EU AI Act Glossary: Every Term You Need to Know

SEO & GEO for WordPress websites

The EU AI Act introduced a dense layer of legal terminology that many businesses are still working through. Terms like “deployer,” “substantial modification,” and “systemic risk” carry precise legal meanings that determine your compliance obligations, and getting them wrong can be costly. This EU AI Act glossary covers every core definition you need, organized by topic so you can find what matters to your situation quickly.

The Act (Regulation (EU) 2024/1689) was published in the Official Journal of the European Union on 12 July 2024 and applies in phases through to 2030. Its obligations fall differently depending on whether you develop AI, deploy it, or both. Understanding the terminology is the first step to understanding where you stand.

How the EU AI Act classifies AI systems

The EU AI Act uses a risk-based framework to classify AI systems into four tiers, each carrying different compliance obligations. The higher the potential harm, the heavier the regulatory burden.

The four risk tiers

Unacceptable-risk systems are prohibited outright. This category covers practices like subliminal manipulation, social scoring by public authorities, and real-time remote biometric identification in public spaces by law enforcement. These prohibitions became enforceable on 2 February 2025.

High-risk systems face the most extensive obligations, covering everything from conformity assessments to post-market monitoring. Most of the Act’s text is dedicated to this tier. Limited-risk systems, such as chatbots and deepfake generators, face lighter transparency obligations: users must be told they are interacting with AI. Minimal-risk systems, including spam filters and AI-enabled video games, face no mandatory compliance requirements.

What counts as an “AI system”

Article 3(1) defines an AI system as a machine-based system designed to operate with varying levels of autonomy, may exhibit adaptiveness after deployment, and infers from its inputs how to generate outputs such as predictions, content, recommendations, or decisions capable of influencing physical or virtual environments. This definition deliberately aligns with the OECD Recommendation on AI and is technology-neutral.

A simple if-then logic tree without any learning capability likely falls outside this definition. A rule-based system with adaptive components may qualify. When a system could fall into more than one risk tier, the highest applicable classification applies to the whole system.

Core definitions every compliance team must understand

Article 3 of the Act contains the foundational definitions that anchor every other obligation in the regulation. These terms determine who must comply, with what, and when.

Provider and deployer

A provider (Article 3(3)) is any natural or legal person, public authority, agency, or other body that develops an AI system or general-purpose AI model and places it on the market or puts it into service under its own name or trademark. This includes both in-house development and outsourced development where the commissioning entity takes responsibility for the output.

A deployer (Article 3(4)) is any natural or legal person, public authority, agency, or other body that uses an AI system in a professional capacity. Personal, non-professional use is excluded. Deployers carry fewer obligations than providers, but they are not exempt from the Act, particularly when deploying high-risk systems.

Operator, intended purpose, and reasonably foreseeable misuse

Operator (Article 3(8)) is a collective term that encompasses providers, product manufacturers, deployers, authorised representatives, importers, and distributors. The same entity can simultaneously hold more than one of these roles.

Intended purpose (Article 3(12)) is the use for which an AI system is intended by the provider, as specified in instructions for use, promotional materials, and technical documentation. Risk classification and applicable requirements are anchored to this definition, so how a provider describes a system matters legally.

Reasonably foreseeable misuse (Article 3(13)) covers use that is not in accordance with the intended purpose but may result from reasonably foreseeable human behaviour or interaction with other systems. Providers must factor this into their risk assessments.

Substantial modification, conformity assessment, and notified body

Substantial modification (Article 3(23)) is a change to an AI system after it has been placed on the market or put into service that was not anticipated in the original conformity assessment and may affect compliance with the Act. A substantial modification triggers re-entry into provider obligations, meaning the compliance process restarts.

A conformity assessment (Article 3(20)) is the process of demonstrating that a high-risk AI system meets the requirements set out in Chapter III, Section 2. A notified body (Article 3(22)) is an accredited third-party assessment body designated to perform conformity assessments where self-assessment is not permitted, such as for biometric identification systems.

High-risk AI: key terms and scope explained

High-risk classification is the threshold that activates the Act’s most demanding obligations. Understanding exactly what triggers it, and what it requires, is central to EU AI Act compliance.

