NEW
Font size
WorksheetsGPAI fundamentals and regulation worksheet
Total questions: 42
Worksheet time: 21mins
GPAI models are best described as:
Models trained for a single narrow task only
Models trained to perform a broad range of tasks across domains and adaptable into many downstream systems
Models used only in government decision-making
Models that are always high risk by definition
A GPAI model can be integrated into:
Only high-risk applications
Only low-risk applications
High-risk or low-risk applications depending on deployment context
No regulated applications
Major laws increasingly regulate GPAI:
Only as end-user products, not as models
As models (not just systems) due to their foundational role
Only if open source
Only if used in healthcare
Under the EU AI Act, duties for GPAI models are set out in:
Chapter V
Annex II
Chapter I only
GDPR
In this module, “systemic-risk” GPAI models are described as:
Any model used in HR
Very large models above computing thresholds with additional obligations
Any recommendation engine
Models used only by governments
Which is a provider obligation for all GPAI models under the EU AI Act?
Publish source code
Maintain technical documentation
Ban downstream fine-tuning
Require government pre-approval for every deployment
Under the EU AI Act, GPAI providers must:
Publish raw training datasets
Publish training-data summaries while respecting IP/copyright
Never discuss training data
Only disclose compute spend
Which best matches the EU requirement for transparency to downstream providers?
Only marketing claims
Model cards, usage conditions, and limitations
Confidential terms only
No disclosure of limitations
If a GPAI provider is outside the EU, it must:
Appoint an EU representative
Appoint a US representative
Appoint no one
Only register a domain name in the EU
For systemic-risk GPAI models, providers must do the baseline requirements plus:
Only an extra marketing disclosure
Risk assessments and mitigation, incident reporting, red-teaming, robust cybersecurity and physical safeguards, and energy disclosure
A ban on all downstream use
Only annual financial audits
Under EU systemic-risk obligations, providers must:
Avoid adversarial testing to prevent misuse
Perform red-teaming/adversarial testing
Only do usability testing
Only rely on customer bug reports
Systemic-risk providers must:
Never report incidents
Document and report serious incidents
Report only to customers
Report only annually
Systemic-risk GPAI providers must disclose:
Staff salaries
Energy consumption
User identities
Source code
Systemic-risk obligations include ensuring robust:
Cybersecurity only, no physical security
Cybersecurity and physical safeguards
Physical safeguards only
None, safeguards are voluntary
Under Colorado SB 24-205 (effective 2026), GPAI developers are considered “developers” of high-risk systems if:
They publish model cards
Their models are integrated into consequential decision tools
Their models generate images
They operate outside Colorado
Colorado SB 24-205 requires GPAI developers to provide documentation to:
Only end users
Deployers and the Attorney General (AG)
Only the federal government
Only regulators, not deployers
Colorado requires developers to disclose known risks of:
Model latency
Algorithmic discrimination
Energy consumption
Network outages
California AB 2013/SB 942 require GPAI/foundation model providers to:
Publish training data transparency reports
Ban generative AI
File with the CAC
Appoint an EU representative
California AB 2013/SB 942 also require providers to:
Provide watermarking/detection tools for audio/visual outputs
Provide only text disclaimers
Provide no detection capability
Provide only internal labelling
California AB 2013/SB 942 require implementation of:
Testing and disclosure frameworks for large-scale GPAI
Only staff training
Only procurement rules
Only privacy policies
South Korea’s AI Basic Act applies to:
Only biometric systems
“General-purpose” and “high-impact” AI models
Only government AI
Only open-source AI
South Korea requires:
Only voluntary guidelines
Lifecycle risk management plan and documentation, transparency to downstream deployers and end-users, plus safety/reliability/human oversight measures
Only filing with CAC
Only EU-style energy disclosures
Foreign GPAI developers above thresholds must:
Appoint a domestic representative in South Korea
Appoint an EU representative
Appoint no representative
Only publish model cards
Generative AI providers in China must:
File systems with the CAC before public release
File in the EU public database
File only if the model is open source
File only after launch
China requires providers to:
Avoid security assessments
Undergo security and safety assessment
Only conduct marketing reviews
Only do privacy impact assessments
China requires providers to:
Never label outputs
Label and watermark outputs under deep synthesis rules
Only label text outputs
Only label on request
China requires providers to:
Allow any content
Ensure content complies with legal/policy standards
Ignore policy requirements
Only comply with contract terms
China requires providers to:
Never update filings
Monitor and rectify risks and report material changes or incidents
Only publish annual transparency reports
Only notify end users, not regulators
Japan’s AI Guidelines are:
Binding law with penalties
Nonbinding but influential
Only applicable to healthcare
Only for government use
Japan encourages GPAI providers to:
Avoid documentation
Maintain documentation and logs and disclose capabilities/limitations
Publish all training data
File with CAC
Japan encourages providers to:
Share no information with downstream deployers
Share information with downstream deployers to enable safe use
Only share marketing brochures
Only share source code
The NIST AI RMF is described as:
Binding law
Nonbinding but widely referenced in federal and state procurement
An EU regulation
A Chinese national standard
When referenced in procurement, the NIST AI RMF typically requires:
Only cost controls
Risk management, documentation and transparency
Only energy disclosure
Only red-teaming
Which set best matches “common global obligations” for GPAI providers?
Only marketing disclosures
Documentation; transparency; detection tools; risk management controls; human oversight support; incident reporting; filing/registration or representative appointment
Which comparative statement is accurate per the module?
China focuses mainly on AI literacy
South Korea emphasises life cycle safety and a domestic representative plus a detailed life cycle safety plan
The EU does not require training data summaries
Japan imposes penalties for noncompliance
A primary GPAI governance challenge is ensuring training data is:
As narrow as possible
High quality and representative across diverse contexts, avoiding bias
Only from one jurisdiction
Always private data
A key risk is that adaptation of a GPAI model to a specific use case may:
Always improve fairness
Compromise integrity or fairness of outputs if not managed
Remove the need for documentation
Eliminate high-risk classification
Which is explicitly cited as a high-risk setting where extra training/adaptation care may be needed?
Video games
Health care or criminal justice
Music generation
Spam filtering
Transparency obligations require GPAI providers to clearly communicate:
Only branding
Intended use, capabilities and limitations to users and deployers
Only employee oversight
Only energy consumption
For high-risk applications of GPAI, automatically generated logs are important for:
Aesthetic design
Traceability and accountability in critical decision-making environments
Reducing compute costs
Avoiding human oversight
The module states organisations must conduct thorough risk assessments for:
Only internal models
External AI products and services, whether integrated or standalone
Only open-source AI
Only government AI
Third-party risk assessment includes evaluating:
Vendor policies, testing results and safety measures to ensure compliance with internal standards
Only vendor marketing
Only the vendor’s share price
Only model popularity
