S0012RS1-T03-S0012-Z · Full risk code

No Planned AI Disclosure Mechanism

未規劃 AI 使用揭露機制

Inception
Risk Description

When a customer service system interacts with customers in a human-like manner without disclosing that it is AI; due to unmitigated control gaps, believing they are communicating with a person, customers share highly sensitive information, triggering external stakeholder impacts and causing once the practice comes to light, the organization faces both potential transparency violations and substantial loss of consumer trust.

Framework Mappings

EU AI ActArt.50
ISO/IEC 42001Annex A.8.2
NIST AI RMFGOVERN 1.1
ISO/IEC 5338啟動
MIT AI Risk RepositoryDomain 5

Risk Treatment & Implementation Guidance

Design AI-identity disclosure into the system so users are clearly informed at the start of the interaction that they are conversing with an AI; Add reminders in interactions involving sensitive information and offer escalation to a human agent; Include disclosure in pre-launch checks so no anthropomorphized interface goes live without passing it