Courseiva

AI0-001 AI Security, Ethics and Governance Practice Question

A global bank deploys a generative AI assistant that summarizes internal policy documents for loan officers across the European Union and the United States. The compliance team must ensure the system respects regional AI regulations. Which of the following actions is MOST appropriate for aligning the deployment with these requirements?

⚠ Common exam trap

The trap here is treating a foundation model provider's documentation as sufficient compliance evidence instead of recognizing the deployer's own assessment and oversight obligations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Classify the assistant's risk level per jurisdiction, document the conformity assessment, and maintain human oversight and logging for its outputs.

Cross-border AI deployments must be governed per jurisdiction rather than by a single global policy. A risk classification, documented assessment, and operational controls such as human oversight and logging create an auditable compliance posture. Vendor documentation alone cannot substitute for deployer obligations, and neither data minimization nor language restriction addresses the core regulatory duties for a credit-adjacent generative tool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Classify the assistant's risk level per jurisdiction, document the conformity assessment, and maintain human oversight and logging for its outputs.

    Why this is correct

    Generative assistants used in credit-related workflows can fall into higher-risk categories under the EU AI Act and are subject to sector rules such as fair lending in the US. A defensible approach maps each jurisdiction's requirements, performs and documents a conformity or impact assessment, and keeps human review plus audit logs. This addresses transparency, accountability, and oversight obligations simultaneously.

  • ✗

    Restrict the assistant to English-language documents only, because language localization is the primary regulatory differentiator across regions.

    Why it's wrong here

    Language is not the basis of AI regulatory obligations; risk classification, use context, and data handling are. Limiting language would not satisfy EU AI Act documentation, transparency, or oversight duties, nor US fair lending and consumer protection expectations. This action addresses a translation concern rather than the actual governance requirements of each jurisdiction.

  • ✗

    Rely on the foundation model provider's terms of service and published model card as sufficient evidence of regulatory compliance.

    Why it's wrong here

    Provider documentation describes the base model, not the bank's specific deployment, data flows, or use case. Regulatory obligations attach to the deployer as well as the provider, especially for high-risk financial uses. Treating a vendor model card as complete compliance evidence ignores required risk classification, local assessments, and operational controls the bank itself must implement and evidence.

  • ✗

    Disable all output logging to minimize the personal data stored, since data minimization is the only regulatory requirement that applies.

    Why it's wrong here

    Data minimization is one principle among many and does not override accountability, auditability, or record-keeping duties. Removing logs would undermine incident investigation, regulatory reporting, and human oversight evidence. Privacy requirements can be met with retention limits, access controls, and pseudonymization rather than eliminating the audit trail entirely, which would create a different compliance failure.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.