A provider has built a CV-screening system that ranks job applicants, a use listed in Annex III of the EU AI Act. Before it can place the system on the EU market, the governance lead asks what the Act requires as the gateway step that lets the system bear a CE marking. Which requirement is that gateway step?
- ARegistering the deployer's data protection officer with the national supervisory authority for personal data
- BObtaining explicit opt-in consent from every applicant before any ranking decision is produced
- CCompleting a conformity assessment against the high-risk requirements and drawing up the EU declaration of conformity Correct
- DPublishing the model's full training source code and weights in an open repository for inspection
Why A is wrong: A data protection officer relates to GDPR governance and may be relevant separately, but registering one is not the AI Act step that authorises a CE marking on a high-risk system.
Why B is wrong: Consent may matter for the lawful processing of applicant data, yet the AI Act does not make applicant consent the precondition for affixing a CE marking to a high-risk system.
Why C is correct: For a high-risk system the provider must run a conformity assessment against the Chapter III requirements and draw up the EU declaration of conformity, which is what permits the CE marking and lawful placement on the market.
Why D is wrong: Open publication can support transparency in some contexts, but the AI Act does not require disclosing source code and weights as the condition for placing a high-risk system on the market.