\r\n\r\n\r\n
\r\n
i
\r\n
\r\n Quick Answer\r\n

AIGP Body of Knowledge v2.1, effective February 2, 2026, is a 10–15% content recalibration — not a structural overhaul. The four-domain structure stays intact. The core shift: governance moved from regulating isolated \"models\" to overseeing interconnected \"AI systems,\" with new emphasis on agentic AI risk, expanded global law coverage (South Korea, Colorado, Texas), and two new ISO standards (42005 alongside 42001).

\r\n
\r\n
\r\n\r\n

On February 2, 2026, the IAPP formally implemented version 2.1 of the Artificial Intelligence Governance Professional (AIGP) Body of Knowledge. For anyone preparing for — or already holding — this certification, understanding exactly what changed is not optional. It is the difference between studying the right material and walking into a 2026 exam armed with a 2024 mental model that no longer reflects what the exam actually tests.

\r\n\r\n

This article is a precise, domain-by-domain breakdown of every substantive update in BoK v2.1, written for candidates who want to study smarter, not just harder — and for practitioners who need to understand how the field\'s professional standard is evolving in real time.

\r\n\r\n
\r\n
\r\n
10–15%
\r\n
Content Update Scope
\r\n
\r\n
\r\n
4
\r\n
Domains Unchanged in Structure
\r\n
\r\n
\r\n
3
\r\n
New Autonomy Risks Formally Added
\r\n
\r\n
\r\n
2
\r\n
ISO Standards Now Explicitly Tested
\r\n
\r\n
\r\n\r\n

The Scale of the Update: Recalibration, Not Reinvention

\r\n\r\n

The first thing to understand is the scope of the changes. Version 2.1 is a 10–15% content update. The established four-domain structure of the AIGP remains fully intact. This is a recalibration — a precision adjustment to align the credential with 2026 industry realities — not a structural overhaul that invalidates prior study or forces candidates to restart their preparation.

\r\n\r\n

The philosophy behind this update can be summarized in a single sentence: AI governance has matured from regulating isolated models to overseeing interconnected systems. The practical implication is that risk is no longer assumed to originate from an algorithm in isolation. In v2.1, risk manifests at the seams — the interaction points between technical components, deployment infrastructure, and human workflows.

\r\n\r\n
\r\n\r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n
Interaction PointWhat Candidates Must Evaluate
AI Models & Data PipelinesHow data quality, provenance, and validation protocols directly impact the reliability of model output.
Deployment InfrastructureCloud frameworks, technical environments, and API endpoints where the AI system resides and operates.
Human Decision-Making & WorkflowsHow end-outputs are interpreted, integrated into organizational workflows, and subjected to human oversight.
\r\n
\r\n\r\n

Domain-by-Domain Breakdown of BoK v2.1 Changes

\r\n\r\n

The modifications in v2.1 are surgical. They target specific performance indicators to reflect modern realities in procurement, intellectual property, and accountability.

\r\n\r\n
\r\n\r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n
Competency Areav2.1 UpdateStrategic Focus
I.C.2 Data & IPEvaluation and updating of data governance and intellectual property policies.Protecting assets in training and use; ensuring data provenance.
I.C.3 Third-Party RiskUpdated assessments, contracts, and procurement documents for the AI supply chain.Managing external vendor risks and acceptable use constraints.
Terminology / New RolesFormal introduction of the \"AI Provider\" and \"Affected Person\" roles.Transparency of capabilities versus rights of the system subject.
Domain II Privacy ShiftShift from \"Notice and Consent\" to \"Lawful Basis and Transparency.\"Alignment with GDPR principles, including legitimate interests.
\r\n
\r\n\r\n
\r\n
\r\n Legal Precision Note\r\n

While the AI Provider and Deployer bear primary responsibility for governance, the Affected Person — the individual subject to the AI\'s output — is now the central figure for whom the Fundamental Rights Impact Assessment (FRIA) is conducted. This distinction is testable.

\r\n
\r\n
\r\n\r\n

The Regulatory Landscape in 2026: What Candidates Must Know

\r\n\r\n

Version 2.1 places significantly increased weighting on Competency II.C (AI-specific laws). The global surge in enforcement and legislative activity means candidates can no longer rely on surface-level familiarity. You must understand the specific obligations, jurisdictional triggers, and extra-territorial reach of each framework.

\r\n\r\n

EU AI Act

\r\n\r\n

The centerpiece of global AI regulation applies a four-tier risk-based classification: Unacceptable, High-Risk, Limited, and Minimal risk. Its extra-territorial reach is the critical exam point — the Act applies to any non-EU provider whose system\'s output is utilized within the European Union, regardless of where the provider is headquartered or where the system was built.

