AIGP - Understanding how laws, standards and frameworks apply to AI (25% of the exam) - Section 2.5

Understand the key requirements of AI-specific laws regarding human oversight, transparency, technical documentation, conformity assessments, general-purpose AI models, and organisational roles.

Describe the key requirements of AI-specific laws, including human oversight mechanisms, transparency obligations, technical documentation, conformity assessments, and rules for general-purpose AI models. Compare requirements under the EU AI Act and the South Korean AI Basic Law.

EU AI ActSouth Korean AI Basic Lawgeneral-purpose AI modelsconformity assessment

Practice question for this objective

Free sampleUnderstanding how laws, standards and frameworks apply to AIhard

A multinational classifies one of its products as a high-impact AI system within the meaning of South Korea's AI Basic Act and is mapping the substantive duties the Act attaches to that classification, as distinct from the broader duties it owes for any generative output. Which two obligations does the Act most directly impose on the operator of a high-impact AI system? Select TWO.

  • ACarry out measures to ensure meaningful human oversight and management of the high-impact system's operation and foreseeable risks. Correct
  • BNotify and obtain advance clearance from the supervisory authority before each individual high-impact inference is generated for a user.
  • CEstablish and operate risk-management and safety measures across the lifecycle of the high-impact AI system to protect users' rights. Correct
  • DUndergo a third-party conformity assessment by a notified body before the high-impact system may be placed on the Korean market.
  • ERegister the high-impact system in a centralised public EU database before deployment and renew that entry annually thereafter.
High-impact classification under South Korea's AI Basic Act triggers operator duties for lifecycle risk management, safety and human oversight rather than EU-style notified-body conformity assessment. South Korea's AI Basic Act regulates by operator obligation: once a system is high-impact, the operator must put lifecycle safety and risk-management measures and human oversight in place, a different mechanism from the EU AI Act's notified-body conformity route and public EU registration database.

Why A is correct: Correct: the Act ties high-impact classification to duties such as putting human oversight and risk-management measures in place for the system's lifecycle.

Why B is wrong: Tempting because high-impact status implies scrutiny, but the Act sets lifecycle safety and oversight duties, not per-inference pre-clearance of every single output.

Why C is correct: Correct: the Act requires operators of high-impact systems to run lifecycle risk-management and safety arrangements aimed at protecting affected users.

Why D is wrong: Tempting by analogy to the EU AI Act's notified-body route, but Korea's Act relies on operator duties rather than mandatory notified-body conformity assessment.

Why E is wrong: Tempting as it echoes a real registration idea, but the EU database is an EU AI Act mechanism and is not a duty imposed by Korea's AI Basic Act.

See more AIGP practice questions, answers explained.

Exam traps in Understanding how laws, standards and frameworks apply to AI

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • Nothing further, because once a general-purpose AI system is placed on the market the downstream integrator alone bears all documentation duties for any product it builds on top of it.

    Why it is wrong: It is tempting to treat documentation as falling wholly on whoever ships the final product, but the Act deliberately places upstream information duties on general-purpose AI providers so integrators are not left unable to comply.

  • The firm must obtain a government licence approving each AI model before it may offer any AI service to Korean users.

    Why it is wrong: Prior model licensing sounds like a strict gatekeeping measure, but the Act is built around trust, transparency, and risk management duties rather than a system of per-model government approval, so this misstates the regime.

  • Only the deployer bears any oversight duty, because oversight happens during use and the provider's responsibility ends once the system is placed on the market.

    Why it is wrong: This matches the employer's intuition and the fact that oversight occurs in operation, but it is wrong because the provider must build oversight measures into the system before placing it on the market, so the duty is shared rather than the deployer's alone.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.