Free AIGP practice questions
70 questions across the syllabus, each with a note on every option — why the right one is right, and what mistake each wrong one is built to catch. No sign-in needed.
Why the real questions feel harder
Candidates who breeze through practice sets are often caught out by the official paper. When we compared our own bank against it, the difference was not the topics but how the options are written. Three patterns explain most of it, and knowing them changes how you should practise.
- The options do not explain themselves. A practice item that says "Red teaming — people trying to make the system fail" lets you match a definition to the scenario. The exam says "Red teaming." and leaves you to know what it is. If you can only pick the answer when it comes with its reason attached, you do not yet know it.
- Every wrong option is right somewhere else. The distractors are real instruments, real duties and real activities: threat modelling beside red teaming, a data protection impact assessment (DPIA) beside a fundamental rights impact assessment (FRIA), the provider's duty offered to the deployer. Elimination by common sense rarely gets you below two.
- Short, bare options. Around a third of official items list four names — laws, harm categories, roles, disciplines — with nothing else to read. There is no wording to reason from; you either know the boundary between them or you do not.
The questions below are written to those standards. Read the note on each option you rejected, not only the one you chose: the notes are where the boundaries are taught. For the routine to use on exam day, see exam technique.
Warm-up: one question from every topic
14 questions, one per set below. A quick way to find the topic to start with.
Synthetic video erodes public willingness to believe genuine footage. Which harm category is this?
- AEcosystem harm.
- BIndividual harm.
- CSocietal harm.
- DGroup harm.
Harms and bias
5 questions. Taught in full on harms and bias.
Synthetic video erodes public willingness to believe genuine footage. Which harm category is this?
- AEcosystem harm.
- BGroup harm.
- CSocietal harm.
- DIndividual harm.
Roles and responsibilities
5 questions. Taught in full on roles and responsibilities.
A SaaS vendor processes customer data on the customer’s documented instructions. Separately, it decides on its own to use the same data to improve its general model. What is its GDPR role in the first operation and in the second?
- AJoint controller with the customer for both.
- BProcessor for the first; controller for the second.
- CProcessor for both operations.
- DController for the first; processor for the second.
Named laws, frameworks and bodies
5 questions. Taught in full on named laws, frameworks and bodies.
Which is LEAST likely to provide guidance on reducing discrimination in an AI hiring tool?
- AThe Equal Employment Opportunity Commission.
- BThe National Artificial Intelligence Initiative Act.
- CThe Fair Credit Reporting Act.
- DTitle VII of the Civil Rights Act of 1964.
GDPR for AI
5 questions. Taught in full on gdpr for ai.
A team wants to process special-category data to test a model for bias. Under the GDPR, what does it need?
- AAn Art. 9(2) condition and a completed DPIA.
- BAn Art. 9(2) condition, which replaces Art. 6.
- CAn Art. 6 basis and a completed DPIA.
- DAn Art. 6 basis and an Art. 9(2) condition.
GDPR versus the EU AI Act
5 questions. Taught in full on gdpr versus the eu ai act.
A company is a GDPR controller for the personal data in its AI system and satisfies every GDPR obligation. What does that establish about its EU AI Act compliance?
- ANothing on its own.
- BThat only Art. 50 duties remain.
- CThat Art. 10 data governance is met.
- DThat it is largely compliant.
Article numbers
5 questions. Taught in full on article numbers.
A non-EU provider of a high-risk AI system must appoint an authorised representative in the Union. Which article requires it?
- AEU AI Act Art. 22.
- BGDPR Art. 22.
- CGDPR Art. 27.
- DEU AI Act Art. 27.
EU AI Act timeline and updates
5 questions. Taught in full on eu ai act timeline and updates.
Under the Digital Omnibus amendments, which AI Act deadline did NOT move?
- AArt. 50 transparency obligations.
- BAnnex III high-risk obligations.
- CAnnex I high-risk obligations.
- DNational regulatory sandboxes.
Which rules apply where
5 questions. Taught in full on which rules apply where.
A US analytics company with no EU establishment tracks the browsing behaviour of users located in Germany. Which provision brings it within the GDPR?
- AArt. 3(1).
- BArt. 3(3).
- CArt. 3(2)(b).
- DArt. 3(2)(a).
Standards and frameworks
5 questions. Taught in full on standards and frameworks.
The BOK describes four value-chain actors: developer, provider, deployer and user. Which of them are also operator roles defined in the EU AI Act?
- AProvider, deployer and user.
- BProvider and deployer only.
- CDeveloper, provider and deployer.
- DAll four of them.
DPIA, FRIA and conformity assessment
5 questions. Taught in full on dpia, fria and conformity assessment.
A private company deploys a high-risk AI system to screen job applicants. Who owes a fundamental rights impact assessment under EU AI Act Art. 27 for this deployment?
- AThe company and the provider jointly.
- BThe provider, before market placement.
- CNobody, on these facts.
- DThe company, as deployer.
Order of operations
5 questions. Taught in full on order of operations.
A team has agreed the business problem its new AI system will solve. Which step comes next?
- ADetermine the specific use cases.
- BIdentify the applicable laws.
- CIdentify the data it will need.
- DIdentify the gaps and risks.
A worked governance programme
5 questions. Taught in full on a worked governance programme.
Aldermere starts using client survey data to improve its own assistant. What changes?
- AIt becomes a joint controller for that processing.
- BIt becomes a controller for all the survey data.
- CIt becomes a controller for that processing.
- DIt remains a processor for that processing.
Lists worth memorising
5 questions. Taught in full on lists worth memorising.
How many principles does GDPR Art. 5 contain?
- ASeven.
- BFive.
- CSix.
- DEight.
Exam technique
5 questions. Taught in full on exam technique.
An option reads: "Anonymising the training data resolves the privacy concerns." Which distractor pattern is this?
- AAbsolutes.
- BSingle safeguard.
- CShifted accountability.
- DWrong risk tier.
Questions about AIGP practice
Are these real AIGP exam questions?
No. The International Association of Privacy Professionals (IAPP) does not publish its live exam items, and anyone claiming to sell them is selling something they should not have. Every question here was written for this site against the Artificial Intelligence Governance Professional (AIGP) Body of Knowledge and the primary sources — the General Data Protection Regulation (GDPR), the European Union Artificial Intelligence Act (EU AI Act), the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF) and the rest — in the style of the official practice paper.
How many questions are on the AIGP exam?
100 multiple-choice questions in three hours. Some are single-answer, some are select-all-that-apply, and a number share a longer scenario. It is scored on a scale of 100 to 500 and the pass mark is 300.
What score on practice questions means I am ready?
A consistent 75–80% on questions of the official difficulty, sustained across all four domains rather than averaged over them. One weak domain can sink an otherwise comfortable paper, because Domains III and IV together carry around half the marks.
Where are the full-length mock exams?
Behind a free sign-in: 305 further exam-style questions, blueprint-weighted 100-question mocks, flashcards and spaced review of the questions you get wrong. The questions on this page are separate from that bank.