Assess whether the system is high-risk under the EU AI Act (615d59)
August 31, 2026
SITUATION Policy and Oversight work in a university licensing an AI proctoring vendor now turns on the system is high-risk because a vendor SOC report that excludes the actual model host region put shadow-IT chatbot connected to customer PII in play. Model-risk officer should say what shadow-IT chatbot connected to customer PII proves.
DECISION Model-risk officer in a university licensing an AI proctoring vendor must choose Policy or governance breach / Model defect / Dual failure / Hold for the missing fact using shadow-IT chatbot connected to customer PII after a vendor SOC report that excludes the actual model host region.
HYPOTHESES TO TEST 1. Model-risk officer can defend Policy or governance breach from shadow-IT chatbot connected to customer PII after a vendor SOC report that excludes the actual model host region in a AI Governance challenge. 2. Model-risk officer cannot defend Policy or governance breach from shadow-IT chatbot connected to customer PII; Model defect is what the extract actually supports after a vendor SOC report that excludes the actual model host region. 3. A vendor SOC report that excludes the actual model host region never reached the population in shadow-IT chatbot connected to customer PII — reopen intake, do not close the system is high-risk. 4. Two facts in shadow-IT chatbot connected to customer PII after a vendor SOC report that excludes the actual model host region conflict for model-risk officer; hold this Policy and Oversight file.
ANALYSIS REQUIRED 1. Reproduce the incident row in shadow-IT chatbot connected to customer PII and say whether it ever touched production data. 2. Split policy-or-governance failure from a model defect using prompts, outputs, and human edits in shadow-IT chatbot connected to customer PII. 3. Reproduce the incident row in shadow-IT chatbot connected to customer PII and say whether it ever touched production data. 4. For this AI Governance Policy and Oversight file, read shadow-IT chatbot connected to customer PII against a vendor SOC report that excludes the actual model host region and write the one fact that would move the system is high-risk for model-risk officer.
RECOMMENDATION Choose Policy or governance breach / Model defect / Dual failure / Hold for the missing fact on this AI Governance / Policy and Oversight packet (shadow-IT chatbot connected to customer PII after a vendor SOC report that excludes the actual model host region). Lead with the AI Governance option shadow-IT chatbot connected to customer PII can support after a vendor SOC report that excludes the actual model host region, then the two facts that force it, then the Monday action for model-risk officer in a university licensing an AI proctoring vendor.
Explore more
More AI Governance prompts
- Assess whether a shadow system must be decommissioned this quarter (b976cc)
- Assess whether explainability artifacts would survive an exam (f1ded5)
- Assess whether the board has been accurately briefed (70ec93)
- Assess whether human review is real or a rubber stamp (2c0ff9)
- Assess whether the inventory can be represented to an examiner as complete
Explore related decision areas
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

