The complete study library
Explore the AIGP study library
Search 127 free study resources for AIGP. Find a lesson, review a term or choose a practice session.
127 resources
No matching resources
Try a broader term or reset the search to see the complete library.
AIGP Body of Knowledge 2026 explained
The four domains in the 2026 IAPP AIGP Body of Knowledge, translated into a practical study plan and exam-scenario checklist.
Guide · AIGPAIGP exam format and blueprint
Current AIGP format, timing and how to use the published IAPP Body of Knowledge and Exam Blueprint.
Guide · AIGPAIGP exam questions
How to approach AIGP questions using context, risk, governance controls and accountability.
Guide · AIGPAIGP practice exam
Independent AIGP practice questions, a timed-study method and an evidence-led review routine.
Guide · AIGPAIGP study guide
Free AIGP notes and study lessons arranged around four current knowledge areas, with retrieval practice and scenario review.
Guide · AIGPAIGP study plan
A four-week AIGP study plan using the published outline, retrieval practice and scenario questions.
Practice · AIGPFind the AIGP areas to study next.
Take a free 10-question AIGP diagnostic. Get an immediate domain score and a personalised study plan without creating an account.
Glossary · AIGPAIGP glossary
AIGP glossary with key AI governance terms, linked lessons and a practical way to review exam vocabulary.
Guide · AIGPHow to pass the AIGP
How to prepare for the IAPP AIGP exam using current format details, a flexible study plan, common mistakes and exam-style practice.
Guide · AIGPIs the AIGP exam hard?
Is the AIGP exam hard? Format, pass mark, the four domain weights, where candidates struggle and a practical way to prepare.
Practice · AIGPFree AIGP mini mock
Try 25 exam-style AIGP practice questions free, with explanations and a domain score. No account or payment required.
Practice · AIGPInstead of 'provider' and 'deployer', what term does South Korea's AI Basic Act use?
Instead of 'provider' and 'deployer', what term does South Korea's AI Basic Act use? Answer with a worked explanation and related free lesson.
Lesson · AIGPThe AI system development life cycle
Seven stages from plan/design to decommissioning, with governance hooks at each. The life cycle is iterative, not linear and building AI is never a…
Lesson · AIGPThe AI family tree
Each layer is a subset of the one above: GenAI ⊂ DL ⊂ ML ⊂ AI. Agentic AI is the odd one out - it can be comprised of all categories of AI, leveraging…
Lesson · AIGPArchitectures and the buzzwords that matter
Governance pros must hold a credible conversation about architectures: transformer models (process inputs in parallel), multimodal models/LMMs (WHO 2024…
Lesson · AIGPFour building-block terms
Data, algorithm, model and system nest inside each other and the exam tests them exactly. An algorithm produces the model; the model applies algorithms to…
Lesson · AIGPExpert systems
An older flavour of AI that mimics a human expert in one field via a knowledge base, inference engine and user interface. The canonical example is a…
Lesson · AIGPFive algorithms to recognise on sight
Governance pros must recognise five algorithms to talk risk: linear regression, logistic regression (binary outcome), decision trees, random forests (an…
Lesson · AIGPThe four ways machines learn
Four ML approaches: supervised (labelled), unsupervised (unlabelled), semi-supervised (small labelled + large unlabelled) and reinforcement (agent learns…
Lesson · AIGPThe intelligence ladder: ANI to ASI
Four levels of AI capability, only ANI fully real today. Broad AI is the intermediate step; AGI and ASI do not currently exist. If a question describes a…
Lesson · AIGPModel face-offs the exam loves
Four head-to-head comparisons straight from the performance indicator: classic vs generative, proprietary vs open source, small vs large LMs, and language…
Lesson · AIGPOECD Framework for the Classification of AI Systems
A user-friendly framework that classifies AI systems and examines their risks across five dimensions (mnemonic PEDMT). Privacy sits under People and…
Lesson · AIGPTech megatrends and AI
Some megatrends fuel AI, some are fuelled by it, and some raise the governance stakes. AI drives the need for PETs; blockchain is not universally…
Lesson · AIGPUse cases and benefits
The course groups AI uses into 7 buckets: Recognition, Event detection, Forecasting, Personalisation, Interaction support, Goal-driven optimisation and…
Lesson · AIGPWhat is AI
There is no single definition of AI; the exam wants the common elements that recur across definitions. AI is not a specific technology, but a branch of…
Lesson · AIGPWhy AI needs a comprehensive governance approach
Seven unique characteristics (mnemonic A COD SHiP) make AI harder to govern than ordinary software. The central governance challenge is balancing…
Lesson · AIGPThree AI harms taxonomies
AI-specific frameworks. The Sociotechnical Harms taxonomy has five themes; the CSET AI Harm Taxonomy defines AI harm with four elements, all four must be…
