Glossary

Plain English definitions of every standard, regulation, and technical term used in the assessment, with full legal and framework references.

65 terms

15-Day Reporting Obligation
In plain English

The duty to notify national authorities of serious AI incidents involving high-risk systems within 15 days.

Legal and framework references
  • Article 73 of the EU AI Act
Why it matters for your organisation

Missing this window is the most common projected enforcement gap.

Acceptable Use Policy
In plain English

Documented rules for which AI tools may be used, for what, by whom, and what is prohibited.

Legal and framework references
  • Article 4 of the EU AI Act
Why it matters for your organisation

Foundational organisational control and a regulator expectation.

Agentic AI
In plain English

Systems composed of one or more AI agents capable of multi-step autonomous task completion.

Legal and framework references
  • Articles 14 and 15 of the EU AI Act
Why it matters for your organisation

Materially raises the bar for human oversight and kill-switch design.

AI Agent
In plain English

An AI system that can take actions or call tools to achieve a goal, not just generate text.

Legal and framework references
  • Articles 14 and 15 of the EU AI Act
Why it matters for your organisation

Agents convert AI output risk into AI action risk.

AI Governance
In plain English

The set of policies, roles, controls, and reporting that allows an organisation to use AI responsibly.

Legal and framework references
  • ISO/IEC 42001:2023
  • NIST AI RMF Govern function
Why it matters for your organisation

The frame within which all specific AI obligations are operated.

AI Literacy
In plain English

The level of skill, knowledge and understanding needed to deploy AI systems safely in a given role.

Legal and framework references
  • Article 4 of the EU AI Act
Why it matters for your organisation

An enforceable obligation since 2 February 2025.

Annex III
Official definition

The annex to the EU AI Act listing high-risk AI use cases across eight defined areas (Article 6(2)).

In plain English

If your AI use falls into Annex III, it is high-risk by default and all high-risk obligations apply.

Legal and framework references
  • Article 6 and Annex III of the EU AI Act (Regulation EU 2024/1689)
Why it matters for your organisation

Annex III is the day-one test for whether you carry full high-risk obligations.

Annex III(1) - Biometrics
In plain English

Biometric categorisation and emotion recognition systems (outside Article 5 prohibitions).

Legal and framework references
  • Annex III(1) of the EU AI Act
Why it matters for your organisation

Common in HR, security, and retail analytics use cases.

Annex III(2) - Critical Infrastructure
In plain English

AI used in safety components of road, water, gas, heating, and electricity networks.

Legal and framework references
  • Annex III(2) of the EU AI Act
Why it matters for your organisation

Triggers high-risk obligations for utilities and operators.

Annex III(3) - Education and Vocational Training
In plain English

AI used to determine access to, or evaluation in, education and training.

Legal and framework references
  • Annex III(3) of the EU AI Act
Why it matters for your organisation

Catches admissions, proctoring, and assessment tools.

Annex III(4) - Employment
In plain English

AI for recruitment, selection, promotion, allocation, and termination decisions about workers.

Legal and framework references
  • Annex III(4) of the EU AI Act
Why it matters for your organisation

Most HR tech is now in scope by default.

Annex III(5) - Essential ServicesFinancial Services
In plain English

AI for credit-scoring, public benefits, emergency dispatch, and life/health insurance pricing.

Legal and framework references
  • Annex III(5) of the EU AI Act
Why it matters for your organisation

Catches retail finance and core insurance use cases.

Annex III(6) - Law Enforcement
In plain English

AI used by law enforcement for risk assessment, evidence evaluation, or profiling.

Legal and framework references
  • Annex III(6) of the EU AI Act
Why it matters for your organisation

Heavy-control area with overlapping fundamental rights obligations.

Annex III(7) - Migration, Asylum, Border Control
In plain English

AI used in visa, asylum, and border decisions.

Legal and framework references
  • Annex III(7) of the EU AI Act
Why it matters for your organisation

Largely public-sector, but private vendors fall in scope as providers.

Annex III(8) - Justice and Democratic Processes
In plain English

AI used to assist judicial authorities and AI that influences elections.

Legal and framework references
  • Annex III(8) of the EU AI Act
Why it matters for your organisation

Strong fundamental-rights overlay; relevant for legaltech and electoral tooling.

Audit Log
In plain English

An immutable record of activity sufficient to reconstruct what happened.

Legal and framework references
  • Article 12 of the EU AI Act
Why it matters for your organisation

Article 12 requires automatic event logging for high-risk AI.

Autonomous System
In plain English

Any system that performs consequential actions without contemporaneous human approval.

Legal and framework references
  • Article 14 of the EU AI Act
Why it matters for your organisation

Demands per-action thresholds, audit trails, and a tested kill-switch.

