Week 1
Understanding AI Components in an Enterprise
Client Background
Meridian Health Group is a regional healthcare network with 14 clinics and 2 hospitals. Over the past 18 months, individual departments quietly adopted AI tools without central IT or security involvement — a pattern often called 'shadow AI.'
Business Environment
The newly hired CISO, Elena Vasquez, has been told by the board that AI is 'everywhere' in the organization but no one can say exactly where. Departments in use include: clinical documentation (an AI scribe plugged into the EHR), a patient-facing chatbot on the website, a marketing content generator, and a finance team experimenting with an AI spreadsheet copilot. Before any risk or governance work can begin, Elena needs a plain-English inventory of what these AI components actually are and how they process data.
Security Incident
There has been no breach yet — this is a proactive governance kickoff. However, a nurse recently pasted a patient's visit notes into a public AI chatbot to 'clean up' her documentation, which is what triggered the CISO's urgency.
Scope
Review the four AI tools currently in informal use across Meridian Health Group. For each, determine: what type of AI component it is (hosted API, embedded plugin, custom-built model, chatbot), what data it touches, where it runs (vendor cloud vs. internal), and who owns it internally.
Objectives
- Distinguish between first-party built AI systems and third-party AI services/APIs
- Identify the core AI component types: foundation models, embeddings/vector stores, plugins, and orchestration layers
- Map what data each AI component sends, receives, and stores
- Determine business ownership for each AI tool in scope
- Translate technical AI architecture into language a non-technical executive can act on
Required Deliverables