An organization reviews a random sample of an AI writing assistant's outputs every month rather than approving each output beforehand. What is this oversight model called, and when is it appropriate?
- A.Post-hoc (after-the-fact) review; appropriate for low-risk, high-volume uses where pre-approving each output is impractical and errors are correctable
- B.Human-on-the-loop; appropriate only for robotics; the EU AI Act's high-risk category covers only systems that make fully automated final decisions, and any human clicking approve removes the classification
- C.Human-in-the-loop; appropriate for safety-critical decisions
- D.Zero-trust oversight; appropriate for all AI systems
Why A is correct
Sampling outputs after the fact is post-hoc review, the lightest oversight tier: it suits high-volume, low-stakes content where mistakes can be corrected without serious harm, and it generates trend data for governance reporting. Human-in-the-loop is the opposite pattern (pre-approval of each decision), "zero-trust oversight" is not a recognized oversight model, and on-the-loop describes live monitoring with intervention authority rather than retrospective sampling.
Know someone studying for AI Security Fundamentals? Send them this one.