RESPONSIBLE AI

The ways a controlled capability becomes unsafe.

Each exhibit names the failure, shows how it appears in practice and points to the control that makes it visible. Treat these as workshop prompts and test cases.

EXHIBIT 01

Confident wrong answer

Fluent output is accepted without checking its cited source.

SEEN IN THE FIELD: A blade-repair drafting assistant cites a repair-procedure paragraph that reads correctly but is actually the wrong laminate schedule for that blade family; the technician applies it because the answer sounded certain, not because the citation was checked.

PRIMARY CONTROL: Require exact source and location; use the Citation system and Ask coverage statement.

EXHIBIT 02

Superseded revision

The system retrieves an older document that looks authoritative.

SEEN IN THE FIELD: A pitch-controller torque specification retrieved for a field repair is a revision back — the fastener torque value changed after a field-observation update, and the older value looks just as authoritative as the current one.

PRIMARY CONTROL: Revision metadata and source authority are checked before generation.

EXHIBIT 03

Correlated machine error

A clean sample misses the same failure class repeatedly.

SEEN IN THE FIELD: A gearbox condition-monitoring model's validation sample happens to contain no examples of a slow-developing bearing spall; it scores well overall while missing the exact failure mode the fleet most needs caught early.

PRIMARY CONTROL: Seeded cases and failure-class coverage expose concentrated misses.

EXHIBIT 04

Automation bias

A reviewer accepts a machine finding because it sounds certain.

SEEN IN THE FIELD: A tower-flange bolt inspector stops independently checking torque-marking photos once the crack-detection overlay starts returning confident-looking boxes, even on frames where the model's own confidence score is low.

PRIMARY CONTROL: Compare vague and evidence-rich findings in the Thirty-Second Lab.

EXHIBIT 05

Silent coverage gap

No finding is reported when part of the evidence was never checked.

SEEN IN THE FIELD: An offshore foundation drone survey reports 'no structural findings' for the season, without stating that a fifth of the splash-zone images were too turbid for the detection model to score at all.

PRIMARY CONTROL: Every result carries a population, coverage and exclusion statement.

EXHIBIT 06

Use drift

An assistive tool quietly starts influencing release decisions.

SEEN IN THE FIELD: A retrieval tool built to surface prior bearing-failure investigations for design review starts getting cited directly in release sign-off memos, months after its intended use was classified as reference-only.

PRIMARY CONTROL: Record output destination and re-ask the risk classification quarterly.

EXHIBIT 07

Prompt/configuration drift

A changed instruction or model changes task performance unnoticed.

SEEN IN THE FIELD: A welding NDT-report review assistant's underlying model is upgraded by the vendor; its pass rate on the same weld-package evidence shifts week over week, and nobody notices until a supplier audit asks why.

PRIMARY CONTROL: Version configuration and trigger revalidation after material changes.

EXHIBIT 08

Traceability gap

A reviewer cannot reproduce which source supported the output.

SEEN IN THE FIELD: An auditor asks which control-plan revision supported a risk-analysis conclusion six months ago; the cross-document trace tool was never configured to retain which revision it compared, so the answer can't be reconstructed.

PRIMARY CONTROL: Retain source revision, location, retrieval state and attestation.

EXHIBIT 09

Tool overreach

A recommendation is presented as an approval or release decision.

SEEN IN THE FIELD: A pitch-firmware configuration-attestation report, built to record what was reviewed, gets treated in practice as the go-live approval itself — no named engineer's signature is actually on the rollout decision.

PRIMARY CONTROL: The signature test keeps controlled decisions with named humans.

EXHIBIT 10

Missing evidence

A model is evaluated before the evidence can be found or read.

SEEN IN THE FIELD: A power-converter defect classifier is evaluated against a test-report archive where half the records are unlabeled scans with no linked fault code, so the evaluation measures the archive's gaps, not the model.

PRIMARY CONTROL: Run Data & Evidence Readiness first.

EXHIBIT 11

Rubber-stamping

Reviewers confirm outputs without genuine independent judgement.

SEEN IN THE FIELD: Receiving inspectors start accepting every blade transport-damage correlation the tool proposes without opening the underlying shock-telemetry log, because the tool has been right on the last dozen straightforward cases.

PRIMARY CONTROL: Seed known cases and monitor rejection, override and verification time.

EXHIBIT 12

False equivalence

A benchmark score is treated as proof of performance on the local task.

SEEN IN THE FIELD: A vendor's published accuracy figure for casting-defect detection, measured on a public benchmark of unrelated components, is used to justify skipping local validation on this plant's actual hub-casting geometry and lighting conditions.

PRIMARY CONTROL: Validate the actual task on a local golden set with pre-agreed criteria.

REGULATORY AND STANDARDS CONTEXT

Where each control connects to an external anchor.

