Every named thing you could be asked about
57 instruments and bodies that appear as AIGP answer options. Most of the exam’s named-thing questions do not ask what an instrument says — they ask what kind of thing it is, because the answer to “which of these is least likely to help?” falls out of force, not subject matter. So they are grouped by force here: what each one can actually do to you.
Sort by force first
Binding creates duties and penalties. Standard can be certified against and required by contract, but carries no fine of its own. Guidance shapes practice and binds nobody outside the body that issued it. Soft law is influential and unenforceable. When two options are both on topic, the one with more force is almost always the answer — and when the question asks which is least likely to help, it is almost always the one with the least.
EU law — binding, enforceable, with penalties
BindingThese create obligations on named parties and carry fines. If one of these applies to the fact pattern, it beats any framework or standard in the same option set.
EU AI Act Regulation (EU) 2024/1689
Risk-tiered product regulation of AI systems and general-purpose models: prohibited, high-risk, limited (transparency) and minimal, with duties split across provider, deployer, importer and distributor.
The tell: Regulates the system as a product placed on the market. It says almost nothing about whether you may use the personal data inside it — that is the GDPR, and both apply at once.
GDPR Regulation (EU) 2016/679
Governs processing of personal data: lawful basis, the principles, individual rights, Art. 22 on solely automated decisions, DPIAs, transfers.
The tell: Follows the personal data wherever it goes, including into training sets and inference logs. Applies extraterritorially where you target or monitor people in the EU.
Digital Services Act DSA, Regulation (EU) 2022/2065
Platform regulation: recommender-system transparency, ad-targeting limits, and systemic-risk assessments for very large online platforms.
The tell: Algorithmic accountability for platforms, not for AI products. A recommender-transparency fact pattern about a large platform is a DSA story before it is an AI Act one.
Product Liability Directive Revised PLD, 2024
Strict liability for defective products, explicitly extended to software and AI systems, with eased proof burdens where AI complexity makes causation hard to show.
The tell: Defectiveness can arise after sale, through updates or the system learning. The separate AI Liability Directive was withdrawn, so the PLD is the operative instrument.
NIS2 Directive Directive (EU) 2022/2555
Cybersecurity risk-management and incident-reporting duties for essential and important entities across named sectors.
The tell: Security of the organisation, not safety of the model. It appears where a stem mixes an AI incident with a cyber incident — the reporting clocks are different.
Data Act & Data Governance Act DA 2023/2854, DGA 2022/868
Access to and sharing of data: who may use data generated by connected products (DA), and trusted intermediaries and altruism structures for data sharing (DGA).
The tell: Both are about data availability. Neither is a privacy law and neither regulates models.
US federal law — no AI statute, but existing law applies in full
BindingThe US has no comprehensive AI or privacy statute. It has sectoral laws that bite on AI without ever mentioning it, and the 2023 joint agency statement is explicit: there is no AI exemption. Every one of these can appear as the instrument that actually governs a scenario.
HIPAA Health Insurance Portability and Accountability Act, 1996
Governs protected health information (PHI) held by covered entities — health plans, clearinghouses and most providers — and their business associates. Privacy Rule, Security Rule and Breach Notification Rule.
The tell: The commonest US-health trap. It reaches PHI held by covered entities and business associates, not health-adjacent data generally: the same step count is HIPAA data in a hospital app and unregulated by HIPAA in a consumer fitness app. A vendor training a model on PHI is typically a business associate, which needs a BAA.
FCRA Fair Credit Reporting Act
Regulates consumer reporting agencies and the furnishing and use of consumer reports, with accuracy duties, dispute rights and adverse-action notice.
The tell: Reaches AI-driven background screening and scoring products — a vendor scoring tenants or employees can be a consumer reporting agency without calling itself one.
ECOA Equal Credit Opportunity Act
Prohibits credit discrimination and requires specific, accurate adverse-action reasons.
The tell: The CFPB has confirmed the reason-giving duty survives model opacity. "The algorithm decided" is not an adverse-action reason.
Title VII Civil Rights Act 1964, Title VII
Prohibits employment discrimination on protected grounds, reaching both disparate treatment and disparate impact.
The tell: Disparate impact is the theory that catches AI: a neutral screening tool with an unjustified adverse effect on a protected group is unlawful without any intent.
ADA Americans with Disabilities Act
Prohibits disability discrimination and requires reasonable accommodation.
The tell: Bites on hiring tools that screen out disabled applicants — video-interview scoring of speech or facial expression is the standard example.
