Article 3 of the EU AI Act runs to seventy definitions. Sixty-eight numbered points, plus two the Digital Omnibus inserted in July.
“High-risk AI system” is not one of them.
Neither is “AI model”, “algorithm”, “AI tool”, or “user.”
The AI Act does define “floating-point operation”, “publicly accessible space”, and “sandbox plan”.
The words you argue about in a call are either missing from the list, or on the list and meaning something different than the meaning you brought to the call.
This is a glossary of both kinds. Each entry gives the definition where the AI Act has one, says where there’s no definition, and then says what turns on the difference. It’s grouped by how the words go wrong rather than alphabetically, because alphabetical order only helps when you already know which word you need.
Words the AI Act Redefines
Provider
Article 3(3): a person or body
“that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.”
Not “the vendor”. There are two ways you can become a provider: you place an AI system on the market, or you put it into service. Putting into service covers your own use, so an internal build you never sell makes you its provider.
“Has an AI system developed” catches you if a supplier built it and your name went on it.
But there’s also a third route: Article 25(1)(a) turns a distributor, importer, deployer or third party into a provider if they “put their name or trademark on a high-risk AI system already placed on the market or put into service, without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated”.
That last clause lets two parties allocate between themselves. It doesn’t bind a regulator, and it sits on 25(1)(a) alone.
You aren’t a provider while you’re still building. Article 2(8) excludes “any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service”, though testing in real-world conditions is carved back out of that exclusion.
Provider obligations for Annex III high-risk systems start December 2, 2027.
Deployer
Article 3(4): a person or body
“using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.”
The one whose authority it’s used under, not the one clicking. The person clicking is usually an employee, and the employer is the deployer.
The AI Act never defines under its authority.
Deployer obligations for high-risk systems start December 2, 2027. Deployer transparency duties under Article 50(3) and 50(4) already apply.
Operator
Article 3(8):
“a provider, product manufacturer, deployer, authorised representative, importer or distributor.”
Not a role. An umbrella for all six, used wherever the AI Act means any of them.
Read it as “deployer” and you’ll invert provisions. Article 111(2) applies the Regulation “to operators of high-risk AI systems” already in service, then names “the providers and deployers” specifically in its next sentence. The AI Act switches between the umbrella and the individual roles inside one paragraph.
Placing on the Market
Article 3(9):
“the first making available of an AI system or a general-purpose AI model on the Union market.”
The first supply. The AI Act hangs its dates on that single moment: legacy status, conformity assessment, CE marking, registration.
A distributor who sells the same system to a hundred customers hasn’t placed it on the market. They make it available. The provider or the importer did the placing.
Putting Into Service
Article 3(11):
“the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose.”
The same trigger as placing on the market, reached without a sale. Or for own use is the phrase that turns in-house builds into provider events.
It covers AI systems only. A general-purpose AI model can be placed on the market. It can’t be put into service.
Intended Purpose
Article 3(12):
“the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation.”
What the provider says the system is for, not what it’s used for. The AI Act names where it will look, and marketing copy is on the list.
Annex III classification runs on intended purpose. A disclaimer in the terms of service doesn’t fix a product page promising the excluded use: the Commission’s draft guidelines on high-risk classification say so.
Reasonably Foreseeable Misuse
Article 3(13):
“the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems.”
The provider owns this too. Declaring a narrow intended purpose doesn’t shed the uses a reasonable person would predict.
Substantial Modification
Article 3(23): a change after placing on the market or putting into service “which is not foreseen or planned in the initial conformity assessment carried out by the provider” and which affects compliance with Chapter III Section 2, or modifies the intended purpose the system was assessed for.
Size is irrelevant here. A small unplanned change is substantial. A large planned one isn’t. The only benchmark is what the initial conformity assessment foresaw.
Make one and Article 25(1)(b) makes you the provider.
The benchmark doesn’t exist for systems already running. A system placed on the market before Chapter III applies never had an initial conformity assessment, so nothing was foreseen or planned in one. That’s the Article 111(2) question.
Legacy status has one hard limit. Article 111(2) opens “without prejudice to the application of Article 5.” An exempt system doing something banned is doing something banned.
Risk
Article 3(2):
“the combination of the probability of an occurrence of harm and the severity of that harm.”
Probability times severity. A two-variable term, not a traffic-light colour.
“High-risk” is not a risk rating, and classification under Article 6(1) and 6(2) never asks you to assess either variable. It asks whether the system is a safety component under Annex I or falls in an Annex III use case.
