Exam-day cheat sheet
The memorise-cold facts on one page. Skim it at the start of revision sessions and the night before the exam. Print it: it's styled for paper.
EU AI Act — risk tiers
| Prohibited (Art. 5) | Social scoring; exploiting vulnerabilities; subliminal manipulation; untargeted facial-image scraping; emotion recognition in workplace/education; real-time remote biometric ID in public by police (narrow exceptions) |
| High-risk (Annex III + regulated products) | Employment/CV screening; credit scoring; education scoring; essential services; law enforcement; migration; justice; critical infrastructure; safety components |
| Limited / transparency (Art. 50) | Chatbots (disclose AI), deepfakes & AI-generated content (label), emotion-recognition/biometric-categorisation systems (inform), GPAI-generated text on matters of public interest |
| Minimal | Everything else (spam filters, games) — voluntary codes of conduct |
EU AI Act — penalties & key numbers
| Prohibited-practice violations | Up to €35M or 7% of global annual turnover (whichever higher) |
| Most other obligations (providers/deployers) | Up to €15M or 3% |
| Supplying incorrect/misleading info to authorities | Up to €7.5M or 1% |
| GPAI systemic-risk presumption | Training compute > 10²⁵ FLOPs (or Commission designation) |
| Timeline | In force Aug 2024 · prohibitions Feb 2025 · GPAI rules Aug 2025 · most high-risk obligations Aug 2026 · Annex I product high-risk Aug 2027 |
EU AI Act — roles
| Provider | Develops / places on market under own name. Heaviest duties: risk management, data governance, technical documentation (Annex IV), conformity assessment + CE marking, post-market monitoring (Art. 72), serious-incident reporting (Art. 73) |
| Deployer | Uses the system under its own authority. Duties: use per instructions, human oversight (Art. 14 arrangements), input-data relevance, monitoring, log retention, FRIA for certain deployers (Art. 27), inform affected persons |
| Importer / Distributor | Verify conformity artifacts (CE marking, documentation) before making available |
| Deployer → becomes provider | If it puts its name on a high-risk system, substantially modifies one, or repurposes a system to high-risk use (Art. 25) |
GDPR — the articles that matter for AI
| Arts. 5–6 | Principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity, accountability) + six lawful bases |
| Art. 9 | Special categories (incl. biometric data for identification) — need an Art. 9(2) condition, not just a lawful basis |
| Art. 22 | Right not to be subject to solely automated decisions with legal/similarly significant effects; exceptions: contract, consent, EU/member-state law — with safeguards incl. human intervention |
| Art. 35 | DPIA required for high-risk processing (systematic profiling, large-scale special categories) |
| Arts. 33–34 | Breach notification: authority within 72h of awareness; individuals if high risk |
NIST AI RMF
| Govern | Cross-cutting culture, policies, roles, accountability (the foundation the other three sit on) |
| Map | Establish context, identify risks and impacts |
| Measure | Analyse, assess, benchmark and track risks |
| Manage | Prioritise, respond to and monitor risks |
| Trustworthy AI characteristics | Valid & reliable (base) · safe · secure & resilient · accountable & transparent · explainable & interpretable · privacy-enhanced · fair with harmful bias managed |
| Bias categories (SP 1270) | Systemic · statistical/computational · human-cognitive |
ISO / OECD / other anchors
| ISO/IEC 22989 | AI concepts & terminology |
| ISO/IEC 42001 | AI management system (AIMS) — certifiable, Plan-Do-Check-Act |
| ISO/IEC 42005 | AI system impact assessment guidance |
| OECD AI Principles | Inclusive growth; human rights & fairness; transparency & explainability; robustness, security & safety; accountability — definition adopted by the EU AI Act |
| Council of Europe Framework Convention | First binding international AI treaty (human rights, democracy, rule of law) |
| SK AI Basic Act | Comprehensive; effective Jan 2026; high-impact AI duties; generative-AI labeling; domestic representative for large foreign providers |
| Colorado AI Act (SB 24-205) | Duty of reasonable care to avoid algorithmic discrimination — developers and deployers of high-risk AI; AG enforcement only |
| NYC Local Law 144 | Bias audit + candidate notice for automated employment decision tools |
Distinctions the exam loves
| Transparency vs explainability vs interpretability | Disclosing that/how AI is used · describing the mechanism behind an output · what the output means in context |
| Verification vs validation | Built right (meets spec) vs built the right thing (meets need/intended use) |
| Data drift vs concept drift | Input distribution shifts vs the input→output relationship itself shifts |
| Accuracy vs precision vs recall | Overall correct share · of predicted positives, how many real · of real positives, how many found |
| Audit vs red teaming vs threat modeling | Independent conformance review · adversarial attack simulation · systematic enumeration of attack surfaces at design time |
| Bias sub-types | Sampling (unrepresentative training data) · temporal (data from wrong period) · confirmation (humans favour agreeing outputs) — under NIST’s systemic / statistical-computational / human-cognitive umbrella |
| AI use-case types | Recognition (what is it) · detection (is it there/anomalous) · forecasting (predict) · personalization (tailor to a person) · optimization (best option under constraints) · interaction (converse) |
| PETs | Differential privacy = add noise · federated learning = train locally, share updates · homomorphic encryption = compute on encrypted data · SMPC = joint compute without revealing inputs |
| Lineage vs provenance | The path/transformations data took · its origin and chain of custody |
| Fine-tuning vs RAG vs prompting | Change weights (durable behaviour) · retrieve knowledge at inference (freshness, citations) · instruct at runtime (lightest) |
| Narrow vs general AI | All deployed AI today is narrow; AGI/ASI remain hypothetical |
Responsible-AI principles & exam facts
| The principles | Fairness · safety & reliability · privacy & security · transparency & explainability · accountability · human-centricity |
| AI-system definition (OECD/EU) | Machine-based system that infers from input how to generate outputs (predictions, content, recommendations, decisions) with varying autonomy and adaptiveness |
| Exam format | 100 MCQs · 3 hours · case-study scenarios · some multi-select (pick N, no partial credit) |
| Scoring | Reported on a 100–500 scale, pass mark 300 (verify in the IAPP Candidate Handbook) |
Every fact here is covered with context in the reference notes — if something on this sheet doesn't ring a bell, go re-read its topic page rather than memorising blind.