Glossary
Plain English definitions of every standard, regulation, and technical term used in the assessment, with full legal and framework references.
65 terms
15-Day Reporting Obligation⌄
The duty to notify national authorities of serious AI incidents involving high-risk systems within 15 days.
- Article 73 of the EU AI Act
Missing this window is the most common projected enforcement gap.
Acceptable Use Policy⌄
Documented rules for which AI tools may be used, for what, by whom, and what is prohibited.
- Article 4 of the EU AI Act
Foundational organisational control and a regulator expectation.
Agentic AI⌄
Systems composed of one or more AI agents capable of multi-step autonomous task completion.
- Articles 14 and 15 of the EU AI Act
Materially raises the bar for human oversight and kill-switch design.
AI Agent⌄
An AI system that can take actions or call tools to achieve a goal, not just generate text.
- Articles 14 and 15 of the EU AI Act
Agents convert AI output risk into AI action risk.
AI Governance⌄
The set of policies, roles, controls, and reporting that allows an organisation to use AI responsibly.
- ISO/IEC 42001:2023
- NIST AI RMF Govern function
The frame within which all specific AI obligations are operated.
AI Literacy⌄
The level of skill, knowledge and understanding needed to deploy AI systems safely in a given role.
- Article 4 of the EU AI Act
An enforceable obligation since 2 February 2025.
Annex III⌄
The annex to the EU AI Act listing high-risk AI use cases across eight defined areas (Article 6(2)).
If your AI use falls into Annex III, it is high-risk by default and all high-risk obligations apply.
- Article 6 and Annex III of the EU AI Act (Regulation EU 2024/1689)
Annex III is the day-one test for whether you carry full high-risk obligations.
Annex III(1) - Biometrics⌄
Biometric categorisation and emotion recognition systems (outside Article 5 prohibitions).
- Annex III(1) of the EU AI Act
Common in HR, security, and retail analytics use cases.
Annex III(2) - Critical Infrastructure⌄
AI used in safety components of road, water, gas, heating, and electricity networks.
- Annex III(2) of the EU AI Act
Triggers high-risk obligations for utilities and operators.
Annex III(3) - Education and Vocational Training⌄
AI used to determine access to, or evaluation in, education and training.
- Annex III(3) of the EU AI Act
Catches admissions, proctoring, and assessment tools.
Annex III(4) - Employment⌄
AI for recruitment, selection, promotion, allocation, and termination decisions about workers.
- Annex III(4) of the EU AI Act
Most HR tech is now in scope by default.
Annex III(5) - Essential ServicesFinancial Services⌄
AI for credit-scoring, public benefits, emergency dispatch, and life/health insurance pricing.
- Annex III(5) of the EU AI Act
Catches retail finance and core insurance use cases.
Annex III(6) - Law Enforcement⌄
AI used by law enforcement for risk assessment, evidence evaluation, or profiling.
- Annex III(6) of the EU AI Act
Heavy-control area with overlapping fundamental rights obligations.
Annex III(7) - Migration, Asylum, Border Control⌄
AI used in visa, asylum, and border decisions.
- Annex III(7) of the EU AI Act
Largely public-sector, but private vendors fall in scope as providers.
Annex III(8) - Justice and Democratic Processes⌄
AI used to assist judicial authorities and AI that influences elections.
- Annex III(8) of the EU AI Act
Strong fundamental-rights overlay; relevant for legaltech and electoral tooling.
Audit Log⌄
An immutable record of activity sufficient to reconstruct what happened.
- Article 12 of the EU AI Act
Article 12 requires automatic event logging for high-risk AI.
Autonomous System⌄
Any system that performs consequential actions without contemporaneous human approval.
- Article 14 of the EU AI Act
Demands per-action thresholds, audit trails, and a tested kill-switch.
Bias Testing⌄
Empirical evaluation of AI performance across demographic and other subgroups.
- Article 10 of the EU AI Act
- NIST AI RMF MAP 4.1
Required for high-risk AI and core to clinical/financial fairness.
Board Accountability⌄
The expectation that the board takes informed responsibility for AI governance posture.
- Article 26 of the EU AI Act
Increasingly tested by regulators and investors.
Clinical ValidationHealthcare⌄
Demonstrating the performance of a clinical AI in the intended population and context of use.
- Annex I of MDR (EU) 2017/745
Required for safety and effectiveness and to mitigate bias risk.
Conformity Assessment⌄
The procedure to demonstrate a high-risk AI system meets all applicable requirements.
- Article 43 of the EU AI Act
Must be completed before placing high-risk AI on the market.
Corrective Action⌄
A documented action taken when an AI system produces unexpected, biased, or harmful output.
- Article 9(6) of the EU AI Act
Required evidence that the risk management system is operational.
Data Governance⌄
Controls on training, validation, and operational data quality, provenance, and bias.
- Article 10 of the EU AI Act (Regulation EU 2024/1689)
Cited in early enforcement priorities as a likely first-look area.