Bias Testing
In plain English

Empirical evaluation of AI performance across demographic and other subgroups.

Legal and framework references
  • Article 10 of the EU AI Act
  • NIST AI RMF MAP 4.1
Why it matters for your organisation

Required for high-risk AI and core to clinical/financial fairness.

Board Accountability
In plain English

The expectation that the board takes informed responsibility for AI governance posture.

Legal and framework references
  • Article 26 of the EU AI Act
Why it matters for your organisation

Increasingly tested by regulators and investors.

Clinical ValidationHealthcare
In plain English

Demonstrating the performance of a clinical AI in the intended population and context of use.

Legal and framework references
  • Annex I of MDR (EU) 2017/745
Why it matters for your organisation

Required for safety and effectiveness and to mitigate bias risk.

Conformity Assessment
In plain English

The procedure to demonstrate a high-risk AI system meets all applicable requirements.

Legal and framework references
  • Article 43 of the EU AI Act
Why it matters for your organisation

Must be completed before placing high-risk AI on the market.

Corrective Action
In plain English

A documented action taken when an AI system produces unexpected, biased, or harmful output.

Legal and framework references
  • Article 9(6) of the EU AI Act
Why it matters for your organisation

Required evidence that the risk management system is operational.

Data Governance
In plain English

Controls on training, validation, and operational data quality, provenance, and bias.

Legal and framework references
  • Article 10 of the EU AI Act (Regulation EU 2024/1689)
Why it matters for your organisation

Cited in early enforcement priorities as a likely first-look area.

Data Loss Prevention (DLP)
In plain English

Controls that detect or block sensitive data leaving controlled environments.

Legal and framework references
  • ISO/IEC 27001 Annex A 8.12
Why it matters for your organisation

AI prompt egress is a new and important DLP surface.

DCB0129Healthcare
In plain English

NHS Digital clinical risk management standard for manufacturers of health IT.

Legal and framework references
  • NHS Digital DCB0129
Why it matters for your organisation

Required for clinical AI deployed in NHS settings, alongside DCB0160 for deployers.

Decision Architecture
In plain English

How responsibility and automation are allocated across humans and AI for a given decision type (advisory, augmented, automated).

Legal and framework references
  • Article 14 of the EU AI Act
Why it matters for your organisation

Without explicit architecture, oversight quietly collapses into rubber-stamping.

Declaration of Conformity
In plain English

Provider's signed statement that a high-risk AI system meets EU AI Act requirements.

Legal and framework references
  • Article 47 of the EU AI Act
Why it matters for your organisation

Required before placing high-risk AI on the EU market.

Deepfake
Official definition

Audio, image or video content that has been generated or manipulated by AI to falsely appear authentic (Article 3(60)).

In plain English

Any AI-generated or manipulated likeness of a real person or scene. Must be disclosed as synthetic.

Legal and framework references
  • Articles 3(60) and 50(3) of the EU AI Act
Why it matters for your organisation

Disclosure is mandatory regardless of intent.

Deployer
Official definition

A natural or legal person using an AI system under its authority (Article 3(4)).

In plain English

If you put an AI tool to work in your organisation, you are the deployer. Most enterprises are deployers.

Legal and framework references
  • Article 3(4) of the EU AI Act
Why it matters for your organisation

Deployers carry Articles 26 and 27 obligations including monitoring and incident reporting.

DORAFinancial Services
In plain English

The Digital Operational Resilience Act, governing ICT risk and third-party ICT risk for EU financial entities.

Legal and framework references
  • Regulation EU 2022/2554 (DORA)
Why it matters for your organisation

AI vendors are increasingly critical ICT third parties under DORA.

DPIA
In plain English

Data Protection Impact Assessment. A structured GDPR risk assessment, required for high-risk personal data processing.

Legal and framework references
  • Article 35 of the GDPR (Regulation EU 2016/679)
Why it matters for your organisation

Most AI deployments processing personal data trigger a DPIA.

EBA Guidelines on Model Risk ManagementFinancial Services
In plain English

European Banking Authority guidance treating ML/AI as in scope of model risk for credit and capital decisions.

Legal and framework references
  • EBA Guidelines on Internal Governance (EBA/GL/2021/05)
  • EBA Discussion Paper on Machine Learning for IRB Models
Why it matters for your organisation

Confirms supervisors will treat AI/ML inside the MRM framework.

EU AI Act
Official definition

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence.

In plain English

The EU's horizontal regulation for AI. It classifies AI systems by risk and imposes obligations on providers and deployers, with phased deadlines from February 2025 to August 2027.

