AI System
A machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
Authorised Representative
A natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by the Regulation.
Affected Person
A natural person who is subject to or otherwise affected by the output of an AI system, including a decision, recommendation, or prediction made by the AI system concerning that person.
AI Regulatory Sandbox
A controlled environment established by a competent authority that offers providers and prospective providers of AI systems the possibility to develop, train, validate, and test AI systems under direct supervision, for a limited time and under limited conditions, before being placed on the market.
Accuracy
The requirement that high-risk AI systems achieve an appropriate level of accuracy in relation to their intended purpose, as specified in the technical documentation. Providers must declare the level of accuracy in the instructions for use.
AI Office
The body established within the European Commission under Article 64, responsible for supervising general-purpose AI models, overseeing the development and implementation of the Regulation, maintaining the EU AI database, and coordinating enforcement across Member States.
AESIA
Agencia Española de Supervisión de la Inteligencia Artificial — Spain's national supervisory authority for artificial intelligence, established in 2023. Designated as Spain's national competent authority under the EU AI Act. Employers must negotiate on AI use that affects working conditions under RDL 9/2021 through collective bargaining.
AI-Generated Content
Text, images, audio, or video produced by an AI system. Under Article 50, providers of AI systems that generate synthetic audio, image, video, or text content must ensure outputs are marked as artificially generated, using machine-readable formats where technically feasible.
AI Literacy
Skills, knowledge, and understanding that allow providers, deployers, and affected persons to make an informed deployment and use of AI systems and to gain an awareness of the opportunities and risks of AI — required under Article 4 as a universal obligation for all operators across all risk tiers.
Biometric Identification
The automated recognition of humans based on their biometric data for the purpose of identifying a natural person by comparing biometric data of that person to stored biometric data in a database.
Biometric Categorisation
The assignment of natural persons to specific categories on the basis of their biometric data, such as sex, age, hair colour, eye colour, tattoos, behavioural or personality traits, or any other characteristics. Inferring sensitive categories (race, political opinion, etc.) is prohibited under Article 5(1)(g).
Biometric Data
Personal data resulting from specific technical processing relating to the physical, physiological, or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data — a special category under GDPR Article 9.
Belgian CAO Stack
The set of Belgian collective labour agreements applicable to AI monitoring systems: CAO 9 (1972) — works council information rights; CAO 39 (1983) — protection against technology-driven dismissal; CAO 81 (2002) — protection of workers' online privacy; CAO 100 (2009) — policy on alcohol, drugs, and monitoring extended to AI surveillance. Administered by the Nationale Arbeidsraad (NAR).
Bundesnetzagentur
The German Federal Network Agency, designated as the national market surveillance authority for the EU AI Act in Germany. Works alongside the Federal Commissioner for Data Protection (BfDI). AI monitoring systems in German workplaces require co-determination with the Betriebsrat (works council) under BetrVG §87(1)(6).
Biometric Categorisation Disclosure
The obligation under Article 50(3) for deployers of biometric categorisation systems to inform the natural persons exposed to the system of its operation, separate from the Article 5 ban on sensitive biometric categorisation.
Conformity Assessment
The process of verifying whether a high-risk AI system complies with the requirements set out in Chapter III Section 2 of the Regulation. Can be conducted through internal control (Annex VI) or with involvement of a notified body (Annex VII).
CE Marking
The marking by which a provider indicates that a high-risk AI system is in conformity with the requirements set out in Chapter III Section 2 of the Regulation and other applicable Union harmonisation legislation that provides for its affixing. Required before placing a high-risk AI system on the EU market.
Common Specification
A set of technical and/or operational requirements adopted by the European Commission to address specific requirements of the Regulation where no harmonised standard exists or where harmonised standards fail to adequately cover the relevant requirements.
Cybersecurity
The requirement that high-risk AI systems are resilient against attempts by third parties to alter their use, behaviour, or performance in ways that could result in risks to health, safety, or fundamental rights, including protection against data poisoning, adversarial examples, and model evasion attacks.
