wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

GPAI fundamentals and regulation worksheet

Total questions: 42

Worksheet time: 21mins

Name
Class
Date
1.

GPAI models are best described as:

a)

Models trained for a single narrow task only

b)

Models trained to perform a broad range of tasks across domains and adaptable into many downstream systems

c)

Models used only in government decision-making

d)

Models that are always high risk by definition

2.

A GPAI model can be integrated into:

a)

Only high-risk applications

b)

Only low-risk applications

c)

High-risk or low-risk applications depending on deployment context

d)

No regulated applications

3.

Major laws increasingly regulate GPAI:

a)

Only as end-user products, not as models

b)

As models (not just systems) due to their foundational role

c)

Only if open source

d)

Only if used in healthcare

4.

Under the EU AI Act, duties for GPAI models are set out in:

a)

Chapter V

b)

Annex II

c)

Chapter I only

d)

GDPR

5.

In this module, “systemic-risk” GPAI models are described as:

a)

Any model used in HR

b)

Very large models above computing thresholds with additional obligations

c)

Any recommendation engine

d)

Models used only by governments

6.

Which is a provider obligation for all GPAI models under the EU AI Act?

a)

Publish source code

b)

Maintain technical documentation

c)

Ban downstream fine-tuning

d)

Require government pre-approval for every deployment

7.

Under the EU AI Act, GPAI providers must:

a)

Publish raw training datasets

b)

Publish training-data summaries while respecting IP/copyright

c)

Never discuss training data

d)

Only disclose compute spend

8.

Which best matches the EU requirement for transparency to downstream providers?

a)

Only marketing claims

b)

Model cards, usage conditions, and limitations

c)

Confidential terms only

d)

No disclosure of limitations

9.

If a GPAI provider is outside the EU, it must:

a)

Appoint an EU representative

b)

Appoint a US representative

c)

Appoint no one

d)

Only register a domain name in the EU

10.

For systemic-risk GPAI models, providers must do the baseline requirements plus:

a)

Only an extra marketing disclosure

b)

Risk assessments and mitigation, incident reporting, red-teaming, robust cybersecurity and physical safeguards, and energy disclosure

c)

A ban on all downstream use

d)

Only annual financial audits

11.

Under EU systemic-risk obligations, providers must:

a)

Avoid adversarial testing to prevent misuse

b)

Perform red-teaming/adversarial testing

c)

Only do usability testing

d)

Only rely on customer bug reports

12.

Systemic-risk providers must:

a)

Never report incidents

b)

Document and report serious incidents

c)

Report only to customers

d)

Report only annually

13.

Systemic-risk GPAI providers must disclose:

a)

Staff salaries

b)

Energy consumption

c)

User identities

d)

Source code

14.

Systemic-risk obligations include ensuring robust:

a)

Cybersecurity only, no physical security

b)

Cybersecurity and physical safeguards

c)

Physical safeguards only

d)

None, safeguards are voluntary

15.

Under Colorado SB 24-205 (effective 2026), GPAI developers are considered “developers” of high-risk systems if:

a)

They publish model cards

b)

Their models are integrated into consequential decision tools

c)

Their models generate images

d)

They operate outside Colorado

16.

Colorado SB 24-205 requires GPAI developers to provide documentation to:

a)

Only end users

b)

Deployers and the Attorney General (AG)

c)

Only the federal government

d)

Only regulators, not deployers

17.

Colorado requires developers to disclose known risks of:

a)

Model latency

b)

Algorithmic discrimination

c)

Energy consumption

d)

Network outages

18.

California AB 2013/SB 942 require GPAI/foundation model providers to:

a)

Publish training data transparency reports

b)

Ban generative AI

c)

File with the CAC

d)

Appoint an EU representative

19.

California AB 2013/SB 942 also require providers to:

a)

Provide watermarking/detection tools for audio/visual outputs

b)

Provide only text disclaimers

c)

Provide no detection capability

d)

Provide only internal labelling

20.

California AB 2013/SB 942 require implementation of:

a)

Testing and disclosure frameworks for large-scale GPAI

b)

Only staff training

c)

Only procurement rules

d)

Only privacy policies

21.

