mediumMultiple Select
AIF-C01 Practice Question: A hospital is deploying an AI system to assist in…
A hospital is deploying an AI system to assist in diagnosing diseases from medical images. According to the EU AI Act, this system may be classified as high-risk. Which THREE requirements should the hospital address to comply with the EU AI Act for high-risk AI systems?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure transparency and provision of information to users
The EU AI Act requires high-risk systems to have risk management, transparency, and human oversight among other requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure transparency and provision of information to users
Why this is correct
The EU AI Act requires high-risk systems to be sufficiently transparent, with clear instructions and information supplied to deployers. For a diagnostic imaging tool, informing clinicians about capabilities, limitations and intended purpose satisfies this requirement, enabling informed, safe use.
- ✓
Establish a risk management system throughout the lifecycle
Why this is correct
The EU AI Act mandates a continuous, iterative risk management system across the entire lifecycle of high-risk systems. For a medical imaging diagnostic tool, this satisfies the compliance requirement by identifying, evaluating and mitigating risks at every stage, from development through deployment and monitoring.
- ✓
Enable human oversight to prevent or minimize risks
Why this is correct
High-risk AI systems under the EU AI Act must be designed to allow effective human oversight, enabling operators to intervene or halt outputs. In disease diagnosis, clinician review of AI-generated findings satisfies this requirement, preventing or minimising risks to patient safety.
- ✗
Use only open-source models
Why it's wrong here
The EU AI Act imposes obligations on providers and deployers regardless of licence type, so mandating open-source models addresses no Article 9-15 requirement such as risk management, data governance, logging or human oversight. It tempts because open weights appear to offer transparency, and open-source would be the right choice where auditability of the model internals is the stated goal.
- ✗
Deploy the system without any testing in a sandbox environment
Why it's wrong here
Deploying without sandbox testing removes the very validation the Act requires; high-risk systems need testing against predefined metrics and real-world conditions before deployment. It tempts because sandboxing sounds like an optional extra step, and a controlled sandbox would be the correct choice when validating a model's behaviour before releasing it to clinical use.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AIF-C01 question from scratch — 862 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.