Lesson · AIGPEnvironmental harms
Four quantified facts - the numbers are the exam bait. Training a large model can emit over 626,000 pounds of CO₂ (~five times the lifetime emissions of…
Lesson · AIGPCreating ethical AI in practice
The operational checklist for deciding which use cases meet an organisation's ethical principles - spanning legal review, equitable design, transparency…
Lesson · AIGPSeven ethical issues and three foundational controls
The Seven ethical issues responsible AI must address - lawfulness, safety, bias protection, transparency, choice, human intervention, security - and the…
Lesson · AIGPEthics by design
Ethics by design is the sibling of privacy by design: ethical issues are resolved at the start and reassessed during deployment because risks change. The…
Lesson · AIGPThe FIPs: where all of this started
AI ethics frameworks descend from the FIPs (Fair Information Practices), originated in 1980 by the OECD Guidelines on the Protection of Privacy and…
Lesson · AIGPWho gets harmed: the five targets
The exam frames every harm question around who is affected. The Five harm targets are individuals, groups, society, organisations and ecosystems - and…
Lesson · AIGPGroup and societal harms
Group harm is discrimination against a population subgroup; societal harm is damage to the democratic process and participation. Examples include group…
Lesson · AIGPHarms taxonomies 101
A Harms taxonomy is a list of negative consequences that could befall a data subject or organisation - an ontological map breaking harms into constituent…
Lesson · AIGPIndividual harms and the anatomy of bias
Individual harms hit civil liberties, safety or economic opportunity, and bias is the engine. Know Implicit bias, Sampling bias and Temporal bias on…
Lesson · AIGPAI impacts and responsible AI
Before deploying AI, governance professionals must grasp the harms it can cause. AI poses risks already understood in existing sectors, but the scale…
Lesson · AIGPThe five OECD AI Principles
The OECD AI Principles are the base layer many organisations copy into their governance frameworks. Know all five (mnemonic: Inclusive Humans Trust Robust…
Lesson · AIGPOrganisational harms
Five harm types every organisation deploying AI must price in: reputational, cultural, economic, Acceleration risk and legal. Acceleration risk is the odd…
Lesson · AIGPThree privacy harms taxonomies
Match the name to the structure. MITRE PANOPTIC combines contextual domains and privacy activities; the Ryan Calo taxonomy splits harm into subjective vs…
Lesson · AIGPTrustworthy AI: the HAT test
The HAT test characterises trustworthy AI as Human-centric, Accountable, Transparent, operating in an expected, legal and fair manner. Explainability and…
Lesson · AIGPAI impact assessments and ISO 42005
The AI impact assessment (AIIA) is the severity lens: it gauges how bad mapped risks are, while a risk assessment flags which systems need extra…
Lesson · AIGPAligning risk strategies
New AI risk processes must slot into existing risk machinery. Determine whether AI increases existing risks or introduces new ones, decide who is…
Lesson · AIGPBusiness, regulatory and legal risks
Six direct business risks: bias & discrimination, job displacement, vendor dependence, liability & accountability, lack of transparency, IP infringement…
Lesson · AIGPCalculating risk
The working Risk formula is probability × severity. High: avoid or change; medium: explore and mitigate. Plus the four technical assessment categories and…
Lesson · AIGPCulture and operationalising responsible AI
Six culture moves (customer value, cultural variation, responsible AI as a discipline, HR engagement, common taxonomy, knowledge resources), then the…
Lesson · AIGPThe four AI risk categories
Operational, legal, security, privacy. The Security risk card carries the most testable vocabulary: Adversarial attacks, Hallucinations, Deepfakes and…
Lesson · AIGPThe four roles: developers, providers, deployers, users
Governance responsibilities shift across the AI life cycle. Know each role's signature duties: and the terminology trap that the Colorado AI Act says…
Lesson · AIGPGovernance structure: build it, then pick a model
Five build principles (leverage existing structures, foster community, clear roles, incentivise responsible AI, evolve the programme), then the three…
Lesson · AIGPISO 42001 and HUDERIA
Two frameworks with different DNA: ISO/IEC 42001:2023 is an AI management system standard for any size and industry, while HUDERIA is the Council of…
Lesson · AIGPLife cycle policies and the use case assessment
Policies must create oversight across nine areas of the AI life cycle. The Use case assessment is the front door, running NIST's Map (NIST), Measure…
Lesson · AIGPNIST AI RMF: the full kit
The NIST AI RMF has four pieces (framework, Core, Playbook, GenAI Profile) plus NIST ARIA. Keep the two quartets separate: the NIST Core functions are…
