Courseiva
AI Governance and Ethics →mediumMultiple Choice

AI0-001 AI Governance and Ethics Practice Question

A software vendor is developing an AI system that generates realistic images of people for use in marketing campaigns. The system will be sold to clients in the EU. Under the EU AI Act, which obligation applies to the vendor regarding the generated content?

⚠ Common exam trap

It's easy for candidates to confuse the AI Act's transparency obligation for synthetic content with GDPR consent requirements, or assuming that any AI system dealing with personal data is automatically high-risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The vendor must ensure that generated images are marked in a machine-readable format as artificially generated.

The EU AI Act requires that AI-generated content, including synthetic images, be marked in a machine-readable format to indicate its artificial origin. This is a transparency obligation for providers of such systems. The vendor must implement this marking. Other obligations like consent, database registration, and conformity assessment apply to different risk categories or legal frameworks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The vendor must register the AI system in the EU database for high-risk systems.

    Why it's wrong here

    Registration in the EU database is required for high-risk AI systems. An image generation system for marketing is typically limited-risk, not high-risk, unless it falls into a high-risk category like deepfake generation for malicious purposes. Thus, registration is not required for this marketing use case.

  • ✗

    The vendor must obtain explicit consent from all individuals whose likeness is used in the training data.

    Why it's wrong here

    While data protection laws like GDPR may require a legal basis for processing personal data, the EU AI Act's specific obligation for synthetic content is marking, not consent. Consent is a separate requirement under GDPR, but the question asks about the AI Act's obligation. The AI Act does not mandate consent for training data under its transparency rules.

  • ✗

    The vendor must conduct a conformity assessment before placing the system on the market.

    Why it's wrong here

    Conformity assessment is required for high-risk AI systems. This image generation system is limited-risk, so it only needs to comply with transparency obligations, such as marking generated content. A full conformity assessment is not mandated for limited-risk systems.

  • ✓

    The vendor must ensure that generated images are marked in a machine-readable format as artificially generated.

    Why this is correct

    The EU AI Act requires providers of AI systems that generate synthetic content, such as images, to mark the output in a machine-readable format to indicate it is AI-generated. This applies to deepfakes and other synthetic media, ensuring transparency and enabling detection.

About these practice questions

Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.