{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/glossary.json",
  "self": "https://aigovernanceengineer.com/api/v1/glossary.json",
  "source": "https://aigovernanceengineer.com/bok/glossary",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "terms": [
    {
      "id": "t-a2a-agent2agent-protocol",
      "term": "A2A (Agent2Agent protocol)",
      "definition": "An open protocol for agents to hand tasks to one another, at version 1.0 since March 2026 and a Growth Stage project of the Linux Foundation-directed Agentic AI Foundation since August 2026. Servers must authenticate every request, but authorisation, and the scope and revocation of authority granted mid-task, are left to the implementer.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/a2a-agent2agent-protocol",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-a2a-agent2agent-protocol",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-abstention-band",
      "term": "Abstention band",
      "definition": "A range of scores in which a system does not act on its own but routes the case to a human reviewer. Its width is set by risk tier; the band size and the reviewers' override rate are monitored as signals. Conformal prediction gives one way to size it.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/abstention-band",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-abstention-band",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-acceptable-use-policy-aup",
      "term": "Acceptable-use policy (AUP)",
      "definition": "The staff-facing rules for using AI tools: which tools are approved, which data classes may go where, duties to review and disclose outputs, logging, attestation before access and consequences. It is enforced through a sanctioned gateway and discovery, not the handbook alone.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/acceptable-use-policy-aup",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-acceptable-use-policy-aup",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-adaptiveness",
      "term": "Adaptiveness",
      "definition": "The ability of an AI system to change its behaviour while in use, through learning after deployment; optional under the EU AI Act definition. For governance it is one change trigger among several: most behaviour change in practice comes from vendor updates, drift, prompt edits or corpus refreshes.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/adaptiveness",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-adaptiveness",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-admt-california",
      "term": "ADMT (California)",
      "definition": "Automated decisionmaking technology under the California CCPA regulations: technology that processes personal information and uses computation to replace, or substantially replace, human decision-making. Using it for significant decisions triggers pre-use notice, opt-out or appeal, access and risk-assessment duties.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/admt-california",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-admt-california",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-adverse-action-notice",
      "term": "Adverse action notice",
      "definition": "The notice a US creditor must give when it denies or worsens credit, stating the specific principal reasons. The reasons must be accurate even when the decision comes from a complex model, so reason codes need a fidelity test.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/adverse-action-notice",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-adverse-action-notice",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-adverse-impact-ratio-air",
      "term": "Adverse-impact ratio (AIR)",
      "definition": "The selection rate of a group divided by the selection rate of the most-selected group. Under the US Uniform Guidelines a ratio below four-fifths is generally treated as evidence of adverse impact; engineering practice reads it as a trigger for investigation, reported with counts and a confidence interval.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/adverse-impact-ratio-air",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-adverse-impact-ratio-air",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-aesia",
      "term": "AESIA",
      "definition": "Spain's Agencia Española de Supervisión de Inteligencia Artificial, a state agency based in A Coruña whose statute was approved by Royal Decree 729/2023, created to act as Spain's national supervisory authority for the AI Act.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/aesia",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-aesia",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-agent-agentic-ai",
      "term": "Agent (agentic AI)",
      "definition": "An AI system that acts (browses, executes code, calls APIs, moves data or delegates to other agents) under delegated authority, rather than only producing text. Agents are the hardest object to govern because their behaviour is emergent and their actions have external effects.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/agent-agentic-ai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-agent-agentic-ai",
      "chapters": [
        {
          "number": "01",
          "url": "https://aigovernanceengineer.com/bok/definition"
        },
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-agent-card",
      "term": "Agent Card",
      "definition": "The JSON document an A2A agent publishes, usually at /.well-known/agent-card.json, describing its identity, skills, service endpoint and the authentication schemes it accepts. It can be signed with JWS over a canonicalised form, so a client can check that the card is untampered and comes from the claimed provider. A peer allow-list admits only registered agents with verified cards.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/agent-card",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-agent-card",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-agent-registry",
      "term": "Agent registry",
      "definition": "The runtime-aware inventory of every non-human actor (model, service and agent), each with an owner, a declared scope, a status and a kill switch, fed by a runtime data path rather than typed by hand. It is the artefact that answers \"what AI is running?\".",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/agent-registry",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-agent-registry",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-ai-act-eu",
      "term": "AI Act (EU)",
      "definition": "Regulation (EU) 2024/1689, the EU's horizontal, risk-tiered law for AI, amended by the Digital Omnibus. It classifies systems by risk (prohibited, high-risk, limited, minimal) and imposes obligations accordingly.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-act-eu",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-act-eu",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-ai-business-operator-korea",
      "term": "AI business operator (Korea)",
      "definition": "Under the Korean AI Basic Act, a legal person, organisation, individual or state body doing AI business, split into development business operators, who develop and provide AI, and utilisation business operators, who offer products or services built on it.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-business-operator-korea",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-business-operator-korea",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-ai-governance",
      "term": "AI governance",
      "definition": "The set of rules, roles, controls and evidence that keeps AI systems within the limits an organisation or a state has chosen. It decides which systems may run and what they may do, and draws on law such as the AI Act, management-system standards, risk frameworks and principle sets.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-governance",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-governance",
      "chapters": [
        {
          "number": "01",
          "url": "https://aigovernanceengineer.com/bok/definition"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-ai-governance-committee",
      "term": "AI governance committee",
      "definition": "The cross-functional body that takes the decisions a gate cannot: accepting residual risk above a product owner's authority, granting exceptions, weighing value trade-offs and approving the policy set. It decides; the pipeline's gates enforce its decisions and record the evidence. US federal agencies run such boards by mandate.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-governance-committee",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-governance-committee",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-ai-governance-engineer",
      "term": "AI governance engineer",
      "definition": "The person who holds the capability of AI governance engineering and is accountable for the three questions in production; a capability and a role, not necessarily a job title.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-governance-engineer",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-governance-engineer",
      "chapters": [
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        }
      ]
    },
    {
      "id": "t-ai-governance-engineering",
      "term": "AI governance engineering",
      "definition": "The application of engineering practice (systems thinking, product thinking and code) to the governance of AI systems; measured by realised risk reduction and audit-ready evidence.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-governance-engineering",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-governance-engineering",
      "chapters": [
        {
          "number": "01",
          "url": "https://aigovernanceengineer.com/bok/definition"
        }
      ]
    },
    {
      "id": "t-ai-harm",
      "term": "AI harm",
      "definition": "A negative consequence of building or using an AI system for a person, a group, an organisation, society or the environment. The book names each harm by the level it lands on, its mechanism, a testable failure mode and the control that catches it, mapped to the MIT AI Risk Repository taxonomy.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-harm",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-harm",
      "chapters": [
        {
          "number": "03",
          "url": "https://aigovernanceengineer.com/bok/values-and-principles"
        }
      ]
    },
    {
      "id": "t-ai-hazard",
      "term": "AI hazard",
      "definition": "In the OECD's definition, an event or series of events where the development, use or malfunction of an AI system could plausibly lead to an AI incident. A hazard is harm that has not happened yet; a near miss is a hazard a control interrupted.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-hazard",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-hazard",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-ai-incident",
      "term": "AI incident",
      "definition": "In the OECD's definition, an event or series of events where the development, use or malfunction of one or more AI systems directly or indirectly leads to harm to health, critical infrastructure, human or fundamental rights, property, communities or the environment.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-incident",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-incident",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-ai-literacy",
      "term": "AI literacy",
      "definition": "Under the EU AI Act, the skills, knowledge and understanding that let providers, deployers and affected persons use AI in an informed way and grasp its opportunities, risks and possible harm. Article 4, as amended in 2026, requires providers and deployers to take measures to support it, without guaranteeing any individual level.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-literacy",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-literacy",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-ai-office",
      "term": "AI Office",
      "definition": "The European Commission body that supervises general-purpose AI and coordinates AI Act enforcement, with investigation powers and the ability to levy penalties on GPAI providers.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-office",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-office",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-ai-regulatory-sandbox",
      "term": "AI regulatory sandbox",
      "definition": "Under the EU AI Act, a controlled framework set up by a competent authority in which providers develop, train, test and validate innovative AI systems for a limited time under a sandbox plan, possibly with real-world testing. Each Member State must have one operational by 2 Aug 2027.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-regulatory-sandbox",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-regulatory-sandbox",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-ai-rmf-functions",
      "term": "AI RMF functions",
      "definition": "The four core functions of the NIST AI Risk Management Framework (Govern, Map, Measure, Manage), used throughout the book as a mapping target for controls.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-rmf-functions",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-rmf-functions",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-ai-rmf-playbook",
      "term": "AI RMF Playbook",
      "definition": "NIST's online companion to the AI RMF. For each subcategory it gives an About note, suggested actions, transparency and documentation questions and references. It is voluntary material to tailor, not a checklist; its documentation questions work well as acceptance criteria.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-rmf-playbook",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-rmf-playbook",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-ai-rmf-profile",
      "term": "AI RMF profile",
      "definition": "An application of the AI RMF Core to a context. NIST describes use-case profiles, temporal profiles (a current and a target profile whose gap guides the work) and cross-sectoral profiles such as NIST AI 600-1 for generative AI.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-rmf-profile",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-rmf-profile",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-ai-system",
      "term": "AI system",
      "definition": "For governance, the object the AI definition brings into scope. Under the EU AI Act, a machine-based system designed to operate with some autonomy, possibly adaptive after deployment, that infers from its input how to generate outputs that can influence physical or virtual environments. Inference separates it from rule-based software.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-system",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-system",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-ai-system-impact-assessment",
      "term": "AI system impact assessment",
      "definition": "An assessment of how an AI system and its foreseeable applications may affect individuals, groups and society, performed across the lifecycle and updated as needed; ISO/IEC 42005:2025 gives the guidance. Often called an AI impact assessment (AIIA).",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-system-impact-assessment",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-system-impact-assessment",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-ai-system-lifecycle-oecd",
      "term": "AI system lifecycle (OECD)",
      "definition": "The OECD's iterative phases of an AI system: plan and design; collect and process data; build or adapt models; test, evaluate, verify and validate; deploy; operate and monitor; retire or decommission. Retirement can happen at any point during operation.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-system-lifecycle-oecd",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-system-lifecycle-oecd",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-ai-washing",
      "term": "AI washing",
      "definition": "Overstating or inventing the use or capability of AI in marketing or investor communications. US regulators treat it as deception; the SEC settled charges against two investment advisers over such claims in March 2024.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/ai-washing",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ai-washing",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-aibom",
      "term": "AIBOM",
      "definition": "AI bill of materials: the machine-readable inventory of an AI system's components (models, datasets, dependencies) in formats such as CycloneDX ML-BOM or the SPDX 3.0 AI profile.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/aibom",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-aibom",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        }
      ]
    },
    {
      "id": "t-aicm",
      "term": "AICM",
      "definition": "The CSA AI Controls Matrix, a control framework (v1.1, 247 control objectives across 18 domains) that maps to ISO 42001, ISO 27001 and NIST AI RMF and underpins STAR for AI.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/aicm",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-aicm",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        }
      ]
    },
    {
      "id": "t-aima",
      "term": "AIMA",
      "definition": "The OWASP AI Maturity Assessment, reported at v1.0 (Aug 2025), which scores the breadth of an AI security and governance programme across domains.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/aima",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-aima",
      "chapters": [
        {
          "number": "07",
          "url": "https://aigovernanceengineer.com/bok/maturity-model"
        }
      ]
    },
    {
      "id": "t-aims",
      "term": "AIMS",
      "definition": "An AI management system: the governance structure, roles, controls and continual-improvement loop that ISO/IEC 42001 certifies. An AIMS is not the AI Act's Article 17 quality management system.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/aims",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-aims",
      "chapters": [
        {
          "number": "07",
          "url": "https://aigovernanceengineer.com/bok/maturity-model"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-algorithmic-disgorgement",
      "term": "Algorithmic disgorgement",
      "definition": "A remedy that orders deletion of models or algorithms developed with unlawfully obtained data, not only the data itself. Complying, and proving it, requires lineage from each dataset to every model trained on it.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/algorithmic-disgorgement",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-algorithmic-disgorgement",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-algorithmic-impact-assessment-aia",
      "term": "Algorithmic Impact Assessment (AIA)",
      "definition": "The assessment Canada's Directive on Automated Decision-Making requires before a federal automated decision system goes into production. It sets an impact level from I to IV that scales the required safeguards, is published on the Open Government Portal and is updated when the system changes.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/algorithmic-impact-assessment-aia",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-algorithmic-impact-assessment-aia",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-algorithmic-management",
      "term": "Algorithmic management",
      "definition": "The use of automated monitoring and decision systems to direct, evaluate or sanction workers. The EU Platform Work Directive limits the data such systems may process and requires transparency, human oversight and a right to human review.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/algorithmic-management",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-algorithmic-management",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-algorithmic-transparency-recording-standard-atrs",
      "term": "Algorithmic Transparency Recording Standard (ATRS)",
      "definition": "The UK's standard template for public-sector bodies to publish how and why they use algorithmic tools; mandatory for government departments and for arm's-length bodies that deliver public or frontline services.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/algorithmic-transparency-recording-standard-atrs",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-algorithmic-transparency-recording-standard-atrs",
      "chapters": [
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-altai",
      "term": "ALTAI",
      "definition": "The Assessment List for Trustworthy AI, published by the EU High-Level Expert Group on AI in July 2020: a self-assessment checklist that turns the seven requirements of the 2019 Ethics Guidelines into questions. Useful as a source of candidate controls; answered once, it is only an attestation.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/altai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-altai",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-annex-i-eu-ai-act",
      "term": "Annex I (EU AI Act)",
      "definition": "The AI Act annex listing the Union harmonisation legislation under which AI is embedded in regulated products (machinery, medical devices, toys and the like); obligations for these high-risk embedded systems phase in from 2 August 2028 under the Digital Omnibus timeline.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/annex-i-eu-ai-act",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-annex-i-eu-ai-act",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-annex-iii",
      "term": "Annex III",
      "definition": "The AI Act annex listing high-risk use cases (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice); obligations for these phase in under the Digital Omnibus timeline.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/annex-iii",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-annex-iii",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-anonymous-data",
      "term": "Anonymous data",
      "definition": "Information that does not relate to an identifiable person, judged against all the means reasonably likely to be used by anyone to identify them. It falls outside the GDPR, but the claim decays as auxiliary data and re-identification techniques improve, so it needs a dated assessment.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/anonymous-data",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-anonymous-data",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-article-6-3-filter",