FTC Act §5 Federal Trade Commission Act, section 5
Prohibits unfair or deceptive acts or practices. The FTC’s principal AI tool.
The tell: Carries algorithmic disgorgement: where a model was built on illegally or deceptively obtained data, the FTC can require deletion of the data and the models derived from it.
COPPA Children’s Online Privacy Protection Act
Requires verifiable parental consent before collecting personal information from children under 13 online.
The tell: Age 13, US-specific. Do not blend it with the GDPR’s Art. 8 digital-consent age, which is 16 with member-state discretion down to 13.
GLBA Gramm-Leach-Bliley Act
Privacy and safeguards duties for financial institutions handling nonpublic personal information.
The tell: The financial-sector counterpart to HIPAA. Where a stem says "bank" and "customer data", GLBA is in play alongside ECOA and FCRA.
FERPA Family Educational Rights and Privacy Act
Protects the privacy of student education records at funded institutions.
The tell: The instrument behind edtech scenarios — a proctoring or grading model trained on student records is a FERPA question first.
Algorithmic Accountability Act Proposed, repeatedly reintroduced
Would require impact assessments for automated decision systems.
The tell: Never enacted. It appears in option sets precisely because it sounds like the US answer to the AI Act — treating a bill as law is the trap.
US state and city law
BindingWhere the US does regulate AI directly, it is mostly here. Dates move; the shape matters more than the calendar. See the jurisdictions page for current status.
Colorado AI Act SB 24-205, amended by SB 189
Duties on developers and deployers of systems making consequential decisions. The 2026 amendment narrowed it substantially and delayed it to 1 January 2027.
The tell: Originally the most EU-like US law, which is why older materials describe a risk-management programme and impact assessments that the amendment removed.
NYC Local Law 144 Automated employment decision tools
Requires an independent bias audit within the previous year, publication of the results, and notice to candidates.
The tell: Independent is the operative word — a self-audit does not satisfy it. City-level, employment-only.
Illinois BIPA Biometric Information Privacy Act
Requires informed written consent before collecting biometric identifiers, with a private right of action.
The tell: The private right of action is what makes it dangerous: individuals sue directly, and statutory damages accrue per violation. Face and voice data in a US scenario should prompt BIPA.
CCPA / CPRA California Consumer Privacy Act, as amended
Comprehensive state privacy law with rights of access, deletion, correction and opt-out of sale/sharing, plus rules on automated decision-making and profiling.
The tell: Opt-out model, not the GDPR’s opt-in lawful-basis model. There is no "legitimate interests balancing test" in California.
Texas TRAIGA HB 149, in force 1 January 2026
A short list of prohibited AI uses plus rules for state-government AI.
The tell: Much narrower than early drafts and not a general high-risk regime — a common overstatement.
US federal instruments that are NOT law
GuidanceThis group produces the single most reliable "least likely to help" item on the exam. These shape federal practice and inform everyone else, but none of them creates a duty on a private deployer.
NAIIA National Artificial Intelligence Initiative Act, 2020
Establishes a national initiative to advance AI research and development — coordination, funding, a National AI Initiative Office.
The tell: The classic wrong answer. It regulates nobody. Asked which instrument is LEAST likely to give guidance on discrimination, hiring or consumer protection, this is it — because it is about research capacity, not conduct.
Blueprint for an AI Bill of Rights OSTP, 2022
Five principles: safe and effective systems; algorithmic discrimination protections; data privacy; notice and explanation; human alternatives, consideration and fallback.
The tell: A white paper. Non-binding, no enforcement, no penalties — offered against the AI Act to see whether you will treat it as an equivalent.
NIST AI RMF AI Risk Management Framework 1.0, 2023
Voluntary framework built on four functions — GOVERN, MAP, MEASURE, MANAGE — with a companion Playbook and a Generative AI Profile.
The tell: GOVERN is cross-cutting and continuous rather than a first step you complete. Voluntary, but the most widely adopted US reference point.
NIST SP 1270 Towards a Standard for Identifying and Managing Bias in AI
The bias taxonomy: systemic, statistical/computational, and human-cognitive.
The tell: The source of the three-category split the BOK adopts. If an option names those three categories, this is where they come from.
NIST ARIA Assessing Risks and Impacts of AI
A NIST programme building evaluation environments to test how systems behave in realistic societal conditions rather than on benchmarks.
The tell: Risk assessment is its centre of gravity. The giveaway in an option is assessment, not ethics principles or a management framework.
