The same 100 essential facts as the printable revision sheet, read aloud. Four episodes, one per AIGP domain, 25 facts each. Listen on the commute, the night before, or the morning of your exam. Free, no login, nothing to install.
The OECD and EU AI Act definition of an AI system, the shift from authored rules to learned behaviour and why it produces opacity and probabilistic outputs, harms at the individual, group, organizational and societal levels, AI-specific security threats, the seven characteristics driving the need for governance, the six named responsible-AI principles, governance roles, and the seven pillars of a governance program. Domain I carries 16 to 20 questions.
The heaviest domain for most candidates. GDPR lawful bases, purpose limitation, DPIA triggers, what Article 22 actually says about solely automated decisions, special category data, disparate treatment and disparate impact, NYC Local Law 144, the Colorado AI Act, the EU AI Act risk pyramid and prohibited practices, the Annex III domains, provider obligations, when a deployer becomes a provider, GPAI, the phasing timeline, the NIST AI RMF functions, and the ISO 42001 family.
Governing the build. Why governance starts before code is written, what a use case definition captures, how a design-stage impact assessment differs from a DPIA, FRIA and conformity assessment, ethics by design, the probability and severity matrix, the risk mitigation hierarchy, data lineage versus provenance, the full testing suite, train and test split discipline, release as a governance gate, the model card, data drift versus concept drift, red teaming, and the incident response sequence.
From the deployer's seat, where Domain III governs the build. Context factors and workforce readiness, model type axes, cloud versus on-premise versus edge, the four adaptation techniques and when fine-tuning turns a deployer into a provider, what RAG fixes and what it does not, guardrails for agentic systems, vendor contract terms and what a liability disclaimer does not transfer, spotting a silent vendor update, post-market monitoring as a process rather than a dashboard, serious incident duties, and the deactivation control. Domain IV carries 21 to 25 questions and IV.C is the heaviest competency on the exam.
If a domain did not stick, the written guide behind it goes deeper with worked explanations and knowledge checks. When you want to find out whether it has actually landed, sit the mock exam.