Everything you need between now and the exam room: the day-by-day plan, the mnemonics that stick, the traps that separate a pass from a fail, and the logistics checklist so nothing surprises you on Thursday morning.
Three blocks left. Each one is 2-3 hours of focused work — not marathon sessions. The goal is active recall and testing, not re-reading.
| Block | Time | What to do | Modules to use |
|---|---|---|---|
| Tue 11 — Morning | 2-3h | Scan Domain I + II modules, flip all cards, retake both quizzes. Focus on the compare tables. | domain-1-foundations · domain-4-laws-standards |
| Tue 11 — Evening | 2-3h | Domain III: scan module-6-v2 + module-7-v2, run the incident game and drift lab, retake quizzes. | module-6-v2 · module-7-v2 · domain-3-v2 |
| Wed 12 — Morning | 2-3h | Full-length practice: practice-exams-v5 (100 Q) in one sitting, timed. Review every miss. | practice-exams-v5 |
| Wed 12 — Evening | 2-3h | Scenario practice: practice-exams-v6 (10 scenarios) + v4. Re-run the EU AI Act module's penalty calculator and risk classifier. | practice-exams-v6 · practice-exams-v4 · eu-ai-act-v2 |
| Thu 13 — Morning | 1-2h | Light review only: this page's mnemonics + traps, re-flash the cards you missed, no new content. | final-48h-sprint · de-identification-pets-v2 |
These are the highest-yield facts in the exam. If a question tests one of these, you should answer in under 10 seconds.
| Mnemonic | Tier | Violation |
|---|---|---|
| "7% for the seven deadly practices" | €35M or 7% | Prohibited practices (Art. 5) |
| "3% for the three letters of Art. 50" | €15M or 3% | Most operator obligations, incl. Art. 50 transparency |
| "1% for the one thing you should have told them" | €7.5M or 1% | Incorrect/misleading info to authorities |
Distorting behaviour and causing harm.
Hidden cues pushing harmful purchases.Exploiting age, disability, or socio-economic situation.
A toy chatbot manipulating a child.Public or private scoring leading to detrimental treatment.
Government trust scores denying benefits.Predicting offending based solely on profiling.
Flagging a person as a future criminal.Scraping the internet or CCTV for facial images.
Harvesting social-media photos for a face database.Inferring emotions in workplaces and education.
Scoring call-centre agents' emotions.Categorising by race, religion, sexual orientation, etc.
Classifying faces by presumed orientation.With 3 narrow exceptions (terrorism, serious crime, victims) + judicial authorisation.
Live facial recognition to find a kidnapped child.| Date | Obligation |
|---|---|
| 2 Feb 2025 | Prohibitions (Art. 5) |
| 2 Aug 2025 | GPAI transparency (Art. 50) |
| 2 Aug 2026 | General application + Art. 50 |
| 2 Dec 2027 | Annex III high-risk obligations (Omnibus shift) |
| 2 Aug 2028 | Annex I (embedded in regulated products) (Omnibus shift) |
Right not to be subject to decisions based SOLELY on automated processing with legal or significant effects. Exceptions: contract, law, explicit consent. Safeguards: human intervention, express views, contest.
The word "solely" is the trigger. A rubber-stamp human does not count.Required where processing is likely to result in HIGH RISK: new tech, profiling, large-scale special data, public monitoring. Four contents: description, necessity/proportionality, risk assessment, mitigation.
Health data at scale = DPIA, always.Pseudonymised data is STILL personal data if the key exists. Only true anonymisation exits GDPR scope.
Destroy the key and it may become anonymised.| Assessment | One-liner |
|---|---|
| DPIA | Personal-data risks (GDPR Art. 35) — controller's duty |
| FRIA | Fundamental rights beyond data (EU AI Act Art. 27) — deployer of high-risk AI |
| AIA | Algorithmic/systemic impacts — organisational policy or law (e.g., NYC Local Law 144) |
Every one of these has appeared in the practice banks as a wrong-answer magnet. Read them twice: once tonight, once Thursday morning.
| Trap | The truth |
|---|---|
| Emotion recognition in retail = prohibited | FALSE — banned only in workplaces and education (Art. 5(f)). Retail = limited-risk with Art. 50 transparency. |
| Pseudonymised = anonymised | FALSE — pseudonymised data is still personal data if the key exists. Only true anonymisation exits GDPR scope. |
| Digital Omnibus repealed high-risk rules | FALSE — delayed (Annex III → 2 Dec 2027, Annex I → 2 Aug 2028). Timeline relief, not repeal. |
| Distributor/importer = provider | FALSE — separate operator roles. Provider = developed the system and placed it on the market. |
| NIST AI RMF is mandatory | FALSE — voluntary framework. EU AI Act is mandatory. "Functions" = NIST; "certification" = ISO 42001. |
| Art. 22 applies when a human rubber-stamps | FALSE — a human who adds no real judgement means the decision is still "solely automated" in substance. |
| Shadow deployment affects real users | FALSE — shadow = predictions logged, not acted on. Real traffic = canary or A/B. |
| Kill switch after full investigation | FALSE — pull it immediately on confirmed significant harm. Contain first, investigate after. |
| Data drift = the rule changed | FALSE — data drift = inputs changed; concept drift = the rule changed; label drift = the answer key changed. |
| ISO 42001 is a voluntary framework like NIST | FALSE — ISO 42001 is a certifiable management system (PDCA). NIST is the voluntary framework. |
| SG MGF is legally binding | FALSE — the PDPA is binding; MGF, AI Verify, FEAT are guidance. |
| 10^25 FLOPs = prohibited threshold | FALSE — it is the systemic-risk presumption (Art. 51), triggering extra duties, not a ban. |
Format, timing, and strategy. Get these right and you walk in calm.
Progress persists in this browser. The goal: every box filled by Thursday morning.