[{"term":"A2A (Agent2Agent protocol)","slug":"t-a2a-agent2agent-protocol","definition":"An open protocol for agents to hand tasks to one another, at version 1.0 since March 2026 and a Growth Stage project of the Linux Foundation-directed Agentic AI Foundation since August 2026.","url":"/glossary/a2a-agent2agent-protocol","anchor":"/bok/glossary#t-a2a-agent2agent-protocol","chapters":["23"]},{"term":"Abstention band","slug":"t-abstention-band","definition":"A range of scores in which a system does not act on its own but routes the case to a human reviewer. Its width is set by risk tier; the band size and the reviewers' override rate are monitored as signals.","url":"/glossary/abstention-band","anchor":"/bok/glossary#t-abstention-band","chapters":["11"]},{"term":"Acceptable-use policy (AUP)","slug":"t-acceptable-use-policy-aup","definition":"The staff-facing rules for using AI tools: which tools are approved, which data classes may go where, duties to review and disclose outputs, logging, attestation before access and consequences.","url":"/glossary/acceptable-use-policy-aup","anchor":"/bok/glossary#t-acceptable-use-policy-aup","chapters":["05","12"]},{"term":"Adaptiveness","slug":"t-adaptiveness","definition":"The ability of an AI system to change its behaviour while in use, through learning after deployment; optional under the EU AI Act definition.","url":"/glossary/adaptiveness","anchor":"/bok/glossary#t-adaptiveness","chapters":["11"]},{"term":"ADMT (California)","slug":"t-admt-california","definition":"Automated decisionmaking technology under the California CCPA regulations: technology that processes personal information and uses computation to replace, or substantially replace, human decision-making.","url":"/glossary/admt-california","anchor":"/bok/glossary#t-admt-california","chapters":["19"]},{"term":"Adverse action notice","slug":"t-adverse-action-notice","definition":"The notice a US creditor must give when it denies or worsens credit, stating the specific principal reasons. The reasons must be accurate even when the decision comes from a complex model, so reason codes need a fidelity test.","url":"/glossary/adverse-action-notice","anchor":"/bok/glossary#t-adverse-action-notice","chapters":["16","20"]},{"term":"Adverse-impact ratio (AIR)","slug":"t-adverse-impact-ratio-air","definition":"The selection rate of a group divided by the selection rate of the most-selected group.","url":"/glossary/adverse-impact-ratio-air","anchor":"/bok/glossary#t-adverse-impact-ratio-air","chapters":["16"]},{"term":"AESIA","slug":"t-aesia","definition":"Spain's Agencia Española de Supervisión de Inteligencia Artificial, a state agency based in A Coruña whose statute was approved by Royal Decree 729/2023, created to act as Spain's national supervisory authority for the AI Act.","url":"/glossary/aesia","anchor":"/bok/glossary#t-aesia","chapters":["08","21"]},{"term":"Agent (agentic AI)","slug":"t-agent-agentic-ai","definition":"An AI system that acts (browses, executes code, calls APIs, moves data or delegates to other agents) under delegated authority, rather than only producing text.","url":"/glossary/agent-agentic-ai","anchor":"/bok/glossary#t-agent-agentic-ai","chapters":["01","11","23"]},{"term":"Agent Card","slug":"t-agent-card","definition":"The JSON document an A2A agent publishes, usually at /.well-known/agent-card.json, describing its identity, skills, service endpoint and the authentication schemes it accepts.","url":"/glossary/agent-card","anchor":"/bok/glossary#t-agent-card","chapters":["23"]},{"term":"Agent registry","slug":"t-agent-registry","definition":"The runtime-aware inventory of every non-human actor (model, service and agent), each with an owner, a declared scope, a status and a kill switch, fed by a runtime data path rather than typed by hand.","url":"/glossary/agent-registry","anchor":"/bok/glossary#t-agent-registry","chapters":["04","05","06","23"]},{"term":"AI Act (EU)","slug":"t-ai-act-eu","definition":"Regulation (EU) 2024/1689, the EU's horizontal, risk-tiered law for AI, amended by the Digital Omnibus. It classifies systems by risk (prohibited, high-risk, limited, minimal) and imposes obligations accordingly.","url":"/glossary/ai-act-eu","anchor":"/bok/glossary#t-ai-act-eu","chapters":["08","18"]},{"term":"AI business operator (Korea)","slug":"t-ai-business-operator-korea","definition":"Under the Korean AI Basic Act, a legal person, organisation, individual or state body doing AI business, split into development business operators, who develop and provide AI, and utilisation business operators, who offer products or…","url":"/glossary/ai-business-operator-korea","anchor":"/bok/glossary#t-ai-business-operator-korea","chapters":["18","21"]},{"term":"AI governance","slug":"t-ai-governance","definition":"The set of rules, roles, controls and evidence that keeps AI systems within the limits an organisation or a state has chosen.","url":"/glossary/ai-governance","anchor":"/bok/glossary#t-ai-governance","chapters":["01","12","22"]},{"term":"AI governance committee","slug":"t-ai-governance-committee","definition":"The cross-functional body that takes the decisions a gate cannot: accepting residual risk above a product owner's authority, granting exceptions, weighing value trade-offs and approving the policy set.","url":"/glossary/ai-governance-committee","anchor":"/bok/glossary#t-ai-governance-committee","chapters":["12"]},{"term":"AI governance engineer","slug":"t-ai-governance-engineer","definition":"The person who holds the capability of AI governance engineering and is accountable for the three questions in production; a capability and a role, not necessarily a job title.","url":"/glossary/ai-governance-engineer","anchor":"/bok/glossary#t-ai-governance-engineer","chapters":["06"]},{"term":"AI governance engineering","slug":"t-ai-governance-engineering","definition":"The application of engineering practice (systems thinking, product thinking and code) to the governance of AI systems; measured by realised risk reduction and audit-ready evidence.","url":"/glossary/ai-governance-engineering","anchor":"/bok/glossary#t-ai-governance-engineering","chapters":["01"]},{"term":"AI harm","slug":"t-ai-harm","definition":"A negative consequence of building or using an AI system for a person, a group, an organisation, society or the environment.","url":"/glossary/ai-harm","anchor":"/bok/glossary#t-ai-harm","chapters":["03"]},{"term":"AI hazard","slug":"t-ai-hazard","definition":"In the OECD's definition, an event or series of events where the development, use or malfunction of an AI system could plausibly lead to an AI incident.","url":"/glossary/ai-hazard","anchor":"/bok/glossary#t-ai-hazard","chapters":["17"]},{"term":"AI incident","slug":"t-ai-incident","definition":"In the OECD's definition, an event or series of events where the development, use or malfunction of one or more AI systems directly or indirectly leads to harm to health, critical infrastructure, human or fundamental rights, property…","url":"/glossary/ai-incident","anchor":"/bok/glossary#t-ai-incident","chapters":["17"]},{"term":"AI literacy","slug":"t-ai-literacy","definition":"Under the EU AI Act, the skills, knowledge and understanding that let providers, deployers and affected persons use AI in an informed way and grasp its opportunities, risks and possible harm.","url":"/glossary/ai-literacy","anchor":"/bok/glossary#t-ai-literacy","chapters":["12","18"]},{"term":"AI Office","slug":"t-ai-office","definition":"The European Commission body that supervises general-purpose AI and coordinates AI Act enforcement, with investigation powers and the ability to levy penalties on GPAI providers.","url":"/glossary/ai-office","anchor":"/bok/glossary#t-ai-office","chapters":["08","18"]},{"term":"AI regulatory sandbox","slug":"t-ai-regulatory-sandbox","definition":"Under the EU AI Act, a controlled framework set up by a competent authority in which providers develop, train, test and validate innovative AI systems for a limited time under a sandbox plan, possibly with real-world testing.","url":"/glossary/ai-regulatory-sandbox","anchor":"/bok/glossary#t-ai-regulatory-sandbox","chapters":["18","21"]},{"term":"AI