The big law matrix — and the which-law gauntlet
Lesson 4 of 4 in AIGP Domains I–II Recap: Foundations, Laws, Standards, and Frameworks.
Here is Domain II compressed into one table: every instrument the BoK names, what the exam actually tests about it, and the module that teaches it properly. Print this mentally. When a practice question stumps you, the failure is almost always in one cell of this matrix.
| Instrument | What AIGP tests about it | Classic trap | Study module |
|---|---|---|---|
GDPR / privacy law generally | Lawful basis for training data; purpose limitation on repurposing; minimization vs data-hungry systems; DPIAs; controller/processor roles; transfers; data-subject rights against models | Assuming “publicly available” data is free to use — scraping still processes personal data (Clearview AI fines across the EU) | Privacy Foundations (Special Topics) |
GDPR Article 22 (automated decision-making) | When the right not to be subject to solely automated decisions bites: solely automated + legal or similarly significant effect; safeguards (human intervention, contestation, explanation) | A trivial human rubber-stamp does not defeat “solely automated” — and the SCHUFA ruling extended Art 22 to scores that determine another party’s decision | Privacy Foundations |
Biometric laws (GDPR Art 9; Illinois BIPA) | Biometrics as special-category data; consent/notice regimes; BIPA’s private right of action and per-scan damages | Confusing biometric identification (matching identity) with categorisation (inferring attributes) — different rules attach | Privacy Foundations · EU AI Act: Prohibited Practices |
Copyright / IP law | Training-data infringement theories and fair use; the EU TDM exception and opt-out; no copyright in purely AI-generated output (human-authorship rule); licence restrictions on AI training | Assuming the training question is settled — it is live litigation; the exam tests the frameworks of argument, not a winner | Special Topics: AI and IP |
Nondiscrimination law (Title VII, ECOA, FHA analogues) | Disparate treatment vs disparate impact; proxies defeating attribute-blindness; four-fifths rule; adverse-action notices in credit; NYC LL144 bias audits | “We removed the protected attribute, so it can’t discriminate” — the exam’s favourite wrong answer | NIST/US: Sectoral Enforcement · Foundations: Ethics and Trustworthy AI |
Consumer protection (FTC Act §5 UDAP) | Deceptive AI claims (AI-washing); undisclosed bots; unfairness from biased or unsafe systems; algorithmic disgorgement as remedy | Thinking the FTC needed a new AI statute — §5 has covered AI all along; “there is no US AI law so no US AI risk” is doubly wrong | NIST/US: Sectoral Enforcement |
Product liability (EU PLD 2024; US doctrine) | Defect categories applied to AI; the revised EU PLD treating software/AI as products, easing proof burdens, covering post-sale updates and learning | Forgetting that a deployer’s misuse doesn’t create PLD liability for it — the PLD targets manufacturers/producers | EU AI Act: Value Chain (context) |
EU AI Act | The whole apparatus: risk tiers and prohibitions; Annex III + Art 6(3) classification; high-risk requirements; provider/deployer/importer/distributor duties; GPAI tiers and 10²⁵ FLOPs; conformity assessment and CE marking; fine ladder (7%/3%/1%); phased application dates | Attaching provider duties to deployers (and vice versa); mixing the fine tiers; missing that fine-tuning or rebranding can switch your role under Art 25 | The entire EU AI Act track — start with At a Glance |
South Korea AI Basic Law (2026) | Awareness level: first comprehensive framework law in Asia — high-impact AI duties, generative-AI notification/labeling, oversight institutions | Treating it as an EU AI Act clone — it is lighter-touch and promotion-oriented alongside its safeguards | Global: Asia-Pacific · Comparing Regimes |
Colorado AI Act | The US archetype of duty-based state AI law: developers and deployers of high-risk systems owe reasonable care against algorithmic discrimination — impact assessments, notices, disclosures | Its effective date was delayed and its text amended after passage — verify current status; also, it covers consequential decisions, not all AI | NIST/US: State Laws |
Texas TRAIGA, Utah AIPA, Illinois, California measures | Recognition level: Texas (prohibited-uses approach), Utah (generative-AI disclosure), Illinois (video-interview and HR decisions), California (transparency, training-data, safety cluster) | Over-generalising “US state law” — each state chose a different mechanism, and questions test which state did what | NIST/US: State Laws |
OECD AI Principles | The principles themselves; the OECD AI-system definition as the shared root of modern statutory definitions | Citing OECD as enforceable law — it is soft law with hard influence | Global: Soft Law · ISO: Standards Landscape |
NIST AI RMF + Playbook + GenAI Profile | Govern–Map–Measure–Manage and what belongs in each function; voluntary status; profiles as tailoring devices | Assigning Govern activities (policies, culture, accountability) to Map; inventing penalties for non-adoption | NIST/US: AI RMF (canonical) · GenAI and Bias |
ISO/IEC 22989 · 42001 · 42005 | Which number does what: terminology / certifiable management system / impact assessment | Swapping 42001 and 42005; claiming a 42001 certificate is an EU conformity assessment | ISO: Standards Landscape · AIMS 42001 · Risk and Impact |
CoE Framework Convention · G7 Hiroshima Process · UNESCO Recommendation | Pure awareness: first binding treaty on AI and human rights (CoE); G7 code of conduct for advanced systems; UNESCO’s global ethics recommendation | Confusing the CoE convention (treaty, Council of Europe, 46+ states) with the EU AI Act (EU regulation) — different bodies, different instruments | Global: UN and Treaty · Soft Law |
The which-law gauntlet: run a use case through the Domain II gates
Interactive decision tree — outcomes:
- Article 22 territory — and almost certainly more
Solely automated significant decisions trigger GDPR Art 22 safeguards (human intervention, contestation, explanation) on top of base privacy duties — and the same facts usually land in Annex III high-risk territory under the AI Act. Layers stack; they never substitute. Continue the gauntlet with the remaining gates.
- Nondiscrimination law is engaged
Employment, credit, housing, and insurance are the civil-rights quadrilateral: disparate-impact analysis, possible bias-audit duties (NYC LL144), adverse-action notices in credit — plus, in the EU, these are Annex III high-risk categories. Note how often one use case fires several gates at once: that is the exam’s favourite scenario architecture.
- Stop — prohibited practice
If the use matches Article 5 (social scoring, exploitative manipulation, most real-time remote biometric ID in public spaces, emotion recognition at work/school…), no compliance program fixes it: the practice is banned, with fines at the top tier (up to €35M or 7% of global turnover). The exam expects you to recognise prohibited fact patterns instantly.
- High-risk regime applies
Annex III + no Art 6(3) escape = the full high-risk stack: provider requirements (risk management through conformity assessment and CE marking) and deployer duties (oversight, input data, monitoring, sometimes a FRIA). Your next question is always which role does this company hold? — that determines the duty list.
- Transparency tier — but keep the other gates in mind
Chatbots must disclose they are AI; synthetic media must be labeled (Art 50). Light-touch under the AI Act — but remember the earlier gates still bind: a minimal-risk system can still violate privacy, IP, or consumer-protection law. “Minimal risk under the AI Act” never means “unregulated.”
Tool: AIGP Exam Simulator — Drill Domains I–II under exam conditions: timed, scenario-weighted questions tagged to competencies I.A through II.D.