● AI Governance Section

AI Governance Vocabulary

281 terms used across AI governance, law and practice — each one in plain language, with a pointer back to where it's taught in the source course. Type to filter, or jump straight to a letter.

281 terms

A

ACA Section 1557
The Affordable Care Act's nondiscrimination provision: bars discrimination in federally funded health programs and activities, and is applied to require covered entities to identify and address biased impacts of AI tools. [II.B.2]
Acceptable use
Defined boundaries for how the deployed system may and may not be used. [IV.C.1]
Acceptable use policy
Rules governing how staff may use third-party AI tools, including data they may input. [I.B.3; I.C.3]
Accountability
Identifiable people and processes are answerable for the system's outcomes. [I.A.4]
Accountable owner
The single named person answerable for a given AI system or decision. [I.B.1]
Administrative fine
A monetary penalty scaled to the severity of the breach and the firm's turnover. [II.C.5]
Adverse impact ratio
A fairness metric comparing a protected group's selection/advancement rate to a reference group's; a ratio below the accepted threshold (e.g. the four-fifths rule) signals potential disparate impact. [III.B.3]
Agentic architecture
Systems where AI plans and takes actions with tools, increasing autonomy and risk. [IV.A.3]
AI Basic Act (South Korea)
The second comprehensive national AI law (effective Jan 2026) — regulates 'high-impact AI' and generative-AI transparency. [II.C.1]
AI governance committee
A cross-functional body that sets policy, reviews high-risk use cases and oversees the program. [I.B.1]
AI impact assessment (AIA)
A structured evaluation of an AI system's potential impacts and the mitigations for them. [III.A.2]
AI incident
An event where an AI system causes or risks harm, failure or non-compliance. [III.C.4]
AI Liability Directive (AILD)
A proposed EU measure on fault-based (negligence) liability for AI harm — withdrawn by the Commission in 2025; distinct from the revised Product Liability Directive's no-fault, defect-based regime. [II.B.4]
AI life cycle
The end-to-end stages from use-case assessment through retirement of an AI system. [I.C.1]
AI literacy
A baseline understanding of AI capabilities, limits and risks — increasingly a legal expectation. [I.B.3]
AI management system (AIMS)
A structured set of policies and processes to govern AI, certifiable under 42001. [II.D.3]
AI maturity model
A staged view of governance capability, from ad hoc to optimised. [I.B.4]
AI Office
The EU body overseeing GPAI and coordinating enforcement. [II.C.5]
AI RMF Playbook
Companion guidance suggesting concrete actions for each function and category. [II.D.2]
AI washing
Overstating or fabricating AI capabilities in marketing. [II.B.3]
Allocative harm
Harm from an AI system withholding or granting opportunities or resources unfairly (a loan, a job, a place). [I.A.2]
Artificial Intelligence
A machine-based system that, for explicit or implicit objectives, infers from its inputs how to generate outputs such as predictions, content, recommendations or decisions. [I.A.1]
Audit
A structured, often independent review of a system against defined criteria. [III.C.3]
Automated decision-making (ADM)
A decision based solely on automated processing, restricted where it produces legal or similarly significant effects. [I.C.2; II.A.3]
Automation bias
Over-reliance on automated outputs — a risk that human oversight must actively counter. [II.C.3]
Autonomy
The degree to which a system acts and decides without real-time human intervention. [I.A.3]
Awareness program
Ongoing communication that keeps AI risks, policies and norms salient across the organisation. [I.B.3]

B

Benchmarking
Comparing performance or risk against references or baselines. [III.A.4]
Bias / interpretability testing
Assessing fairness across groups and the explainability of outputs. [III.B.3]
Biometric data
Data derived from physical or behavioural traits used to identify a person (face, fingerprint, voice). [II.A.4]
Brittleness
Failure on inputs slightly different from the training conditions. [III.C.5]
Business context
The organisational objectives, constraints and stakeholders surrounding the system. [III.A.1]

