To everyone who has passed the AIGP since the last issue, congratulations. Well earned.
New study material this issue, then a timeline change that quietly rewrote a date most people preparing for the exam still have memorised wrong.
The mock exam question bank just grew by 100 questions, based on feedback received from readers and Playbook users.
If you work anywhere near India, this one is for you too. There is now a full training guide to the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, built the same way as the EU AI Act material: the Act's obligations kept separate from the Rules that operationalise them, every duty traced back to its actual section, and a knowledge graph you can explore rather than just read top to bottom.
It covers notice and consent, breach timelines, the Consent Manager, children's data, cross-border transfer, and the three-phase compliance calendar, with the traps that trip people up called out directly. Free, no login.
If you learned the AI Act's timeline as "high-risk obligations apply from August 2, 2026," that date is no longer correct, and it changed quietly enough that a lot of people preparing right now are still working from it.
The EU's Digital Omnibus, which entered into force on July 27, 2026, postponed application of the Annex III high-risk AI system rules from August 2, 2026 to December 2, 2027, roughly sixteen months later. High-risk AI embedded in regulated products, things like machinery, toys, and lifts, moves even further out, to August 2, 2028. The stated reason centres on the harmonised standards the Act depends on for high-risk compliance not being finalised in time, with the designation of national competent authorities also cited as behind schedule.
This is not a repeal. It is a postponement, and it is narrow. It does not touch the prohibited practices, which are still fully in force. And it does not touch GPAI obligations. Article 50 transparency is more nuanced than a flat yes or no: the core disclosure duties, covered in issues #06 and #07, chatbots disclosing they are AI, emotion recognition disclosure, labelling AI-generated content, have applied since August 2, 2026 regardless of a system's risk tier. But the technical marking obligation under Article 50(2) specifically already had its own narrow grace period running to December 2, 2026, so do not read "Article 50 applies from August 2" as meaning every sub-obligation within it started on the same day with no exceptions. Only the Annex III high-risk requirements moved in this Omnibus, using fixed calendar dates rather than a conditional clock tied to when standards actually show up.
For the exam, this is worth being precise about. The AIGP tests the Act's architecture, the risk-tier framework, what counts as high-risk under Annex III, what the prohibited practices are, how GPAI splits into two tiers. That structure has not changed. What changed is when one tier's obligations start applying in practice. If a question ever turns on a specific compliance date rather than the framework itself, this is exactly the kind of thing to double check against the current text before you answer, because the ground has moved once already this year.
Missed an earlier issue? Every one of these is now on the site, in full and free to read: https://aigpplaybook.com/newsletter/
If you know someone preparing for the AIGP or building in this space, forward this to them. They can subscribe at aigpplaybook.com.
One thing before you go. If you have not sat the AIGP yet, what is actually holding you up? Time, confidence, or just not sure where to start? Reply and tell me. I read every one, and it tells me what to build next.
What is actually moving in AI governance, plus what it means if you are sitting the AIGP. No fixed schedule, only when something matters.