A hospital is performing an AI impact assessment for a proposed diagnostic-imaging tool. To ensure compliance with regulatory and ethical standards, which risk needs the MOST domain-specific assessment beyond that normally included in a standard IT risk assessment?
A System downtime may increase due to hardware failure in the hosting environment, preventing medical professionals from accessing the tool. B Software vulnerabilities in the application's web server may allow an attacker to gain unauthorized access to the system. C The model may produce systematically biased diagnoses for specific demographics, potentially leading to widespread clinical harm. D Noncompliance with data residency laws may occur if patient data is processed in a cloud region outside the required jurisdiction. Show Answer Answer Explanation Systematic bias in diagnostic outputs can cause different demographic groups to receive less accurate diagnoses and can create widespread clinical harm. Assessing this risk requires AI- and healthcare-specific validation of model performance and fairness across relevant patient populations, rather than only conventional infrastructure, security, or data-location controls. NIST’s AI Risk Management Framework identifies fairness with harmful biases managed as a core trustworthy-AI characteristic and calls for fairness and bias evaluation to be documented.
Learn more
Community Discussion