Legal and framework references
  • Regulation EU 2024/1689 (EU AI Act)
Why it matters for your organisation

It is the framework that defines what counts as high-risk AI, what transparency is required, and what fines apply.

EU AI Database
In plain English

The public EU register of high-risk AI systems maintained by the Commission.

Legal and framework references
  • Article 71 of the EU AI Act
Why it matters for your organisation

Many high-risk systems must be registered before use.

FCA Consumer DutyFinancial Services
In plain English

UK FCA rule requiring firms to deliver good outcomes for retail customers.

Legal and framework references
  • FCA Handbook PRIN 2A
Why it matters for your organisation

AI in retail customer journeys is now actively supervised under Consumer Duty.

GDPR
Official definition

Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.

In plain English

The EU's data protection regulation. Applies in parallel to the EU AI Act whenever personal data is processed.

Legal and framework references
  • Regulation EU 2016/679 (GDPR)
Why it matters for your organisation

Most AI use cases trigger GDPR obligations and AI Act obligations together.

High-Risk AI System
Official definition

AI systems falling within Article 6 of the EU AI Act, either because they are safety components of regulated products or because they are listed in Annex III.

In plain English

AI that triggers the full obligation set: risk management, data governance, technical documentation, logging, human oversight, accuracy/robustness, and post-market monitoring.

Legal and framework references
  • Articles 6 to 27 of the EU AI Act (Regulation EU 2024/1689)
Why it matters for your organisation

High-risk classification drives the heaviest compliance lift and the highest enforcement risk.

Human Accountability Model
In plain English

A clear allocation of named ownership for AI systems, decisions, and incidents.

Legal and framework references
  • Article 26 of the EU AI Act
Why it matters for your organisation

Regulators look for one accountable person, not a committee.

Human Oversight
In plain English

Practical ability for humans to monitor, intervene in, and override AI outputs.

Legal and framework references
  • Article 14 of the EU AI Act (Regulation EU 2024/1689)
Why it matters for your organisation

Oversight must be real, not nominal. Regulators inspect operational evidence.

ISO 42001
In plain English

The international standard for an AI Management System (AIMS).

Legal and framework references
  • ISO/IEC 42001:2023
Why it matters for your organisation

Provides a certifiable management system aligned to the EU AI Act.

IVDRHealthcare
In plain English

The EU In Vitro Diagnostic Regulation, covering diagnostic devices and assays.

Legal and framework references
  • Regulation (EU) 2017/746 (IVDR)
Why it matters for your organisation

Diagnostic AI commonly falls under IVDR.

Lawful Basis
In plain English

The legal ground for processing personal data under GDPR.

Legal and framework references
  • Article 6 of the GDPR (Regulation EU 2016/679)
Why it matters for your organisation

Many AI use cases lack a clear lawful basis. This is enforceable today.

Least Privilege
In plain English

Granting the minimum access needed for a role or process to function.

Legal and framework references
  • ISO/IEC 27001 Annex A 5.15
Why it matters for your organisation

Applies to AI service accounts, plugin scopes, and grounding connectors.

MDRHealthcare
In plain English

The EU Medical Devices Regulation, covering safety and conformity of medical devices.

Legal and framework references
  • Regulation (EU) 2017/745 (MDR)
Why it matters for your organisation

Software, including AI, can qualify as a medical device.

MiFID IIFinancial Services
In plain English

The EU's directive on markets in financial instruments, including suitability and record-keeping rules.

Legal and framework references
  • Article 25 of MiFID II (Directive 2014/65/EU)
Why it matters for your organisation

AI-generated advice content remains within MiFID II record-keeping.

Multi-Agent System
In plain English

An architecture in which multiple AI agents collaborate to complete a task.

Legal and framework references
  • Articles 14 and 15 of the EU AI Act
Why it matters for your organisation

Combined permissions across agents can quietly escalate privilege.

Named Owner
In plain English

A specific individual accountable for an AI system or risk.

Legal and framework references
  • Article 26 of the EU AI Act
Why it matters for your organisation

The single most consistent expectation across EU AI Act, ISO 42001, and DORA.

NIST AI RMF
In plain English

The US National Institute of Standards and Technology AI Risk Management Framework, organised around Govern, Map, Measure, Manage.

Legal and framework references
  • NIST AI Risk Management Framework 1.0
Why it matters for your organisation

Widely used reference framework, complementary to ISO 42001 and the EU AI Act.

OAuth
In plain English

A standard for delegated access. Often used by AI plugins to act on a user's behalf.

Legal and framework references
  • RFC 6749
Why it matters for your organisation

Over-scoped OAuth grants are a leading cause of AI plugin sprawl.