Data Loss Prevention (DLP)⌄
Controls that detect or block sensitive data leaving controlled environments.
- ISO/IEC 27001 Annex A 8.12
AI prompt egress is a new and important DLP surface.
DCB0129Healthcare⌄
NHS Digital clinical risk management standard for manufacturers of health IT.
- NHS Digital DCB0129
Required for clinical AI deployed in NHS settings, alongside DCB0160 for deployers.
Decision Architecture⌄
How responsibility and automation are allocated across humans and AI for a given decision type (advisory, augmented, automated).
- Article 14 of the EU AI Act
Without explicit architecture, oversight quietly collapses into rubber-stamping.
Declaration of Conformity⌄
Provider's signed statement that a high-risk AI system meets EU AI Act requirements.
- Article 47 of the EU AI Act
Required before placing high-risk AI on the EU market.
Deepfake⌄
Audio, image or video content that has been generated or manipulated by AI to falsely appear authentic (Article 3(60)).
Any AI-generated or manipulated likeness of a real person or scene. Must be disclosed as synthetic.
- Articles 3(60) and 50(3) of the EU AI Act
Disclosure is mandatory regardless of intent.
Deployer⌄
A natural or legal person using an AI system under its authority (Article 3(4)).
If you put an AI tool to work in your organisation, you are the deployer. Most enterprises are deployers.
- Article 3(4) of the EU AI Act
Deployers carry Articles 26 and 27 obligations including monitoring and incident reporting.
DORAFinancial Services⌄
The Digital Operational Resilience Act, governing ICT risk and third-party ICT risk for EU financial entities.
- Regulation EU 2022/2554 (DORA)
AI vendors are increasingly critical ICT third parties under DORA.
DPIA⌄
Data Protection Impact Assessment. A structured GDPR risk assessment, required for high-risk personal data processing.
- Article 35 of the GDPR (Regulation EU 2016/679)
Most AI deployments processing personal data trigger a DPIA.
EBA Guidelines on Model Risk ManagementFinancial Services⌄
European Banking Authority guidance treating ML/AI as in scope of model risk for credit and capital decisions.
- EBA Guidelines on Internal Governance (EBA/GL/2021/05)
- EBA Discussion Paper on Machine Learning for IRB Models
Confirms supervisors will treat AI/ML inside the MRM framework.
EU AI Act⌄
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence.
The EU's horizontal regulation for AI. It classifies AI systems by risk and imposes obligations on providers and deployers, with phased deadlines from February 2025 to August 2027.
- Regulation EU 2024/1689 (EU AI Act)
It is the framework that defines what counts as high-risk AI, what transparency is required, and what fines apply.
EU AI Database⌄
The public EU register of high-risk AI systems maintained by the Commission.
- Article 71 of the EU AI Act
Many high-risk systems must be registered before use.
FCA Consumer DutyFinancial Services⌄
UK FCA rule requiring firms to deliver good outcomes for retail customers.
- FCA Handbook PRIN 2A
AI in retail customer journeys is now actively supervised under Consumer Duty.
GDPR⌄
Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.
The EU's data protection regulation. Applies in parallel to the EU AI Act whenever personal data is processed.
- Regulation EU 2016/679 (GDPR)
Most AI use cases trigger GDPR obligations and AI Act obligations together.
High-Risk AI System⌄
AI systems falling within Article 6 of the EU AI Act, either because they are safety components of regulated products or because they are listed in Annex III.
AI that triggers the full obligation set: risk management, data governance, technical documentation, logging, human oversight, accuracy/robustness, and post-market monitoring.
- Articles 6 to 27 of the EU AI Act (Regulation EU 2024/1689)
High-risk classification drives the heaviest compliance lift and the highest enforcement risk.
Human Accountability Model⌄
A clear allocation of named ownership for AI systems, decisions, and incidents.
- Article 26 of the EU AI Act
Regulators look for one accountable person, not a committee.
Human Oversight⌄
Practical ability for humans to monitor, intervene in, and override AI outputs.
- Article 14 of the EU AI Act (Regulation EU 2024/1689)
Oversight must be real, not nominal. Regulators inspect operational evidence.
ISO 42001⌄
The international standard for an AI Management System (AIMS).
- ISO/IEC 42001:2023
Provides a certifiable management system aligned to the EU AI Act.
IVDRHealthcare⌄
The EU In Vitro Diagnostic Regulation, covering diagnostic devices and assays.
- Regulation (EU) 2017/746 (IVDR)
Diagnostic AI commonly falls under IVDR.
Lawful Basis⌄
The legal ground for processing personal data under GDPR.
- Article 6 of the GDPR (Regulation EU 2016/679)
Many AI use cases lack a clear lawful basis. This is enforceable today.
Least Privilege⌄
Granting the minimum access needed for a role or process to function.
- ISO/IEC 27001 Annex A 5.15
Applies to AI service accounts, plugin scopes, and grounding connectors.
MDRHealthcare⌄
The EU Medical Devices Regulation, covering safety and conformity of medical devices.
