Free AIGP practice questions
70 questions across the syllabus, each with a note on every option — why the right one is right, and what mistake each wrong one is built to catch. No sign-in needed.
Why the real questions feel harder
Candidates who breeze through practice sets are often caught out by the official paper. When we compared our own bank against it, the difference was not the topics but how the options are written. Three patterns explain most of it, and knowing them changes how you should practise.
- The options do not explain themselves. A practice item that says "Red teaming — people trying to make the system fail" lets you match a definition to the scenario. The exam says "Red teaming." and leaves you to know what it is. If you can only pick the answer when it comes with its reason attached, you do not yet know it.
- Every wrong option is right somewhere else. The distractors are real instruments, real duties and real activities: threat modelling beside red teaming, a data protection impact assessment (DPIA) beside a fundamental rights impact assessment (FRIA), the provider's duty offered to the deployer. Elimination by common sense rarely gets you below two.
- Short, bare options. Around a third of official items list four names — laws, harm categories, roles, disciplines — with nothing else to read. There is no wording to reason from; you either know the boundary between them or you do not.
The questions below are written to those standards. Read the note on each option you rejected, not only the one you chose: the notes are where the boundaries are taught. For the routine to use on exam day, see exam technique.
Warm-up: one question from every topic
14 questions, one per set below. A quick way to find the topic to start with.
Synthetic video erodes public willingness to believe genuine footage. Which harm category is this?
- AGroup harm.
- BEcosystem harm.
- CSocietal harm.
- DIndividual harm.
Harms and bias
5 questions. Taught in full on harms and bias.
Synthetic video erodes public willingness to believe genuine footage. Which harm category is this?
- AIndividual harm.
- BSocietal harm.
- CGroup harm.
- DEcosystem harm.
Roles and responsibilities
5 questions. Taught in full on roles and responsibilities.
A SaaS vendor processes customer data on the customer’s documented instructions. Separately, it decides on its own to use the same data to improve its general model. What is its GDPR role in the first operation and in the second?
- AController for the first; processor for the second.
- BProcessor for both operations.
- CJoint controller with the customer for both.
- DProcessor for the first; controller for the second.
Named laws, frameworks and bodies
5 questions. Taught in full on named laws, frameworks and bodies.
Which is LEAST likely to provide guidance on reducing discrimination in an AI hiring tool?
- AThe Equal Employment Opportunity Commission.
- BThe Fair Credit Reporting Act.
- CTitle VII of the Civil Rights Act of 1964.
- DThe National Artificial Intelligence Initiative Act.
GDPR for AI
5 questions. Taught in full on gdpr for ai.
A team wants to process special-category data to test a model for bias. Under the GDPR, what does it need?
- AAn Art. 9(2) condition, which replaces Art. 6.
- BAn Art. 6 basis and an Art. 9(2) condition.
- CAn Art. 6 basis and a completed DPIA.
- DAn Art. 9(2) condition and a completed DPIA.
GDPR versus the EU AI Act
5 questions. Taught in full on gdpr versus the eu ai act.
A company is a GDPR controller for the personal data in its AI system and satisfies every GDPR obligation. What does that establish about its EU AI Act compliance?
- AThat it is largely compliant.
- BThat Art. 10 data governance is met.
- CNothing on its own.
- DThat only Art. 50 duties remain.
Article numbers
5 questions. Taught in full on article numbers.
A non-EU provider of a high-risk AI system must appoint an authorised representative in the Union. Which article requires it?
- AEU AI Act Art. 27.
- BGDPR Art. 22.
- CEU AI Act Art. 22.
- DGDPR Art. 27.
EU AI Act timeline and updates
5 questions. Taught in full on eu ai act timeline and updates.
Under the Digital Omnibus amendments, which AI Act deadline did NOT move?
- AAnnex I high-risk obligations.
- BArt. 50 transparency obligations.
- CAnnex III high-risk obligations.
- DNational regulatory sandboxes.
Which rules apply where
5 questions. Taught in full on which rules apply where.
A US analytics company with no EU establishment tracks the browsing behaviour of users located in Germany. Which provision brings it within the GDPR?
- AArt. 3(3).
- BArt. 3(2)(a).
- CArt. 3(2)(b).
- DArt. 3(1).
Standards and frameworks
5 questions. Taught in full on standards and frameworks.
The BOK describes four value-chain actors: developer, provider, deployer and user. Which of them are also operator roles defined in the EU AI Act?
- AProvider and deployer only.
- BDeveloper, provider and deployer.
- CAll four of them.
- DProvider, deployer and user.
DPIA, FRIA and conformity assessment
5 questions. Taught in full on dpia, fria and conformity assessment.
A private company deploys a high-risk AI system to screen job applicants. Who owes a fundamental rights impact assessment under EU AI Act Art. 27 for this deployment?
- AThe provider, before market placement.
- BThe company, as deployer.
- CNobody, on these facts.
- DThe company and the provider jointly.
Order of operations
5 questions. Taught in full on order of operations.
A team has agreed the business problem its new AI system will solve. Which step comes next?
- AIdentify the data it will need.
- BIdentify the gaps and risks.
- CDetermine the specific use cases.
- DIdentify the applicable laws.
A worked governance programme
5 questions. Taught in full on a worked governance programme.
Aldermere starts using client survey data to improve its own assistant. What changes?
- AIt becomes a controller for that processing.
- BIt becomes a joint controller for that processing.
- CIt becomes a controller for all the survey data.
- DIt remains a processor for that processing.
Lists worth memorising
5 questions. Taught in full on lists worth memorising.
How many principles does GDPR Art. 5 contain?
- AEight.
- BSix.
- CFive.
- DSeven.
Exam technique
5 questions. Taught in full on exam technique.
An option reads: "Anonymising the training data resolves the privacy concerns." Which distractor pattern is this?
- AWrong risk tier.
- BShifted accountability.
- CAbsolutes.
- DSingle safeguard.
Questions about AIGP practice
Are these real AIGP exam questions?
No. The International Association of Privacy Professionals (IAPP) does not publish its live exam items, and anyone claiming to sell them is selling something they should not have. Every question here was written for this site against the Artificial Intelligence Governance Professional (AIGP) Body of Knowledge and the primary sources — the General Data Protection Regulation (GDPR), the European Union Artificial Intelligence Act (EU AI Act), the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF) and the rest — in the style of the official practice paper.
How many questions are on the AIGP exam?
100 multiple-choice questions in three hours. Some are single-answer, some are select-all-that-apply, and a number share a longer scenario. It is scored on a scale of 100 to 500 and the pass mark is 300.
What score on practice questions means I am ready?
A consistent 75–80% on questions of the official difficulty, sustained across all four domains rather than averaged over them. One weak domain can sink an otherwise comfortable paper, because Domains III and IV together carry around half the marks.
Where are the full-length mock exams?
Behind a free sign-in: 305 further exam-style questions, blueprint-weighted 100-question mocks, flashcards and spaced review of the questions you get wrong. The questions on this page are separate from that bank.