29 terms · Last updated 7 July 2026
EU AI Act glossary
The EU AI Act glossary is a plain-English reference for the 29 terms that appear most often when working with the Act - from provider and deployer through to Annex III, Article 50, GPAI, conformity assessment and the Digital Omnibus on AI. Each entry is self-contained and carries the underlying article reference.
Showing 29 of 29 terms
- AI systemArticle 3(1)
- An AI system under the EU AI Act is a machine-based system designed to operate with varying levels of autonomy that infers, from the input it receives, how to generate outputs such as predictions, recommendations or decisions influencing physical or virtual environments. The definition is aligned with the OECD's 2023 update.
- ProviderArticle 3(3)
- A provider is the natural or legal person that develops an AI system - or has one developed - and places it on the EU market or puts it into service under its own name or trademark, whether for payment or free of charge. Providers carry the AI Act's heaviest obligations.
- DeployerArticle 3(4)
- A deployer is any natural or legal person using an AI system under its own authority in the course of a professional activity. Deployers have lighter but real duties: human oversight, transparency to end-users, monitoring and, for high-risk systems, fundamental-rights impact assessments.
- ImporterArticle 3(6); Article 23
- An importer is a person established in the EU that places on the EU market an AI system bearing the name or trademark of a natural or legal person established outside the EU. Before making a high-risk system available, an importer must verify that the provider completed the conformity assessment, drew up the technical documentation, and affixed CE marking and contact details - and must keep that evidence available to authorities.
- DistributorArticle 3(7); Article 24
- A distributor is any person in the supply chain - other than the provider or importer - that makes an AI system available on the EU market. Distributors must check that a high-risk system carries CE marking, the EU declaration of conformity and instructions for use, must not supply a system they know to be non-conforming, and must ensure storage and transport do not compromise it.
- General-Purpose AI (GPAI)also: Foundation modelArticle 3(63); Chapter V
- A general-purpose AI model is trained on large amounts of data with self-supervision at scale, displays significant generality, and can be integrated into a wide range of downstream systems. GPT, Gemini, Claude, Mistral and Llama are examples. GPAI provider obligations have applied since 2 August 2025.
- GPAI with systemic riskArticle 51; Article 55
- A GPAI model is presumed to pose systemic risk when the cumulative compute used for its training exceeds 10^25 FLOPs, or when the Commission designates it. Providers must run model evaluations, adversarial testing, incident reporting, cybersecurity protection and post-market monitoring.
- High-risk AI systemArticle 6; Annex I & III
- A high-risk AI system is one used in a domain listed in Annex III (HR, credit, education, biometrics, essential services, law enforcement, migration, justice) or embedded as a safety component in a product covered by Annex I (medical devices, machinery, vehicles, toys). Full lifecycle risk management, technical documentation and human oversight are required.
- Annex IIIAnnex III
- Annex III lists the stand-alone use cases the AI Act treats as high-risk by default: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and justice. Obligations apply from 2 December 2027 following the Digital Omnibus deferral.
- Annex IAnnex I
- Annex I lists the EU harmonisation legislation whose products may contain safety-relevant AI components - for example medical devices, machinery, vehicles, toys, lifts and pressure equipment. High-risk obligations for embedded AI apply from 2 August 2028.
- Annex IVAnnex IV
- Annex IV specifies the technical documentation a provider of a high-risk AI system must keep and hand over to the notified body and market surveillance authorities. It covers system design, data governance, testing results, monitoring plans and post-market performance.
- Prohibited AI practicesArticle 5
- Article 5 bans specific AI uses that are considered unacceptable: social scoring, subliminal manipulation, exploitation of vulnerable groups, untargeted scraping of facial images, real-time public biometric identification (with narrow exceptions), and - from 2 December 2026 - AI-generated non-consensual intimate imagery and CSAM. Fines reach €35M or 7% of global turnover.
- Article 4 (AI competency)also: AI literacyArticle 4
- Article 4 requires providers and deployers to take appropriate measures to support AI literacy among their staff and anyone else operating or using AI on their behalf - in practice, they should support their staff to building up adequate AI competency. Regulation (EU) 2026/1744 changed this from guaranteeing a level of literacy into a duty to support its development, proportionate to the role and the systems in use.
