Before staff enter information into a tool, establish what data it receives, whether personal information is necessary, who has access, and what retention and vendor terms apply. Bring security, privacy, legal, and procurement teams into the review under applicable requirements.
Name the people responsible for approving outputs, recording errors, handling complaints, and escalating consequential cases. Staff instructions should distinguish permitted assistance from uses that are prohibited or require a person to decide. Training should address inaccurate outputs, secure handling, and automation bias—the tendency to accept a tool’s answer too readily.
The NIST AI Risk Management Framework and the U.S. Government Accountability Office AI Accountability Framework can help structure questions about risk and accountability throughout a system’s life cycle. Revisit fairness, transparency, security, and performance after launch, not only before it.
Leave a comment