RMF functions","slug":"t-ai-rmf-functions","definition":"The four core functions of the NIST AI Risk Management Framework (Govern, Map, Measure, Manage), used throughout the book as a mapping target for controls.","url":"/glossary/ai-rmf-functions","anchor":"/bok/glossary#t-ai-rmf-functions","chapters":["08","22"]},{"term":"AI RMF Playbook","slug":"t-ai-rmf-playbook","definition":"NIST's online companion to the AI RMF. For each subcategory it gives an About note, suggested actions, transparency and documentation questions and references.","url":"/glossary/ai-rmf-playbook","anchor":"/bok/glossary#t-ai-rmf-playbook","chapters":["22"]},{"term":"AI RMF profile","slug":"t-ai-rmf-profile","definition":"An application of the AI RMF Core to a context. NIST describes use-case profiles, temporal profiles (a current and a target profile whose gap guides the work) and cross-sectoral profiles such as NIST AI 600-1 for generative AI.","url":"/glossary/ai-rmf-profile","anchor":"/bok/glossary#t-ai-rmf-profile","chapters":["22"]},{"term":"AI system","slug":"t-ai-system","definition":"For governance, the object the AI definition brings into scope. Under the EU AI Act, a machine-based system designed to operate with some autonomy, possibly adaptive after deployment, that infers from its input how to generate outputs that…","url":"/glossary/ai-system","anchor":"/bok/glossary#t-ai-system","chapters":["11","18"]},{"term":"AI system impact assessment","slug":"t-ai-system-impact-assessment","definition":"An assessment of how an AI system and its foreseeable applications may affect individuals, groups and society, performed across the lifecycle and updated as needed; ISO/IEC 42005:2025 gives the guidance.","url":"/glossary/ai-system-impact-assessment","anchor":"/bok/glossary#t-ai-system-impact-assessment","chapters":["14"]},{"term":"AI system lifecycle (OECD)","slug":"t-ai-system-lifecycle-oecd","definition":"The OECD's iterative phases of an AI system: plan and design; collect and process data; build or adapt models; test, evaluate, verify and validate; deploy; operate and monitor; retire or decommission.","url":"/glossary/ai-system-lifecycle-oecd","anchor":"/bok/glossary#t-ai-system-lifecycle-oecd","chapters":["22"]},{"term":"AI washing","slug":"t-ai-washing","definition":"Overstating or inventing the use or capability of AI in marketing or investor communications. US regulators treat it as deception; the SEC settled charges against two investment advisers over such claims in March 2024.","url":"/glossary/ai-washing","anchor":"/bok/glossary#t-ai-washing","chapters":["05","20"]},{"term":"AIBOM","slug":"t-aibom","definition":"AI bill of materials: the machine-readable inventory of an AI system's components (models, datasets, dependencies) in formats such as CycloneDX ML-BOM or the SPDX 3.0 AI profile.","url":"/glossary/aibom","anchor":"/bok/glossary#t-aibom","chapters":["04","05"]},{"term":"AICM","slug":"t-aicm","definition":"The CSA AI Controls Matrix, a control framework (v1.1, 247 control objectives across 18 domains) that maps to ISO 42001, ISO 27001 and NIST AI RMF and underpins STAR for AI.","url":"/glossary/aicm","anchor":"/bok/glossary#t-aicm","chapters":["08"]},{"term":"AIMA","slug":"t-aima","definition":"The OWASP AI Maturity Assessment, reported at v1.0 (Aug 2025), which scores the breadth of an AI security and governance programme across domains.","url":"/glossary/aima","anchor":"/bok/glossary#t-aima","chapters":["07"]},{"term":"AIMS","slug":"t-aims","definition":"An AI management system: the governance structure, roles, controls and continual-improvement loop that ISO/IEC 42001 certifies. An AIMS is not the AI Act's Article 17 quality management system.","url":"/glossary/aims","anchor":"/bok/glossary#t-aims","chapters":["07","08","22"]},{"term":"Algorithmic disgorgement","slug":"t-algorithmic-disgorgement","definition":"A remedy that orders deletion of models or algorithms developed with unlawfully obtained data, not only the data itself. Complying, and proving it, requires lineage from each dataset to every model trained on it.","url":"/glossary/algorithmic-disgorgement","anchor":"/bok/glossary#t-algorithmic-disgorgement","chapters":["05","20"]},{"term":"Algorithmic Impact Assessment (AIA)","slug":"t-algorithmic-impact-assessment-aia","definition":"The assessment Canada's Directive on Automated Decision-Making requires before a federal automated decision system goes into production.","url":"/glossary/algorithmic-impact-assessment-aia","anchor":"/bok/glossary#t-algorithmic-impact-assessment-aia","chapters":["14","21"]},{"term":"Algorithmic management","slug":"t-algorithmic-management","definition":"The use of automated monitoring and decision systems to direct, evaluate or sanction workers. The EU Platform Work Directive limits the data such systems may process and requires transparency, human oversight and a right to human review.","url":"/glossary/algorithmic-management","anchor":"/bok/glossary#t-algorithmic-management","chapters":["20"]},{"term":"Algorithmic Transparency Recording Standard (ATRS)","slug":"t-algorithmic-transparency-recording-standard-atrs","definition":"The UK's standard template for public-sector bodies to publish how and why they use algorithmic tools; mandatory for government departments and for arm's-length bodies that deliver public or frontline services.","url":"/glossary/algorithmic-transparency-recording-standard-atrs","anchor":"/bok/glossary#t-algorithmic-transparency-recording-standard-atrs","chapters":["21"]},{"term":"ALTAI","slug":"t-altai","definition":"The Assessment List for Trustworthy AI, published by the EU High-Level Expert Group on AI in July 2020: a self-assessment checklist that turns the seven requirements of the 2019 Ethics Guidelines into questions.","url":"/glossary/altai","anchor":"/bok/glossary#t-altai","chapters":["11","22"]},{"term":"Annex I (EU AI Act)","slug":"t-annex-i-eu-ai-act","definition":"The AI Act annex listing the Union harmonisation legislation under which AI is embedded in regulated products (machinery, medical devices, toys and the like); obligations for these high-risk embedded systems phase in from 2 August 2028…","url":"/glossary/annex-i-eu-ai-act","anchor":"/bok/glossary#t-annex-i-eu-ai-act","chapters":["08","18"]},{"term":"Annex III","slug":"t-annex-iii","definition":"The AI Act annex listing high-risk use cases (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice); obligations for these phase in under the Digital Omnibus timeline.","url":"/glossary/annex-iii","anchor":"/bok/glossary#t-annex-iii","chapters":["08","18"]},{"term":"Anonymous data","slug":"t-anonymous-data","definition":"Information that does not relate to an identifiable person, judged against all the means reasonably likely to be used by anyone to identify them.","url":"/glossary/anonymous-data","anchor":"/bok/glossary#t-anonymous-data","chapters":["19"]},{"term":"Article 6(3) filter","slug":"t-article-6-3-filter","definition":"The derogation under which an Annex III system is not high-risk when it poses no significant risk of harm and meets one of four conditions (narrow procedural task, improving completed human work, detecting patterns, preparatory task).","url":"/glossary/article-6-3-filter","anchor":"/bok/glossary#t-article-6-3-filter","chapters":["18"]},{"term":"ASI01–ASI10","slug":"t-asi01-asi10","definition":"The ten risks of the OWASP Top 10 for Agentic Applications 2026: ASI01 Agent Goal Hijack, ASI02 Tool Misuse and Exploitation, ASI03 Identity and Privilege Abuse, ASI04 Agentic Supply Chain Vulnerabilities, ASI05 Unexpected Code Execution…","url":"/glossary/asi01-asi10","anchor":"/bok/glossary#t-asi01-asi10","chapters":["05","08","23"]},{"term":"ATLAS","slug":"t-atlas","definition":"MITRE's Adversarial Threat Landscape for Artificial-Intelligence Systems, a knowledge base of adversary tactics and techniques against AI, including agent-specific techniques.","url":"/glossary/atlas","anchor":"/bok/glossary#t-atlas","chapters":["05","10","15","23"]},{"term":"Audit-ready evidence","slug":"t-audit-ready-evidence","definition":"Evidence emitted as a by-product of the build in a form an auditor can read directly (machine-readable, signed, timestamped), so