Lesson · AIGPRisk assessment mechanics
Greatest resources go to the highest-risk areas. The 3×3 harms matrix multiplies severity × probability for a score, tolerances vary by organisation, and…
Lesson · AIGPStakeholders: who sits at the table
Cross-functional collaboration is a tested performance indicator. Privacy, security, accessibility and digital safety personnel are crucial first…
Lesson · AIGPTailoring governance: six differentiators
There is no universal AI governance design. Six organisational factors drive the differences: company size, maturity, industry/sector, products &…
Lesson · AIGPTraining, awareness and AI literacy
Training targets the organisation's own AI use and governance, not general AI expertise, across three focus areas. AI literacy is a legal obligation under…
Lesson · AIGPWhat AI governance actually is
AI governance is an organisation's approach to using laws, policies, frameworks, practices and processes at international, national and organisational…
Lesson · AIGPWinning leadership support
Gain leadership support at the earliest opportunity. The course gives a five-step path: understand context, find champions, frame responsible AI as a…
Lesson · AIGPChina, Japan and the rest of the world
China runs a multi-layered, use-case-specific network overseen by the CAC, requiring security reviews and algorithm registration. Japan takes…
Lesson · AIGPConformity assessments, registration and notification
The Conformity assessment (CA) is how compliance is demonstrated for high-risk AI, underpinned by technical documentation. CAs borrow from DPIAs and…
Lesson · AIGPDeployers, importers and distributors
Deployer obligations are fewer than a provider's but broader, centred on transparency and monitoring (EU six-month minimum log retention; FRIA in the EU…
Lesson · AIGPThe eight requirements for high-risk AI
Major AI laws converge on eight obligations for high-risk AI: risk management, data governance, technical documentation, record-keeping, transparency…
Lesson · AIGPEnforcement and penalties
Enforcement runs through central authorities (EU AI Office, SK Ministry of Science & ICT, China's CAC), sectoral regulators and advisory bodies, using…
Lesson · AIGPThe EU AI Act and the Digital Omnibus
The EU AI Act is a risk-based regulation with extraterritorial reach. The AI Omnibus entered into force on 27 July 2026. Most of the Act applied from 2…
Lesson · AIGPThe four regulated roles
Regulation distributes duties across the supply chain: a Provider builds the system, an Importer brings it in, a Distributor passes it on, and a Deployer…
Lesson · AIGPGeneral-purpose AI models
General-Purpose AI (GPAI) models are trained for broad tasks and adapt into many downstream systems. EU AI Act Chapter V sets two tiers: baseline duties…
Lesson · AIGPHigh risk - where most regulation lives
High risk / high-impact AI significantly affects rights, safety or access to essential services. It is allowed but under strict obligations, and the…
Lesson · AIGPAI regulation across jurisdictions
Global AI laws share a common regulatory DNA of risk-based classification, role-based responsibilities and transparency requirements; what differs is how…
Lesson · AIGPLimited risk and minimal risk
Limited / transparency risk means disclosure or labelling duties only - inform users they are interacting with AI, label or watermark generated content…
Lesson · AIGPProhibited risk and the banned list
Prohibited risk AI is inherently harmful and restricted or banned in many jurisdictions. Six categories recur, including social scoring, manipulation…
Lesson · AIGPHigh-risk provider obligations
Providers carry the heaviest load because they build the system and put it on the market, so duties span the whole life cycle. Eight converging global…
Lesson · AIGPThe risk classification framework
Risk-based legislation classifies AI into four tiers - Prohibited, High, Limited, Minimal (mnemonic 'Please Handle Laws Mindfully') - and scales the…
Lesson · AIGPSouth Korea's AI Basic Act
The AI Basic Act is the second comprehensive national AI law, effective January 2026. It applies duties uniformly to Business operators (Development and…
Lesson · AIGPThe United States - orders, guidance and state laws
There is no single federal AI statute. Instead: executive orders (EO 14179 replaced the rescinded EO 14110, then America's AI Action Plan), federal…
Lesson · AIGPAnonymisation, Pseudonymisation and PETs
Recital 26 territory: anonymisation removes data from the GDPR entirely, while pseudonymisation is still personal information so GDPR obligations apply…
Lesson · AIGPArticle 22 and Automated Decision-Making
Article 22 is a general prohibition with three exceptions, never an outright ban: automated decision-making is allowed only when necessary for a Contract…
Lesson · AIGPConsumer Protection Laws and AI
The FTC's broad authority over "unfair or deceptive" practices already covers algorithms, and the agency will keep applying it to AI. Several US laws…
