Glossary
All 68 defined terms from Article 3, in plain language. The legal definition is always one click away on EUR-Lex — what you read here is our original translation, not the statute.
A machine-based system that operates with some degree of autonomy and may keep changing after deployment. Pursuing stated or implied objectives, it works out from the input it receives what outputs to produce: predictions, content, recommendations or decisions that can affect physical or virtual surroundings.
How much potential harm something carries, judged by combining two things: how likely the harm is to occur and how severe it would be if it did.
The party that builds an AI system or general-purpose model—or pays to have one built—and then releases it or puts it into use under its own name or brand. Applies whether the offering is paid or free.
Any organisation or person using an AI system under their own authority, for example a firm running a hiring tool. Purely personal, non-professional use falls outside this role.
A person or company in the EU that a provider of an AI system or general-purpose model has given a written mandate to, and that has accepted it, so as to handle the Act's obligations and procedures on the provider's behalf.
An EU-based business that places on the market an AI system carrying the name or brand of a company established outside the EU.
Any party in the supply chain—other than the provider or importer—that makes an AI system available on the EU market, such as a reseller.
An umbrella label covering everyone with a defined role around an AI system: providers, product manufacturers, deployers, authorised representatives, importers and distributors.
The moment an AI system or general-purpose model is first made available on the EU market—its debut, not each later copy or sale.
Supplying an AI system or general-purpose model for distribution or use on the EU market as part of commercial activity, whether charged for or given away.
Supplying an AI system for its first use in the EU—handed directly to the deployer, or used by the provider itself—for the purpose it was designed to serve.
The specific use a provider designs a system for, including the context and conditions of use, as described in its instructions, marketing materials and technical documentation.
Use that departs from what a system was designed for, yet could be predicted from normal human behaviour or from how the system interacts with other systems.
A part of a product or AI system that performs a safety function, or whose failure would put people's health, safety or property at risk.
The information a provider gives the deployer explaining what a system is for and how to operate it correctly.
Steps taken to bring an AI system already in deployers' hands back to the provider, or to take it out of service or disable it.
Steps taken to stop an AI system still in the supply chain from reaching the market, before it gets into users' hands.
How well a system does the job it was built to do—its ability to achieve its intended purpose.
The national authority that sets up and runs the procedures for assessing, designating and notifying conformity assessment bodies, and that keeps those bodies under ongoing monitoring.
The process of showing whether a high-risk AI system satisfies the requirements set out in Chapter III, Section 2 of the Act.
A body that carries out conformity assessment work as an independent third party, including testing, certification and inspection.
A conformity assessment body that has been notified under the AI Act and the other relevant EU harmonisation legislation, and so is recognised to perform those third-party assessments.
A change to an AI system after it reaches the market or enters service that the provider did not foresee or plan in the original conformity assessment, and that either affects compliance with Chapter III, Section 2 or alters the intended purpose already assessed.
The mark a provider affixes to signal that an AI system conforms with the requirements in Chapter III, Section 2 and with any other EU harmonisation law that calls for the mark.
Everything providers do to collect and review real-world experience with the systems they have placed on the market or put into service, so that any corrective or preventive action can be identified and taken immediately.
The national authority that carries out the activities and takes the measures required under the EU market surveillance regulation, Regulation (EU) 2019/1020.
A standard adopted at EU level, taking the meaning given in the EU standardisation regulation. Article 3 only borrows that definition; what follows from applying such a standard is dealt with elsewhere in the Act.
A set of technical specifications, in the sense used by the EU standardisation regulation, that provides a way of meeting particular requirements imposed by the Act.
Data used to train an AI system by fitting the parameters it learns during training.
Data used to evaluate the trained AI system and to tune the parameters it does not learn, along with the learning process itself—helping guard against underfitting and overfitting.
The data set that supplies validation data. It may be a stand-alone set or a slice of the training set, and the split can be fixed or varied.
Data used to evaluate an AI system independently, confirming it performs as expected before it is placed on the market or put into service.
Data given to an AI system, or picked up directly by it, that the system works from to produce an output.
Personal data about a person's physical, physiological or behavioural traits—such as a face image or fingerprint—produced by technical processing.
Automated recognition of a person's physical, physiological, behavioural or psychological features in order to establish who they are, by comparing their biometric data against biometric data held in a database.
Automated one-to-one checking—authentication included—that a person is who they claim to be, comparing their biometric data with biometric data supplied earlier.
The sensitive data categories singled out by EU data protection law—the GDPR, the law enforcement directive and the EU institutions regulation—covering matters such as ethnic origin, political opinions, health and sexual orientation.
