Domain II

Understanding how laws, standards and frameworks apply to AI

Existing laws that apply to AI, as well as AI-specific laws, standards and frameworks — including the major elements of current AI laws (e.g., the EU AI Act, the South Korean AI Basic Law, federal and state AI laws that apply to private sector organizations).

Exam weight: 19–23 of 100 4 competencies 61 practice questions
II.A

Understand how existing data privacy laws apply to AI.

4–6 Q
  • II.A.1 Understand how transparency, choice, lawful basis and purpose limitation requirements apply to AI.
  • II.A.2 Understand how data minimization and privacy by design requirements apply to AI.
  • II.A.3 Understand how obligations on data controllers apply to AI (e.g., regarding privacy impact assessments, use of third-party processors, cross-border data transfers, data subject rights, automated decision making, incident management, breach notification and record keeping).
  • II.A.4 Understand the requirements that apply to sensitive or special categories of data (e.g., biometrics).
Study this topic →
II.B

Understand how other types of existing laws apply to AI.

4–6 Q
  • II.B.1 Understand how intellectual property laws apply to AI (e.g., prohibiting or limiting use of data for AI training).
  • II.B.2 Understand how nondiscrimination laws apply to AI (e.g., in the employment, credit, lending, housing and insurance contexts).
  • II.B.3 Understand how consumer protection laws apply to AI (e.g., prohibiting unfair and deceptive acts or practices).
  • II.B.4 Understand how product liability laws apply to AI (e.g., prohibiting design and manufacturing defects).
Study this topic →
II.C

Understand the main elements of AI-specific laws.

6–8 Q
  • II.C.1 Understand the risk classification framework for AI (e.g., prohibited/high/limited/minimal risk) and what systems/uses fall into each category.
  • II.C.2 Understand the key requirements around risk management, data governance, technical documentation, conformity/impact assessments and record keeping.
  • II.C.3 Understand the key requirements around human oversight, transparency and notification, and quality management.
  • II.C.4 Understand the distinct requirements for general-purpose AI models.
  • II.C.5 Understand the enforcement framework and penalties for noncompliance.
  • II.C.6 Understand the differences in requirements based on organizational context (e.g., providers, deployers, importers and distributors).
Study this topic →
II.D

Understand the main industry standards and tools that apply to AI.

3–5 Q
  • II.D.1 Understand the Organisation for Economic Co-operation and Development (OECD) principles, framework, policies and recommended practices for trustworthy AI.
  • II.D.2 Understand the NIST AI Risk Management Framework and Playbook (e.g., core functions, categories and subcategories).
  • II.D.3 Understand the core ISO AI standards (i.e., 22989, 42001 and 42005).
Study this topic →