Generative AI Leader Practice Question: Business Strategies for Generative AI Solutions
A global financial services firm wants to deploy generative AI for personalized investment recommendations. They must comply with regulations in multiple jurisdictions, including GDPR and the SEC's Marketing Rule. The solution must also be auditable. Which approach best balances regulatory compliance, scalability, and cost?
⚠ Common exam trap
Google Cloud often tests the misconception that a single global model with a post-generation compliance layer is sufficient, but the trap is that post-generation filtering cannot undo model outputs that already violate local regulations, and it fails to provide the granular audit trails required for each jurisdiction's specific rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy separate, jurisdiction-specific models with tailored guardrails and audit trails for each region.
Deploying separate, jurisdiction-specific models allows each model to be trained and governed with guardrails and audit trails that directly map to local regulations like GDPR (data minimization, right to erasure) and the SEC Marketing Rule (fair, clear, and not misleading disclosures). This approach avoids the compliance conflicts that arise when a single model must satisfy contradictory requirements across regions, and it scales cost-effectively by only applying the necessary compliance overhead to each region's data and inference pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Build a centralized model in a cloud region with the most stringent regulations and apply it globally.
Why it's wrong here
This may not satisfy data residency requirements for other regions.
- ✗
Use a single global model with a unified compliance layer applied post-generation.
Why it's wrong here
Post-generation compliance may not catch all violations and is hard to audit.
- ✓
Deploy separate, jurisdiction-specific models with tailored guardrails and audit trails for each region.
Why this is correct
This ensures compliance with local regulations and provides auditable logs.
- ✗
Rely on a third-party API with built-in compliance for all regions.
Why it's wrong here
Third-party APIs may not cover all specific regulations and reduce control.
Go deeper
Related to this question
About these practice questions
This Generative AI Leader question is part of Courseiva's 683-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.