CAIC AI Governance & Compliance Flashcards
6 cards from real CAIC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CAIC AI Governance & Compliance flashcards as text
What does 'data minimization' mean in the context of AI compliance?
Answer: Collecting and using only the personal data necessary for the specified purpose
Data minimization is a privacy principle requiring organizations to collect only the personal data strictly necessary for the AI system's stated purpose, reducing privacy risk.
Which process involves continuously monitoring a deployed AI model for performance degradation over time?
Answer: Model drift monitoring
Model drift monitoring tracks whether a deployed model's accuracy or prediction quality degrades as real-world data distributions shift away from training data.
In AI governance, what is a 'human-in-the-loop' (HITL) design?
Answer: Requiring human review or approval at key decision points in an automated AI process
HITL design incorporates human judgment at critical stages of an AI workflow, ensuring oversight and the ability to override or correct automated decisions.
What is 'right to explanation' as it applies to automated AI decisions affecting individuals in the US context?
Answer: An individual's right to receive a meaningful explanation of how an automated decision that affects them was made
The right to explanation gives individuals the ability to understand the logic behind automated decisions that significantly affect them, influenced by GDPR Article 22 and emerging US state laws.
Which governance practice involves testing an AI system against adversarial inputs before deployment?
Answer: Red teaming
Red teaming for AI involves a team deliberately trying to elicit harmful, biased, or incorrect outputs from an AI system to identify vulnerabilities before public release.
A company trains an AI model using customer purchase data without explicit consent. Which compliance violation is most directly applicable?
Answer: Violation of data privacy regulations such as CCPA or GDPR
Using personal data for AI training without consent or a lawful basis violates privacy regulations like GDPR and the California Consumer Privacy Act (CCPA).