Skip to main content

Techné AI · Free reference · Edition 3.0.0

Glossary of AI Governance Terms

Working definitions for AI governance, safety, privacy and regulation, with distinctions between explanatory language and authoritative legal definitions.

Reviewed Download complete PDF Corrections

These are plain-language working definitions, not verbatim ISO clauses or substitutes for statutory definitions. Similar words can have different meanings across frameworks. Follow the linked chapters and primary sources for the exact scope, conditions and applicable dates; classification depends on facts, not a glossary label.

Agentic AI

AI system designed to perform multi-step actions in pursuit of a goal, typically via tool use, code execution, or interaction with external systems. Distinguished from non-agentic AI by the ability to take autonomous actions beyond producing output for direct human use.

AI agent

A system that uses observations and available tools or actions to pursue objectives within an environment. Its actual autonomy depends on permissions, design and human oversight.

AI Act (EU)

Regulation (EU) 2024/1689 establishing harmonised AI rules. Entry into force, application dates and enforcement powers are distinct. See EU AI Act for the current timeline and amendment status.

AI component

A functional part of an AI system, such as a model, retrieval service, data-processing step or evaluation component. Its dependencies and role should be documented.

AI Office (EU)

A European Commission office supporting AI Act implementation, including GPAI oversight. It was established in 2024; 2 August 2025 was an application milestone for GPAI provisions, not its creation date. It does not replace every national competent authority. See EU AI Act.

AI Safety Institute / Center for AI Standards and Innovation (CAISI)

Organisations concerned with AI evaluation and safety or security research. The US CAISI and UK AI Security Institute have different mandates; a testing partnership is not automatically a regulatory approval. See Frontier Models.

Artificial intelligence (AI)

A broad field of engineered systems performing tasks associated with learning, inference, perception or reasoning. The precise legal definition depends on the instrument being applied.

Artificial intelligence system (AI system)

A deployed arrangement of models, data, software and other components producing outputs or actions. The system is not necessarily identical to its underlying model; applicable legal definitions may also address autonomy, adaptiveness and objectives.

Automated decision-making (ADM)

Decisions made or supported by automated processing, which need not use AI. “Solely automated” decision-making is a narrower legal category under GDPR Article 22, subject to qualifying effects, exceptions and safeguards. See Privacy.

Bias audit

An evaluation of specified disparities under a defined method. NYC Local Law 144 requires an independent bias audit for covered automated employment decision tools; it is not a complete finding that a hiring process is lawful or unbiased.

Conformity assessment

A process for demonstrating that specified requirements are fulfilled. EU AI Act routes for covered high-risk systems vary, including internal-control and notified-body procedures. ISO management-system certification is not automatically an AI Act conformity assessment.

Consequential decision

A term used in some laws for decisions affecting important opportunities or services. Its covered domains and thresholds depend on the statute. Do not apply the repealed Colorado SB 24-205 definition as current law; see US State Laws for the replacement regime.

Constitutional AI / RLAIF

Alignment technique using AI-generated feedback against an explicit set of principles to train models toward desired behaviour. Reduces reliance on human raters at scale.

Datasheet for dataset

Standardised documentation describing a dataset's motivation, composition, collection process, preprocessing, recommended uses, distribution, and maintenance. Proposed by Gebru et al. (2018); widely adopted as a transparency tool.

Differential privacy

A mathematical framework for bounding privacy loss under a specified mechanism, protected unit and privacy budget. Its guarantee depends on assumptions, implementation and composition; it is not a promise of zero disclosure. See Privacy.

Explainability

The ability to provide a useful, understandable account of a system's outputs or behaviour. An explanation can be plausible without being faithful; evaluate its audience, accuracy and limits.

Federated learning

Training across distributed datasets without pooling the raw records centrally. Shared updates can still reveal information, so privacy and security safeguards remain necessary.

Foundation model

A model trained on broad data that can be adapted for multiple tasks. “Foundation,” “general-purpose” and “frontier” overlap in everyday usage but are not interchangeable technical or legal classifications.

Frontier model

A context-dependent label for highly capable models. California SB 53 defines its own category; the EU uses GPAI and systemic-risk criteria. No single compute threshold defines “frontier” everywhere. See Frontier Models.

