An organization shares an AI model with external partners. One partner reports that sensitive data has been inadvertently exposed through the model's outputs. Which of the following is the IS auditor's BEST recommendation?
Select an option, then click Submit answer.
Reference / correct answer:
Disable the shared model and notify partners of the potential breach.
Most accepted answer: B. Disable the shared model and notify partners of the potential breach.
Community votes: B=3, C=1
Selected Answer: B In frameworks like ISACA’s AAIA, NIST AI RMF, or ISO 42001, when a data leakage incident occurs in shared AI systems, auditors emphasize: Contain the breach. Notify stakeholders. Investigate & remediate (including technical fixes like privacy techniques). Review governance/controls (data lineage, output guardrails, etc.). upvoted 1 times
Selected Answer: B When sensitive data is actively leaking through an AI model's outputs (often via "training data extraction" or "membership inference" attacks), the auditor's first priority is to stop the bleeding. The first action must be to stop the exposure Disabling the model: Prevents further leakage Protects all partners and stakeholders Notifying partners ensures: Transparency Regulatory compliance (e.g., breach notification requirements) upvoted 1 times
Selected Answer: C While option B is highly appropriate from an incident response standpoint, it does not reflect an auditor’s perspective. upvoted 1 times
Selected Answer: B Containtment first upvoted 2 times