- Regulation (EU) 2017/745 (MDR)
Software, including AI, can qualify as a medical device.
MiFID IIFinancial Services⌄
The EU's directive on markets in financial instruments, including suitability and record-keeping rules.
- Article 25 of MiFID II (Directive 2014/65/EU)
AI-generated advice content remains within MiFID II record-keeping.
Multi-Agent System⌄
An architecture in which multiple AI agents collaborate to complete a task.
- Articles 14 and 15 of the EU AI Act
Combined permissions across agents can quietly escalate privilege.
Named Owner⌄
A specific individual accountable for an AI system or risk.
- Article 26 of the EU AI Act
The single most consistent expectation across EU AI Act, ISO 42001, and DORA.
NIST AI RMF⌄
The US National Institute of Standards and Technology AI Risk Management Framework, organised around Govern, Map, Measure, Manage.
- NIST AI Risk Management Framework 1.0
Widely used reference framework, complementary to ISO 42001 and the EU AI Act.
OAuth⌄
A standard for delegated access. Often used by AI plugins to act on a user's behalf.
- RFC 6749
Over-scoped OAuth grants are a leading cause of AI plugin sprawl.
Open-Source AI Model⌄
An AI model released under a licence allowing access to weights and use.
- Recital 102 and Article 2 of the EU AI Act
Open-source has partial exemptions but not for high-risk or GPAI obligations.
PCI DSS 4.0Financial Services⌄
The current Payment Card Industry Data Security Standard.
- PCI DSS v4.0
Any AI tool that can touch cardholder data expands PCI scope.
Permissions Sprawl⌄
Accumulation of broad or unused permissions over time, often inherited by AI tooling.
- ISO/IEC 27001 Annex A 5.18
Sprawl is the single biggest enabler of accidental AI data exposure.
Prohibited AI⌄
AI practices banned outright under Article 5 of the EU AI Act, including social scoring by public authorities, untargeted facial image scraping, and certain emotion-inference and biometric-categorisation systems.
There are eight prohibited practices. Using them carries the largest fines (up to EUR 35m or 7% of global turnover).
- Article 5 of the EU AI Act (Regulation EU 2024/1689)
Article 5 has been enforceable since 2 February 2025.
Prompt Injection⌄
An attack technique that hides malicious instructions in content the AI reads, causing it to act against its intended policy.
- OWASP LLM Top 10 (LLM01)
Now a primary AI security threat; not covered by traditional appsec controls.
Provider⌄
A natural or legal person that develops, or has developed, an AI system and places it on the market or puts it into service under its own name (Article 3(3)).
If you build the AI or substantially modify it, you are a provider with the heaviest set of obligations.
- Article 3(3) of the EU AI Act
Provider status applies to vendors and to enterprises that fine-tune or rebrand AI.
PSD2Financial Services⌄
The EU's revised Payment Services Directive, covering authentication and fraud monitoring.
- Directive (EU) 2015/2366 (PSD2)
- Commission Delegated Regulation 2018/389 (SCA RTS)
AI-driven SCA exemption decisions must remain explainable.
Risk Management System⌄
A continuous, documented process that identifies, evaluates, and mitigates risks across the AI lifecycle.
- Article 9 of the EU AI Act (Regulation EU 2024/1689)
A one-off assessment does not meet Article 9; the system must be live.
Risk Register⌄
A live record of identified risks with severity, owner, treatment, and status.
- ISO 31000:2018
Where AI risks live alongside operational and cyber risks.
Sensitivity Labels⌄
Metadata applied to documents that signals confidentiality and drives access and DLP rules.
- NIST SP 800-60
- ISO/IEC 27001 Annex A 5.12
The primary mechanism for stopping AI tools like Copilot from surfacing sensitive content.
Shadow AI⌄
AI tools used by employees on personal accounts or outside sanctioned channels.
- Articles 4 and 26 of the EU AI Act
It is where most enterprises are most exposed; invisible to security and to governance.
Solvency IIFinancial Services⌄
EU prudential regime for insurers, including governance and model approval rules.
- Directive 2009/138/EC (Solvency II)
AI in capital and reserving models inherits Solvency II governance.
SR 11-7Financial Services⌄
US Federal Reserve guidance on model risk management.
- SR 11-7 (Federal Reserve)
Reference framework for MRM treatment of ML models, including in EU practice.
Synthetic Data⌄
Artificial data generated by algorithms to mimic real data characteristics.
- Article 10(3) of the EU AI Act
Useful, but must be labelled and validated under Article 10.
Technical Documentation⌄
The provider's compliance file describing system design, data, performance, and risk controls.
- Article 11 and Annex IV of the EU AI Act
The default evidence pack regulators will ask for.
Transparency Obligation⌄
The duty to disclose AI interactions and AI-generated content to people, including chatbots, deepfakes, and AI-assisted content.
- Article 50 of the EU AI Act (Regulation EU 2024/1689)
Enforceable from 2 August 2026.