The Article 3(2) meaning returns at the 6(3) derogation, which asks the risk question directly: an Annex III system isn’t high-risk “where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.” It also governs Article 9, the risk management system.
Classification is categorical. The way out of classification is a risk assessment.
Performance
Article 3(18):
“the ability of an AI system to achieve its intended purpose.”
Accuracy and latency don’t enter into it. Performance is defined against intended purpose, so a model with 99% accuracy on the wrong objective has no performance in the AI Act’s sense.
Article 15 accuracy and robustness are judged against this, which means a narrow declared purpose lowers the bar. Article 15 applies from December 2, 2027 for Annex III systems, August 2, 2028 for Annex I. Widen it later and Article 25 catches you: 25(1)(c) if the widening makes a not-high-risk system high-risk, 25(1)(b) if it was high-risk already.
Safety Component
Article 3(14), amended in July:
“a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property.”
The Omnibus added a tail:
“for the purposes of this definition, a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to health and safety of persons or property.”
One of two gateways to Annex I high-risk, the other being a system that is itself a product covered by Annex I. The Omnibus narrowed this one twice over. There are three new paragraphs in Article 6:
6(1a): systems “solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control” don’t qualify.
6(1b): systems whose failure “would endanger health and safety” do.
6(1c): a product needing third-party conformity assessment “solely due to risks other than risks to health and safety,” radio spectrum and electromagnetic interference among them, doesn’t satisfy 6(1)(b).
Quality control is named. Annex I obligations start August 2, 2028.
The Role Chain Past Provider and Deployer
The Omnibus left all five definitions alone. It did amend what attaches to them: Articles 25 and 43 both changed.
Authorised Representative
Article 3(5): a person
“located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model”
to carry out the provider’s obligations on its behalf.
A mandated agent who accepted the mandate in writing. Your EU subsidiary isn’t one, and neither is your local reseller.
Two separate obligations, both on third-country providers only:
Article 22(1), for high-risk systems: “Prior to making their high-risk AI systems available on the Union market, providers established in third countries shall, by written mandate, appoint an authorised representative which is established in the Union.”
Article 54(1), for general-purpose AI models.
Article 54 has applied since August 2, 2025. Article 22 applies from December 2, 2027 for Annex III systems, August 2, 2028 for Annex I.
Importer
Article 3(6): a person
“located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country.”
Buying from a US vendor doesn’t make you one. You have to be EU-established and it has to be you doing the placing on the market. If the third-country provider places its own system on the Union market directly, there’s no importer in the chain.
The definition says “an AI system.” There’s no importer role for general-purpose AI models, where Article 3(9) covers both.
Importer obligations sit in Article 23 and start December 2, 2027.
Distributor
Article 3(7): anyone
“in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market.”
A residual category, defined by exclusion. No contract required.
Same omission as the importer: AI systems only, no distributor role for models. Two roles were extended to models and two weren’t, which looks deliberate but who knows.
Distributor obligations sit in Article 24 and start December 2, 2027.
Product Manufacturer
Not defined in Article 3, despite being one of the six operators.
It appears in Article 2(1)(e), and in Article 25(3), which makes the product manufacturer the provider where a high-risk AI system is a safety component of a product covered by Section A of Annex I.
Section A is the operative word. Section B products (aviation, motor vehicles, rail, marine) get a thinner regime, and the Omnibus moved machinery from A to B. Moved, not released: Article 5, Article 50 and Chapter V still apply.
Downstream Provider
Article 3(68):
“a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.”
A provider, of an AI system, positioned below a model. It’s heard as “the customer,” which it isn’t. It also covers vertical integration, so a company that builds its own model and its own system on top is a downstream provider of itself.
The consequence is the information you’re owed. Article 53(1)(b) requires model providers to give downstream providers what they need “to have a good understanding of the capabilities and limitations of the general-purpose AI model and to comply with their obligations pursuant to this Regulation.” Call yourself a deployer and you won’t know to ask. Article 53 has applied since August 2, 2025.
Terms That Get Used Interchangeably
AI System
Article 3(1):
“a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.”
The core unit of the Regulation. Almost everything in Chapters II, III and IV attaches to this and not to a model.
AI Model
Not defined in the AI Act. The phrase is used and never explained: inside Article 3(63), inside Article 3(68), and in Article 2. The Omnibus added it to Article 25(4) in July, to the list of things a third party can supply into a high-risk system. A new obligation hung on an undefined word, two years after the AI Act passed.
