AIGP · Question #104
Your company is developing an AI system for global markets. This system involves personal data processing and some decision making that may affect rights of the individuals. Part of your role as an…
The correct answer is C. Develop a compliance strategy based on the strictest requirements in various regulations. Developing a compliance strategy based on the strictest requirements across multiple regulations (C) is the gold standard for global AI systems because it ensures the system meets the highest bar in any jurisdiction it operates in - if you satisfy the strictest rule, you almost…
Question
Your company is developing an AI system for global markets. This system involves personal data processing and some decision making that may affect rights of the individuals. Part of your role as an AI governance professional is to ensure the AI system complies with various international regulatory requirements. Which of the following approaches best aligns with a comprehensive understanding of and compliance with AI regulatory requirements in this scenario?
Options
- AFocus on the EU AI Act as it is the most comprehensive regulation and its likely compliance with
- BConsider that if the AI system complies with local regulations of the country where the company is
- CDevelop a compliance strategy based on the strictest requirements in various regulations,
- DAdopt a region-specific compliance strategy where the AI is modified to meet regulatory
How the community answered
(41 responses)- A10% (4)
- B5% (2)
- C68% (28)
- D17% (7)
Explanation
Developing a compliance strategy based on the strictest requirements across multiple regulations (C) is the gold standard for global AI systems because it ensures the system meets the highest bar in any jurisdiction it operates in - if you satisfy the strictest rule, you almost certainly satisfy the more lenient ones too. This is especially critical when personal data processing and rights-affecting decisions are involved, since gaps in compliance can trigger enforcement actions across multiple countries simultaneously.
Why the distractors fail:
- A is wrong because the EU AI Act, while comprehensive, is not the only relevant framework - systems operating globally must also account for other regimes (e.g., Brazil's LGPD, China's AI rules, U.S. state laws), and no single regulation covers all scenarios everywhere.
- B is wrong because local compliance in the company's home country does not grant permission to process the personal data of citizens in other countries under their laws - jurisdictional reach follows the data subject, not just the company's location.
- D is wrong because siloed, region-specific modifications create operational fragmentation and risk - data flows and AI behavior don't respect borders cleanly, and maintaining divergent versions increases the chance of regulatory gaps.
Memory tip: Think of it as the "highest watermark" rule - when sailing in waters with different depth requirements, you build your ship to clear the shallowest passage, and you automatically clear all the deeper ones. One strong design beats four fragile regional patches.
Topics
Community Discussion
No community discussion yet for this question.