AI Debris: Residual Risk and the Afterlife of Failed AI Systems
AI governance frameworks primarily focus on risks during the development and deployment phases, implicitly treating system withdrawal as merely a technical shutdown. This paper argues that decommissioned AI systems generate residual risk, termed "AI debris", that persists after models are removed and continues to shape institutional behaviour, accountability, and trust. AI debris is defined as the post-withdrawal socio-technical residue of AI systems, including workflow dependency, data contamination, capability displacement (deskilling), legitimacy erosion, and accountability breakdown. It is distinguished from adjacent concepts such as technical debt and safety-critical post-incident review on the grounds of temporal locus and institutional scope. The paper develops a typology of six debris domains and explains the mechanisms by which debris persists through institutional memory, path dependency, blame avoidance, and feedback effects within organisational data. To operationalise the concept, it proposes an evaluator-ready AI Debris Decommissioning Protocol (AIDP), a stepwise checklist specifying auditable evidence for freezing decision footprints, incident review, remediation, contestability, and post-withdrawal accountability assignment. It also examines the incentive conditions, including external enforcement through procurement or regulation and protected disclosure, under which such a protocol is plausibly adopted. The paper contributes a practical governance instrument for regulators, auditors, and organisations seeking to prevent "paper compliance", strengthen AI lifecycle governance, and improve institutional resilience in high-stakes decision environments.