Two routes to high-risk classification under Article 6

Article 6 defines two independent routes to high-risk status. The first applies when an AI system is a safety component of, or is itself, a product covered by EU harmonisation legislation listed in Annex I (such as machinery, medical devices, or aviation equipment). The second applies when a system falls into one of the eight use-case areas listed in Annex III.

Those Annex III areas are: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice and democratic processes. Any AI system operating in one of these areas inherits the full obligation set under Articles 9, 12, 13, 14, and 26.

Key compliance terms for high-risk systems

A declaration of conformity is the formal document signed by the provider confirming that the high-risk AI system meets all applicable requirements of the Act. It is the legal basis for affixing CE marking. For systems provided digitally, a digital CE marking is used where it can be easily accessed via the interface or via a machine-readable code.

A Fundamental Rights Impact Assessment (FRIA), required under Article 27, is a systematic evaluation of the potential impact of a high-risk AI system on individuals’ fundamental rights. It is mandatory for certain deployers, including public sector bodies and deployers in areas such as credit scoring and insurance, before deployment begins.

Post-market monitoring (Article 72) requires providers to actively and systematically collect, document, and analyse data on performance throughout the system’s operational lifetime. A serious incident (Article 3(49)) is defined as an incident or malfunction that directly or indirectly leads to death, serious harm to health, or serious and irreversible disruption of critical infrastructure. Serious incidents must be reported to the relevant authority.

GPAI models and frontier AI terminology

General-purpose AI models, or GPAI models, introduced a distinct regulatory category within the Act. These are models trained on vast amounts of data that can perform a wide range of tasks, and they carry their own obligations separate from the high-risk framework.

What is a GPAI model

Article 3(63) defines a general-purpose AI model as an AI model trained with a large amount of data using self-supervision at scale, displaying significant generality, and capable of competently performing a wide range of distinct tasks. Models like GPT-4, Claude, and Gemini fall into this category. The European Commission’s July 2025 guidelines use a training compute threshold of 10²³ FLOPs as a presumptive indicator of GPAI status.

Systemic risk and the 10²⁵ FLOPs threshold

Under Article 51(2), a GPAI model is presumed to present systemic risk if its cumulative training compute exceeds 10²⁵ FLOPs. The Commission can also designate a model as presenting systemic risk based on Annex XIII criteria, including number of parameters, quality and quantity of training data, and number of users. Providers must notify the Commission within two weeks of reasonably foreseeing or reaching this threshold.

Systemic-risk GPAI models face additional obligations under Article 55 beyond the baseline Article 53 requirements. These include adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting to the AI Office, and cybersecurity measures.

Baseline GPAI obligations and the Code of Practice

Every GPAI provider, regardless of systemic risk status, must maintain technical documentation under Annex XI, provide downstream-provider documentation under Annex XII, maintain a copyright compliance policy, and publish a training-data summary. Open-source GPAI models benefit from reduced obligations under Article 53(2), but this exemption does not apply to models that present systemic risk.

The GPAI Code of Practice was finalized by the European AI Office on 10 July 2025 after four drafting rounds involving more than 1,000 stakeholders. It is not legally binding, but signatories receive increased trust and reduced enforcement scrutiny. Non-signatories must demonstrate compliance through other adequate means.

Governance and enforcement vocabulary

The Act created a layered governance structure with distinct bodies at EU and national level. Knowing who enforces what, and the penalty structure behind it, is essential context for any compliance programme.

The AI Office, the AI Board, and national competent authorities

The AI Office, established within the European Commission, oversees implementation of the Act across EU Member States and holds exclusive competence for enforcing obligations on GPAI model providers. It also acts as market surveillance authority for AI systems based on a GPAI model where both the model and the system are developed by the same provider.

The governance structure also includes the European Artificial Intelligence Board (composed of EU Member State representatives), the Scientific Panel (independent AI experts), and the Advisory Forum (diverse commercial and non-commercial stakeholders). Each Member State must designate at least one national competent authority (Article 3(48)), which encompasses both a notifying authority and a market surveillance authority.

Penalty tiers under Article 99

Article 99 establishes three administrative fine tiers. Violations of Article 5 prohibited practices carry fines of up to €35 million or 7% of global annual turnover. Most other operator obligation violations carry fines of up to €15 million or 3%. Supplying incorrect or misleading information to authorities carries fines of up to €7.5 million or 1%. For larger undertakings, the higher of the fixed amount or percentage applies. For SMEs and start-ups, the lower applies.

