Under the Canadian Artificial Intelligence and Data Act, when must the Minister of Innovation, Science and Industry be notified about a high-impact Al system?
Which stakeholder is responsible for lawful collection of data for the training of the foundational AI model?
Scenario:
An organization is developing a powerful general-purpose AI (GPAI) model that has systemic impact. The compliance team is assessing what legal obligations apply under the EU AI Act.
Under the EU AI Act, which of the following compliance actions appliesonly to General Purpose AI models with systemic risk?
A Canadian company is developing an Al solution to evaluate candidates in the course of job interviews.
Before offering the Al solution in the EU market, the company must take all of the following steps EXCEPT?
An EU bank intends to launch a multi-modal Al platform for customer engagement and automated decision-making assist with the opening of bank accounts. The platform has been subject to thorough risk assessments and testing, where it proves to be effective in not discriminating against any individual on the basis of a protected class.
What additional obligations must the bank fulfill prior to deployment?
CASE STUDY
Please use the following answer the next question:
A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.
The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system ' s accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.
The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.
The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.
Which Al risk would NOT have been identified during the procurement process based on the categories of information requested by the third-party consultant?
According to the Singapore Model Al Governance Framework, all of the following are recommended measures to promote the responsible use of Al EXCEPT?
What is a key opportunity for companies deploying proprietary Agentic AI models?
A company is creating a mobile app to enable individuals to upload images and videos, and analyze this data using ML to provide lifestyle improvement recommendations. The signup form has the following data fields:
1.First name
2.Last name
3.Mobile number
4.Email ID
5.New password
6.Date of birth
7.Gender
In addition, the app obtains a device ' s IP address and location information while in use.
What GDPR privacy principles does this violate?
CASE STUDY
Please use the following answer the next question:
XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company ' s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.
It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.
Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.
The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team ' s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization ' s operations in a responsible, cost-effective manner.
The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.
If XYZ does not deploy and use the Al hiring tool responsibly in the United States, its liability would likely increase under all of the following laws EXCEPT?
The benefit of having a clear process for handling AI-related incidents is that it reduces?
What type of organizational risk is associated with Al ' s resource-intensive computing demands?
A company has developed a proprietary AI model that analyzes consumer online behavior and predicts what prices consumers would be willing to pay for certain products, so that retailers may modify pricing accordingly. To test the model, the company has:
Performed an impact assessment
Conducted repeatability tests
Exposed the model to edge cases and potential malicious input
Conducted adversarial testing to identify security threats
Assessed and mitigated discrimination risks
Which additional responsible AI principle has the company failed to assess?
All of the following are reasons to deploy a challenger Al model in addition a champion Al model EXCEPT to?
After initially deploying a third-party AI model, you learn the developer has released a new version.
As deployer of this third-party model, what should you do?
All of the following are required for high-risk AI systems under the EU AI Act EXCEPT?
A bank is aiming to comply with ISO/IEC 42005:2025, and is studying how to adopt the standard in light of a new AI customer service system that it would like to implement.
In addition to the risk management process the bank already has in place to assess the risks of any potential new systems, which of the following actions is the most effective in adopting the ISO/IEC 42005:2025 standard?
CASE STUDY
Please use the following answer the next question:
XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company ' s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.
It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.
Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.
The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team ' s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization ' s operations in a responsible, cost-effective manner.
The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.
The frameworks that would be most appropriate for XYZ ' s governance needs would be the NIST Al Risk Management Framework and?
What is the most important factor when deciding whether or not to select a proprietary AI model?
Why is it important that conformity requirements are satisfied before an AI system is released into production?
Scenario:
An organization is evaluating different AI models for integration into its internal workflows. Before moving forward with a particular AI solution from a third-party vendor, the governance team needs to assess the ethical and operational implications of the model.
The most important policy to assess the operations of an AI model is to follow the:
All of the following issues are unique for proprietary AI model deployments EXCEPT?
A company developing and deploying its own AI model would perform all of the following steps to monitor and evaluate the model ' s performance EXCEPT?
Scenario:
A U.S.-based AI governance professional is evaluating resources from the National Institute of Standards and Technology (NIST) to guide the organization’s AI risk assessment strategy. They are particularly interested in programs focused on assessing AI-specific impacts.
The main purpose of NIST’sAssessing Risks and Impacts of AI (ARIA)program is to:
The best method to ensure a comprehensive identification of risks for a new AI model is?
Which of the following arenotconsidered biometric data under U.S. privacy laws?
Which of the following statements is correct regarding South Korea ' s Basic Act on the Development of Artificial Intelligence and the Establishment of Trust (the " AI Basic Act " )?
You are a privacy program manager at a large e-commerce company that uses an Al tool to deliver personalized product recommendations based on visitors ' personal information that has been collected from the company website, the chatbot and public data the company has scraped from social media.
A user submits a data access request under an applicable U.S. state privacy law, specifically seeking a copy of their personal data, including information used to create their profile for productrecommendations.
What is the most challenging aspect of managing this request?
Which of the following would be the least likely step for an organization to take when designing an integrated compliance strategy for responsible Al?
To assist its internal recruiters with filtering job applications, a company decides to develop in-house an AI model for screening and ranking job applicants ' resumes.
Which of the following is a unique issue this company might face compared with using a third-party AI service?
CASE STUDY
A global marketing agency is adapting a large language model ( " LLM " ) to generate content for an upcoming marketing campaign for a client ' s new product: a hard hat designed for construction workers of any gender to better protect them from head injuries.
The marketing agency is accessing the LLM through an application programming interface ( " API " ) developed by a third-party technology company. They want to generate text to be used for targeted advertising communications that highlight the benefits of the hard hat to potential purchasers. Both the marketing agency and the technology company have taken reasonable steps to address Al governance.