      "term": "Article 6(3) filter",
      "definition": "The derogation under which an Annex III system is not high-risk when it poses no significant risk of harm and meets one of four conditions (narrow procedural task, improving completed human work, detecting patterns, preparatory task). Profiling of natural persons always defeats it; the provider documents and registers the assessment.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/article-6-3-filter",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-article-6-3-filter",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-asi01-asi10",
      "term": "ASI01–ASI10",
      "definition": "The ten risks of the OWASP Top 10 for Agentic Applications 2026: ASI01 Agent Goal Hijack, ASI02 Tool Misuse and Exploitation, ASI03 Identity and Privilege Abuse, ASI04 Agentic Supply Chain Vulnerabilities, ASI05 Unexpected Code Execution (RCE), ASI06 Memory & Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation and ASI10 Rogue Agents.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/asi01-asi10",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-asi01-asi10",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-atlas",
      "term": "ATLAS",
      "definition": "MITRE's Adversarial Threat Landscape for Artificial-Intelligence Systems, a knowledge base of adversary tactics and techniques against AI, including agent-specific techniques.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/atlas",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-atlas",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "10",
          "url": "https://aigovernanceengineer.com/bok/reading-list"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-audit-ready-evidence",
      "term": "Audit-ready evidence",
      "definition": "Evidence emitted as a by-product of the build in a form an auditor can read directly (machine-readable, signed, timestamped), so the audit is a query, not a collection project.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/audit-ready-evidence",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-audit-ready-evidence",
      "chapters": [
        {
          "number": "01",
          "url": "https://aigovernanceengineer.com/bok/definition"
        },
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        }
      ]
    },
    {
      "id": "t-authorised-representative",
      "term": "Authorised representative",
      "definition": "Under the EU AI Act, a person established in the Union with a written mandate from a non-EU provider of a high-risk AI system or general-purpose AI model to carry out that provider's obligations on its behalf, including keeping documentation available to authorities.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/authorised-representative",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-authorised-representative",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-automated-decision-making-adm",
      "term": "Automated decision-making (ADM)",
      "definition": "A decision about a person taken by automated means. GDPR Article 22 restricts decisions based solely on automated processing with legal or similarly significant effects; after the SCHUFA judgment, a score that lenders treat as determining is itself such a decision.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/automated-decision-making-adm",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-automated-decision-making-adm",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-automation-bias",
      "term": "Automation bias",
      "definition": "The tendency of a person to over-rely on an automated system's output. EU AI Act Article 14 asks that people overseeing high-risk systems stay aware of it; the human gate logs approver, time to decide and override rate so that degrading oversight is visible.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/automation-bias",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-automation-bias",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-autonomy",
      "term": "Autonomy",
      "definition": "In the EU AI Act and OECD texts, some degree of independence of action from human involvement, which almost every AI system has. ISO/IEC 22989 uses the word for a much stronger property, a system that can change its own goal or domain of use, and calls the ordinary case automation.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/autonomy",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-autonomy",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-autonomy-level",
      "term": "Autonomy level",
      "definition": "How far an agent acts without a person between its steps, set by the deployer as a design decision rather than taken as a property of the model; one research scale names five levels by the user's role, from operator to observer. It is a registry field tied to a minimum control set, and raising it is a reviewed change.",
      "letter": "A",
      "url": "https://aigovernanceengineer.com/glossary/autonomy-level",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-autonomy-level",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-bias",
      "term": "Bias",
      "definition": "A systematic error that favours or disadvantages some people or outcomes. NIST sorts AI bias into three categories: systemic, statistical and computational, and human. Bias can enter at any lifecycle stage, so it is tested per stage rather than once.",
      "letter": "B",
      "url": "https://aigovernanceengineer.com/glossary/bias",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-bias",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-bias-audit-nyc-local-law-144",
      "term": "Bias audit (NYC Local Law 144)",
      "definition": "An independent audit, required within the year before an employer uses an automated employment decision tool in New York City, that reports selection or scoring rates and impact ratios by sex, race and ethnicity and their intersections; its summary must be published.",
      "letter": "B",
      "url": "https://aigovernanceengineer.com/glossary/bias-audit-nyc-local-law-144",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-bias-audit-nyc-local-law-144",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-biometric-data",
      "term": "Biometric data",
      "definition": "Personal data from the technical processing of physical, physiological or behavioural traits that allows or confirms a person's unique identification, such as facial images or fingerprints. Identification, verification and categorisation are treated differently across the GDPR, the AI Act and other laws.",
      "letter": "B",
      "url": "https://aigovernanceengineer.com/glossary/biometric-data",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-biometric-data",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-blameless-post-mortem",
      "term": "Blameless post-mortem",
      "definition": "An incident review that identifies contributing causes without indicting any individual or team, on the premise that people acted reasonably on what they knew and that systems and processes are what can be fixed. Its triggers are set in advance.",
      "letter": "B",
      "url": "https://aigovernanceengineer.com/glossary/blameless-post-mortem",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-blameless-post-mortem",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-blue-green-deployment",
      "term": "Blue-green deployment",
      "definition": "Two identical production environments with traffic switched between them, so a release can be rolled back by switching back. It gives an AI system a tested, instant path to the previous version.",
      "letter": "B",
      "url": "https://aigovernanceengineer.com/glossary/blue-green-deployment",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-blue-green-deployment",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-build-provenance-slsa",
      "term": "Build provenance (SLSA)",
      "definition": "A verifiable record, in the SLSA format, of what built an artefact, by what process and from which top-level inputs. Its build levels run from L1, provenance exists, through L2, signed by a hosted build platform, to L3, hardened builds whose provenance is very hard to forge. For a model, inputs include the base model's digest and dataset admission records.",
      "letter": "B",
      "url": "https://aigovernanceengineer.com/glossary/build-provenance-slsa",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-build-provenance-slsa",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        }
      ]
    },
    {
      "id": "t-cac-cyberspace-administration-of-china",
      "term": "CAC (Cyberspace Administration of China)",
      "definition": "China's internet regulator (国家互联网信息办公室), lead issuer of the binding AI rules (algorithmic recommendation, deep synthesis, generative AI services and AI-content labelling) and the body under whose guidance TC260 publishes the AI Safety Governance Framework.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/cac-cyberspace-administration-of-china",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-cac-cyberspace-administration-of-china",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-calibration",
      "term": "Calibration",
      "definition": "The property that a model's confidence matches its accuracy: of the cases scored 0.9, about nine in ten are right. Modern neural networks are often poorly calibrated, so calibration is measured in the eval gate per version and subgroup before any threshold is trusted.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/calibration",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-calibration",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-calibration-within-groups",
      "term": "Calibration within groups",
      "definition": "The fairness property that, in every group, the people given a score s turn out positive at rate s, so a score means the same thing for everyone. It generally conflicts with equal error rates when base rates differ.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/calibration-within-groups",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-calibration-within-groups",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-canary-release",
      "term": "Canary release",
      "definition": "A partial, time-limited deployment of a change to a small share of production traffic, evaluated against a control group before the rollout continues. For AI systems the evaluation compares live quality, safety and fairness metrics with pre-registered rollback criteria.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/canary-release",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-canary-release",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-capa",
      "term": "CAPA",
      "definition": "Corrective and preventive action, the output of an incident review. The corrective action fixes this instance; the preventive action stops the class of failure recurring across the fleet, typically as a regression eval, a policy change and a risk-register update, verified before the incident closes.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/capa",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-capa",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-catastrophic-forgetting",
      "term": "Catastrophic forgetting",
      "definition": "The tendency of neural networks to lose earlier competence when trained on new tasks. It is a reason every retraining is a change event that re-runs the full eval suite, not only the tests for the new capability.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/catastrophic-forgetting",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-catastrophic-forgetting",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-catastrophic-severity-override",
      "term": "Catastrophic-severity override",
      "definition": "The rule that any scenario rated at the top severity level is Critical whatever its likelihood, cannot be accepted by the delivery team, and must be eliminated, reduced in severity or accepted explicitly by the governing body for a fixed period. NIST asks that such risks can be ceased safely.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/catastrophic-severity-override",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-catastrophic-severity-override",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-ce-marking",
      "term": "CE marking",
      "definition": "The mark showing a high-risk AI system's conformity with the EU AI Act, affixed visibly, legibly and indelibly, or digitally for systems provided digitally, with the notified body's number where one was involved.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/ce-marking",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-ce-marking",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-cedar",
      "term": "Cedar",
      "definition": "An open-source policy language for fine-grained authorization, used as a policy-as-code engine for runtime access decisions; a schema-typed, analysable alternative to OPA/Rego.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/cedar",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-cedar",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        }
      ]
    },
    {
      "id": "t-cen-cenelec-jtc-21",
      "term": "CEN-CENELEC JTC 21",
      "definition": "The joint technical committee of the European standardisation organisations CEN and CENELEC that drafts the AI Act harmonised standards, including EN 18286 on quality management and the drafts on risk management, trustworthiness and cybersecurity.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/cen-cenelec-jtc-21",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-cen-cenelec-jtc-21",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-cimd",
      "term": "CIMD",
      "definition": "Client ID Metadata Document: the mechanism by which an OAuth client identifies itself with a URL, used as its client ID, that points to its metadata document. The MCP specification of 2026-07-28 has clients and authorisation servers support it and deprecates Dynamic Client Registration; the IETF specification is still an Internet-Draft (revision 02, 6 Jul 2026) as of 2026-09-24.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/cimd",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-cimd",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-claims-register",
      "term": "Claims register",
      "definition": "The record of every public statement about an AI system's accuracy, fairness, safety or capability: the exact wording, where it appears, and the eval run, measured value, interval and population behind it. Copy carrying a claim whose evidence is missing, stale or failing is not published; the FTC requires competent and reliable evidence for such claims when they are made.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/claims-register",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-claims-register",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-classification-decision-record",
      "term": "Classification decision record",
      "definition": "A versioned registry record of why a system sits on a given rung of the AI Act risk ladder: the Annex III point, any Article 6(3) condition relied on, an explicit profiling flag, the reviewer and the date. It is re-evaluated whenever the intended purpose changes.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/classification-decision-record",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-classification-decision-record",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-common-specifications",
      "term": "Common specifications",
      "definition": "Technical specifications the Commission may adopt by implementing act under AI Act Article 41 when a standardisation request is not accepted, the standards are late or they insufficiently address fundamental-rights concerns; conforming with them also gives a presumption of conformity.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/common-specifications",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-common-specifications",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-concept-drift",
      "term": "Concept drift",
      "definition": "A change in the relationship between a system's inputs and the correct output, so the same input should now get a different answer. Unlike data drift, it shows only in outcomes: in production it appears in performance on fresh labels and in change-point tests on the error rate.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/concept-drift",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-concept-drift",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-conformal-prediction",
      "term": "Conformal prediction",
      "definition": "A distribution-free method that turns a trained model's output into a set of candidate answers that contains the right one with a chosen probability. A large set signals uncertainty that a governance rule can route on.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/conformal-prediction",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-conformal-prediction",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-conformity-assessment",
      "term": "Conformity assessment",
      "definition": "The procedure by which a provider shows a high-risk AI system meets the EU AI Act before placing it on the market: internal control for most Annex III systems, a notified body for some biometric systems, and the sectoral procedure for Annex I products. It precedes the declaration, CE marking and registration.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/conformity-assessment",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-conformity-assessment",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-content-provenance-c2pa",
      "term": "Content provenance (C2PA)",
      "definition": "Signed, tamper-evident information about where a piece of content came from and how it was edited, bound to the asset. The C2PA specification packages it as a manifest of assertions, a claim and a claim signature; NIST treats provenance tracking as one approach to synthetic-content transparency.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/content-provenance-c2pa",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-content-provenance-c2pa",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-contest-path",
      "term": "Contest path",
      "definition": "The route by which a person affected by an automated decision reaches a reviewer who did not take the original decision, sees the inputs, the reasons and the person's representations, and can change the outcome, with the result written back to the decision record. It is how the right to contest in GDPR Article 22(3) is honoured in practice.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/contest-path",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-contest-path",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-contestability",
      "term": "Contestability",
      "definition": "The ability of a person affected by an AI-supported decision to challenge it and obtain a response that can change it. GDPR Article 22(3) gives a right to contest solely automated decisions, and the OECD principles ask that people adversely affected can challenge an output.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/contestability",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-contestability",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-continuous-assurance",
      "term": "Continuous assurance",
      "definition": "Assurance produced continuously from telemetry rather than at a point in time; the control's status is a live query, not an annual sign-off. It is Level 5 of the maturity model.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/continuous-assurance",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-continuous-assurance",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "07",
          "url": "https://aigovernanceengineer.com/bok/maturity-model"
        }
      ]
    },
    {
      "id": "t-contributing-factor",
      "term": "Contributing factor",
      "definition": "A property of a system or its context (autonomy, exposure, reversibility, vulnerable groups, data sensitivity, opacity) that moves the likelihood or severity of a risk without creating it. It is captured as registry fields at intake so a policy can compute the tier.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/contributing-factor",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-contributing-factor",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-controller-and-processor",
      "term": "Controller and processor",
      "definition": "Under the GDPR the controller decides the purposes and means of processing and carries most duties; the processor acts on its documented instructions. An AI vendor serving your inference is usually a processor, but becomes a controller for any use of your data it decides on, such as training.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/controller-and-processor",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-controller-and-processor",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-counterfactual-explanation",
      "term": "Counterfactual explanation",
      "definition": "An explanation that states the smallest change to the input that would have changed the outcome, restricted to features the person can actually change. It is the natural basis for recourse.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/counterfactual-explanation",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-counterfactual-explanation",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-counterfactual-fairness",
      "term": "Counterfactual fairness",
      "definition": "The requirement that a decision about an individual be the same in a counterfactual world where the individual belonged to a different group, defined through a causal model; approximated in practice by counterfactual flip tests.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/counterfactual-fairness",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-counterfactual-fairness",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-counterfactual-flip-test",
      "term": "Counterfactual flip test",
