hardMultiple Choice
Generative AI Leader Practice Question: Required by the EU AI Act to ensure high-risk AI…
A company is required by the EU AI Act to ensure high-risk AI systems are transparent and auditable. They are using a proprietary model from a vendor. Which step is CRITICAL?
⚠ Common exam trap
The trap is confusing output safety controls (filters) with regulatory transparency artifacts (Model Cards and datasheets), which are the actual audit evidence required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ask the vendor to provide a Model Card and datasheets for the training data
Under the EU AI Act, high-risk AI systems must be transparent and auditable, which requires documentation of the model's intended purpose, training data characteristics, performance metrics, and limitations. A vendor-provided Model Card and datasheets for the training data are the standard artifacts that satisfy this transparency and auditability obligation for a proprietary model. Without them, the deploying company cannot demonstrate compliance or perform meaningful risk assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement custom safety filters on the model outputs
Why it's wrong here
Output filters only police generated content; they neither document the vendor model's training data, limitations and evaluation metrics nor expose its decision logic, which the EU AI Act's transparency and auditability duties demand. Filters are tempting because they mitigate harmful outputs in deployment, but model documentation is the actual requirement here.
- ✓
Ask the vendor to provide a Model Card and datasheets for the training data
Why this is correct
Model Cards and training datasheets document intended use, evaluation results, limitations and data provenance, giving the deployer the evidence needed for transparency and audit obligations under the EU AI Act. Vendor contracts or accuracy benchmarks alone cannot demonstrate the system's design, risks and training data characteristics.
- ✗
Use a larger context window to capture all interactions
Why it's wrong here
A larger context window only lets the model retain more tokens per request; it produces no documentation of the vendor model's training data, evaluation results or limitations, so it cannot satisfy the Act's transparency and auditability obligations. Context windows are tempting for handling long inputs, not for regulatory disclosure.
- ✗
Train an internal model from scratch to replace the vendor model
Why it's wrong here
Training an internal model replaces the vendor but does not itself yield the training-data provenance, evaluation metrics and limitation disclosures the Act requires; the obligation attaches to documenting the high-risk system, not to who owns the weights. Building from scratch is tempting for control, yet it is unnecessary and far costlier.
Go deeper
Related to this question
About these practice questions
One of 1,008 original Generative AI Leader practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.