C

Catastrophic forgetting
Losing earlier capabilities when a model is retrained on new data. [III.B.4]
Classic (predictive) AI
Models that predict or classify, often more interpretable and task-specific. [IV.A.2]
Cloud / on-premise / edge
Where the model runs, trading scalability, control, latency and privacy. [IV.A.3]
Code of conduct
A voluntary commitment to responsible-AI practices that minimal-risk providers are encouraged to adopt. [II.C.1]
Conformity assessment
The process of demonstrating a high-risk system meets legal requirements before it is placed on the market. [II.C.2]
Conformity requirements
The legal pre-market checks a high-risk system must satisfy. [III.C.1]
Contextual risk
Risk that depends on how and where a system is actually used. [IV.B.1]
Continuous monitoring
Ongoing observation of an AI system's performance and behaviour in production. [III.C.2]
Contractual safeguards
Clauses on data use, transparency, audit, liability and incident notice that allocate AI risk. [I.C.3]
Copyright
Exclusive rights in original creative works — relevant to both training inputs and AI outputs. [II.B.1]
Counterfactual explanation
An explanation showing what minimal change would alter the outcome — e.g., 'approved if income were higher.' [III.C.6]
Crisis communication
Prepared messaging for incidents and failures. [IV.C.6]
Cross-functional collaboration
Structured joint work across legal, technical, business, ethics and risk functions on AI decisions. [I.B.2]

D

Dark pattern
An interface designed to manipulate users into choices against their own interest. [II.B.3]
Data availability
Whether suitable data exists to run or adapt the system. [IV.A.1]
Data catalog
A managed inventory of datasets with metadata, sources and lineage. [III.B.2]
Data controller
The entity that determines the purposes and means of processing personal data. [II.A.3]
Data dependency
An AI system's behaviour is determined by training data, so data flaws become system flaws. [I.A.3]
Data governance
Policies and processes for sourcing, quality, use, access and retention of data. [III.B.1]
Data governance policy
Rules for how data is sourced, classified, used, retained and protected — extended here to AI training and use. [I.C.2]
Data leakage
Test information contaminating training, which inflates performance. [III.B.4]
Data localization
A legal requirement that certain data be stored and processed only within the country where it was collected. [II.A.3]
Data minimization
Processing only personal data that is adequate, relevant and limited to what is necessary for the purpose. [II.A.2]
Data quality
The accuracy, completeness, consistency and timeliness of data. [III.B.1]
Data residency
Where data is physically stored — often a business or policy choice rather than a legal mandate. [II.A.3]
Data sovereignty
The principle that data is subject to the laws of the country in which it is located. [II.A.3]
Data-use clause
Terms on whether and how the vendor uses your data, including for training. [IV.B.2]
Datasheet (for datasets)
Documentation of a dataset's source, composition and limitations. [III.A.5]
Deactivation (kill switch)
The ability to stop or disable an AI system promptly. [IV.C.7]
Deceptive practice
A material representation or omission likely to mislead a reasonable consumer. [II.B.3]
Decision rights
Explicit rules about who can approve, escalate or veto an AI decision. [I.B.2]
Decommissioning
The controlled retirement of an AI system, including data handling. [IV.C.7]
Demographic parity
A fairness metric requiring outcomes to be distributed similarly across groups. [III.B.3]
Deployer
The party that uses an AI system under its own authority in a real context. [I.B.5; II.C.6]
Deployer impact assessment
An assessment of risks in the specific deployment context. [IV.B.1]
Deployment audit
A periodic review of a deployed system against criteria in your environment. [IV.C.3]
Deployment governance
Applying policies and controls to the operational use of an AI system. [IV.C.1]
Design defect
A foreseeable risk that a safer, reasonable alternative design would have avoided. [II.B.4]
Design log / decision record
A record of key design choices and the rationale behind them. [III.A.5]
Developer / provider
The party that builds an AI system or places it on the market under its name. [I.B.5]
Digital Markets Act (DMA)
EU competition law imposing obligations on large 'gatekeeper' platforms (e.g. no self-preferencing, interoperability, data-combination limits) — distinct from the DSA's content/transparency focus. [II.B.3]
Digital Services Act (DSA)
EU law on online platforms requiring recommender-system transparency, profiling/ad-targeting disclosure, and action against illegal content and systemic risks such as disinformation. [II.B.3]
Disparate impact
A neutral practice that disproportionately harms a protected group, potentially unlawful absent justification. [I.A.4; II.B.2]
Disparate treatment
Intentional differential treatment based on a protected characteristic. [II.B.2]
Distribution shift
When live data diverges from training data, degrading performance. [III.B.4]
Distributor
A supply-chain party (other than provider or importer) that makes a system available, checking marking and conformity downstream. [I.B.5]
Diversity of perspective
Including varied roles, backgrounds and affected viewpoints to reduce blind spots. [I.B.2]
Downstream harm
Harm arising further along from the system's outputs or decisions. [IV.C.5]
Downstream provider
A party that builds an AI system on top of a GPAI model. [II.C.4]
DPIA
A data protection impact assessment, required for processing likely to result in high risk to individuals. [II.A.3; III.A.2]
Drift
Degradation as live inputs or relationships diverge from training. [IV.C.2]

