A multi-national company is deploying the same AI hiring model across operations in the United States, European Union, and Brazil. The AI risk team must ensure compliance with employment AI regulations in all jurisdictions. Which approach BEST manages cross-jurisdictional AI compliance risk?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because multi-jurisdictional AI compliance requires understanding each jurisdiction's specific requirements (EU AI Act + GDPR, U.S. EEOC/CFPB/state AI laws, Brazil LGPD + employment laws) and implementing controls that satisfy all applicable requirements.
Full explanation below image
Full Explanation
B is correct because multi-jurisdictional AI compliance requires understanding each jurisdiction's specific requirements (EU AI Act + GDPR, U.S. EEOC/CFPB/state AI laws, Brazil LGPD + employment laws) and implementing controls that satisfy all applicable requirements. In practice, this often means implementing the most stringent requirements across all jurisdictions where they do not conflict. Using only the most permissive framework (A) creates compliance failures in stricter jurisdictions. EU-only legal opinion (C) misses U.S. and Brazilian requirements. Limiting deployment to explicitly permitted jurisdictions (D) may be unnecessarily restrictive and overlooks jurisdictions where use is regulated but permitted with appropriate controls.