AI regulatory sandbox

An AI regulatory sandbox is a controlled environment where AI providers can develop, test, and validate innovative systems under the supervision of a competent authority before market deployment. Access is free for SMEs and start-ups, and Member States must have at least one operational sandbox by 2 August 2026. The knowledge base confirms that personal data can be used within a sandbox for public-interest AI development, provided it remains separate, secure, and is deleted once the project concludes.

Transparency and human oversight terms

The Act dedicates specific provisions to ensuring that AI systems are understandable to the people they affect. These terms define the boundaries of those obligations.

Human oversight under Article 14

Article 14 requires that high-risk AI systems be designed so that humans can effectively oversee them throughout their operation. The goal is to prevent or minimise risks to health, safety, or fundamental rights. Oversight measures must match the risks and context of use and can be built into the system by the provider or implemented operationally by the deployer.

Transparency obligations under Article 50

Article 50 establishes transparency obligations for providers and deployers of certain AI systems, applicable from 2 August 2026. It covers four scenarios: AI systems interacting directly with natural persons, systems generating synthetic audio, image, video, or text, emotion recognition and biometric categorisation systems, and systems generating or manipulating deepfake content or text published for public information purposes.

Under Article 50(1), providers of AI systems designed to interact directly with natural persons must ensure users are informed clearly and without ambiguity that they are interacting with an AI system. Deployers of AI systems that generate text published to inform the public on matters of public interest must disclose that the content has been artificially generated or manipulated, with narrow exceptions for law enforcement and content that has undergone human editorial review.

Logging and the oversight architecture

Article 12 requires automatic logging for high-risk AI systems. Article 26 places monitoring and log-keeping obligations on deployers. Together with Article 14 (human oversight) and Article 72 (post-market monitoring), these four provisions form the Act’s oversight architecture for high-risk systems. The AI literacy obligation under Article 4, in force since 2 February 2025, requires providers and deployers to ensure a sufficient level of AI literacy among staff who operate or use AI systems on their behalf.

EU AI Act timeline and transitional terminology

The Act does not apply as a single block. Its obligations rolled out in phases, and recent legislative changes have shifted some deadlines. Getting the timeline right matters because different terms become legally operative at different points.

The three main application phases

The Act entered into force on 1 August 2024. Phase 1 (2 February 2025) made Article 5 prohibited AI practices enforceable and activated the Article 4 AI literacy obligation. Phase 2 (2 August 2025) brought GPAI model obligations under Articles 51 to 56 into application, along with the Article 99 penalty regime for new models placed on the market.

Phase 3 centres on 2 August 2026, when Article 50 transparency obligations apply to new systems. However, the Digital Omnibus, adopted by the Council on 29 June 2026, defers most high-risk AI obligations for Annex III stand-alone systems from August 2026 to 2 December 2027. Annex I embedded systems face a revised deadline of 2 August 2028. The revised deadlines take legal effect upon Official Journal publication of the Digital Omnibus, which was pending confirmation as of the research date for this article.

Legacy system and GPAI transitional terms

Providers of GPAI models placed on the market before 2 August 2025 have until 2 August 2027 to bring those models into compliance with GPAI obligations. AI systems that are components of large-scale IT systems listed in Annex X and placed on the market before 2 August 2027 must reach compliance by 31 December 2030.

Two terms are worth knowing in this context. “Placing on the market” refers to the first making available of an AI system on the EU market. “Putting into service” refers to the first supply of an AI system for use in the EU by a deployer or for the provider’s own use. Both trigger compliance obligations, and the distinction matters for systems that are developed internally and never sold commercially.

Keeping pace with these shifting deadlines, while also managing the technical documentation, risk assessments, and ongoing monitoring the Act demands, is a significant operational challenge for most businesses. If your team is also producing the content needed to stay visible in search and generative AI platforms, scaling content output efficiently becomes equally important. The compliance burden does not reduce the need for organic growth; it makes efficient, well-structured content production more valuable, not less.

This content was generated with the help of AI and it may contain mistakes

Your customers are asking AI. Are you part of the answer?

In a quick demo, we show how WP SEO AI tracks your AI visibility, finds content gaps, and helps your website appear in ChatGPT, Google AI Overviews and more.

Dive deeper in