The marketing company has:
• Entered into a contract with the technology company with suitable representations and warranties.
• Completed an impact assessment on the LLM for this intended use.
• Built technical guidance on how to measure and mitigate bias in the LLM.
• Enabled technical aspects of transparency, explainability, robustness and privacy.
• Followed applicable regulatory requirements.
• Created specific legal statements and disclosures regarding the use of the Al on its client ' s advertising.
The technology company has:
• Provided guidance and resources to developers to address environmental concerns.
• Build technical guidance on how to measure and mitigate bias in the LLM.
• Provided tools and resources to measure bias specific to the LLM.
• Enabled technical aspects of transparency, explainability, robustness and privacy.
• Mapped and mitigated potential societal harms and large-scale impacts.
• Followed applicable regulatory requirements and industry standards.
• Created specific legal statements and disclosures regarding the LLM. including with respect to IP and rights to data.
The technology company has also addressed environmental concerns and societal harms.
Which of the following results would be considered biased outputs from this AI system EXCEPT?
CASE STUDY
A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.
All of the following are obligations of the company as a data controller when implementing its AI system EXCEPT?
What is the best reason for a company adopt a policy that prohibits the use of generative Al?
A deployer discovers that a high-risk AI recruiting system has been making widespread errors, resulting in harms to the rights of a considerable number of EU residents who are denied consideration for jobs for improper reasons such as ethnicity, gender and age.
According to the EU AI Act, what should the company do first?
Which of the following elements of feature engineering is most important to mitigate the potential bias in an Al system?
Pursuant to the White House Executive Order of November 2023, who is responsible for creating guidelines to conduct red-teaming tests of Al systems?
Which of the following is NOT required to be included in an AI impact assessment for a narrow AI use case?
What is the main purpose of accountability structures under the Govern function of the NIST Al Risk Management Framework?
Scenario:
An enterprise is evaluating multiple third-party generative AI tools to integrate into its platform. As part of its AI governance policy, it is assessing themost effective methodsto reduce risks related to bias, data misuse, and liability when using third-party solutions.
All of the following are commonly adopted processes and policies in reducing potential risks introduced by third-party AI tools or applications EXCEPT:
After completing model testing and validation, which of the following is the most important step that an organization takes prior to deploying the model into production?
CASE STUDY
Please use the following to answer the next question:
A small local flower delivery company operates a few stores and has a limited IT budget. To reduce the time spent on customer service, which is a major drain on employee time, the company plans to implement a simple but high-performance generative AI chatbot on its website. The chatbot will provide real-time, fact-based responses to customer inquiries and assist with order processing, helping to reduce incoming phone calls.
The company currently uses a single on-premises server for its order database and email system and has not yet partnered with a cloud provider.
An internal data privacy policy governs the use of customer data. This policy, written before the adoption of AI, allows the use or transfer of customer data beyond name and contact information but requires that all such data be deleted after the order is completed. The company prefers to maintain this policy without changes.
What deployment option is the simplest, quickest, and most cost-effective option across the various potential AI models for this particular company?
Which of the following best describes the data minimization principle as it relates to an AI model?
All of the following are included within the scope of post-deployment Al maintenance EXCEPT?
Scenario:
A large multinational organization is rolling out a company-wide AI governance initiative. To build awareness and support adoption, they are evaluating different ways to train employees and stakeholders across departments, including legal, technical, marketing, and customer-facing roles.
Which of the following typical approaches is a large organization least likely to use to responsibly train stakeholders on AI terminology, strategy and governance?
The OECD ' s Ethical Al Governance Framework is a self-regulation model that proposes to prevent societal harms by?
Which of the following considerations is the most important in mitigating the potential of bias in training and testing data?
CASE STUDY
Please use the following answer the next question:
A mid-size US healthcare network has decided to develop an Al solution to detect a type of cancer that is most likely arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records a radiologist for secondary review pursuant Agreed-upon criteria (e.g., a confidence score below a threshold).
To date, the healthcare network has taken the following steps: defined its Al ethical principles: conducted discovery to identify the intended uses and success criteria for the system: established an Al governance committee; assembled a broad, crossfunctional team with clear roles and responsibilities; and created policies and procedures to document standards, workflows, timelines and risk thresholds during the project.
The healthcare network intends to retain a cloud provider to host the solution and a consulting firm to help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.
The most significant risk from combining the healthcare network’s existing data with the clinical research partner data is?
CASE STUDY
Please use the following answer the next question:
ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.
ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (“LLM”). In particular, ABC intends to use its historical customer data—including applications, policies, and claims—and proprietary pricing and risk strategies to provide an initial qualification assessment of potential customers, which would then be routed .. human underwriter for final review.
ABC and the cloud provider have completed training and testing the LLM, performed a readiness assessment, and made the decision to deploy the LLM into production. ABC has designated an internal compliance team to monitor the model during the first month, specifically to evaluate the accuracy, fairness, and reliability of its output. After the first month in production, ABC realizes that the LLM declines a higher percentage of women ' s loan applications due primarily to women historically receiving lower salaries than men.
During the first month when ABC monitors the model for bias, it is most important to?
The processes and methods that allow human users to understand and trust the outputs produced by AI are important in addressing which key regulatory concern?
Which of the following deployments of generative Al best respects intellectual property rights?
MULTI-SELECT
Please select 3 of the 5 options below. No partial credit will be given.
From a governance perspective, which of the following correctly describe the responsibilities of AI developers or deployers?
During the planning and design phases of the Al development life cycle, bias can be reduced by all of the following EXCEPT?
Why is it important that conformity requirements are satisfied before an AI system is released into production?