hardMultiple Select
Generative AI Leader Practice Question: Developing a generative AI application that will…
A company is developing a generative AI application that will be used by customers in the EU. To comply with the GDPR and the upcoming EU AI Act, which THREE measures should they implement? (Select 3)
⚠ Common exam trap
Generative AI Leader often tests whether candidates conflate 'open-source' with 'compliant' — open-source licensing has nothing to do with GDPR or AI Act obligations, which apply to processing activities, not model provenance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store and process all user data within the EU or in regions with adequacy decisions
Option A is correct because GDPR data-transfer rules (Chapter V) require personal data to remain in the EU/EEA or be transferred only to countries with an adequacy decision from the European Commission, so localizing storage and processing is a valid compliance measure. Option D is correct because GDPR Articles 13-15 grant data subjects the right to meaningful information about and explanation of automated decision-making, and the EU AI Act reinforces transparency and explainability obligations for AI systems. Option E is correct because the EU AI Act requires transparency so that users are informed when they are interacting with an AI system rather than a human, and GDPR fairness/transparency principles support this disclosure. Option B is not required: open-source models are neither mandated by GDPR nor by the AI Act, and transparency obligations apply regardless of model licensing. Option C is not required: GDPR does not impose a fixed 30-day log deletion period; retention must be limited to what is necessary, but the specific 30-day value is arbitrary and not a legal requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store and process all user data within the EU or in regions with adequacy decisions
Why this is correct
GDPR restricts transfers of personal data outside the EEA unless an adequacy decision or equivalent safeguard applies. Keeping storage and processing within the EU, or in adequacy-approved regions, satisfies that transfer constraint directly rather than relying on contractual patches.
- ✗
Use only open-source models to ensure transparency
Why it's wrong here
Open-source licences grant code access, not transparency of training data, weights or evaluation, and the EU AI Act imposes duties regardless of licence. It tempts because openness is associated with auditability, but compliance instead requires risk management, technical documentation, logging and human oversight proportionate to the system's risk classification.
- ✗
Automatically delete all user logs after 30 days
Why it's wrong here
GDPR does not specify a fixed retention period; it depends on purpose.
- ✓
Provide users with the ability to obtain an explanation of the AI's decisions
Why this is correct
GDPR Articles 13–15 and 22 grant data subjects meaningful information about automated decision-making logic. Providing explanations satisfies the transparency and contestability obligations the EU AI Act reinforces for high-risk systems, addressing the stem's compliance requirement.
- ✓
Clearly inform users that they are interacting with an AI system
Why this is correct
Both GDPR transparency duties and the EU AI Act require that people know when they interact with an AI system, not a human. Disclosing this satisfies the stem's transparency constraint and prevents deception, which is a core regulatory expectation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every Generative AI Leader question from scratch — 1,008 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.