Resources / EU AI Act glossary
Understand the language before deciding what applies.
51 practical definitions covering systems, regulatory roles, classification, evidence, general-purpose AI, people and enforcement. Each explains why the term changes the work—not only what it means.
Plain-language guidance reviewed 27 August 2026. It is not legal advice and does not replace the current official text.
Keep these distinctions clear
The vocabulary describes different layers of responsibility.
Model and system
A GPAI model can sit inside many AI systems. The system purpose and context still matter.
Role and risk
Provider or deployer describes conduct. High-risk describes the system and use.
Evidence and conformity
A readiness record or specialist opinion is not automatically conformity assessment.
People and impact
4 terms
Affected person
Used throughout the ActA person whose rights, safety, opportunities or treatment may be influenced by an AI system, even if they are not its user.
Why it matters: Operators and affected people may be different groups. Both perspectives matter to impact, oversight, transparency and literacy.
Apply this in exposure checkAI literacy
Articles 3(56) and 4The skills, knowledge and understanding needed to make informed use or deployment of AI and recognise its opportunities, risks and possible harms.
Why it matters: Measures should reflect responsibilities, existing knowledge, use context and affected people—not attendance at one generic course.
Apply this in implementation planningHuman oversight
Article 14Measures enabling competent people to understand relevant capabilities and limitations, monitor operation, interpret outputs and intervene where necessary.
Why it matters: A nominal human-in-the-loop is weak if that person lacks information, time, competence, authority or a practical way to stop the system.
Apply this in obligations and evidenceFundamental rights impact assessment (FRIA)
Article 27An assessment required before certain deployers use specified Annex III high-risk systems, covering process, affected groups, harm, oversight and mitigation.
Why it matters: Applicability depends on the deployer and use. It complements rather than automatically replaces a data-protection impact assessment.
Scope and systems
5 terms
AI system
Article 3(1)A machine-based system designed to operate with varying autonomy that infers from inputs how to generate outputs capable of influencing physical or virtual environments.
Why it matters: The definition extends beyond generative AI to prediction, recommendation and decision-support systems.
Apply this in ai inventoryIntended purpose
Article 3(12)The provider's intended use, including context and conditions described in instructions, technical documentation, promotional material and statements.
Why it matters: Purpose is central to classification. A model name does not describe the decision, affected people or operating context.
Reasonably foreseeable misuse
Article 3(13)Use outside the intended purpose that may result from reasonably foreseeable human behaviour or interaction with other systems.
Why it matters: Risk work should consider plausible workarounds, operational pressure and combinations—not only the ideal provider workflow.
Apply this in risk and incidentsInstructions for use
Articles 3(15) and 13Provider information about intended purpose, proper use, characteristics, limitations, oversight and other matters needed by deployers.
Why it matters: Instructions shape controls, learning and monitoring, so teams should retain the version relied on and track material updates.
Substantial modification
Articles 3(23) and 25An unplanned post-market change affecting compliance with high-risk requirements or modifying the assessed intended purpose.
Why it matters: It can change responsibilities in the value chain and should trigger role and classification review.
Apply this in role and classification
Regulatory roles
7 terms
Provider
Article 3(3)A person or body that develops, or has developed, an AI system or GPAI model and places it on the market or puts the system into service under its own name or trade mark.
Why it matters: Using a third-party model does not automatically prevent a business being provider of its own AI system.
Apply this in role and classificationDeployer
Article 3(4)A person or body using an AI system under its authority, except for personal non-professional activity.
Why it matters: The deployer is normally the organisation, not every employee operating its tool.
Importer
Article 3(6)An EU-established person placing on the market an AI system bearing the name or trade mark of someone established outside the EU.
Why it matters: Importers have their own checks and cooperation duties and should not be grouped automatically with distributors.
Distributor
Article 3(7)A supply-chain participant, other than provider or importer, that makes an AI system available on the EU market.
Why it matters: Distribution can carry checks, corrective-action and cooperation duties even without development responsibility.
