AML Regulatory Compliance & Legal Framework 3 — Questions and Answers
Question 1: Which provision of GDPR specifically grants individuals the right to contest automated decisions that produce legal or similarly significant effects?
- Article 13
- Article 17
- Article 22 (Correct answer)
- Article 35
Correct answer: Article 22
GDPR Article 22 grants individuals the right not to be subject to solely automated decisions with significant effects and to request human review.
Question 2: A hospital deploys an ML triage model. Which regulatory framework is most directly applicable in the US?
- FERPA
- FDA Software as a Medical Device (SaMD) guidance (Correct answer)
- FINRA Rule 3110
- NIST SP 800-53
Correct answer: FDA Software as a Medical Device (SaMD) guidance
The FDA regulates ML-based software used in clinical decision-making as Software as a Medical Device (SaMD) under its digital health framework.
Question 3: The concept of 'red-teaming' in the context of AI regulatory compliance refers to:
- Deploying models only on red-labeled servers
- Adversarial testing to identify model failures, biases, and safety risks (Correct answer)
- Restricting model access to authorized red team members
- Color-coding model risk tiers in documentation
Correct answer: Adversarial testing to identify model failures, biases, and safety risks
Red-teaming in AI compliance involves adversarially probing models to uncover failure modes, harmful outputs, and systemic biases before and after deployment.
Question 4: Section 5 of the FTC Act is relevant to ML deployments because it prohibits:
- Use of personal data without encryption
- Unfair or deceptive acts or practices, including misleading algorithmic outputs (Correct answer)
- Automated hiring decisions without human review
- Cross-border data transfers to non-GDPR countries
Correct answer: Unfair or deceptive acts or practices, including misleading algorithmic outputs
The FTC uses Section 5 authority to act against companies whose ML systems produce deceptive or unfair outcomes for consumers.
Question 5: Which of the following is a core requirement of the Colorado AI Act (SB 21-169) for high-risk AI systems?
- Mandatory open-sourcing of model weights
- Conducting impact assessments and providing adverse action notices (Correct answer)
- Prohibiting use of synthetic training data
- Requiring government pre-approval before deployment
Correct answer: Conducting impact assessments and providing adverse action notices
Colorado's AI Act requires developers and deployers of high-risk AI to conduct impact assessments and provide consumers with adverse action notices and explanations.
Question 6: In EU AI Act terminology, a 'general-purpose AI model' with systemic risk is characterized by training compute exceeding:
- 10^23 FLOPs
- 10^25 FLOPs (Correct answer)
- 10^20 FLOPs
- 10^30 FLOPs
Correct answer: 10^25 FLOPs
The EU AI Act designates GPAI models trained with more than 10^25 FLOPs as having systemic risk, triggering additional obligations like adversarial testing.
Question 7: A model card, as originally proposed by Mitchell et al. (2019), is best described as:
- A marketing document highlighting model capabilities
- A structured transparency report disclosing model performance across subgroups and use contexts (Correct answer)
- A software license specifying terms of model use
- A compliance checklist mandated by GDPR
Correct answer: A structured transparency report disclosing model performance across subgroups and use contexts
Model cards are structured documentation tools that report a model's intended uses, performance across demographic subgroups, limitations, and ethical considerations.
Which provision of GDPR specifically grants individuals the right to contest automated decisions that produce legal or similarly significant effects?