the audit is a query, not a collection project.","url":"/glossary/audit-ready-evidence","anchor":"/bok/glossary#t-audit-ready-evidence","chapters":["01","04"]},{"term":"Authorised representative","slug":"t-authorised-representative","definition":"Under the EU AI Act, a person established in the Union with a written mandate from a non-EU provider of a high-risk AI system or general-purpose AI model to carry out that provider's obligations on its behalf, including keeping…","url":"/glossary/authorised-representative","anchor":"/bok/glossary#t-authorised-representative","chapters":["18"]},{"term":"Automated decision-making (ADM)","slug":"t-automated-decision-making-adm","definition":"A decision about a person taken by automated means. GDPR Article 22 restricts decisions based solely on automated processing with legal or similarly significant effects; after the SCHUFA judgment, a score that lenders treat as determining…","url":"/glossary/automated-decision-making-adm","anchor":"/bok/glossary#t-automated-decision-making-adm","chapters":["16","19"]},{"term":"Automation bias","slug":"t-automation-bias","definition":"The tendency of a person to over-rely on an automated system's output. EU AI Act Article 14 asks that people overseeing high-risk systems stay aware of it; the human gate logs approver, time to decide and override rate so that degrading…","url":"/glossary/automation-bias","anchor":"/bok/glossary#t-automation-bias","chapters":["04","11","23"]},{"term":"Autonomy","slug":"t-autonomy","definition":"In the EU AI Act and OECD texts, some degree of independence of action from human involvement, which almost every AI system has.","url":"/glossary/autonomy","anchor":"/bok/glossary#t-autonomy","chapters":["11","23"]},{"term":"Autonomy level","slug":"t-autonomy-level","definition":"How far an agent acts without a person between its steps, set by the deployer as a design decision rather than taken as a property of the model; one research scale names five levels by the user's role, from operator to observer.","url":"/glossary/autonomy-level","anchor":"/bok/glossary#t-autonomy-level","chapters":["15","17","23"]},{"term":"Bias","slug":"t-bias","definition":"A systematic error that favours or disadvantages some people or outcomes. NIST sorts AI bias into three categories: systemic, statistical and computational, and human.","url":"/glossary/bias","anchor":"/bok/glossary#t-bias","chapters":["16"]},{"term":"Bias audit (NYC Local Law 144)","slug":"t-bias-audit-nyc-local-law-144","definition":"An independent audit, required within the year before an employer uses an automated employment decision tool in New York City, that reports selection or scoring rates and impact ratios by sex, race and ethnicity and their intersections…","url":"/glossary/bias-audit-nyc-local-law-144","anchor":"/bok/glossary#t-bias-audit-nyc-local-law-144","chapters":["14","20"]},{"term":"Biometric data","slug":"t-biometric-data","definition":"Personal data from the technical processing of physical, physiological or behavioural traits that allows or confirms a person's unique identification, such as facial images or fingerprints.","url":"/glossary/biometric-data","anchor":"/bok/glossary#t-biometric-data","chapters":["19"]},{"term":"Blameless post-mortem","slug":"t-blameless-post-mortem","definition":"An incident review that identifies contributing causes without indicting any individual or team, on the premise that people acted reasonably on what they knew and that systems and processes are what can be fixed.","url":"/glossary/blameless-post-mortem","anchor":"/bok/glossary#t-blameless-post-mortem","chapters":["17"]},{"term":"Blue-green deployment","slug":"t-blue-green-deployment","definition":"Two identical production environments with traffic switched between them, so a release can be rolled back by switching back. It gives an AI system a tested, instant path to the previous version.","url":"/glossary/blue-green-deployment","anchor":"/bok/glossary#t-blue-green-deployment","chapters":["05","15"]},{"term":"Build provenance (SLSA)","slug":"t-build-provenance-slsa","definition":"A verifiable record, in the SLSA format, of what built an artefact, by what process and from which top-level inputs.","url":"/glossary/build-provenance-slsa","anchor":"/bok/glossary#t-build-provenance-slsa","chapters":["05"]},{"term":"CAC (Cyberspace Administration of China)","slug":"t-cac-cyberspace-administration-of-china","definition":"China's internet regulator (国家互联网信息办公室), lead issuer of the binding AI rules (algorithmic recommendation, deep synthesis, generative AI services and AI-content labelling) and the body under whose guidance TC260 publishes the AI Safety…","url":"/glossary/cac-cyberspace-administration-of-china","anchor":"/bok/glossary#t-cac-cyberspace-administration-of-china","chapters":["08","21"]},{"term":"Calibration","slug":"t-calibration","definition":"The property that a model's confidence matches its accuracy: of the cases scored 0.9, about nine in ten are right.","url":"/glossary/calibration","anchor":"/bok/glossary#t-calibration","chapters":["11"]},{"term":"Calibration within groups","slug":"t-calibration-within-groups","definition":"The fairness property that, in every group, the people given a score s turn out positive at rate s, so a score means the same thing for everyone. It generally conflicts with equal error rates when base rates differ.","url":"/glossary/calibration-within-groups","anchor":"/bok/glossary#t-calibration-within-groups","chapters":["16"]},{"term":"Canary release","slug":"t-canary-release","definition":"A partial, time-limited deployment of a change to a small share of production traffic, evaluated against a control group before the rollout continues.","url":"/glossary/canary-release","anchor":"/bok/glossary#t-canary-release","chapters":["05","14","15","23"]},{"term":"CAPA","slug":"t-capa","definition":"Corrective and preventive action, the output of an incident review. The corrective action fixes this instance; the preventive action stops the class of failure recurring across the fleet, typically as a regression eval, a policy change and…","url":"/glossary/capa","anchor":"/bok/glossary#t-capa","chapters":["17"]},{"term":"Catastrophic forgetting","slug":"t-catastrophic-forgetting","definition":"The tendency of neural networks to lose earlier competence when trained on new tasks. It is a reason every retraining is a change event that re-runs the full eval suite, not only the tests for the new capability.","url":"/glossary/catastrophic-forgetting","anchor":"/bok/glossary#t-catastrophic-forgetting","chapters":["11"]},{"term":"Catastrophic-severity override","slug":"t-catastrophic-severity-override","definition":"The rule that any scenario rated at the top severity level is Critical whatever its likelihood, cannot be accepted by the delivery team, and must be eliminated, reduced in severity or accepted explicitly by the governing body for a fixed…","url":"/glossary/catastrophic-severity-override","anchor":"/bok/glossary#t-catastrophic-severity-override","chapters":["13"]},{"term":"CE marking","slug":"t-ce-marking","definition":"The mark showing a high-risk AI system's conformity with the EU AI Act, affixed visibly, legibly and indelibly, or digitally for systems provided digitally, with the notified body's number where one was involved.","url":"/glossary/ce-marking","anchor":"/bok/glossary#t-ce-marking","chapters":["14","18"]},{"term":"Cedar","slug":"t-cedar","definition":"An open-source policy language for fine-grained authorization, used as a policy-as-code engine for runtime access decisions; a schema-typed, analysable alternative to OPA/Rego.","url":"/glossary/cedar","anchor":"/bok/glossary#t-cedar","chapters":["04","05","06"]},{"term":"CEN-CENELEC JTC 21","slug":"t-cen-cenelec-jtc-21","definition":"The joint technical committee of the European standardisation organisations CEN and CENELEC that drafts the AI Act harmonised standards, including EN 18286 on quality management and the drafts on risk management, trustworthiness and…","url":"/glossary/cen-cenelec-jtc-21","anchor":"/bok/glossary#t-cen-cenelec-jtc-21","chapters":["22"]},{"term":"CIMD","slug":"t-cimd","definition":"Client