AIGP Body of Knowledge v2.1, effective February 2, 2026, is a 10–15% content recalibration — not a structural overhaul. The four-domain structure stays intact. The core shift: governance moved from regulating isolated \"models\" to overseeing interconnected \"AI systems,\" with new emphasis on agentic AI risk, expanded global law coverage (South Korea, Colorado, Texas), and two new ISO standards (42005 alongside 42001).
\r\nOn February 2, 2026, the IAPP formally implemented version 2.1 of the Artificial Intelligence Governance Professional (AIGP) Body of Knowledge. For anyone preparing for — or already holding — this certification, understanding exactly what changed is not optional. It is the difference between studying the right material and walking into a 2026 exam armed with a 2024 mental model that no longer reflects what the exam actually tests.
\r\n\r\nThis article is a precise, domain-by-domain breakdown of every substantive update in BoK v2.1, written for candidates who want to study smarter, not just harder — and for practitioners who need to understand how the field\'s professional standard is evolving in real time.
\r\n\r\nThe Scale of the Update: Recalibration, Not Reinvention
\r\n\r\nThe first thing to understand is the scope of the changes. Version 2.1 is a 10–15% content update. The established four-domain structure of the AIGP remains fully intact. This is a recalibration — a precision adjustment to align the credential with 2026 industry realities — not a structural overhaul that invalidates prior study or forces candidates to restart their preparation.
\r\n\r\nThe philosophy behind this update can be summarized in a single sentence: AI governance has matured from regulating isolated models to overseeing interconnected systems. The practical implication is that risk is no longer assumed to originate from an algorithm in isolation. In v2.1, risk manifests at the seams — the interaction points between technical components, deployment infrastructure, and human workflows.
\r\n\r\n| Interaction Point | What Candidates Must Evaluate |
|---|---|
| AI Models & Data Pipelines | How data quality, provenance, and validation protocols directly impact the reliability of model output. |
| Deployment Infrastructure | Cloud frameworks, technical environments, and API endpoints where the AI system resides and operates. |
| Human Decision-Making & Workflows | How end-outputs are interpreted, integrated into organizational workflows, and subjected to human oversight. |
Domain-by-Domain Breakdown of BoK v2.1 Changes
\r\n\r\nThe modifications in v2.1 are surgical. They target specific performance indicators to reflect modern realities in procurement, intellectual property, and accountability.
\r\n\r\n| Competency Area | v2.1 Update | Strategic Focus |
|---|---|---|
| I.C.2 Data & IP | Evaluation and updating of data governance and intellectual property policies. | Protecting assets in training and use; ensuring data provenance. |
| I.C.3 Third-Party Risk | Updated assessments, contracts, and procurement documents for the AI supply chain. | Managing external vendor risks and acceptable use constraints. |
| Terminology / New Roles | Formal introduction of the \"AI Provider\" and \"Affected Person\" roles. | Transparency of capabilities versus rights of the system subject. |
| Domain II Privacy Shift | Shift from \"Notice and Consent\" to \"Lawful Basis and Transparency.\" | Alignment with GDPR principles, including legitimate interests. |
While the AI Provider and Deployer bear primary responsibility for governance, the Affected Person — the individual subject to the AI\'s output — is now the central figure for whom the Fundamental Rights Impact Assessment (FRIA) is conducted. This distinction is testable.
\r\nThe Regulatory Landscape in 2026: What Candidates Must Know
\r\n\r\nVersion 2.1 places significantly increased weighting on Competency II.C (AI-specific laws). The global surge in enforcement and legislative activity means candidates can no longer rely on surface-level familiarity. You must understand the specific obligations, jurisdictional triggers, and extra-territorial reach of each framework.
\r\n\r\nEU AI Act
\r\n\r\nThe centerpiece of global AI regulation applies a four-tier risk-based classification: Unacceptable, High-Risk, Limited, and Minimal risk. Its extra-territorial reach is the critical exam point — the Act applies to any non-EU provider whose system\'s output is utilized within the European Union, regardless of where the provider is headquartered or where the system was built.
\r\n\r\nSouth Korean AI Basic Law
\r\n\r\nA landmark legislative development from January 2026: the unification of numerous previously separate regulatory proposals into a single, cohesive national AI framework. This consolidation represents the kind of regulatory maturation the AIGP curriculum now explicitly addresses.
