A multinational corporation is deploying AI models and must comply with the EU AI Act. The organization's AI security architect needs to classify the risk level of an AI system used for resume screening in the hiring process. Which EU AI Act risk category applies, and what are the resulting compliance obligations?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because under the EU AI Act, AI systems used for recruitment and employment screening—including resume screening, candidate evaluation, and hiring decisions—are classified as 'high-risk' AI systems (listed in Annex III). High-risk AI systems must undergo a conformity assessment, maintain technical documentation, implement a risk management system, ensure data governance, provide human oversight mechanisms, maintain logs for auditability, and be registered in the EU AI systems database.
Full explanation below image
Full Explanation
C is correct because under the EU AI Act, AI systems used for recruitment and employment screening—including resume screening, candidate evaluation, and hiring decisions—are classified as 'high-risk' AI systems (listed in Annex III). High-risk AI systems must undergo a conformity assessment, maintain technical documentation, implement a risk management system, ensure data governance, provide human oversight mechanisms, maintain logs for auditability, and be registered in the EU AI systems database. B is wrong because 'Limited risk' applies to systems like chatbots that must disclose they are AI, but resume screening is explicitly categorized as high risk due to its impact on employment decisions. A is wrong because resume screening is not minimal risk; it directly affects people's livelihoods. D is wrong because resume screening is not prohibited (unacceptable risk is reserved for systems like social scoring, subliminal manipulation, or real-time biometric surveillance in public spaces).