\r\n\r\n

South Korean AI Basic Law

\r\n\r\n

A landmark legislative development from January 2026: the unification of numerous previously separate regulatory proposals into a single, cohesive national AI framework. This consolidation represents the kind of regulatory maturation the AIGP curriculum now explicitly addresses.

\r\n\r\n

U.S. State-Level Mandates

\r\n\r\n

In the absence of federal legislation, two state laws now drive domestic compliance standards and carry explicit focus in the BoK: the Colorado AI Act and the Texas Responsible AI Governance Act (TRAIGA). Candidates must understand their scope, the entities they regulate, and the obligations they impose on developers and deployers.

\r\n\r\n
\r\n\r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n
FrameworkStatusKey Point
EU AI ActExtra-territorial reachRisk-based framework (Unacceptable → High → Limited → Minimal). Applies to any system whose output is consumed within the EU, regardless of where the provider is based.
South Korean AI Basic LawEffective Jan 2026Consolidated numerous separate proposals into a single national framework.
Colorado AI ActState-level mandateOne of two U.S. state laws receiving explicit focus in BoK v2.1. Focuses on high-risk AI systems used in consequential decisions.
Texas RAIGAState-level mandateThe second explicit U.S. state focus in BoK v2.1. Scope and obligations for developers and deployers are a direct exam target.
\r\n
\r\n\r\n

The Fundamental Rights Impact Assessment (FRIA)

\r\n\r\n

The FRIA is not merely a best practice — it\'s a mandatory requirement under the EU AI Act for high-risk systems deployed by public bodies and certain private entities. It requires a formal, documented evaluation of the system\'s impact on non-discrimination, equality, and access to essential services, conducted on behalf of the Affected Person. Candidates who treat FRIA as a theoretical concept rather than an operational artifact will struggle on scenario-based questions.

\r\n\r\n

The New Technical Frontier: Agentic AI and ISO/IEC Standards

\r\n\r\n

The single most significant technical addition in BoK v2.1 is the formal introduction of agentic AI and agentic architectures as a governance frontier. Unlike static models, agentic AI involves autonomous agents capable of independent planning and multi-step execution — which introduces a category of risk that traditional governance frameworks were not designed to address.

\r\n\r\n

Governance professionals must now demonstrate proficiency in managing three specific autonomy risks. These are not hypothetical edge cases; they represent operational failure modes that have already occurred in real-world deployments and are now explicitly testable exam material.

\r\n\r\n
\r\n
\r\n
1
\r\n
\r\n

Autonomy

\r\n

Maintaining meaningful human control over systems capable of independently planning their own multi-step execution.

\r\n
\r\n
\r\n
\r\n
2
\r\n
\r\n

Feedback Loops

\r\n

The risk of systems learning from their own outputs, leading to rapid, compounding, and unintended model drift.

\r\n
\r\n
\r\n
\r\n
3
\r\n
\r\n

Escalation of Privileges

\r\n

Unmonitored code executing across internal endpoints and accessing sensitive company data via APIs without human visibility.

\r\n
\r\n
\r\n
\r\n\r\n

ISO/IEC 42005 and ISO/IEC 42001: The Governance Blueprint

\r\n\r\n

To manage the frontier of agentic risk, v2.1 identifies two ISO standards as the primary operational toolkit. These are not interchangeable — they serve distinct, complementary functions.

\r\n\r\n
    \r\n
  • ISO/IEC 42005 (AI System Impact Assessment) is the primary blueprint for assessing autonomy risks. It provides the assessment methodology you apply before and during the deployment of high-stakes systems.
  • \r\n
  • ISO/IEC 42001 (AI Management System) provides the certifiable management system framework — the operational infrastructure within which that impact assessment lives. Think of 42001 as the governance architecture, and 42005 as one of the critical processes running inside it.
  • \r\n
\r\n\r\n

The Business Case for AIGP in 2026

\r\n\r\n

The market signal for AI governance credentials has never been stronger. A large majority of organizations admit they lack confidence in governing AI responsibly — a gap that translates directly into organizational budget for credentialed professionals who can close it.

\r\n\r\n
\r\n\r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n
Metric2026 Value
Average base salary, AI governance professionals$182,000
Wage premium for verified AI governance skills56%
Additional salary boost, AIGP + CIPP/E or CIPM stack27%
Standard premium, any IAPP certification vs. non-certified13%
\r\n
\r\n\r\n

The Expert\'s Study Path: An 8-Week Plan for BoK v2.1

\r\n\r\n

Mastering v2.1 requires a mindset shift: from memorizing facts to building skills. The AIGP is fundamentally a translation exam. Every scenario-based item presents a fact pattern and asks you to identify the correct Role, Framework, and Lifecycle Stage simultaneously. Your study plan must train that three-variable reasoning, not just domain recall.