ID Metadata Document: the mechanism by which an OAuth client identifies itself with a URL, used as its client ID, that points to its metadata document.","url":"/glossary/cimd","anchor":"/bok/glossary#t-cimd","chapters":["04","05","23"]},{"term":"Claims register","slug":"t-claims-register","definition":"The record of every public statement about an AI system's accuracy, fairness, safety or capability: the exact wording, where it appears, and the eval run, measured value, interval and population behind it.","url":"/glossary/claims-register","anchor":"/bok/glossary#t-claims-register","chapters":["05","20"]},{"term":"Classification decision record","slug":"t-classification-decision-record","definition":"A versioned registry record of why a system sits on a given rung of the AI Act risk ladder: the Annex III point, any Article 6(3) condition relied on, an explicit profiling flag, the reviewer and the date.","url":"/glossary/classification-decision-record","anchor":"/bok/glossary#t-classification-decision-record","chapters":["18"]},{"term":"Common specifications","slug":"t-common-specifications","definition":"Technical specifications the Commission may adopt by implementing act under AI Act Article 41 when a standardisation request is not accepted, the standards are late or they insufficiently address fundamental-rights concerns; conforming…","url":"/glossary/common-specifications","anchor":"/bok/glossary#t-common-specifications","chapters":["22"]},{"term":"Concept drift","slug":"t-concept-drift","definition":"A change in the relationship between a system's inputs and the correct output, so the same input should now get a different answer.","url":"/glossary/concept-drift","anchor":"/bok/glossary#t-concept-drift","chapters":["11","15"]},{"term":"Conformal prediction","slug":"t-conformal-prediction","definition":"A distribution-free method that turns a trained model's output into a set of candidate answers that contains the right one with a chosen probability. A large set signals uncertainty that a governance rule can route on.","url":"/glossary/conformal-prediction","anchor":"/bok/glossary#t-conformal-prediction","chapters":["11"]},{"term":"Conformity assessment","slug":"t-conformity-assessment","definition":"The procedure by which a provider shows a high-risk AI system meets the EU AI Act before placing it on the market: internal control for most Annex III systems, a notified body for some biometric systems, and the sectoral procedure for…","url":"/glossary/conformity-assessment","anchor":"/bok/glossary#t-conformity-assessment","chapters":["14","18"]},{"term":"Content provenance (C2PA)","slug":"t-content-provenance-c2pa","definition":"Signed, tamper-evident information about where a piece of content came from and how it was edited, bound to the asset.","url":"/glossary/content-provenance-c2pa","anchor":"/bok/glossary#t-content-provenance-c2pa","chapters":["18","20"]},{"term":"Contest path","slug":"t-contest-path","definition":"The route by which a person affected by an automated decision reaches a reviewer who did not take the original decision, sees the inputs, the reasons and the person's representations, and can change the outcome, with the result written…","url":"/glossary/contest-path","anchor":"/bok/glossary#t-contest-path","chapters":["05","19","22"]},{"term":"Contestability","slug":"t-contestability","definition":"The ability of a person affected by an AI-supported decision to challenge it and obtain a response that can change it.","url":"/glossary/contestability","anchor":"/bok/glossary#t-contestability","chapters":["05","12","16"]},{"term":"Continuous assurance","slug":"t-continuous-assurance","definition":"Assurance produced continuously from telemetry rather than at a point in time; the control's status is a live query, not an annual sign-off. It is Level 5 of the maturity model.","url":"/glossary/continuous-assurance","anchor":"/bok/glossary#t-continuous-assurance","chapters":["04","05","07"]},{"term":"Contributing factor","slug":"t-contributing-factor","definition":"A property of a system or its context (autonomy, exposure, reversibility, vulnerable groups, data sensitivity, opacity) that moves the likelihood or severity of a risk without creating it.","url":"/glossary/contributing-factor","anchor":"/bok/glossary#t-contributing-factor","chapters":["13"]},{"term":"Controller and processor","slug":"t-controller-and-processor","definition":"Under the GDPR the controller decides the purposes and means of processing and carries most duties; the processor acts on its documented instructions.","url":"/glossary/controller-and-processor","anchor":"/bok/glossary#t-controller-and-processor","chapters":["19"]},{"term":"Counterfactual explanation","slug":"t-counterfactual-explanation","definition":"An explanation that states the smallest change to the input that would have changed the outcome, restricted to features the person can actually change. It is the natural basis for recourse.","url":"/glossary/counterfactual-explanation","anchor":"/bok/glossary#t-counterfactual-explanation","chapters":["16"]},{"term":"Counterfactual fairness","slug":"t-counterfactual-fairness","definition":"The requirement that a decision about an individual be the same in a counterfactual world where the individual belonged to a different group, defined through a causal model; approximated in practice by counterfactual flip tests.","url":"/glossary/counterfactual-fairness","anchor":"/bok/glossary#t-counterfactual-fairness","chapters":["16"]},{"term":"Counterfactual flip test","slug":"t-counterfactual-flip-test","definition":"A test that changes only a protected attribute in an input, or swaps identity terms in otherwise identical prompts, and measures how often the outcome or the answer quality changes.","url":"/glossary/counterfactual-flip-test","anchor":"/bok/glossary#t-counterfactual-flip-test","chapters":["05","16"]},{"term":"Data card","slug":"t-data-card","definition":"Structured, versioned documentation of a dataset (provenance, lawful basis, rights, composition and known limitations) maintained as code alongside the system.","url":"/glossary/data-card","anchor":"/bok/glossary#t-data-card","chapters":["04"]},{"term":"Data drift","slug":"t-data-drift","definition":"A change in the distribution of the inputs a system sees in production relative to the data it was validated on, such as a new customer segment or a changed upstream form.","url":"/glossary/data-drift","anchor":"/bok/glossary#t-data-drift","chapters":["11","15"]},{"term":"Data lineage","slug":"t-data-lineage","definition":"The record of how data moved and changed through an organisation's pipelines. Backward lineage shows what fed a model; forward lineage shows which models used a dataset, which erasure requests and licence withdrawals need.","url":"/glossary/data-lineage","anchor":"/bok/glossary#t-data-lineage","chapters":["14"]},{"term":"Data minimisation","slug":"t-data-minimisation","definition":"The GDPR principle that personal data must be adequate, relevant and limited to what the purpose needs.","url":"/glossary/data-minimisation","anchor":"/bok/glossary#t-data-minimisation","chapters":["19"]},{"term":"Data provenance","slug":"t-data-provenance","definition":"Information about the entities, activities and people involved in producing data, used to judge its quality and trustworthiness. In practice: where a dataset originally came from and on what terms (source, licence, lawful basis).","url":"/glossary/data-provenance","anchor":"/bok/glossary#t-data-provenance","chapters":["12","14"]},{"term":"Dataset admission gate","slug":"t-dataset-admission-gate","definition":"A pipeline control that lets a training job read only datasets whose admission record is complete and signed by the data owner: lawful basis or licence, reservation checks, quality results, provenance, permitted uses and retention.","url":"/glossary/dataset-admission-gate","anchor":"/bok/glossary#t-dataset-admission-gate","chapters":["05","14"]},{"term":"Datasheet for datasets","slug":"t-datasheet-for-datasets","definition":"Documentation that accompanies a dataset with its motivation, composition, collection process, preprocessing, uses, distribution