Exam-day revision sheet

Not a summary of the syllabus — that's the cheat sheet. This is what is worth holding in short-term memory for the twenty minutes before you go in: the exact numbers, the pairs people mix up under time pressure, and the routine.

Prints to two sides of A4. Choose "Save as PDF" as the destination to keep a copy.

Numbers to know exactly

AI Act — prohibited practices €35M or 7% of global turnover
AI Act — most other obligations €15M or 3%
AI Act — misleading info to authorities €7.5M or 1%
GDPR — top tier (for contrast) €20M or 4%
GPAI systemic-risk presumption 10²⁵ FLOPs training compute
GDPR breach notification 72 hours from awareness, to the authority
Exam 100 questions · 180 min · 100–500 scale · 300 to pass
Blueprint weighting I 16–20 · II 19–23 · III 21–25 · IV 21–25

AI Act timeline

Aug 2024 AI Act enters into force
Feb 2025 Prohibitions apply
Aug 2025 GPAI obligations apply
Aug 2026 Most high-risk obligations apply
Aug 2027 High-risk safety components of regulated products

Riskiest conduct regulated earliest: prohibitions need no build-out, conformity assessments do.

Risk tiers

ProhibitedSocial scoring · untargeted facial scraping · emotion inference at work/school · subliminal manipulation · exploiting vulnerabilities · most real-time remote biometric ID by police
High riskAnnex III: employment · credit · education · essential services · biometrics · critical infrastructure · law enforcement · migration · justice. Plus safety components of regulated products
LimitedChatbots (disclose), synthetic media and deepfakes (label), emotion recognition (inform) — Art. 50
MinimalEverything else. No mandatory obligations

AI Act roles

Provider Builds and places on market under own name. Risk mgmt, data governance, Annex IV docs, conformity assessment, CE marking, registration, QMS, post-market monitoring, Art. 73 incidents
Deployer Uses under own authority. Per instructions, human oversight, input relevance, monitoring, keep logs, inform affected persons, FRIA (Art. 27) where required
Importer Verifies the provider did the conformity assessment, docs and marking before import
Distributor Checks marking and docs; must not supply a system believed non-conforming
Auth. representative EU-established, appointed in writing by a non-EU provider (Art. 22). Holds docs, cooperates
Role flip Deployer → provider on rebranding, substantial modification, or repurposing to high-risk

Pairs that decide marks

Opacity vs Complexity Output already produced vs behaviour hard to predict
Data drift vs Concept drift Inputs moved vs the input→target relationship moved
FRIA (Art. 27) vs Conformity assessment (Art. 43) Deployer, before use vs provider, before market
DPIA (GDPR 35) vs FRIA (AI Act 27) Personal-data risk vs fundamental-rights impact
Art. 13 vs Art. 50 Instructions to deployers vs disclosure to people
Post-market monitoring vs Continuous monitoring Art. 72 documented plan vs day-to-day practice
Transparency vs Explainability That AI is used vs how an output arose
Explainability vs Interpretability The mechanism vs what it means for the person
Anonymised vs Pseudonymised Outside GDPR vs still personal data
RAG vs Fine-tuning Knowledge and freshness vs behaviour and format
Verification vs Validation Built it right vs built the right thing
Accountable (RACI) vs Responsible One owner, cannot delegate vs does the work

Framework anchors

NIST AI RMF Govern (cross-cutting) · Map · Measure · Manage. Voluntary. Playbook = suggested actions
NIST bias (SP 1270) Systemic · statistical/computational · human-cognitive
ISO/IEC 22989 Terminology and concepts
ISO/IEC 42001 AI management system — the certifiable one
ISO/IEC 42005 AI system impact assessment
OECD principles Inclusive growth · human rights & democratic values · transparency & explainability · robustness, security & safety · accountability. Non-binding. Source of the AI-system definition

GDPR articles for AI

Art. 5Lawfulness · purpose limitation · minimisation · accuracy · storage limitation · integrity · accountability
Art. 6Six lawful bases. Legitimate interests needs a balancing test and yields to Art. 21 objection
Art. 9Special categories prohibited unless an Art. 9(2) exception. Biometrics only when used to uniquely identify
Art. 22Solely automated + legal/similar effect. Safeguards: human intervention, contest, info about the logic
Arts. 33–3472h to the authority from awareness; individuals only if high risk
Art. 35DPIA where high risk. Art. 25 = by design and by default. Art. 30 = records

Per-question routine

S — Signal word MOST / FIRST / EXCEPT / LEAST. Read the stem twice before any option
T — Territory Which framework, role, lifecycle phase, risk tier
E — Eliminate Absolutes · shifted accountability · single safeguard · wrong role · wrong phase · wrong framework · wrong level
M — Margin call Name the axis the last two differ on, apply a tiebreaker, commit

~1.8 min per question. Tiebreakers: answer what was asked · rights beat convenience · proactive beats reactive · upstream beats downstream · layered beats single · accountability never transfers.

Exam logistics change. Verify the format, scoring and policies in the IAPP certification candidate handbook before you sit. LearnAIGP is an independent study aid and is not affiliated with the IAPP.

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →