Exam-day cheat sheet

The memorise-cold facts on one page. Skim it at the start of revision sessions and the night before the exam. Print it: it's styled for paper.

EU AI Act — risk tiers

Prohibited (Art. 5) Social scoring; exploiting vulnerabilities; subliminal manipulation; untargeted facial-image scraping; emotion recognition in workplace/education; real-time remote biometric ID in public by police (narrow exceptions)
High-risk (Annex III + regulated products) Employment/CV screening; credit scoring; education scoring; essential services; law enforcement; migration; justice; critical infrastructure; safety components
Limited / transparency (Art. 50) Chatbots (disclose AI), deepfakes & AI-generated content (label), emotion-recognition/biometric-categorisation systems (inform), GPAI-generated text on matters of public interest
Minimal Everything else (spam filters, games) — voluntary codes of conduct

EU AI Act — penalties & key numbers

Prohibited-practice violations Up to €35M or 7% of global annual turnover (whichever higher)
Most other obligations (providers/deployers) Up to €15M or 3%
Supplying incorrect/misleading info to authorities Up to €7.5M or 1%
GPAI systemic-risk presumption Training compute > 10²⁵ FLOPs (or Commission designation)
Timeline In force Aug 2024 · prohibitions Feb 2025 · GPAI rules Aug 2025 · most high-risk obligations Aug 2026 · Annex I product high-risk Aug 2027

EU AI Act — roles

Provider Develops / places on market under own name. Heaviest duties: risk management, data governance, technical documentation (Annex IV), conformity assessment + CE marking, post-market monitoring (Art. 72), serious-incident reporting (Art. 73)
Deployer Uses the system under its own authority. Duties: use per instructions, human oversight (Art. 14 arrangements), input-data relevance, monitoring, log retention, FRIA for certain deployers (Art. 27), inform affected persons
Importer / Distributor Verify conformity artifacts (CE marking, documentation) before making available
Deployer → becomes provider If it puts its name on a high-risk system, substantially modifies one, or repurposes a system to high-risk use (Art. 25)

GDPR — the articles that matter for AI

Arts. 5–6 Principles (lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity, accountability) + six lawful bases
Art. 9 Special categories (incl. biometric data for identification) — need an Art. 9(2) condition, not just a lawful basis
Art. 22 Right not to be subject to solely automated decisions with legal/similarly significant effects; exceptions: contract, consent, EU/member-state law — with safeguards incl. human intervention
Art. 35 DPIA required for high-risk processing (systematic profiling, large-scale special categories)
Arts. 33–34 Breach notification: authority within 72h of awareness; individuals if high risk

NIST AI RMF

Govern Cross-cutting culture, policies, roles, accountability (the foundation the other three sit on)
Map Establish context, identify risks and impacts
Measure Analyse, assess, benchmark and track risks
Manage Prioritise, respond to and monitor risks
Trustworthy AI characteristics Valid & reliable (base) · safe · secure & resilient · accountable & transparent · explainable & interpretable · privacy-enhanced · fair with harmful bias managed
Bias categories (SP 1270) Systemic · statistical/computational · human-cognitive

ISO / OECD / other anchors

ISO/IEC 22989 AI concepts & terminology
ISO/IEC 42001 AI management system (AIMS) — certifiable, Plan-Do-Check-Act
ISO/IEC 42005 AI system impact assessment guidance
OECD AI Principles Inclusive growth; human rights & fairness; transparency & explainability; robustness, security & safety; accountability — definition adopted by the EU AI Act
Council of Europe Framework Convention First binding international AI treaty (human rights, democracy, rule of law)
SK AI Basic Act Comprehensive; effective Jan 2026; high-impact AI duties; generative-AI labeling; domestic representative for large foreign providers
Colorado AI Act (SB 24-205) Duty of reasonable care to avoid algorithmic discrimination — developers and deployers of high-risk AI; AG enforcement only
NYC Local Law 144 Bias audit + candidate notice for automated employment decision tools

Distinctions the exam loves

Transparency vs explainability vs interpretability Disclosing that/how AI is used · describing the mechanism behind an output · what the output means in context
Verification vs validation Built right (meets spec) vs built the right thing (meets need/intended use)
Data drift vs concept drift Input distribution shifts vs the input→output relationship itself shifts
Accuracy vs precision vs recall Overall correct share · of predicted positives, how many real · of real positives, how many found
Audit vs red teaming vs threat modeling Independent conformance review · adversarial attack simulation · systematic enumeration of attack surfaces at design time
Bias sub-types Sampling (unrepresentative training data) · temporal (data from wrong period) · confirmation (humans favour agreeing outputs) — under NIST’s systemic / statistical-computational / human-cognitive umbrella
AI use-case types Recognition (what is it) · detection (is it there/anomalous) · forecasting (predict) · personalization (tailor to a person) · optimization (best option under constraints) · interaction (converse)
PETs Differential privacy = add noise · federated learning = train locally, share updates · homomorphic encryption = compute on encrypted data · SMPC = joint compute without revealing inputs
Lineage vs provenance The path/transformations data took · its origin and chain of custody
Fine-tuning vs RAG vs prompting Change weights (durable behaviour) · retrieve knowledge at inference (freshness, citations) · instruct at runtime (lightest)
Narrow vs general AI All deployed AI today is narrow; AGI/ASI remain hypothetical

Responsible-AI principles & exam facts

The principles Fairness · safety & reliability · privacy & security · transparency & explainability · accountability · human-centricity
AI-system definition (OECD/EU) Machine-based system that infers from input how to generate outputs (predictions, content, recommendations, decisions) with varying autonomy and adaptiveness
Exam format 100 MCQs · 3 hours · case-study scenarios · some multi-select (pick N, no partial credit)
Scoring Reported on a 100–500 scale, pass mark 300 (verify in the IAPP Candidate Handbook)

Every fact here is covered with context in the reference notes — if something on this sheet doesn't ring a bell, go re-read its topic page rather than memorising blind.