and maintenance, as proposed by Gebru and colleagues; the human-readable companion to the dataset admission…","url":"/glossary/datasheet-for-datasets","anchor":"/bok/glossary#t-datasheet-for-datasets","chapters":["14"]},{"term":"Decision notice","slug":"t-decision-notice","definition":"The notice a person receives at the point of an automated or AI-assisted decision, rendered from a versioned template and the decision record: that a system was used, the principal reasons and what the person can do by when.","url":"/glossary/decision-notice","anchor":"/bok/glossary#t-decision-notice","chapters":["05","08","18"]},{"term":"Decision threshold","slug":"t-decision-threshold","definition":"The score above or below which an AI output triggers an action. It is where risk appetite becomes behaviour, so it is governed as a policy with an owner, version and effective date, tested in the eval gate and logged with every decision…","url":"/glossary/decision-threshold","anchor":"/bok/glossary#t-decision-threshold","chapters":["11"]},{"term":"Decommissioning","slug":"t-decommissioning","definition":"The planned retirement of an AI system: dependency analysis, fallback and transition, sunset notices, a final evidence snapshot, archive or disposal of weights and data, revocation of every identity, and a registry entry marked retired…","url":"/glossary/decommissioning","anchor":"/bok/glossary#t-decommissioning","chapters":["05","15"]},{"term":"Deepfake","slug":"t-deepfake","definition":"Under the EU AI Act, a deep fake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic; deployers must…","url":"/glossary/deepfake","anchor":"/bok/glossary#t-deepfake","chapters":["18","20"]},{"term":"Delegation (OAuth token exchange)","slug":"t-delegation-oauth-token-exchange","definition":"In RFC 8693, the mode in which one party acts for another while both stay identifiable: the token names the subject and, in its act claim, the current actor, with nested act claims for earlier actors.","url":"/glossary/delegation-oauth-token-exchange","anchor":"/bok/glossary#t-delegation-oauth-token-exchange","chapters":["23"]},{"term":"Delegation chain","slug":"t-delegation-chain","definition":"The sequence of agents a task passes through from the person or system that started it.","url":"/glossary/delegation-chain","anchor":"/bok/glossary#t-delegation-chain","chapters":["23"]},{"term":"Demographic parity","slug":"t-demographic-parity","definition":"A group fairness criterion that holds when the rate of positive decisions is equal across groups; the adverse-impact ratio is its ratio form. It ignores differences in base rates.","url":"/glossary/demographic-parity","anchor":"/bok/glossary#t-demographic-parity","chapters":["16"]},{"term":"Deployer","slug":"t-deployer","definition":"Under the EU AI Act, whoever uses an AI system under its own authority, other than in a purely personal, non-professional activity.","url":"/glossary/deployer","anchor":"/bok/glossary#t-deployer","chapters":["15","18"]},{"term":"Deployment Decision Record (DDR)","slug":"t-deployment-decision-record-ddr","definition":"The artefact that records the decision to deploy an AI system: objective, the people it acts on, negative space, risk tier and obligations, per-group performance floors, retirement conditions, owner and approver.","url":"/glossary/deployment-decision-record-ddr","anchor":"/bok/glossary#t-deployment-decision-record-ddr","chapters":["15"]},{"term":"Design defect","slug":"t-design-defect","definition":"In product liability, a defect inherent in the design of every unit, judged by consumer expectations or by weighing risk against utility.","url":"/glossary/design-defect","anchor":"/bok/glossary#t-design-defect","chapters":["20"]},{"term":"Differential privacy","slug":"t-differential-privacy","definition":"A mathematical guarantee that bounds how much any single person's record can change the output of an analysis or a trained model, tuned by a privacy budget.","url":"/glossary/differential-privacy","anchor":"/bok/glossary#t-differential-privacy","chapters":["19"]},{"term":"Digital Omnibus","slug":"t-digital-omnibus","definition":"The 2026 reform package amending the EU AI Act (in force 27 Jul 2026), which adjusted the high-risk timeline, added AI Office investigation powers and reworked several articles.","url":"/glossary/digital-omnibus","anchor":"/bok/glossary#t-digital-omnibus","chapters":["08","18"]},{"term":"Disparate impact","slug":"t-disparate-impact","definition":"A facially neutral practice that falls harder on a protected group. Under US Title VII the employer must show the practice is job related and consistent with business necessity, and loses if it refuses a less discriminatory alternative.","url":"/glossary/disparate-impact","anchor":"/bok/glossary#t-disparate-impact","chapters":["16","20"]},{"term":"Disparate treatment","slug":"t-disparate-treatment","definition":"Treating a person less favourably because of a protected characteristic such as race, sex or age, including through a feature or rule that deliberately stands in for it. The EU counterpart is direct discrimination.","url":"/glossary/disparate-treatment","anchor":"/bok/glossary#t-disparate-treatment","chapters":["16","20"]},{"term":"Distributor","slug":"t-distributor","definition":"Under the EU AI Act, a person in the supply chain, other than the provider or the importer, who makes an AI system available on the Union market.","url":"/glossary/distributor","anchor":"/bok/glossary#t-distributor","chapters":["18"]},{"term":"Domestic representative (Korea)","slug":"t-domestic-representative-korea","definition":"A person with an address or office in Korea whom a foreign AI business operator above thresholds set by decree must designate in writing.","url":"/glossary/domestic-representative-korea","anchor":"/bok/glossary#t-domestic-representative-korea","chapters":["21"]},{"term":"Downstream modifier (GPAI)","slug":"t-downstream-modifier-gpai","definition":"An actor that fine-tunes or modifies another provider's general-purpose AI model. The Commission's guidelines make it the modified model's provider only when the modification uses over a third of the original training compute; its Art.","url":"/glossary/downstream-modifier-gpai","anchor":"/bok/glossary#t-downstream-modifier-gpai","chapters":["15","18"]},{"term":"Downstream provider","slug":"t-downstream-provider","definition":"Under the EU AI Act, the provider of an AI system that integrates an AI model, its own or one supplied by another entity. It relies on the model information that general-purpose AI model providers must hand downstream.","url":"/glossary/downstream-provider","anchor":"/bok/glossary#t-downstream-provider","chapters":["18"]},{"term":"Downstream use register","slug":"t-downstream-use-register","definition":"The record of every consumer of an AI system's outputs (a system, team, partner or training pipeline), each with its approved use, the re-test that cleared the outputs for that context and any contract, held against the producing system's…","url":"/glossary/downstream-use-register","anchor":"/bok/glossary#t-downstream-use-register","chapters":["05","15"]},{"term":"DPIA","slug":"t-dpia","definition":"Data Protection Impact Assessment: the GDPR Article 35 assessment of processing likely to result in high risk to individuals, maintained in this discipline as a versioned artefact, not a one-off document.","url":"/glossary/dpia","anchor":"/bok/glossary#t-dpia","chapters":["04","05","19"]},{"term":"Drift","slug":"t-drift","definition":"The gradual divergence of a model's inputs, outputs or performance from its validated baseline over time; a runtime signal that a control or eval must catch.","url":"/glossary/drift","anchor":"/bok/glossary#t-drift","chapters":["04","05","11","15","16","17"]},{"term":"Dual use","slug":"t-dual-use","definition":"The capacity of the same AI capability to serve harmful ends as well as legitimate ones, for example a toxicity model inverted to propose toxic molecules.","url":"/glossary/dual-use","anchor":"/bok/glossary#t-dual-use","chapters":["11"]},{"term":"Duty holder","slug":"t-duty-holder","definition":"Who an obligation legally binds (under the EU AI Act, the