Exam-day revision sheet

Not a summary of the syllabus — that's the cheat sheet. This is what is worth holding in short-term memory for the twenty minutes before you go in: the exact numbers, the pairs people mix up under time pressure, and the routine.

Prints to two sides of A4. Choose "Save as Portable Document Format (PDF)" as the destination to keep a copy.

Numbers to know exactly

Artificial Intelligence (AI) Act — prohibited practices €35M or 7% of global turnover
AI Act — most other obligations €15M or 3%
AI Act — misleading info to authorities €7.5M or 1%
General Data Protection Regulation (GDPR) — top tier (for contrast) €20M or 4%
General-purpose artificial intelligence (GPAI) systemic-risk presumption 10²⁵ floating-point operations (FLOPs) training compute
GDPR breach notification 72 hours from awareness, to the authority
Exam 100 questions · 180 min · 100–500 scale · 300 to pass
Blueprint weighting I 16–20 · II 19–23 · III 21–25 · IV 21–25

AI Act timeline

Aug 2024 AI Act enters into force
Feb 2025 Prohibitions apply
Aug 2025 GPAI obligations apply
Aug 2026 Most high-risk obligations apply
Aug 2027 High-risk safety components of regulated products

Riskiest conduct regulated earliest: prohibitions need no build-out, conformity assessments do.

Risk tiers

ProhibitedSocial scoring · untargeted facial scraping · emotion inference at work/school · subliminal manipulation · exploiting vulnerabilities · most real-time remote biometric identification (ID) by police
High riskAnnex III: employment · credit · education · essential services · biometrics · critical infrastructure · law enforcement · migration · justice. Plus safety components of regulated products
LimitedChatbots (disclose), synthetic media and deepfakes (label), emotion recognition (inform) — Art. 50
MinimalEverything else. No mandatory obligations

AI Act roles

Provider Builds and places on market under own name. Risk mgmt, data governance, Annex IV docs, conformity assessment, Conformité Européenne (CE) marking, registration, quality management system (QMS), post-market monitoring, Art. 73 incidents
Deployer Uses under own authority. Per instructions, human oversight, input relevance, monitoring, keep logs, inform affected persons, fundamental rights impact assessment (FRIA) (Art. 27) where required
Importer Verifies the provider did the conformity assessment, docs and marking before import
Distributor Checks marking and docs; must not supply a system believed non-conforming
Auth. representative Established in the European Union (EU) and appointed in writing by a provider from outside it (Art. 22). Holds docs, cooperates
Role flip Deployer → provider on rebranding, substantial modification, or repurposing to high-risk

Pairs that decide marks

Opacity vs Complexity Output already produced vs behaviour hard to predict
Data drift vs Concept drift Inputs moved vs the input→target relationship moved
FRIA (Art. 27) vs Conformity assessment (Art. 43) Deployer, before use vs provider, before market
Data protection impact assessment (DPIA) (GDPR 35) vs FRIA (AI Act 27) Personal-data risk vs fundamental-rights impact
Art. 13 vs Art. 50 Instructions to deployers vs disclosure to people
Post-market monitoring vs Continuous monitoring Art. 72 documented plan vs day-to-day practice
Transparency vs Explainability That AI is used vs how an output arose
Explainability vs Interpretability The mechanism vs what it means for the person
Anonymised vs Pseudonymised Outside GDPR vs still personal data
Retrieval-augmented generation (RAG) vs Fine-tuning Knowledge and freshness vs behaviour and format
Verification vs Validation Built it right vs built the right thing
Accountable (RACI) vs Responsible One owner, cannot delegate vs does the work

Framework anchors

National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF) Govern (cross-cutting) · Map · Measure · Manage. Voluntary. Playbook = suggested actions
NIST bias (Special Publication (SP) 1270) Systemic · statistical/computational · human-cognitive
International Organization for Standardization and International Electrotechnical Commission (ISO/IEC) 22989 Terminology and concepts
ISO/IEC 42001 AI management system — the certifiable one
ISO/IEC 42005 AI system impact assessment
Organisation for Economic Co-operation and Development (OECD) principles Inclusive growth · human rights & democratic values · transparency & explainability · robustness, security & safety · accountability. Non-binding. Source of the AI-system definition

GDPR articles for AI

Art. 5Lawfulness · purpose limitation · minimisation · accuracy · storage limitation · integrity · accountability
Art. 6Six lawful bases. Legitimate interests needs a balancing test and yields to Art. 21 objection
Art. 9Special categories prohibited unless an Art. 9(2) exception. Biometrics only when used to uniquely identify
Art. 22Solely automated + legal/similar effect. Safeguards: human intervention, contest, info about the logic
Arts. 33–3472h to the authority from awareness; individuals only if high risk
Art. 35DPIA where high risk. Art. 25 = by design and by default. Art. 30 = records

Per-question routine

S — Signal word MOST / FIRST / EXCEPT / LEAST. Read the stem twice before any option
T — Territory Which framework, role, lifecycle phase, risk tier
E — Eliminate Absolutes · shifted accountability · single safeguard · wrong role · wrong phase · wrong framework · wrong level
M — Margin call Name the axis the last two differ on, apply a tiebreaker, commit

~1.8 min per question. Tiebreakers: answer what was asked · rights beat convenience · proactive beats reactive · upstream beats downstream · layered beats single · accountability never transfers.

Exam logistics change. Verify the format, scoring and policies in the IAPP certification candidate handbook before you sit. LearnAIGP is an independent study aid and is not affiliated with the IAPP.

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →