IAPP AIGP Exam Prep
Artificial Intelligence Governance Professional (Page 8 )

Updated On: 10-Sep-2026

A US company has developed an AI system, CrimeBuster 7909, that collects information about incarcerated individuals that predicts whether someone is likely to commit another crime if released from prison.
When considering expanding to the EU market, this type of technology would:

  1. Require the company to register the tool with the EU database.
  2. Require the application of privacy enhancing technologies.
  3. Be subject to approval by the relevant EU authority.
  4. Be banned under the EU AI Act.

Answer(s): D

Explanation:

The correct answer is D: Be banned under the EU AI Act. Here's why:
The EU AI Act categorizes AI systems based on risk. AI systems used for predicting recidivism (the likelihood of re-offending) in law enforcement and criminal justice are classified as high-risk and, critically, certain applications within this category are prohibited. The CrimeBuster 7909 system falls squarely into this prohibited category because it predicts the likelihood of an individual committing another crime based on data collected about incarcerated individuals.
Article 5(1)(a) of the EU AI Act specifically prohibits "the placing on the market, putting into service or use of AI systems that deploy subliminal techniques beyond a person’s awareness or purposeful manipulative or deceptive techniques, with the objective or the effect of materially distorting the behaviour of that person in a manner that causes or is likely to cause that person or another person physical or psychological harm." Although CrimeBuster 7909 may not be directly manipulating individuals, its predictive capabilities, if acted upon, could significantly distort decisions related to parole, rehabilitation, or sentencing, impacting individual liberty and potentially causing psychological harm.
Furthermore, the Act places a high emphasis on fundamental rights, including the right to non-discrimination and fair trial. AI systems like CrimeBuster 7909 often suffer from inherent biases present in the training data, leading to discriminatory outcomes against certain demographic groups. Because of this inherent risk of perpetuating systemic bias and potential violation of fundamental rights, the EU AI Act is highly likely to ban such a system. It is important to differentiate this from other high-risk AI applications where strict regulatory compliance may be sufficient; in this specific case, the inherent risk means a prohibition is more probable.
Therefore, the US company must seriously consider the ramifications of the EU AI Act before considering expansion of CrimeBuster 7909 into the EU, as it would likely face an outright ban due to its potential for bias, harm, and conflict with fundamental rights.
Authoritative Links:
EU AI Act - Provisional Agreement: https://www.europarl.europa.eu/news/en/press-room/20231206IPR15699/artificial-intelligence-act-deal-on-comprehensive-rules-for-trustworthy-ai European Commission AI Act Proposal: https://artificialintelligenceact.eu/



Which of the following disclosures is NOT required for an EU organization that developed and deployed a high-risk AI system?

  1. The human oversight measures employed.
  2. How an individual may contest a decision.
  3. The location(s) where data is stored.
  4. The fact that an AI system is being used.

Answer(s): C

Explanation:

The correct answer is C, "The location(s) where data is stored," because under the EU AI Act, the primary disclosure focus for high-risk AI systems revolves around transparency concerning the system's operation and impact on individuals, not necessarily the granular details of data storage locations.
The EU AI Act prioritizes transparency and accountability. Disclosing that an AI system is in use (D) is crucial for individuals to understand they are interacting with AI and not a human, directly addressing transparency mandates. Describing the human oversight measures (A) employed is critical because it demonstrates accountability and risk mitigation, showing how humans retain control over the AI system's output and can intervene when necessary. Explaining how an individual may contest a decision (B) ensures procedural fairness and allows recourse if the AI system makes an unfavorable or inaccurate judgment about them, fulfilling principles of fairness and redress.
While data governance and security are vital considerations for AI systems and are covered by GDPR, the specific storage locations are not a direct disclosure requirement under the AI Act's transparency provisions for high-risk AI systems. This doesn't mean data location is irrelevant; GDPR still requires organizations to know where data is stored. However, the AI Act specifically aims to inform individuals about how the AI system functions and impacts them.
Instead of focusing on the location of data storage, the AI Act emphasizes disclosing details like the system's intended purpose, performance metrics, potential biases, and the mechanisms for human oversight and intervention. This makes sense because individuals are more concerned with the outcome of the AI system's operation and the procedures they can follow if the outcome is unfair or incorrect. Requiring details about specific datacenters, for instance, would add complexity and information overload without significantly enhancing the individual's ability to understand or challenge the AI's actions.
Authoritative Links:
EU AI Act Draft: https://artificialintelligenceact.eu/ European Commission AI Strategy: https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence



In accordance with the EU AI Act, for how long after a high-risk AI system has been placed on the market must the provider keep the relevant documentations at the disposal of the national competent authorities?

  1. 10 years.
  2. 8 years.
  3. 6 years.
  4. 5 years.