\r\n\r\nU.S. State-Level Mandates
\r\n\r\nIn the absence of federal legislation, two state laws now drive domestic compliance standards and carry explicit focus in the BoK: the Colorado AI Act and the Texas Responsible AI Governance Act (TRAIGA). Candidates must understand their scope, the entities they regulate, and the obligations they impose on developers and deployers.
\r\n\r\n| Framework | Status | Key Point |
|---|---|---|
| EU AI Act | Extra-territorial reach | Risk-based framework (Unacceptable → High → Limited → Minimal). Applies to any system whose output is consumed within the EU, regardless of where the provider is based. |
| South Korean AI Basic Law | Effective Jan 2026 | Consolidated numerous separate proposals into a single national framework. |
| Colorado AI Act | State-level mandate | One of two U.S. state laws receiving explicit focus in BoK v2.1. Focuses on high-risk AI systems used in consequential decisions. |
| Texas RAIGA | State-level mandate | The second explicit U.S. state focus in BoK v2.1. Scope and obligations for developers and deployers are a direct exam target. |
The Fundamental Rights Impact Assessment (FRIA)
\r\n\r\nThe FRIA is not merely a best practice — it\'s a mandatory requirement under the EU AI Act for high-risk systems deployed by public bodies and certain private entities. It requires a formal, documented evaluation of the system\'s impact on non-discrimination, equality, and access to essential services, conducted on behalf of the Affected Person. Candidates who treat FRIA as a theoretical concept rather than an operational artifact will struggle on scenario-based questions.
\r\n\r\nThe New Technical Frontier: Agentic AI and ISO/IEC Standards
\r\n\r\nThe single most significant technical addition in BoK v2.1 is the formal introduction of agentic AI and agentic architectures as a governance frontier. Unlike static models, agentic AI involves autonomous agents capable of independent planning and multi-step execution — which introduces a category of risk that traditional governance frameworks were not designed to address.
\r\n\r\nGovernance professionals must now demonstrate proficiency in managing three specific autonomy risks. These are not hypothetical edge cases; they represent operational failure modes that have already occurred in real-world deployments and are now explicitly testable exam material.
\r\n\r\nAutonomy
\r\nMaintaining meaningful human control over systems capable of independently planning their own multi-step execution.
\r\nFeedback Loops
\r\nThe risk of systems learning from their own outputs, leading to rapid, compounding, and unintended model drift.
\r\nEscalation of Privileges
\r\nUnmonitored code executing across internal endpoints and accessing sensitive company data via APIs without human visibility.
\r\nISO/IEC 42005 and ISO/IEC 42001: The Governance Blueprint
\r\n\r\nTo manage the frontier of agentic risk, v2.1 identifies two ISO standards as the primary operational toolkit. These are not interchangeable — they serve distinct, complementary functions.
\r\n\r\n- \r\n
- ISO/IEC 42005 (AI System Impact Assessment) is the primary blueprint for assessing autonomy risks. It provides the assessment methodology you apply before and during the deployment of high-stakes systems. \r\n
- ISO/IEC 42001 (AI Management System) provides the certifiable management system framework — the operational infrastructure within which that impact assessment lives. Think of 42001 as the governance architecture, and 42005 as one of the critical processes running inside it. \r\n
The Business Case for AIGP in 2026
\r\n\r\nThe market signal for AI governance credentials has never been stronger. A large majority of organizations admit they lack confidence in governing AI responsibly — a gap that translates directly into organizational budget for credentialed professionals who can close it.
\r\n\r\n| Metric | 2026 Value |
|---|---|
| Average base salary, AI governance professionals | $182,000 |
| Wage premium for verified AI governance skills | 56% |
| Additional salary boost, AIGP + CIPP/E or CIPM stack | 27% |
| Standard premium, any IAPP certification vs. non-certified | 13% |
The Expert\'s Study Path: An 8-Week Plan for BoK v2.1
\r\n\r\nMastering v2.1 requires a mindset shift: from memorizing facts to building skills. The AIGP is fundamentally a translation exam. Every scenario-based item presents a fact pattern and asks you to identify the correct Role, Framework, and Lifecycle Stage simultaneously. Your study plan must train that three-variable reasoning, not just domain recall.
