All of the following are included within the scope of post-deployment Al maintenance EXCEPT?
A bank is aiming to comply with ISO/IEC 42005:2025, and is studying how to adopt the standard in light of a new AI customer service system that it would like to implement.
In addition to the risk management process the bank already has in place to assess the risks of any potential new systems, which of the following actions is the most effective in adopting the ISO/IEC 42005:2025 standard?
An EU bank intends to launch a multi-modal Al platform for customer engagement and automated decision-making assist with the opening of bank accounts. The platform has been subject to thorough risk assessments and testing, where it proves to be effective in not discriminating against any individual on the basis of a protected class.
What additional obligations must the bank fulfill prior to deployment?
All of the following are potential benefits of using private over public LLMs EXCEPT?
CASE STUDY
Please use the following answer the next question:
A mid-size US healthcare network has decided to develop an Al solution to detect a type of cancer that is most likely arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records a radiologist for secondary review pursuant Agreed-upon criteria (e.g., a confidence score below a threshold).
To date, the healthcare network has taken the following steps: defined its Al ethical principles: conducted discovery to identify the intended uses and success criteria for the system: established an Al governance committee; assembled a broad, crossfunctional team with clear roles and responsibilities; and created policies and procedures to document standards, workflows, timelines and risk thresholds during the project.
The healthcare network intends to retain a cloud provider to host the solution and a consulting firm to help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.
The most significant risk from combining the healthcare network’s existing data with the clinical research partner data is?
The best method to ensure a comprehensive identification of risks for a new AI model is?
Retraining an LLM can be necessary for all of the following reasons EXCEPT?
CASE STUDY
Please use the following answer the next question:
A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.
The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system ' s accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.
The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.
The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.
The best human oversight mechanism for the police department to implement is that a police officer should?
Each of the following actors are typically engaged in the Al development life cycle EXCEPT?
CASE STUDY
Please use the following answer the next question:
ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.
ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (“LLM”). In particular, ABC intends to use its historical customer data—including applications, policies, and claims—and proprietary pricing and risk strategies to provide an initial qualification assessment of potential customers, which would then be routed .. human underwriter for final review.
ABC and the cloud provider have completed training and testing the LLM, performed a readiness assessment, and made the decision to deploy the LLM into production. ABC has designated an internal compliance team to monitor the model during the first month, specifically to evaluate the accuracy, fairness, and reliability of its output. After the first month in production, ABC realizes that the LLM declines a higher percentage of women ' s loan applications due primarily to women historically receiving lower salaries than men.
During the first month when ABC monitors the model for bias, it is most important to?
Business A sells software that provides users with writing and grammar assistance. Business B is a cloud services provider that trains its own AI models.
* Business A has decided to add generative AI features to their software.
* Rather than create their own generative AI model, Business A has chosen to license a model from Business B.
* Business A will then integrate the model into their writing assistance software to provide generative AI capabilities.
* Business A is most concerned that its writing assistance software could recommend toxic or obscene text to its users.
Which of the following governance processes should Business A take to best protect its users against potentially inappropriate text?
CASE STUDY
A global marketing agency is adapting a large language model ( " LLM " ) to generate content for an upcoming marketing campaign for a client ' s new product: a hard hat designed for construction workers of any gender to better protect them from head injuries.
The marketing agency is accessing the LLM through an application programming interface ( " API " )developed by a third-party technology company. They want to generate text to be used for targeted advertising communications that highlight the benefits of the hard hat to potential purchasers. Both the marketing agency and the technology company have taken reasonable steps to address Al governance.
The marketing company has:
• Entered into a contract with the technology company with suitable representations and warranties.
• Completed an impact assessment on the LLM for this intended use.
• Built technical guidance on how to measure and mitigate bias in the LLM.
• Enabled technical aspects of transparency, explainability, robustness and privacy.
• Followed applicable regulatory requirements.
• Created specific legal statements and disclosures regarding the use of the Al on its client ' s advertising.
The technology company has:
• Provided guidance and resources to developers to address environmental concerns.
• Build technical guidance on how to measure and mitigate bias in the LLM.
• Provided tools and resources to measure bias specific to the LLM.
• Enabled technical aspects of transparency, explainability, robustness and privacy.
• Mapped and mitigated potential societal harms and large-scale impacts.
• Followed applicable regulatory requirements and industry standards.
• Created specific legal statements and disclosures regarding the LLM. including with respect to IP and rights to data.
