An AI risk manager discovers that a deployed sentiment analysis model was updated by the vendor to 'improve performance' without notifying the deploying organization. The model's change manifested as a shift in how it classified certain political language. Which AI supply chain risk does this represent?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because unannounced material changes to a third-party AI model violate the governance principle that material model changes must be documented, assessed, and validated before production deployment. The deploying organization has no visibility into what changed, whether the change was validated, or what the implications are for their use case.
Full explanation below image
Full Explanation
B is correct because unannounced material changes to a third-party AI model violate the governance principle that material model changes must be documented, assessed, and validated before production deployment. The deploying organization has no visibility into what changed, whether the change was validated, or what the implications are for their use case. This undermines the entire model governance framework. Model staleness (A) is the opposite concern. Data poisoning (C) requires adversarial intent. Regulatory compliance (D) may be a consequence but is not the primary supply chain risk.