The big law matrix — and the which-law gauntlet

Lesson 4 of 4 in AIGP Domains I–II Recap: Foundations, Laws, Standards, and Frameworks.

Here is Domain II compressed into one table: every instrument the BoK names, what the exam actually tests about it, and the module that teaches it properly. Print this mentally. When a practice question stumps you, the failure is almost always in one cell of this matrix.

Law → what AIGP tests about it
InstrumentWhat AIGP tests about itClassic trapStudy module

GDPR / privacy law generally

Lawful basis for training data; purpose limitation on repurposing; minimization vs data-hungry systems; DPIAs; controller/processor roles; transfers; data-subject rights against models

Assuming “publicly available” data is free to use — scraping still processes personal data (Clearview AI fines across the EU)

Privacy Foundations (Special Topics)

GDPR Article 22 (automated decision-making)

When the right not to be subject to solely automated decisions bites: solely automated + legal or similarly significant effect; safeguards (human intervention, contestation, explanation)

A trivial human rubber-stamp does not defeat “solely automated” — and the SCHUFA ruling extended Art 22 to scores that determine another party’s decision

Privacy Foundations

Biometric laws (GDPR Art 9; Illinois BIPA)

Biometrics as special-category data; consent/notice regimes; BIPA’s private right of action and per-scan damages

Confusing biometric identification (matching identity) with categorisation (inferring attributes) — different rules attach

Privacy Foundations · EU AI Act: Prohibited Practices

Copyright / IP law

Training-data infringement theories and fair use; the EU TDM exception and opt-out; no copyright in purely AI-generated output (human-authorship rule); licence restrictions on AI training

Assuming the training question is settled — it is live litigation; the exam tests the frameworks of argument, not a winner

Special Topics: AI and IP

Nondiscrimination law (Title VII, ECOA, FHA analogues)

Disparate treatment vs disparate impact; proxies defeating attribute-blindness; four-fifths rule; adverse-action notices in credit; NYC LL144 bias audits

“We removed the protected attribute, so it can’t discriminate” — the exam’s favourite wrong answer

NIST/US: Sectoral Enforcement · Foundations: Ethics and Trustworthy AI

Consumer protection (FTC Act §5 UDAP)

Deceptive AI claims (AI-washing); undisclosed bots; unfairness from biased or unsafe systems; algorithmic disgorgement as remedy

Thinking the FTC needed a new AI statute — §5 has covered AI all along; “there is no US AI law so no US AI risk” is doubly wrong

NIST/US: Sectoral Enforcement

Product liability (EU PLD 2024; US doctrine)

Defect categories applied to AI; the revised EU PLD treating software/AI as products, easing proof burdens, covering post-sale updates and learning

Forgetting that a deployer’s misuse doesn’t create PLD liability for it — the PLD targets manufacturers/producers

EU AI Act: Value Chain (context)

EU AI Act

The whole apparatus: risk tiers and prohibitions; Annex III + Art 6(3) classification; high-risk requirements; provider/deployer/importer/distributor duties; GPAI tiers and 10²⁵ FLOPs; conformity assessment and CE marking; fine ladder (7%/3%/1%); phased application dates

Attaching provider duties to deployers (and vice versa); mixing the fine tiers; missing that fine-tuning or rebranding can switch your role under Art 25

The entire EU AI Act track — start with At a Glance

South Korea AI Basic Law (2026)

Awareness level: first comprehensive framework law in Asia — high-impact AI duties, generative-AI notification/labeling, oversight institutions

Treating it as an EU AI Act clone — it is lighter-touch and promotion-oriented alongside its safeguards

Global: Asia-Pacific · Comparing Regimes

Colorado AI Act

The US archetype of duty-based state AI law: developers and deployers of high-risk systems owe reasonable care against algorithmic discrimination — impact assessments, notices, disclosures

Its effective date was delayed and its text amended after passage — verify current status; also, it covers consequential decisions, not all AI

NIST/US: State Laws

Texas TRAIGA, Utah AIPA, Illinois, California measures

Recognition level: Texas (prohibited-uses approach), Utah (generative-AI disclosure), Illinois (video-interview and HR decisions), California (transparency, training-data, safety cluster)

Over-generalising “US state law” — each state chose a different mechanism, and questions test which state did what

NIST/US: State Laws

OECD AI Principles

The principles themselves; the OECD AI-system definition as the shared root of modern statutory definitions

Citing OECD as enforceable law — it is soft law with hard influence

Global: Soft Law · ISO: Standards Landscape

NIST AI RMF + Playbook + GenAI Profile

Govern–Map–Measure–Manage and what belongs in each function; voluntary status; profiles as tailoring devices

Assigning Govern activities (policies, culture, accountability) to Map; inventing penalties for non-adoption

NIST/US: AI RMF (canonical) · GenAI and Bias

ISO/IEC 22989 · 42001 · 42005

Which number does what: terminology / certifiable management system / impact assessment

Swapping 42001 and 42005; claiming a 42001 certificate is an EU conformity assessment

ISO: Standards Landscape · AIMS 42001 · Risk and Impact

CoE Framework Convention · G7 Hiroshima Process · UNESCO Recommendation

Pure awareness: first binding treaty on AI and human rights (CoE); G7 code of conduct for advanced systems; UNESCO’s global ethics recommendation

Confusing the CoE convention (treaty, Council of Europe, 46+ states) with the EU AI Act (EU regulation) — different bodies, different instruments

Global: UN and Treaty · Soft Law

The which-law gauntlet: run a use case through the Domain II gates

Interactive decision tree — outcomes:

  • Article 22 territory — and almost certainly more

    Solely automated significant decisions trigger GDPR Art 22 safeguards (human intervention, contestation, explanation) on top of base privacy duties — and the same facts usually land in Annex III high-risk territory under the AI Act. Layers stack; they never substitute. Continue the gauntlet with the remaining gates.

  • Nondiscrimination law is engaged

    Employment, credit, housing, and insurance are the civil-rights quadrilateral: disparate-impact analysis, possible bias-audit duties (NYC LL144), adverse-action notices in credit — plus, in the EU, these are Annex III high-risk categories. Note how often one use case fires several gates at once: that is the exam’s favourite scenario architecture.

  • Stop — prohibited practice

    If the use matches Article 5 (social scoring, exploitative manipulation, most real-time remote biometric ID in public spaces, emotion recognition at work/school…), no compliance program fixes it: the practice is banned, with fines at the top tier (up to €35M or 7% of global turnover). The exam expects you to recognise prohibited fact patterns instantly.

  • High-risk regime applies

    Annex III + no Art 6(3) escape = the full high-risk stack: provider requirements (risk management through conformity assessment and CE marking) and deployer duties (oversight, input data, monitoring, sometimes a FRIA). Your next question is always which role does this company hold? — that determines the duty list.

  • Transparency tier — but keep the other gates in mind

    Chatbots must disclose they are AI; synthetic media must be labeled (Art 50). Light-touch under the AI Act — but remember the earlier gates still bind: a minimal-risk system can still violate privacy, IP, or consumer-protection law. “Minimal risk under the AI Act” never means “unregulated.”

Tool: AIGP Exam Simulator — Drill Domains I–II under exam conditions: timed, scenario-weighted questions tagged to competencies I.A through II.D.