Operator
Article 3(8)The collective term for a provider, product manufacturer, deployer, authorised representative, importer or distributor.
Why it matters: A provision applying to an operator may reach further than providers and deployers alone.
Downstream provider
Article 3(68)A provider of an AI system that integrates an AI model, whether supplied internally or by another entity under contract.
Why it matters: This distinguishes responsibility for a downstream system from responsibility for its underlying model.
Market activity
3 terms
Placing on the market
Article 3(9)The first making available of an AI system or GPAI model on the EU market.
Why it matters: It is a specific market event, not every later supply or use.
Making available on the market
Article 3(10)Supplying an AI system or GPAI model for distribution or use on the EU market as a commercial activity, for payment or free.
Why it matters: Free supply can still be market activity under the Act.
Putting into service
Article 3(11)Supplying an AI system for first use directly to a deployer, or for the provider's own EU use, for its intended purpose.
Why it matters: An in-house system may be put into service without a conventional sale.
Risk classification
6 terms
High-risk AI system
Article 6 and Annexes I and IIIAn AI system meeting the product-safety route or a listed Annex III use, subject to the detailed rules and exceptions in Article 6.
Why it matters: Classification depends on intended purpose and context, not sector keywords alone.
Apply this in role and classificationAnnex I route
Article 6(1) and Annex IThe route for AI that is a safety component of, or is itself, a regulated product requiring third-party conformity assessment under listed legislation.
Why it matters: It is distinct from the use cases in Annex III.
Annex III
Article 6(2) and Annex IIIListed sensitive uses in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes.
Why it matters: A listed area still requires analysis of the exact use and Article 6 conditions.
Prohibited AI practice
Article 5An AI practice prohibited by the Act, subject to the exact elements and exceptions in Article 5.
Why it matters: A screen should test the complete legal conditions rather than applying a simplified label.
Apply this in exposure checkTransparency obligation
Article 50Disclosure or marking requirements for specified AI interactions, synthetic outputs, emotion recognition, biometric categorisation or deepfakes.
Why it matters: The right control depends on actor, output, audience, timing and context.
Minimal or no-risk AI
Common explanatory termA common label for AI outside the prohibited, high-risk and specific transparency regimes.
Why it matters: It is not a universal exemption: AI literacy, data protection, consumer, employment and sector rules may still matter.
Risk and controls
6 terms
Risk
Article 3(2)The combination of the probability that harm occurs and the severity of that harm.
Why it matters: A risk record should identify harm, affected people, likelihood basis and severity—not only an unexplained rating.
Risk-management system
Article 9A continuous and iterative lifecycle process for identifying, analysing, evaluating and addressing risks for high-risk AI.
Why it matters: Testing, post-market information and material change should keep feeding the process.
Apply this in risk and incidentsData governance
Article 10Governance and management practices applied to training, validation and testing data for relevant high-risk AI.
Why it matters: Origin, preparation, assumptions, suitability, representativeness, errors, gaps and bias need use-specific consideration.
Accuracy, robustness and cybersecurity
Article 15Requirements for appropriate performance, resilience to errors or faults and resistance to relevant security threats.
Why it matters: Metrics and thresholds must be declared, tested and understood in the operating context.
Serious incident
Articles 3(49) and 73An incident or malfunction leading to specified severe outcomes including serious health harm, critical-infrastructure disruption, fundamental-rights infringement, or serious property or environmental harm.
Why it matters: Organisations need a broader incident process capable of recognising events that may reach this defined threshold.
Post-market monitoring
Articles 3(25) and 72Provider activities for collecting and reviewing experience after market placement or service to identify corrective or preventive action.
Why it matters: Operational data, complaints, incidents, performance and change should connect back to risk management.
Evidence and assurance
7 terms
Technical documentation
Article 11 and Annex IVDocumentation for a high-risk AI system intended to demonstrate compliance and enable authority assessment.
Why it matters: A generated draft remains a working file until gaps are completed and competent reviewers approve it.