Fundamental Rights Impact Assessment (FRIA)

An assessment of effects on fundamental rights. EU AI Act Article 27 imposes a particular FRIA duty on specified deployers and uses. A general impact-assessment standard can help organise work but does not replace its legal requirements.

General-purpose AI (GPAI) model

The EU AI Act's model category based on significant generality and capability across distinct tasks, with further conditions and exclusions in Article 3(63). Not every GPAI model presents systemic risk. See EU AI Act.

GPAI Code of Practice

A voluntary tool to help demonstrate compliance with binding EU GPAI obligations. Its three chapters cover Transparency, Copyright, and Safety and Security; chapter coverage and implementation matter, not just signature status. See Frontier Models.

Hallucination

Generation of plausible but factually incorrect or fabricated output by a generative AI model. Mitigated through retrieval grounding, output verification, and clearer uncertainty signalling.

High-risk AI system (EU AI Act)

A system meeting Article 6 classification rules, including certain product-safety and Annex III uses. Merely appearing in a sector list does not answer every scope question; exceptions and application dates matter. See EU AI Act.

Impact assessment (AI)

Structured evaluation of an AI system's effects on individuals, groups, and society, covering risks, stakeholder analysis, fundamental-rights impacts, and mitigations. Standardised in ISO/IEC 42005:2025.

Interpretability

Understanding how a system or model produces its behaviour, using intrinsic structure or analytical methods. Its boundary with explainability varies by discipline; neither label guarantees a causal or complete explanation.

ISO/IEC 42001

A certifiable AI management-system standard published in 2023. Certification concerns a defined organisational scope, not proof that all AI products are safe or legally compliant. See ISO Standards.

Machine learning (ML)

Computational methods that fit patterns or decision rules from data or experience, rather than specifying every rule manually. Learning does not imply human-like understanding.

Model card

A documentation format describing intended use, evaluations, limitations and other model information. It can support required disclosures, but a model card is not automatically equivalent to technical documentation, a training-data summary or a statutory transparency report.

NIST AI Risk Management Framework (RMF)

A voluntary framework published in January 2023 with four functions: Govern, Map, Measure and Manage. The July 2024 Generative AI Profile (NIST AI 600-1) is a companion resource. Distinguish it from NIST cybersecurity publications and check each publication's draft or final status. See US Federal.

Reinforcement Learning from Human Feedback (RLHF)

Alignment technique training models using human preference signals. Widely deployed for instruction-following and value alignment in large language models.

Responsible Scaling Policy (RSP)

Frontier developer's published commitment to specific capability evaluations and risk thresholds, with mitigation actions triggered at defined thresholds. Originated with Anthropic; adopted in different forms by other frontier developers.

Risk-based regulation

An approach that calibrates duties to specified risks, actors or uses. Each law defines its own scope and thresholds; a low-risk label under one framework does not establish an exemption elsewhere.

Safety case

A structured claim, argument and supporting evidence about safety in a defined context, including assumptions and residual risks. It is not a guarantee of safety or identical to California SB 53's statutory transparency report. See Technical Safety.

Systemic risk (EU AI Act)

A defined EU GPAI risk category. Training above 10²⁵ floating-point operations triggers a presumption of high-impact capabilities; Commission designation and the Article 52 procedure also matter. See Frontier Models.

Trustworthiness (in AI)

A context-dependent assessment of whether a system merits reliance, considering validity, reliability, safety, security, accountability, transparency, explainability, privacy and fairness. Trade-offs and evidence matter; no single score settles all of these.

Sources and scope

Use the chapter citations for legal terms. Foundational references include NIST AI RMF, Regulation (EU) 2024/1689 and ISO/IEC 42001. The Commission’s 2024 AI Office establishment decision and Colorado’s enacted SB 26-189 support the historical corrections above. These working definitions do not reproduce licensed ISO terminology or claim clause-by-clause conformity.

This free handbook is a dated educational reference, not a determination of your organization's obligations. Check the source, jurisdiction and role before applying a requirement. For working documents, see TalentSight Intelligence and BoardSight Intelligence.