The agency has taken governance actions such as:
Conducting an impact assessment
Providing legal disclosures
Enabling bias mitigation and explainability
Complying with regulatory requirements
Which of the following should be included in the marketing company’s disclosures about the use of the LLM EXCEPT?
A company has trained an ML model primarily using synthetic data, and now intends to use live personal data to test the model.
Which of the following is NOT a best practice apply during the testing?
A deployer discovers that a high-risk AI recruiting system has been making widespread errors, resulting in harms to the rights of a considerable number of EU residents who are denied consideration for jobs for improper reasons such as ethnicity, gender and age.
According to the EU AI Act, what should the company do first?
CASE STUDY
Please use the following answer the next question:
A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the publicsites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.
The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system ' s accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.
The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.
The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.
When notifying an accused perpetrator, what additional information should a police officer provide about the use of the Al system?
A company that deploys AI but is not currently a provider or developer intends to develop and market its own AI system.
Which obligation would then be likely to apply?
Scenario:
A U.S.-based AI governance professional is evaluating resources from the National Institute of Standards and Technology (NIST) to guide the organization’s AI risk assessment strategy. They are particularly interested in programs focused on assessing AI-specific impacts.
The main purpose of NIST’sAssessing Risks and Impacts of AI (ARIA)program is to:
Decreasing the complexity of a machine learning model reduces variance and?
The OECD ' s Ethical Al Governance Framework is a self-regulation model that proposes to prevent societal harms by?
What is the best method to proactively train an LLM so that there is mathematical proof that no specific piece of training data has more than a negligible effect on the model or its output?
Scenario:
A financial services company is planning a new AI project to assess creditworthiness. The AI team is mapping out what tasks should be completed during theplanning phaseof the AI lifecycle.
The planning phase of the AI lifecycle includes all of the following EXCEPT:
CASE STUDY
Please use the following answer the next question:
A mid-size US healthcare network has decided to develop an Al solution to detect a type of cancer that is most likely arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records a radiologist for secondary review pursuant agreed-upon criteria (e.g., a confidence score below a threshold).
To date, the healthcare network has taken the following steps: defined its Al ethical principles: conducted discovery to identify the intended uses and success criteria for the system: established an Al governance committee; assembled a broad, crossfunctional team with clear roles and responsibilities; and created policies and procedures to document standards, workflows, timelines and risk thresholds during the project.
The healthcare network intends to retain a cloud provider to host the solution and a consulting firm to help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.
In the design phase, which of the following steps is most important in gathering the data from the clinical research partner?
Which model is best for efficiency and agility, and tailored for lower-resource settings?
CASE STUDY
A global marketing agency is adapting a large language model ( " LLM " ) to generate content for an upcoming marketing campaign for a client ' s new product: a hard hat designed for construction workers of any gender to better protect them from head injuries.
The marketing agency is accessing the LLM through an application programming interface ( " API " ) developed by a third-party technology company. They want to generate text to be used for targeted advertising communications that highlight the benefits of the hard hat to potential purchasers. Both the marketing agency and the technology company have taken reasonable steps to address Al governance.
The marketing company has:
• Entered into a contract with the technology company with suitable representations and warranties.
• Completed an impact assessment on the LLM for this intended use.
• Built technical guidance on how to measure and mitigate bias in the LLM.
• Enabled technical aspects of transparency, explainability, robustness and privacy.
• Followed applicable regulatory requirements.
• Created specific legal statements and disclosures regarding the use of the Al on its client ' s advertising.
The technology company has:
• Provided guidance and resources to developers to address environmental concerns.
• Build technical guidance on how to measure and mitigate bias in the LLM.
• Provided tools and resources to measure bias specific to the LLM.
• Enabled technical aspects of transparency, explainability, robustness and privacy.
• Mapped and mitigated potential societal harms and large-scale impacts.
• Followed applicable regulatory requirements and industry standards.
• Created specific legal statements and disclosures regarding the LLM. including with respect to IP and rights to data.
The marketing company and its tech provider have taken reasonable steps to govern the AI’s use, including legal disclosures, impact assessments, and bias mitigation. However, the company wants to takeone more stepto improve governance and reduce risks related to ongoing oversight and accountability.
While the marketing agency took steps to mitigate its risks, the best additional step would be to:
Which of the following steps occurs in the design phase of the Al life cycle?
All of the following are reasons to deploy a challenger Al model in addition a champion Al model EXCEPT to?
What is the primary objective of continuous monitoring in the lifecycle of an AI tool?