Apply this in obligations and evidenceRecord-keeping and logs
Articles 12, 19 and 26(6)Capabilities and duties concerning automatic event recording and retention of logs under relevant provider or deployer control.
Why it matters: A governance audit trail is useful but is not the same as system-generated logging.
Quality-management system
Article 17Documented policies, procedures and instructions through which a high-risk provider addresses compliance across design, testing, change, records and post-market activity.
Why it matters: A policy is one element; the management system requires connected ownership and operating processes.
Conformity assessment
Articles 3(20) and 43The process for demonstrating whether a high-risk AI system meets Chapter III, Section 2 requirements.
Why it matters: It may involve internal control or a notified body and is not the same as a general readiness review.
EU declaration of conformity
Article 47 and Annex VThe provider's formal declaration that a high-risk AI system conforms with applicable requirements.
Why it matters: It is a regulated provider output, not a readiness badge an adviser can casually issue.
CE marking
Articles 3(24) and 48The marking through which a provider indicates conformity with relevant AI Act and harmonisation requirements.
Why it matters: A readiness report or specialist opinion must not be represented as CE marking or regulatory certification.
Independent review
Governance practiceA scoped review by a suitably qualified person separate from the original decision or delivery work.
Why it matters: Its value depends on credentials, independence, scope, sources and the stable record reviewed; it is not automatically certification.
Apply this in independent review
General-purpose AI
4 terms
General-purpose AI model (GPAI)
Article 3(63)A broadly capable model, typically trained at scale, able to perform many tasks and integrate into varied downstream systems.
Why it matters: A GPAI model and an AI system using it are different regulatory objects and may have different providers.
General-purpose AI system
Article 3(66)An AI system based on a GPAI model that can serve varied purposes directly or through integration.
Why it matters: Inventory should record both the system and its underlying model dependency.
High-impact capabilities
Article 3(64)Capabilities matching or exceeding those recorded in the most advanced GPAI models.
Why it matters: The concept contributes to identifying GPAI models with systemic risk.
Systemic risk
Articles 3(65) and 51Risk specific to high-impact GPAI capabilities that can significantly affect the EU market and propagate at scale.
Why it matters: This defined GPAI concept differs from informally describing an operational issue as systemic.
Biometrics and synthetic content
4 terms
Deepfake
Articles 3(60) and 50AI-generated or manipulated image, audio or video resembling real subjects or events and falsely appearing authentic or truthful.
Why it matters: The defined term is narrower than all synthetic media; disclosure depends on content and context.
Emotion-recognition system
Article 3(39)An AI system intended to identify or infer emotions or intentions from biometric data.
Why it matters: Certain uses are prohibited and others can carry transparency or high-risk implications.
Biometric categorisation system
Article 3(40)An AI system assigning people to categories on the basis of biometric data, subject to the definition's qualification.
Why it matters: This differs from identity verification; purpose and categories materially affect analysis.
Remote biometric identification
Article 3(41)–(43)Identification without active involvement, usually at a distance, by comparing biometric data with a reference database; real-time and post-remote forms are distinguished.
Why it matters: The form, actor and setting affect prohibition, authorisation, documentation and high-risk analysis.
Governance and enforcement
5 terms
AI Office
Articles 3(47) and 64The European Commission function contributing to implementation, monitoring and supervision of AI systems, GPAI models and EU AI governance.
Why it matters: It has particular GPAI responsibilities and supports consistent implementation.
Notified body
Article 3(22)A conformity-assessment body formally notified under the Act and relevant harmonisation legislation.
Why it matters: An independent adviser is not a notified body merely because they review an assessment.
EU database for high-risk AI systems
Articles 49 and 71The EU database supporting registration and transparency for specified high-risk systems and operator information.
Why it matters: Registration depends on role and category and should be checked against current implementation requirements.
Official source
Check the legal wording before relying on a definition.
The glossary paraphrases the Act for practical use. Amendments and implementation material may change the current position, so dated source review remains essential.