Courseiva
AI Governance and Ethics →hardMultiple Select

AI0-001 AI Governance and Ethics Practice Question

A company is deploying an AI system that falls under the EU AI Act's high-risk category. Which THREE requirements must the company fulfill?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure human oversight to prevent or minimise risks

The EU AI Act for high-risk systems requires risk management, human oversight, and transparency documentation. Open-sourcing the model is not required; obtaining consent is not a specific requirement for high-risk systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ensure human oversight to prevent or minimise risks

    Why this is correct

    High-risk systems must be designed so natural persons can effectively oversee them, including the ability to intervene, override or halt operation. Human oversight detects and mitigates emerging risks during real-world use, directly fulfilling the EU AI Act's requirement to prevent or minimise harm.

  • ✗

    Obtain explicit consent from all affected individuals

    Why it's wrong here

    Explicit consent is a GDPR lawful-basis concept for processing personal data, not an EU AI Act high-risk obligation. Consent feels intuitive because affected individuals are involved, and it would be the correct route where no other lawful basis applies, but the Act instead requires risk management, data governance, technical documentation and human oversight.

  • ✗

    Open-source the model's code to the public

    Why it's wrong here

    Publishing model code is not mandated; the EU AI Act obliges providers to supply technical documentation, logging and conformity assessment to authorities, not public disclosure. Open-sourcing is tempting as a transparency gesture, and it is a legitimate choice for non-high-risk or research models, but it is not a high-risk requirement.

  • ✓

    Create and maintain technical documentation including the system's intended purpose

    Why this is correct

    High-risk providers must draw up technical documentation covering the system's intended purpose, design, data and performance, enabling conformity assessment and regulator scrutiny. This documented record evidences compliance with the EU AI Act's obligations before the system is placed on the market.

  • ✓

    Establish a risk management system throughout the AI system's lifecycle

    Why this is correct

    Continuous, iterative risk management across the entire lifecycle is a mandatory EU AI Act obligation for high-risk systems, requiring identification, evaluation and mitigation of risks at every stage from design through deployment and post-market monitoring.

About these practice questions

One of 962 original AI0-001 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.