AI governance glossary
Plain-language definitions of the terms that matter in AI governance and the EU AI Act. Where a term is defined in law, the definition follows the legal text and cites the article.
- AI literacy
- The skills and understanding providers and deployers must ensure their staff have to operate AI systems responsibly. Required since 2 February 2025.AI Act, Art. 4
- AI system
- A machine-based system designed to operate with varying levels of autonomy, which may adapt after deployment, and which infers from its input how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.AI Act, Art. 3(1)
- Audit chain
- An append-only record in which every entry contains the hash of the one before it and is digitally signed, so any later alteration of any entry is detected when the chain is verified.Read more
- Byzantine fault tolerance (BFT)
- A consensus property: a group of n participants reaches a correct decision even if up to f of them are faulty or adversarial, provided n ≥ 3f + 1. ICOSA applies it to a council of independent AI models, so no single model can decide a verdict.Read more
- Conformity assessment
- The process of demonstrating that a high-risk AI system meets the Act’s requirements before it is placed on the market, either by internal control or with a notified body.AI Act, Art. 43
- Deployer
- The person or organisation using an AI system under its authority in a professional capacity. Deployers of high-risk AI must follow its instructions, ensure human oversight and keep its logs.AI Act, Art. 3(4)
- Fundamental rights impact assessment (FRIA)
- An assessment of how a high-risk AI system may affect people’s fundamental rights, which certain deployers must complete before first use — public bodies, private entities providing public services, and deployers using AI for credit scoring or life and health insurance pricing.AI Act, Art. 27
- General-purpose AI model (GPAI)
- An AI model trained on large amounts of data that can competently perform a wide range of distinct tasks and be integrated into many downstream systems. GPAI providers have documentation and copyright obligations since 2 August 2025.AI Act, Art. 3(63)
- High-risk AI system
- An AI system that is a safety component of a product under EU harmonisation law (Annex I), or is used in an area listed in Annex III such as hiring, credit scoring, insurance pricing, education, critical infrastructure or law enforcement. It must meet the Act’s risk-management, data, documentation, oversight and accuracy requirements.AI Act, Art. 6 · Read more
- Human oversight
- Design measures that let the people using a high-risk AI system understand its output, recognise automation bias, and override or stop it.AI Act, Art. 14
- Model risk management
- The supervisory framework US banks use to validate, govern and monitor models, including AI and machine-learning models, so model errors do not cause financial or consumer harm.Federal Reserve SR 26-2 (replaced SR 11-7 in April 2026) · Read more
- Notified body
- An independent conformity assessment body designated by a Member State to assess high-risk AI systems where third-party assessment is required.AI Act, Art. 3(21)
- Post-market monitoring
- The provider’s ongoing collection and review of data on a high-risk AI system’s real-world performance, to catch problems after it is deployed.AI Act, Art. 72
- Pre-action gating
- Runtime AI governance that checks an AI agent’s proposed action against policy, and allows or blocks it, before the action executes — rather than logging it for review afterwards.Read more
- Prohibited AI practice
- An AI use banned outright in the EU since 2 February 2025, including social scoring, untargeted scraping of facial images, emotion recognition at work or school, and most real-time remote biometric identification by police in public spaces.AI Act, Art. 5
- Provider
- The person or organisation that develops an AI system or model, or has one developed, and places it on the market or puts it into service under its own name or trademark.AI Act, Art. 3(3)
- Safety component
- A component of a product or system that fulfils a safety function, whose failure could endanger the health or safety of people or property. AI used solely for assistance, performance optimisation or convenience is not a safety component.AI Act, Art. 3(14), as amended by Regulation (EU) 2026/1744
- Serious incident
- An AI malfunction leading to death or serious harm to health, serious and irreversible disruption of critical infrastructure, breach of fundamental-rights law, or serious harm to property or the environment. Providers must report it to authorities within set deadlines.AI Act, Art. 3(49) and Art. 73
- Technical documentation
- The file a provider must keep showing how a high-risk AI system was designed, trained, tested and validated, and how it meets each requirement.AI Act, Art. 11 and Annex IV
More on EU AI Act
- EU AI ActWhat the EU AI Act requires, which risk class your system falls in, the obligation dates as amended in 2026, and how to prove compliance.
- EU AI Act timelineEvery EU AI Act obligation date in one tracker, updated for Regulation (EU) 2026/1744: what applies now, what comes next, and the source for each.
- Example scorecardAn illustrative example of ICOSA’s multi-model assessment output against the EU AI Act, across common AI architecture classes.
- RemediationArticle-by-article remediation for EU AI Act gaps: risk management, data governance, documentation, human oversight and transparency.