Codes of Practice
Industry-developed codes developed under the facilitation of the AI Office, covering GPAI model provider obligations including intellectual property rights, transparency, data governance, and measures for models with systemic risk. Codes constitute a presumption of compliance when followed by GPAI model providers.
CNIL
Commission Nationale de l'Informatique et des Libertés — the French data protection authority responsible for overseeing AI and data processing in France. AI systems in French workplaces require prior consultation with employee representatives (CSE — Comité Social et Économique) and CNIL guidance must be followed for biometric and surveillance systems.
Deployer
A natural or legal person, public authority, agency, or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.
Distributor
A natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market.
Data Governance
Practices and policies applicable to training, validation, and testing data sets used for high-risk AI systems, covering the design choices, data collection, and preparation processes, and ensuring datasets are relevant, sufficiently representative, and free of errors and complete.
Deep Fake
AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, entities, or events and that falsely appears to a person to be authentic or truthful. Subject to mandatory disclosure obligations under Article 50(4).
Downstream Provider
A provider of an AI system that integrates a general-purpose AI model into its system. Article 25 allocates responsibilities between GPAI model providers and downstream providers, including obligations transferred through the model's technical documentation.
Deep Fake Disclosure
The mandatory obligation under Article 50(4) for deployers who use AI systems to generate or manipulate images, audio, or video constituting a deep fake to disclose that the content has been artificially generated or manipulated — unless the content is clearly labelled as AI-generated or for authorised law enforcement purposes.
Detection Tool
A regulatory detection instrument that identifies indicators of EU AI Act obligations, risk classifications, and documentation gaps — as distinct from a legal advice service or compliance certification authority. Detection tools operate under Article 86 information obligations and must clearly communicate the scope and limitations of their analysis.
Emotion Recognition
An AI system for the purpose of identifying or inferring emotions or intentions of natural persons based on their biometric data. Prohibited in professional contexts (workplace and education) under Article 5(1)(f); requires disclosure to individuals when used in other permitted contexts.
EU Declaration of Conformity
A statement made by the provider affirming that a high-risk AI system is in conformity with the provisions of the Regulation and all applicable Union legislation. Must include the information set out in Annex V.
EU Database for High-Risk AI Systems
A publicly accessible EU-wide database established and maintained by the European Commission, in which providers of high-risk AI systems listed in Annex III must register their systems before placing them on the market or putting them into service.
European AI Board
An independent advisory body established under Article 65, composed of one representative from each Member State's national competent authority. Advises the Commission and national authorities, issues opinions and recommendations, and coordinates consistent application of the Regulation.
Emotion Recognition Disclosure
The obligation under Article 50(3) for deployers of emotion recognition systems to inform the natural persons exposed to the system of its operation, with law-enforcement exceptions handled narrowly and separately.
General-Purpose AI Model
An AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications.
GPAI with Systemic Risk
A general-purpose AI model that poses systemic risk — designated as such based on cumulative compute threshold exceeding 10²⁵ FLOPs for training, or designated by the AI Office following a case-by-case assessment based on capabilities. Subject to enhanced obligations including adversarial testing, incident reporting, and cybersecurity measures.
GPAI Transparency Obligations
Requirements under Article 53 applicable to all GPAI model providers: drawing up and keeping up-to-date technical documentation; providing technical documentation and instructions for use to downstream providers; establishing a policy respecting EU copyright law; and publishing a sufficiently detailed summary about training data.
Garante per la Protezione dei Dati
Italy's data protection authority (DPA), which also acts as a primary oversight body for AI systems involving personal data processing. Remote monitoring of workers in Italy requires INL (National Labour Inspectorate) authorisation or collective agreement under Statuto dei Lavoratori Article 4.
