Resources / EU AI Act glossary

Understand the language before deciding what applies.

51 practical definitions covering systems, regulatory roles, classification, evidence, general-purpose AI, people and enforcement. Each explains why the term changes the work—not only what it means.

Plain-language guidance reviewed 27 August 2026. It is not legal advice and does not replace the current official text.

Keep these distinctions clear

The vocabulary describes different layers of responsibility.

Model and system

A GPAI model can sit inside many AI systems. The system purpose and context still matter.

Role and risk

Provider or deployer describes conduct. High-risk describes the system and use.

Evidence and conformity

A readiness record or specialist opinion is not automatically conformity assessment.

People and impact

4 terms

Affected person

Used throughout the Act

A person whose rights, safety, opportunities or treatment may be influenced by an AI system, even if they are not its user.

Why it matters: Operators and affected people may be different groups. Both perspectives matter to impact, oversight, transparency and literacy.

Apply this in exposure check

AI literacy

Articles 3(56) and 4

The skills, knowledge and understanding needed to make informed use or deployment of AI and recognise its opportunities, risks and possible harms.

Why it matters: Measures should reflect responsibilities, existing knowledge, use context and affected people—not attendance at one generic course.

Apply this in implementation planning

Human oversight

Article 14

Measures enabling competent people to understand relevant capabilities and limitations, monitor operation, interpret outputs and intervene where necessary.

Why it matters: A nominal human-in-the-loop is weak if that person lacks information, time, competence, authority or a practical way to stop the system.

Apply this in obligations and evidence

Fundamental rights impact assessment (FRIA)

Article 27

An assessment required before certain deployers use specified Annex III high-risk systems, covering process, affected groups, harm, oversight and mitigation.

Why it matters: Applicability depends on the deployer and use. It complements rather than automatically replaces a data-protection impact assessment.

Scope and systems

5 terms

AI system

Article 3(1)

A machine-based system designed to operate with varying autonomy that infers from inputs how to generate outputs capable of influencing physical or virtual environments.

Why it matters: The definition extends beyond generative AI to prediction, recommendation and decision-support systems.

Apply this in ai inventory

Intended purpose

Article 3(12)

The provider's intended use, including context and conditions described in instructions, technical documentation, promotional material and statements.

Why it matters: Purpose is central to classification. A model name does not describe the decision, affected people or operating context.

Reasonably foreseeable misuse

Article 3(13)

Use outside the intended purpose that may result from reasonably foreseeable human behaviour or interaction with other systems.

Why it matters: Risk work should consider plausible workarounds, operational pressure and combinations—not only the ideal provider workflow.

Apply this in risk and incidents

Instructions for use

Articles 3(15) and 13

Provider information about intended purpose, proper use, characteristics, limitations, oversight and other matters needed by deployers.

Why it matters: Instructions shape controls, learning and monitoring, so teams should retain the version relied on and track material updates.

Substantial modification

Articles 3(23) and 25

An unplanned post-market change affecting compliance with high-risk requirements or modifying the assessed intended purpose.

Why it matters: It can change responsibilities in the value chain and should trigger role and classification review.

Apply this in role and classification

Regulatory roles

7 terms

Provider

Article 3(3)

A person or body that develops, or has developed, an AI system or GPAI model and places it on the market or puts the system into service under its own name or trade mark.

Why it matters: Using a third-party model does not automatically prevent a business being provider of its own AI system.

Apply this in role and classification

Deployer

Article 3(4)

A person or body using an AI system under its authority, except for personal non-professional activity.

Why it matters: The deployer is normally the organisation, not every employee operating its tool.

Authorised representative

Article 3(5)

An EU-established person who accepts a written mandate from a provider to perform specified obligations and procedures on its behalf.

Why it matters: The written mandate must be understood precisely; it does not erase all provider responsibility.

Importer

Article 3(6)

An EU-established person placing on the market an AI system bearing the name or trade mark of someone established outside the EU.

Why it matters: Importers have their own checks and cooperation duties and should not be grouped automatically with distributors.

Distributor

Article 3(7)

A supply-chain participant, other than provider or importer, that makes an AI system available on the EU market.

Why it matters: Distribution can carry checks, corrective-action and cooperation duties even without development responsibility.

