Master EU AI Act vocabulary: risk tiers, prohibited AI, conformity assessment, high-risk AI system classification.
0 / 22 completed
1 / 22
Under the EU AI Act, which category of AI system faces the strictest requirements?
High-risk AI systems (used in critical infrastructure, healthcare, education, employment) face the strictest requirements: conformity assessment, logging, human oversight, and transparency obligations.
2 / 22
The EU AI Act 'conformity assessment' requires AI providers to:
Conformity assessment is the process of demonstrating an AI system meets EU AI Act requirements — similar to CE marking for physical products.
3 / 22
Which type of AI system is prohibited under the EU AI Act?
The EU AI Act prohibits AI systems that use subliminal manipulation, exploit vulnerabilities, enable mass social scoring by governments, and certain biometric categorisation systems.
4 / 22
An 'AI system card' or 'transparency obligation' for limited-risk AI requires:
Limited-risk AI systems (chatbots, deepfakes) have transparency obligations — users must know when they are interacting with AI so they can make informed decisions.
5 / 22
The EU AI Act defines GPAI (General Purpose AI) models as those that:
GPAI models (like large language models) are capable of many tasks across domains. The Act imposes specific transparency, risk assessment, and copyright compliance requirements on their providers.
6 / 22
Code Review Comment
During a code review of the new image recognition API integration, Sarah flagged a section in Mark's code. She commented: 'This system is classified as 'High Risk' based on its potential impact on fundamental rights – specifically, it could be used to unfairly discriminate against individuals. To ensure compliance with the EU AI Act, we need to thoroughly document all data sources and mitigation strategies.'
Which of the following best represents Sarah's meaning in this context?
Sarah is referring to the classification of AI systems under the EU AI Act. 'High Risk' AI – which includes systems like this image recognition API when deployed in sensitive areas (e.g., law enforcement or social scoring) – faces stringent requirements for risk management and documented safeguards. The key is demonstrating compliance with the EU AI Act's criteria, not just following general coding practices; failing to do so could lead to significant legal ramifications.
7 / 22
As a senior developer, you're drafting a PR description for an AI model used in fraud detection. The model utilizes transaction data to identify suspicious patterns. You need to include information relevant to the EU AI Act's transparency obligations. Which of the following statements is MOST accurate?
The EU AI Act mandates transparency regarding AI systems. Describing just the functionality (option 1) isn't sufficient. Providing details about the training data and bias mitigation techniques – as part of an 'AI system card'— demonstrates compliance with documentation requirements outlined in the Act. Accuracy rates, while relevant, are secondary to demonstrating explainability.
8 / 22
During a standup meeting, David explains his work on a new AI-powered chatbot designed for customer support. He states: 'We're using a GPAI model to generate responses and personalize the interaction.'
Which of the following accurately reflects the EU AI Act's definition of this GPAI model?
The EU AI Act defines GPAI models (General Purpose AI) as those that aren't restricted to a specific use case. David's description – 'generating responses and personalizing interaction'– aligns with this definition. This allows for a less stringent regulatory approach compared to systems with narrowly defined applications, although ongoing monitoring is still required.
9 / 22
Code Review Comment
During a code review of the new image recognition API integration, Sarah flagged a section in Mark's code. She commented: 'This system is classified as 'High Risk' based on its potential impact on fundamental rights – specifically, it could be used to unfairly discriminate against individuals. To ensure compliance with the EU AI Act, we need to thoroughly document all data sources and mitigation strategies.'
Which of the following best represents Sarah's meaning in this context?
Sarah is referring to the classification of AI systems under the EU AI Act. 'High Risk' AI – which includes systems like this image recognition API when deployed in sensitive areas (e.g., law enforcement or social scoring) – faces stringent requirements for risk management and documented safeguards. The key is demonstrating compliance with the EU AI Act's criteria, not just following general coding practices; failing to do so could lead to significant legal ramifications.
10 / 22
As a senior developer, you're drafting a PR description for an AI model used in fraud detection. The model utilizes transaction data to identify suspicious patterns. You need to include information relevant to the EU AI Act's transparency obligations. Which of the following statements is MOST accurate?
The EU AI Act mandates transparency regarding AI systems. Describing just the functionality (option 1) isn't sufficient. Providing details about the training data and bias mitigation techniques – as part of an 'AI system card'— demonstrates compliance with documentation requirements outlined in the Act. Accuracy rates, while relevant, are secondary to demonstrating explainability.
11 / 22
During a standup meeting, David explains his work on a new AI-powered chatbot designed for customer support. He states: 'We're using a GPAI model to generate responses and personalize the interaction.'
