Exam-day revision sheet
Not a summary of the syllabus — that's the cheat sheet. This is what is worth holding in short-term memory for the twenty minutes before you go in: the exact numbers, the pairs people mix up under time pressure, and the routine.
Numbers to know exactly
| AI Act — prohibited practices | €35M or 7% of global turnover |
| AI Act — most other obligations | €15M or 3% |
| AI Act — misleading info to authorities | €7.5M or 1% |
| GDPR — top tier (for contrast) | €20M or 4% |
| GPAI systemic-risk presumption | 10²⁵ FLOPs training compute |
| GDPR breach notification | 72 hours from awareness, to the authority |
| Exam | 100 questions · 180 min · 100–500 scale · 300 to pass |
| Blueprint weighting | I 16–20 · II 19–23 · III 21–25 · IV 21–25 |
AI Act timeline
| Aug 2024 | AI Act enters into force |
| Feb 2025 | Prohibitions apply |
| Aug 2025 | GPAI obligations apply |
| Aug 2026 | Most high-risk obligations apply |
| Aug 2027 | High-risk safety components of regulated products |
Riskiest conduct regulated earliest: prohibitions need no build-out, conformity assessments do.
Risk tiers
| Prohibited | Social scoring · untargeted facial scraping · emotion inference at work/school · subliminal manipulation · exploiting vulnerabilities · most real-time remote biometric ID by police |
| High risk | Annex III: employment · credit · education · essential services · biometrics · critical infrastructure · law enforcement · migration · justice. Plus safety components of regulated products |
| Limited | Chatbots (disclose), synthetic media and deepfakes (label), emotion recognition (inform) — Art. 50 |
| Minimal | Everything else. No mandatory obligations |
AI Act roles
| Provider | Builds and places on market under own name. Risk mgmt, data governance, Annex IV docs, conformity assessment, CE marking, registration, QMS, post-market monitoring, Art. 73 incidents |
| Deployer | Uses under own authority. Per instructions, human oversight, input relevance, monitoring, keep logs, inform affected persons, FRIA (Art. 27) where required |
| Importer | Verifies the provider did the conformity assessment, docs and marking before import |
| Distributor | Checks marking and docs; must not supply a system believed non-conforming |
| Auth. representative | EU-established, appointed in writing by a non-EU provider (Art. 22). Holds docs, cooperates |
| Role flip | Deployer → provider on rebranding, substantial modification, or repurposing to high-risk |
Pairs that decide marks
| Opacity vs Complexity | Output already produced vs behaviour hard to predict |
| Data drift vs Concept drift | Inputs moved vs the input→target relationship moved |
| FRIA (Art. 27) vs Conformity assessment (Art. 43) | Deployer, before use vs provider, before market |
| DPIA (GDPR 35) vs FRIA (AI Act 27) | Personal-data risk vs fundamental-rights impact |
| Art. 13 vs Art. 50 | Instructions to deployers vs disclosure to people |
| Post-market monitoring vs Continuous monitoring | Art. 72 documented plan vs day-to-day practice |
| Transparency vs Explainability | That AI is used vs how an output arose |
| Explainability vs Interpretability | The mechanism vs what it means for the person |
| Anonymised vs Pseudonymised | Outside GDPR vs still personal data |
| RAG vs Fine-tuning | Knowledge and freshness vs behaviour and format |
| Verification vs Validation | Built it right vs built the right thing |
| Accountable (RACI) vs Responsible | One owner, cannot delegate vs does the work |
Framework anchors
| NIST AI RMF | Govern (cross-cutting) · Map · Measure · Manage. Voluntary. Playbook = suggested actions |
| NIST bias (SP 1270) | Systemic · statistical/computational · human-cognitive |
| ISO/IEC 22989 | Terminology and concepts |
| ISO/IEC 42001 | AI management system — the certifiable one |
| ISO/IEC 42005 | AI system impact assessment |
| OECD principles | Inclusive growth · human rights & democratic values · transparency & explainability · robustness, security & safety · accountability. Non-binding. Source of the AI-system definition |
GDPR articles for AI
| Art. 5 | Lawfulness · purpose limitation · minimisation · accuracy · storage limitation · integrity · accountability |
| Art. 6 | Six lawful bases. Legitimate interests needs a balancing test and yields to Art. 21 objection |
| Art. 9 | Special categories prohibited unless an Art. 9(2) exception. Biometrics only when used to uniquely identify |
| Art. 22 | Solely automated + legal/similar effect. Safeguards: human intervention, contest, info about the logic |
| Arts. 33–34 | 72h to the authority from awareness; individuals only if high risk |
| Art. 35 | DPIA where high risk. Art. 25 = by design and by default. Art. 30 = records |
Per-question routine
| S — Signal word | MOST / FIRST / EXCEPT / LEAST. Read the stem twice before any option |
| T — Territory | Which framework, role, lifecycle phase, risk tier |
| E — Eliminate | Absolutes · shifted accountability · single safeguard · wrong role · wrong phase · wrong framework · wrong level |
| M — Margin call | Name the axis the last two differ on, apply a tiebreaker, commit |
~1.8 min per question. Tiebreakers: answer what was asked · rights beat convenience · proactive beats reactive · upstream beats downstream · layered beats single · accountability never transfers.
Exam logistics change. Verify the format, scoring and policies in the IAPP certification candidate handbook before you sit. LearnAIGP is an independent study aid and is not affiliated with the IAPP.