How this works
- When a checkpoint appears on screen, read the question here and decide your answer.
- Everyone answers — the lecture room and the Zoom room use the same link.
- When the presenter gives the reveal word, type it in to unlock the answer and the story behind it.
Diagnose the failure
A fast-growing Saudi e-commerce platform launches a GenAI returns agent that auto-approves refunds up to SAR 2,000 — no human review, no daily cap. Within three weeks, organised fraud rings are exploiting it at scale.
What was the primary governance failure?
- AThe model’s accuracy was too low
- BAutonomy was granted without consequence-based limits or a named owner
- CThe agent lacked Arabic-dialect support
- DThe cloud vendor’s security was weak
Answer locked. Type the reveal word the presenter gives.
Why B. Autonomy was set on speed and scale — instant, unlimited volume — with no link to consequence, which here is cumulative financial loss, and nobody watching the pattern. The model may have worked exactly as designed.
Why not A. Accuracy on an individual refund is not the issue. Adversaries exploit the policy, not the error rate.
Why not C. Language support changes the experience, not the exploit.
Why not D. Nothing was breached. The system was used exactly as built — which is the insight: most AI governance failures are not security breaches.
The fix. Value thresholds, velocity caps per account, anomaly monitoring, human review above a set amount, and one named owner in customer operations with risk as second line.
Salam Bank’s ten-minute SME loan
Salam Bank, a mid-size Saudi bank, wants generative AI plus credit models to pre-approve SME working-capital loans up to SAR 500,000 in ten minutes instead of three weeks. It is a growth lever under Vision 2030’s SME-finance ambitions.
You are the Chief Risk Officer. Which do you approve?
- AFull autonomy for all loans up to SAR 500,000
- BAI decides below SAR 100,000; above that it recommends and a human approves
- CPilot option B on existing customers for six months with a drift and fairness dashboard, then expand
Answer locked. Type the reveal word the presenter gives.
Why C. It captures most of the speed value, keeps high-consequence decisions in the Executive Approval zone, generates evidence before autonomy scales, and gives the board a first step it can reverse.
Why A fails. Reversibility. A wrongly declined SME may never come back, and a wrongly approved loan is a credit loss you carry for years. Full autonomy at machine speed on an irreversible decision is the top-right corner of the matrix.
Why B alone is not enough. The threshold is sound, but B scales before any fairness or drift evidence exists. C is B with the evidence plan attached.
The transferable rule. No AI system should gain autonomy faster than the institution gains accountability.