Which of the following accurately reflects the EU AI Act's definition of this GPAI model?
The EU AI Act defines GPAI models (General Purpose AI) as those that aren't restricted to a specific use case. David's description – 'generating responses and personalizing interaction'– aligns with this definition. This allows for a less stringent regulatory approach compared to systems with narrowly defined applications, although ongoing monitoring is still required.
12 / 22
Code Review Comment
During a code review of the new image recognition API integration, Sarah flagged a section in Mark's code. She commented: 'This system is classified as 'High Risk' based on its potential impact on fundamental rights – specifically, it could be used to unfairly discriminate against individuals. To ensure compliance with the EU AI Act, we need to thoroughly document all data sources and mitigation strategies.'
Which of the following best represents Sarah's meaning in this context?
Sarah is referring to the classification of AI systems under the EU AI Act. 'High Risk' AI – which includes systems like this image recognition API when deployed in sensitive areas (e.g., law enforcement or social scoring) – faces stringent requirements for risk management and documented safeguards. The key is demonstrating compliance with the EU AI Act's criteria, not just following general coding practices; failing to do so could lead to significant legal ramifications.
13 / 22
As a senior developer, you're drafting a PR description for an AI model used in fraud detection. The model utilizes transaction data to identify suspicious patterns. You need to include information relevant to the EU AI Act's transparency obligations. Which of the following statements is MOST accurate?
The EU AI Act mandates transparency regarding AI systems. Describing just the functionality (option 1) isn't sufficient. Providing details about the training data and bias mitigation techniques – as part of an 'AI system card'— demonstrates compliance with documentation requirements outlined in the Act. Accuracy rates, while relevant, are secondary to demonstrating explainability.
14 / 22
During a standup meeting, David explains his work on a new AI-powered chatbot designed for customer support. He states: 'We're using a GPAI model to generate responses and personalize the interaction.'
Which of the following accurately reflects the EU AI Act's definition of this GPAI model?
The EU AI Act defines GPAI models (General Purpose AI) as those that aren't restricted to a specific use case. David's description – 'generating responses and personalizing interaction'– aligns with this definition. This allows for a less stringent regulatory approach compared to systems with narrowly defined applications, although ongoing monitoring is still required.
15 / 22
Code Review Comment
During a code review of the new image recognition API integration, Sarah flagged a section in Mark's code. She commented: 'This system is classified as 'High Risk' based on its potential impact on fundamental rights – specifically, it could be used to unfairly discriminate against individuals. To ensure compliance with the EU AI Act, we need to thoroughly document all data sources and mitigation strategies.'
Which of the following best represents Sarah's meaning in this context?
Sarah is referring to the classification of AI systems under the EU AI Act. 'High Risk' AI – which includes systems like this image recognition API when deployed in sensitive areas (e.g., law enforcement or social scoring) – faces stringent requirements for risk management and documented safeguards. The key is demonstrating compliance with the EU AI Act's criteria, not just following general coding practices; failing to do so could lead to significant legal ramifications.
16 / 22
As a senior developer, you're drafting a PR description for an AI model used in fraud detection. The model utilizes transaction data to identify suspicious patterns. You need to include information relevant to the EU AI Act's transparency obligations. Which of the following statements is MOST accurate?
The EU AI Act mandates transparency regarding AI systems. Describing just the functionality (option 1) isn't sufficient. Providing details about the training data and bias mitigation techniques – as part of an 'AI system card'— demonstrates compliance with documentation requirements outlined in the Act. Accuracy rates, while relevant, are secondary to demonstrating explainability.
17 / 22
During a standup meeting, David explains his work on a new AI-powered chatbot designed for customer support. He states: 'We're using a GPAI model to generate responses and personalize the interaction.'
Which of the following accurately reflects the EU AI Act's definition of this GPAI model?
The EU AI Act defines GPAI models (General Purpose AI) as those that aren't restricted to a specific use case. David's description – 'generating responses and personalizing interaction'– aligns with this definition. This allows for a less stringent regulatory approach compared to systems with narrowly defined applications, although ongoing monitoring is still required.
18 / 22
During a code review of the new facial recognition system for employee access control, Emily commented to Liam: 'To comply with the EU AI Act, we need to ensure this system meets the requirements for 'Transparency and Explainability' regarding its decision-making process. Specifically, users should be able to understand why they were denied access.' Considering this comment, which of the following best describes the key principle Emily is referencing?