E

Equalized odds
A fairness metric requiring comparable error rates (false positives/negatives) across groups. [III.B.3]
Escalation path
A defined route for raising a contested or higher-risk AI decision to a more senior or specialised body. [I.B.2]
Ethics
The overarching commitment to build and use AI in ways that respect human rights and societal values — the umbrella over the other responsible-AI principles. [I.A.4]
Ethics by design
Building ethical requirements into the system from the outset, not bolting them on later. [I.C.1; III.A.3]
EU AI Act Article 4
Requires providers and deployers to ensure a sufficient level of AI literacy among staff and others operating AI on their behalf. [I.B.3]
Evaluation (TEVV)
The broader assessment of a system's overall performance and quality against defined metrics. [III.B.3]
Evaluation metrics
The quantitative measures used to judge performance and fairness. [III.B.5]
Expert system
A rule- and knowledge-based system that emulates the decision-making of a human specialist — a classic non-ML form of AI. [I.A.1]
Explainability
The reasons for a specific output can be understood by an appropriate audience. [I.A.4]
Explicit consent
A clear, specific, affirmative agreement, frequently required to process special-category data. [II.A.4]
External communication plan
A plan for informing external stakeholders about the AI system and any incidents. [IV.C.6]

F

Failure to warn
Inadequate instructions or warnings about a product's risks and limitations. [II.B.4]
Fairness
Avoiding unjust bias and ensuring comparable treatment across individuals and groups. [I.A.4]
Fallback process
The manual or alternative process used when the AI is disabled. [IV.C.7]
Feature
An individual measurable property or characteristic of the data used as input to a model (e.g. a house's square footage or location). [I.A.1]
Feature flag (feature toggle)
A switch that turns specific functionality or model behaviour on or off dynamically at runtime without redeploying the system — enabling controlled experiments, gradual rollout and immediate shut-off. [IV.C.7]
Fine-tuning
Further training a model on specific data to fit a task. [IV.A.3]
Fit-for-purpose
Data suitable in content and quality for the model's intended use. [III.B.1]
Foundation model
A large model trained on broad data that can be adapted (e.g., fine-tuned) to many downstream tasks. [I.A.1]
Four-fifths (80%) rule
A US disparate-impact screen: a selection rate below 80% of the highest group's signals adverse impact. [III.B.3]
Framework Convention on AI
The Council of Europe's 2024 treaty — the first legally binding international agreement on AI, open to non-European states. [II.C.1]
FRIA
A fundamental-rights impact assessment required of certain high-risk deployers. [III.A.2; IV.B.1]
Function creep
Gradual expansion of a system's use beyond the original scope. [IV.C.5]
Fundamental-rights impact assessment (FRIA)
A deployer assessment required for certain high-risk uses. [II.C.6]