      "definition": "A test that changes only a protected attribute in an input, or swaps identity terms in otherwise identical prompts, and measures how often the outcome or the answer quality changes. It is the practical approximation of counterfactual fairness and runs in the fairness eval suite.",
      "letter": "C",
      "url": "https://aigovernanceengineer.com/glossary/counterfactual-flip-test",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-counterfactual-flip-test",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-data-card",
      "term": "Data card",
      "definition": "Structured, versioned documentation of a dataset (provenance, lawful basis, rights, composition and known limitations) maintained as code alongside the system.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/data-card",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-data-card",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        }
      ]
    },
    {
      "id": "t-data-drift",
      "term": "Data drift",
      "definition": "A change in the distribution of the inputs a system sees in production relative to the data it was validated on, such as a new customer segment or a changed upstream form. It shows in the inputs before any label arrives, so it is monitored directly.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/data-drift",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-data-drift",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-data-lineage",
      "term": "Data lineage",
      "definition": "The record of how data moved and changed through an organisation's pipelines. Backward lineage shows what fed a model; forward lineage shows which models used a dataset, which erasure requests and licence withdrawals need. OpenLineage is an open standard for emitting it.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/data-lineage",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-data-lineage",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-data-minimisation",
      "term": "Data minimisation",
      "definition": "The GDPR principle that personal data must be adequate, relevant and limited to what the purpose needs. For AI it is argued feature by feature, applied to training snapshots, retrieval indexes, logs and eval sets, and evidenced by feature justifications and filter logs.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/data-minimisation",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-data-minimisation",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-data-provenance",
      "term": "Data provenance",
      "definition": "Information about the entities, activities and people involved in producing data, used to judge its quality and trustworthiness. In practice: where a dataset originally came from and on what terms (source, licence, lawful basis). Perfect lineage over unknown provenance is still ungoverned.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/data-provenance",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-data-provenance",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-dataset-admission-gate",
      "term": "Dataset admission gate",
      "definition": "A pipeline control that lets a training job read only datasets whose admission record is complete and signed by the data owner: lawful basis or licence, reservation checks, quality results, provenance, permitted uses and retention. It evidences the data-governance practices of AI Act Article 10.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/dataset-admission-gate",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-dataset-admission-gate",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-datasheet-for-datasets",
      "term": "Datasheet for datasets",
      "definition": "Documentation that accompanies a dataset with its motivation, composition, collection process, preprocessing, uses, distribution and maintenance, as proposed by Gebru and colleagues; the human-readable companion to the dataset admission record and the data card.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/datasheet-for-datasets",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-datasheet-for-datasets",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-decision-notice",
      "term": "Decision notice",
      "definition": "The notice a person receives at the point of an automated or AI-assisted decision, rendered from a versioned template and the decision record: that a system was used, the principal reasons and what the person can do by when. Content follows each regime, such as notice of use under AI Act Article 26(11) or reasons under US Regulation B.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/decision-notice",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-decision-notice",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-decision-threshold",
      "term": "Decision threshold",
      "definition": "The score above or below which an AI output triggers an action. It is where risk appetite becomes behaviour, so it is governed as a policy with an owner, version and effective date, tested in the eval gate and logged with every decision; the AI Act asks for declared accuracy metrics.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/decision-threshold",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-decision-threshold",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-decommissioning",
      "term": "Decommissioning",
      "definition": "The planned retirement of an AI system: dependency analysis, fallback and transition, sunset notices, a final evidence snapshot, archive or disposal of weights and data, revocation of every identity, and a registry entry marked retired rather than deleted. NIST asks that systems be phased out safely.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/decommissioning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-decommissioning",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-deepfake",
      "term": "Deepfake",
      "definition": "Under the EU AI Act, a deep fake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic; deployers must disclose it, with lighter duties for evident art or satire.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/deepfake",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-deepfake",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-delegation-oauth-token-exchange",
      "term": "Delegation (OAuth token exchange)",
      "definition": "In RFC 8693, the mode in which one party acts for another while both stay identifiable: the token names the subject and, in its act claim, the current actor, with nested act claims for earlier actors. Under impersonation the actor becomes indistinguishable from the subject. An agent should hold a delegated, narrower token, never the user's own.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/delegation-oauth-token-exchange",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-delegation-oauth-token-exchange",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-delegation-chain",
      "term": "Delegation chain",
      "definition": "The sequence of agents a task passes through from the person or system that started it. It is governed so that each hop authenticates as itself, scope narrows or stays equal but never widens, the purpose travels with the task, depth and fan-out are bounded, and one trace spans every hop.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/delegation-chain",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-delegation-chain",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-demographic-parity",
      "term": "Demographic parity",
      "definition": "A group fairness criterion that holds when the rate of positive decisions is equal across groups; the adverse-impact ratio is its ratio form. It ignores differences in base rates.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/demographic-parity",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-demographic-parity",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-deployer",
      "term": "Deployer",
      "definition": "Under the EU AI Act, whoever uses an AI system under its own authority, other than in a purely personal, non-professional activity. For high-risk systems it follows the instructions for use, staffs oversight, monitors, keeps logs, informs affected people and, in listed cases, performs the FRIA. The label names a task, not a kind of organisation.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/deployer",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-deployer",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-deployment-decision-record-ddr",
      "term": "Deployment Decision Record (DDR)",
      "definition": "The artefact that records the decision to deploy an AI system: objective, the people it acts on, negative space, risk tier and obligations, per-group performance floors, retirement conditions, owner and approver. It is committed with the system's code; its floors become eval-gate thresholds.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/deployment-decision-record-ddr",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-deployment-decision-record-ddr",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-design-defect",
      "term": "Design defect",
      "definition": "In product liability, a defect inherent in the design of every unit, judged by consumer expectations or by weighing risk against utility. For AI: untested operating conditions, a missing guardrail or missing oversight where a safer alternative was reasonably available.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/design-defect",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-design-defect",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-differential-privacy",
      "term": "Differential privacy",
      "definition": "A mathematical guarantee that bounds how much any single person's record can change the output of an analysis or a trained model, tuned by a privacy budget. Its strength depends on the budget and on implementation choices that NIST calls privacy hazards.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/differential-privacy",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-differential-privacy",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-digital-omnibus",
      "term": "Digital Omnibus",
      "definition": "The 2026 reform package amending the EU AI Act (in force 27 Jul 2026), which adjusted the high-risk timeline, added AI Office investigation powers and reworked several articles.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/digital-omnibus",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-digital-omnibus",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-disparate-impact",
      "term": "Disparate impact",
      "definition": "A facially neutral practice that falls harder on a protected group. Under US Title VII the employer must show the practice is job related and consistent with business necessity, and loses if it refuses a less discriminatory alternative. The EU counterpart is indirect discrimination.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/disparate-impact",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-disparate-impact",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-disparate-treatment",
      "term": "Disparate treatment",
      "definition": "Treating a person less favourably because of a protected characteristic such as race, sex or age, including through a feature or rule that deliberately stands in for it. The EU counterpart is direct discrimination.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/disparate-treatment",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-disparate-treatment",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-distributor",
      "term": "Distributor",
      "definition": "Under the EU AI Act, a person in the supply chain, other than the provider or the importer, who makes an AI system available on the Union market. It checks the marking and documents and holds back high-risk systems it believes do not conform.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/distributor",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-distributor",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-domestic-representative-korea",
      "term": "Domestic representative (Korea)",
      "definition": "A person with an address or office in Korea whom a foreign AI business operator above thresholds set by decree must designate in writing. It submits safety results, files high-impact confirmation requests and supports the high-impact measures.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/domestic-representative-korea",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-domestic-representative-korea",
      "chapters": [
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-downstream-modifier-gpai",
      "term": "Downstream modifier (GPAI)",
      "definition": "An actor that fine-tunes or modifies another provider's general-purpose AI model. The Commission's guidelines make it the modified model's provider only when the modification uses over a third of the original training compute; its Art. 53(1) duties then cover the modification, but a modified systemic-risk model is presumed to keep that risk and its duties.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/downstream-modifier-gpai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-downstream-modifier-gpai",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-downstream-provider",
      "term": "Downstream provider",
      "definition": "Under the EU AI Act, the provider of an AI system that integrates an AI model, its own or one supplied by another entity. It relies on the model information that general-purpose AI model providers must hand downstream.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/downstream-provider",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-downstream-provider",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-downstream-use-register",
      "term": "Downstream use register",
      "definition": "The record of every consumer of an AI system's outputs (a system, team, partner or training pipeline), each with its approved use, the re-test that cleared the outputs for that context and any contract, held against the producing system's registry entry. Access is granted per registered consumer, and a model change or retirement is notified to all of them.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/downstream-use-register",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-downstream-use-register",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-dpia",
      "term": "DPIA",
      "definition": "Data Protection Impact Assessment: the GDPR Article 35 assessment of processing likely to result in high risk to individuals, maintained in this discipline as a versioned artefact, not a one-off document.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/dpia",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-dpia",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-drift",
      "term": "Drift",
      "definition": "The gradual divergence of a model's inputs, outputs or performance from its validated baseline over time; a runtime signal that a control or eval must catch. The two kinds to tell apart are data drift, in the inputs, and concept drift, in the input-to-answer relationship.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/drift",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-drift",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-dual-use",
      "term": "Dual use",
      "definition": "The capacity of the same AI capability to serve harmful ends as well as legitimate ones, for example a toxicity model inverted to propose toxic molecules. It is answered with misuse threat models, red-team cases for harmful uses of legitimate capability and runtime detection.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/dual-use",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-dual-use",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-duty-holder",
      "term": "Duty holder",
      "definition": "Who an obligation legally binds (under the EU AI Act, the provider, the deployer or both), as distinct from who enforces it; chapter 08 carries a duty-holder column so an engineer can tell which artefacts their organisation is responsible for producing.",
      "letter": "D",
      "url": "https://aigovernanceengineer.com/glossary/duty-holder",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-duty-holder",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-effective-challenge",
      "term": "Effective challenge",
      "definition": "Critical analysis of a model by objective experts with the expertise, independence and organisational standing to force change. The term comes from US model-risk guidance, now SR 26-2, and is borrowed for independent validation of AI systems.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/effective-challenge",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-effective-challenge",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-en-18286",
      "term": "EN 18286",
      "definition": "The European standard for the AI Act's Article 17 quality management system, published by CEN-CENELEC in July 2026 (the first JTC 21 AI Act standard to reach publication), but not yet cited in the Official Journal as of 2026-09-24, so it confers no presumption of conformity.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/en-18286",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-en-18286",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-equalised-odds",
      "term": "Equalised odds",
      "definition": "A group fairness criterion that holds when true-positive and false-positive rates are both equal across groups; equal opportunity is the weaker version that equalises only true-positive rates.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/equalised-odds",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-equalised-odds",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-eu-declaration-of-conformity",
      "term": "EU declaration of conformity",
      "definition": "The provider's signed statement, following AI Act Annex V, that a high-risk AI system meets the Act's requirements; drawn up after the conformity assessment and kept for 10 years.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/eu-declaration-of-conformity",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-eu-declaration-of-conformity",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-eval-gate",
      "term": "Eval gate",
      "definition": "A pipeline stage that fails the build when an eval fails; the mechanism that turns an evaluation into an enforced control rather than a report.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/eval-gate",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-eval-gate",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        }
      ]
    },
    {
      "id": "t-evals",
      "term": "Evals",
      "definition": "Automated tests of a model's or agent's behaviour (capability, safety and adversarial), run as controls, not as one-off research.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/evals",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-evals",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        }
      ]
    },
    {
      "id": "t-evals-as-evidence",
      "term": "Evals as evidence",
      "definition": "The principle that the eval run is the assurance evidence: a failing eval blocks the build and its structured result is stored as proof the control fired.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/evals-as-evidence",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-evals-as-evidence",
      "chapters": [
        {
          "number": "03",
          "url": "https://aigovernanceengineer.com/bok/values-and-principles"
        },
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        }
      ]
    },
    {
      "id": "t-evidence-record",
      "term": "Evidence record",
      "definition": "The signed, structured record a control writes each time it decides: which control, about which system version, what it decided, against which metric, threshold and obligation, on which input, when and by whom. One shape for every control lets an audit run as a query over one store.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/evidence-record",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-evidence-record",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        }
      ]
    },
    {
      "id": "t-exception-register",
      "term": "Exception register",
      "definition": "A version-controlled list of approved exceptions, each tied to one rule and one system, with justification, compensating controls, approver and expiry. The policy engine reads it, so a release can pass under a live exception, the verdict says so, and the rule fails again once the exception expires.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/exception-register",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-exception-register",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-explainability",
      "term": "Explainability",
      "definition": "In NIST's framing, a representation of the mechanisms behind a system's operation: how a decision was made. In practice a per-decision explanation such as feature attributions, reason codes or a counterfactual.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/explainability",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-explainability",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-explanation-record",
      "term": "Explanation record",
      "definition": "The evidence artefact for one explained decision: model version, explanation method and version, baseline, reason codes, counterfactual, template, audience and delivery, written at decision time so the explanation can be reproduced when a person invokes a right to explanation.",
      "letter": "E",
      "url": "https://aigovernanceengineer.com/glossary/explanation-record",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-explanation-record",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-failure-posture",
      "term": "Failure posture",
      "definition": "What a guardrail, guardian agent or tool gateway does when it cannot reach a decision: fail open lets the call through, fail closed blocks it. The reference guardian of the OWASP Agent Control Standard starts at proceed unless set to deny. The posture is a governance decision, set per operation class and recorded in the agent's Policy Card.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/failure-posture",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-failure-posture",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-failure-to-warn",
