AIGP · Domain 2
Risk and Compliance for AI
About 25% of the exam
The AI risk cycle
- Identify
- Analyze
- Evaluate
- Treat
- Accept residual
- Monitor
- Report
- Inherent versus residual
- shrinking gap means controls weakening
- Appetite versus tolerance
- direction versus a measurable limit
- Velocity and detectability
- fast, silent risks rank higher
- KPI, KRI, KCI
- performance, exposure, control health
- Control cost test
- decline when cost exceeds expected loss
- Acceptance record
- approver, risk, rationale, conditions, review
- Likelihood for AI
- expert elicitation plus early telemetry
Normalize AI risks onto the enterprise impact and likelihood scales so they compete for the same board attention
NIST AI RMF
- Govern
- culture, roles, policies, accountability
- Map
- context, purpose, stakeholders, impacts
- Measure
- analyze, benchmark, track, test
- Manage
- prioritize, respond, accept, monitor
- Hierarchy
- function, category, subcategory
- Seven characteristics
- valid and reliable comes first
- Secure versus resilient
- adversaries versus withstanding change
- GenAI Profile
- AI 600-1, confabulation named
AI risk taxonomy
- Safety
- physical or psychological harm
- Security
- malicious actors, attacks
- Privacy
- disclosure, inference, re-identification
- Fairness
- bias, legal, reputational
- Intellectual property
- outputs resembling protected works
- Systemic
- population-scale harm from broad models
- Cascading
- one failure triggers others
- Vendor lock-in
- cannot migrate, abstraction layers
- Drift
- performance decays as data shifts
EU AI Act risk tiers
Prohibited
- Manipulative or deceptive techniques distorting behavior
- Exploiting vulnerabilities of age or disability
- Social scoring causing unjustified detriment
- Untargeted facial image scraping
- Emotion recognition at work or school
- Real-time remote biometric ID, narrow exceptions
High-risk
- Annex I: safety components of regulated products
- Annex III: biometrics, infrastructure, education, employment
- Essential services, law enforcement, migration, justice
- Profiling natural persons never gets the derogation
- Full obligations before market placement
Limited and minimal
- Chatbots disclose they are AI
- Deepfakes and synthetic media labeled
- Public-interest AI text disclosed unless editorial review
- Minimal: no new duties, voluntary codes
- GPAI models governed separately
High-risk obligations
- Risk management system across the lifecycle
- Data governance and bias examination
- Technical documentation and automatic logging
- Transparency and instructions for deployers
- Human oversight designed in
- Accuracy, robustness, cybersecurity, proportionate
- Quality management system
- Conformity assessment, CE mark, declaration
- Register in the EU database first
- Post-market monitoring, serious incident reports
Who does what
- Provider
- develops or places on market
- Deployer
- uses under its authority
- Importer, distributor
- check conformity before supply
- Authorized representative
- EU stand-in for non-EU provider
- Notified body
- third-party conformity assessment
- Market surveillance authority
- national enforcement
- AI Office
- Commission, GPAI oversight
- European AI Board
- member states, consistent application
A deployer that modifies a system substantially or rebrands it becomes the provider
GPAI and timelines
- GPAI: technical documentation, copyright policy, training summary
- Systemic risk: compute threshold, evaluations, incidents
- Code of Practice shows GPAI compliance
- AI Pact: voluntary early pledge
- Prohibitions bite about six months in
- GPAI duties about twelve months in
- Most Annex III high-risk about 24 months
- Extraterritorial when output is used in EU
- National sandboxes for supervised testing
Wider regulatory landscape
United States
- EO 14110 rescinded 2025, EO 14179 replaces it
- SR 11-7: model risk, independent validation
- ECOA, Regulation B: specific adverse action reasons
- NYC Local Law 144: AEDT bias audit
- Colorado: reasonable care, 2026, rebuttable presumption
- Illinois video interviews, Utah disclosure duty
