← All tools

EPSO/AD/430/26 · Artificial intelligence · AD 8

EPSO artificial intelligence field test: 10 questions, exam pace

The only test that ranks candidates in EPSO/AD/430/26 is a 30-question multiple-choice test on the field, 40 minutes, in your second language. Here are 10 questions in the same format and at the same pace (80 seconds each), covering the three duty areas of the notice: building and operating AI systems, compliant and trustworthy AI, and AI policy.

240 posts · deadline 13 October 2026, 12:00 Brussels · pass mark 15/30 and a ranking

Question 1 of 10Time left1:20

The 80-second clock starts with your first answer.

A company wants to deploy an AI system that infers the emotions of its employees from webcam footage to measure engagement during working hours. Under Article 5 of Regulation (EU) 2024/1689 (AI Act), this is:

Which language do you sit each test in?

Application formAny of the 24 official EU languages
Reasoning tests (verbal, numerical, abstract)L1Your language 1: any of the 24 official EU languages, minimum level C1
Field test (30 questions, 40 min)L2Your language 2: a different one of the remaining 23, minimum level B2
EUFTE essayL2Your language 2

You declare language 1 and language 2 in the application form, by 13 October. Source: Notice of Competition EPSO/AD/430/26, OJ C/2026/4668, section 4.2.

Download the 10 questions as PDF

What the field test covers — the full guide · Competition sheet and deadlines

The ten questions, with answers and sources

The same ten questions with answers and sources, for reading and for search engines. Real questions from the EU-now bank, written from the official texts. No account.

  1. 1. A company wants to deploy an AI system that infers the emotions of its employees from webcam footage to measure engagement during working hours. Under Article 5 of Regulation (EU) 2024/1689 (AI Act), this is:

    • A Permitted as a high-risk use listed in Annex III, subject to a conformity assessment and human oversight.
    • B Permitted, provided the employees give explicit consent under the GDPR and staff representatives are consulted.
    • C Prohibited: emotion inference in the workplace is banned unless it is intended for medical or safety reasons.
    • D Prohibited only where the footage is also used for the remote biometric identification of each employee.
    Correct answer: C

    Article 5(1)(f) of the AI Act prohibits placing on the market, putting into service or using AI systems to infer the emotions of a natural person in the areas of workplace and education institutions, except where the system is intended for medical or safety reasons. Engagement measurement is neither. The Article 5 prohibitions apply since 2 February 2025. Source: Regulation (EU) 2024/1689, Article 5(1)(f) and Article 113.

    • AAnnex III lists emotion recognition as high-risk only where its use is permitted; in the workplace Article 5(1)(f) bans it.
    • BNeither GDPR consent nor consulting staff representatives can lift an AI Act prohibition.
    • CCorrect: banned in the workplace unless for medical or safety reasons.
    • DThe ban does not depend on biometric identification; it targets emotion inference as such.
  2. 2. Under Article 51 of the AI Act, when is a general-purpose AI model presumed to have high-impact capabilities and therefore to present systemic risk?

    • A When it has more than one billion parameters and can competently perform a wide range of distinct tasks.
    • B When the cumulative computation used for its training, measured in floating point operations, exceeds 10^25.
    • C When it is offered to more than 10 000 business users in the Union, even if trained with modest compute.
    • D Only when the AI Board designates it by a two-thirds majority, following a qualified alert from the scientific panel.
    Correct answer: B

    Article 51(2) of the AI Act presumes high-impact capabilities when the cumulative training compute, measured in floating point operations, exceeds 10^25. The Commission may adjust the thresholds by delegated act and may also designate a model on the basis of the criteria in Annex XIII. Providers of such models carry the additional obligations of Article 55 (evaluation, adversarial testing, incident reporting, cybersecurity). Source: Regulation (EU) 2024/1689, Articles 51 and 55.

    • AGenerality makes a model general-purpose; the systemic-risk presumption rests on training compute, not on parameter count.
    • BCorrect: more than 10^25 FLOP of cumulative training compute.
    • CReach is an Annex XIII criterion the Commission weighs when designating a model; it does not trigger the Article 51(2) presumption.
    • DDesignation is a Commission decision, ex officio or after a qualified alert from the scientific panel; the Board does not vote on it.
  3. 3. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amended the calendar of the AI Act. From when do the requirements of Chapter III, Sections 1 to 3, apply to a high-risk AI system listed in Annex III, such as a recruitment tool?

    • A 2 August 2026, the original date, which the Omnibus left unchanged for Annex III systems.
    • B 2 February 2025, together with the prohibited practices and the AI literacy obligation.
    • C 2 August 2028 for all high-risk systems, whether they fall under Annex III or Annex I.
    • D 2 December 2027; product-embedded systems under Annex I follow on 2 August 2028.
    Correct answer: D

    The Digital Omnibus on AI replaces the application date of Chapter III, Sections 1, 2 and 3 (except Article 6(5)) with 2 December 2027 for AI systems classified as high-risk under Article 6(2) and Annex III, and 2 August 2028 for those classified under Article 6(1) and Annex I. Prohibited practices and the AI literacy duty have applied since 2 February 2025. Source: Regulation (EU) 2026/1744, amending Article 113 of Regulation (EU) 2024/1689.