      "term": "Failure to warn",
      "definition": "In product liability, a defect in instructions or warnings about non-obvious dangers. For AI: undisclosed limitations or out-of-scope uses, which is why model cards and instructions for use are versioned with each release.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/failure-to-warn",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-failure-to-warn",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-fair-use",
      "term": "Fair use",
      "definition": "The US copyright defence that weighs four factors: purpose and transformativeness, nature of the work, amount used and market effect. Courts apply it to AI training case by case; results so far turn on how the data was acquired and on each record.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/fair-use",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-fair-use",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-fairness",
      "term": "Fairness",
      "definition": "The property that a system's outcomes and errors do not unjustifiably disadvantage people or groups. NIST lists \"fair, with harmful bias managed\" among its trustworthy characteristics; in practice fairness is a chosen, recorded metric (group, individual or counterfactual) with a threshold, not a general claim.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/fairness",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-fairness",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-fairness-gerrymandering",
      "term": "Fairness gerrymandering",
      "definition": "The failure in which a model satisfies a fairness constraint on each predefined group but violates it on subgroups defined by combinations of attributes; the reason intersectional testing is needed.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/fairness-gerrymandering",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-fairness-gerrymandering",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-fairness-policy",
      "term": "Fairness policy",
      "definition": "The per-system record, fixed before results are seen, of what fairness means for that system: the protected attributes in each jurisdiction and where their values come from, the chosen metric and why, the threshold, the minimum cell size, the multiple-comparison correction and the approver. The fairness eval suite is judged against it.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/fairness-policy",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-fairness-policy",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-federated-learning",
      "term": "Federated learning",
      "definition": "Training a model across devices or sites where the data lives, sharing model updates instead of raw records. It limits data movement but does not by itself hide personal data, because shared updates can leak training examples.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/federated-learning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-federated-learning",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-fine-tuning",
      "term": "Fine-tuning",
      "definition": "Further training of an existing model on new data to adapt it to a task or domain. It changes the model, so it is a change event with its own evals; for general-purpose AI models, the Commission treats a modifier as a provider only above one third of the original training compute.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/fine-tuning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-fine-tuning",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-foundation-model",
      "term": "Foundation model",
      "definition": "A model trained on broad data at scale and adaptable to a wide range of downstream tasks. Its defects are inherited by every system built on it, so organisations that call or adapt one collect the provider's evidence and manage the pinned version as a change.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/foundation-model",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-foundation-model",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-four-fifths-rule",
      "term": "Four-fifths rule",
      "definition": "The US Uniform Guidelines rule of thumb that a group selection rate below 80% of the highest group's rate will generally be regarded as evidence of adverse impact, qualified by statistical and practical significance. It is not a safe harbour: smaller gaps can still count.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/four-fifths-rule",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-four-fifths-rule",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-framework-convention-on-ai-cets-no-225",
      "term": "Framework Convention on AI (CETS No. 225)",
      "definition": "The Council of Europe's treaty on AI and human rights, democracy and the rule of law, opened for signature in September 2024. It binds its Parties, which decide how to reach private actors, and asks for risk and impact management and remedies.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/framework-convention-on-ai-cets-no-225",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-framework-convention-on-ai-cets-no-225",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-framework-crosswalk",
      "term": "Framework crosswalk",
      "definition": "A mapping of one framework's controls onto another's; useful as an index, but a crosswalk proves you read the framework, not that the mapped control fires.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/framework-crosswalk",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-framework-crosswalk",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        }
      ]
    },
    {
      "id": "t-fria",
      "term": "FRIA",
      "definition": "Fundamental Rights Impact Assessment: the AI Act Article 27 assessment of a high-risk system's impact on rights, maintained here as a versioned, reviewable artefact.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/fria",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-fria",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-frontier-model",
      "term": "Frontier model",
      "definition": "A general-purpose model at or near the capability frontier. Laws draw the line by training compute: California's SB 53, for example, covers models trained with more than 10^26 operations. Frontier-developer laws ask for a published safety framework and incident reporting.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/frontier-model",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-frontier-model",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-fulfilment-record",
      "term": "Fulfilment record",
      "definition": "The per-request record of how a data-subject request was honoured wherever the person's data sits, from source systems, snapshots, retrieval indexes, logs and eval sets to model weights: the action in each, the model versions affected, any scheduled retrain and whether the GDPR deadline of one month, extendable by two, was met.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/fulfilment-record",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-fulfilment-record",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-function-creep",
      "term": "Function creep",
      "definition": "The gradual reuse of personal data or an AI system for purposes nobody approved, usually by configuration rather than a new release. For personal data it breaches purpose limitation unless a compatibility assessment or new basis covers the new use; negative space in the deployment record makes it detectable.",
      "letter": "F",
      "url": "https://aigovernanceengineer.com/glossary/function-creep",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-function-creep",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-generative-ai",
      "term": "Generative AI",
      "definition": "AI that outputs new content (text, images, audio, video, code) rather than an estimate about something that exists. Its distinctive risks include confabulation, information integrity, intellectual property and abusive synthetic content; its evidence is groundedness, refusal and red-team evals and content marking.",
      "letter": "G",
      "url": "https://aigovernanceengineer.com/glossary/generative-ai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-generative-ai",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-go-no-go-decision",
      "term": "Go/no-go decision",
      "definition": "The signed release decision for one system version, taken by named reviewer roles against a checklist whose items each link the record that answers them. NIST frames it as the determination whether development or deployment should proceed; the pipeline deploys only on a go.",
      "letter": "G",
      "url": "https://aigovernanceengineer.com/glossary/go-no-go-decision",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-go-no-go-decision",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-governance-as-code",
      "term": "Governance-as-code",
      "definition": "Governance rules expressed as executable code that evaluates pull requests, deployments and runtime calls and returns a decision; the umbrella term of which policy-as-code is the CI/CD subset.",
      "letter": "G",
      "url": "https://aigovernanceengineer.com/glossary/governance-as-code",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-governance-as-code",
      "chapters": [
        {
          "number": "03",
          "url": "https://aigovernanceengineer.com/bok/values-and-principles"
        },
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        }
      ]
    },
    {
      "id": "t-gpai",
      "term": "GPAI",
      "definition": "General-purpose AI model: under the AI Act, a model that shows significant generality, can competently perform a wide range of distinct tasks and can be integrated into many downstream systems. The Commission's indicative criterion is training compute above 10^23 FLOP. The AI Office enforces GPAI duties from 2 Aug 2026.",
      "letter": "G",
      "url": "https://aigovernanceengineer.com/glossary/gpai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-gpai",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-gpai-code-of-practice",
      "term": "GPAI Code of Practice",
      "definition": "The voluntary instrument (published 10 July 2025) that general-purpose-AI providers use to demonstrate compliance with their AI Act obligations until harmonised standards exist; three chapters: Transparency, Copyright, and Safety and Security (the last for systemic-risk models).",
      "letter": "G",
      "url": "https://aigovernanceengineer.com/glossary/gpai-code-of-practice",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-gpai-code-of-practice",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-graduated-degradation",
      "term": "Graduated degradation",
      "definition": "Pre-built, tested operating modes short of switching an AI system off: advice-only, raised confidence thresholds, grounded-only answers, disabling for one group, language or region, and a return to the pilot cohort. Each is an operational toggle with a named trigger.",
      "letter": "G",
      "url": "https://aigovernanceengineer.com/glossary/graduated-degradation",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-graduated-degradation",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-guardian-agent",
      "term": "Guardian agent",
      "definition": "An AI agent whose job is to supervise, check or constrain other agents at runtime; Gartner predicts guardian-agent technologies will account for at least 10 to 15% of agentic AI markets by 2030.",
      "letter": "G",
      "url": "https://aigovernanceengineer.com/glossary/guardian-agent",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-guardian-agent",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-guardrail",
      "term": "Guardrail",
      "definition": "A runtime control that inspects or mediates a model's or agent's inputs, outputs or tool calls and blocks, rewrites or escalates what breaks a policy, logging each decision as evidence. Guardrails are deterministic code or classifiers in the call path, unlike a guardian agent, which is itself an AI system.",
      "letter": "G",
      "url": "https://aigovernanceengineer.com/glossary/guardrail",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-guardrail",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-hallucination",
      "term": "Hallucination",
      "definition": "Generative output that is stated confidently but is false or unsupported by its sources; NIST's generative AI profile calls it confabulation and lists it among the risks generative AI creates or worsens. Groundedness and citation checks are the usual evidence against it.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/hallucination",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-hallucination",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-harmonised-standard",
      "term": "Harmonised standard",
      "definition": "A European standard adopted on a Commission standardisation request. Under the AI Act, conformity with one whose reference is published in the Official Journal gives a presumption of conformity with the requirements it covers; publication by CEN-CENELEC alone does not. As of 2026-09-24, none is yet cited.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/harmonised-standard",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-harmonised-standard",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-harmonized-structure-iso",
      "term": "Harmonized Structure (ISO)",
      "definition": "The common clause layout and core text shared by ISO management-system standards such as ISO/IEC 42001, 27001 and 27701 and ISO 9001, which lets one integrated management system meet several of them. Not to be confused with an EU harmonised standard.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/harmonized-structure-iso",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-harmonized-structure-iso",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-hidden-context-exposure",
      "term": "Hidden Context Exposure",
      "definition": "LLM08:2026 in the OWASP LLM Top 10, which replaced System Prompt Leakage: extracting, inferring or reconstructing the hidden context a model sees, such as system prompts, developer instructions, retrieved policy text and tool schemas. The advice is to assume hidden context is discoverable, keep credentials out of it and never rely on it as a security boundary.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/hidden-context-exposure",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-hidden-context-exposure",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-high-impact-ai-korea",
      "term": "High-impact AI (Korea)",
      "definition": "Under Korea's AI Basic Act, an AI system that may significantly affect life, physical safety or fundamental rights and is used in a listed area such as health care, hiring and loan screening, biometric analysis, transport or public-service decisions. It triggers risk-management, explanation, human-oversight and record-keeping duties.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/high-impact-ai-korea",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-high-impact-ai-korea",
      "chapters": [
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-high-risk-ai-system",
      "term": "High-risk AI system",
      "definition": "Under the EU AI Act, an AI system that is a safety component of, or itself, a product under Annex I legislation needing third-party conformity assessment, or that is used in an Annex III area, unless the Article 6(3) filter applies. It carries the Articles 8 to 15 requirements and provider and deployer duties.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/high-risk-ai-system",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-high-risk-ai-system",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-hiroshima-code-of-conduct",
      "term": "Hiroshima Code of Conduct",
      "definition": "The G7's voluntary International Code of Conduct for Organizations Developing Advanced AI Systems (October 2023): 11 actions covering lifecycle risk evaluation, post-deployment monitoring, public reporting, incident sharing, governance policies, security, provenance and data protection.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/hiroshima-code-of-conduct",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-hiroshima-code-of-conduct",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-holding-statement",
      "term": "Holding statement",
      "definition": "A short public statement prepared in skeleton before any incident: what happened as far as it is known, what has been done to contain it, what affected people should do, and when the next update will come. It never speculates about cause.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/holding-statement",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-holding-statement",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-huderia",
      "term": "HUDERIA",
      "definition": "The Council of Europe's non-binding methodology for assessing the risks and impacts of AI systems on human rights, democracy and the rule of law. Parties to the Framework Convention may use or adapt it.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/huderia",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-huderia",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-human-oversight",
      "term": "Human oversight",
      "definition": "The measures that let natural persons understand, monitor and, when needed, override or stop a high-risk AI system, required by AI Act Article 14, including awareness of automation bias and a way to halt the system safely. Engineered as gates, review tooling and override drills that leave records.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/human-oversight",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-human-oversight",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-human-in-command-hic",
      "term": "Human-in-command (HIC)",
      "definition": "The oversight mode, named by the EU High-Level Expert Group, in which people oversee the overall activity of an AI system and decide when and whether to use it in a given situation.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/human-in-command-hic",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-human-in-command-hic",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-human-in-the-loop-hitl",
      "term": "Human-in-the-loop (HITL)",
      "definition": "The oversight mode in which a person can intervene in every decision cycle of an AI system; in engineering terms, a gate that holds each consequential action until a named approver decides, logging approver, time to decide and override.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/human-in-the-loop-hitl",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-human-in-the-loop-hitl",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-human-on-the-loop-hotl",
      "term": "Human-on-the-loop (HOTL)",
      "definition": "The oversight mode in which a person can intervene in the design cycle and monitors the system's operation, rather than approving each decision. The system acts; people watch the signals and can stop it, so the stop path and the alerting are what must be tested.",
      "letter": "H",
      "url": "https://aigovernanceengineer.com/glossary/human-on-the-loop-hotl",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-human-on-the-loop-hotl",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-implicit-deny",
      "term": "Implicit deny",
      "definition": "The authorisation rule that a request no policy explicitly permits is refused. Cedar denies by default and lets any matching forbid override every permit; an agent's tool allow-list works the same way, so an unlisted tool is blocked without a rule of its own.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/implicit-deny",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-implicit-deny",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-importer",
      "term": "Importer",
      "definition": "Under the EU AI Act, a person established in the Union who places on the market an AI system bearing the name or trademark of a provider established outside the Union. It must verify the provider's conformity work before placing a high-risk system on the market.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/importer",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-importer",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-indirect-discrimination",
      "term": "Indirect discrimination",
      "definition": "The EU counterpart of disparate impact: an apparently neutral criterion that puts a protected group at a particular disadvantage, unlawful unless objectively justified by a legitimate aim pursued by appropriate and necessary means.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/indirect-discrimination",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-indirect-discrimination",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-inference-ai-act-sense",
      "term": "Inference (AI Act sense)",
      "definition": "The capability to derive outputs from input by learning from data or reasoning over encoded knowledge, rather than by executing rules people wrote. The Commission treats it as the indispensable condition that separates an AI system from conventional software.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/inference-ai-act-sense",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-inference-ai-act-sense",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-inferred-sensitive-data",
      "term": "Inferred sensitive data",
      "definition": "Sensitive information a system derives from ordinary inputs (health from purchases, beliefs from behaviour) or carries through a proxy feature. Washington's My Health My Data Act covers health data derived by algorithms or machine learning; proxy tests and inference policies make it checkable.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/inferred-sensitive-data",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-inferred-sensitive-data",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-inherent-risk",
      "term": "Inherent risk",