Operator

Article 3(8)

The collective term for a provider, product manufacturer, deployer, authorised representative, importer or distributor.

Why it matters: A provision applying to an operator may reach further than providers and deployers alone.

Downstream provider

Article 3(68)

A provider of an AI system that integrates an AI model, whether supplied internally or by another entity under contract.

Why it matters: This distinguishes responsibility for a downstream system from responsibility for its underlying model.

Market activity

3 terms

Placing on the market

Article 3(9)

The first making available of an AI system or GPAI model on the EU market.

Why it matters: It is a specific market event, not every later supply or use.

Making available on the market

Article 3(10)

Supplying an AI system or GPAI model for distribution or use on the EU market as a commercial activity, for payment or free.

Why it matters: Free supply can still be market activity under the Act.

Putting into service

Article 3(11)

Supplying an AI system for first use directly to a deployer, or for the provider's own EU use, for its intended purpose.

Why it matters: An in-house system may be put into service without a conventional sale.

Risk classification

6 terms

High-risk AI system

Article 6 and Annexes I and III

An AI system meeting the product-safety route or a listed Annex III use, subject to the detailed rules and exceptions in Article 6.

Why it matters: Classification depends on intended purpose and context, not sector keywords alone.

Apply this in role and classification

Annex I route

Article 6(1) and Annex I

The route for AI that is a safety component of, or is itself, a regulated product requiring third-party conformity assessment under listed legislation.

Why it matters: It is distinct from the use cases in Annex III.

Annex III

Article 6(2) and Annex III

Listed sensitive uses in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes.

Why it matters: A listed area still requires analysis of the exact use and Article 6 conditions.

Prohibited AI practice

Article 5

An AI practice prohibited by the Act, subject to the exact elements and exceptions in Article 5.

Why it matters: A screen should test the complete legal conditions rather than applying a simplified label.

Apply this in exposure check

Transparency obligation

Article 50

Disclosure or marking requirements for specified AI interactions, synthetic outputs, emotion recognition, biometric categorisation or deepfakes.

Why it matters: The right control depends on actor, output, audience, timing and context.

Minimal or no-risk AI

Common explanatory term

A common label for AI outside the prohibited, high-risk and specific transparency regimes.

Why it matters: It is not a universal exemption: AI literacy, data protection, consumer, employment and sector rules may still matter.

Risk and controls

6 terms

Risk

Article 3(2)

The combination of the probability that harm occurs and the severity of that harm.

Why it matters: A risk record should identify harm, affected people, likelihood basis and severity—not only an unexplained rating.

Risk-management system

Article 9

A continuous and iterative lifecycle process for identifying, analysing, evaluating and addressing risks for high-risk AI.

Why it matters: Testing, post-market information and material change should keep feeding the process.

Apply this in risk and incidents

Data governance

Article 10

Governance and management practices applied to training, validation and testing data for relevant high-risk AI.

Why it matters: Origin, preparation, assumptions, suitability, representativeness, errors, gaps and bias need use-specific consideration.

Accuracy, robustness and cybersecurity

Article 15

Requirements for appropriate performance, resilience to errors or faults and resistance to relevant security threats.

Why it matters: Metrics and thresholds must be declared, tested and understood in the operating context.

Serious incident

Articles 3(49) and 73

An incident or malfunction leading to specified severe outcomes including serious health harm, critical-infrastructure disruption, fundamental-rights infringement, or serious property or environmental harm.

Why it matters: Organisations need a broader incident process capable of recognising events that may reach this defined threshold.

Post-market monitoring

Articles 3(25) and 72

Provider activities for collecting and reviewing experience after market placement or service to identify corrective or preventive action.

Why it matters: Operational data, complaints, incidents, performance and change should connect back to risk management.

Evidence and assurance

7 terms

Technical documentation

Article 11 and Annex IV

Documentation for a high-risk AI system intended to demonstrate compliance and enable authority assessment.

Why it matters: A generated draft remains a working file until gaps are completed and competent reviewers approve it.

Apply this in obligations and evidence

Record-keeping and logs

Articles 12, 19 and 26(6)

Capabilities and duties concerning automatic event recording and retention of logs under relevant provider or deployer control.