provider, the deployer or both), as distinct from who enforces it; chapter 08 carries a duty-holder column so an engineer can tell which artefacts their organisation is responsible…","url":"/glossary/duty-holder","anchor":"/bok/glossary#t-duty-holder","chapters":["08","18"]},{"term":"Effective challenge","slug":"t-effective-challenge","definition":"Critical analysis of a model by objective experts with the expertise, independence and organisational standing to force change.","url":"/glossary/effective-challenge","anchor":"/bok/glossary#t-effective-challenge","chapters":["14"]},{"term":"EN 18286","slug":"t-en-18286","definition":"The European standard for the AI Act's Article 17 quality management system, published by CEN-CENELEC in July 2026 (the first JTC 21 AI Act standard to reach publication), but not yet cited in the Official Journal as of 2026-09-24, so it…","url":"/glossary/en-18286","anchor":"/bok/glossary#t-en-18286","chapters":["08","22"]},{"term":"Equalised odds","slug":"t-equalised-odds","definition":"A group fairness criterion that holds when true-positive and false-positive rates are both equal across groups; equal opportunity is the weaker version that equalises only true-positive rates.","url":"/glossary/equalised-odds","anchor":"/bok/glossary#t-equalised-odds","chapters":["16"]},{"term":"EU declaration of conformity","slug":"t-eu-declaration-of-conformity","definition":"The provider's signed statement, following AI Act Annex V, that a high-risk AI system meets the Act's requirements; drawn up after the conformity assessment and kept for 10 years.","url":"/glossary/eu-declaration-of-conformity","anchor":"/bok/glossary#t-eu-declaration-of-conformity","chapters":["18"]},{"term":"Eval gate","slug":"t-eval-gate","definition":"A pipeline stage that fails the build when an eval fails; the mechanism that turns an evaluation into an enforced control rather than a report.","url":"/glossary/eval-gate","anchor":"/bok/glossary#t-eval-gate","chapters":["04","05"]},{"term":"Evals","slug":"t-evals","definition":"Automated tests of a model's or agent's behaviour (capability, safety and adversarial), run as controls, not as one-off research.","url":"/glossary/evals","anchor":"/bok/glossary#t-evals","chapters":["04"]},{"term":"Evals as evidence","slug":"t-evals-as-evidence","definition":"The principle that the eval run is the assurance evidence: a failing eval blocks the build and its structured result is stored as proof the control fired.","url":"/glossary/evals-as-evidence","anchor":"/bok/glossary#t-evals-as-evidence","chapters":["03","04"]},{"term":"Evidence record","slug":"t-evidence-record","definition":"The signed, structured record a control writes each time it decides: which control, about which system version, what it decided, against which metric, threshold and obligation, on which input, when and by whom.","url":"/glossary/evidence-record","anchor":"/bok/glossary#t-evidence-record","chapters":["05"]},{"term":"Exception register","slug":"t-exception-register","definition":"A version-controlled list of approved exceptions, each tied to one rule and one system, with justification, compensating controls, approver and expiry.","url":"/glossary/exception-register","anchor":"/bok/glossary#t-exception-register","chapters":["12"]},{"term":"Explainability","slug":"t-explainability","definition":"In NIST's framing, a representation of the mechanisms behind a system's operation: how a decision was made. In practice a per-decision explanation such as feature attributions, reason codes or a counterfactual.","url":"/glossary/explainability","anchor":"/bok/glossary#t-explainability","chapters":["11","16"]},{"term":"Explanation record","slug":"t-explanation-record","definition":"The evidence artefact for one explained decision: model version, explanation method and version, baseline, reason codes, counterfactual, template, audience and delivery, written at decision time so the explanation can be reproduced when a…","url":"/glossary/explanation-record","anchor":"/bok/glossary#t-explanation-record","chapters":["05","16"]},{"term":"Failure posture","slug":"t-failure-posture","definition":"What a guardrail, guardian agent or tool gateway does when it cannot reach a decision: fail open lets the call through, fail closed blocks it. The reference guardian of the OWASP Agent Control Standard starts at proceed unless set to deny.","url":"/glossary/failure-posture","anchor":"/bok/glossary#t-failure-posture","chapters":["23"]},{"term":"Failure to warn","slug":"t-failure-to-warn","definition":"In product liability, a defect in instructions or warnings about non-obvious dangers. For AI: undisclosed limitations or out-of-scope uses, which is why model cards and instructions for use are versioned with each release.","url":"/glossary/failure-to-warn","anchor":"/bok/glossary#t-failure-to-warn","chapters":["20"]},{"term":"Fair use","slug":"t-fair-use","definition":"The US copyright defence that weighs four factors: purpose and transformativeness, nature of the work, amount used and market effect.","url":"/glossary/fair-use","anchor":"/bok/glossary#t-fair-use","chapters":["20"]},{"term":"Fairness","slug":"t-fairness","definition":"The property that a system's outcomes and errors do not unjustifiably disadvantage people or groups.","url":"/glossary/fairness","anchor":"/bok/glossary#t-fairness","chapters":["16"]},{"term":"Fairness gerrymandering","slug":"t-fairness-gerrymandering","definition":"The failure in which a model satisfies a fairness constraint on each predefined group but violates it on subgroups defined by combinations of attributes; the reason intersectional testing is needed.","url":"/glossary/fairness-gerrymandering","anchor":"/bok/glossary#t-fairness-gerrymandering","chapters":["16"]},{"term":"Fairness policy","slug":"t-fairness-policy","definition":"The per-system record, fixed before results are seen, of what fairness means for that system: the protected attributes in each jurisdiction and where their values come from, the chosen metric and why, the threshold, the minimum cell size…","url":"/glossary/fairness-policy","anchor":"/bok/glossary#t-fairness-policy","chapters":["05","16"]},{"term":"Federated learning","slug":"t-federated-learning","definition":"Training a model across devices or sites where the data lives, sharing model updates instead of raw records. It limits data movement but does not by itself hide personal data, because shared updates can leak training examples.","url":"/glossary/federated-learning","anchor":"/bok/glossary#t-federated-learning","chapters":["19"]},{"term":"Fine-tuning","slug":"t-fine-tuning","definition":"Further training of an existing model on new data to adapt it to a task or domain.","url":"/glossary/fine-tuning","anchor":"/bok/glossary#t-fine-tuning","chapters":["15","18"]},{"term":"Foundation model","slug":"t-foundation-model","definition":"A model trained on broad data at scale and adaptable to a wide range of downstream tasks.","url":"/glossary/foundation-model","anchor":"/bok/glossary#t-foundation-model","chapters":["11"]},{"term":"Four-fifths rule","slug":"t-four-fifths-rule","definition":"The US Uniform Guidelines rule of thumb that a group selection rate below 80% of the highest group's rate will generally be regarded as evidence of adverse impact, qualified by statistical and practical significance.","url":"/glossary/four-fifths-rule","anchor":"/bok/glossary#t-four-fifths-rule","chapters":["16","20"]},{"term":"Framework Convention on AI (CETS No. 225)","slug":"t-framework-convention-on-ai-cets-no-225","definition":"The Council of Europe's treaty on AI and human rights, democracy and the rule of law, opened for signature in September 2024.","url":"/glossary/framework-convention-on-ai-cets-no-225","anchor":"/bok/glossary#t-framework-convention-on-ai-cets-no-225","chapters":["22"]},{"term":"Framework crosswalk","slug":"t-framework-crosswalk","definition":"A mapping of one framework's controls onto another's; useful as an index, but a crosswalk proves you read the framework, not that the mapped control fires.","url":"/glossary/framework-crosswalk","anchor":"/bok/glossary#t-framework-crosswalk","chapters":["05","08"]},{"term":"FRIA","slug":"t-fria","definition":"Fundamental