G

Gap assessment
A structured review comparing current policies against AI-specific risks. [I.C.2]
General-purpose AI (GPAI) model
A model with broad capability usable across many downstream tasks. [II.C.4]
Generative AI
Models that produce new content — text, image, audio, code — by learning the statistical structure of large training datasets. [I.A.1; IV.A.2]
Global vs local explanation
Global explains the model's overall behaviour; local explains one specific output. [III.C.6]
Go/no-go decision
A deliberate release decision to proceed or halt, based on whether gate criteria are met. [I.C.1]
Govern / Map / Measure / Manage
The four core functions of the AI RMF. [II.D.2]

H

High-impact AI
South Korea's term for AI affecting life, safety or fundamental rights — the analogue of the EU's high-risk tier. [II.C.1]
High-risk AI
Systems posing significant risk to health, safety or rights, subject to strict obligations. [II.C.1]
Hub-and-spoke governance
A central AI governance committee setting policy and reviewing high-risk cases, with embedded contacts ('spokes') handling triage in each business unit. [I.B.2]
HUDERAF / HUDERIA
The Council of Europe's Human Rights, Democracy and the Rule of Law Assurance Framework (and its HUDERIA impact-assessment methodology) — proportional impact assessments plus stakeholder engagement to operationalise the Framework Convention's principles. [II.C.1]
Human authorship requirement
The rule in several regimes that copyright requires a human author, limiting protection for AI-generated works. [II.B.1]
Human oversight
A person's ability to monitor, intervene in or override an AI system's operation, scaled to its risk and autonomy. [I.A.3; II.C.3]
Human-centricity
AI is designed to respect human autonomy, rights and wellbeing. [I.A.4]
Hyperparameter
A configuration setting chosen before training that controls how the model learns (e.g. learning rate, number of layers); tuned, not learned. [I.A.1]

I

IEEE 7000
IEEE standard model process for addressing ethical concerns during system design — embeds individual/societal values into the life cycle with traceability, distinct from ISO 22989's terminology focus. [II.D.3]
Importer
A party that places an AI system from a non-EU provider on the EU market and must verify its conformity first. [I.B.5]
Importer / distributor
Parties that bring or make AI available on the market and verify its conformity. [II.C.6]
Incident log
A record of issues and incidents arising in deployment. [IV.C.4]
Incident management
The defined process for detecting, responding to and learning from AI failures. [I.C.1]
Indemnification
A contractual shift of liability — for example for IP infringement. [IV.B.2]
Inferred data
Attributes a model derives about a person that were never directly provided — often missed by pre-AI privacy policy. [I.C.2]
Inferred sensitive data
Special-category attributes a model derives from non-sensitive inputs. [II.A.4]
Instructions for use
Provider documentation enabling deployers to operate the system correctly and safely. [II.C.3; III.C.6]
Intake process
A defined route by which new AI use cases enter governance review. [I.B.2]
Integration risk
Risk arising from how the model connects to your systems and data. [IV.C.3]
Intellectual-property exposure
The risk that an AI system trains on or reproduces copyrighted or proprietary material, or leaks trade secrets through its outputs. [I.A.3]
IP in AI
Questions of rights in training data and ownership of AI-generated outputs. [I.C.2]
ISO 31000:2018
The general enterprise risk-management standard (principles + framework + process) for any organisation and any risk; ISO/IEC 23894 adapts it specifically for AI. [II.D.3]
ISO/IEC 22989
The standard defining AI concepts and terminology. [II.D.3]
ISO/IEC 42001
The certifiable AI management system (AIMS) standard. [II.D.3]
ISO/IEC 42005
Guidance on conducting AI system impact assessments. [II.D.3]
Issue / risk register
A maintained list of open issues and risks with owners. [IV.C.4]
Issue management
The process for handling problems that arise during use. [IV.C.1]

