AI system provider
Any natural or legal person, public authority, agency or other body that develops an AI system or that has an AI system developed and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. (Art. 3 Regulation (EU) 2024/1689)
AI system deployer
Any natural or legal person, public authority, agency or other body using an AI system under its authority in the course of a professional activity, except where the AI system is used in the course of a personal non-professional activity. (Art. 3 Regulation (EU) 2024/1689)
High-risk AI system
An AI system that, by its intended purpose and mode of operation, poses a significant risk to the health, safety or fundamental rights of natural persons. Listed in Annexes I and III of the Regulation, including biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and justice. (Art. 6)
Minimal-risk AI system
An AI system that does not fall into any of the prohibited, high-risk, or limited-transparency risk categories. Not subject to specific obligations, but voluntary adoption of codes of conduct is encouraged. (Art. 69)
Limited-transparency AI system
AI systems that interact directly with natural persons, generate deep fake content, or are used to detect emotions or categorize people. Subject to specific transparency obligations, such as informing the user that they are interacting with an AI system. (Art. 50)
Prohibited AI practices
AI applications deemed unacceptable for violating EU values, including subliminal manipulation, exploitation of vulnerabilities, social scoring, emotion inference in workplace/educational settings, and certain uses of real-time biometrics in public spaces. From December 2026, also includes AI systems that generate, or assist in generating, non-consensual intimate imagery (NCII) or child sexual abuse material (CSAM). (Art. 5)
General-purpose AI model (GPAI)
An AI model trained on a broad amount of data using self-supervised learning at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks. GPAI models with systemic risk are subject to additional obligations. (Art. 3(63))
GPAI with systemic risk
A general-purpose AI model that, due to its high impact, may negatively affect the EU market significantly. Systemic risk is presumed when the model has been trained with cumulative computing power exceeding 10^25 FLOPS. Subject to obligations for evaluation, risk mitigation and notification of serious incidents. (Art. 51)
Conformity assessment
Process by which the provider of a high-risk AI system demonstrates that it meets the requirements set out in Chapter II of Title III of the Regulation. May be carried out through an internal procedure (most systems) or through assessment by a notified body (only for biometrics and certain critical systems). (Art. 43)
Technical documentation
Set of documents that the provider of a high-risk AI system must prepare before placing it on the market, including system description, training data, performance metrics, human oversight design, and cybersecurity measures. (Art. 11 and Annex IV)
Human oversight
Set of measures ensuring that the high-risk AI system can be effectively overseen by natural persons during the period of use, including understanding the capabilities and limitations of the system, and the ability to decide not to use it or stop it. (Art. 14)
Regulatory sandbox
A controlled environment established by a national supervisory authority that facilitates the development, testing and validation of innovative AI systems under regulatory oversight before their placement on the market. Startups and SMEs have priority access. (Art. 57)
EU database
Electronic database managed by the European Commission where providers must register their high-risk AI systems before placing them on the market or putting them into service in the EU. Contains information about the system, its risk category and conformity assessment. (Art. 71)
Authorised representative
Any natural or legal person established in the EU who, through a written mandate from a provider established outside the EU, acts on its behalf to carry out the obligations under the Regulation. Mandatory when the provider is not established in the EU but its system is marketed there. (Art. 25)
Importer
Any natural or legal person established in the EU that places a high-risk AI system on the market under its own name or trademark, or introduces an AI system into the EU from a third country. Must verify that the provider has complied with the Regulation obligations. (Art. 26)
Distributor
Any natural or legal person in the supply chain, other than the provider or importer, that makes an AI system available on the EU market. Must verify that the system bears the required documentation and CE marking of conformity. (Art. 27)
CE marking of conformity
Marking by which the provider indicates that the high-risk AI system complies with the requirements of the Regulation. Must appear on the system or, where not possible, on the packaging and accompanying documentation. (Art. 48)
Data quality and data governance
Requirement applicable to high-risk AI systems requiring that training, validation and testing datasets meet adequate quality and governance criteria, including relevance, representativeness, absence of errors and examination of possible biases. (Art. 10)
Logging (incident recording)
Obligation of high-risk AI systems to automatically record events (logs) throughout their operation to facilitate human oversight and post-hoc auditing. Logs must be retained for a period proportionate to the purpose of the system. (Art. 12)
Transparency
Principle requiring that AI systems be designed and developed so that natural persons can understand and interpret them, including traceability of system decisions, explainability of outputs, and clarity about system operation. (Art. 13)
Robustness and cybersecurity
Requirement for high-risk AI systems to be designed to resist errors, faults and malicious attacks, including attempts to manipulate training data or system inputs. (Art. 15)
Fundamental rights impact assessment
Assessment that deployers of high-risk AI systems must carry out before putting them into service, analyzing the potential impact on fundamental rights recognized by the EU Charter of Fundamental Rights. (Art. 27a)
Serious incident notification
Obligation of the provider to immediately inform the competent national authorities when a high-risk AI system presents a serious incident constituting an infringement of EU law that may affect the rights or safety of natural persons. (Art. 62)
