Glossary · reviewed 2026-09-21

AI regulation terms, in plain words

31 terms you meet in the EU AI Act, the Polish and Korean laws, US state laws and the standards around them. Each gives the legal reference and the source it is paraphrased from.

EU AI Act

AI literacy

The skills, knowledge and understanding that let providers, deployers and affected people use AI in an informed way and be aware of its opportunities, risks and possible harm. Article 4 requires providers and deployers to take measures, to their best extent, so that their staff have it. The Digital Omnibus clarified that no specific level has to be guaranteed.

EU AI Act, Article 3(56) and Article 4 as amended. Source: artificialintelligenceact.eu · Tracker row

AI system

A machine-based system that works with some autonomy and infers from its input how to produce outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. It may keep adapting after deployment. Almost every obligation in the Act starts with the question of whether you use one.

EU AI Act, Article 3(1). Source: artificialintelligenceact.eu · Build your AI inventory

Annex I (AI in regulated products)

AI that is part of products already covered by EU product law, such as machinery, medical devices and vehicles. The high-risk obligations for these systems were deferred to 2 August 2028.

EU AI Act, Annex I; deferral by Regulation (EU) 2026/1744. Source: gibsondunn.com · Tracker row

Article 50 (transparency obligations)

The rules that apply since 2 August 2026 to AI that talks to people or produces content: chatbots must say they are AI unless obvious, generated audio, images, video and text must be marked as artificial in a machine-readable way, deepfakes and AI-written public-interest text must be disclosed, and people exposed to emotion recognition or biometric categorisation must be told. Disclosure is due at the latest at the first interaction.

EU AI Act, Article 50. Source: artificialintelligenceact.eu · Disclosure generator · Guide

Biometric categorisation system

An AI system that assigns people to categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for technical reasons. People exposed to it must be informed.

EU AI Act, Article 3(40) and Article 50(3). Source: artificialintelligenceact.eu

Deep fake

AI-generated or manipulated image, audio or video that resembles existing people, objects, places, entities or events and would falsely appear authentic. Deployers must disclose deepfakes; for evidently artistic, satirical or fictional work the duty is lighter.

EU AI Act, Article 3(60) and Article 50(4). Source: artificialintelligenceact.eu

Deployer

The organisation that uses an AI system under its own authority, except for purely personal, non-professional use. A company that uses a vendor chatbot or a copilot is a deployer. Deployers carry the AI-literacy duty and some Article 50 duties.

EU AI Act, Article 3(4). Source: artificialintelligenceact.eu · What applies to deployers now

Digital Omnibus on AI

Regulation (EU) 2026/1744, published on 24 July 2026 and in force since 27 July 2026. It deferred the high-risk obligations, softened the AI-literacy duty, and added a machine-readable marking duty for generative output from 2 December 2026. It did not defer Article 50.

Regulation (EU) 2026/1744. Source: compliancehub.wiki · What changed

Distributor

Anyone in the supply chain, other than the provider or the importer, who makes an AI system available on the EU market, such as a reseller.

EU AI Act, Article 3(7). Source: artificialintelligenceact.eu

Emotion recognition system

An AI system that identifies or infers people's emotions or intentions from their biometric data. Deployers must inform the people exposed to it; using it at work or in education is prohibited except for medical or safety reasons.

EU AI Act, Article 3(39), Article 5 and Article 50(3). Source: artificialintelligenceact.eu

Fine tiers and the SME rule

Three maximums: EUR 35 million or 7% of global turnover for prohibited practices, EUR 15 million or 3% for most other duties including Article 50, and EUR 7.5 million or 1% for incorrect information to authorities. Larger companies face the higher of the two figures; SMEs and start-ups the lower.

EU AI Act, Article 99. Source: artificialintelligenceact.eu · Fine calculator

General-purpose AI model

An AI model that displays significant generality and can competently perform a wide range of distinct tasks, and can be integrated into many downstream systems, typically trained on large data with self-supervision. Obligations for model providers have applied since 2 August 2025; companies that only use such models are not in scope of those duties.

EU AI Act, Article 3(63). Source: artificialintelligenceact.eu · Tracker row

High-risk AI system (Annex III)

AI used in listed sensitive areas such as employment and recruitment, education, credit scoring, essential services, law enforcement, migration and justice. These systems carry the heaviest duties: risk management, data governance, documentation, logging, human oversight, conformity assessment. The Digital Omnibus deferred these obligations from 2 August 2026 to 2 December 2027.

EU AI Act, Annex III; deferral by Regulation (EU) 2026/1744. Source: gibsondunn.com · Tracker row

Importer

An organisation located or established in the EU that places on the EU market an AI system carrying the name or trademark of someone established outside the EU.

EU AI Act, Article 3(6). Source: artificialintelligenceact.eu

Machine-readable marking

Metadata or watermark signals embedded in AI-generated content so software can recognise it as artificial. Article 50(2) requires providers of generative systems to mark output; the Digital Omnibus adds a marking duty for generative output from 2 December 2026.

