1. Why do most AI policies fail to control anything?○ They are not enforced with disciplinary measures○ They are written to cover every conceivable misuse, making them long and abstract, so they cannot decide whether a specific thing someone wants to do is allowed○ They are updated too frequently○ They are written by legal rather than technical staff
2. Why do six literal red lines beat two pages about "confidential information"?○ Because shorter documents are legally safer○ Because people can hold six concrete items in their head while working, whereas a category invites argument about whether something falls inside it○ Because categories are unenforceable○ Because regulators require enumerated lists
3. Why must an AI policy state what is explicitly fine, not only what is prohibited?○ To satisfy works council requirements○ Because a policy that only prohibits teaches people the tool is dangerous — and stating what is fine is what makes the prohibitions credible○ Because permitted uses must be logged○ Because it shortens the document
4. What is wrong with placing all AI use in the highest approval tier?○ It breaches the principle of proportionality in law○ It creates a queue, the queue creates delay, and delay creates workarounds that are now invisible○ It requires more governance staff than most organisations have○ Nothing; maximum scrutiny is the safest approach
5. What distinguishes an AI provider from a deployer, and why does it matter?○ Providers are larger organisations; deployers are smaller○ A provider develops and places a system on the market while a deployer uses one under its own authority — deployer obligations are substantially lighter, though naming or substantially modifying a system can make you a provider○ Providers process personal data; deployers do not○ The distinction applies only to high-risk systems
6. On what basis does the EU AI Act's high-risk tier apply?○ The technical sophistication of the model○ The application area — employment, education access, essential services, credit, law enforcement and safety components○ The volume of data processed○ Whether the system uses deep learning
7. Which EU AI Act obligation is most likely to apply to a small organisation that simply uses a bought AI assistant?○ Full high-risk obligations○ The Article 4 AI literacy obligation, which covers deployers as well as providers, has no size exemption, and applied from February 2025○ None — obligations rest with the provider○ Conformity assessment obligations
8. Which four conditions does genuine human oversight require?○ Training, certification, documentation and audit○ Capacity, context, authority and incentive○ Seniority, independence, tenure and clearance○ Speed, accuracy, consistency and coverage
9. A review control shows a 1.5% override rate, an eleven-second median review time, and overrides falling steadily over a year. What does this indicate?○ The system is performing excellently○ The control has stopped producing information — it records agreement rather than review and would read identically whether the system were excellent or degrading○ Reviewers require more training○ The confidence threshold is set too low
10. What does a very quiet incident log usually mean?○ That controls are working effectively○ That people are not reporting — because reporting is inconvenient or unwelcome — which means you have lost your best detection while believing your controls work○ That the systems in use are low risk○ That incidents are being handled locally without escalation