# AI Act
EU-wide regulation defining obligations for AI systems based on risk.
Example: Provider must run conformity steps for high-risk systems.
56 terms across legal, policy, and implementation practice.
EU-wide regulation defining obligations for AI systems based on risk.
Example: Provider must run conformity steps for high-risk systems.
A procedure a system follows to produce outputs from inputs.
Example: Ranking loan applicants by risk score.
Systematic and unfair differences in outcomes across groups.
Example: Hiring tool gives lower scores to women.
Structured review of AI controls, risks, and compliance evidence.
Example: Third-party review of model governance.
Decisions made with little or no human intervention.
Example: Automated welfare fraud flags.
Standardized test used to compare model performance.
Example: Safety benchmark before release.
Matching people using physical or behavioral traits.
Example: Face matching in airport gates.
Operational list of legal and policy controls to complete.
Example: Pre-launch transparency and logging checks.
Process proving a system meets required regulatory standards.
Example: Technical documentation and testing evidence.
Conformity mark showing product meets EU requirements.
Example: Affixing CE mark after assessment completion.
Movement of data across jurisdictions with legal controls.
Example: EU user data transferred to US processor.
Policies and controls for data quality, access, and lifecycle.
Example: Dataset lineage with access approvals.
Person whose personal data is processed.
Example: Employee in HR analytics dataset.
Synthetic media designed to imitate real people or events.
Example: AI-generated video of a public official.
Clear statement of where a model may be used safely.
Example: Medical triage support only, not diagnosis.
Organization using an AI system in operations.
Example: Bank using vendor model for underwriting.
Ability to understand why an AI output was produced.
Example: Reason codes for credit denial.
Design objective to avoid unjustified outcome disparities.
Example: Balanced false-positive rates across groups.
General model trained on broad data for many tasks.
Example: Large language model used across products.
AI model usable in many downstream applications.
Example: Text model later adapted for legal drafting.
Short form for general-purpose AI models and obligations.
Example: Provider publishes training summary.
Internal committee overseeing AI risk and approvals.
Example: Cross-functional AI risk board.
AI system in sensitive domains with stricter obligations.
Example: AI for employment screening.
Meaningful ability for people to monitor and intervene.
Example: Caseworker can override automated flags.
Structured analysis of social and legal impacts before use.
Example: Assessment before AI in public benefits.
Obligation to disclose serious malfunctions or harms.
Example: Report unsafe chatbot behavior to regulator.
Legal responsibility for harms caused by AI use.
Example: Compensation claims after discriminatory denial.
Record keeping of model inputs, outputs, and decisions.
Example: Store prompt and output trace for audits.
Structured document describing model purpose, limits, and risks.
Example: Known failure modes and safety boundaries.
Testing process to verify performance and safety criteria.
Example: Stress test with multilingual prompts.
Any information relating to an identifiable person.
Example: IP address tied to a user account.
Ongoing tracking of system performance after deployment.
Example: Monthly safety incident review.
Use cases banned due to unacceptable risk.
Example: Social scoring by public authorities.
Entity developing or placing an AI system on market.
Example: Company shipping a hiring model.
Use of AI by government bodies and public agencies.
Example: Municipal permit triage automation.
Adversarial testing to find vulnerabilities and unsafe outputs.
Example: Prompt attacks against safety guardrails.
Controlled environment where innovators test under supervision.
Example: Pilot health AI with regulator oversight.
Categorizing AI systems by potential impact and harm.
Example: Limited-risk chatbot vs high-risk scoring.
Continuous process for identifying and reducing AI risks.
Example: Quarterly mitigation control review.
User request to access, correct, or delete personal data.
Example: Request model training data deletion.
Non-binding explanations from authorities on legal expectations.
Example: Agency FAQ clarifying lawful AI use.
Program where AI can be trialed with supervised safeguards.
Example: Public-sector innovation sandbox.
Voluntary or mandatory technical norm guiding compliance.
Example: ISO AI management standard adoption.
AI obligations enacted by subnational jurisdictions.
Example: US state rules for hiring algorithms.
National capability strategy for models, compute, and data.
Example: Domestic compute program for public services.
Large-scale risk affecting markets, safety, or rights broadly.
Example: Widely deployed GPAI misuse at scale.
Notice that text, image, audio, or video is AI-generated.
Example: Disclosure text on generated campaign media.
Non-binding norms influencing AI behavior and market practice.
Example: Industry code of conduct.
Quality checks proving systems meet target outcomes safely.
Example: Holdout testing before launch.
External review attesting governance and risk controls.
Example: Independent assessor confirms controls.
Data used to fit model parameters during development.
Example: Multilingual text corpora for LLMs.
Duty to disclose AI use, limits, and key risk information.
Example: Labeling chatbot interactions to users.
Ability to follow system decisions and data lineage end-to-end.
Example: Link output to model version and dataset.
Boundary limiting where or how a model may be deployed.
Example: No use in credit scoring without approval.
Compliance and safety risk from third-party AI providers.
Example: Insufficient documentation from model vendor.
Marking generated content to indicate synthetic origin.
Example: Machine-generated image provenance label.