An AI system for automated email phishing detection incorrectly classifies legitimate vendor invoices as phishing attempts at a rate of 12%, causing operational disruptions. The security team defends the high false positive rate as necessary to maintain the system's 99.2% detection rate for actual phishing. How should the AI risk manager evaluate this trade-off?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the trade-off between false positives (operational disruption) and false negatives (missed phishing) must be explicitly evaluated in terms of their actual risk costs. A 12% false positive rate on vendor invoices may create significant payment delays, vendor disputes, and employee burden that could exceed the phishing risk benefit.
Full explanation below image
Full Explanation
B is correct because the trade-off between false positives (operational disruption) and false negatives (missed phishing) must be explicitly evaluated in terms of their actual risk costs. A 12% false positive rate on vendor invoices may create significant payment delays, vendor disputes, and employee burden that could exceed the phishing risk benefit. Risk managers must quantify both sides and evaluate whether model tuning or a tiered review can achieve a more favorable operating point. Accepting the status quo without analysis (A) is insufficient. Zero false positives (C) would require setting detection so conservatively that actual phishing would not be caught. Human-only review (D) is disproportionate and introduces its own accuracy and scalability issues.