J

Joint controllers
Two or more parties that together determine the purposes and means of processing (GDPR Art. 26); they must agree an arrangement allocating their respective responsibilities. [II.A.3]

L

Label
The target or output value a supervised model learns to predict (e.g. the house's price). [I.A.1]
Lack of robustness
Sensitivity to noise, edge cases or adversarial inputs. [III.C.5]
Lawful basis
A legal ground required to process personal data (e.g., consent, contract, legitimate interests under GDPR). [II.A.1]
Legitimate interests
A lawful basis permitting processing necessary for an interest not overridden by individuals' rights and freedoms. [II.A.1]
Licence terms
Contractual conditions governing whether data or a model may be used for training. [II.B.1]
Licensing agreement
The contract governing use of a vendor's AI model or system. [IV.B.2]
LIME / SHAP
Post-hoc techniques that estimate how much each input feature contributed to a prediction. [III.C.6]
Limited-memory AI
An AI system that retains recent data to inform its decisions; nearly all useful AI today is limited-memory. [I.A.1]
Limited-risk AI
Systems subject mainly to transparency obligations such as disclosure. [II.C.1]
Lineage
The record of data's movement and transformations through the pipeline. [III.B.2]
Localization
Restricting a system's operation to certain regions or contexts. [IV.C.7]

M

Machine Learning (ML)
A subset of AI in which models learn patterns from data rather than executing explicitly programmed rules. [I.A.1]
Maintenance schedule
A planned cadence for updates, checks and retraining. [III.C.2; IV.C.2]
Make-vs-buy
The decision to build and own versus license a third-party model. [IV.B.3]
Manufacturing defect
A departure from the intended design — for AI, e.g., flawed data or training producing unintended behaviour. [II.B.4]
Market-surveillance authority
A national body enforcing the AI Act and policing the market. [II.C.5]
Membership inference
An attack that determines whether a specific person's data was in the training set. [III.C.3]
Minimal-risk AI
Systems with no specific obligations beyond generally applicable law. [II.C.1]
Misalignment
A gap between the objective the system optimises and the outcome the organisation actually intends. [I.A.2]
Misuse
Use contrary to the intended purpose or acceptable-use rules. [IV.C.5]
Model / data drift
Degradation as data or relationships change over time. [III.C.5]
Model card
A standard document describing a model's purpose, data, performance and limits — common release-gate evidence. [I.C.1; III.A.5; III.C.1]
Model drift
Degradation of a model's performance over time as data or the world diverge from what it was trained on. [I.A.3; III.C.2]
Model inversion
An attack that reconstructs sensitive training data from a model's outputs. [III.C.3]
Model memorisation
When a model reproduces training data, creating privacy and IP exposure. [I.C.2]
Model provenance
The documented origin and history of a model and its training data, used to assess third-party risk. [I.C.3]
Model selection
Choosing an architecture or model fit for the purpose, risk and explainability needs. [III.A.3]
Multimodal model
A model that handles multiple data types such as text, image and audio. [IV.A.2]

N

Narrow (weak) AI
AI built for a specific task or bounded set of tasks. All AI in real-world use today is narrow AI. [I.A.1]
Natural language processing (NLP)
Techniques that let systems understand, interpret and generate human language. [I.A.1]
NIST AI RMF
A voluntary US framework (2023) for managing AI risks and improving trustworthiness. [II.D.2]