EU AI Act, Article 50(2); Regulation (EU) 2026/1744. Source: compliancehub.wiki · Tracker row

Prohibited practices

A short list of AI uses banned outright under Article 5, carrying the highest fine tier of up to EUR 35 million or 7% of global annual turnover. Check any system that scores, manipulates, or reads emotions or biometrics against it first.

EU AI Act, Article 5 and Article 99. Source: artificialintelligenceact.eu · Fine calculator

Provider

The organisation that develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, paid or free. Most technical duties fall on providers.

EU AI Act, Article 3(3). Source: artificialintelligenceact.eu

Serious incident

An incident or malfunction of an AI system that directly or indirectly leads to a death or serious harm to health, serious and irreversible disruption of critical infrastructure, an infringement of EU law protecting fundamental rights, or serious harm to property or the environment.

EU AI Act, Article 3(49). Source: artificialintelligenceact.eu

Substantial modification

A change to an AI system after it was placed on the market that the provider did not foresee in its conformity assessment and that affects compliance with the high-risk requirements or changes the intended purpose. A deployer who substantially modifies a system, or puts its own name on it, can take on provider obligations.

EU AI Act, Article 3(23); roles along the value chain in Article 25. Source: artificialintelligenceact.eu

Poland

KRiBSI

Komisja Rozwoju i Bezpieczeństwa Sztucznej Inteligencji, Poland's national AI supervisor under the Act on AI systems. From 28 October 2026 it can inspect, on seven days' notice and remotely by default, and impose fines. Companies can ask it for a binding individual opinion for a fee of 150 PLN.

Ustawa o systemach sztucznej inteligencji. Source: ktzr.pl · Tracker row · Poland hub

Polish Act on AI systems

Ustawa o systemach sztucznej inteligencji: passed on 3 July 2026, published on 27 July 2026, main provisions in force since 11 August 2026. It creates the national supervision and enforcement structure for the EU AI Act; the substantive duties come from the EU regulation.

Ustawa o systemach sztucznej inteligencji. Source: ktzr.pl · Poland hub

South Korea

Domestic representative (Korea)

A local representative that foreign companies must appoint under Korea's AI Basic Act when they exceed any threshold: annual revenue over KRW 1 trillion, AI-service revenue over KRW 10 billion, or more than one million average daily Korean users.

AI Basic Act. Source: cooley.com

High-impact AI (Korea)

Under Korea's AI Basic Act, AI in areas such as healthcare, energy, transport, hiring and biometric analysis. Operators must assess the impact on fundamental rights before deployment, explain outcomes, provide human oversight, keep a user protection plan and document the system.

AI Basic Act. Source: cooley.com · Tracker row

Korea AI Basic Act

South Korea's framework AI law, in force since 22 January 2026, with high-impact duties activated on 21 July 2026 and a grace period of at least one year before fines. It applies to domestic and foreign businesses; generative AI must be disclosed and labelled.

AI Basic Act. Source: cooley.com · South Korea hub

United States

ADMT (automated decision-making technology)

Technology that makes or substantially assists decisions about consumers. Colorado's SB 26-189 and California's CPPA regulations both set duties from 1 January 2027: pre-use notices, explanations after adverse outcomes and human review in Colorado; notices and opt-out rights in California.

Colorado SB 26-189; California CPPA ADMT regulations. Source: cooley.com · United States hub

TRAIGA

The Texas Responsible AI Governance Act (HB 149), in force since 1 January 2026. It bans a short list of intentional uses, including AI that incites self-harm or crime, AI-generated child sexual abuse material, non-consensual deepfake pornography and government social scoring.

Texas HB 149. Source: kslaw.com · Tracker row

Standards

ISO/IEC 42001

The international standard for an AI management system, published in 2023. Organisations can be certified against it by accredited certification bodies. Annex A lists 38 controls under nine objectives; clause 6.1.3 asks organisations to pick the controls their risk treatment needs.

ISO/IEC 42001:2023. Source: isms.online · Kit mapping

NIS2

The EU cybersecurity directive (EU) 2022/2555 for essential and important entities in listed sectors. Article 21 requires ten groups of risk-management measures; Article 23 requires an early warning within 24 hours of a significant incident, a notification within 72 hours and a final report within one month. AI systems are part of the network and information systems it covers.

Directive (EU) 2022/2555, Articles 21 and 23. Source: nis-2-directive.com · Kit mapping

Statement of Applicability

The ISO/IEC 42001 record of which Annex A controls an organisation applies, which it excludes, and why. Certification auditors read it early; the kit's document 14 is a starting point for it.

ISO/IEC 42001:2023, clause 6.1.3. Source: isms.online · Kit mapping

Practice

AI inventory (AI register)

A list of every AI system an organisation uses, with vendor, purpose, owner, data, users, jurisdictions and risk class. It is not a single article of the Act, but every obligation depends on it and Polish guidance names it first in what an inspector expects.

Practice; Polish inspection expectations summarised by KTZR. Source: ktzr.pl · Free template · Build it in a day

Impact assessment

A documented review of how an AI system could affect people's rights, safety and access to services, with mitigations and oversight. Korea requires one for high-impact AI; the EU requires one from certain deployers of high-risk systems once those obligations apply.

Korea AI Basic Act; EU AI Act, Article 27. Source: cooley.com