Glossary

The AI Act, term by term.

Plain-language definitions of the concepts that decide your obligations. Reference material, not legal advice.

AI system (Art. 3)
A machine-based system operating with some autonomy that infers, from inputs, how to generate outputs — predictions, content, recommendations or decisions — that can influence physical or virtual environments.
Provider
An entity that develops an AI system or model, or has it developed, and places it on the market under its own name or trademark. Carries the bulk of obligations for high-risk systems.
Deployer
An entity using an AI system under its own authority in a professional capacity. Lighter obligations than a provider, centred on use, oversight and information.
High-risk system
A system falling under Annex I (a safety component of a regulated product) or Annex III (a listed sensitive use case), subject to substantial obligations.
Annex I / Annex III
Two lists in the Regulation: Annex I covers Union product-safety legislation; Annex III lists the eight high-risk use-case areas.
Article 6(3) filter
A derogation by which an Annex III system may not be high-risk if it poses no significant risk — but never where it performs profiling of natural persons.
Prohibited practices (Art. 5)
Eight AI practices banned outright, in force since 2 February 2025 (e.g. social scoring, untargeted facial-image scraping).
Transparency obligations (Art. 50)
Four distinct duties to disclose AI interaction, mark synthetic content, reveal deepfakes, and notify emotion-recognition / biometric use.
General-purpose AI (GPAI)
A broadly capable foundation model, governed by its own regime (Arts. 51–55).
Systemic risk
A Union-level risk attributed to the most capable GPAI models, presumed above a training-compute threshold of 10²⁵ FLOP.
Conformity assessment
The procedure, by internal control or via a notified body, by which a high-risk system is shown to meet the requirements before market placement (Art. 43).
Notified body
An independent conformity-assessment body designated by a national notifying authority.
Presumption of conformity
The effect by which complying with a harmonised standard cited in the Official Journal is presumed to satisfy the corresponding legal requirement.
FRIA
Fundamental-rights impact assessment, required of certain deployers of Annex III systems (Art. 27).
EU database (Art. 71)
A public database, maintained by the Commission, in which high-risk systems (and those relying on the Art. 6(3) filter) are registered.
Serious incident (Art. 73)
An incident or malfunction leading to death or serious harm, critical-infrastructure disruption, a fundamental-rights infringement, or serious harm to property or the environment — with graduated reporting deadlines.
AI Office
The Commission body (in DG CNECT) that supervises general-purpose AI models across the Union and facilitates codes of practice.
Market-surveillance authority
A national authority responsible for enforcing the Act in its territory, receiving incident reports and handling complaints.

Definitions are simplified for orientation. The authoritative source is Regulation (EU) 2024/1689 (Official Journal, 12 July 2024).