Sources
A small, exam-aligned set of authoritative primary sources — the laws, standards and frameworks the AIGP Body of Knowledge names. Each reference note cites the ones it draws on.
- EU Artificial Intelligence Act — Regulation (EU) 2024/1689 European Union · 2024
The flagship AI-specific law. Risk-tier classification, prohibited practices, high-risk obligations, GPAI rules, roles (provider/deployer/importer/distributor), conformity assessment, transparency, penalties and timeline.
II.C II.B III.A III.C IV.B IV.C - Basic Act on the Development of AI and Establishment of Trust (AI Basic Act) Republic of Korea · 2025 (effective Jan 2026)
Asia's first comprehensive AI law. High-impact AI obligations, generative-AI transparency, and domestic-representative requirements for large foreign providers.
II.C - AI Risk Management Framework (AI RMF 1.0) + Playbook NIST (U.S.) · 2023
Voluntary, widely referenced framework. Four core functions — Govern, Map, Measure, Manage — with categories/subcategories, plus characteristics of trustworthy AI.
II.D I.C III.A III.C IV.C - OECD AI Principles & definition of an AI system OECD · 2019 (updated 2024)
The most widely adopted statement of values-based AI principles; its AI-system definition was adopted by the EU AI Act and others.
I.A II.D - General Data Protection Regulation (Regulation (EU) 2016/679) European Union · 2016 (in force 2018)
Core data-privacy obligations as applied to AI: lawful basis & purpose limitation (Art. 5–6), special-category data (Art. 9), automated decision-making (Art. 22), DPIAs (Art. 35), controller/processor duties and transfers.
II.A I.C - ISO/IEC 42001 — AI management system (AIMS) ISO/IEC · 2023
Certifiable management-system standard for AI (Plan-Do-Check-Act), analogous to ISO 27001 for security.
II.D I.C III.A - ISO/IEC 22989 — AI concepts and terminology ISO/IEC · 2022
Foundational vocabulary and concepts for AI — the standard definitions of AI system, ML, life cycle stages, etc.
II.D I.A - ISO/IEC 42005 — AI system impact assessment ISO/IEC · 2025
Guidance for conducting and documenting AI system impact assessments across the life cycle.
II.D III.A IV.B - U.S. nondiscrimination law (Title VII, ECOA, FHA) + EEOC AI guidance U.S. federal agencies · various
Anti-discrimination regimes that reach AI in hiring, credit/lending, housing and insurance — including disparate-impact liability for algorithmic decisions.
II.B - FTC Act §5 — Unfair or Deceptive Acts or Practices (UDAP) U.S. Federal Trade Commission · ongoing
Consumer-protection backstop for AI: bans deceptive AI claims and unfair practices; basis for FTC enforcement (e.g., algorithmic disgorgement).
II.B - U.S. Copyright Office — Copyright and Artificial Intelligence U.S. Copyright Office · 2023–2025
Guidance on human-authorship requirement and the IP issues around training data and AI-generated output.
II.B I.C - Colorado AI Act (SB 24-205) State of Colorado (U.S.) · 2024
Leading U.S. state AI law: duty of reasonable care to avoid algorithmic discrimination by developers and deployers of high-risk AI; a frequent EU-AI-Act comparison.
II.B II.C - NYC Local Law 144 — Automated Employment Decision Tools New York City (U.S.) · 2023
Requires bias audits and candidate notice for automated employment decision tools — a concrete example of sector-specific AI regulation.
II.B - Council of Europe Framework Convention on AI, Human Rights, Democracy and the Rule of Law Council of Europe · 2024
First binding international treaty on AI; aligns signatories around human-rights-based AI governance.
II.C II.D - IAPP AI Governance glossary & resources IAPP · current
IAPP’s own terminology and responsible-AI framing — useful for matching the exam’s preferred definitions.
I.A I.B