GLOSSARY
AI Act glossary
The AI Act comes with its own vocabulary - deployer, GPAI, high risk, conformity assessment. We've gathered the key terms in one place, in plain definitions, grouped the same way as our training programme.
AI Literacy
- AI system
- Software that operates with a degree of autonomy and, from input data, generates outputs (content, predictions, recommendations, decisions) that influence physical or virtual environments. Simplified definition from Article 3 of the AI Act.
- Provider
- The party that develops an AI system (or has one developed) and places it on the market under its own name or brand.
- Deployer
- An organisation or person that uses an AI system in the course of its own activities, without being its provider. Most companies using off-the-shelf AI tools act in this role.
- AI literacy
- The knowledge and skills needed to use AI systems safely and knowingly. An obligation under Article 4 of the AI Act, in force since 2 February 2025.
- GPAI (general-purpose AI model)
- A model trained on a large amount of data, capable of performing a wide range of different tasks - for example, the large language models behind popular chatbots.
Risk & System
- High-risk system
- An AI system whose use (e.g. in recruitment, credit scoring, education) carries elevated risk to health, safety or fundamental rights, and is subject to additional obligations.
- Prohibited AI practices
- AI uses explicitly banned by the regulation - for example, behavioural manipulation beyond a person's awareness, or social scoring of citizens.
- Deepfake / synthetic content
- Image, audio or video generated or manipulated by AI that resembles existing people, objects or events in a way that could mislead.
- Generative models
- AI systems that create new content - text, images, audio - from input data. Example: chatbots and image generators.
AI Governance
- AI Governance
- How an organisation manages its use of AI: roles, processes, policies and oversight of how and for what AI is used.
- Human oversight
- The requirement that a person can supervise, intervene in or stop an AI system's operation - especially for high-risk systems.
- Risk assessment
- The process of identifying and estimating potential hazards from using a given AI system in a given context.
- AI use policy
- An organisation's internal document setting out the rules and limits for employees using AI tools.
Evidence & Compliance
- AI system register
- An organisation's internal record of the AI tools it uses, along with their purpose and risk level.
- Technical documentation
- A set of information about an AI system - purpose, data, architecture, testing - required for high-risk systems, among others.
- Due-diligence evidence
- An organisation's documented actions (policies, training, risk assessments, registers) that show it took reasonable steps toward using AI responsibly.
- Conformity assessment
- A formal procedure for checking whether an AI system meets the regulation's requirements - required for some high-risk systems.
- Administrative sanctions
- Fines under the AI Act for breaching obligations, reaching up to EUR 35 million or 7% of global turnover.
- Notified body
- An independent institution authorised to carry out conformity assessments for certain high-risk AI systems.
- Market surveillance authority
- The national body responsible for checking compliance with the AI Act and enforcing obligations.
Not sure where to start?
Check in 3 minutes which AI Act obligations apply to your organisation. No commitment.
The AI Act is now in force. Transparency obligations have applied since 2 August 2026 - documented diligence is what counts.