National competent authority
Body designated by each EU Member State responsible for the application and supervision of compliance with the AI Regulation. In Spain, the designated authority must be notified to the European Commission. (Art. 59-70)
European AI Office
Body of the European Commission responsible for coordinating the application of the AI Regulation among Member States, overseeing compliance with obligations for GPAI models with systemic risk, and managing the EU database. (Art. 64-68)
Voluntary code of conduct
Set of rules and commitments that providers and deployers of minimal-risk AI systems may voluntarily adopt to promote trust and responsibility in AI development and use. Their adoption is encouraged by the Regulation. (Art. 69)
Biometric system
AI system used for the identification, authentication or categorization of natural persons based on biometric data (facial features, fingerprints, iris, etc.). Real-time biometric systems in public spaces for law enforcement purposes are subject to specific restrictions. (Art. 5 and Annex III)
Social scoring
AI practice that evaluates or classifies natural persons through the collection and analysis of social or behavioral data, producing detrimental or unfavorable outcomes. Expressly prohibited by the AI Regulation when used in a harmful manner. (Art. 5(1)(c))
Deep fake
AI-generated or manipulated content that resembles authentic images, audio or video but is not real. Providers of systems generating deep fakes must ensure that outputs carry an identification mark as AI-generated content. (Art. 50)
Explainability
The ability of an AI system to provide understandable information about how its outputs or recommendations were generated. It is a requirement for high-risk systems and a general principle of the Regulation, closely linked to the right to explanation under the GDPR. (Recital 71)
AI system (definition)
A machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, generating outputs such as predictions, recommendations, decisions or content that can influence physical or virtual environments. The definition aligns with the OECD to ensure international consistency. (Art. 3(1))
Safety component
A component of a product or of software that is independent of the product and that fulfils a safety function for that product, or a safety component of an AI system. Products with safety components that are AI systems are classified as high-risk under Annex I. (Art. 3(14))
Quality management system
A formalised system that the provider of a high-risk AI system must establish, implement, document and maintain, including a compliance strategy, procedures for risk management, conformity assessment, technical documentation review, incident management and audit. (Art. 17)
AI system risk management
A continuous, iterative process that the provider of a high-risk AI system must carry out throughout the entire lifecycle of the system, identifying and evaluating known and foreseeable risks, estimating and evaluating risks that may materialise, and applying appropriate risk mitigation measures. (Art. 9)
Instructions for use
Document that the provider of a high-risk AI system must attach to the system, written clearly and in an appropriate language, including the provider identity, system characteristics, capabilities and limitations, instructions for human use and oversight measures. (Art. 13)
Biometric identification
Automated identification or authentication of natural persons through their biometrics. Biometric identification is classified as high-risk when used to uniquely identify persons, except in specific Annex III cases. Real-time identification in public spaces for law enforcement is prohibited (with Art. 5 exceptions). (Art. 3(33))
Biometric categorisation
Assigning natural persons to specific categories based on their biometric data, unless used as part of an identification system. Biometric categorisation that infers sensitive data (ethnic origin, gender, religion) is subject to Art. 5 restrictions. (Art. 3(35))
Emotion recognition
An AI system that identifies or infers emotions or intentions of a natural person from their behaviour, facial expressions, voice or other data. Emotion recognition in the workplace or educational institutions is prohibited by Art. 5, except for safety or medical monitoring purposes. (Art. 3(39))
AI literacy
Skills, knowledge and understanding that enable providers, deployers and natural persons to make informed use of AI systems, as well as their associated risks and benefits. Providers and deployers must ensure AI literacy of their staff and persons operating AI systems under their responsibility. Obligation applicable since 2 February 2025. (Art. 4)
Post-market monitoring
Systematic activities that the provider of a high-risk AI system must carry out to evaluate and document ongoing compliance with the Regulation throughout the system lifecycle, ensuring it remains conformant after being placed on the market. Must include a post-market monitoring plan. (Art. 72)
AI system interacting with persons
An AI system designed to interact directly with natural persons (chatbots, virtual assistants). Subject to Art. 50 transparency obligations: the user must be informed that they are interacting with an AI system, unless this is obvious from the context. (Art. 50(1))
AI systems already on the market (transitional regime)
High-risk AI systems already placed on the market or in service before 2 August 2026 must comply with the Regulation by 2 August 2027. High-risk AI systems under Annex I already on the market before 2 August 2027 must comply by 2 August 2030. (Art. 96)
Administrative fines
Fines that national competent authorities may impose for non-compliance with the Regulation. Levels: (1) up to €35M or 7% of turnover for prohibited practices; (2) up to €15M or 3% for non-compliance with high-risk obligations or other obligations; (3) up to €7.5M or 1.5% for providing incorrect information to authorities. For SMEs and startups, the lower absolute amount applies. (Art. 99)
Notified body
A national conformity assessment body designated by a Member State to carry out third-party conformity assessment procedures. Notified body assessment is only required for high-risk AI systems using biometrics and certain critical Annex III systems. Most high-risk systems may use the internal procedure. (Art. 43, Art. 31-33)