← All AML Flashcard Decks

Regulatory Compliance & Legal Framework Flashcards

7 cards from real AML practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Legal Framework flashcards as text
  1. Which provision of GDPR specifically grants individuals the right to contest automated decisions that produce legal or similarly significant effects?

    Answer: Article 22

    GDPR Article 22 grants individuals the right not to be subject to solely automated decisions with significant effects and to request human review.

  2. A hospital deploys an ML triage model. Which regulatory framework is most directly applicable in the US?

    Answer: FDA Software as a Medical Device (SaMD) guidance

    The FDA regulates ML-based software used in clinical decision-making as Software as a Medical Device (SaMD) under its digital health framework.

  3. The concept of 'red-teaming' in the context of AI regulatory compliance refers to:

    Answer: Adversarial testing to identify model failures, biases, and safety risks

    Red-teaming in AI compliance involves adversarially probing models to uncover failure modes, harmful outputs, and systemic biases before and after deployment.

  4. Section 5 of the FTC Act is relevant to ML deployments because it prohibits:

    Answer: Unfair or deceptive acts or practices, including misleading algorithmic outputs

    The FTC uses Section 5 authority to act against companies whose ML systems produce deceptive or unfair outcomes for consumers.

  5. Which of the following is a core requirement of the Colorado AI Act (SB 21-169) for high-risk AI systems?

    Answer: Conducting impact assessments and providing adverse action notices

    Colorado's AI Act requires developers and deployers of high-risk AI to conduct impact assessments and provide consumers with adverse action notices and explanations.

  6. In EU AI Act terminology, a 'general-purpose AI model' with systemic risk is characterized by training compute exceeding:

    Answer: 10^25 FLOPs

    The EU AI Act designates GPAI models trained with more than 10^25 FLOPs as having systemic risk, triggering additional obligations like adversarial testing.

  7. A model card, as originally proposed by Mitchell et al. (2019), is best described as:

    Answer: A structured transparency report disclosing model performance across subgroups and use contexts

    Model cards are structured documentation tools that report a model's intended uses, performance across demographic subgroups, limitations, and ethical considerations.