296 KP-linked cards with spaced repetition and weak-card surfacing.
02 · Reference
Study Materials
Study Guide, Cram Sheet, Exam Essentials, and narrated Lectures.
03 · Schedule
Study Planner
Personalized day-by-day schedule calibrated to your exam date.
04 · Practice
Mock Exam & Practice
5 mock exams · Wrong Answer Review · Key Practice by KP.
Domain I — Today's Session
Card 4 of 12 · Due Today · Weak Cards Surfaced First
Domain I · Foundations of AI Governance
KP-I-A-1-003
Risk-Based Approach to AI Governance
Tap to flip and see the full explanation
Risk-Based Approach
Governance obligations are calibrated to actual risks posed by an AI system — not to technical capability or sector. High-risk applications face stricter requirements; minimal-risk systems face light or no requirements.
This principle underpins both the EU AI Act (4-tier classification) and the NIST AI RMF (MAP function: categorize risk in context). Applying it prevents both over-regulation of low-stakes tools and under-regulation of dangerous systems.
Exam angle: If a question asks why the EU AI Act does NOT regulate a simple spam filter as heavily as a medical diagnosis system — the answer is risk-based proportionality.
Comprehensive textbook across all 4 domains with inline KP cross-references.
02 · Quick Ref
Cram Sheet
Comparison tables, mnemonics, and last-minute review lists.
03 · Focus
Exam Essentials
Must-memorize definitions, trigger words, and exam death traps.
04 · Audio
Lectures
Narrated slide decks with karaoke highlights and per-slide notes.
Study Guide
Domain I · Foundations of AI & Privacy Governance
Domain I
Domain II
Domain III
Domain IV
I.A — AI Governance Frameworks
Modern AI governance is built on a risk-based model: the obligations imposed on an AI system are proportional to the potential harm it could cause. KP-I-A-1-003
The NIST AI Risk Management Framework (AI RMF) organizes governance into four core functions that apply throughout the AI lifecycle: KP-I-A-1-008
GOVERN · MAP · MEASURE · MANAGE
GOVERN establishes policies, culture, and roles. MAP identifies and categorizes AI risks in context. MEASURE analyzes and prioritizes those risks. MANAGE addresses, monitors, and responds to risks on an ongoing basis.
Exam Tip
NIST AI RMF is voluntary and sector-agnostic. The EU AI Act is mandatory and risk-tiered. Both are risk-based — but differ in legal weight and geographic scope. This distinction is a frequent exam differentiator.
The framework was published in January 2023 and revised (AI RMF 1.0) the same month. It is designed to be used alongside sector-specific guidance — it does not replace existing regulations.
I.A — EU AI Act Risk Tiers
The EU AI Act classifies AI systems into four risk tiers, each with distinct obligations: KP-I-A-1-001
Unacceptable Risk (Prohibited)
Systems that pose an unacceptable threat to people's safety, livelihoods, or rights. Examples: subliminal manipulation below conscious awareness causing harm; real-time biometric surveillance in public spaces (narrow exceptions apply); social scoring by public authorities.
High Risk
Systems used in critical areas listed in Annex III: biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice. These must undergo conformity assessment, maintain technical documentation, and enable human oversight.
Exam Tip
Annex III lists 8 categories of high-risk AI. Memorize: biometrics, infrastructure, education, employment, essential services, law enforcement, migration/border, justice/democracy.
Limited Risk
Systems with specific transparency obligations — for example, chatbots must disclose they are AI; deepfake content must be labeled as AI-generated.
Minimal Risk
All other AI systems: spam filters, AI in video games, recommendation systems. No specific obligations under the Act, though voluntary codes of practice apply.
Death Trap
High-risk AI is NOT the same as prohibited AI. High-risk AI is permitted subject to conformity requirements. Prohibited AI is banned outright. Conflating these is one of the most common AIGP exam errors.
Cram Sheet
Domain I · Quick-reference comparisons
GDPR vs. EU AI Act — Core Differences
Dimension
GDPR
EU AI Act
Subject matter
Personal data processing
AI systems placed on EU market
Risk model
Data subject rights + harm
4-tier (prohibited → minimal)
Key duty
Lawful basis + DPO + DPIA
Conformity assessment + CE marking
Enforcer
National DPA
National market surveillance + AI Office
Max fine
4% global turnover / €20M
3–7% global turnover (tier-dependent)
Mnemonic
GDPR = data flows · EU AI Act = system tiers. They overlap when a high-risk AI system also processes personal data — both regimes apply simultaneously. A DPIA may be required AND a conformity assessment.
