S0103RS1-T03-S0103-Z · Full risk code

Opaque Source Attribution

來源標示不透明

Operation & Monitoring
Risk Description

When a user produces a formal document based on system answers without verifying each item; due to unmitigated control gaps, some content is later found to have no actual source, and the system's presentation made inference indistinguishable from established fact, triggering compliance exposure and operational reputational costs.

Framework Mappings

EU AI ActArt.50
ISO/IEC 42001Annex A.8.2
NIST AI RMFMEASURE 2.9
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 3

Risk Treatment & Implementation Guidance

Attribute each answer segment to its actual source in retrieval-augmented applications, distinguishing sourced content from model inference; Provide citation traceability so users can inspect the original source; Clearly advise in the interface that generated content requires verification, recommending item-by-item source checks for important uses