- Article 50 (transparency)Article 50
- Article 50 imposes transparency duties on limited-risk AI: users must be told when they interact with a chatbot, AI-generated content must be marked, deepfakes disclosed, and emotion recognition or biometric categorisation notified to affected persons. These obligations have applied since 2 August 2026.
- Conformity assessmentArticle 43
- Conformity assessment is the process by which a provider demonstrates that a high-risk AI system meets the AI Act's technical requirements before placing it on the EU market. Depending on the system it is done through internal control (Annex VI) or by a notified body (Annex VII), and results in CE marking.
- CE markingArticle 48
- CE marking on a high-risk AI system indicates that the provider claims conformity with the AI Act and any other applicable EU harmonisation legislation. Without CE marking, the system may not be placed on the EU market.
- Notified bodyArticle 29–39
- A notified body is a conformity assessment organisation designated by an EU member state to carry out third-party assessments of high-risk AI systems under Annex VII. Their opinion is required for certain biometric systems and Annex I products.
- Post-market monitoringArticle 72
- Post-market monitoring is the systematic collection and review of data on how a high-risk AI system performs after it has been placed on the market. Providers must have a plan, act on the findings and update the technical documentation accordingly.
- Serious incidentArticle 73
- A serious incident is a malfunction of a high-risk AI system that leads directly or indirectly to death, serious health damage, serious and irreversible disruption of critical infrastructure, or breach of fundamental-rights obligations. Providers must notify the relevant market surveillance authority within 15 days.
- Fundamental Rights Impact Assessment (FRIA)Article 27
- A FRIA is a structured assessment public-sector deployers and certain private deployers of high-risk AI must perform before first use, documenting the affected persons, the context, the risks to fundamental rights, and the mitigation measures.
- AI OfficeArticle 64
- The AI Office is the European Commission's unit that supervises GPAI models, coordinates enforcement across member states, and issues guidance on the AI Act. It has been operational since 2 August 2025.
- AI BoardArticle 65–66
- The European Artificial Intelligence Board brings together national supervisory authorities and the AI Office. It coordinates enforcement, issues opinions and drives consistency across member states.
- Digital Omnibus on AIalso: Regulation (EU) 2026/1744Regulation (EU) 2026/1744
- The Digital Omnibus on AI is Regulation (EU) 2026/1744, the package that amended the AI Act. It was signed on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers Annex III obligations to 2 December 2027 and Annex I to 2 August 2028, reframes Article 4 as a duty to support AI competency, and adds a new Article 5 ban on AI-generated NCII/CSAM from 2 December 2026.
- Regulatory sandboxArticle 57
- An AI regulatory sandbox is a controlled environment set up by a national authority that allows providers to develop, train, test and validate innovative AI systems for a limited time under regulator supervision. Each member state must have one operational by 2 August 2027.
- Real-time remote biometric identificationArticle 5(1)(h)
- Real-time remote biometric identification is the automated identification of a person from biometric data at a distance and without significant delay. Its use in publicly accessible spaces for law-enforcement purposes is prohibited except in narrowly defined situations subject to judicial authorisation.
- Emotion recognitionArticle 5(1)(f); Article 50(3)
- An emotion recognition system infers emotions or intentions of natural persons from their biometric data. Its use in the workplace and in education is banned except for medical or safety reasons, and users must always be informed when it is in operation.
- Biometric categorisationArticle 5(1)(g); Article 50(3)
- A biometric categorisation system assigns persons to specific categories based on their biometric data. Categorisation to infer race, political opinions, trade-union membership, religious beliefs, sex life or sexual orientation is prohibited.
- DeepfakeArticle 50(4)
- A deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places or events and could falsely appear authentic. Deployers must disclose that the content has been artificially generated or manipulated.
- WatermarkingArticle 50(2)
- Watermarking under Article 50(2) is a machine-readable marking that outputs of an AI system are AI-generated. It has applied to new AI systems since 2 August 2026; the grace period for systems placed on the market before that date ends on 2 December 2026.
Ready to apply this in your organisation?
Take the free 15-20 minute readiness assessment and get a report that maps these terms to your actual AI use.
Start free assessment