- NAIC bulletin: insurer AI program
International
- Council of Europe convention: binding treaty
- UNESCO recommendation: non-binding
- OECD principles, soft law
- China: deep synthesis labeling
- GDPR Article 22 on automated decisions
- Brazil LGPD review of automated decisions
Reading the landscape
- Strategy, framework, statute: rising bindingness
- Sector law applies regardless of AI
- Layers coexist: binding, sectoral, soft, technical
- Divergent definitions block mutual recognition
- Common baseline plus jurisdiction modules
Assessments compared
- DPIA
- personal data, necessity, proportionality
- FRIA
- fundamental rights, certain deployers, Article 27
- Algorithmic impact assessment
- individuals, communities, society
- Conformity assessment
- provider proves the system complies
- Threshold assessment
- does a full assessment apply
- ISO 42001 impact assessment
- consequences to individuals and society
- HUDERIA
- human rights, democracy, rule of law
Conformity is the provider's pre-market proof; the impact assessment is the deployer's look at people affected
Running an impact assessment
- Scope
- Stakeholders
- Impacts
- Rate
- Mitigate
- Residual sign-off
- Review cadence
- Depth proportional to risk and scale
- Engage affected communities early
- Intersectional analysis of compounded disadvantage
- Vulnerable groups: differential impacts assessed
- Senior accountable owner accepts residual risk
- Material drift triggers re-assessment
- Coordinate DPIA and FRIA, reuse findings
- FRIA results go to the market surveillance authority
Monitoring and incidents
- Monitoring cadence set by risk tier
- Watch data drift and concept drift
- AI incident: harm, near miss, unexpected behavior
- Serious incidents reported to authorities
- Deployer suspends and informs on risk
- Provider corrects, withdraws or recalls
- Quarterly red teaming validates controls
- Logs kept as the Act requires
Vendor and supply chain
- Ask for documentation, evaluations, attestations, disclosures
- Upstream model and labelers are dependencies
- Rolling retraining: pin a versioned snapshot
- Exit strategy against lock-in
- SLA silent on accuracy and change notice
- Fine-tuning data vetting stays with the customer
- Shared responsibility for hosted models
Key numbers
- Four
- AI Act risk tiers
- Four
- NIST AI RMF functions
- Seven
- NIST trustworthiness characteristics
- Eight
- Annex III high-risk areas
- 6, 12, 24 months
- prohibitions, GPAI, Annex III
- 36 months
- Annex I product systems
- 7% or 35 million
- top fine, prohibited practices
- 3% or 15 million
- most other obligations
- 10^25 FLOPs
- systemic risk presumption
Reference strip: risk, NIST, AI Act, landscape, assessment
Risk basics
- Inherent, residual, appetite, tolerance
- KPI performs, KRI warns, KCI checks
- Accept with owner and review date
- Velocity and detectability matter
NIST AI RMF
- Govern, map, measure, manage
- Valid and reliable first
- Voluntary, not certifiable
- GenAI Profile: confabulation
EU AI Act
- Prohibited, high, limited, minimal
- Provider proves, deployer oversees
- Conformity, CE mark, registration
- GPAI: documentation, copyright, summary
- Post-market monitoring and incidents
Landscape
- SR 11-7, ECOA, LL144, Colorado
- Council of Europe treaty binds
- UNESCO and OECD are soft
- Sector law still applies
Assessments
- DPIA: data protection
- FRIA: fundamental rights
- Conformity: provider, pre-market
- Re-assess on drift or change
Quick exam traps
- Trap: The EU AI Act replaces the GDPR when AI processes personal data
- Trap: A conformity assessment and a FRIA are the same exercise
- Trap: An Annex III system that profiles people can claim the low-risk derogation
- Trap: Minimal-risk systems are free of every legal obligation
- Trap: ISO/IEC 23894 certification proves AI risk compliance
- Trap: A shrinking gap between inherent and residual risk means controls are improving
- Trap: Insurance transfers the harm to individuals away
- Trap: A DPIA signed at launch stays valid for the life of the system
cybercertprep.com · original revision sheet written from the public body of knowledge