Assess application-level duties: Which missing control is most direct?
GPAI model compliance does not settle the lending application’s duties; the bank must assess the downstream application separately.
The question
Under the EU AI Act, assume all relevant duties apply. A bank uses a general-purpose language model to extract information from financial documents, then deploys a separate application that scores applicants for lending decisions. The GPAI provider’s model-level obligations are satisfied. The bank’s application-level risk classification, documentation, data governance, oversight, and transparency have not been assessed. Which missing control is most direct?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Treat the bank solely as a model providerUsing a GPAI model within a downstream lending application does not automatically make the bank the upstream model provider.
- Assess application-level duties ✓The downstream lending application requires separate assessment because GPAI model compliance does not resolve the application’s high-risk system obligations.
- Repeat the GPAI provider’s copyright policyThe provider’s copyright policy is a model-level obligation and does not assess the bank’s downstream lending application.
- Publish the model’s training summaryA public training summary concerns certain GPAI obligations, while the unresolved facts concern the bank’s application-level duties.
The trap
Separate the model layer from the application layer; downstream use can create independent duties even when GPAI obligations are satisfied. How to remember it
GPAI model compliance does not settle the lending application’s duties; the bank must assess the downstream application separately.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How Laws, Standards and Frameworks Apply to AI questions
- Establish post-market monitoring and incident response: Which missing control is most direct? →
- Add a formal serious-incident reporting and response: What is the most direct missing control? →
- Adopt a copyright-compliance policy: Which control is missing? →
- All 394 Understanding How Laws, Standards and Frameworks Apply to AI questions →
Part of the Certsqill AIGP question bank · Understanding How Laws, Standards and Frameworks Apply to AI ·
Every answer, right and wrong, comes with its own explanation.