Emily is referring to *explainability*, which is a core requirement of the EU AI Act for 'High Risk' systems. The Act mandates that users should be able to understand how decisions are made, promoting accountability and trust. Options A, B, and C represent other important aspects of AI risk management but aren't directly related to Emily's comment about understanding the system's reasoning.
19 / 22
You're part of a team developing an AI-powered recommendation engine for e-commerce. During a discussion in a Slack channel, Alex says: 'We're using a 'Limited Risk' AI system to personalize product recommendations based on browsing history and purchase data. We've documented the model's limitations and potential biases and are regularly monitoring its performance.' Which of the following statements best reflects Alex's understanding of the EU AI Act's requirements for this scenario?
Alex correctly understands that *Limited Risk* AI systems have fewer obligations than 'High Risk' ones. While monitoring is crucial, the core difference lies in the scope of requirements – focusing on performance and documented limitations rather than full transparency or extensive risk assessments. Option A is incorrect because Limited Risk systems are subject to certain obligations; Option C is too strong a statement about immediate action; and Option D misrepresents the Act's overall principles.
20 / 22
As a lead developer, you're preparing a PR description for an AI model used to predict customer churn. The model analyzes various data points including engagement metrics and support tickets. You need to highlight relevant aspects for the EU AI Act's requirements. Which of the following should be included in your PR description?
The PR description must address *potential biases*, as this is a key requirement for 'High Risk' AI systems under the EU AI Act. Transparency around algorithmic decisions and mitigation strategies are essential components of responsible AI development. While GDPR compliance is important, it's not directly addressed in the Act's requirements for AI risk management; Option A is too technical and unnecessary for a PR description, and Option D lacks critical contextual information.
21 / 22
During a daily stand-up meeting, Sarah reports: 'I'm building an AI chatbot designed to answer frequently asked questions about our company's services. We're using a 'General Purpose AI' model – specifically, a large language model – and fine-tuning it on our internal documentation.' Considering this update, what does Sarah primarily need to address regarding the EU AI Act?
The EU AI Act defines *GPAI (General Purpose AI) models* as those that are not specifically designed for a particular use case. While all GPAIs require attention to potential risks, the key focus is on ensuring robust monitoring and bias mitigation strategies due to their broader applicability and potential for unforeseen harms – this is what triggers additional obligations under the Act. Options A, B, and C represent related concerns but aren't the primary area of focus in this scenario.
22 / 22
Reviewing a code change for an AI-powered diagnostic tool used in medical imaging, David leaves a comment: 'This system is classified as 'High Risk' because it could directly affect individuals' health and well-being. We need to ensure the model's decisions are explainable and auditable to maintain patient trust.' Which of the following best reflects David's primary concern regarding the EU AI Act?
David's comment highlights the importance of *risk assessment* – this is a core requirement for 'High Risk' AI systems under the EU AI Act. The system's potential impact on individuals' health and well-being necessitates thorough risk evaluation and mitigation strategies before deployment. While accuracy, GDPR compliance, and automated testing are important considerations, they are secondary to David's primary concern about managing the inherent risks.
This is an AI Ethics exercise set. It walks through 22 scenario-based multiple-choice questions built around real usage of AI Ethics terminology that IT professionals encounter on the job.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to complete with no account, sign-up, or paywall.
How many questions are in this exercise?
This set contains 22 questions. Each one shows immediate feedback and a detailed explanation after you answer, so you learn the correct usage right away rather than waiting for a final score.
Do I need prior experience to complete this exercise?
No prior experience is required. Each question includes a full explanation covering the reasoning behind the correct answer, so the exercise itself teaches the AI Ethics vocabulary as you go.
Can I retry the exercise if I get questions wrong?
Yes — use the "Try again" button on the results screen to reset your answers and go through all the questions again. There is no limit on attempts.
Is my progress saved?
Your answers and score for the current session are tracked in the browser as you go. No account or login is needed, and there is nothing to install.
What if I don't understand a term used in a question?
Read the explanation shown after you answer each question — it breaks down the correct term in plain English with a real-world example. You can also check the site Glossary for quick definitions.
How is this different from reading a blog article on the topic?
Exercises like this one are interactive drills that test and reinforce specific vocabulary through multiple-choice questions, while blog articles explain concepts in prose. Practising here after reading builds active recall, not just passive recognition.
Where can I find more AI Ethics exercises?
See the AI Ethics exercises hub for the full set of related pages, or browse all exercise categories from the main Exercises index.
Can I use this exercise to prepare for a technical interview?
Yes — AI Ethics vocabulary comes up often in technical discussions and interviews. Pair this exercise with our dedicated Interview Preparation section for role-specific practice.