Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
CASE STUDY
Please use the following to answer the next question:
A mid-size US healthcare network has decided to develop an AI solution to detect a type of cancer that is most likely to arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records to a radiologist for secondary review pursuant to agreed-upon criteria such as a confidence score below a threshold.
To date, the healthcare network has:
Defined its AI ethical principles
Conducted discovery to identify the intended uses and success criteria for the system
Established an AI risk committee
Assembled a cross-functional team with clear roles and responsibilities
Created policies and procedures to document standards, workflows, timelines and risk thresholds during the project
The healthcare network intends to retain a cloud provider to host the solution. It also intends to retain a large consulting firm to supplement its small data science team and help develop the algorithm using the healthcare network's existing data and de-identified data that is licensed from a large US clinical research partner.
Which of the following steps can best mitigate the possibility of discrimination prior to training and testing the AI solution?
The correct answer is C because performing an impact assessment is the most effective proactive measure to identify and mitigate discrimination risks before model training and testing. AI governance frameworks emphasize early-stage risk identification, particularly for high-stakes domains like healthcare, where bias can lead to harmful or inequitable outcomes. Impact assessments, such as algorithmic or data protection impact assessments, evaluate potential harms, affected populations, and fairness risks prior to development. This enables organizations to design appropriate safeguards, adjust data selection, and implement mitigation strategies before biases become embedded in the model. Options like audits and bias bounty programs are reactive or post-development controls, while simply acquiring more data does not guarantee reduced bias without proper analysis. A structured impact assessment aligns with risk-based governance and supports fairness, accountability, and regulatory compliance.
According to the EU Al Act, providers of what kind of machine learning systems will be required to register with an EU oversight agency before placing their systems in the EU market?
According to the EU AI Act, providers of high-risk AI systems are required to register with an EU oversight agency before these systems can be placed on the market. This requirement is part of the Act's framework to ensure that high-risk AI systems comply with stringent safety, transparency, and accountability standards. High-risk systems are those that pose significant risks to health, safety, or fundamental rights. Registration with oversight agencies helps facilitate ongoing monitoring and enforcement of compliance with the Act's provisions. Systems categorized under other criteria, such as those trained on sensitive personal data or exhibiting 'strong' general intelligence, also fall under scrutiny but are primarily covered under different regulatory requirements or classifications.
You are the chief privacy officer of a medical research company that would like to collect and use sensitive data about cancer patients, such as their names, addresses, race and ethnic origin, medical histories, insurance claims, pharmaceutical prescriptions, eating and drinking habits and physical activity.
The company will use this sensitive data to build an Al algorithm that will spot common attributes that will help predict if seemingly healthy people are more likely to get cancer. However, the company is unable to obtain consent from enough patients to sufficiently collect the minimum data to train its model.
Which of the following solutions would most efficiently balance privacy concerns with the lack of available data during the testing phase?
Utilizing synthetic data to offset the lack of patient data is an efficient solution that balances privacy concerns with the need for sufficient data to train the model. Synthetic data can be generated to simulate real patient data while avoiding the privacy issues associated with using actual patient data. This approach allows for the development and testing of the AI algorithm without compromising patient privacy, and it can be refined with real data as it becomes available. Reference: AIGP Body of Knowledge on Data Privacy and AI Model Training.
The planning phase of the Al life cycle articulates all of the following EXCEPT the?
The planning phase of the AI life cycle typically includes defining the objective of the model, choosing the appropriate architecture, and understanding the context in which the model will operate. However, the approach to governance is usually established as part of the overall AI governance framework, not specifically within the planning phase. Governance encompasses broader organizational policies and procedures that ensure AI development and deployment align with legal, ethical, and operational standards. Reference: AIGP Body of Knowledge, AI lifecycle planning phase section.
In 2025, which U.S. agency ordered companies to provide information about the safety of their AI companion chatbots?
The correct answer is C, the Federal Trade Commission. The FTC plays a central role in U.S. AI governance by enforcing consumer protection and unfair or deceptive practices laws. In the context of AI systems such as companion chatbots, the FTC has authority to investigate risks related to user harm, transparency, safety, and misleading claims. AI governance frameworks emphasize regulatory oversight where AI systems may impact individuals psychologically, financially, or socially. Agencies like the FTC focus on ensuring that companies deploying AI systems do not cause harm through unsafe or deceptive practices and that they provide adequate disclosures about risks and system behavior. This aligns with broader AI governance principles of accountability, transparency, and risk management highlighted in the AI Governance in Practice Report 2024 , which stresses the importance of regulatory involvement in managing AI-related risks.
194 questions covering all exam domains, starting from $20
Exam domains verified against: Official IAPP AIGP exam guide, last checked August 2026.
Understand core concepts of AI and machine learning, different types of AI models and systems, and the AI development life cycle.
Sample question from this domain above: Q4
Identify core harms and impacts of AI, recognize characteristics of trustworthy AI systems, and apply ethical guidance.
Establish AI strategy and AI governance, conduct AI risk identification and assessment, and apply risk management frameworks and standards.
Sample question from this domain above: Q1
Apply global AI-specific regulations, understand existing laws that apply to AI, navigate GDPR intersections, assess IP legislation and AI impacts, and evaluate liability reform.
Govern design and development of AI systems and manage the collection and use of data in training and testing.
Sample question from this domain above: Q3
Assess key factors and risks relevant to deployment decisions, evaluate the AI model, and establish governance for deployment and use.
Common questions about the exam itself