The AI Act does explain the relationship, just not in a definition. Recital 97: “Although AI models are essential components of AI systems, they do not constitute AI systems on their own. AI models require the addition of further components, such as for example a user interface, to become AI systems.”
In ordinary technical use that means the model is the trained artefact, the weights and architecture that turn an input into an output, and the system is the model plus what makes it usable.
Only one kind of model is regulated as a model, and that’s the general-purpose kind. A narrow single-task model that isn’t part of any system sits outside both regimes.
General-Purpose AI Model
Article 3(63):
“an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market.”
Two limbs get dropped when this is quoted: integration into a variety of downstream systems, and the research and prototyping carve-out. Both are in the definition.
The indicative threshold is 10^23 floating-point operations of training compute, in the Annex to Commission Decision C(2025) 5045 final of 18 July 2025. Guidance, not law.
Obligations for model providers, Articles 53 to 55, have applied since 2 August 2025. Models placed on the market before that date have until 2 August 2027.
“We built it ourselves and only we use it” is an exit with three conditions. Recital 97: where a provider “integrates an own model into its own AI system that is made available on the market or put into service, that model should be considered to be placed on the market.” The carve-out applies only where the model is used “for purely internal processes” that are “not essential for providing a product or a service to third parties” and where “the rights of natural persons are not affected.” A bank running an own model behind a customer-facing service fails the second condition. A model scoring employees fails the third.
General-Purpose AI System
Article 3(66):
“an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems.”
A system built on a general-purpose model. It can be high-risk under Article 6 like any other system, and the model underneath it stays on its own separate track of obligations.
Model duties started August 2, 2025. Annex III system duties start December 2, 2027. Annex I system duties start 2 August 2028.
High-Risk AI System
Not defined in Article 3. Article 6 decides it instead, by two routes.
Article 6(1), the product route: the system is “intended to be used as a safety component of a product,” or is itself a product, covered by the “Union harmonisation legislation” listed in Annex I, and that product must undergo third-party conformity assessment. Note the words “intended to be used as.” Classification runs on intended purpose here too.
Article 6(2), the use-case route: the system falls within Annex III. Eight areas: biometrics, critical infrastructure, education and vocational training, employment, access to essential private and public services, law enforcement, migration and border control, administration of justice and democratic processes.
Article 6(3) is the way out of the Annex III route, for systems that don’t “pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making.”
But the AI system also has to fit at least one of four listed conditions:
“intended to perform a narrow procedural task,”
“intended to improve the result of a previously completed human activity,”
“intended to detect decision-making patterns or deviations from prior decision-making patterns” without replacing a human assessment, or
“intended to perform a preparatory task to an assessment.” Every one of them turns on intended purpose again.
However: “Notwithstanding the first subparagraph, an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons.”
For most Annex III systems that touch individuals, profiling closes the door before the first exemption opens. Take the derogation anyway and Article 6(4) requires you to document the assessment.
Neither route asks how risky the system is in the ordinary sense. Provider and deployer obligations for Annex III systems start December 2, 2027, and for Annex I systems August 2, 2028.
Systemic Risk
Article 3(65):
“a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole.”
This attaches to general-purpose AI models and to nothing else. It isn’t a worse tier of high-risk, and an AI system can’t enter the category. A hiring tool is never a systemic-risk anything.
Article 51(2) sets the presumption: a model is presumed to have high-impact capabilities when training compute is “greater than 10^25” floating-point operations. That one is in the AI Act, not in guidance.
Two separate ladders. High risk runs through Article 6 and Chapter III, from December 2027. Systemic risk runs through Articles 51 and 55, since August 2025.
Classification and Role
Neither is defined.
Classification is a property of the system: prohibited under Article 5, high-risk under Article 6, transparency-triggering under Article 50, or none of those.
Role is a property of you: provider, deployer, importer, distributor, authorised representative, product manufacturer.
Your obligations are the product of the two. High-risk plus provider is Article 16. High-risk plus deployer is Article 26. Not-high-risk plus provider is still a documented assessment under Article 6(4) and a registration under Article 49(2).
Those last two arrive on different dates. Article 49(2) sits in Chapter III Section 5, which Article 113 doesn’t defer, so it has been in application since August 2, 2026. Article 6(4), which produces the assessment it registers, arrives sixteen months later.
