Domain II, second half: AI-specific law and the framework stack (II.C–II.D)
Lesson 3 of 4 in AIGP Domains I–II Recap: Foundations, Laws, Standards, and Frameworks.
II.C (6–8 questions) is the EU AI Act’s home turf, with the South Korean AI Basic Law and US state laws as supporting cast. This academy teaches the Act canonically across eight EU AI Act modules — the recap here is only the exam’s skeleton of it:
- Risk classification: prohibited practices (social scoring, exploitative manipulation, most real-time remote biometric ID, emotion recognition at work and school…) → high risk via Annex III use cases and regulated products, with the Article 6(3) filter → limited-risk transparency duties (chatbots, deepfakes) → minimal risk. Taught in: Prohibited Practices; High-Risk Classification.
- High-risk requirements: risk management, data governance, technical documentation, record keeping, instructions for use, human oversight, accuracy-robustness-cybersecurity — plus the provider’s conformity assessment and CE marking and the deployer’s duties (oversight, input data, monitoring, and fundamental-rights impact assessments for some deployers). Taught in: High-Risk Requirements; Conformity and Standards.
- GPAI: documentation and copyright-policy duties for all model providers; the systemic risk (GPAI) tier presumed at 10²⁵ FLOPs of training compute with added evaluation, incident-reporting, and cybersecurity duties. Taught in: Transparency and GPAI.
- Roles and enforcement: provider / deployer / importer (AI Act) / distributor (AI Act) duty ladders and Article 25 role-switching; fines tiered up to €35M or 7% of global turnover for prohibited practices, €15M/3% for most other violations, €7.5M/1% for supplying misleading information; market surveillance authorities and the AI Office. Taught in: Value Chain; Governance and Enforcement.
II.D (3–5 questions) is the framework stack, and its questions are nearly always the same move: which instrument, and which part of it, does this scenario call for? The OECD AI Principles give the shared vocabulary (and the AI-system definition the EU AI Act adopted); the NIST AI RMF gives a voluntary risk process (Govern–Map–Measure–Manage, plus the Playbook and the Generative AI Profile); and three ISO standards divide the labour — 22989 defines the words, 42001 defines the management system you can certify against, and 42005 defines the impact-assessment process.
| Instrument | What it is | What the exam asks about it | The trap |
|---|---|---|---|
OECD AI Principles (2019, rev. 2023) | Intergovernmental principles — the first, and the source of the near-universal AI-system definition | Recognise the principles (human-centred values, transparency, robustness, accountability, inclusive growth) and that the EU AI Act borrowed the OECD definition | Not binding law, and not a process framework — it tells you what good looks like, not how |
NIST AI RMF 1.0 (2023) + Playbook + GenAI Profile | Voluntary US risk-management process framework | Name the four functions — Govern (cross-cutting culture) wrapped around Map → Measure → Manage — and place an activity in the right one | “Voluntary” is load-bearing: no certification, no penalties. Candidates who answer “fined for violating the NIST RMF” fail that question |
ISO/IEC 22989 (2022) | AI concepts and terminology standard | Pure vocabulary questions — which standard defines the shared language | It imposes zero obligations; it only defines terms |
ISO/IEC 42001 (2023) | AI management-system standard (AIMS) — Plan-Do-Check-Act, the “ISO 27001 of AI” | It is the certifiable one: organisations can be audited and certified against it, and it can evidence (not presume) EU AI Act readiness | Certification ≠ legal compliance — a 42001 certificate is not a conformity assessment under the AI Act |
ISO/IEC 42005 (2025) | AI system impact assessment guidance | The standard to name when a scenario needs a structured harms-to-people assessment process | Guidance, not certifiable requirements — and distinct from a DPIA |
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.