AIGP - Understanding how laws, standards and frameworks apply to AI (25% of the exam) - Section 2.4

Understand the risk classification framework for AI (prohibited, high, limited and minimal risk), the key compliance requirements for each category, and the enforcement framework and penalties.

Apply the EU AI Act risk classification framework - prohibited, high-risk, limited-risk, and minimal-risk - to a given AI system. Describe the compliance requirements and enforcement penalties that correspond to each category.

EU AI ActAI risk classificationhigh-risk AIprohibited AI practices

Practice question for this objective

Free sampleUnderstanding how laws, standards and frameworks apply to AIhard

A governance committee is sorting four planned AI projects into the EU AI Act risk tiers so it can allocate compliance effort. One project is an AI-driven spam filter for internal email. The committee wants to apply effort in proportion to the obligations each tier attracts. Which statement most accurately describes how the obligations scale across the tiers?

  • AMinimal-risk systems such as the spam filter attract no mandatory AI Act obligations, while high-risk systems carry the heaviest duties including risk management, data governance, logging and human oversight. Correct
  • BEvery AI system regardless of tier must undergo the same third-party conformity assessment, with the tiers differing only in the size of the potential fine.
  • CLimited-risk systems carry the heaviest substantive duties because their transparency obligations are more demanding than the requirements placed on high-risk systems.
  • DMinimal-risk systems must still complete a fundamental rights impact assessment, while high-risk systems are exempt because they are already covered by sectoral law.
Understand that AI Act obligations scale with risk, concentrating substantive duties on high-risk systems while minimal-risk systems face no mandatory requirements. The AI Act is built as a risk-tiered regime. Prohibited practices are banned, high-risk systems bear the bulk of the substantive obligations such as risk management, data governance, logging and human oversight, limited-risk systems mainly owe transparency duties, and minimal-risk systems such as an internal spam filter carry no mandatory obligations and are only invited to adopt voluntary codes of conduct.

Why A is correct: The AI Act imposes its substantive duties chiefly on high-risk systems, covering risk management, data governance, record-keeping and human oversight, while minimal-risk systems like a spam filter face no mandatory requirements and are only encouraged to follow voluntary codes.

Why B is wrong: A uniform conformity assessment sounds orderly and is therefore tempting, but the Act calibrates obligations to risk, so minimal and limited-risk systems are not subjected to the high-risk conformity assessment, making this incorrect.

Why C is wrong: This is tempting because limited-risk transparency duties are real, but they are comparatively light disclosure duties, and it is the high-risk tier that carries the most demanding substantive requirements, so the ranking is reversed.

Why D is wrong: The fundamental rights impact assessment is a genuine AI Act tool, which makes this plausible, but it is associated with certain high-risk deployments rather than minimal-risk systems, so this assigns the duty to the wrong tier and wrongly exempts high-risk systems.

See more AIGP practice questions, answers explained.

Exam traps in Understanding how laws, standards and frameworks apply to AI

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • Label every generated output so users are told an AI produced it, the core duty the limited-risk tier imposes.

    Why it is wrong: Tempting because transparency feels universal, but output labelling is the limited-risk transparency duty; it is not the defining obligation that high-risk classification triggers.

  • Every tier carries the same baseline conformity assessment, and the tiers differ only in the size of the administrative fine that applies when an obligation is breached.

    Why it is wrong: Tempting because penalties do vary by infringement, but it is wrong because conformity assessment is a high-risk obligation, not a uniform baseline, and the tiers differ in substantive duties, not just fines.

  • The hospital may rely on the original provider's CE marking, because that marking covers the system for the life of the device regardless of later changes to its purpose.

    Why it is wrong: A CE marking does feel like a durable certificate, but it attests conformity for the system as assessed, and a change of intended purpose takes the system outside what was assessed, so the original marking no longer covers it.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.