“Is our AI high-risk?” is usually unanswerable as asked. It’s a role question in a classification question’s clothes.
Conformity Assessment, CE Marking, Notified Body
Three terms, three definitions, and they aren’t steps in one process.
Conformity assessment, Article 3(20): “the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled.” The demonstrating, by whoever has to do it.
CE marking, Article 3(24): “a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing.” A provider indicates. Not an assessor.
Notified body, Article 3(22): “a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation.” The second half is why one body can be notified for medical devices and for the AI Act at once. Required for very little on the Annex III side, as the closing section sets out.
Again it applies from December 2, 2027 for Annex III systems, August 2, 2028 for Annex I.
FRIA
Fundamental Rights Impact Assessment. The abbreviation is a practitioner invention. The AI Act writes the phrase out, in the heading of Article 27, in Article 27(2) and in Article 5(2), and never abbreviates or defines it. Article 27(1) simply requires certain deployers to perform “an assessment of the impact on fundamental rights that the use of such system may produce,” then lists six things it has to contain.
It’s a two-condition test and both conditions get dropped.
The system has to be one “referred to in Article 6(2),” which means Annex III. A FRIA never attaches to an Annex I high-risk system, however public the deployer. Annex III point 2, critical infrastructure, is exempt even then.
The deployer has to be a body governed by public law, a private entity providing public services, or a deployer of an Annex III point 5(b) or 5(c) system, which is credit scoring and life and health insurance. Fail either condition and you owe no FRIA.
You don’t do one per deployment. Article 27(2): the obligation “applies to the first use of the high-risk AI system,” and the deployer “may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider.” If the elements change or go stale, you update.
Applies from December 2, 2027.
DPIA
Data Protection Impact Assessment. It’s not an AI Act instrument. GDPR Article 35 requires one where processing is likely to result in a high risk to people’s rights and freedoms, and it assesses the processing of personal data.
The difference in one line: a DPIA asks what your processing does to personal data. A FRIA asks what the system’s use does to fundamental rights, which is broader and covers people whose data you never process.
They overlap, and the Omnibus changed how. The amended Article 27(4) is permissive: where a DPIA already meets one of the Article 27 obligations, the deployer “may” cross-reference the relevant sections or include relevant parts. The older text said the FRIA “shall complement” the DPIA. That sentence is gone, so an alert quoting it predates the Omnibus.
What a DPIA can’t reach is the elements it doesn’t cover, and two of the six aren’t GDPR territory: 27(1)(b), the period and frequency of intended use, and 27(1)(e), the human oversight measures.
Article 27(5) has the AI Office building “a template for a questionnaire, including through an automated tool,” to let deployers comply “in a simplified manner.” That has been in the AI Act since 2024.
The binding link runs the other way. Article 26(9): deployers of high-risk systems “shall use the information provided under Article 13 of this Regulation to comply with their obligation to carry out a data protection impact assessment.” FRIA to DPIA is optional. Article 13 information to DPIA is mandatory.
Quality Management System
Article 17(1): “Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation.” The paragraph then lists what it has to contain, starting with “a strategy for regulatory compliance.”
This is what the AI Act actually names, and it’s owed by providers of high-risk systems only. Not an AI policy. Not a governance framework.
It’s specific enough that another regime can be deemed to satisfy it. Article 17(4): providers that are financial institutions subject to internal governance requirements under Union financial services law are deemed to satisfy the QMS obligation by complying with those governance rules, except for risk management, post-market monitoring and serious-incident reporting. The deeming is conditional on the complying.
Applies December 2, 2027.
Training, Validation, Testing and Input Data
Four defined terms for what usually gets called one.
Training data, Article 3(29): “data used for training an AI system through fitting its learnable parameters.”
Validation data, Article 3(30): data for evaluating the trained system and tuning its non-learnable parameters, “in order, inter alia, to prevent underfitting or overfitting.”
Testing data, Article 3(32): data for “an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service.”
Input data, Article 3(33): “data provided to or directly acquired by an AI system on the basis of which the system produces an output.”
The first three are the provider’s, under Article 10 data governance. Input data is the deployer’s, under Article 26(4), which scopes it: “to the extent the deployer exercises control over the input data,” the deployer ensures it’s “relevant and sufficiently representative in view of the intended purpose.”
Feed your own records into a bought-in system and that’s yours. If the system pulls its inputs from a third-party feed, arguably it isn’t. Both provisions apply December 2, 2027.