Lesson · AIGPObligations on Data Controllers
Controllers decide what and how personal data is processed - whether a human or an AI does the processing, the GDPR still applies. Nine duty areas span…
Lesson · AIGPThe EDPB Opinion on AI Models (2024)
Prompted by the Irish DPA, the European Data Protection Board harmonised how the GDPR treats AI models in three answers: when a model is anonymous, when…
Lesson · AIGPThe GDPR and AI
In effect since 2018, the GDPR is the global baseline for data protection, deliberately technology-agnostic so it can evolve alongside AI. Three…
Lesson · AIGPIntellectual Property and AI
IP is creations of the human mind protected by patents, copyright and trademarks - and generative AI stretches every part of that definition. Key anchors…
Lesson · AIGPThe Lay of the Land
AI may dodge a dedicated statute, but it lives in the same legal context as every other technology: ALL existing laws for a sector or jurisdiction still…
Lesson · AIGPLicensing AI Models and Data
The contract is where IP risk gets managed. Traditional IP indemnities break down for AI because they exclude modifications, combinations and out-of-scope…
Lesson · AIGPNondiscrimination Laws Across Five Sectors
Sector nondiscrimination laws still apply to AI across healthcare, insurance, hiring, credit and housing. Key anchors: Section 1557 (healthcare), NYC…
Lesson · AIGPPrivacy Principles That Govern AI
GDPR, CCPA/CPRA, US state privacy laws, biometrics laws like Illinois BIPA and breach laws all reach consumer-facing AI. Seven principles do the heavy…
Lesson · AIGPProduct Liability Foundations
Who answers when AI causes harm? Two regimes: fault liability (prove an action/inaction caused harm) and strict liability (no-fault - prove only defect…
Lesson · AIGPThe Revised Product Liability Directive
Directive 2024/2853, effective December 2026, makes it easier for victims of AI-caused harm to prove liability and get compensated. It expands "products"…
Lesson · AIGPSensitive and Special Categories of Data
Special categories of data need extra protection under the GDPR and Brazil's LGPD - eight types captured by the mnemonic "Really Private Records Take…
Lesson · AIGPBuilding, Training and the Three Lines of Defence
Development is iterative - train, test, fine-tune, then prove the model generalises on new data beyond the training set. Human oversight uses the 3LOD…
Lesson · AIGPData Formats and the Five V's
Know the three structure types (structured, unstructured, semi-structured), the static/streaming split, and the five V's of data preparation: Volume…
Lesson · AIGPGoverning the AI Data Life Cycle
Data governance spans ingestion to decommissioning with cross-functional stewardship. The data life cycle runs Collection: Use: Disclosure: Retention…
Lesson · AIGPData Questions, Quality, Jurisdiction and Lineage
Without the right, enough and accurate data the system won't perform - garbage in, garbage out. Anticipate jurisdiction (data localisation laws, KYC), and…
Lesson · AIGPDocumentation, Communication and Decommissioning
Document every decision with model cards, counterfactual explanations and remediation owners; communicate by audience; and retire systems via ten…
Lesson · AIGPFeatures and Feature Engineering
A feature is a specific measurable aspect or characteristic. Feature engineering decides which ones matter, with three purposes - improve performance (the…
Lesson · AIGPImpact Assessments in the Design Phase
An impact assessment is a risk management tool assessing an AI system's benefits, risks and limitations across the life cycle. The AIA covers data issues…
Lesson · AIGPThe AI Development Life Cycle Revisited
AI development mirrors the software life cycle plus a data obsession and continuous monitoring. Policies, procedures, best practices and ethics apply at…
Lesson · AIGPMetrics, Thresholds, Audits and Monitoring
Establish measures (e.g. the Adverse Impact Ratio), set thresholds, baseline, then monitor over time. Audits assess performance, reliability and safety…
Lesson · AIGPOperational Controls - Five Owners to Name
Controls are only real when someone owns them. The memorable owner is the kill switch - a named person with authority to shut the system down when an AI…
Lesson · AIGPPlanning Essentials - The Five Moves
Define objectives, pick use cases, scope, check the data, stand up governance - in that order. Scope is prioritised via Impact, Effort and Fit, and…
Lesson · AIGPThe Six Risk Assessment Strategies, In Order
A repeatable sequence - Use Smart Methods, Handle Big Projects - to identify, evaluate, treat and mitigate risk: use case evaluation, stakeholder mapping…
Lesson · AIGPStakeholders - Who, What, and the Hard Calls
Engage stakeholders early, agree the goal, and decide who owns the failures. When values clash - e.g. more accuracy than privacy - the organisation must…
Lesson · AIGPTesting and Validation
Testing is continuous, risk-tailored and documented - test for accuracy, robustness, reliability, privacy, interpretability, safety, security and bias…