High-Risk AI System
An AI system that poses significant risks to health, safety, or fundamental rights, as listed in Annex III (e.g. biometric systems, critical infrastructure management, educational assessment, employment tools, essential services, law enforcement, migration and border control, administration of justice) or embedded as a safety component in products covered by Annex I.
Harmonised Standard
A European standard developed by a recognised European standardisation organisation (CEN, CENELEC, or ETSI) upon request from the European Commission, compliance with which creates a presumption of conformity with the corresponding requirements of the Regulation.
Human Oversight
Measures built into high-risk AI systems enabling natural persons to understand, monitor, and — where necessary — override or shut down the system. Must be proportionate to the risks and must ensure that deployers can intervene in the system's output before it takes effect.
Intended Purpose
The use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the instructions for use, promotional or sales materials, and statements, as well as in the technical documentation.
Importer
A natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country.
Instructions for Use
Information provided by the provider of a high-risk AI system to inform deployers about the system's intended purpose, performance characteristics, limitations, maintenance requirements, human oversight mechanisms, and the technical measures needed to ensure the system can be effectively overseen by natural persons.
Input Data
Data provided to or directly acquired by an AI system on the basis of which the system produces an output.
Limited Risk AI
AI systems whose primary EU AI Act duties are Article 50 transparency obligations. Article 50 can also apply as an independent transparency layer beside high-risk, GPAI, or prohibited classifications.
Logging Capabilities
The automatic recording of events by a high-risk AI system during its operation — required under Article 12 to enable monitoring of its operation, post-hoc investigation of incidents, and to support the post-market monitoring obligations of providers and deployers.
Minimal Risk AI
AI systems that present negligible risk and are not subject to any mandatory requirements under the Regulation. The vast majority of AI applications currently in use, such as AI-enabled spam filters, belong to this category.
Market Surveillance Authority
The national authority responsible for market surveillance activities under the Regulation, including investigating complaints, conducting inspections, accessing documentation, ordering corrective actions, and notifying serious incidents to the AI Office.
Model Evaluation
Systematic assessment of a GPAI model's capabilities and limitations, including standardised protocols and tools for evaluating adversarial robustness, model alignment, and potential systemic risks. Providers of GPAI models with systemic risk must conduct state-of-the-art model evaluations before deployment and on a regular basis.
Notified Body
A conformity assessment body that has been notified by a Member State to the European Commission as being authorised to carry out third-party conformity assessment activities for high-risk AI systems as specified in Annex VII.
National Competent Authority
The authority or authorities designated by each Member State to supervise the application and implementation of the Regulation, act as market surveillance authority for AI systems placed on the market, and serve as the notifying authority for notified bodies.
Placing on Market
The first making available of an AI system or a general-purpose AI model on the Union market, in the course of a commercial activity, whether for payment or free of charge.
Putting into Service
The supply of an AI system for first use directly to the deployer or for own use on the Union market for its intended purpose.
Provider
A natural or legal person, public authority, agency, or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.
Prohibited AI Practices
AI systems and uses explicitly banned by Article 5, including AI that deploys subliminal or manipulative techniques, exploits vulnerabilities, performs real-time remote biometric identification in public spaces for law enforcement (with limited exceptions), conducts social scoring by public authorities, and infers sensitive attributes from biometric data.
Post Remote Biometric Identification
Remote biometric identification carried out with a significant delay — i.e. after the biometric data has been captured — used in retrospective investigations by law enforcement, subject to specific conditions and prior judicial or administrative authorisation.
Post-Market Monitoring
Proactive collection and review of experience gained from the use of high-risk AI systems, to identify any need for corrective or preventive actions and ensure continued compliance throughout the system lifecycle.
Penalties and Fines
Administrative fines applicable under Article 99: up to €35 million or 7% of total worldwide annual turnover for violations of prohibited AI practices; up to €15 million or 3% for non-compliance with other obligations; up to €7.5 million or 1.5% for supplying incorrect information to authorities.