      "definition": "The likelihood and severity rating of a risk scenario before any control is counted. The gap between inherent and residual risk is the value claimed for the controls, and must be backed by their evidence.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/inherent-risk",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-inherent-risk",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-instructions-for-use",
      "term": "Instructions for use",
      "definition": "The information a provider of a high-risk AI system must give deployers: intended purpose, declared accuracy and robustness, known risks, how to read the output, human oversight measures, maintenance and logging. Best generated from the registry entry and test report, so the numbers match the evidence.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/instructions-for-use",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-instructions-for-use",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-intended-purpose",
      "term": "Intended purpose",
      "definition": "The use for which the provider intends an AI system, including its specific context and conditions of use. Most high-risk duties are measured against it, so it is a field of the use-case record that classification, tests and instructions for use read. A model moved to a new purpose is, for risk, a new system.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/intended-purpose",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-intended-purpose",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-internal-reporting-channel",
      "term": "Internal reporting channel",
      "definition": "A confidential route for staff and contractors to raise concerns about AI systems outside the chain of command, with statutory clocks encoded (under the EU Whistleblower Directive, acknowledgment within seven days and feedback within three months) and protection against retaliation.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/internal-reporting-channel",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-internal-reporting-channel",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-interpretability",
      "term": "Interpretability",
      "definition": "In NIST's framing, the meaning of a system's output in the context of its purpose: why a decision was made and what it means to the user. An inherently interpretable model, such as a scorecard or a shallow tree, is its own explanation.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/interpretability",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-interpretability",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-iso-iec-22989",
      "term": "ISO/IEC 22989",
      "definition": "The ISO/IEC standard (2022) that establishes AI concepts and terminology for use by other standards and by diverse stakeholders. Naming registry fields after its vocabulary reduces translation when auditing against the SC 42 family.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/iso-iec-22989",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-iso-iec-22989",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-iso-iec-42001",
      "term": "ISO/IEC 42001",
      "definition": "The ISO/IEC standard (2023) that specifies requirements for an AI management system, certifiable by accredited bodies. As of 2026-09-24 it is not a harmonised standard under the AI Act, so certification gives no presumption of conformity.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/iso-iec-42001",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-iso-iec-42001",
      "chapters": [
        {
          "number": "07",
          "url": "https://aigovernanceengineer.com/bok/maturity-model"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-iso-iec-42005",
      "term": "ISO/IEC 42005",
      "definition": "ISO/IEC 42005:2025, the AI system impact-assessment standard (a companion to the AI Act's Article 27 FRIA and to ISO/IEC 42001 Annex A.5), giving a structured method for assessing an AI system's impacts on people and society.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/iso-iec-42005",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-iso-iec-42005",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-issue-versus-incident",
      "term": "Issue (versus incident)",
      "definition": "A defect, deviation or control weakness that has not produced a harmful event, such as an eval regression in staging or a drift alert. It is tracked to closure with an owner and a due date and starts no legal clock; most issues are nonconformities in management-system terms.",
      "letter": "I",
      "url": "https://aigovernanceengineer.com/glossary/issue-versus-incident",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-issue-versus-incident",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-jailbreak",
      "term": "Jailbreak",
      "definition": "A prompt crafted to make a model disregard its safety instructions entirely. OWASP treats jailbreaking as a form of prompt injection; it is tested with red-team suites in the eval gate and contained at runtime by guardrails that do not depend on the model's own refusals.",
      "letter": "J",
      "url": "https://aigovernanceengineer.com/glossary/jailbreak",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-jailbreak",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-json-schema",
      "term": "JSON Schema",
      "definition": "A vocabulary for describing the structure of JSON documents so a validator can check them: which fields exist, which are required, their types and allowed values. The templates library publishes one draft 2020-12 schema per governance record, so a record either validates or fails the build.",
      "letter": "J",
      "url": "https://aigovernanceengineer.com/glossary/json-schema",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-json-schema",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        }
      ]
    },
    {
      "id": "t-justification-memo",
      "term": "Justification memo",
      "definition": "The intake record for an AI use case: the problem, the non-AI alternative, the measurable benefit, who bears errors and how they contest them, reversibility and kill criteria. It answers \"should AI be used at all\" before a system reaches a gate, the go/no-go determination NIST places early.",
      "letter": "J",
      "url": "https://aigovernanceengineer.com/glossary/justification-memo",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-justification-memo",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-key-risk-indicator-kri",
      "term": "Key risk indicator (KRI)",
      "definition": "A metric that shows whether a risk is moving towards the edge of appetite (unregistered AI found, open exceptions by age, override rates), as distinct from a key performance indicator, which shows whether the programme is doing its job.",
      "letter": "K",
      "url": "https://aigovernanceengineer.com/glossary/key-risk-indicator-kri",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-key-risk-indicator-kri",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-kill-switch",
      "term": "Kill switch",
      "definition": "A tested mechanism to stop an agent or system from acting; a precondition of granting autonomy, registered against the agent's identity.",
      "letter": "K",
      "url": "https://aigovernanceengineer.com/glossary/kill-switch",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-kill-switch",
      "chapters": [
        {
          "number": "03",
          "url": "https://aigovernanceengineer.com/bok/values-and-principles"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-large-language-model-llm",
      "term": "Large language model (LLM)",
      "definition": "A foundation model for language, usually served from a data centre behind an API. Because calls pass through a gateway, runtime controls (tracing, filtering, stopping) can sit centrally.",
      "letter": "L",
      "url": "https://aigovernanceengineer.com/glossary/large-language-model-llm",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-large-language-model-llm",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-latent-disclosure",
      "term": "Latent disclosure",
      "definition": "Under California's AI Transparency Act, provenance information embedded in AI-generated image, video or audio so that it persists and can be read by a detection tool, as opposed to a visible label shown to the user.",
      "letter": "L",
      "url": "https://aigovernanceengineer.com/glossary/latent-disclosure",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-latent-disclosure",
      "chapters": [
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-lawful-basis",
      "term": "Lawful basis",
      "definition": "One of the six grounds in GDPR Article 6 that make processing of personal data lawful: consent, contract, legal obligation, vital interests, public task and legitimate interests. For AI, each processing moment (training, retrieval, inference, logging) needs its own basis, recorded per dataset and stage.",
      "letter": "L",
      "url": "https://aigovernanceengineer.com/glossary/lawful-basis",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-lawful-basis",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-least-agency",
      "term": "Least agency",
      "definition": "The principle, in the OWASP agentic list, of giving an agent no more autonomy than its task needs: agentic behaviour deployed where it is not needed widens the attack surface without adding value. The cheapest agent control is the agent not built, such as a fixed workflow with one model call in place of a planner.",
      "letter": "L",
      "url": "https://aigovernanceengineer.com/glossary/least-agency",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-least-agency",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-legitimate-interest-assessment-lia",
      "term": "Legitimate-interest assessment (LIA)",
      "definition": "The documented three-step test for relying on legitimate interests: a lawful, precise and present interest; processing necessary for it; and a balance not overridden by people's rights and reasonable expectations. Kept as a versioned artefact that points each mitigation at the control implementing it.",
      "letter": "L",
      "url": "https://aigovernanceengineer.com/glossary/legitimate-interest-assessment-lia",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-legitimate-interest-assessment-lia",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-lime",
      "term": "LIME",
      "definition": "Local Interpretable Model-agnostic Explanations: explains one prediction by fitting a simple interpretable model to the black box's behaviour on perturbed samples around the input; vulnerable to off-manifold manipulation.",
      "letter": "L",
      "url": "https://aigovernanceengineer.com/glossary/lime",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-lime",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-localisation-by-jurisdiction",
      "term": "Localisation (by jurisdiction)",
      "definition": "Controlling where an AI system runs and which features it offers in each jurisdiction, with per-jurisdiction rule sets as code, regional instances where residency requires them and feature flags by region, so one market can be switched off without touching the others. A system launches in a jurisdiction only once its duties there are shown to be met.",
      "letter": "L",
      "url": "https://aigovernanceengineer.com/glossary/localisation-by-jurisdiction",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-localisation-by-jurisdiction",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-loss-of-control",
      "term": "Loss of control",
      "definition": "One of the systemic risks the GPAI Code of Practice specifies: risks from humans losing the ability to reliably direct, modify or shut down a model, which may emerge from misalignment, self-replication, deception, resistance to goal modification or power-seeking. Signatories assess it for models with systemic risk; a deployer of agents asks how autonomy and tool use were evaluated.",
      "letter": "L",
      "url": "https://aigovernanceengineer.com/glossary/loss-of-control",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-loss-of-control",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-machine-learning",
      "term": "Machine learning",
      "definition": "The branch of AI in which a system improves at a task by learning patterns from data rather than by following rules people wrote. ISO/IEC 22989 groups its approaches into supervised, unsupervised, semi-supervised and reinforcement learning.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/machine-learning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-machine-learning",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-machine-unlearning",
      "term": "Machine unlearning",
      "definition": "Techniques that remove a training record's influence from a model without full retraining. Exact methods retrain an affected shard; approximate methods adjust weights and are hard to verify, so an unlearning claim is tested with membership-inference or extraction evals.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/machine-unlearning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-machine-unlearning",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-machine-readable-evidence",
      "term": "Machine-readable evidence",
      "definition": "Evidence a machine can query, diff and aggregate (OSCAL artefacts, structured eval results, signed logs), as opposed to screenshots and exported spreadsheets.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/machine-readable-evidence",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-machine-readable-evidence",
      "chapters": [
        {
          "number": "03",
          "url": "https://aigovernanceengineer.com/bok/values-and-principles"
        },
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        }
      ]
    },
    {
      "id": "t-major-ict-related-incident-dora",
      "term": "Major ICT-related incident (DORA)",
      "definition": "Under the EU Digital Operational Resilience Act, an ICT-related incident at a financial entity that meets the classification criteria for a major incident. It is reported within 4 hours of classification and no later than 24 hours from awareness (within 4 hours of a classification made after those 24 hours), then in intermediate and final reports.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/major-ict-related-incident-dora",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-major-ict-related-incident-dora",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-manufacturing-defect",
      "term": "Manufacturing defect",
      "definition": "In product liability, a departure of a unit from its own design. For AI: the wrong model version, corrupted weights, a misconfigured guardrail or a broken data pipeline in the deployed system.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/manufacturing-defect",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-manufacturing-defect",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-market-surveillance-authority",
      "term": "Market surveillance authority",
      "definition": "The national authority designated to enforce the AI Act for products placed on its market, with powers to investigate, demand documentation and require corrective action.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/market-surveillance-authority",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-market-surveillance-authority",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-maturity-floor",
      "term": "Maturity floor",
      "definition": "The single overall maturity level of an AI governance function: the level of its weakest stack layer. It is a floor for planning, not a verdict on the whole function. The per-layer profile shows where the leverage is, and the next move is the next criterion in the weakest layer.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/maturity-floor",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-maturity-floor",
      "chapters": [
        {
          "number": "07",
          "url": "https://aigovernanceengineer.com/bok/maturity-model"
        }
      ]
    },
    {
      "id": "t-mcp",
      "term": "MCP",
      "definition": "Model Context Protocol: an open protocol for connecting AI applications to tools and data sources; its 2026 specification adds OAuth 2.1 resource-server patterns and issuer-bound credentials for agent authorisation. It secures the hop between one client and one server; which agent sits behind the client is for a workload identity to say.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/mcp",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-mcp",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-membership-inference",
      "term": "Membership inference",
      "definition": "An attack that determines whether a specific person's record was in a model's training set from the model's behaviour. The EDPB counts resistance to it among the evidence for claiming a model is anonymous.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/membership-inference",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-membership-inference",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-memory-poisoning",
      "term": "Memory poisoning",
      "definition": "An injection that writes to an agent's long-term memory, a retrieval corpus, a vector store or a hosted memory service, and so taints every later session that reads from that store. OWASP's agentic list has it as ASI06 Memory & Context Poisoning and MITRE ATLAS as AI Agent Context Poisoning (AML.T0080).",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/memory-poisoning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-memory-poisoning",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-mitigation-hierarchy",
      "term": "Mitigation hierarchy",
      "definition": "The order in which risk treatments are tried: eliminate, substitute, engineer, administrative, then accept and monitor. Borrowed from the occupational-safety hierarchy of controls and mirrored in AI Act Article 9(5); higher rungs first, with the reason recorded when they are infeasible.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/mitigation-hierarchy",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-mitigation-hierarchy",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-model-anonymity",
      "term": "Model anonymity",
      "definition": "The EDPB's test for when a trained model falls outside the GDPR: both direct extraction of training subjects' data and obtaining it through queries must be insignificant, given all means reasonably likely to be used. Evidenced by design records and attack evals.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/model-anonymity",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-model-anonymity",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-model-card",
      "term": "Model card",
      "definition": "Structured, versioned documentation of a model (provenance, intended use, capabilities, evaluations and known failure modes) maintained as code.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/model-card",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-model-card",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-model-inversion",
      "term": "Model inversion",
      "definition": "An attack that reconstructs features of training subjects, such as a face, from a model's outputs and confidence scores. It can turn a deployed model into a channel for disclosing personal data.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/model-inversion",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-model-inversion",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-model-risk-management",
      "term": "Model risk management",
      "definition": "The banking-supervision practice of validating models for conceptual soundness, monitoring and outcomes analysis under effective challenge. SR 11-7 set the US tradition until SR 26-2 superseded it on 17 Apr 2026, and SR 26-2 leaves generative and agentic AI models out of its scope. A neighbour of this discipline, extended here to runtime behaviour and agents.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/model-risk-management",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-model-risk-management",
      "chapters": [
        {
          "number": "01",
          "url": "https://aigovernanceengineer.com/bok/definition"
        },
        {
          "number": "02",
          "url": "https://aigovernanceengineer.com/bok/why-now"
        },
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-model-signing",
      "term": "Model signing",
      "definition": "Signing a model's files at build: a manifest lists every file with its cryptographic digest and a detached signature covers the manifest, so any changed file fails verification. The OpenSSF Model Signing specification uses the Sigstore bundle format and supports keyless signing, private PKI, self-signed certificates or bare keys. Serving verifies the signature before it loads a model.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/model-signing",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-model-signing",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-multimodal-model",
      "term": "Multimodal model",
      "definition": "A model that takes or produces more than one modality (text, image, audio, video). Each modality is a new channel for personal data, injected instructions and synthetic content that may need marking, so guardrails and evals are needed per modality.",
      "letter": "M",
      "url": "https://aigovernanceengineer.com/glossary/multimodal-model",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-multimodal-model",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-near-miss",
      "term": "Near miss",
      "definition": "A hazard that a control, or luck, interrupted before harm occurred: the guardrail blocked the exfiltration, the reviewer caught the invented dosage. Near-miss data is evidence; the GPAI Code of Practice asks providers to report connected near-miss patterns with serious incidents.",
      "letter": "N",
      "url": "https://aigovernanceengineer.com/glossary/near-miss",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-near-miss",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-negative-space",
      "term": "Negative space",
