several digital services, but the library has no formal process for classifying proposed AI use cases by risk level before they move forward, such as distinguishing a low-risk catalog recommendation tool from a higher-risk patron-facing chatbot handling personal data. What kind of gap does this represent?
Select an answer to reveal the explanation.
Short Explanation
Cloud-ready doesn't mean decision-ready, and that's the trap here: the library's servers are fine, but nobody has written down how to sort a harmless recommendation tool from a chatbot that touches patron data. That's a process problem, not a plumbing problem, so buying more infrastructure won't fix it. Think of it like having a great kitchen but no recipe for deciding which dishes need a food-safety check first.
Full Explanation
A readiness assessment separates infrastructure capability from governance maturity because a strong technology base does not automatically produce sound decision-making processes. Here, the scenario explicitly states the cloud environment is modern and scalable, ruling out infrastructure as the limiting factor. The missing piece is a formal risk-classification process: a repeatable method for sorting proposed AI use cases into tiers based on data sensitivity, patron impact, and potential harm, so that higher-risk initiatives like a chatbot handling personal information receive more scrutiny than a low-risk recommendation feature. Framing this as a technology gap misdiagnoses the problem, since rebuilding infrastructure does nothing to create a classification rubric. Framing it as a workforce-skills gap conflates data science expertise with governance design; risk tiering is a policy exercise, not a modeling task. Framing it as a budget gap assumes classification requires new spending, when many organizations build a simple tiering rubric using existing staff and a lightweight review checklist. A scope caveat: a mature classification process still needs periodic review as new use cases emerge. An operational check: ask whether any two currently proposed AI projects have ever been assigned different risk tiers.