\r\n\r\nWeeks 1–2: Foundations (Domain I)
\r\nEmphasize the harm taxonomy and the common principles of responsible AI: Fairness, Transparency, and Accountability. Build your definitional base before touching any regulatory material.
\r\nWeeks 3–4: Frameworks (Domain II)
\r\nMaster the role-based obligations in the EU AI Act and the four NIST AI RMF functions: Govern, Map, Measure, Manage. This is the heaviest regulatory load in the exam — give it two full weeks.
\r\nWeeks 5–6: Development (Domain III)
\r\nLearn through artifacts. Practice drafting model cards and Fundamental Rights Impact Assessments from scratch — don\'t just read about them. Writing a FRIA forces the kind of applied thinking the exam rewards.
\r\nWeek 7: Deployment (Domain IV)
\r\nConcentrate on vendor due diligence, third-party risk contracts, and monitoring runbooks. The v2.1 updates to I.C.3 make this domain more important than prior study guides suggest.
\r\nWeek 8: Synthesis
\r\nConduct full timed practice exams and scenario-based drills. The goal is to refine your elimination logic under pressure — identifying the \"least wrong\" answer in a field of intentional traps.
\r\nEvery AIGP scenario question contains three identifiable variables — Role (who has the obligation?), Framework (which standard or law applies?), and Lifecycle Stage (where in the AI development cycle does this occur?). Train yourself to extract these three variables before reading the answer choices.
\r\nExam Logistics at a Glance
\r\n\r\nThe administrative facts of the AIGP have not changed in v2.1, but they\'re worth restating precisely. Misunderstanding the scoring mechanic or cost structure is a preventable mistake.
\r\n\r\n| Detail | Specification |
|---|---|
| Format | 100 multiple-choice questions |
| Scored / Pilot | 85 scored + 15 unscored pilot items |
| Time Limit | 2 hours 45 minutes testing (3 hours with break) |
| Passing Score | 300 / 500 (scaled) |
| Scenario-Based | ~30% of items are case study format |
| Cost | $649 (members) / $799 (non-members) |
Frequently Asked Questions
\r\n\r\nDo I need to re-study everything if I already studied from BoK v2.0?
\r\nNo. This is a 10–15% content update, not a full rewrite. Focus your incremental study specifically on the areas covered in this article — agentic AI, the new global laws, ISO 42005, and the terminology shifts — rather than restarting your preparation from zero.
\r\nIs ISO/IEC 42005 a replacement for ISO/IEC 42001?
\r\nNo, they\'re complementary, not competing. 42001 is the certifiable management system standard; 42005 is a narrower companion standard specifically for AI System Impact Assessments that operates within the broader 42001 framework.
\r\nHow likely is a BoK v3.0 update, and when?
\r\nGiven the pace of regulatory change since v2.1\'s release, a future update is plausible, but no confirmed timeline should be assumed. Candidates should verify they\'re studying the current published version directly through IAPP rather than relying on secondhand summaries, including this one, for anything exam-critical.
\r\nDoes the v2.1 update change the passing score or exam format?
\r\nNo. The 300 scaled passing score, the 100-question format with 85 scored items, and the overall time allocation are unchanged. Only the content weighting and specific tested material shifted.
\r\nWhich single change in v2.1 causes the most missed points among candidates?
\r\nThe Provider, Deployer, and Affected Person terminology shift tends to catch candidates studying from older material off guard the most, since it changes how scenario stems are worded even when the underlying governance concept being tested hasn\'t fundamentally changed. Candidates who haven\'t internalized the new terminology sometimes misread a familiar concept as unfamiliar.
\r\nBoK v2.1 is a precision recalibration, not a reinvention — but the specific areas it touches (agentic AI, expanded global law coverage, the Provider/Deployer/Affected Person terminology, and the two ISO standards) are exactly the areas most likely to trip up candidates studying from older material. Confirm you\'re working from v2.1-aligned resources, weight your study time toward the updated emphasis areas, and the \"recalibration, not reinvention\" framing becomes a genuine advantage rather than just reassurance going into exam day.
\r\n\r\nContinue your AIGP exam prep: What is the passing score for the AIGP exam? and Read this before booking your AIGP exam.
\r\n