GLOSSARY

AI Act glossary

The AI Act comes with its own vocabulary - deployer, GPAI, high risk, conformity assessment. We've gathered the key terms in one place, in plain definitions, grouped the same way as our training programme.

AI Literacy

AI system
Software that operates with a degree of autonomy and, from input data, generates outputs (content, predictions, recommendations, decisions) that influence physical or virtual environments. Simplified definition from Article 3 of the AI Act.
Provider
The party that develops an AI system (or has one developed) and places it on the market under its own name or brand. The role is defined in Article 3 of the AI Act.
Deployer
An organisation or person that uses an AI system in the course of its own activities, without being its provider. Most companies using off-the-shelf AI tools act in this role, which is set out in Article 3 of the AI Act.
AI literacy
The knowledge and skills needed to use AI systems safely and knowingly. An obligation under Article 4 of the AI Act, in force since 2 February 2025. In July 2026 the Digital Omnibus changed its wording: providers and deployers take measures to support the development of AI literacy, rather than guaranteeing any specific level of knowledge.
GPAI (general-purpose AI model)
A model trained on a large amount of data, capable of performing a wide range of different tasks - for example, the large language models behind popular chatbots. Obligations for providers of such models are set out in Article 51 of the AI Act.

Risk & System

High-risk system
An AI system whose use (e.g. in recruitment, credit scoring, education) carries elevated risk to health, safety or fundamental rights, and is subject to additional obligations. The classification rules are in Article 6 of the AI Act. We cover the detail on our page about high-risk systems.
Annex III
The list of AI uses treated as high-risk - among them employment, education, creditworthiness assessment and access to public services. The full list is in Annex III to the AI Act, and the related obligations apply from 2 December 2027. We cover the detail on our page about high-risk systems.
Prohibited AI practices
AI uses explicitly banned by the regulation - for example, behavioural manipulation beyond a person's awareness, or social scoring of citizens. The catalogue is in Article 5 of the AI Act; it has applied since 2 February 2025, with two further prohibitions from 2 December 2026.
Transparency obligations
The requirement to tell people they are dealing with AI: marking AI-generated content, disclosing that a chatbot is a bot, revealing deepfakes. It follows from Article 50 of the AI Act and has applied since 2 August 2026.
Deepfake / synthetic content
Image, audio or video generated or manipulated by AI that resembles existing people, objects or events in a way that could mislead. The duty to disclose it follows from Article 50 of the AI Act.
Generative models
AI systems that create new content - text, images, audio - from input data. Example: chatbots and image generators. Their outputs are subject to the marking obligations in Article 50 of the AI Act.

AI Governance

AI Governance
How an organisation manages its use of AI: roles, processes, policies and oversight of how and for what AI is used. The wider regulatory framework is described by the European Commission.
Human oversight
The requirement that a person can supervise, intervene in or stop an AI system's operation. As a formal obligation under Article 14 of the AI Act it applies to high-risk systems, but as good practice it is worth applying wherever AI supports decisions about people. We cover the detail on our page about high-risk systems.
Risk assessment
The process of identifying and estimating potential hazards from using a given AI system in a given context. The formal risk management system under Article 9 of the AI Act applies to high-risk systems; an organisational risk assessment is useful to any company. We cover the detail on our page about high-risk systems.
AI use policy
An organisation's internal document setting out the rules and limits for employees using AI tools.

Evidence & Compliance

AI system register
An organisation's internal record of the AI tools it uses, along with their purpose and risk level. The AI Act does not explicitly require one of every deployer, but without it you cannot check whether any use case falls into the high-risk category, or show that nobody is doing something prohibited. We cover the detail on our page about high-risk systems.
Technical documentation
A set of information about an AI system - purpose, data, architecture, testing - required for high-risk systems, among others. We cover the detail on our page about high-risk systems.
Due-diligence evidence
An organisation's documented actions (policies, training, risk assessments, registers) that show it took reasonable steps toward using AI responsibly. On the literacy obligation, the European Commission's Q&A on Article 4 indicates that an internal record of training and initiatives is enough.
Conformity assessment
A formal procedure for checking whether an AI system meets the regulation's requirements - required for some high-risk systems and set out in Article 43 of the AI Act. We cover the detail on our page about high-risk systems.
Administrative sanctions
Fines under Article 99 of the AI Act for breaching obligations, reaching up to EUR 35 million or 7% of global turnover. The amount depends on which obligation was breached.
Notified body
An independent institution authorised to carry out conformity assessments for certain high-risk AI systems and to issue certificates within the meaning of Article 44 of the AI Act. We cover the detail on our page about high-risk systems.
Market surveillance authority
The national body responsible for checking compliance with the AI Act and enforcing obligations; its powers are set out in Article 74 of the AI Act. In Poland this is KRiBSI.
KRiBSI
The Commission for AI Development and Safety - the Polish market surveillance authority for AI systems, established by the Act of 3 July 2026 on artificial intelligence systems. It handles complaints, carries out inspections and imposes penalties - those provisions take effect on 28 October 2026, and the Commission starts work in November.
Digital Omnibus on AI
Regulation 2026/1744, in force since 27 July 2026 - the first amendment to the AI Act since its adoption. It moved the deadlines for high-risk systems to December 2027 and August 2028, softened the wording of the literacy obligation and added two new prohibitions to Article 5.

Not sure where to start?

Check in 3 minutes which AI Act obligations apply to your organisation. No commitment.

The AI Act is now in force. Transparency obligations under Article 50 of the AI Act have applied since 2 August 2026, and the European Commission has started enforcing the rules. Documented diligence is what counts.
Check your AI Act readiness →