Assess whether the hiring tool should be paused pending audit (bea6d0)
August 31, 2026
SITUATION Model-risk officer in a university licensing an AI proctoring vendor has one working extract — shadow-IT chatbot connected to customer PII — after a DPA inquiry about training on European user data. Model-risk officer in a university licensing an AI proctoring vendor has shadow-IT chatbot connected to customer PII after a DPA inquiry about training on European user data. If that extract cannot support the hiring tool should, the only defensible AI Governance Policy and Oversight output is hold.
DECISION Model-risk officer in a university licensing an AI proctoring vendor must choose Policy or governance breach / Model defect / Dual failure / Hold for the missing fact using shadow-IT chatbot connected to customer PII after a DPA inquiry about training on European user data.
HYPOTHESES TO TEST 1. A DPA inquiry about training on European user data is noise around an already-controlled Policy and Oversight process in a university licensing an AI proctoring vendor, given shadow-IT chatbot connected to customer PII. 2. A DPA inquiry about training on European user data is the event in shadow-IT chatbot connected to customer PII that forces Policy or governance breach for model-risk officer under AI Governance. 3. Shadow-IT chatbot connected to customer PII shows a one-file miss after a DPA inquiry about training on European user data, not a Policy and Oversight program failure. 4. Shadow-IT chatbot connected to customer PII cannot decide the hiring tool should yet after a DPA inquiry about training on European user data; hold is the only AI Governance close a university licensing an AI proctoring vendor can defend.
ANALYSIS REQUIRED 1. Check intended purpose and inventory status against EU AI Act / exam-readiness language after a DPA inquiry about training on European user data. 2. Map the approved-use case to the system the hiring tool should would bind. 3. Check intended purpose and inventory status against EU AI Act / exam-readiness language after a DPA inquiry about training on European user data. 4. For this AI Governance Policy and Oversight file, read shadow-IT chatbot connected to customer PII against a DPA inquiry about training on European user data and write the one fact that would move the hiring tool should for model-risk officer.
RECOMMENDATION Choose Policy or governance breach / Model defect / Dual failure / Hold for the missing fact on this AI Governance / Policy and Oversight packet (shadow-IT chatbot connected to customer PII after a DPA inquiry about training on European user data). The follow-on Policy and Oversight action is what model-risk officer does next: implement the option, assign an owner, and log the missing fact.
Explore more
More AI Governance prompts
- Assess whether the system is high-risk under the EU AI Act (e2db71)
- Assess whether the inventory can be represented to an examiner as complete
- Assess whether human review is real or a rubber stamp (cf5d07)
- Assess whether human review is real or a rubber stamp (60fcf3)
- Assess whether deprecation of a legacy scorecard creates a governance gap
Explore related decision areas
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