    • A2 August 2026 was the original date; the Omnibus moved it.
    • BFebruary 2025 is the date of Chapters I and II (prohibitions, AI literacy), not of the high-risk requirements.
    • C2028 applies only to Annex I product-embedded systems.
    • DCorrect: 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
  4. 4. A ministry uses a generative AI system to produce a realistic video of a spokesperson reading a statement, and a chatbot to answer citizens. Which Article 50 AI Act obligations apply, and to whom?

    • A The provider must mark outputs as AI-generated; the ministry must disclose the deep fake; chatbot users must be told it is an AI.
    • B The ministry must register both systems in the EU database for high-risk AI and carry out a fundamental rights impact assessment.
    • C No obligation applies, because public authorities communicating with citizens are exempt from the transparency duties of Article 50.
    • D The ministry must obtain the spokesperson's GDPR consent and label the chatbot; the generative system's provider has no duty of its own.
    Correct answer: A

    Article 50 allocates duties by role: providers of systems generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated; deployers of deep fakes must disclose that the content was artificially generated or manipulated; and providers must ensure that people interacting with an AI system are informed of it, unless obvious. The Commission's guidelines and the Code of Practice on transparency of AI-generated content (2026) detail these obligations, which apply from 2 August 2026. Source: Regulation (EU) 2024/1689, Article 50.

    • ACorrect: marking (provider), deep-fake disclosure (deployer), chatbot disclosure.
    • BEU-database registration and the fundamental rights impact assessment are high-risk obligations, not Article 50 transparency duties.
    • CArticle 50 has no public-authority exemption.
    • DConsent is a data-protection question, and Article 50(2) puts a marking duty on the provider of the generative system.
  5. 5. Since the Digital Omnibus on AI (Regulation (EU) 2026/1744), what does Article 4 of the AI Act require of an organisation that deploys AI systems?

    • A To have every employee who uses AI certified through an accredited training programme by 2 August 2026 at the latest.
    • B To take measures that support the AI literacy of staff dealing with AI, with no level guaranteed per person.
    • C To ensure that every member of staff dealing with AI systems reaches, and keeps, a sufficient level of AI literacy.
    • D Nothing yet: Article 4 applies only together with the high-risk requirements, from 2 December 2027.
    Correct answer: B

    The Digital Omnibus on AI replaced Article 4: providers and deployers must take measures to support the development of AI literacy of their staff and of other persons dealing with the operation and use of AI systems on their behalf, taking into account their knowledge, experience, education and training and the context of use. The obligation does not require them to guarantee any specific level of AI literacy of any individual, and the Commission and the Member States must support these efforts, in particular those of SMEs. Article 4 sits in Chapter I, which has applied since 2 February 2025. Source: Regulation (EU) 2024/1689, Articles 4 and 113, as amended by Regulation (EU) 2026/1744.

    • ANo certification or accredited programme is required; the measures depend on the staff and the context of use.
    • BCorrect: supporting measures, with no specific level of AI literacy guaranteed for any individual.
    • CThat was the original 2024 wording (a sufficient level); the Omnibus replaced it with a duty to support AI literacy.
    • DArticle 4 is in Chapter I, which has applied since February 2025, independent of the high-risk calendar.
  6. 6. The Ethics Guidelines for Trustworthy AI of the High-Level Expert Group (2019) list seven key requirements. Which set is correct?

    • A Human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; environmental and societal well-being; accountability.
    • B Respect for human autonomy; prevention of harm; fairness; explicability; lawfulness; adherence to ethical principles and values; technical and social robustness.
    • C Valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; fair with harmful bias managed.
    • D Risk management system; data and data governance; technical documentation; record-keeping; transparency and provision of information to deployers; human oversight; accuracy, robustness and cybersecurity.
    Correct answer: A

    The Guidelines derive seven requirements from the principles of respect for human autonomy, prevention of harm, fairness and explicability: human agency and oversight; technical robustness and safety; privacy and data governance; transparency; diversity, non-discrimination and fairness; environmental and societal well-being; and accountability. ALTAI (2020) turns them into a self-assessment list. Source: HLEG, Ethics Guidelines for Trustworthy AI, Chapter II.

    • ACorrect: the seven HLEG requirements.
    • BThese are the four ethical principles and the three components of trustworthy AI (lawful, ethical, robust), from which the seven requirements derive.
    • CThese are the seven characteristics of trustworthy AI in the NIST AI RMF 1.0, a different framework.
    • DThese are the titles of the AI Act's high-risk requirements, Articles 9 to 15 (Chapter III, Section 2).
  7. 7. In the NIST AI Risk Management Framework 1.0, how do the core functions relate to each other?