OMB M-24-10 Advancing governance, innovation and risk management for agency use of AI
Directs federal agencies: Chief AI Officers, AI use-case inventories, and minimum practices for rights- and safety-impacting AI.
The tell: Binds federal agencies only. It is the closest thing the US has to a high-risk regime, and it does not touch the private sector.
SR 11-7 Federal Reserve supervisory guidance on model risk management, 2011
Model inventory, independent validation, effective challenge, ongoing monitoring.
The tell: Predates the AI-governance wave by a decade and is the template it borrowed from. A bank credit-model scenario is as much an SR 11-7 story as an AI Act one.
Executive orders EO 14110 (2023), rescinded January 2025
Directed federal agencies on safe, secure and trustworthy AI; replaced by a deregulatory order.
The tell: Volatile by design — a new administration can reverse them. What persists is the agencies’ underlying statutory authority.
Standards — voluntary, but certifiable and auditable
StandardNobody can fine you for ignoring these. They matter because you can be certified against them, contracts can require them, and the AI Act works through harmonised standards to give a presumption of conformity.
ISO/IEC 42001 AI management system
The certifiable management-system standard for AI: Plan-Do-Check-Act, policy, roles, objectives, controls, internal audit, management review.
The tell: Certifies an organisation’s system of governance, not a model’s performance and not a person. Contrast with the AIGP, which certifies a person.
ISO/IEC 42005 AI system impact assessment
How to run an AI impact assessment: affected stakeholders, benefits, harms with likelihood and severity, mitigations, residual risk, and a deploy decision.
The tell: Guidance rather than a legal trigger. It is the method you use to run the assessments the law does require.
ISO/IEC 23894 AI risk management
Adapts ISO 31000 risk management to AI, sitting inside a 42001 management system.
The tell: 42001 is the management system; 23894 is how you run risk management within it. Options swap the two.
ISO/IEC 22989 AI concepts and terminology
The vocabulary standard — definitions of AI system, machine learning, life cycle stages.
The tell: The one named in the BOK alongside 42001 and 42005. It defines terms; it imposes nothing.
ISO/IEC 5338 AI system life cycle processes
The process model behind the lifecycle stages used across Domain III.
The tell: Where the phase names come from when a question talks about lifecycle stages generically.
ISO 31000 Risk management guidelines
General, non-AI-specific risk-management guidelines.
The tell: The parent that AI risk standards adapt. If an option needs the generic risk standard rather than an AI one, this is it.
IEEE 7000 Model process for addressing ethical concerns during system design
Value-based engineering: elicit stakeholder values and translate them into design requirements.
The tell: A design-time process standard. Distinct from IEEE’s broader Ethically Aligned Design report, which is a treatise rather than a process.
Principles, declarations and soft law
Soft lawUnenforceable, and still examinable: their principle names turn up as answer options, and questions test whether you know an influential declaration from a binding rule.
OECD AI Principles Adopted 2019, updated 2024
Five values-based principles — inclusive growth and wellbeing; human rights and democratic values with fairness and privacy; transparency and explainability; robustness, security and safety; accountability — plus recommendations to policymakers.
The tell: The most influential soft-law instrument, and the source of the AI-system definition the EU AI Act aligned with. Adopted by governments, binding on nobody.
UNESCO Recommendation on the Ethics of AI 2021
The first global ethics instrument for AI, adopted by all UNESCO member states.
The tell: Notable for breadth of adoption, not for enforceability. If an option needs "global and non-binding", this is usually it.
Asilomar AI Principles 2017, Future of Life Institute
Twenty-three research-community principles across research, ethics and values, and longer-term issues — including failure transparency, judicial transparency, human control, personal privacy and shared benefit.
The tell: A conference statement by researchers, not a government instrument. Its distinctive principle names — failure transparency, judicial transparency — are the giveaway when they appear as options.
Montreal Declaration Responsible AI, 2018
Ten principles from a public consultation process — wellbeing, autonomy, privacy, solidarity, democratic participation, equity, diversity, prudence, responsibility, sustainable development.
The tell: Academic and participatory in origin. Grouped with Asilomar and Beijing as the ethics declarations that predate the regulatory wave.
Beijing AI Principles 2019
Chinese research-community principles covering research, development, use and governance.
The tell: Recognise it as a national research-community declaration, not as Chinese AI regulation — that is the separate set of algorithm, deep-synthesis and generative-AI measures.
G7 Hiroshima AI Process 2023
International Guiding Principles plus a voluntary Code of Conduct for organisations developing advanced AI systems.
The tell: Aimed at frontier developers. Voluntary, and specifically about advanced systems rather than AI generally.
