Domain II, first half: old law meets new machines (II.A–II.B)
Lesson 2 of 4 in AIGP Domains I–II Recap: Foundations, Laws, Standards, and Frameworks.
Domain II supplies 19–23 questions, and its first half (II.A privacy law, II.B other existing law — 4–6 questions each) rests on one insight the exam returns to obsessively: AI did not arrive into a legal vacuum. Privacy, IP, anti-discrimination, consumer-protection, and product-liability law all applied to AI systems the day they shipped. The questions test whether you can run an old statute against a new system without flinching.
Each tab below is the exam-relevant skeleton. The flesh — full statutes, cases, and mechanics — lives in Privacy Foundations, NIST/US: Sectoral Enforcement, and Foundations: Harms and Risks.
Privacy (II.A)
The GDPR vocabulary is the test vocabulary: lawful basis for processing training and input data, purpose limitation (data collected for service delivery cannot be silently repurposed for model training), minimization and privacy-by-design applied to systems that want all the data, DPIAs for high-risk processing, controller/processor allocation when a model API sits in the middle, cross-border transfers, and data-subject rights that get genuinely hard against a trained model (delete from a model? — see machine unlearning).
Two guaranteed question magnets: automated decision-making — the right not to be subject to solely automated decisions with legal or similarly significant effects, with its safeguards of human intervention, contestation, and explanation — and biometrics as special-category data (with Illinois BIPA as the US analogue that made Clearview AI and the $650M Facebook settlement into exam-friendly cautionary tales).
IP & copyright (II.B)
Three tested pressure points. Input: does training on scraped copyrighted works infringe? Know the shape of the US fair use fight (NYT v. OpenAI, Andersen v. Stability AI as live examples) and the EU’s text-and-data-mining exception with its machine-readable opt-out — which the EU AI Act’s GPAI copyright-policy duty explicitly references. Output: purely AI-generated works get no US copyright (the human-authorship requirement — Thaler; the Zarya of the Dawn partial registration). Contract: licence terms can prohibit or limit use of data for AI training regardless of what copyright allows.
Nondiscrimination (II.B)
Existing civil-rights law reaches algorithmic decisions in employment, credit, housing, and insurance — no AI-specific statute needed. The load-bearing distinction is disparate treatment (intentional) versus disparate impact (neutral practice, skewed outcome) — AI cases are almost always impact cases, screened with tools like the four-fifths rule. Know the enforcement texture: the EEOC’s iTutorGroup settlement (age discrimination by screening software), Mobley v. Workday (can a vendor be an “agent” of the employer?), and NYC Local Law 144 requiring independent bias audits of automated employment decision tools. Credit adds adverse-action notices: “the algorithm said so” is not a lawful reason.
Consumer protection & product liability (II.B)
UDAP authorities (FTC Act §5 and state analogues) police AI the same way they police everything: were claims deceptive, were practices unfair? Overstated AI marketing (“AI-powered” washing machines that aren’t), undisclosed bots, and models trained on improperly obtained data all fit — and the FTC’s signature AI remedy, algorithmic disgorgement (delete the models built on tainted data, as in the Everalbum and Rite Aid matters), is a favourite exam fact.
Product liability: design defects, manufacturing defects, and failure to warn map onto AI systems — and the EU’s updated Product Liability Directive (2024) explicitly treats software, including AI, as a product, eases the injured party’s burden of proof, and covers post-sale defects from updates and learning. Moffatt v. Air Canada — the airline held to its chatbot’s invented refund policy — is the canonical “your AI’s output is your problem” case.
Key terms: data protection impact assessment, GDPR Article 22, disparate impact, algorithmic disgorgement, fair use, bias audit (NYC LL144)
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.