      "definition": "The uses an AI system is explicitly not for, written into its Deployment Decision Record. It sits inside the provider's intended purpose and makes function creep detectable, because an unapproved use has somewhere to be recorded as out of scope.",
      "letter": "N",
      "url": "https://aigovernanceengineer.com/glossary/negative-space",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-negative-space",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-neural-data",
      "term": "Neural data",
      "definition": "Information generated by measuring the activity of a person's central or peripheral nervous system. California treats it as sensitive personal information, which switches on consent and assessment duties for AI systems that read wearables or brain-computer interfaces.",
      "letter": "N",
      "url": "https://aigovernanceengineer.com/glossary/neural-data",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-neural-data",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-nhi",
      "term": "NHI",
      "definition": "Non-human identity: the identity of an agent, service account or machine actor. Every NHI gets a registry entry, an owner and a scope before it is allowed to act.",
      "letter": "N",
      "url": "https://aigovernanceengineer.com/glossary/nhi",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-nhi",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-nist-ai-rmf",
      "term": "NIST AI RMF",
      "definition": "The NIST Artificial Intelligence Risk Management Framework 1.0 (NIST AI 100-1, January 2023): voluntary guidance organised as a Core of four functions (Govern, Map, Measure, Manage) with categories and subcategories, plus profiles and a companion Playbook.",
      "letter": "N",
      "url": "https://aigovernanceengineer.com/glossary/nist-ai-rmf",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-nist-ai-rmf",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-notified-body",
      "term": "Notified body",
      "definition": "A conformity assessment body designated under the EU AI Act to carry out third-party conformity assessment of high-risk AI systems. Under the notified-body procedure it assesses a provider's quality management system and technical documentation, with access to training, validation and testing data.",
      "letter": "N",
      "url": "https://aigovernanceengineer.com/glossary/notified-body",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-notified-body",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-oecd-ai-principles",
      "term": "OECD AI Principles",
      "definition": "The five values-based principles (inclusive growth and well-being; human rights, fairness and privacy; transparency and explainability; robustness, security and safety; accountability) and five policy recommendations of the OECD Recommendation on AI, adopted in 2019 and revised in 2024. A commitment by adhering governments, not a binding rule for companies.",
      "letter": "O",
      "url": "https://aigovernanceengineer.com/glossary/oecd-ai-principles",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-oecd-ai-principles",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-oecd-framework-for-the-classification-of-ai-systems",
      "term": "OECD Framework for the Classification of AI Systems",
      "definition": "An OECD tool (2022) for characterising an AI system from a policy perspective along five dimensions: People & Planet, Economic Context, Data & Input, AI Model, and Task & Output. In engineering practice its dimensions become groups of registry fields that route controls.",
      "letter": "O",
      "url": "https://aigovernanceengineer.com/glossary/oecd-framework-for-the-classification-of-ai-systems",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-oecd-framework-for-the-classification-of-ai-systems",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-opa-rego",
      "term": "OPA/Rego",
      "definition": "The Open Policy Agent and its Rego policy language, a general-purpose policy-as-code engine that evaluates governance rules in CI/CD and at runtime admission; the canonical example of executable policy-as-code.",
      "letter": "O",
      "url": "https://aigovernanceengineer.com/glossary/opa-rego",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-opa-rego",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        }
      ]
    },
    {
      "id": "t-opacity",
      "term": "Opacity",
      "definition": "The inability of a person to follow how a system reached an output. It has three sources (secrecy, technical illiteracy, and the nature and scale of machine learning), each with a different fix: disclosure, literacy, and explanation methods plus behavioural evals.",
      "letter": "O",
      "url": "https://aigovernanceengineer.com/glossary/opacity",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-opacity",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-open-weight-model",
      "term": "Open-weight model",
      "definition": "A model whose trained weights are published for download under a licence that may be permissive, copyleft, use-restricted or custom. Open weights are not open source; the deployer produces almost all the evidence (hashes, scans, evals, red team) and must honour the licence and any acceptable-use policy.",
      "letter": "O",
      "url": "https://aigovernanceengineer.com/glossary/open-weight-model",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-open-weight-model",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-operator-eu-ai-act",
      "term": "Operator (EU AI Act)",
      "definition": "The umbrella term for the actors the AI Act binds: provider, product manufacturer, deployer, authorised representative, importer and distributor. The same organisation can be several operators for different systems, or for the same one.",
      "letter": "O",
      "url": "https://aigovernanceengineer.com/glossary/operator-eu-ai-act",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-operator-eu-ai-act",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-oscal",
      "term": "OSCAL",
      "definition": "The Open Security Controls Assessment Language, a NIST machine-readable format for controls, assessments and evidence, used here as the format for audit-ready evidence.",
      "letter": "O",
      "url": "https://aigovernanceengineer.com/glossary/oscal",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-oscal",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "10",
          "url": "https://aigovernanceengineer.com/bok/reading-list"
        }
      ]
    },
    {
      "id": "t-output-suppression",
      "term": "Output suppression",
      "definition": "A filter around a model that stops it producing a person's data: the fast first answer to an erasure or objection request when the data sits in the weights and retraining is disproportionate. The CNIL accepts filters shown to be effective and robust and prefers general rules to a list of names. The data stays in the model.",
      "letter": "O",
      "url": "https://aigovernanceengineer.com/glossary/output-suppression",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-output-suppression",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-paved-path",
      "term": "Paved path",
      "definition": "A supported, low-friction default route (a template, library or pipeline) that makes the governed way the easiest way to ship, so engineers adopt governance without asking permission.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/paved-path",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-paved-path",
      "chapters": [
        {
          "number": "03",
          "url": "https://aigovernanceengineer.com/bok/values-and-principles"
        },
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        }
      ]
    },
    {
      "id": "t-personal-data-breach",
      "term": "Personal data breach",
      "definition": "A breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data, notified to the authority within 72 hours unless unlikely to result in a risk. AI adds regurgitation, inversion and prompt-injection exfiltration as routes.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/personal-data-breach",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-personal-data-breach",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-pipia",
      "term": "PIPIA",
      "definition": "China's personal information protection impact assessment under PIPL Articles 55 and 56, required in advance for sensitive data, automated decision-making, entrusted processing and cross-border provision, with the report kept for at least three years.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/pipia",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-pipia",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-placing-on-the-market",
      "term": "Placing on the market",
      "definition": "Under the EU AI Act, the first making available of an AI system or general-purpose AI model on the Union market; later supplies in the course of a commercial activity are making available. For a high-risk system, the conformity assessment and the technical documentation come before it, or before putting into service.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/placing-on-the-market",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-placing-on-the-market",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-policy-card",
      "term": "Policy Card",
      "definition": "A JSON-schema, machine-readable governance artefact that declares an agent's allowed and forbidden behaviours for runtime enforcement.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/policy-card",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-policy-card",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "10",
          "url": "https://aigovernanceengineer.com/bok/reading-list"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-policy-verdict",
      "term": "Policy verdict",
      "definition": "The structured record a policy engine emits each time it evaluates a rule: allow or deny, the versioned rule id, a hash of the input and a timestamp, signed and written to the evidence store. A release or tool call without a verdict is an audit finding, and one that passed under an exception names it in its verdict.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/policy-verdict",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-policy-verdict",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-policy-as-code",
      "term": "Policy-as-code",
      "definition": "Governance policy expressed in an executable policy language (OPA/Rego, Cedar) that evaluates in CI/CD and at admission; the narrower, pipeline subset of governance-as-code.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/policy-as-code",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-policy-as-code",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        }
      ]
    },
    {
      "id": "t-post-market-monitoring",
      "term": "Post-market monitoring",
      "definition": "The AI Act Article 72 duty to actively monitor a high-risk system's performance and risks after deployment, throughout its lifetime.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/post-market-monitoring",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-post-market-monitoring",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-pre-determined-changes",
      "term": "Pre-determined changes",
      "definition": "Changes to a high-risk system that continues to learn, planned by the provider at the initial conformity assessment and described in the technical documentation; they are not substantial modifications. Engineered as a change envelope written in code.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/pre-determined-changes",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-pre-determined-changes",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-predictive-ai",
      "term": "Predictive AI",
      "definition": "AI that outputs an estimate about something that exists: a score, class or forecast. Its harms are mostly allocation harms, and its evidence is accuracy, calibration and error rates by subgroup, with a decision threshold someone owns. Also called discriminative AI.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/predictive-ai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-predictive-ai",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-presumption-of-conformity",
      "term": "Presumption of conformity",
      "definition": "The legal effect under AI Act Article 40: a high-risk system or GPAI model that conforms with OJ-cited harmonised standards is presumed to meet the requirements those standards cover, and no others. Unavailable until a standard is cited, which as of 2026-09-24 none is.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/presumption-of-conformity",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-presumption-of-conformity",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-privacy-by-design-and-by-default",
      "term": "Privacy by design and by default",
      "definition": "The GDPR Article 25 duty to build data protection principles into processing through technical and organisational measures, and to process by default only the personal data each purpose needs. In an AI stack it shows up as filters, retention rules and access limits enforced as code.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/privacy-by-design-and-by-default",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-privacy-by-design-and-by-default",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-privacy-enhancing-technology-pet",
      "term": "Privacy-enhancing technology (PET)",
      "definition": "A technique that reduces what an attacker, vendor or insider can learn from personal data, such as differential privacy, federated learning, synthetic data, masking or trusted execution. None makes a system compliant alone; each has a known failure mode and is evidenced by a test.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/privacy-enhancing-technology-pet",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-privacy-enhancing-technology-pet",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-product-liability-directive-pld",
      "term": "Product Liability Directive (PLD)",
      "definition": "Directive (EU) 2024/2853, which treats software, including AI, as a product; judges defect with learning and updates in view; lets courts order disclosure and presume defect; and applies to products placed on the market after 9 Dec 2026.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/product-liability-directive-pld",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-product-liability-directive-pld",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-profiling-override",
      "term": "Profiling override",
      "definition": "The rule in the third subparagraph of AI Act Article 6(3) that an Annex III system which performs profiling of natural persons is always high-risk, whichever filter condition it meets. A classification decision record therefore carries an explicit profiling flag, so a filter claim the override defeats is visible.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/profiling-override",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-profiling-override",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-progressive-delivery",
      "term": "Progressive delivery",
      "definition": "Releasing a change to a small, growing share of real traffic in stages (shadow, pilot, canary, general availability), each with rollback criteria registered before it starts and a tested path back to the previous version, so evidence about live behaviour arrives before full exposure. For AI systems it covers model, prompt, corpus and vendor-version changes alike.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/progressive-delivery",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-progressive-delivery",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-prohibited-practice",
      "term": "Prohibited practice",
      "definition": "An AI practice banned outright by AI Act Article 5, such as manipulative techniques that cause significant harm, social scoring, untargeted scraping of facial images, emotion recognition at work or school, and most real-time remote biometric identification in public for law enforcement. No risk acceptance can cover one.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/prohibited-practice",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-prohibited-practice",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-prompt-injection",
      "term": "Prompt injection",
      "definition": "An input that alters a model's behaviour or output in ways its designers did not intend. It is direct when the user supplies it and indirect when it arrives inside content the model processes, such as a web page, file or tool result. Contained by guardrails, least-privilege tools and evals.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/prompt-injection",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-prompt-injection",
      "chapters": [
        {
          "number": "01",
          "url": "https://aigovernanceengineer.com/bok/definition"
        },
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-proportionate-governance",
      "term": "Proportionate governance",
      "definition": "Running the same risk loop at an intensity set by organisation size, sector, maturity and risk tolerance, above a floor of controls that never tailors away. The AI Act itself scales documentation and quality-management duties for smaller firms. It lowers the cost of governance, not the protection owed.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/proportionate-governance",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-proportionate-governance",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-provider",
      "term": "Provider",
      "definition": "Under the EU AI Act, whoever develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free. It carries the design, documentation, conformity and monitoring duties for high-risk systems.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/provider",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-provider",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-proxy-label",
      "term": "Proxy label",
      "definition": "A training target that stands in for the construct a decision is meant to capture, such as health-care cost standing in for health need. When the proxy is shaped by unequal treatment, a model can be accurate on the proxy and biased on the construct.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/proxy-label",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-proxy-label",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-proxy-scan",
      "term": "Proxy scan",
      "definition": "A test that trains a model to predict a protected attribute from a system's features; features that predict it strongly are flagged as proxies to justify or remove, and the result is recorded in the data card. It finds proxy variables before an outcome metric shows their effect.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/proxy-scan",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-proxy-scan",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-proxy-variable",
      "term": "Proxy variable",
      "definition": "A feature that carries the information of a protected characteristic, such as postcode for ethnicity, so that a model can discriminate without using the attribute itself. Proxy tests look for features that predict the protected attribute.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/proxy-variable",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-proxy-variable",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-pseudonymisation",
      "term": "Pseudonymisation",
      "definition": "Processing personal data so it can no longer be attributed to a person without additional information kept separately and protected. Pseudonymised data stays personal data for whoever can re-attribute it; it is a security measure, not anonymisation.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/pseudonymisation",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-pseudonymisation",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-purpose-limitation",
      "term": "Purpose limitation",
      "definition": "The GDPR principle that personal data collected for a specified purpose may not be further processed in an incompatible way; Article 6(4) sets the compatibility test. Enforced in AI pipelines by purpose tags on datasets and a policy that denies runs whose declared purpose does not match.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/purpose-limitation",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-purpose-limitation",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-putting-into-service",
      "term": "Putting into service",
      "definition": "Under the EU AI Act, the supply of an AI system for first use directly to the deployer, or for the provider's own use, in the Union for its intended purpose. Own use counts: an organisation that builds a system and runs it itself is its provider and its deployer, with no sale involved.",
      "letter": "P",
      "url": "https://aigovernanceengineer.com/glossary/putting-into-service",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-putting-into-service",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-qms-art-17",
      "term": "QMS (Art. 17)",
      "definition": "The quality management system that AI Act Article 17 requires of high-risk providers; distinct from an ISO/IEC 42001 AIMS, which certifies a management system but is not harmonised.",
      "letter": "Q",
      "url": "https://aigovernanceengineer.com/glossary/qms-art-17",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-qms-art-17",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-raise-act",
      "term": "RAISE Act",
      "definition": "New York's Responsible AI Safety and Education Act, a frontier-AI safety law binding large frontier developers to publish a safety framework and every frontier developer to report critical safety incidents; signed 19 December 2025 and taking effect 1 January 2027 after a March 2026 chapter amendment that placed oversight in an office within the Department of Financial Services (DFS).",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/raise-act",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-raise-act",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-realised-risk-reduction",
      "term": "Realised risk reduction",