\r\n\r\n
\r\n
\r\n
1
\r\n
\r\n

Weeks 1–2: Foundations (Domain I)

\r\n

Emphasize the harm taxonomy and the common principles of responsible AI: Fairness, Transparency, and Accountability. Build your definitional base before touching any regulatory material.

\r\n
\r\n
\r\n
\r\n
2
\r\n
\r\n

Weeks 3–4: Frameworks (Domain II)

\r\n

Master the role-based obligations in the EU AI Act and the four NIST AI RMF functions: Govern, Map, Measure, Manage. This is the heaviest regulatory load in the exam — give it two full weeks.

\r\n
\r\n
\r\n
\r\n
3
\r\n
\r\n

Weeks 5–6: Development (Domain III)

\r\n

Learn through artifacts. Practice drafting model cards and Fundamental Rights Impact Assessments from scratch — don\'t just read about them. Writing a FRIA forces the kind of applied thinking the exam rewards.

\r\n
\r\n
\r\n
\r\n
4
\r\n
\r\n

Week 7: Deployment (Domain IV)

\r\n

Concentrate on vendor due diligence, third-party risk contracts, and monitoring runbooks. The v2.1 updates to I.C.3 make this domain more important than prior study guides suggest.

\r\n
\r\n
\r\n
\r\n
5
\r\n
\r\n

Week 8: Synthesis

\r\n

Conduct full timed practice exams and scenario-based drills. The goal is to refine your elimination logic under pressure — identifying the \"least wrong\" answer in a field of intentional traps.

\r\n
\r\n
\r\n
\r\n\r\n
\r\n The Translation Exam Principle\r\n

Every AIGP scenario question contains three identifiable variables — Role (who has the obligation?), Framework (which standard or law applies?), and Lifecycle Stage (where in the AI development cycle does this occur?). Train yourself to extract these three variables before reading the answer choices.

\r\n
\r\n\r\n

Exam Logistics at a Glance

\r\n\r\n

The administrative facts of the AIGP have not changed in v2.1, but they\'re worth restating precisely. Misunderstanding the scoring mechanic or cost structure is a preventable mistake.

\r\n\r\n
\r\n\r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n \r\n
DetailSpecification
Format100 multiple-choice questions
Scored / Pilot85 scored + 15 unscored pilot items
Time Limit2 hours 45 minutes testing (3 hours with break)
Passing Score300 / 500 (scaled)
Scenario-Based~30% of items are case study format
Cost$649 (members) / $799 (non-members)
\r\n
\r\n\r\n

Frequently Asked Questions

\r\n\r\n
\r\n
\r\n

Do I need to re-study everything if I already studied from BoK v2.0?

\r\n

No. This is a 10–15% content update, not a full rewrite. Focus your incremental study specifically on the areas covered in this article — agentic AI, the new global laws, ISO 42005, and the terminology shifts — rather than restarting your preparation from zero.

\r\n
\r\n
\r\n

Is ISO/IEC 42005 a replacement for ISO/IEC 42001?

\r\n

No, they\'re complementary, not competing. 42001 is the certifiable management system standard; 42005 is a narrower companion standard specifically for AI System Impact Assessments that operates within the broader 42001 framework.

\r\n
\r\n
\r\n

How likely is a BoK v3.0 update, and when?

\r\n

Given the pace of regulatory change since v2.1\'s release, a future update is plausible, but no confirmed timeline should be assumed. Candidates should verify they\'re studying the current published version directly through IAPP rather than relying on secondhand summaries, including this one, for anything exam-critical.

\r\n
\r\n
\r\n

Does the v2.1 update change the passing score or exam format?

\r\n

No. The 300 scaled passing score, the 100-question format with 85 scored items, and the overall time allocation are unchanged. Only the content weighting and specific tested material shifted.

\r\n
\r\n
\r\n

Which single change in v2.1 causes the most missed points among candidates?

\r\n

The Provider, Deployer, and Affected Person terminology shift tends to catch candidates studying from older material off guard the most, since it changes how scenario stems are worded even when the underlying governance concept being tested hasn\'t fundamentally changed. Candidates who haven\'t internalized the new terminology sometimes misread a familiar concept as unfamiliar.

\r\n
\r\n
\r\n\r\n
\r\n
Bottom Line
\r\n

BoK v2.1 is a precision recalibration, not a reinvention — but the specific areas it touches (agentic AI, expanded global law coverage, the Provider/Deployer/Affected Person terminology, and the two ISO standards) are exactly the areas most likely to trip up candidates studying from older material. Confirm you\'re working from v2.1-aligned resources, weight your study time toward the updated emphasis areas, and the \"recalibration, not reinvention\" framing becomes a genuine advantage rather than just reassurance going into exam day.

\r\n\r\n

Continue your AIGP exam prep: What is the passing score for the AIGP exam? and Read this before booking your AIGP exam.

\r\n
\r\n