Assess whether a generative-AI incident is a policy breach or a model defect
August 31, 2026 · SmartSolo
Situation
Inventory and Regulatory Fit work in a hospital deploying a sepsis-risk model now turns on a generative-AI incident is because a new use case bolted onto a model approved for a narrower purpose put training-data provenance questionnaire in play. Privacy counsel supporting AI inventory should say what training-data provenance questionnaire proves.
Decision
Privacy counsel supporting AI inventory in a hospital deploying a sepsis-risk model must choose A generative-AI incident is a policy breach / A model defect using training-data provenance questionnaire after a new use case bolted onto a model approved for a narrower purpose.
Hypotheses to test
- Authorize A generative-AI incident is a policy breach now; training-data provenance questionnaire already has the discriminator after a new use case bolted onto a model approved for a narrower purpose.
- Keep A model defect in force until training-data provenance questionnaire is completed after a new use case bolted onto a model approved for a narrower purpose for privacy counsel supporting AI inventory.
- Treat training-data provenance questionnaire as A generative-AI incident is a policy breach because both readings appear after a new use case bolted onto a model approved for a narrower purpose.
- Refuse a AI Governance close: privacy counsel supporting AI inventory does not have the page a generative-AI incident is turns on in training-data provenance questionnaire.
Analysis required
- Split policy-or-governance failure from a model defect using prompts, outputs, and human edits in training-data provenance questionnaire.
- Reproduce the incident row in training-data provenance questionnaire and say whether it ever touched production data.
- Split policy-or-governance failure from a model defect using prompts, outputs, and human edits in training-data provenance questionnaire.
- For this AI Governance Inventory and Regulatory Fit file, read training-data provenance questionnaire against a new use case bolted onto a model approved for a narrower purpose and write the one fact that would move a generative-AI incident is for privacy counsel supporting AI inventory.
Recommendation
Choose A generative-AI incident is a policy breach / A model defect on this AI Governance / Inventory and Regulatory Fit packet (training-data provenance questionnaire after a new use case bolted onto a model approved for a narrower purpose). If training-data provenance questionnaire cannot force a AI Governance label under Inventory and Regulatory Fit, stop. If training-data provenance questionnaire after a new use case bolted onto a model approved for a narrower purpose cannot support A generative-AI incident is a policy breach versus A model defect on this AI Governance Inventory and Regulatory Fit close, privacy counsel supporting AI inventory must leave the classification unresolved and name the missing control or provenance fact.
Explore more
More AI Governance prompts
- Assess whether deprecation of a legacy scorecard creates a governance gap
- Whether the system is high-risk under the EU AI Act from vendor model card
- Assess whether a shadow system must be decommissioned this quarter (fdd697)
- Assess whether the vendor can be used in a regulated process (2d5dff)
- Model-risk officer must resolve whether explainability artifacts would
Explore related decision areas
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