Bletchley & Seoul Declarations 2023, 2024
Summit declarations on frontier AI safety; Seoul added commitments from frontier developers and a network of AI Safety Institutes.
The tell: Declarations from summits, producing commitments and institutes rather than obligations.
Council of Europe Framework Convention AI, human rights, democracy and the rule of law, 2024
The first international treaty on AI, open to non-European states, with HUDERIA as its risk and impact methodology.
The tell: The exception in this group: it is a treaty, so it binds states that ratify it — but it binds states, not companies directly.
Universal Declaration of Human Rights 1948
The foundational human-rights instrument that fundamental-rights language throughout AI governance ultimately traces to.
The tell: Appears where an option needs the ultimate source of "fundamental rights" rather than a specific AI instrument.
Belmont Report 1979
Respect for persons, beneficence and justice — the ethical basis of human-subjects research, and of informed consent and IRB review.
The tell: Where research-ethics vocabulary in AI comes from. It is about research on people, not about products.
Fair Information Practices FIPs, 1970s
The principles underlying data-protection law in most jurisdictions — notice, choice, access, accuracy, security, accountability.
The tell: Older than every privacy statute and the common ancestor of all of them, including the GDPR principles.
Bodies — who does what
ActorA question can name the instrument correctly and still be answered wrongly if you attribute it to the wrong body. These are the actors worth recognising on sight.
EU AI Office
Sits within the Commission; supervises general-purpose AI models and coordinates enforcement of the AI Act.
The tell: GPAI supervision is centralised here. High-risk systems are supervised by national market surveillance authorities instead.
European AI Board
Member-state representatives advising and coordinating consistent application of the AI Act.
The tell: The AI Act’s analogue of the EDPB. Advisory and coordinating, not the enforcer.
Notified bodies
Independent conformity assessment bodies designated by member states.
The tell: Required only in specific cases — notably certain biometric systems, and AI that is a safety component of a product already regulated under sectoral law. Most Annex III conformity assessment is internal control by the provider.
Market surveillance authorities
National authorities policing systems already on the market; receive FRIA notifications and serious-incident reports.
The tell: Post-market. Notified bodies are the pre-market gate; these are what happens afterwards.
EDPB / EDPS
The Board issues GDPR guidance and consistency decisions; the Supervisor regulates EU institutions.
The tell: Data protection, not AI product safety. A question about AI Act enforcement is not an EDPB question.
NIST
US standards body; publishes the AI RMF, SP 1270 and the ARIA programme.
The tell: It writes frameworks and measurement science. It has no enforcement power at all.
FTC / EEOC / CFPB / DOJ
US enforcers applying consumer protection, employment, credit and civil-rights law to AI under existing authority.
The tell: Their 2023 joint statement — "there is no AI exemption" — is the shape of US AI enforcement in one line.
FDA / OSHA
Medical devices including AI as software as a medical device with predetermined change control plans; and workplace and robot safety.
The tell: Sector regulators reach AI inside their remit without needing an AI statute.
IAPP
The professional body that publishes the AIGP Body of Knowledge and administers the certification.
The tell: The BOK is the syllabus. Where a source and the BOK differ in vocabulary, the BOK is what is examined.
AI Safety / Security Institutes
National institutes evaluating frontier models, networked after the Seoul summit.
The tell: Evaluation and research bodies. They test models; they do not license them.
How these are turned into questions
Force, not subject matter
The most common item shape gives you four instruments that all sound relevant and asks which is least likely to help. Sort by what each one can do — bind, certify, or merely recommend — before you sort by topic.
Bills read like laws
The Algorithmic Accountability Act and Brazil’s Bill 2338 are not in force. An option describing what an instrument "requires" is not evidence that it exists.
Research initiatives are not regulation
The NAIIA advances research. It creates no obligation on anyone, which is exactly why it wins "least likely to provide guidance" items.
Declarations have distinctive vocabulary
Failure transparency and judicial transparency are Asilomar. Inclusive growth and wellbeing is OECD. Learning a couple of signature phrases per declaration is cheaper than learning the lists.
Test yourself
5 questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.
Which is LEAST likely to provide guidance on reducing discrimination in an AI hiring tool?
- AThe National Artificial Intelligence Initiative Act.
- BThe Equal Employment Opportunity Commission.
- CTitle VII of the Civil Rights Act of 1964.
- DThe Fair Credit Reporting Act.
Related: Which rules apply where · BOK vs frameworks · Glossary · Cheat sheet