Reference
EU Compliance Glossary
A working dictionary of the terms that appear in EU compliance documentation — NIS2, DORA, the AI Act and the regulation around them. Each entry gives a one-line definition you can quote, a short explanation, why it matters, and links to the pages where the term matters in practice.
A
- AI Act·AI Act overview
Regulation (EU) 2024/1689, the EU's law on artificial intelligence, regulating AI systems according to the risk they pose.
- AI Literacy·What high-risk AI requires
The Article 4 duty, in force since February 2025, to ensure staff working with AI systems have sufficient AI knowledge and skills.
- AI Office·AI Act fines and enforcement
The European Commission body that supervises general-purpose AI models and coordinates AI Act enforcement across the EU.
- Annex III (AI Act)·The AI Act risk pyramid
The AI Act's list of use-case areas in which AI systems are classified as high-risk.
C
- CE Marking (AI Act)·What high-risk AI requires
The conformity mark that high-risk AI systems must carry before being placed on the EU market, signalling compliance with the AI Act.
- Conformity Assessment·What high-risk AI requires
The process of verifying that a high-risk AI system meets the AI Act's requirements before it can be CE-marked and sold in the EU.
F
- FRIA (Fundamental Rights Impact Assessment)·What high-risk AI requires
An assessment of the impact on fundamental rights that certain deployers must complete before using a high-risk AI system.
G
- GPAI (General-Purpose AI)·General-purpose AI models (GPAI)
AI models trained for broad capability and usable across many tasks, subject to their own obligations under the AI Act since August 2025.
H
- High-Risk AI System·The AI Act risk pyramid
An AI system in a use case listed by the AI Act as high-risk, subject to the law's full compliance regime.
N
- Notified Body·What high-risk AI requires
An independent organisation designated by a member state to perform third-party conformity assessments of certain high-risk AI systems.
P
- Prohibited AI Practices·The AI Act risk pyramid
The AI uses banned outright under Article 5 of the AI Act, applicable since 2 February 2025.
- Provider vs Deployer·Who must comply with the AI Act
The AI Act's two central roles: the provider develops or places an AI system on the market; the deployer uses it under its own authority.
R
- Regulatory Sandbox·Who must comply with the AI Act
A controlled environment, run by authorities, where AI systems can be developed and tested under regulatory supervision before market launch.
- Risk-Based Approach·AI Act overview
The AI Act's structure of four risk tiers — unacceptable, high, limited, and minimal — with obligations scaled to each.
S
- Systemic Risk (GPAI)·General-purpose AI models (GPAI)
The AI Act's designation for the most capable general-purpose AI models, whose reach could cause large-scale harm across the EU.
T
- Transparency Obligations (Article 50)·The AI Act risk pyramid
The AI Act duties to disclose when people interact with AI, and when content is AI-generated or manipulated.