Answer(s): A

Explanation:

The correct answer, 10 years, stems directly from the requirements outlined within the EU AI Act. Article 52(5) of the proposed Act specifically states that providers of high-risk AI systems must keep the technical documentation and the EU declaration of conformity at the disposal of the national competent authorities for a period of 10 years after the AI system has been placed on the market or put into service. This requirement is crucial for ensuring ongoing oversight and accountability regarding high-risk AI systems.
The rationale behind the decade-long retention period is to allow sufficient time for potential risks or adverse impacts of the AI system to manifest and be investigated. AI systems, particularly complex models deployed in cloud environments, can exhibit emergent behaviors over time, making long-term monitoring and auditing essential. Having access to detailed documentation allows authorities to assess the system's design, development process, and compliance with the Act's requirements, even years after its initial deployment.
This documentation might include details about the training data used, the system's architecture, the risk management strategy employed, and the results of conformity assessments. Consider a high-risk AI system used in cloud-based credit scoring: if biases are discovered five years after deployment leading to discriminatory lending practices, regulators require access to historical documentation to investigate and rectify the problem. The 10-year requirement enables effective post-market monitoring, auditability, and enforcement of the AI Act, enhancing consumer protection and promoting responsible AI innovation. Failing to comply with this retention requirement can lead to substantial penalties under the AI Act.
Relevant Link:
EU AI Act (Draft): https://artificialintelligenceact.eu/



The OECD’s Ethical AI Governance Framework is a self-regulation model that proposes to prevent societal harms by:

  1. Establishing explainability criteria to ethically source and use data to train AI systems
  2. Defining ethical requirements specific to each industry sector and high-risk AI domain.
  3. Focusing on ethical AI technical design and post-deployment monitoring
  4. Balancing AI innovation with ethical considerations.

Answer(s): D

Explanation:

The correct answer is D. Balancing AI innovation with ethical considerations. Here's a detailed justification:
The OECD’s AI Ethical Framework aims to foster responsible AI development and deployment, not by rigidly defining technical specifications or sector-specific requirements, but by advocating for a holistic approach that weighs the potential benefits of AI innovation against its possible societal harms. The core principle involves proactively identifying and mitigating risks associated with AI systems while simultaneously encouraging innovation and growth within the AI space.
Option A is incorrect because, while explainability is important, the framework's primary goal isn't solely establishing explainability criteria. Option B is incorrect as the OECD Framework is a broad guideline intended to be adaptable across different sectors and not a prescriptive, sector-specific rulebook. Option C is also incorrect as the OECD framework addresses the entire lifecycle of AI, from design to deployment and beyond, rather than just focusing on technical design and post-deployment monitoring.
The OECD framework promotes the core values of fairness, transparency, accountability, and human oversight in the development and application of AI. It encourages stakeholders to implement mechanisms to identify, assess, and mitigate risks, thus ensuring that AI advancements align with societal values and respect human rights. The key is striking the balance between encouraging AI advancement and ensuring its ethical and responsible use. This is achieved through principles and recommendations applicable across various sectors and promotes continuous monitoring and adaptation to manage the evolving risks associated with AI.
Authoritative Links:
OECD AI Principles: https://oecd.ai/ Recommendation of the Council on Artificial Intelligence: https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449



ISO 42001 International Standard offers guidance for organizations to develop trustworthy AI management systems by:

  1. Requiring specific minimum parameters for key suppliers and key aspects of AI management systems.
  2. Requiring organizations to continuously improve the effectiveness of their AI management systems.
  3. Focusing on high-risk aspects of development of AI management systems.
  4. Explicitly over-riding previously issued and now outdated ISO standards.

Answer(s): B

Explanation:

ISO 42001 focuses on establishing, implementing, maintaining, and continuously improving an AI management system (AIMS). This aligns directly with option B. The standard adopts the Plan-Do-Check-Act (PDCA) cycle, a core principle of management systems, which inherently emphasizes continuous improvement. This iterative approach ensures that the AIMS remains relevant, effective, and adapts to evolving AI technologies and organizational needs.
Option A is incorrect because while ISO 42001 provides guidance for risk management and supply chain oversight, it doesn't prescribe specific minimum parameters. Instead, it guides organizations to define their own parameters based on their unique context and risk assessments. The standard provides a framework, not a rigid checklist.
Option C is partially correct as ISO 42001 emphasizes risk management, particularly concerning high-risk AI applications. However, it doesn't exclusively focus on high-risk aspects; the standard covers the entire AI lifecycle and associated management processes, including development, deployment, and monitoring.
Option D is incorrect because ISO standards are designed to be complementary and evolve together. ISO 42001 builds upon existing management system standards, not replaces them. The intention is to integrate AI governance seamlessly within broader organizational governance frameworks. In essence, ISO 42001 provides the framework for trustworthy AI by mandating a system of continuous improvement, adjusting to the AI landscape, and mitigating risks.
Further research:
ISO 42001: Search online for official announcements and explanations about the standard. Details might be subject to changes, check for official publications and related webinars from the ISO itself. Plan-Do-Check-Act (PDCA) Cycle: https://asq.org/quality-resources/pdca-cycle (This explains the basic concept behind continual improvement)



Viewing page 8 of 46
Viewing questions 36 - 40 out of 222 questions


Post your Comments and Discuss IAPP AIGP exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!