Glossary

The words that decide what you owe.

24 terms, each with the article it comes from. These are plain-English restatements written to be understood, not the legal text — where a definition decides something, read the provision itself. Veritome is not legal advice.

01

Who you are

Role decides your duty set, and it attaches to a system rather than to a company. Most organisations hold more than one.

Provider

Art. 3(3)

Whoever develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark. The heaviest role.

Deployer

Art. 3(4)

Whoever uses an AI system under their own authority, other than in a personal non-professional activity. The role most organisations actually hold.

Importer

Art. 3(6)

Someone in the Union placing on the market an AI system that bears the name or trademark of a provider established outside it.

Distributor

Art. 3(7)

Anyone else in the supply chain who makes an AI system available on the market, other than the provider or the importer.

Operator

Art. 3(8)

The collective term: provider, deployer, importer, distributor or authorised representative. Used where a duty falls on more than one role.

Authorised representative

Art. 3(5)

A person in the Union appointed in writing by a provider outside it, to carry out the obligations the Regulation places on that provider.

02

What the thing is

Scope questions. Whether the Regulation applies at all, and in which class.

AI system

Art. 3(1)

A machine-based system designed to operate with varying autonomy, that may adapt after deployment, and that infers from its input how to generate outputs — predictions, content, recommendations or decisions — which can influence its environment.

General-purpose AI model

Art. 3(63)

A model showing significant generality, capable of performing a wide range of distinct tasks, that can be integrated into downstream systems. The obligations on these have applied since 2 August 2026.

High-risk

Art. 6, Annex III

Either an AI system that is a safety component of a product covered by the Annex I legislation, or one used in an Annex III area — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.

Prohibited practice

Art. 5

Uses banned outright, with no conformity route that makes them permissible — among them social scoring, untargeted facial-image scraping, and inferring emotions in the workplace or in education. In force since 2 February 2025.

Intended purpose

Art. 3(12)

The use the provider intends, as stated in the instructions, the marketing material and the technical documentation. It governs what a deployer may lawfully do with the system.

Substantial modification

Art. 3(23)

A change after placing on the market that is not foreseen in the provider's initial assessment and affects compliance or the intended purpose. It can make the modifier the provider.

03

What you have to produce

The artefacts. Most are the provider's; two are the deployer's.

Technical documentation

Art. 11, Annex IV

The file that shows a high-risk system meets the requirements — system description, development process, risk management, data, oversight design, accuracy and robustness evidence.

Instructions for use

Art. 13

What the provider must give the deployer: capabilities, limitations, intended purpose, oversight measures, expected lifetime. Without them a deployer cannot discharge its own Art. 26 duty.

Declaration of conformity

Art. 47

The provider's written statement that the system meets the requirements, kept for ten years and given to authorities on request.

CE marking

Art. 48

The mark affixed by the provider claiming conformity. It is a claim by them, not a verification by anyone else — an importer still has to check what lies behind it.

FRIA

Art. 27

The fundamental-rights impact assessment, required of public bodies and of deployers of the Annex III creditworthiness and insurance-pricing systems. It may build on a DPIA under Art. 27(4).

DPIA

GDPR Art. 35

The data-protection impact assessment. Distinct from a FRIA and often required alongside it; the two overlap, and the Act says where the overlap counts.

04

Keeping it true

The duties that continue after go-live, which is where most programmes quietly stop.

Human oversight

Art. 14, Art. 26(2)

Designed in by the provider, exercised by the deployer through a named person with the competence and the authority to override an output.

Post-market monitoring

Art. 72

The provider's system for collecting and reviewing experience from systems in use, feeding back into risk management.

Serious incident

Art. 3(49), Art. 73

An incident or malfunction leading, directly or indirectly, to death, serious harm to health, serious disruption of critical infrastructure, breach of fundamental-rights obligations, or serious harm to property or the environment. Reportable on a clock that starts when you knew.

AI literacy

Art. 4

Skills, knowledge and understanding sufficient for staff to deploy AI informedly and be aware of its risks. It applies whatever the risk class — one of the few duties that is not tier-dependent.

Conformity assessment

Art. 43, Annex VI

The procedure demonstrating a high-risk system meets the requirements. Most Annex III systems take the internal-control route; some require a notified body.

Notified body

Art. 3(22)

A conformity-assessment body designated under the Regulation. Involved only where the third-party route applies.