O

OECD AI Principles
Intergovernmental, values-based principles for trustworthy AI adopted in 2019 and updated in 2024. [II.D.1]
OECD.AI Policy Observatory
The OECD's hub tracking national AI policies, metrics and trends. [II.D.1]
Opacity (black box)
The difficulty of inspecting or explaining how a model reached a particular output. [I.A.3]
Operational controls
Design-time mechanisms — guardrails, thresholds, oversight points — that govern behaviour. [III.A.3]
Overfitting
A model that learns training noise and fails to generalise to new data. [III.B.4]

P

Parameter
An internal value the model learns from data during training — the weights adjusted to fit the data; not set by hand. [I.A.1]
Performance requirements
The accuracy, latency and reliability the use case demands. [IV.A.1]
Phased applicability
Staggered dates on which different obligations take legal effect. [II.C.5]
Policy floor
A minimum baseline of controls that applies everywhere, even under decentralised or federated governance. [I.B.4]
Post-market monitoring plan
A provider's plan to track a system's real-world performance after release. [III.C.6; IV.C.4]
Post-mortem
A structured, blameless review of an incident's causes. [III.C.5]
Precision / recall / F1
Performance (accuracy) metrics — precision = share of positive predictions that are correct, recall = share of actual positives caught, F1 = their harmonic mean; they measure correctness, not fairness across groups. [III.B.3]
Privacy
Personal data used by an AI system is collected and processed lawfully and minimally, with individuals' rights protected. [I.A.4]
Privacy by default
The most privacy-protective settings apply automatically, without the user having to act. [II.A.2]
Privacy by design
Embedding data-protection measures into systems and processes from the outset. [II.A.2]
Privacy-enhancing technologies (PETs)
Techniques such as pseudonymisation, anonymisation, differential privacy and federated learning that reduce privacy risk. [II.A.2]
Probabilistic output
Outputs are statistical likelihoods, not guaranteed results — the same prompt can yield different answers. [I.A.3]
Probability/severity matrix
A tool ranking risks by their likelihood and their impact. [III.A.4]
Problem framing
Articulating the underlying need and whether AI is the appropriate solution. [III.A.1]
Processor
An entity that processes personal data on the controller's behalf (e.g., a cloud or model vendor). [II.A.3]
Production monitoring
Observing a deployed system's behaviour in real use. [IV.C.2]
Prohibited (unacceptable-risk) AI
Practices banned outright due to unacceptable risk to rights and safety. [II.C.1]
Prompt injection
Crafting inputs that override a generative model's instructions or guardrails. [III.C.3]
Proportionality
Calibrating the strength of controls to the level of risk and organisational capacity. [I.B.4; III.A.2]
Proprietary model
A model an organisation builds, owns and controls. [IV.B.3]
Proprietary vs open-source model
Vendor-controlled vs openly available models, differing on control, support and transparency. [IV.A.2]
Protected characteristic
A trait (race, sex, age, disability and others) that law shields from discrimination. [II.B.2]
Provenance
The origin and source history of data — who, where, and under what rights. [III.B.2]
Provider
Builds or places an AI system on the market under its name; bears the primary obligations. [II.C.6]
Provider notification
Informing the provider of incidents for their post-market duties. [IV.C.4]
Provider obligations
The heavier legal duties borne by those who build or place AI on the market. [IV.B.3]
Proxy variable
A feature correlated with a protected attribute that can reproduce its effect. [II.B.2]
Purpose limitation
Personal data collected for one purpose may not be freely reused for an incompatible new purpose. [II.A.1]

Q

Quality management system (QMS)
Documented processes ensuring the ongoing compliance of high-risk AI. [II.C.3]