Open-Source AI Model
In plain English

An AI model released under a licence allowing access to weights and use.

Legal and framework references
  • Recital 102 and Article 2 of the EU AI Act
Why it matters for your organisation

Open-source has partial exemptions but not for high-risk or GPAI obligations.

PCI DSS 4.0Financial Services
In plain English

The current Payment Card Industry Data Security Standard.

Legal and framework references
  • PCI DSS v4.0
Why it matters for your organisation

Any AI tool that can touch cardholder data expands PCI scope.

Permissions Sprawl
In plain English

Accumulation of broad or unused permissions over time, often inherited by AI tooling.

Legal and framework references
  • ISO/IEC 27001 Annex A 5.18
Why it matters for your organisation

Sprawl is the single biggest enabler of accidental AI data exposure.

Prohibited AI
Official definition

AI practices banned outright under Article 5 of the EU AI Act, including social scoring by public authorities, untargeted facial image scraping, and certain emotion-inference and biometric-categorisation systems.

In plain English

There are eight prohibited practices. Using them carries the largest fines (up to EUR 35m or 7% of global turnover).

Legal and framework references
  • Article 5 of the EU AI Act (Regulation EU 2024/1689)
Why it matters for your organisation

Article 5 has been enforceable since 2 February 2025.

Prompt Injection
In plain English

An attack technique that hides malicious instructions in content the AI reads, causing it to act against its intended policy.

Legal and framework references
  • OWASP LLM Top 10 (LLM01)
Why it matters for your organisation

Now a primary AI security threat; not covered by traditional appsec controls.

Provider
Official definition

A natural or legal person that develops, or has developed, an AI system and places it on the market or puts it into service under its own name (Article 3(3)).

In plain English

If you build the AI or substantially modify it, you are a provider with the heaviest set of obligations.

Legal and framework references
  • Article 3(3) of the EU AI Act
Why it matters for your organisation

Provider status applies to vendors and to enterprises that fine-tune or rebrand AI.

PSD2Financial Services
In plain English

The EU's revised Payment Services Directive, covering authentication and fraud monitoring.

Legal and framework references
  • Directive (EU) 2015/2366 (PSD2)
  • Commission Delegated Regulation 2018/389 (SCA RTS)
Why it matters for your organisation

AI-driven SCA exemption decisions must remain explainable.

Risk Management System
In plain English

A continuous, documented process that identifies, evaluates, and mitigates risks across the AI lifecycle.

Legal and framework references
  • Article 9 of the EU AI Act (Regulation EU 2024/1689)
Why it matters for your organisation

A one-off assessment does not meet Article 9; the system must be live.

Risk Register
In plain English

A live record of identified risks with severity, owner, treatment, and status.

Legal and framework references
  • ISO 31000:2018
Why it matters for your organisation

Where AI risks live alongside operational and cyber risks.

Sensitivity Labels
In plain English

Metadata applied to documents that signals confidentiality and drives access and DLP rules.

Legal and framework references
  • NIST SP 800-60
  • ISO/IEC 27001 Annex A 5.12
Why it matters for your organisation

The primary mechanism for stopping AI tools like Copilot from surfacing sensitive content.

Shadow AI
In plain English

AI tools used by employees on personal accounts or outside sanctioned channels.

Legal and framework references
  • Articles 4 and 26 of the EU AI Act
Why it matters for your organisation

It is where most enterprises are most exposed; invisible to security and to governance.

Solvency IIFinancial Services
In plain English

EU prudential regime for insurers, including governance and model approval rules.

Legal and framework references
  • Directive 2009/138/EC (Solvency II)
Why it matters for your organisation

AI in capital and reserving models inherits Solvency II governance.

SR 11-7Financial Services
In plain English

US Federal Reserve guidance on model risk management.

Legal and framework references
  • SR 11-7 (Federal Reserve)
Why it matters for your organisation

Reference framework for MRM treatment of ML models, including in EU practice.

Synthetic Data
In plain English

Artificial data generated by algorithms to mimic real data characteristics.

Legal and framework references
  • Article 10(3) of the EU AI Act
Why it matters for your organisation

Useful, but must be labelled and validated under Article 10.

Technical Documentation
In plain English

The provider's compliance file describing system design, data, performance, and risk controls.

Legal and framework references
  • Article 11 and Annex IV of the EU AI Act
Why it matters for your organisation

The default evidence pack regulators will ask for.

Transparency Obligation
In plain English

The duty to disclose AI interactions and AI-generated content to people, including chatbots, deepfakes, and AI-assisted content.

Legal and framework references
  • Article 50 of the EU AI Act (Regulation EU 2024/1689)
Why it matters for your organisation

Enforceable from 2 August 2026.