    • A Seven requirements inherited from the EU Ethics Guidelines, applied one after another in a fixed order.
    • B Six functions — Govern, Identify, Protect, Detect, Respond and Recover — applied to AI systems.
    • C Three sequential phases — design, deployment and decommissioning — each with a mandatory audit.
    • D Four functions — Govern, Map, Measure and Manage — with Govern cross-cutting the other three.
    Correct answer: D

    The AI RMF Core organises risk management activities into four functions: Govern, Map, Measure and Manage. Governance is designed as a cross-cutting function that informs and is infused throughout the other three; the functions are not a fixed sequence. The generative AI profile (NIST AI 600-1) adds GenAI-specific risks and actions on the same structure. Source: NIST AI 100-1, section 5.

    • AThe seven requirements are the EU HLEG's, a different framework.
    • BThose six are the Cybersecurity Framework 2.0 functions.
    • CThe RMF is organised by functions, not by mandatory audited phases.
    • DCorrect: four functions, Govern cross-cutting.
  8. 8. According to EDPB Opinion 28/2024, when can an AI model trained with personal data be considered anonymous, and how should a controller justify legitimate interest as the legal basis for training?

    • A Any model is anonymous once training ends, because its weights are not personal data; legitimate interest then applies automatically to scientific research.
    • B A model is anonymous if its training data were pseudonymised before use, and the consent of each data subject is the only valid legal basis for training.
    • C Anonymity is assessed case by case, on how likely personal data can be extracted or obtained by queries; legitimate interest needs the three-step test.
    • D Anonymity is certified by the AI Office under the AI Act, and once a model is certified its training falls outside the GDPR altogether.
    Correct answer: C

    The Opinion states that AI models trained with personal data cannot in all cases be considered anonymous: claims of anonymity are assessed case by case, looking at the likelihood of direct extraction of personal data from the model and of obtaining it through queries. For legitimate interest it recalls the three-step test: identify the legitimate interest, analyse the necessity of the processing, and balance it against the data subjects' interests and rights. Source: EDPB Opinion 28/2024 of 17 December 2024.

    • ANeither automatic anonymity nor automatic legitimate interest exists in the Opinion.
    • BPseudonymisation is not anonymisation, and consent is not the only basis.
    • CCorrect: case-by-case anonymity and the three-step test.
    • DThe AI Office does not certify anonymity; the GDPR applies to training on personal data.
  9. 9. A retrieval-augmented generation (RAG) assistant reads documents from a shared drive to answer staff questions. An attacker plants a document containing hidden instructions that the assistant later follows. In the OWASP Top 10 for LLM Applications 2025, which risk categories does this scenario illustrate?

    • A Indirect prompt injection via the retrieved content, and vector and embedding weaknesses in the RAG pipeline.
    • B Model theft and denial of service, since the planted document lets the attacker copy and overload the model.
    • C A GDPR data breach only, to be handled by the data protection officer and outside the scope of application security.
    • D Data and model poisoning, since the planted document is absorbed into the model's weights when it is retrieved.
    Correct answer: A

    OWASP lists Prompt Injection as LLM01:2025, including indirect injection where instructions arrive through content the model processes, and Vector and Embedding Weaknesses as LLM08:2025 for risks in retrieval-augmented pipelines. Retrieved content does not change the model's weights, so it is not training data poisoning. NIST AI 100-2 (2025) uses the same distinction between inference-time and training-time attacks. Source: OWASP Top 10 for LLM Applications 2025; NIST AI 100-2e2025.

    • ACorrect: indirect prompt injection plus RAG vector/embedding weaknesses.
    • BNothing is stolen or overloaded in the scenario.
    • CIt may also be a data protection issue, but the security categories still apply.
    • DPoisoning targets training or fine-tuning data; a retrieved document acts at inference time and leaves the weights unchanged.
  10. 10. Which pair of measures correctly matches the Commission's 2025 AI policy documents?

    • A Both are Council recommendations of 2024, on AI skills in schools and on AI in public administration.
    • B AI Continent Action Plan: the ban on emotion recognition; Apply AI Strategy: the 10^25 FLOP threshold for systemic-risk models.
    • C AI Continent Action Plan: creation of the AI Office; Apply AI Strategy: the Code of Practice for general-purpose AI models.
    • D AI Continent Action Plan: AI Factories and Gigafactories; Apply AI Strategy: 'AI first', building on European solutions.
    Correct answer: D

    The AI Continent Action Plan of 9 April 2025 sets out to scale public AI infrastructure, strengthening the network of AI Factories and establishing AI Gigafactories inspired by the CERN model, alongside data, skills and adoption measures. The Apply AI Strategy of 8 October 2025 promotes an 'AI first' policy so that companies and public sector organisations integrate AI building on European solutions. The prohibitions, the FLOP threshold, the AI Office and the Code of Practice belong to the AI Act framework. Source: COM(2025) 165 final; COM(2025) 723 final.

    • ABoth are Commission communications of 2025, not Council recommendations.
    • BThose are AI Act provisions, not policy communications.
    • CThe AI Office was established by Commission decision in 2024 and the Code of Practice is an AI Act instrument.
    • DCorrect: AI Factories and Gigafactories; 'AI first'.

Every explanation cites the official text it is drawn from: the Notice of Competition C/2026/4668 and the regulations, NIST and ENISA publications listed on the field guide.