Lesson · AIGPWrangling the Data
Five considerations turn raw data into model-ready data without trampling privacy: cleansing, labelling, anonymisation and minimisation. Master the two…
Lesson · AIGPAdapting existing policies for AI
Review the current policy framework for gaps first, then tailor what exists and add what's missing across five areas - data privacy, security…
Lesson · AIGPAgentic AI - what it is
Agentic systems engage, interact and influence rather than sit passively. AI agents focus on specific tasks with simple workflows; Agentic AI involves…
Lesson · AIGPThe agentic risk landscape
Autonomy brings four new risk families: goal misalignment (right goal, wrong way), compounded systemic impact (errors spread across departments and…
Lesson · AIGPWhere the model lives - three environments
The deployment environment depends on budget, IT expertise, model purpose and data type. Cloud scales, on-prem controls, edge localises - each buys one…
Lesson · AIGPGenAI choices and the pre-launch checklist
Generative deployments add their own questions - fine-tuning, retrieval-augmented generation, vector/graph databases and agentic architectures…
Lesson · AIGPIncidents, consequences and accountability
Treat every occurrence as an incident, keep records in an AI registrar, and know the five usual causes - brittleness, lack of robustness, lack of quality…
Lesson · AIGPGoverning AI deployment
Whatever was built, bought or customised, every organisation deploys AI as the final step before use. Deployment is the transition from a development and…
Lesson · AIGPMonitoring, maintenance and drift
Watch for deviations in accuracy and model drift - when the relationship between input data and output predictions changes over time. Model cards document…
Lesson · AIGPPeriodic assessment - performance, reliability, safety
Three assessment lanes keep an ageing model in check: performance, reliability and safety. Four definitions recur: red teaming (simulated adversarial…
Lesson · AIGPDeploying a proprietary model
Developing AND deploying your own model creates a dual role with heightened liability from both providing and using the technology. It brings five…
Lesson · AIGPPublic disclosures and transparency obligations
One notice never fits all, but one rule is near-universal: almost all AI laws worldwide require disclosure that AI is in place, treated by the FTC as a…
Lesson · AIGPRelease readiness
A readiness assessment decides whether the system goes to production. Well-Tested Code Deserves Model-cards - Works as intended, Testing turned out well…
Lesson · AIGPThird-party products and risk
Less visibility never means less responsibility. Third-party AI splits into two contexts - integrated into business operations (needs the more…
Lesson · AIGPThe three-tier guardrail framework
Guardrails scale with use-case risk: Foundation: Risk: Society. Tier 1 foundational guardrails apply to every system and follow ISO/IEC 42001 and the NIST…
Lesson · AIGPThe vendor / open-source agreement checklist
Eight areas to evaluate before signing a vendor or open-source agreement: data considerations, security/safety, bias metrics, product type, technical…
Lesson · AIGPCore AI concepts
The foundation layer of the AIGP vocabulary: what AI is, what it runs on, and its classic forms. Artificial intelligence is defined as machine-based…
Lesson · AIGPData terms
Everything the model eats, before and after cooking. Know which dataset does which job: training data teaches, validation data tunes and checks…
Lesson · AIGPGenerative AI
The GenAI stack from foundation model to prompt - architecture names matter here. RAG is defined by retrieving from a knowledge base beyond the training…
Lesson · AIGPGovernance, assurance and oversight
The accountability vocabulary - who answers, who checks, who can challenge. Conformity assessment is the EU AI Act gate for high-risk systems before…
Lesson · AIGPLearning techniques and methods
The named techniques and model types that show up as one-line scenario answers - including federated learning (data never leaves the site), transfer…
Lesson · AIGPMachine learning families
The four learning paradigms plus the architecture they run on. Label availability is the sorting key: supervised uses labelled pairs, unsupervised finds…
Lesson · AIGPModel mechanics and performance
What is inside the model and how its behaviour is measured and goes wrong. Variables live in the data; parameters and weights live in the model - and…
Lesson · AIGPRisks, security and harms
The attack surface and the falsehood family. Intent is the dividing line: disinformation is deliberate, misinformation is not - and data poisoning is an…
Lesson · AIGPTrust attributes and safeguards
The qualities systems must show and the artifacts and controls that prove or protect them. Reliability is consistency over time; robustness is resilience…
Looking for AI governance? Explore the AIGP study guide.