Risk-Based Approach
The overarching regulatory framework of the EU AI Act that categorises AI systems by the level of risk they pose — prohibited, high-risk, limited-risk, and minimal-risk — and imposes proportionate obligations accordingly.
Reasonably Foreseeable Misuse
The use of an AI system in a way that is not in accordance with its intended purpose, but that may result from reasonably foreseeable human behaviour or interaction with other systems, including AI systems.
Remote Biometric Identification
The automated recognition of humans at a distance through the comparison of a person's biometric data with the biometric data contained in a reference database, and without prior knowledge of the user of the AI system and regardless of the particular technology, processes, or types of biometric data used.
Real-Time Remote Biometric Identification
Remote biometric identification where the capturing of biometric data, the comparison, and the identification all occur without a significant delay — prohibited in publicly accessible spaces for law enforcement purposes under Article 5(1)(h), subject to limited exceptions.
Risk Management System
A continuous iterative process that must be established, implemented, documented, and maintained by providers of high-risk AI systems throughout the entire lifecycle. Must include identification and analysis of known and reasonably foreseeable risks, estimation of risks that may emerge from misuse, and evaluation of residual risks.
Robustness
The ability of a high-risk AI system to maintain its level of performance under adverse conditions — including technical limitations, adversarial inputs, errors, or unexpected situations — or within foreseeable operating conditions outside the intended purpose.
Right to Explanation
The right under Article 86 of affected persons to obtain an explanation of the role of the AI system in a decision-making procedure and the main elements of the decision taken in their individual case, where a high-risk AI system has been used to make a decision that significantly affects them.
Right to Lodge a Complaint
The right of any natural or legal person to lodge a complaint with the relevant national competent authority regarding non-compliance with the Regulation, and to receive a reply within a reasonable time. Market surveillance authorities must investigate complaints substantiated by sufficient evidence.
Safety Component
A component of a product or of a system that fulfils a safety function for that product or system, or the failure or malfunctioning of which endangers the health and safety of persons or property.
Substantial Modification
A change to an AI system after its placing on the market or putting into service that affects the compliance of the AI system with this Regulation or results in a modification to the intended purpose for which the AI system has been assessed.
Social Scoring
The evaluation or classification of natural persons or groups of persons over a period of time based on their social behaviour or known, inferred, or predicted personal or personality characteristics, with a social score that leads to detrimental or unfavourable treatment — prohibited under Article 5(1)(c) when carried out by public authorities.
Subliminal Techniques
AI techniques that operate below the threshold of human consciousness or use manipulative methods that exploit psychological weaknesses or biases to distort a person's behaviour in ways that may cause significant harm — prohibited under Article 5(1)(a).
Scientific Panel of Independent Experts
A panel established under Article 68 to support the AI Office in the enforcement of obligations applicable to general-purpose AI models with systemic risk. Provides technical expertise, evaluates model evaluations, and can alert the AI Office to systemic risks.
Serious Incident
An incident or malfunction of a high-risk AI system that directly or indirectly leads to the death of a person or serious damage to a person's health, a serious and irreversible disruption of the management of critical infrastructure, a breach of obligations under Union law protecting fundamental rights, or serious damage to property or the environment.
Systemic Risk
A risk that is specific to the high-impact capabilities of general-purpose AI models — having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or society at large.
Technical Documentation
The documentation that providers of high-risk AI systems must draw up before placing the system on the market, containing all necessary information to assess compliance with the Regulation, including a general description, design specifications, training data information, risk management records, and performance metrics. Content requirements are set out in Annex IV.
Transparency Requirements
Obligations under Article 13 requiring that high-risk AI systems are designed to ensure that their operation is sufficiently transparent to enable deployers to interpret the system's output and use it appropriately, and under Article 50 for specific systems (chatbots, synthetic content) to notify persons they are interacting with AI.
Training Data
Data used for training an AI system through fitting its learnable parameters, including the weights of a neural network, to ensure the system can produce the outputs corresponding to its intended purpose.
Testing Data
Data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service.