South Korea’s AI Basic Act applies to:

a)

Only biometric systems

b)

“General-purpose” and “high-impact” AI models

c)

Only government AI

d)

Only open-source AI

22.

South Korea requires:

a)

Only voluntary guidelines

b)

Lifecycle risk management plan and documentation, transparency to downstream deployers and end-users, plus safety/reliability/human oversight measures

c)

Only filing with CAC

d)

Only EU-style energy disclosures

23.

Foreign GPAI developers above thresholds must:

a)

Appoint a domestic representative in South Korea

b)

Appoint an EU representative

c)

Appoint no representative

d)

Only publish model cards

24.

Generative AI providers in China must:

a)

File systems with the CAC before public release

b)

File in the EU public database

c)

File only if the model is open source

d)

File only after launch

25.

China requires providers to:

a)

Avoid security assessments

b)

Undergo security and safety assessment

c)

Only conduct marketing reviews

d)

Only do privacy impact assessments

26.

China requires providers to:

a)

Never label outputs

b)

Label and watermark outputs under deep synthesis rules

c)

Only label text outputs

d)

Only label on request

27.

China requires providers to:

a)

Allow any content

b)

Ensure content complies with legal/policy standards

c)

Ignore policy requirements

d)

Only comply with contract terms

28.

China requires providers to:

a)

Never update filings

b)

Monitor and rectify risks and report material changes or incidents

c)

Only publish annual transparency reports

d)

Only notify end users, not regulators

29.

Japan’s AI Guidelines are:

a)

Binding law with penalties

b)

Nonbinding but influential

c)

Only applicable to healthcare

d)

Only for government use

30.

Japan encourages GPAI providers to:

a)

Avoid documentation

b)

Maintain documentation and logs and disclose capabilities/limitations

c)

Publish all training data

d)

File with CAC

31.

Japan encourages providers to:

a)

Share no information with downstream deployers

b)

Share information with downstream deployers to enable safe use

c)

Only share marketing brochures

d)

Only share source code

32.

The NIST AI RMF is described as:

a)

Binding law

b)

Nonbinding but widely referenced in federal and state procurement

c)

An EU regulation

d)

A Chinese national standard

33.

When referenced in procurement, the NIST AI RMF typically requires:

a)

Only cost controls

b)

Risk management, documentation and transparency

c)

Only energy disclosure

d)

Only red-teaming

34.

Which set best matches “common global obligations” for GPAI providers?

a)

Only marketing disclosures

b)

Documentation; transparency; detection tools; risk management controls; human oversight support; incident reporting; filing/registration or representative appointment

35.

Which comparative statement is accurate per the module?

a)

China focuses mainly on AI literacy

b)

South Korea emphasises life cycle safety and a domestic representative plus a detailed life cycle safety plan

c)

The EU does not require training data summaries

d)

Japan imposes penalties for noncompliance

36.

A primary GPAI governance challenge is ensuring training data is:

a)

As narrow as possible

b)

High quality and representative across diverse contexts, avoiding bias

c)

Only from one jurisdiction

d)

Always private data

37.

A key risk is that adaptation of a GPAI model to a specific use case may:

a)

Always improve fairness

b)

Compromise integrity or fairness of outputs if not managed

c)

Remove the need for documentation

d)

Eliminate high-risk classification

38.

Which is explicitly cited as a high-risk setting where extra training/adaptation care may be needed?

a)

Video games

b)

Health care or criminal justice

c)

Music generation

d)

Spam filtering

39.

Transparency obligations require GPAI providers to clearly communicate:

a)

Only branding

b)

Intended use, capabilities and limitations to users and deployers

c)

Only employee oversight

d)

Only energy consumption

40.

For high-risk applications of GPAI, automatically generated logs are important for:

a)

Aesthetic design

b)

Traceability and accountability in critical decision-making environments

c)

Reducing compute costs

d)

Avoiding human oversight

41.

The module states organisations must conduct thorough risk assessments for:

a)

Only internal models

b)

External AI products and services, whether integrated or standalone

c)

Only open-source AI

d)

Only government AI

42.

Third-party risk assessment includes evaluating:

a)

Vendor policies, testing results and safety measures to ensure compliance with internal standards

b)

Only vendor marketing

c)

Only the vendor’s share price

d)

Only model popularity