      "definition": "The measured drop in a named failure mode's rate or blast radius in production; one of the two tests of the discipline, against framework coverage.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/realised-risk-reduction",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-realised-risk-reduction",
      "chapters": [
        {
          "number": "01",
          "url": "https://aigovernanceengineer.com/bok/definition"
        },
        {
          "number": "03",
          "url": "https://aigovernanceengineer.com/bok/values-and-principles"
        }
      ]
    },
    {
      "id": "t-reason-code",
      "term": "Reason code",
      "definition": "A stable, human-readable statement of a principal factor behind an adverse decision, mapped from the factors the model actually scored and versioned with the model; required in substance by US adverse-action rules.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/reason-code",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-reason-code",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-reasonably-foreseeable-misuse",
      "term": "Reasonably foreseeable misuse",
      "definition": "Use of an AI system not in accordance with its intended purpose that may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems. Distinct from an attack; kept in a misuse register that feeds tests, runtime policy and the instructions for use.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/reasonably-foreseeable-misuse",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-reasonably-foreseeable-misuse",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-records-of-processing-activities-ropa",
      "term": "Records of processing activities (ROPA)",
      "definition": "The GDPR Article 30 record of each processing activity: purposes, categories of data and people, recipients, transfers, retention and security. For AI it is best generated per processing moment from the registry and data cards, so it does not go stale.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/records-of-processing-activities-ropa",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-records-of-processing-activities-ropa",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-recourse",
      "term": "Recourse",
      "definition": "The ability of a person to obtain a different decision by changing inputs they can actually act on, such as income rather than age. Counterfactual explanations restricted to actionable features are its usual engineering form; a system can offer contestation and still leave no recourse.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/recourse",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-recourse",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-red-teaming",
      "term": "Red teaming",
      "definition": "Structured adversarial testing of a model or agent to elicit failures (jailbreaks, injection, tool misuse) before an attacker does; treated here as an evidence-producing control.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/red-teaming",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-red-teaming",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-regurgitation",
      "term": "Regurgitation",
      "definition": "A model reproducing memorised training data verbatim, including personal data, whether prompted deliberately (training-data extraction) or not. Detected by output checks and canaries, and tested by extraction evals.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/regurgitation",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-regurgitation",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-reinforcement-learning",
      "term": "Reinforcement learning",
      "definition": "Learning to maximise a reward signal through trial and feedback. Its characteristic failure is reward hacking, so the reward is recorded as the system's objective and evals look for unintended strategies.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/reinforcement-learning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-reinforcement-learning",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-reinforcement-learning-from-human-feedback-rlhf",
      "term": "Reinforcement learning from human feedback (RLHF)",
      "definition": "A way to align a pre-trained model: supervised fine-tuning on human demonstrations, then reinforcement learning against a reward model trained on human rankings of outputs. The raters' instructions and the reward model become governed artefacts, because they shape what the model refuses and prefers.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/reinforcement-learning-from-human-feedback-rlhf",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-reinforcement-learning-from-human-feedback-rlhf",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-reporting-clock",
      "term": "Reporting clock",
      "definition": "A statutory deadline for an incident notification, defined by its trigger (awareness, classification, causal link or determination), recipient, content and follow-ups, as in AI Act Article 73. One event can start several clocks, so each is held as its own timer on a single incident record.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/reporting-clock",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-reporting-clock",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-residual-risk",
      "term": "Residual risk",
      "definition": "What is left of a risk once treatment is applied. The EU AI Act requires residual risk per hazard and overall to be judged acceptable for high-risk systems. A residual rating credits only controls whose evidence is current.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/residual-risk",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-residual-risk",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-responsible-ai-licence-openrail",
      "term": "Responsible-AI licence (OpenRAIL)",
      "definition": "A licence that grants open, royalty-free access to an AI artefact while attaching prohibited uses that every redistribution and derivative must carry forward. The restrictions travel with the model, so a deployer's own terms of use must repeat them.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/responsible-ai-licence-openrail",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-responsible-ai-licence-openrail",
      "chapters": [
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-responsible-ai-principle-set",
      "term": "Responsible-AI principle set",
      "definition": "A published set of normative targets for AI, such as the OECD AI Principles, the UNESCO Recommendation, the HLEG requirements or the G7 Hiroshima principles. Not the house \"principle\", which is a rule of method; a principle set counts as applied only when an artefact evidences it.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/responsible-ai-principle-set",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-responsible-ai-principle-set",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-retrieval-augmented-generation-rag",
      "term": "Retrieval-augmented generation (RAG)",
      "definition": "A system that combines a model's learned memory with a retrievable store of documents at answer time. The corpus becomes behaviour, so it is governed like a model: versioned, carded, tied to the eval that tested it, with an entitlement check on what each user may retrieve.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/retrieval-augmented-generation-rag",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-retrieval-augmented-generation-rag",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-reward-hacking",
      "term": "Reward hacking",
      "definition": "A system finding an unintended way to maximise its reward or objective without doing what its designers meant. Answered by recording the objective and testing for unintended strategies, not only for the intended task.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/reward-hacking",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-reward-hacking",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-right-to-explanation-ai-act-art-86",
      "term": "Right to explanation (AI Act Art. 86)",
      "definition": "The right of a person affected by a deployer's decision based on an Annex III high-risk system's output, with legal or similarly significant adverse effects, to clear and meaningful explanations of the system's role and the main elements of the decision, where Union law does not already provide it.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/right-to-explanation-ai-act-art-86",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-right-to-explanation-ai-act-art-86",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-rights-reservation-tdm-opt-out",
      "term": "Rights reservation (TDM opt-out)",
      "definition": "A rightholder's express reservation of text and data mining under Article 4(3) of the DSM Directive, which takes the content out of the general mining exception; for content made publicly available online it must be made in an appropriate manner, such as machine-readable means. General-purpose AI model providers must identify and comply with such reservations.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/rights-reservation-tdm-opt-out",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-rights-reservation-tdm-opt-out",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-risk-acceptance",
      "term": "Risk acceptance",
      "definition": "A named, signed and expiring decision by someone with the authority a residual band requires, that a risk may remain for a bounded period under named compensating controls and a monitoring signal that voids it. Authority rises with the rating; a prohibited use cannot be accepted by anyone.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/risk-acceptance",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-risk-acceptance",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-risk-appetite",
      "term": "Risk appetite",
      "definition": "How much risk, and of which kinds, an organisation is prepared to take on in pursuit of its objectives. In this book it is compiled from an approved statement into a versioned data file that gates read, rather than left in a board paper.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/risk-appetite",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-risk-appetite",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-risk-management",
      "term": "Risk management",
      "definition": "The organised practice of steering an organisation's decisions with its risks in view: identify, assess, treat and monitor, in a loop. For high-risk systems the AI Act requires a documented risk management system across the lifecycle.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/risk-management",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-risk-management",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-risk-matrix",
      "term": "Risk matrix",
      "definition": "A grid that turns a likelihood rating and a severity rating, each on defined scales, into a band that triggers a treatment, a gate and a review cadence. Useful for consistency, not precision; keep the numbers behind each cell.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/risk-matrix",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-risk-matrix",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-risk-register",
      "term": "Risk register",
      "definition": "The evidence record of the risk loop: one versioned file per risk, keyed to a registry id, with ratings, treatment, controls that resolve to evidence, owner, acceptance, review cadence and links to evals, incidents and obligations. Deploy gates read it; it evidences an Article 9 risk management system.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/risk-register",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-risk-register",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-risk-source",
      "term": "Risk source",
      "definition": "Anything that can give rise to risk alone or in combination, such as a dataset, a tool grant, an adversary or a user group. Internal sources sit inside the organisation's control; external ones arise outside it and are mostly engineered against and monitored.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/risk-source",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-risk-source",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-risk-tier",
      "term": "Risk tier",
      "definition": "An organisation's own rating of an AI use case, computed at intake by a versioned policy from declared profile fields such as autonomy, decision impact, exposure, reversibility, vulnerable groups, data class and third parties. The tier selects the assessments, evals, thresholds, approvers and review cadence a system must pass; it sits beside the legal classification, not in place of it.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/risk-tier",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-risk-tier",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-risk-tolerance",
      "term": "Risk tolerance",
      "definition": "The readiness to bear a given risk in order to achieve objectives. Engineered as the highest residual band a system tier may carry before a deploy gate requires a signed acceptance.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/risk-tolerance",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-risk-tolerance",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-rollback-criteria",
      "term": "Rollback criteria",
      "definition": "The conditions, written into the rollout plan before a release stage starts, under which the pipeline returns to the previous version automatically: a floor breached against the control group, a disagreement or override rate above a threshold, a severity-1 event. A criterion set after the metric moved is a negotiation, not a control.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/rollback-criteria",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-rollback-criteria",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-root-cause-analysis-rca",
      "term": "Root-cause analysis (RCA)",
      "definition": "The review that answers why an incident happened and why the controls did not stop it, using techniques such as five whys, fault tree analysis and blameless post-mortems, and codes each confirmed cause against a taxonomy that names the control that should have caught it.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/root-cause-analysis-rca",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-root-cause-analysis-rca",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-runtime-data-path",
      "term": "Runtime data path",
      "definition": "The live connection between production and the governance function (discovery, telemetry and enforcement), without which a registry or dashboard describes the program but cannot see what is running.",
      "letter": "R",
      "url": "https://aigovernanceengineer.com/glossary/runtime-data-path",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-runtime-data-path",
      "chapters": [
        {
          "number": "02",
          "url": "https://aigovernanceengineer.com/bok/why-now"
        },
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "07",
          "url": "https://aigovernanceengineer.com/bok/maturity-model"
        }
      ]
    },
    {
      "id": "t-safetensors",
      "term": "Safetensors",
      "definition": "A file format for storing a model's tensors safely, as opposed to Python pickle, whose loading can run arbitrary code and which the Python documentation calls not secure. Storing weights as safetensors, and scanning any remaining pickle files for code-executing imports before they reach a registry, closes a common supply-chain route into serving.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/safetensors",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-safetensors",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-safety-component",
      "term": "Safety component",
      "definition": "Under the AI Act as amended in 2026, a component of a product or AI system whose intended purpose is to prevent or mitigate risks to the health and safety of persons or property, or whose failure endangers them. AI used solely for convenience, efficiency or quality control is excluded unless its failure would endanger safety.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/safety-component",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-safety-component",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-sanctioned-ai-gateway",
      "term": "Sanctioned AI gateway",
      "definition": "The single approved route by which staff reach AI tools and model APIs: approved tools behind single sign-on and a gateway that classifies each request by data class, allows, redacts or blocks it under the acceptable-use policy, checks for a current attestation and logs a decision per call. It works by being the easiest route.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/sanctioned-ai-gateway",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-sanctioned-ai-gateway",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-sb-53",
      "term": "SB 53",
      "definition": "California's frontier-AI transparency law (TFAIA), in force 1 Jan 2026, covering frontier developers training models above 10^26 FLOP: all of them publish transparency reports and report critical safety incidents, and large frontier developers also publish a safety framework.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/sb-53",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-sb-53",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-self-supervised-learning",
      "term": "Self-supervised learning",
      "definition": "Learning by predicting parts of the input itself, such as the next token, over large corpora; the AI Act's definition of a general-purpose model names self-supervision at scale. Corpus provenance, rights and memorisation are hard to trace, which is why the AIBOM records dataset provenance.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/self-supervised-learning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-self-supervised-learning",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-serious-incident",
      "term": "Serious incident",
      "definition": "Under AI Act Article 3(49), an incident or malfunction of an AI system that directly or indirectly leads to (a) a death or serious harm to health, (b) serious and irreversible disruption of critical infrastructure, (c) infringement of Union-law obligations protecting fundamental rights, or (d) serious harm to property or the environment, triggering Article 73 reporting.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/serious-incident",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-serious-incident",
      "chapters": [
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-shadow-ai",
      "term": "Shadow AI",
      "definition": "An AI system, model or agent running without registration, including staff use of unapproved AI tools; the failure mode that makes an inventory complete only for the honest. It is found by discovery and answered with a sanctioned route, not a ban.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/shadow-ai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-shadow-ai",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "07",
          "url": "https://aigovernanceengineer.com/bok/maturity-model"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-shadow-deployment",
      "term": "Shadow deployment",
      "definition": "A release stage in which a new model or system receives live inputs but its outputs are not used, so its behaviour on real traffic can be compared with the incumbent or with human decisions before any exposure. The disagreement log is its evidence.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/shadow-deployment",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-shadow-deployment",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-shap",
      "term": "SHAP",
      "definition": "SHapley Additive exPlanations: a feature-attribution method that assigns each input feature a share of a particular prediction, based on Shapley values; its explanations depend on the chosen baseline or background data.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/shap",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-shap",
      "chapters": [
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-small-language-model-slm",
      "term": "Small language model (SLM)",
      "definition": "A language model small enough to run close to the user, for example on a phone. Its controls must ship with it: guardrails on the device, a version inventory across the fleet and a kill switch delivered as a remote flag or app update.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/small-language-model-slm",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-small-language-model-slm",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-small-mid-cap-enterprise-smc",
      "term": "Small mid-cap enterprise (SMC)",
      "definition": "An enterprise that has outgrown the SME definition but falls within the EU small mid-cap definition. The Digital Omnibus extends some SME relief under the AI Act to SMCs, such as simplified technical documentation and a proportionate quality management system.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/small-mid-cap-enterprise-smc",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-small-mid-cap-enterprise-smc",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-special-category-data",
      "term": "Special category data",
      "definition": "The GDPR Article 9 categories whose processing is prohibited unless a condition applies: data revealing racial or ethnic origin, political opinions, beliefs or union membership, and genetic, biometric (for identification), health, sex-life and sexual-orientation data. AI can create it by inference.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/special-category-data",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-special-category-data",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-stakeholder-mapping",
      "term": "Stakeholder mapping",
