AI-Specific Laws and Risk Classification
This topic covers AI-specific legal requirements, risk classification, technical documentation, assessments, record keeping, human oversight, transparency, quality management, general-purpose AI model obligations, enforcement, penalties, and role-based requirements.
How to study for IAPP AIGP
Treat each question as a governance decision: identify the AI role and life-cycle stage, classify the legal or risk issue, then choose the control, evidence, and accountability path.
Core concepts
Concept 1
AI-specific laws often classify systems by risk level and impose obligations based on use case, role, geography, and organizational context.
Exam cue: Classify the system and the organization's role before choosing the legal obligation.
Concept 2
Higher-risk AI systems commonly require risk management, data governance, technical documentation, assessment, record keeping, human oversight, transparency, and quality controls.
Exam cue: Use documentation and assessment controls for high-risk AI contexts.
Concept 3
General-purpose AI models can carry distinct obligations that differ from systems deployed for a specific use case.
Exam cue: Separate general-purpose model obligations from deployer obligations.
Risk pitfalls and guardrails
Treating every AI system as the same legal risk category.
Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.
Ignoring the difference between provider and deployer obligations.
Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.
Waiting until enforcement to create required technical documentation.
Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.
Memory anchors
Risk Classification
Risk classification assigns an AI system to a legal or policy risk tier.
Prohibited Risk
Prohibited risk refers to AI uses that a law or policy bars outright.
High-Risk AI
High-risk AI requires heightened controls because it can significantly affect rights, safety, or access.
Technical Documentation
Technical documentation records system design, purpose, controls, data, performance, and limitations.
Human Oversight
Human oversight gives people meaningful ability to supervise, intervene, or challenge AI behavior.
Quality Management
Quality management creates repeatable controls for compliant and reliable AI development or deployment.
GPAI Model
A general-purpose AI model can support many downstream use cases and may have distinct obligations.
Role-Based Obligation
A role-based obligation depends on whether an organization provides, deploys, imports, distributes, or uses AI.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
What approach does the EU AI Act take to regulating AI?
What are unacceptable-risk AI practices under the EU AI Act?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