R

RACI
A matrix assigning who is Responsible, Accountable, Consulted and Informed for each activity. [I.B.1]
Reactive machine
An AI system that responds only to current input and keeps no memory of past interactions (e.g., IBM Deep Blue). [I.A.1]
Rebuttable presumption of defectiveness
A legal assumption that a product is defective unless the manufacturer proves otherwise (e.g. that it met applicable safety and legal requirements) — it shifts the burden, it is not a permanent or automatic finding. [II.B.4]
Record-keeping (logging)
Automatic logs enabling traceability of the system's operation. [II.C.2]
Red teaming
Adversarial testing that actively tries to make the system fail or misbehave. [III.C.3; IV.C.3]
Redress channel
A route for affected people to complain or seek correction. [IV.C.6]
Release readiness
A go/no-go evaluation that a system is fit and compliant for production. [III.C.1]
Representational harm
Harm from a system reinforcing stereotypes, demeaning or erasing groups, even without a direct allocation decision. [I.A.2]
Representativeness
Whether the data reflects the population the model will affect. [III.B.1]
Reproducibility
The ability to recreate the model and results from documented inputs. [III.B.2; III.B.5]
Requirements gathering
Eliciting functional, legal and ethical requirements before building. [III.A.3]
Residual risk
Risk remaining after mitigations, requiring formal sign-off. [IV.B.1]
Retraining trigger
A predefined condition that prompts a model refresh. [III.C.2]
Retrieval-augmented generation (RAG)
Grounding a model's outputs in retrieved, authoritative data. [IV.A.3]
Revised EU Product Liability Directive
An updated regime expressly covering software and AI and easing proof of defect. [II.B.4]
Risk tiering
Sorting use cases into risk bands so the weight of controls scales with potential harm. [I.B.4]
Risk tolerance
The amount and type of risk an organisation is willing to accept in pursuit of its objectives. [I.B.4]
Risk-management system
A continuous process to identify, evaluate and mitigate risks across the AI lifecycle. [II.C.2]
Risk-mitigation hierarchy
A preference order: eliminate > reduce > transfer > accept. [III.A.4]
Robustness testing
Checking behaviour under edge cases, noise and adversarial inputs. [III.B.3]
Role-based training
Training content tailored to what each audience must know and do. [I.B.3]
Rollback plan
A predefined way to revert or disable the system if needed. [III.C.1]
Root-cause analysis
Determining the underlying cause to prevent recurrence. [III.C.4]

S

Safety and reliability
An AI system performs as intended within safe limits and behaves consistently, including on unexpected inputs. [I.A.4]
Safety component
An AI system whose failure could endanger health or safety — a high-risk route independent of Annex III (e.g., autonomous vehicles, aviation, medical devices). [II.C.1]
Scalability risk
The amplification of a small error or bias into systemic harm once a model is deployed at scale. [I.A.2]
Secondary use
Using a system for a purpose beyond its intended one. [IV.C.5]
Security
AI systems and their data are protected from unauthorised access, manipulation and attacks such as poisoning or evasion. [I.A.4]
Security testing
Probing for vulnerabilities such as data poisoning, prompt injection and model theft. [III.C.3; IV.C.3]
Self-aware AI
A hypothetical AI possessing consciousness and awareness of its own existence — the highest, theoretical level. [I.A.1]
Serious-incident reporting
A legal duty to notify authorities of significant AI incidents. [III.C.4]
Service-level agreement (SLA)
Committed performance and availability terms. [IV.B.2]
Shadow AI
Unsanctioned use of AI tools by staff outside approved channels — a key risk that awareness programs aim to reduce. [I.B.3; I.B.4]
Soft law
Non-binding standards that shape norms and frequently harden into binding law over time. [II.D.1]
Special-category data
Personal data needing extra protection: health, race/ethnicity, religion, political opinions, sexual orientation, biometric and genetic data. [II.A.4]
Stage gate
A checkpoint a project must clear before moving to the next lifecycle stage. [I.C.1]
Stakeholder disclosure
Telling affected parties about AI use and its implications. [IV.C.6]
Stakeholder mapping
Identifying who is affected and how, to surface risks. [III.A.4]
Sub-processor
A vendor's own downstream supplier that processes data or provides an AI component on its behalf. [I.C.3]
Substantial modification
Changing a system enough that the deployer takes on provider-like obligations. [I.B.5]
Success metrics
Defined measures of whether the system achieves its intended purpose. [III.A.1]
Systemic risk
Risk from highly capable GPAI that could have large-scale impact, triggering extra obligations. [II.C.4]