Other Words
Three of these do appear in the AI Act but are not defined.
Shadow AI
Not in the AI Act, or anywhere in EU law. Industry shorthand for employees using AI tools their organization never approved or inventoried.
The AI Act’s nearest equivalent is the deployer test: a system used “under its authority.” Corporate card, corporate work, and the employer is almost certainly the deployer. Personal account on a personal device producing work output is genuinely open.
Article 4, amended in July, has providers and deployers taking “measures to support the development of AI literacy” of staff and others operating systems on their behalf. The amendment also added: “This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.”
Article 50(3) and 50(4) deployer transparency duties have applied since August 2, 2026. An employee producing a deep fake on an unapproved tool is a live disclosure question now.
You can’t train staff on AI systems you don’t know exist, and the AI Act has no word for the systems you don’t know exist.
AI Tool
Not in the AI Act. Not defined, not a category, not a threshold.
In general use it means a piece of software with AI in it. The AI Act’s test is Article 3(1), which asks nothing about price, size or procurement. A twenty-euro browser extension that infers outputs influencing decisions is an AI system.
It usually arrives with a companion sentence: “so we’re just users.” There’s no user role.
Algorithm
In the AI Act once, and not as a category. Annex IV point 2(b) requires technical documentation to describe “the general logic of the AI system and of the algorithms.” Something you document, never something you classify.
Outside the AI Act it covers any defined computational procedure, from a sorting routine to a neural network. That breadth is why it’s useless as a legal test.
“It’s just an algorithm, not AI” isn’t an argument the Regulation recognizes, because it never asks the question. It asks the Article 3(1) question. The nearest thing to a real exclusion is in the Commission’s guidelines on the AI system definition, the Annex to Commission Decision C(2025) 924 final of 6 February 2025, which is non-binding and gives “linear or logistic regression methods” as an example of systems for improving mathematical optimization. Whether that gets your model out is contested.
User
Deleted from the AI Act. “User” was the term in the European Commission’s 2021 proposal. The final text replaced it with “deployer,” and no obligation attaches to a user anywhere.
The word survives only in compounds, like Annex IV’s “user-interface provided to the deployer” and Article 6(1a)’s “user assistance.”
Every vendor document that says “the user is responsible for X” allocates to a role that doesn’t exist. Between the two of you it may still work as a contract. It tells a regulator nothing about who the deployer is.
AI Governance Framework
Not a term of art in the AI Act. “Governance” appears as data governance in Article 10(2), as “arrangements for internal governance and complaint mechanisms” inside the FRIA contents, and as “internal governance, arrangements or processes” in the financial-institution provisions. Chapter VII is headed governance and covers the AI Office and national authorities, which is the regulator’s governance rather than yours.
Companies use it for the whole internal apparatus: policies, committees, inventories, sign-off gates.
The Article 17 QMS. The Article 9 risk management system. The Article 27 FRIA. And the Article 26(2) assignment of human oversight to people with “the necessary competence, training and authority,” which means a person you can name.
A framework can hold all four. It’s the container, and nothing in the AI Act requires the container.
However, article 26(1) requires “appropriate technical and organisational measures,” Article 26(2) requires the oversight staffing, and Article 4 already applies. But a policy is the ordinary way of discharging all three.
Are You Compliant with the AI Act?
Article 43(2):
“For high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body.”
Points 2 to 8 is every high-risk use case except biometrics. Critical infrastructure. Education. Employment. Essential private and public services, which is where credit scoring and life and health insurance sit. Law enforcement. Migration. Justice.
You assess yourself. You affix your own marking. “Audit” appears once in the whole machinery, at Annex VII point 5.3, on the notified body route that points 2 to 8 can’t use.
Real certificates exist under Annex VII for Annex I products and Annex III point 1, and Article 42(2) recognizes a cybersecurity certificate once its scheme is published in the Official Journal. Neither is what a vendor means by AI Act certified for a hiring tool.
For that there’s no certificate and no one to issue it. Only you, signing your own declaration against requirements that don’t apply until December 2, 2027, in words the AI Act defined and your vendor didn’t.
Like this article? The AI Governance Roadmap is something you can use in practice. It’s a company’s roadmap with steps and working documents. It includes the classification, the inventory spreadsheet, the role assignment, the vendor questions, the AI policy template. Everything a company needs to govern AI, at one place.