NIST AI RMF vs. ISO/IEC 42001
Dimension
NIST AI RMF
ISO/IEC 42001
Type
Framework (voluntary guidance)
Certifiable standard
Origin
US (NIST)
International (ISO/IEC)
Structure
GOVERN/MAP/MEASURE/MANAGE
Plan-Do-Check-Act (PDCA)
Certification
No third-party cert
Yes — auditable AI management system
Exam Essentials
Domain I · Death traps & trigger words
Death Traps — EU AI Act
⚠ Death Trap #1
"High-risk AI = Prohibited AI" — WRONG. These are separate tiers. Prohibited systems are banned outright. High-risk systems are allowed but must meet strict conformity, documentation, and transparency requirements. On the exam, if a question describes a system that "requires conformity assessment" — that's high-risk, not prohibited.
⚠ Death Trap #2
"NIST AI RMF is legally binding in the US" — WRONG. It is voluntary guidance. No US federal AI law currently mandates its adoption, though sector-specific agencies may reference it in regulation. Contrast with the EU AI Act, which IS legally binding.
⚠ Death Trap #3
"A GPAI model = an AI system under the EU AI Act" — NOT automatically. A general-purpose AI model becomes subject to high-risk obligations only when it is integrated into a high-risk application and actually deployed. The provider of the foundation model has separate, lighter duties under Article 53.
⚠ Death Trap #4
"Deterministic rule-based software = AI system" — WRONG under EU AI Act Article 3(1). A system that applies fixed IF-THEN rules with no learning capability does not perform "inference" and is therefore NOT an AI system for regulatory purposes. This distinction matters for scope questions.
Trigger Words — Domain I
Real-time biometric
→ Likely prohibited (in public, law enforcement)
Subliminal
→ Prohibited if causes harm below threshold
Conformity assessment
→ High-risk (not prohibited)
Voluntary / guidance
→ NIST AI RMF (not EU AI Act)
CE marking
→ EU AI Act high-risk obligation
GOVERN/MAP/MEASURE
→ NIST AI RMF functions
1:24 / 3:427 / 15
I.A · AI Governance Frameworks · Slide 7
The EU AI Act Risk Classification System
The EU AI Act uses a tiered risk model — obligations scale with potential harm. Each tier carries a distinct set of requirements, from outright prohibition to voluntary codes.
Tier 1 — Prohibited:Systems banned for posing unacceptable societal risk — subliminal manipulation, real-time public biometrics, social scoring by state actors.
Tier 2 — High Risk: Annex III applications (8 categories). Must pass conformity assessment, maintain documentation, enable human oversight, register in EU database.
Tier 3 — Limited Risk:Transparency obligations only — chatbots must disclose AI identity; deepfakes must be labeled.
Tier 4 — Minimal Risk: No specific obligations. Voluntary AI codes of practice encouraged.
The critical exam insight: conformity assessment ≠ prohibition. A system requiring conformity assessment is high-risk — it can be deployed after assessment. Only Tier 1 systems are banned.
📝 My Note — Slide 7
Remember: Annex III has exactly 8 categories. Conformity = high-risk permitted. Real-time biometrics in PUBLIC = prohibited (law enforcement narrow exceptions). Post-market monitoring mandatory for high-risk after deployment.
The EU AI Act uses a tiered risk model — obligations scale with potential harm.
KP-I-A-1-003 · Risk-Based Approach
Practice Questions · 7 questions for this KP
Domain I · KP-I-A-1-003
Under the EU AI Act, an organization's automated CV screening tool rejects candidates based on AI-assessed cultural fit scores. The system has been validated and certified. Which tier most accurately describes this system?
A. Prohibited AI — cultural fit scoring constitutes social scoring by an employer.
B. High-risk AI — employment screening is an Annex III category requiring conformity assessment.
C. Limited risk — only transparency obligations apply since it involves decision-making.
D. Minimal risk — the system has been validated and poses no significant harm.
✓ Correct — Option B
Employment and recruitment screening is explicitly listed in Annex III, Category 4 of the EU AI Act as a high-risk AI use case. High-risk AI is permitted subject to conformity assessment, documentation, and human oversight requirements. Option A is incorrect: social scoring by employers is not a prohibited practice — prohibition applies to social scoring by public authorities. Option D is a classic death trap: validation does not change the tier classification.
Mock Exam & Practice
targeted review · full simulation
01 · Exam
Mock Exam
100 q · 180 min · Part 1 + Break + Part 2.
02 · Browse
All Practice
1,170 questions by domain, topic, or KP.
03 · Flagged
Key Practice
Questions you flagged as critical review points.
04 · Review
Wrong Answer Review
Re-attempt every question you've answered incorrectly.
