AI0-001 AI Governance and Ethics Practice Question
A company is deploying an AI system that falls under the EU AI Act's high-risk category. Which THREE requirements must the company fulfill?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure human oversight to prevent or minimise risks
The EU AI Act for high-risk systems requires risk management, human oversight, and transparency documentation. Open-sourcing the model is not required; obtaining consent is not a specific requirement for high-risk systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure human oversight to prevent or minimise risks
Why this is correct
High-risk systems must be designed so natural persons can effectively oversee them, including the ability to intervene, override or halt operation. Human oversight detects and mitigates emerging risks during real-world use, directly fulfilling the EU AI Act's requirement to prevent or minimise harm.
- ✗
Obtain explicit consent from all affected individuals
Why it's wrong here
Explicit consent is a GDPR lawful-basis concept for processing personal data, not an EU AI Act high-risk obligation. Consent feels intuitive because affected individuals are involved, and it would be the correct route where no other lawful basis applies, but the Act instead requires risk management, data governance, technical documentation and human oversight.
- ✗
Open-source the model's code to the public
Why it's wrong here
Publishing model code is not mandated; the EU AI Act obliges providers to supply technical documentation, logging and conformity assessment to authorities, not public disclosure. Open-sourcing is tempting as a transparency gesture, and it is a legitimate choice for non-high-risk or research models, but it is not a high-risk requirement.
- ✓
Create and maintain technical documentation including the system's intended purpose
Why this is correct
High-risk providers must draw up technical documentation covering the system's intended purpose, design, data and performance, enabling conformity assessment and regulator scrutiny. This documented record evidences compliance with the EU AI Act's obligations before the system is placed on the market.
- ✓
Establish a risk management system throughout the AI system's lifecycle
Why this is correct
Continuous, iterative risk management across the entire lifecycle is a mandatory EU AI Act obligation for high-risk systems, requiring identification, evaluation and mitigation of risks at every stage from design through deployment and post-market monitoring.
About these practice questions
One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.