Why it matters: A governance audit trail is useful but is not the same as system-generated logging.

Quality-management system

Article 17

Documented policies, procedures and instructions through which a high-risk provider addresses compliance across design, testing, change, records and post-market activity.

Why it matters: A policy is one element; the management system requires connected ownership and operating processes.

Conformity assessment

Articles 3(20) and 43

The process for demonstrating whether a high-risk AI system meets Chapter III, Section 2 requirements.

Why it matters: It may involve internal control or a notified body and is not the same as a general readiness review.

EU declaration of conformity

Article 47 and Annex V

The provider's formal declaration that a high-risk AI system conforms with applicable requirements.

Why it matters: It is a regulated provider output, not a readiness badge an adviser can casually issue.

CE marking

Articles 3(24) and 48

The marking through which a provider indicates conformity with relevant AI Act and harmonisation requirements.

Why it matters: A readiness report or specialist opinion must not be represented as CE marking or regulatory certification.

Independent review

Governance practice

A scoped review by a suitably qualified person separate from the original decision or delivery work.

Why it matters: Its value depends on credentials, independence, scope, sources and the stable record reviewed; it is not automatically certification.

Apply this in independent review

General-purpose AI

4 terms

General-purpose AI model (GPAI)

Article 3(63)

A broadly capable model, typically trained at scale, able to perform many tasks and integrate into varied downstream systems.

Why it matters: A GPAI model and an AI system using it are different regulatory objects and may have different providers.

General-purpose AI system

Article 3(66)

An AI system based on a GPAI model that can serve varied purposes directly or through integration.

Why it matters: Inventory should record both the system and its underlying model dependency.

High-impact capabilities

Article 3(64)

Capabilities matching or exceeding those recorded in the most advanced GPAI models.

Why it matters: The concept contributes to identifying GPAI models with systemic risk.

Systemic risk

Articles 3(65) and 51

Risk specific to high-impact GPAI capabilities that can significantly affect the EU market and propagate at scale.

Why it matters: This defined GPAI concept differs from informally describing an operational issue as systemic.

Biometrics and synthetic content

4 terms

Deepfake

Articles 3(60) and 50

AI-generated or manipulated image, audio or video resembling real subjects or events and falsely appearing authentic or truthful.

Why it matters: The defined term is narrower than all synthetic media; disclosure depends on content and context.

Emotion-recognition system

Article 3(39)

An AI system intended to identify or infer emotions or intentions from biometric data.

Why it matters: Certain uses are prohibited and others can carry transparency or high-risk implications.

Biometric categorisation system

Article 3(40)

An AI system assigning people to categories on the basis of biometric data, subject to the definition's qualification.

Why it matters: This differs from identity verification; purpose and categories materially affect analysis.

Remote biometric identification

Article 3(41)–(43)

Identification without active involvement, usually at a distance, by comparing biometric data with a reference database; real-time and post-remote forms are distinguished.

Why it matters: The form, actor and setting affect prohibition, authorisation, documentation and high-risk analysis.

Governance and enforcement

5 terms

AI Office

Articles 3(47) and 64

The European Commission function contributing to implementation, monitoring and supervision of AI systems, GPAI models and EU AI governance.

Why it matters: It has particular GPAI responsibilities and supports consistent implementation.

National competent authority

Articles 3(48) and 70

A notifying authority or market-surveillance authority designated by a Member State.

Why it matters: Responsibilities and contact points can vary by Member State and subject.

Market-surveillance authority

Articles 3(26) and 74

A national authority carrying out market-surveillance activities and measures for AI systems.

Why it matters: Operators may need to cooperate, provide records or take corrective action.

Notified body

Article 3(22)

A conformity-assessment body formally notified under the Act and relevant harmonisation legislation.

Why it matters: An independent adviser is not a notified body merely because they review an assessment.

EU database for high-risk AI systems

Articles 49 and 71

The EU database supporting registration and transparency for specified high-risk systems and operator information.

Why it matters: Registration depends on role and category and should be checked against current implementation requirements.

Official source

Check the legal wording before relying on a definition.

The glossary paraphrases the Act for practical use. Amendments and implementation material may change the current position, so dated source review remains essential.