AI guide
【One-Line Pitch】
A structured, exam-oriented guide that turns AIGP certification domains into a working AI governance playbook—covering risk tiering, lifecycle controls, global regulation, and audit evidence. Best for privacy, compliance, legal, risk, security, and product professionals who need both a passing score and a program they can actually run.
【Book Arc】
- **Opening (~0%–10%)**: Frames AI governance as a business capability rather than a legal afterthought, and sets up the book's dual promise: AIGP exam readiness plus workplace-ready governance skills.
- **Early (~10%–35%)**: Builds foundations—what AI is, how models learn, why AI must be viewed as a socio-technical system, harm taxonomies, bias and privacy risks, responsible AI principles, and the organizational infrastructure (roles, policies, stakeholder engagement, risk scoring) behind governance.
- **Middle (~35%–60%)**: Moves into lifecycle governance and regulation: development checkpoints, impact assessments, testing and monitoring, documentation and audit trails, prompt-injection defenses, then the EU AI Act's scope, actor roles, four-tier risk classification, and obligations for general-purpose AI.
- **Late (~60%–75%)**: Widens to the global landscape—U.S. federal and state rules, local hiring and consumer AI laws, privacy principles across the lifecycle, and international standards including ISO/IEC 22989, 42001, and 42005.
- **Ending (~75%+)**: Closes with exam-focused consolidation and practical checklists/scenarios for generative AI, RAG, vendor oversight, and model deployment, plus book benefits and next-reading pointers.
【Key Takeaways】
- **AI governance starts with a shared definition of AI** (Early): without agreement on what counts as an AI system, teams approve projects while imagining different technologies—so the book defines AI through technology, objective, autonomy, and output.
- **AI is a socio-technical system, not just a model** (Early): a résumé-ranking tool can quietly shift from decision support to decision-making once recruiters treat its output as the default; governance must cover people, workflows, escalation paths, and incentives, not only code.
- **Risk classification is the hinge of proportionate governance** (Middle): the EU AI Act's four-tier framework and OECD-style dimensions (who is affected, economic context, data, model type, task/output) let organizations match controls to actual risk instead of applying maximum scrutiny everywhere.
- **The lifecycle needs checkpoints, not one-time reviews** (Middle): impact assessments, documentation, human oversight, testing, monitoring, incident response, and audit evidence are presented as recurring gates—because systems drift as data, users, and business processes change.
- **Regulation is global and uneven** (Late): the book maps the EU AI Act alongside U.S. federal guidance, state and city rules (e.g., NYC Local Law 144, Illinois video-interview disclosure, Colorado algorithmic-discrimination rules), and South Korea's AI Basic Law, emphasizing alignment and dissonance across jurisdictions.
- **Standards turn principles into management systems** (Late): ISO/IEC 42001 provides the AI management system structure (context, leadership, planning, operation, improvement), while ISO/IEC 22989 supplies shared terminology and ISO/IEC 42005 addresses impact assessment.
- **Vendors and generative AI expand the governance perimeter** (Late): due diligence, disclosures, drift monitoring, RAG-specific controls, and prompt-injection defenses are treated as core governance work, not edge cases.
- **Exam prep and program-building reinforce each other** (Ending): checklists and scenarios are designed so certification knowledge translates directly into workplace artifacts such as policies, assessments, and audit trails.
【Reading Tips】
- **Deep-read the risk classification and EU AI Act chapters** (Middle): these are the densest regulatory sections and the most likely to be tested; map each risk tier to concrete provider/deployer obligations as you go.
- **Skim the AI fundamentals if you already work in tech** (Early): use it to align vocabulary—especially the socio-technical framing—then move quickly to governance structures and risk assessment.
- **Treat checklists and scenarios as practice artifacts**: pause and draft your own policy outline, impact-assessment template, or vendor questionnaire before reading the book's version.
- **Use the standards chapters as reference, not memorization** (Late): know what ISO/IEC 42001, 22989, and 42005 are for and how they relate, rather than memorizing clause numbers.
- **Connect each chapter to your own organization**: the book's value is strongest when you map its controls onto a real AI system you can observe.
【Coverage Limits】
The excerpts cover the book's structure, chapter topics, and several conceptual passages in detail, but do not include full regulatory text, complete checklists, or sample exam questions. Specific figures, tables, and chapter-level examples beyond those summarized here are not covered.
Passage locations
Excerpt 1
on, vendor due diligence, disclosures, and drift monitoring. You will also explore the EU AI Act, global AI laws, OECD principles, NIST AI RMF, and ISO AI st...
View in text
Excerpt 2
using a taxonomy approach • Who is affected by AI harms?
View in text
Excerpt 3
a taxonomy approach • Who is affected by AI harms? • Understanding bias and discrimination in AI • Assessing organizational harm from AI • Assessing organiza...
View in text
Excerpt 4
anagement practices that support trustworthy AI development. Chapter 5 , Governing AI in Production , focuses on operational governance after deployment, inc...
View in text