All Practice — By Knowledge Point
Select a domain to browse knowledge points
Domain I
Foundations of AI & Privacy Governance
289 questions · 24 KPs
Domain II
AI Laws, Regulations & Standards
312 questions · 28 KPs
Domain III
AI Development Governance
341 questions · 31 KPs
Domain IV
AI Deployment & Use Governance
228 questions · 21 KPs
Domain I — Knowledge Points
289 questions across 24 KPs
Competency A · AI Concepts & Technologies
KP-I-A-1-003Risk-Based Approach to AI Governance7 q
KP-I-A-1-001Definition and Types of AI Systems13 q⚡ gap
KP-I-A-1-008NIST AI Risk Management Framework19 q✓ done
KP-I-A-2-001Machine Learning Fundamentals11 q
KP-I-A-3-001Foundation Models & GPAI8 q⚡ gap
Competency B · AI Risks & Harms
KP-I-B-3-001Bias, Fairness & Discrimination in AI20 q⚡ gap
KP-I-B-5-007AI Transparency & Explainability13 q
KP-I-B-1-001AI System Lifecycle & Governance Points9 q
Question 1 of 7KP-I-A-1-003
Domain I · Foundations · KP-I-A-1-003
A manufacturing company deploys an AI system that uses fixed IF-THEN rules: alerts trigger if temperature exceeds 80°C; shutdown occurs if pressure falls below 2 atm. The system has no learning capability and does not adapt to new data. Under EU AI Act Article 3(1), how is this system most likely classified?
A. A general-purpose AI model requiring transparency obligations under Article 53.
B. A high-risk AI system that qualifies for exemption under Annex III industrial machinery provisions.
C. A minimal-risk AI system subject only to voluntary codes of practice.
D. Deterministic software that does not qualify as an AI system under the EU AI Act definition.
✓ Correct — Option D
Article 3(1) requires that an AI system generate outputs "through inference." A purely fixed IF-THEN rule system applies pre-set thresholds — it performs no inference and has no adaptive capability. It therefore falls outside the EU AI Act's scope entirely. This is a frequent exam trap: not all automated software is AI under the Act.
Wrong Answer Review
✕ 34 questions answered incorrectly
#1
Which EU AI Act tier requires CE marking and registration in the EU AI database?
✗ Your answer: Limited Risk
✓ Correct: High Risk
KP-I-A-1-001
#2
NIST AI RMF is described as "sector-agnostic." This means it...
✗ Your answer: Applies only to federal agencies
✓ Correct: Can be adopted by any organization regardless of sector
KP-I-A-1-008
#3
An AI chatbot on an e-commerce site assists customers. The EU AI Act most likely classifies this as...
Which function of the NIST AI RMF involves identifying and categorizing AI risks in their organizational context?
✗ Your answer: GOVERN
✓ Correct: MAP
KP-I-A-1-008
Key Practice
⚑ 18 questions flagged for review
⚑
A law enforcement agency uses an AI system for real-time facial recognition in a public square to identify suspects. Under the EU AI Act, this system is most likely...
Flagged during Mock Exam B · Part 1
KP-I-A-1-001
⚑
Which of the following best describes the relationship between a DPIA under GDPR and a conformity assessment under the EU AI Act when a high-risk AI system processes personal data?
Flagged during Practice — Domain II
KP-II-A-2-001
Part 1 / 50
Question 7 of 50
02:43:18
Domain II · Laws & Standards
An organization's AI governance policy requires a Data Protection Impact Assessment before deploying any AI system that processes personal data. Which EU regulation most directly mandates this DPIA requirement?
A. EU AI Act — Article 9 (Risk Management System for high-risk AI)
B. GDPR — Article 35 (Data Protection Impact Assessment)
C. EU AI Act — Recital 47 (High-Risk System Documentation)
D. ePrivacy Directive — Article 5 (Confidentiality of Communications)
Flashcards — Domain III (57 due) · Study Guide III.C
9
Wed Jun 11
Wrong Answer Review · Cram Sheet — Domain III (weak)
10
Thu Jun 12
Mock Exam — Form B (180 min)
📋 Mock
11
Fri Jun 13
Review mock results · Practice Domain III (gap KPs)
12
Sat Jun 14
Lectures — Domain IV · Key Practice (flagged 18 q)
Tuesday, June 10
Day 8 of 18 · 45 min target · Domain III weighted
Today's Tasks
🃏
Flashcards — Domain III
57 cards due · Weak: KP-III-C-1-001, KP-III-C-5-005
~20 min
○
📖
Study Guide — Domain III.C
AI Development Governance · Technical Robustness
↩ rolled over from Jun 9
~15 min
○
✕
Wrong Answer Review
Focus: Domain III misses from Mock Form A
~10 min
○
Each task links directly into the study mode — tap to open. Completing all tasks marks the day done and unlocks tomorrow's schedule.
Why JC AIGP Quick Pass
One product. Every angle of the exam.
The same knowledge point appears in your flashcards, study guide, cram sheet, and lecture — connected by clickable KP badges. You build a map, not just a list of facts.
🌐
Auto-translates in any browser
Pure HTML — right-click → Translate in Chrome, Safari, Edge. No plugin required. Full bilingual support for any language.
💻
Fully offline, any machine
One HTML file. Works on locked-down corporate laptops, tablets, or any device with a browser — no installation ever.
🔗
KP-linked multimodal study
Every flashcard, question, and lecture slide links to the same KP. Click any badge to cross-navigate all formats for that concept.
📊
Calibrated to real exam format
5 mock exams built to the official 5-tier question blueprint. Your mock score is a reliable readiness thermometer.