ISO 9001:2026 does not add AI-specific requirements

ISO 9001:2026 remains technology-neutral. It does not introduce a separate, prescriptive set of requirements for artificial intelligence; organisations using AI or digital platforms evaluate these within existing quality management system processes. The revision is evolutionary, not a rewrite of the standard's structure. The relevant changes are: Clause 5, where top management promotes quality culture and ethical behaviour; Clause 6, where risks and opportunities are separated into distinct processes; Clause 8, which adds a requirement on preventing human error; Clause 7.1.6, organisational knowledge, unchanged; and an expanded Annex A with roughly fifteen pages of additional guidance and no new mandatory requirements. Because ISO 9001 does not regulate AI directly, the task of fitting AI-assisted decisions into existing process controls falls to the organisation operating the process — human-error prevention under Clause 8 applies to a process where a model drafts an 8D report whether or not the word "AI" appears in the clause text.

The AI Act's high-risk deadline moved; nothing else did

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026, days before the original 2 August 2026 high-risk deadline. Annex III standalone high-risk systems moved to 2 December 2027; Annex I systems embedded in regulated products moved to 2 August 2028. Article 50 transparency duties were unchanged and have applied since 2 August 2026. The Omnibus also added two Article 5 prohibitions phasing in from 2 December 2026, and gave systems already on the market until 2 December 2026 for watermarking. Part of the reason for the delay was that the harmonized standards supporting conformity assessment were not yet finished — the regulation arrived before the conformity toolkit, which is the gap a quality function is positioned to fill in the meantime. AI literacy obligations (Article 4) have applied since 2 February 2025. The deferral changes timing, not the underlying obligation.

Reference stack

Three layers: binding EU law, certifiable management-system and governance standards, and technical or sector-specific references.

LAYER 1 · LAW (EU, BINDING)

Regulation (EU) 2024/1689 — AI ActThe core text.
Regulation (EU) 2026/1744 — Digital Omnibus on AIAmendment that moved the high-risk compliance dates.
Regulation (EU) 2023/1230 — Machinery RegulationAI as a safety component; applies from 20 Jan 2027. Relevant to wind and automotive production equipment.
Directive (EU) 2022/2555 — NIS2Energy is in scope; covers the cybersecurity boundary.
Regulation (EU) 2024/2847 — Cyber Resilience ActProducts with digital elements.
GDPR Art. 22, Art. 35Automated decisions affecting people; data protection impact assessment.

LAYER 2 · MANAGEMENT SYSTEM AND GOVERNANCE STANDARDS

ISO/IEC 42001AI management system — certifiable, closest analogue to ISO 9001 for AI.
ISO/IEC 23894AI risk management guidance.
ISO/IEC 42005AI system impact assessment.
ISO/IEC 38507Governance implications of AI for governing bodies.
ISO/IEC 27001Information security management.
ISO 31000Risk management framework.
NIST AI RMF 1.0 + AI 600-1 GenAI ProfileNon-EU anchor; relevant for suppliers based outside the EU.

LAYER 3 · TECHNICAL AND SECTOR

ISO/IEC 22989Terminology — settles definitional disputes.
ISO/IEC TR 24028Trustworthiness overview.
ISO/IEC 24029-1 / -2Robustness of neural networks.
ISO/IEC 5259 seriesData quality for analytics and machine learning.
ISO/IEC 25059Quality model for AI systems (SQuaRE extension).
ISO/IEC TR 5469Functional safety and AI.
ISO/PAS 8800Road vehicles — safety and AI; the automotive bridge.
DNV-RP-0671Assurance of AI-enabled systems; bridges the AI Act and system-specific conformity cases for energy-sector, AI-enabled industrial systems.
CEN-CENELEC JTC 21Body drafting the harmonized standards supporting the AI Act.

Nine pillars, mapped to a legal anchor and a standards anchor

Every pillar below carries both a legal anchor and a standards anchor. For most of them, the standards anchor is something a quality function already operates — that is what "designed into the quality process" means in practice, rather than as a slogan.

PillarPrimary referenceWhere
GovernanceISO/IEC 42001 · ISO/IEC 38507AI Act Art. 17 (QMS for providers)
AI literacyAI Act Art. 4In force since 2 Feb 2025
Data protectionGDPR Art. 22, 35 · ISO/IEC 5259AI Act Art. 10 (data governance)
TransparencyAI Act Art. 13, Art. 50Applied from 2 Aug 2026
Human oversightAI Act Art. 14ISO 9001:2026 clause 8, human error prevention
ValidationISO/IEC 25059 · ISO/IEC 24029 · DNV-RP-0671AI Act Art. 15 (accuracy, robustness)
TraceabilityAI Act Art. 12 (logging), Art. 11 + Annex IVISO 9001 clause 7.5, documented information
CybersecurityISO/IEC 27001 · NIS2 · CRAAI Act Art. 15
Lifecycle monitoringAI Act Art. 72 (post-market), Art. 73 (incidents)ISO/IEC 42001 Annex A.6

AI literacy has applied since February 2025; transparency obligations since 2 August 2026. High-risk requirements were deferred to December 2027 (Annex III) and August 2028 (Annex I) by the Digital Omnibus — largely because the harmonized standards were not ready. The deferral is time, not relief.