Operational data tied to preventing, detecting, investigating or prosecuting criminal offences, where disclosure could jeopardise the integrity of criminal proceedings.
An AI system that identifies or infers people's emotions or intentions from their biometric data, such as reading a face or voice.
An AI system that places people into particular categories using their biometric data. It falls outside the definition only where the categorisation is ancillary to another commercial service and strictly necessary for objective technical reasons.
An AI system that identifies people without their active involvement, usually at a distance, by comparing a person's biometric data with data held in a reference database.
Remote biometric identification in which capture, comparison and identification all happen without significant delay. Short lags remain covered, so that small deliberate delays cannot be used to sidestep the rules.
Any remote biometric identification system that is not real-time. The Act defines it purely by exclusion, so identification performed after a significant delay falls into this category.
Any physical place, publicly or privately owned, that an undetermined number of people can enter. Conditions on access or limits on capacity do not change that.
A public authority competent to prevent, investigate, detect or prosecute criminal offences or to execute criminal penalties, including guarding against threats to public security—or another body given those public powers under national law.
Work carried out by law enforcement authorities, or by others on their behalf, to prevent, investigate, detect or prosecute criminal offences, to execute criminal penalties, and to guard against threats to public security.
Not a separate agency: a Commission function, created by a January 2024 Commission decision, that contributes to implementing, monitoring and supervising AI systems, general-purpose AI models and AI governance. References to it count as references to the Commission.
Either a notifying authority or a market surveillance authority. Where an AI system is put into service or used by an EU institution or body, the European Data Protection Supervisor stands in that role.
An incident or malfunction of an AI system leading, directly or indirectly, to death or serious harm to health; serious, irreversible disruption to critical infrastructure; breach of EU law obligations protecting fundamental rights; or serious harm to property or the environment.
Any information relating to an identified or identifiable person, as defined under EU data-protection law.
Any data that is not personal data—information that does not relate to an identified or identifiable individual.
Automated processing of personal data to evaluate or predict aspects of a person, such as their performance, health, preferences, behaviour or location.
A document setting out the aims and methodology of a real-world test, together with its geographic, population and time scope, and how the test will be monitored, organised and conducted.
A document the participating provider and the competent authority agree on, covering the objectives, conditions, timeframe, methodology and requirements for the activities carried out inside the sandbox.
A controlled framework a competent authority sets up so providers, actual or prospective, can develop, train, validate and test an innovative AI system for a limited period under supervision, following a sandbox plan and, where appropriate, in real-world conditions.
The skills, knowledge and understanding that let providers, deployers and affected people make informed decisions about deploying AI systems, and stay aware of the opportunities, risks and possible harm—read against their own rights and obligations.
Temporary testing of an AI system for its intended purpose outside a lab or simulated setting, to gather solid data and verify conformity. Where the conditions in Article 57 or 60 are met, it counts as neither placing on the market nor putting into service.
A person who takes part in a real-world test of an AI system.
A subject's freely given, specific, unambiguous and voluntary agreement to join a particular real-world test, expressed after being told everything about the test that bears on that decision.
AI-generated or AI-manipulated image, audio or video that resembles real people, objects, places, entities or events, and that would strike someone as authentic or truthful when it is not.
An act or omission breaching EU law that protects individuals' interests, where it harms collective interests in at least two Member States beyond the one it originated in, or where the same operator causes comparable harm concurrently in at least three.
Essential assets and services—such as energy, water and transport—as defined in EU critical-entity resilience law, whose disruption would seriously affect society.
An AI model, often trained on very large data volumes using self-supervision at scale, that shows broad generality, performs many distinct tasks competently and can be built into varied downstream systems. Models used for research, development or prototyping before market release are excluded.
Capabilities level with, or beyond, the highest capabilities recorded in the most advanced general-purpose AI models. The benchmark is the current frontier, so it shifts as leading models improve.
A risk arising specifically from those high-impact capabilities: one weighing significantly on the EU market because of a model's reach, or through actual or foreseeable damage to public health, safety, security, fundamental rights or society, spreading at scale down the value chain.
An AI system built on a general-purpose model that, thanks to that model, can serve many different purposes both on its own and inside other systems.
A single arithmetic step or assignment on floating-point numbers—the way computers approximate real numbers, as a fixed-precision integer scaled by an exponent over a fixed base. Counting them measures training compute; the systemic-risk threshold sits in Article 51, not here.
A provider of an AI system—a general-purpose AI system included—that has an AI model built into it. It makes no difference whether the model is the provider's own or comes from another firm under contract.