Which of the following use cases would be best served by a non-AI solution?
During the planning and design phases of the Al development life cycle, bias can be reduced by all of the following EXCEPT?
A US company has developed an Al system, Crime Buster 9619, that collects information about incarcerated individuals to help parole boards predict whether someone is likely to commit another crime if released from prison.
When considering expanding to the EU market, this type of technology would?
All of the following are penalties and enforcements outlined in the EU Al Act EXCEPT?
Scenario:
A company is using different types of AI systems to enhance consumer engagement. These include chatbots, recommendation engines, and automated content generation tools.
Which of the following situations would beleast likelyto raise concerns under existing consumer protection laws?
All of the following areunique characteristics of AIthat require a comprehensive approach to governanceEXCEPT?
You are part of your organization’s ML engineering team and notice that the accuracy of a model that was recently deployed into production is deteriorating.
What is the best first step address this?
According to November 2023 White House Executive Order, which of the following best describes the guidance given to governmental agencies on the use of generative Al as a workplace tool?
CASE STUDY
Please use the following to answer the next question:
You have recently assumed the role of AI Governance leader for a California-based medical technology company. The organization primarily serves hospitals and has recently expanded to include walk-in clinics located within local pharmacies.
The company ' s core business focuses on diagnostic assistance powered by a large language model LLM and back-office process optimization using Agentic AI, including chatbots, medical record request handling, scheduling and billing.
In preparation for its next round of funding, the board has asked you to prepare an AI Risk report to demonstrate to investors how the company is addressing AI-related risks. In preparing the report you learn that last year the company generated 30 million dollars in gross revenue across the US, EU, India, and South Korea and that vendors are engaged for various activities, including model testing and providing third-party AI solutions for chatbots.
Which of the following would provide you the best information addressing quality principles pertaining to the functioning of the AI agents and LLM?
Pursuant to the White House Executive Order of November 2023, who is responsible for creating guidelines to conduct red-teaming tests of Al systems?
Which risk management framework/guide/standard focuses on value-based engineering methodology?
Scenario:
Business A provides grammar and writing assistance tools and licenses a generative AI model from Business B to enhance its offerings. Business A is concerned that the AI model might produce inappropriate or toxic content and wants to implement governance processes to prevent this.
Which of the following governance processes should Business A take tobest protect its usersagainst potentially inappropriate text?
Scenario:
An organization is planning to deploy a new internal application that uses AI to make automated decisions about individuals. This application will process personal information and may affect individuals’ access to certain benefits or opportunities.
Which of the following documents must be updated to ensure transparency?
A company ' s AI-powered hiring tool is found to be consistently ranking male candidates higher than female candidates with similar qualifications.
Which of the following is the most immediate and critical governance action required to address this issue?
Which of the following use cases would be best served by a non-AI solution?
According to the GDPR, what is an effective control to prevent a determination based solely on automated decision-making?
CASE STUDY
Please use the following answer the next question:
Good Values Corporation (GVC) is a U.S. educational services provider that employs teachers to create and deliver enrichment courses for high school students. GVC has learned that many of its teacher employees are using generative Al to create the enrichment courses, and that many of the students are using generative Al to complete their assignments.
In particular, GVC has learned that the teachers they employ used open source large language models (“LLM”) to develop an online tool that customizes study questions for individual students. GVC has also discovered that an art teacher has expressly incorporated the use of generative Al into the curriculum to enable students to use prompts to create digital art.
GVC has started to investigate these practices and develop a process to monitor any use of generative Al, including by teachers and students, going forward.
What is the best reason for GVC to offer students the choice to utilize generative Al in limited, defined circumstances?
Scenario:
An organization is building a compliance program to ensure responsible AI deployment. It aims to align operations with AI risk frameworks and mitigate legal, ethical, and operational risks, while still promoting innovation.
Which of the following would be theleast likelystep for an organization to take when designing an integrated compliance strategy for responsible AI?
According to the Singapore Model Al Governance Framework, all of the following are recommended measures to promote the responsible use of Al EXCEPT?
An Al system that maintains its level of performance within defined acceptable limits despite real world or adversarial conditions would be described as?
CASE STUDY
Please use the following answer the next question:
A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.
The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system ' s accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.
The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.
The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.
During the procurement process, what is the most likely reason that the third-party consultant asked each vendor for information about the diversity of their datasets?
According to the EU Al Act, providers of what kind of machine learning systems will be required to register with an EU oversight agency before placing their systems in the EU market?