      "definition": "Naming who is affected by or holds a view on an AI system (users, affected non-users, deployers, providers, internal functions, regulators, the governing body) and how each view enters the risk loop, with the consultation logged. A FRIA names the affected groups too.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/stakeholder-mapping",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-stakeholder-mapping",
      "chapters": [
        {
          "number": "13",
          "url": "https://aigovernanceengineer.com/bok/risk-management"
        }
      ]
    },
    {
      "id": "t-star-for-ai",
      "term": "STAR for AI",
      "definition": "CSA's security assurance and certification programme for AI, built on the AICM, with a self-assessment tier, an automated \"Valid-AI-ted\" tier and a Level 2 combining ISO/IEC 42001 with the validated assessment.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/star-for-ai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-star-for-ai",
      "chapters": [
        {
          "number": "07",
          "url": "https://aigovernanceengineer.com/bok/maturity-model"
        },
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        }
      ]
    },
    {
      "id": "t-stride",
      "term": "STRIDE",
      "definition": "A threat-classification checklist from Microsoft's Security Development Lifecycle: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege. For an AI system it is walked per element of the data-flow diagram and then extended with AI-specific catalogues such as MITRE ATLAS and the OWASP lists.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/stride",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-stride",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-sub-processor",
      "term": "Sub-processor",
      "definition": "A processor that another processor engages to carry out processing for a controller, such as the model host behind an AI vendor. Under GDPR Article 28 it needs the controller's prior written authorisation, specific or general with notice of changes and a chance to object, and the same data protection obligations flow down to it by contract.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/sub-processor",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-sub-processor",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-substantial-modification",
      "term": "Substantial modification",
      "definition": "Under the EU AI Act, a change after placing on the market that the initial conformity assessment did not foresee and that affects compliance or changes the intended purpose. It triggers a new conformity assessment and can turn a deployer or distributor into the provider; pre-determined changes are exempt.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/substantial-modification",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-substantial-modification",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-supervised-learning",
      "term": "Supervised learning",
      "definition": "Learning from labelled examples. Labels encode past human decisions with their errors and bias, so the data card records label provenance and the eval gate tests error rates by subgroup.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/supervised-learning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-supervised-learning",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-svid",
      "term": "SVID",
      "definition": "SPIFFE Verifiable Identity Document: a short-lived cryptographic identity document, either an X.509 certificate or a JWT, that proves a workload's SPIFFE ID and is issued and rotated through the SPIFFE Workload API, which SPIRE implements. A credential that expires in minutes need not be hunted down after an incident, only not reissued.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/svid",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-svid",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-synthetic-data",
      "term": "Synthetic data",
      "definition": "Data generated by a model or simulation rather than collected from people or events, used to augment training sets, test edge cases or reduce exposure of personal data. It inherits the biases of its generator and can leak the records it was fitted on, so it is tested like any other dataset.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/synthetic-data",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-synthetic-data",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-system-card",
      "term": "System card",
      "definition": "Documentation of a deployed AI system as a whole (models, prompts, retrieval, tools, guardrails and oversight), where a model card documents one model. Its audience is deployers, authorities and the public; its evidence is the registry entry, the guardrail configuration and red-team results.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/system-card",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-system-card",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-systemic-risk",
      "term": "Systemic risk",
      "definition": "Under the AI Act, the risk posed by the most capable general-purpose AI models, triggering extra evaluation, adversarial-testing and incident-reporting duties on their providers.",
      "letter": "S",
      "url": "https://aigovernanceengineer.com/glossary/systemic-risk",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-systemic-risk",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-tabletop-exercise",
      "term": "Tabletop exercise",
      "definition": "A scheduled, scored rehearsal of an incident playbook against a named failure mode, producing the same records a real incident would (record, clocks, draft reports, containment events) tagged as a drill. The playbook is the claim; the drill result is the evidence.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/tabletop-exercise",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-tabletop-exercise",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-tc260",
      "term": "TC260",
      "definition": "The National Technical Committee 260 on Cybersecurity of the Standardization Administration of China (全国网络安全标准化技术委员会), which drafts China's cybersecurity and AI national standards (GB and GB/T) and publishes the voluntary AI Safety Governance Framework (1.0 in 2024, 2.0 in 2025, 3.0 on 14 September 2026).",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/tc260",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-tc260",
      "chapters": [
        {
          "number": "08",
          "url": "https://aigovernanceengineer.com/bok/regulatory-map"
        },
        {
          "number": "21",
          "url": "https://aigovernanceengineer.com/bok/ai-laws-worldwide"
        }
      ]
    },
    {
      "id": "t-tdm-exception",
      "term": "TDM exception",
      "definition": "Two EU copyright exceptions for text and data mining (DSM Directive). Article 3 covers scientific research by research organisations and cultural heritage institutions; no reservation or contract can override it (Article 7(1)). Article 4 lets anyone mine lawfully accessible works, AI training included, unless the rightholder has reserved it, for online content in an appropriate manner such as machine-readable means.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/tdm-exception",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-tdm-exception",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-technical-documentation-annex-iv",
      "term": "Technical documentation (Annex IV)",
      "definition": "The provider's technical file for a high-risk AI system, drawn up before placing on the market and kept up to date under Article 11: description, development process, data, testing, oversight, risk management, standards, declaration and post-market monitoring plan. Most items can be generated from pipeline records.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/technical-documentation-annex-iv",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-technical-documentation-annex-iv",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-test-set-contamination",
      "term": "Test-set contamination",
      "definition": "The presence of evaluation items in a model's training data, which inflates its scores; it can be demonstrated even for black-box language models. Mitigated with private held-out sets, rotated items and dated test items.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/test-set-contamination",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-test-set-contamination",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-testing-in-real-world-conditions",
      "term": "Testing in real-world conditions",
      "definition": "Under the EU AI Act, temporary testing of an AI system for its intended purpose outside a laboratory, under a plan approved by the market surveillance authority, with registration, informed consent of subjects, effective oversight and reversible outputs, for a limited period.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/testing-in-real-world-conditions",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-testing-in-real-world-conditions",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        }
      ]
    },
    {
      "id": "t-threat-model-ai",
      "term": "Threat model (AI)",
      "definition": "A versioned record of what can go wrong with an AI system and what is done about it: data flows and trust boundaries, threats per element from STRIDE and AI-specific catalogues, a decision on each, and the test that proves each mitigation. It answers the four threat-modelling questions, ending with whether the job was done well enough.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/threat-model-ai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-threat-model-ai",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-three-lines-model",
      "term": "Three Lines Model",
      "definition": "The Institute of Internal Auditors' 2020 update of the \"three lines of defense\": the governing body oversees; management holds first-line roles (delivering products and services) and second-line roles (risk expertise, support and challenge); internal audit gives independent third-line assurance.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/three-lines-model",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-three-lines-model",
      "chapters": [
        {
          "number": "12",
          "url": "https://aigovernanceengineer.com/bok/governance-program"
        }
      ]
    },
    {
      "id": "t-token-passthrough",
      "term": "Token passthrough",
      "definition": "The anti-pattern in which a server accepts a token that was not issued to it and forwards it, unmodified, to a downstream API, which may then trust it as if the server had validated it. The MCP specification forbids it: a server must not accept any token not explicitly issued for it, and so checks each token's audience.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/token-passthrough",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-token-passthrough",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-tool-allow-list",
      "term": "Tool allow-list",
      "definition": "The deny-by-default list of tools an agent may call, each entry pinned by a hash of the tool's definition and bounded by resource scope, operation class, rate, egress destinations, data classes and a checkpoint rule, evaluated by the tool gateway on every call. OWASP asks for such per-tool least-privilege profiles.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/tool-allow-list",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-tool-allow-list",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-tool-poisoning",
      "term": "Tool poisoning",
      "definition": "Tampering with a tool an agent uses, through its model-visible definition (description, schema, metadata) or its behaviour, so the agent acts on false premises. OWASP files manipulation of a legitimate tool's interface under ASI02 and a tool compromised at the source under ASI04; MITRE ATLAS lists AI Agent Tool Poisoning (AML.T0110).",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/tool-poisoning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-tool-poisoning",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-training-content-summary",
      "term": "Training-content summary",
      "definition": "The public summary of the content used to train a general-purpose AI model, required by AI Act Article 53(1)(d) on a mandatory Commission template covering data sources, including the most-scraped domains, and data processing.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/training-content-summary",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-training-content-summary",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-training-validation-and-testing-data",
      "term": "Training, validation and testing data",
      "definition": "The three data sets the AI Act defines for high-risk systems: training data fits the model, validation data tunes it and guards against overfitting, and testing data gives an independent check before release. Keeping them separate, and proving it, is what stops test-set contamination.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/training-validation-and-testing-data",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-training-validation-and-testing-data",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-trajectory-agent",
      "term": "Trajectory (agent)",
      "definition": "The sequence of plans, tool calls and memory operations that led an agent to an effect. Agents are evaluated on their trajectories as well as their final outputs, because a right result reached through a tool the agent should never have held is still a failure.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/trajectory-agent",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-trajectory-agent",
      "chapters": [
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-transaction-token-txn-token",
      "term": "Transaction token (Txn-Token)",
      "definition": "A short-lived, signed token, specified in an IETF OAuth working group draft, that carries user identity, workload identity and authorisation context through a call chain within one trusted domain, so downstream services can decide on protected context. Still a draft (revision 11, 30 Jul 2026) as of 2026-09-24.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/transaction-token-txn-token",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-transaction-token-txn-token",
      "chapters": [
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    },
    {
      "id": "t-transfer-impact-assessment-tia",
      "term": "Transfer impact assessment (TIA)",
      "definition": "The data exporter's assessment of whether the law of a third country lets the importer honour the transfer tool, such as standard contractual clauses, and which supplementary measures are needed. Remote inference endpoints and vendor telemetry outside the EEA can trigger it.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/transfer-impact-assessment-tia",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-transfer-impact-assessment-tia",
      "chapters": [
        {
          "number": "19",
          "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
        }
      ]
    },
    {
      "id": "t-transparency",
      "term": "Transparency",
      "definition": "In NIST's framing, how far information about an AI system and its outputs reaches the people who interact with it: what happened. Evidenced by records of what ran (registry, model and system cards, logs) and by the disclosures the law requires.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/transparency",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-transparency",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        },
        {
          "number": "16",
          "url": "https://aigovernanceengineer.com/bok/fairness-and-explainability"
        }
      ]
    },
    {
      "id": "t-trustworthy-ai",
      "term": "Trustworthy AI",
      "definition": "A banner used by other people's frameworks, notably the EU High-Level Expert Group and NIST, whose seven trustworthy characteristics make it concrete. This book cites it rather than adopting it: the discipline is measured by realised risk reduction and evidence, not by the label.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/trustworthy-ai",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-trustworthy-ai",
      "chapters": [
        {
          "number": "01",
          "url": "https://aigovernanceengineer.com/bok/definition"
        },
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-trustworthy-characteristics-nist",
      "term": "Trustworthy characteristics (NIST)",
      "definition": "The seven characteristics of trustworthy AI in the NIST AI RMF: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; fair with harmful bias managed. Valid and reliable is the base; accountable and transparent spans the others.",
      "letter": "T",
      "url": "https://aigovernanceengineer.com/glossary/trustworthy-characteristics-nist",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-trustworthy-characteristics-nist",
      "chapters": [
        {
          "number": "22",
          "url": "https://aigovernanceengineer.com/bok/principles-and-standards"
        }
      ]
    },
    {
      "id": "t-udap",
      "term": "UDAP",
      "definition": "Unfair or deceptive acts or practices, prohibited by section 5 of the FTC Act and by state laws. Deception is a material representation likely to mislead; unfairness is substantial, unavoidable injury not outweighed by benefits. Unsubstantiated AI performance claims fall under it.",
      "letter": "U",
      "url": "https://aigovernanceengineer.com/glossary/udap",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-udap",
      "chapters": [
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-unsupervised-learning",
      "term": "Unsupervised learning",
      "definition": "Learning structure (clusters, anomalies) from data without labels. With no ground truth to test against, controls rely on stability tests and human review of the segments before they are used in decisions.",
      "letter": "U",
      "url": "https://aigovernanceengineer.com/glossary/unsupervised-learning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-unsupervised-learning",
      "chapters": [
        {
          "number": "11",
          "url": "https://aigovernanceengineer.com/bok/ai-defined"
        }
      ]
    },
    {
      "id": "t-use-case-record",
      "term": "Use-case record",
      "definition": "The intake record for a proposed AI use: business context, intended purpose and the uses ruled out, affected persons, decision authority, success metrics and error appetite, stored as fields on the registry entry so classification, thresholds, tests and impact assessments read the same facts.",
      "letter": "U",
      "url": "https://aigovernanceengineer.com/glossary/use-case-record",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-use-case-record",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "06",
          "url": "https://aigovernanceengineer.com/bok/the-role"
        },
        {
          "number": "14",
          "url": "https://aigovernanceengineer.com/bok/governing-development"
        }
      ]
    },
    {
      "id": "t-version-pinning",
      "term": "Version pinning",
      "definition": "Fixing, in the registry entry, the exact versions of the model, prompts, retrieval corpus and guardrails a deployed system uses, so what ran is known and any unpinned change, including a vendor's model update, is detected and treated as a release.",
      "letter": "V",
      "url": "https://aigovernanceengineer.com/glossary/version-pinning",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-version-pinning",
      "chapters": [
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "15",
          "url": "https://aigovernanceengineer.com/bok/governing-deployment"
        }
      ]
    },
    {
      "id": "t-watermarking",
      "term": "Watermarking",
      "definition": "Embedding a signal in generated content (image, audio, video or text) that a detector can later read to identify it as AI-generated. The AI Act asks providers of generative systems for machine-readable, detectable marking; NIST reviews watermarking alongside provenance tracking and detection. Marks can degrade under ordinary transformations, so their survival is tested.",
      "letter": "W",
      "url": "https://aigovernanceengineer.com/glossary/watermarking",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-watermarking",
      "chapters": [
        {
          "number": "18",
          "url": "https://aigovernanceengineer.com/bok/eu-ai-act"
        },
        {
          "number": "20",
          "url": "https://aigovernanceengineer.com/bok/existing-law"
        }
      ]
    },
    {
      "id": "t-widespread-infringement",
      "term": "Widespread infringement",
      "definition": "Under AI Act Article 3(61), an act or omission contrary to Union law protecting individuals' interests that harms, or is likely to harm, the collective interests of individuals across several Member States. It shortens the Article 73 serious-incident deadline to two days.",
      "letter": "W",
      "url": "https://aigovernanceengineer.com/glossary/widespread-infringement",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-widespread-infringement",
      "chapters": [
        {
          "number": "17",
          "url": "https://aigovernanceengineer.com/bok/incidents"
        }
      ]
    },
    {
      "id": "t-workload-identity",
      "term": "Workload identity",
      "definition": "The attributable identity a workload such as an agent carries across every hop, under which its actions are logged and its access is revoked, typically a short-lived, attested credential such as an SVID. It differs from channel authentication, which secures a single hop, such as a client talking to an MCP server.",
      "letter": "W",
      "url": "https://aigovernanceengineer.com/glossary/workload-identity",
      "anchor": "https://aigovernanceengineer.com/bok/glossary#t-workload-identity",
      "chapters": [
        {
          "number": "03",
          "url": "https://aigovernanceengineer.com/bok/values-and-principles"
        },
        {
          "number": "04",
          "url": "https://aigovernanceengineer.com/bok/the-stack"
        },
        {
          "number": "05",
          "url": "https://aigovernanceengineer.com/bok/patterns"
        },
        {
          "number": "23",
          "url": "https://aigovernanceengineer.com/bok/governing-agents"
        }
      ]
    }
  ]
}