T

Technical documentation
Records demonstrating a high-risk system meets requirements (design, data, testing). [II.C.2; III.A.5]
Test (TEVV)
Controlled checks with predefined inputs and expected outputs confirming specific functions behave correctly under known conditions — narrow functionality, not overall performance. [III.B.3]
Test data
A dataset held untouched until the end, used once for a final, unbiased simulation of real-world performance (a.k.a. evaluation data). [III.B.4]
Test report
A record of test plans, metrics, results and pass/fail decisions. [III.B.5]
TEVV
Test, evaluation, verification and validation processes for AI. [III.B.3]
Text and data mining (TDM) exception
A legal carve-out permitting some analysis of copyrighted works, frequently subject to a rights-holder opt-out. [II.B.1]
Theory-of-mind AI
A hypothetical, advanced AI that understands the beliefs, intentions and emotions of others. [I.A.1]
Third-party risk
Risk introduced by external vendors, models or services embedded in your operations. [I.C.3]
Threat modeling
Systematic identification of attack vectors and abuse cases. [III.C.3]
Three lines model
A governance accountability structure: the business owns and manages risk (1st line), risk/compliance sets policy and oversees (2nd line), and internal audit gives independent assurance to the board (3rd line). There is no fourth line. [I.B.1]
Tiered disclosure
Giving each audience the appropriate level of information. [III.C.6]
Total cost of ownership
The full cost of building, securing and maintaining a model. [IV.B.3]
Training data
The dataset the model learns from — it adjusts the model's internal parameters (weights). [III.B.4]
Training documentation
Records of the data, configuration and process used to train the model. [III.B.5]
Training-data summary
A required public summary of the content used to train a GPAI model. [II.C.4]
Transparency
Individuals must be clearly informed about how their personal data is processed and with what consequences. [I.A.4; II.A.1]
Transparency obligation
A duty to disclose specified information about an AI system. [III.C.6]
Triage
Classifying an incident by severity to drive the response. [III.C.4]
Trustworthy AI
AI that is lawful, ethical and robust, reflecting agreed responsible-AI principles. [II.D.1]
Trustworthy-AI characteristics
The properties the RMF promotes — valid/reliable, safe, secure, accountable/transparent, explainable, privacy-enhanced, fair. [II.D.2]

U

Unfair practice
A practice causing substantial, unavoidable consumer harm not outweighed by countervailing benefits. [II.B.3]
Use case
The specific problem, users and context an AI system is built to serve. [III.A.1]
Use-case context
The business, data, ethical and organisational setting of a deployment. [IV.A.1]
User / end-user
The individual interacting with the system or affected by its output. [I.B.5]
User training
Preparing staff to use and oversee the system correctly. [IV.C.1]

V

Validation (TEVV)
Confirming the right system was built — that it meets the real-world need and intended use. [III.B.3]
Validation data
A held-aside dataset never used to adjust internal parameters; used repeatedly during development to give an unbiased performance check that guides hyperparameter/design tuning and the decision to keep tuning or stop. [III.B.4]
Validation testing
Confirming the model meets its requirements on held-out data. [III.B.3]
Vendor due diligence
Structured assessment of a supplier's AI practices before and during engagement. [I.C.3]
Vendor-update management
Tracking and validating model changes pushed by a vendor. [IV.C.2]
Verification (TEVV)
Confirming the system was built right — that it meets its design specifications and requirements. [III.B.3]

W

Workforce readiness
Whether staff are trained and prepared to use and oversee the system. [IV.A.1]

Z

Zero-shot learning (ZSL)
A model recognising or categorising classes it was never explicitly trained on. [I.A.1]
No terms match "".
kashifz.com