Resource · Glossary
EU AI Act glossary
Key terms from the regulation, translated into plain English with article references.
AI system
A machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, recommendations, or decisions that can influence physical or virtual environments (Art. 3(1)).
Provider
A natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge (Art. 3(3)).
Deployer
A natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity (Art. 3(4)). If you use an AI tool in your business, you are a deployer.
Distributor
Any natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market (Art. 3(6)).
Importer
Any natural or legal person established in the Union that places on the market an AI system that bears the name or trademark of a person established outside the Union (Art. 3(7)).
High-risk AI system
An AI system listed in Annex III or otherwise meeting the criteria in Article 6. These systems are subject to the full set of obligations under Articles 8–17 and 72.
General-purpose AI model (GPAI)
An AI model — including when trained with a large amount of data using self-supervision at scale — that displays significant generality and is capable of competently performing a wide range of distinct tasks, and that can be integrated into a variety of downstream systems or applications (Art. 3(63)).
General-purpose AI system
An AI system based on a general-purpose AI model, that has the capability to serve a variety of purposes — both intended and unforeseen by the provider — and can be used, or adapted for use, in a variety of contexts (Art. 3(66)).
Systemic risk
A risk that is specific to the capabilities of general-purpose AI models with high-impact capabilities, having a significant impact on the Union market, with potential to negatively affect public health, security, public safety, fundamental rights, or the society as a whole (Art. 3(65)).
Risk management system
A continuous, iterative process designed and integrated into the AI system's lifecycle to identify, estimate, evaluate, and mitigate risks (Art. 9).
Human oversight
The capability of natural persons to understand and supervise an AI system's operation, including its relevant capacities and limitations, and to detect, prevent, and minimise adverse impacts (Art. 14).
Post-market monitoring
Activities carried out by providers of AI systems to systematically collect, document, and analyse relevant data provided by deployers or collected through other means on the performance and compliance of AI systems throughout their lifecycle (Art. 72).
Transparency obligation
The requirement under Article 50 for certain AI systems (chatbots, deepfakes, emotion recognition, biometric categorisation) to inform users that they are interacting with AI or that content has been artificially generated or manipulated.
Annex III
The list of high-risk AI system categories in the AI Act, covering: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential public and private services, law enforcement, migration and border control, administration of justice, and democratic processes.
CE marking
A marking by which the provider indicates that an AI system is in conformity with the requirements set out in the AI Act and other applicable Union legislation. Required before placing a high-risk AI system on the market.
Notifying authority
A national authority responsible for setting up and carrying out the necessary procedures for the conformity assessment of high-risk AI systems (Art. 3(19)).
Fundamental rights impact assessment (FRIA)
An assessment required for certain high-risk AI systems deployed by public bodies or certain private entities, evaluating the impact on fundamental rights before deployment (Art. 27).
AI literacy
Skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make informed decisions regarding AI systems (Art. 4).
Need help applying these?
Our risk classifier walks you through these terms in the context of your actual AI systems.
Start free assessment