AICP · Domain 1
AI Fundamentals & Ethics
About 30% of the exam
What counts as an AI system
- Core test
- infers outputs from received inputs
- Adaptiveness
- behavior may change after deployment
- Excluded
- purely deterministic rule-based software
- General-purpose model
- broad capability, many downstream uses
- Governance
- the overarching decision framework
- Compliance
- conformity with binding legal duties
- Ethics
- value choices law leaves open
- AI literacy
- competence duty across all staff
Governance sets the frame, compliance proves the law is met, and ethics decides everything the law never says
Lifecycle and its compliance touchpoints
- Inception
- Design
- Data
- Development
- Verification
- Deployment
- Operation
- Retirement
- Inception fixes intended purpose and scope
- Data phase carries provenance and consent
- Verification produces the evidence auditors want
- Deployment triggers registration and disclosure duties
- Operation owns monitoring, logging and incidents
- Retirement keeps records and honors deletion
- Substantial modification restarts the assessment
Who decides what
- First line
- builds and owns the risk
- Second line
- sets policy, monitors adherence
- Third line
- independent assurance through internal audit
- Ethics board
- advises and escalates, never decides
- Governance committee
- holds the decision authority
- Board
- duty of care covers AI
- Accountable owner
- named role, survives staff turnover
Ethical failure patterns
- Ethics washing without operational change
- Dark patterns manufacturing hollow consent
- Proxy features reinstating a removed attribute
- Feedback loops entrenching historic enforcement bias
- Specification gaming of a proxy reward
- Aggregate accuracy hiding concentrated subgroup harm
- Filter bubbles narrowing what users see
- Cultural erasure flattening minority perspectives
- Automation bias silencing the human reviewer
Fairness definitions
- Demographic parity
- equal positive rates across groups
- Equal opportunity
- equal true positive rates
- Equalized odds
- both error rates equalized
- Predictive parity
- equal precision across groups
- Individual fairness
- similar people treated similarly
- Counterfactual fairness
- flip the attribute, outcome holds
- Impossibility result
- unequal base rates block joint satisfaction
- Proxy discrimination
- neutral feature encodes protected class
Ethics by design controls
- Translate principles into measurable thresholds
- Ethics review gate before each release
- Subgroup evaluation required, never optional
- Operational design domain limits documented
- Safe fallback when inputs leave the envelope
- Appeal route staffed by competent humans
- Opt-out preserved where consent is meaningful
- Working conditions covered for data labeling
Principle frameworks compared
Soft law
- OECD principles, the widely referenced baseline
- UNESCO recommendation adds a readiness assessment
- UNESCO also names ethical impact assessment
- Bletchley Declaration on frontier model risk
- Non-binding, yet it shapes national policy
Binding and certifiable
- Council of Europe convention binds its parties
- First treaty on AI and human rights
- ISO/IEC 42001 certifies a management system
- ISO/IEC 23894 guides risk, no certificate
- The EU AI Act applies directly
Trust characteristics
- EU expert group lists seven requirements
- Human agency and oversight comes first
- Societal and environmental well-being included
- NIST names seven trustworthiness characteristics
- IEEE 7001 sets transparency levels per audience
Accountability machinery
- Redress
- challenge, explanation and remedy
- Complaint handling
- named function, documented response
- Algorithmic audit
- independent examination of design and impact
- Sock-puppet audit
- synthetic profiles probe live behavior
- Whistleblower protection
- reporting without retaliation
- Tamper-evident logs
- automatic records across the lifetime
- Rebranding a system
- the distributor becomes the provider
- Layered accountability
- base model, fine-tuner, application
- Two-person verification
- biometric matches confirmed independently
Accountability that lives in one person's head leaves when the person does, so anchor it to a role in the AI inventory
Explaining a decision
- Local explanation
- why this single case
- Global explanation
- what drives the model overall
- LIME and SHAP
- model-agnostic attribution from queries
- Counterfactual
- smallest change flipping the outcome
- Anchors
- if-then rule that usually holds
- Contrastive
- why A rather than B
- Partial dependence
- average effect of one feature
- Saliency map
- which input regions mattered
- Mechanistic interpretability
- reverse engineering internal circuits
Transparency artifacts
- Model card
- one model, uses and limits
- System card
- whole deployed system and safeguards
- Data card
- collection, distribution, known limitations
- Instructions for use
- provider informs the deployer
- Declaration of conformity
- formal legal statement of compliance
- Technical documentation
- the evidence file behind conformity
- Training data summary
- sufficiently detailed, published template
- C2PA manifest
- signed provenance travels with content
Disclosure duties
- Tell people they face an AI
- Exception only when it is obvious
- Label synthetic and manipulated media
- Mark outputs in machine-readable form
- Deepfakes disclosed unless plainly artistic
- Emotion recognition subjects must be informed
- Explain the role of an automated decision
- Layered disclosure protects security-sensitive detail
Manipulation, misuse and dual use
Manipulation
- Persuasion appeals openly to reason
- Manipulation covertly exploits cognitive bias
- Exploiting age or disability is prohibited
- Prompts timed at moments of frustration
- Pre-ticked boxes defeat informed consent
Misuse and dual use
- Beneficial capability repurposed for harm
- Open weights widen both access and misuse
- Deepfakes erode shared trust in evidence
- Pervasive scoring degrades worker dignity
- Anthropomorphizing hides where accountability sits
Glossary
- Provider
- develops or places on market
- Deployer
- uses under its own authority
- Notified body
- third-party conformity assessor
- Accreditation
- confirms the certifier is competent
- CE marking
- provider declares the product conforms
- Data protection officer
- statutory adviser and authority contact
- Confabulation
- confident output that is wrong
- Ethics washing
- rhetoric without operational change
Numbers to recall
- Seven
- EU trustworthy AI requirements
- Seven
- NIST trustworthiness characteristics
- Three
- lines of defense
- Two
- people verify a biometric match
- Four
- AI Act risk tiers
- Article 22
- solely automated decisions under GDPR
- Article 86
- right to an explanation
- Article 85
- complaint to a market authority
Reference strip: definitions, ethics, fairness, accountability, transparency
Definitions
- Inference and adaptiveness define an AI system
- Governance frames, compliance proves, ethics chooses
- Provider builds it, deployer uses it
- Substantial modification transfers the provider duties
Ethics
- Autonomy, beneficence, non-maleficence, justice
- Manipulation bypasses a person's rational agency
- Ethics washing is itself a compliance risk
- Dual use is a design assumption
Fairness
- Parity, opportunity, odds, precision
- Deleting the attribute leaves the proxies
- Disaggregate before you claim fairness
- Unequal base rates create impossibility
Accountability
- Named owner recorded in the inventory
- Logs are the evidence of record
- Redress means challenge and remedy
- Rebranding makes you the provider
Transparency
- Local explains one, global explains all
- Counterfactual gives an actionable change
- A model card is not legal documentation
- Mark synthetic media in machine-readable form
Quick exam traps
- Trap: A published model card by itself discharges the statutory transparency duties
- Trap: Removing the protected attribute removes the discrimination risk
- Trap: The ethics board can approve a high-risk deployment on its own authority
- Trap: A rubber-stamp human review lifts a decision out of Article 22
- Trap: High average accuracy proves the system treats every group fairly
- Trap: Publishing a set of principles is evidence that ethics is operational
- Trap: Certification and accreditation are two words for the same activity
cybercertprep.com · original revision sheet written from the public body of knowledge