Topic module

AI-Specific Laws and Risk Classification

This topic covers AI-specific legal requirements, risk classification, technical documentation, assessments, record keeping, human oversight, transparency, quality management, general-purpose AI model obligations, enforcement, penalties, and role-based requirements.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for IAPP AIGP

Treat each question as a governance decision: identify the AI role and life-cycle stage, classify the legal or risk issue, then choose the control, evidence, and accountability path.

Core concepts

Concept 1

AI-specific laws often classify systems by risk level and impose obligations based on use case, role, geography, and organizational context.

Exam cue: Classify the system and the organization's role before choosing the legal obligation.

Concept 2

Higher-risk AI systems commonly require risk management, data governance, technical documentation, assessment, record keeping, human oversight, transparency, and quality controls.

Exam cue: Use documentation and assessment controls for high-risk AI contexts.

Concept 3

General-purpose AI models can carry distinct obligations that differ from systems deployed for a specific use case.

Exam cue: Separate general-purpose model obligations from deployer obligations.

Risk pitfalls and guardrails

Treating every AI system as the same legal risk category.

Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.

Ignoring the difference between provider and deployer obligations.

Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.

Waiting until enforcement to create required technical documentation.

Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.

Memory anchors

Risk Classification

Risk classification assigns an AI system to a legal or policy risk tier.

Prohibited Risk

Prohibited risk refers to AI uses that a law or policy bars outright.

High-Risk AI

High-risk AI requires heightened controls because it can significantly affect rights, safety, or access.

Technical Documentation

Technical documentation records system design, purpose, controls, data, performance, and limitations.

Human Oversight

Human oversight gives people meaningful ability to supervise, intervene, or challenge AI behavior.

Quality Management

Quality management creates repeatable controls for compliant and reliable AI development or deployment.

GPAI Model

A general-purpose AI model can support many downstream use cases and may have distinct obligations.

Role-Based Obligation

A role-based obligation depends on whether an organization provides, deploys, imports, distributes, or uses AI.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

What approach does the EU AI Act take to regulating AI?

What are unacceptable-risk AI practices under the EU AI Act?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.