An AI product team argues that their machine learning model does not need governance oversight because it is a 'recommendation system,' not a decision-making system. How should the AI risk manager respond?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the label 'recommendation system' does not determine governance requirements. What matters is the practical influence of the recommendations on consequential decisions.
Full explanation below image
Full Explanation
B is correct because the label 'recommendation system' does not determine governance requirements. What matters is the practical influence of the recommendations on consequential decisions. A recommendation that is almost always accepted has functionally the same impact as a binding decision, and must be governed accordingly. Many AI risks (bias, drift, error propagation) are present regardless of whether outputs are labeled as recommendations or decisions. A is incorrect; advisory systems can still cause harm and create liability. C ignores the upstream risk in the recommendation model itself. D addresses legal liability cosmetically, not the underlying risk.