An enterprise has deployed multiple AI systems and is building an AI governance framework aligned with Microsoft's Responsible AI principles. The security team needs to define the process for reporting AI safety incidents—cases where an AI system produces harmful or unexpected outputs that affect users. Which element of the governance framework should specify the incident classification, escalation path, and post-incident review process for AI safety incidents?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because AI systems introduce unique incident types that standard IT security incident response plans are not designed to address—such as safety failures (model producing harmful content), fairness incidents (biased outputs affecting a group), model failures (degraded accuracy in production), and security breaches (model extraction or data poisoning). A dedicated AI Incident Response Plan that defines AI-specific incident categories, severity levels, escalation paths (including the AI governance committee and Responsible AI team), and mandatory post-incident review processes ensures that AI incidents are handled with appropriate expertise and governance.
Full explanation below image
Full Explanation
B is correct because AI systems introduce unique incident types that standard IT security incident response plans are not designed to address—such as safety failures (model producing harmful content), fairness incidents (biased outputs affecting a group), model failures (degraded accuracy in production), and security breaches (model extraction or data poisoning). A dedicated AI Incident Response Plan that defines AI-specific incident categories, severity levels, escalation paths (including the AI governance committee and Responsible AI team), and mandatory post-incident review processes ensures that AI incidents are handled with appropriate expertise and governance. A is wrong because the existing IT security IR plan lacks the AI-specific incident categories, severity criteria, and Responsible AI review components needed; supplementing it with AI-specific content (option B) is the correct approach. C is wrong because the model deployment approval checklist is a pre-deployment governance artifact, not an incident response procedure. D is wrong because Azure Monitor alert rules and notifications are technical monitoring tools that detect incidents; they are not the governance process or framework for classifying and responding to them.