Rights Impact Assessment: the AI Act Article 27 assessment of a high-risk system's impact on rights, maintained here as a versioned, reviewable artefact.","url":"/glossary/fria","anchor":"/bok/glossary#t-fria","chapters":["04","05","18"]},{"term":"Frontier model","slug":"t-frontier-model","definition":"A general-purpose model at or near the capability frontier. Laws draw the line by training compute: California's SB 53, for example, covers models trained with more than 10^26 operations.","url":"/glossary/frontier-model","anchor":"/bok/glossary#t-frontier-model","chapters":["08","21"]},{"term":"Fulfilment record","slug":"t-fulfilment-record","definition":"The per-request record of how a data-subject request was honoured wherever the person's data sits, from source systems, snapshots, retrieval indexes, logs and eval sets to model weights: the action in each, the model versions affected, any…","url":"/glossary/fulfilment-record","anchor":"/bok/glossary#t-fulfilment-record","chapters":["05","08","19"]},{"term":"Function creep","slug":"t-function-creep","definition":"The gradual reuse of personal data or an AI system for purposes nobody approved, usually by configuration rather than a new release.","url":"/glossary/function-creep","anchor":"/bok/glossary#t-function-creep","chapters":["05","14","15","19"]},{"term":"Generative AI","slug":"t-generative-ai","definition":"AI that outputs new content (text, images, audio, video, code) rather than an estimate about something that exists.","url":"/glossary/generative-ai","anchor":"/bok/glossary#t-generative-ai","chapters":["11"]},{"term":"Go/no-go decision","slug":"t-go-no-go-decision","definition":"The signed release decision for one system version, taken by named reviewer roles against a checklist whose items each link the record that answers them.","url":"/glossary/go-no-go-decision","anchor":"/bok/glossary#t-go-no-go-decision","chapters":["14"]},{"term":"Governance-as-code","slug":"t-governance-as-code","definition":"Governance rules expressed as executable code that evaluates pull requests, deployments and runtime calls and returns a decision; the umbrella term of which policy-as-code is the CI/CD subset.","url":"/glossary/governance-as-code","anchor":"/bok/glossary#t-governance-as-code","chapters":["03","04"]},{"term":"GPAI","slug":"t-gpai","definition":"General-purpose AI model: under the AI Act, a model that shows significant generality, can competently perform a wide range of distinct tasks and can be integrated into many downstream systems.","url":"/glossary/gpai","anchor":"/bok/glossary#t-gpai","chapters":["08","11","18"]},{"term":"GPAI Code of Practice","slug":"t-gpai-code-of-practice","definition":"The voluntary instrument (published 10 July 2025) that general-purpose-AI providers use to demonstrate compliance with their AI Act obligations until harmonised standards exist; three chapters: Transparency, Copyright, and Safety and…","url":"/glossary/gpai-code-of-practice","anchor":"/bok/glossary#t-gpai-code-of-practice","chapters":["08","18"]},{"term":"Graduated degradation","slug":"t-graduated-degradation","definition":"Pre-built, tested operating modes short of switching an AI system off: advice-only, raised confidence thresholds, grounded-only answers, disabling for one group, language or region, and a return to the pilot cohort.","url":"/glossary/graduated-degradation","anchor":"/bok/glossary#t-graduated-degradation","chapters":["05","15","23"]},{"term":"Guardian agent","slug":"t-guardian-agent","definition":"An AI agent whose job is to supervise, check or constrain other agents at runtime; Gartner predicts guardian-agent technologies will account for at least 10 to 15% of agentic AI markets by 2030.","url":"/glossary/guardian-agent","anchor":"/bok/glossary#t-guardian-agent","chapters":["04","23"]},{"term":"Guardrail","slug":"t-guardrail","definition":"A runtime control that inspects or mediates a model's or agent's inputs, outputs or tool calls and blocks, rewrites or escalates what breaks a policy, logging each decision as evidence.","url":"/glossary/guardrail","anchor":"/bok/glossary#t-guardrail","chapters":["04","05","23"]},{"term":"Hallucination","slug":"t-hallucination","definition":"Generative output that is stated confidently but is false or unsupported by its sources; NIST's generative AI profile calls it confabulation and lists it among the risks generative AI creates or worsens.","url":"/glossary/hallucination","anchor":"/bok/glossary#t-hallucination","chapters":["11","17"]},{"term":"Harmonised standard","slug":"t-harmonised-standard","definition":"A European standard adopted on a Commission standardisation request. Under the AI Act, conformity with one whose reference is published in the Official Journal gives a presumption of conformity with the requirements it covers; publication…","url":"/glossary/harmonised-standard","anchor":"/bok/glossary#t-harmonised-standard","chapters":["08","22"]},{"term":"Harmonized Structure (ISO)","slug":"t-harmonized-structure-iso","definition":"The common clause layout and core text shared by ISO management-system standards such as ISO/IEC 42001, 27001 and 27701 and ISO 9001, which lets one integrated management system meet several of them.","url":"/glossary/harmonized-structure-iso","anchor":"/bok/glossary#t-harmonized-structure-iso","chapters":["22"]},{"term":"Hidden Context Exposure","slug":"t-hidden-context-exposure","definition":"LLM08:2026 in the OWASP LLM Top 10, which replaced System Prompt Leakage: extracting, inferring or reconstructing the hidden context a model sees, such as system prompts, developer instructions, retrieved policy text and tool schemas.","url":"/glossary/hidden-context-exposure","anchor":"/bok/glossary#t-hidden-context-exposure","chapters":["23"]},{"term":"High-impact AI (Korea)","slug":"t-high-impact-ai-korea","definition":"Under Korea's AI Basic Act, an AI system that may significantly affect life, physical safety or fundamental rights and is used in a listed area such as health care, hiring and loan screening, biometric analysis, transport or public-service…","url":"/glossary/high-impact-ai-korea","anchor":"/bok/glossary#t-high-impact-ai-korea","chapters":["21"]},{"term":"High-risk AI system","slug":"t-high-risk-ai-system","definition":"Under the EU AI Act, an AI system that is a safety component of, or itself, a product under Annex I legislation needing third-party conformity assessment, or that is used in an Annex III area, unless the Article 6(3) filter applies.","url":"/glossary/high-risk-ai-system","anchor":"/bok/glossary#t-high-risk-ai-system","chapters":["18"]},{"term":"Hiroshima Code of Conduct","slug":"t-hiroshima-code-of-conduct","definition":"The G7's voluntary International Code of Conduct for Organizations Developing Advanced AI Systems (October 2023): 11 actions covering lifecycle risk evaluation, post-deployment monitoring, public reporting, incident sharing, governance…","url":"/glossary/hiroshima-code-of-conduct","anchor":"/bok/glossary#t-hiroshima-code-of-conduct","chapters":["22"]},{"term":"Holding statement","slug":"t-holding-statement","definition":"A short public statement prepared in skeleton before any incident: what happened as far as it is known, what has been done to contain it, what affected people should do, and when the next update will come. It never speculates about cause.","url":"/glossary/holding-statement","anchor":"/bok/glossary#t-holding-statement","chapters":["05","15"]},{"term":"HUDERIA","slug":"t-huderia","definition":"The Council of Europe's non-binding methodology for assessing the risks and impacts of AI systems on human rights, democracy and the rule of law. Parties to the Framework Convention may use or adapt it.","url":"/glossary/huderia","anchor":"/bok/glossary#t-huderia","chapters":["22"]},{"term":"Human oversight","slug":"t-human-oversight","definition":"The measures that let natural persons understand, monitor and, when needed, override or stop a high-risk AI system, required by AI Act Article 14, including awareness of automation bias and a way to halt the system safely.","url":"/glossary/human-oversight","anchor":"/bok/glossary#t-human-oversight","chapters":["04","11","23"]},{"term":"Human-in-command (HIC)","slug":"t-human-in-command-hic","definition":"The oversight mode, named by the EU High-Level Expert Group, in which people oversee the overall activity of an AI system and decide when and whether to use it in a given situation.","url":"/glossary/human-in-command-hic","anchor":"/bok/glossary#t-human-in-command-hic","chapters":["11"]},{"term":"Human-in-the-loop (HITL)","slug":"t-human-in-the-loop-hitl","definition":"The oversight mode in which a person can intervene in every decision cycle of an AI system; in engineering terms, a gate that holds each consequential action until a named approver decides, logging approver, time to decide and override.","url":"/glossary/human-in-the-loop-hitl","anchor":"/bok/glossary#t-human-in-the-loop-hitl","chapters":["05","11","23"]},{"term":"Human-on-the-loop (HOTL)","slug":"t-human-on-the-loop-hotl","definition":"The oversight mode in which a person can intervene in the design cycle and monitors the system's operation, rather than approving each decision.","url":"/glossary/human-on-the-loop-hotl","anchor":"/bok/glossary#t-human-on-the-loop-hotl","chapters":["11"]},{"term":"Implicit deny","slug":"t-implicit-deny","definition":"The authorisation rule that a request no policy explicitly permits is refused. Cedar denies by default and lets any matching forbid override every permit; an agent's tool allow-list works the same way, so an unlisted tool is blocked…","url":"/glossary/implicit-deny","anchor":"/bok/glossary#t-implicit-deny","chapters":["08","23"]},{"term":"Importer","slug":"t-importer","definition":"Under the EU AI Act, a person established in the Union who places on the market an AI system bearing the name or trademark of a provider established outside the Union.","url":"/glossary/importer","anchor":"/bok/glossary#t-importer","chapters":["18"]},{"term":"Indirect discrimination","slug":"t-indirect-discrimination","definition":"The EU counterpart of disparate impact: an apparently neutral criterion that puts a protected group at a particular disadvantage, unlawful unless objectively justified by a legitimate aim pursued by appropriate and necessary means.","url":"/glossary/indirect-discrimination","anchor":"/bok/glossary#t-indirect-discrimination","chapters":["20"]},{"term":"Inference (AI Act sense)","slug":"t-inference-ai-act-sense","definition":"The capability to derive outputs from input by learning from data or reasoning over encoded knowledge, rather than by executing rules people wrote.","url":"/glossary/inference-ai-act-sense","anchor":"/bok/glossary#t-inference-ai-act-sense","chapters":["11"]},{"term":"Inferred sensitive data","slug":"t-inferred-sensitive-data","definition":"Sensitive information a system derives from ordinary inputs (health from purchases, beliefs from behaviour) or carries through a proxy feature.","url":"/glossary/inferred-sensitive-data","anchor":"/bok/glossary#t-inferred-sensitive-data","chapters":["19"]},{"term":"Inherent risk","slug":"t-inherent-risk","definition":"The likelihood and severity rating of a risk scenario before any control is counted. The gap between inherent and residual risk is the value claimed for the controls, and must be backed by their evidence.","url":"/glossary/inherent-risk","anchor":"/bok/glossary#t-inherent-risk","chapters":["13"]},{"term":"Instructions for use","slug":"t-instructions-for-use","definition":"The information a provider of a high-risk AI system must give deployers: intended purpose, declared accuracy and robustness, known risks, how to read the output, human oversight measures, maintenance and logging.","url":"/glossary/instructions-for-use","anchor":"/bok/glossary#t-instructions-for-use","chapters":["14","18"]},{"term":"Intended purpose","slug":"t-intended-purpose","definition":"The use for which the provider intends an AI system, including its specific context and conditions of use.","url":"/glossary/intended-purpose","anchor":"/bok/glossary#t-intended-purpose","chapters":["11","14"]},{"term":"Internal reporting channel","slug":"t-internal-reporting-channel","definition":"A confidential route for staff and contractors to raise concerns about AI systems outside the chain of command, with statutory clocks encoded (under the EU Whistleblower Directive, acknowledgment within seven days and feedback within three…","url":"/glossary/internal-reporting-channel","anchor":"/bok/glossary#t-internal-reporting-channel","chapters":["12"]},{"term":"Interpretability","slug":"t-interpretability","definition":"In NIST's framing, the meaning of a system's output in the context of its purpose: why a decision was made and what it means to the user. An inherently interpretable model, such as a scorecard or a shallow tree, is its own explanation.","url":"/glossary/interpretability","anchor":"/bok/glossary#t-interpretability","chapters":["16"]},{"term":"ISO/IEC 22989","slug":"t-iso-iec-22989","definition":"The ISO/IEC standard (2022) that establishes AI concepts and terminology for use by other standards and by diverse stakeholders. Naming registry fields after its vocabulary reduces translation when auditing against the SC 42 family.","url":"/glossary/iso-iec-22989","anchor":"/bok/glossary#t-iso-iec-22989","chapters":["11","22"]},{"term":"ISO/IEC 42001","slug":"t-iso-iec-42001","definition":"The ISO/IEC standard (2023) that specifies requirements for an AI management system, certifiable by accredited bodies. As of 2026-09-24 it is not a harmonised standard under the AI Act, so certification gives no presumption of conformity.","url":"/glossary/iso-iec-42001","anchor":"/bok/glossary#t-iso-iec-42001","chapters":["07","08","22"]},{"term":"ISO/IEC 42005","slug":"t-iso-iec-42005","definition":"ISO/IEC 42005:2025, the AI system impact-assessment standard (a companion to the AI Act's Article 27 FRIA and to ISO/IEC 42001 Annex A.5), giving a structured method for assessing an AI system's impacts on people and society.","url":"/glossary/iso-iec-42005","anchor":"/bok/glossary#t-iso-iec-42005","chapters":["08","14"]},{"term":"Issue (versus incident)","slug":"t-issue-versus-incident","definition":"A defect, deviation or control weakness that has not produced a harmful event, such as an eval regression in staging or a drift alert.","url":"/glossary/issue-versus-incident","anchor":"/bok/glossary#t-issue-versus-incident","chapters":["17"]},{"term":"Jailbreak","slug":"t-jailbreak","definition":"A prompt crafted to make a model disregard its safety instructions entirely. OWASP treats jailbreaking as a form of prompt injection; it is tested with red-team suites in the eval gate and contained at runtime by guardrails that do not…","url":"/glossary/jailbreak","anchor":"/bok/glossary#t-jailbreak","chapters":["14","17"]},{"term":"JSON Schema","slug":"t-json-schema","definition":"A vocabulary for describing the structure of JSON documents so a validator can check them: which fields exist, which are required, their types and allowed values.","url":"/glossary/json-schema","anchor":"/bok/glossary#t-json-schema","chapters":["05"]},{"term":"Justification memo","slug":"t-justification-memo","definition":"The intake record for an AI use case: the problem, the non-AI alternative, the measurable benefit, who bears errors and how they contest them, reversibility and kill criteria.","url":"/glossary/justification-memo","anchor":"/bok/glossary#t-justification-memo","chapters":["12"]},{"term":"Key risk indicator (KRI)","slug":"t-key-risk-indicator-kri","definition":"A metric that shows whether a risk is moving towards the edge of appetite (unregistered AI found, open exceptions by age, override rates), as distinct from a key performance indicator, which shows whether the programme is doing its job.","url":"/glossary/key-risk-indicator-kri","anchor":"/bok/glossary#t-key-risk-indicator-kri","chapters":["12"]},{"term":"Kill switch","slug":"t-kill-switch","definition":"A tested mechanism to stop an agent or system from acting; a precondition of granting autonomy, registered against the agent's identity.","url":"/glossary/kill-switch","anchor":"/bok/glossary#t-kill-switch","chapters":["03","05","23"]},{"term":"Large language model (LLM)","slug":"t-large-language-model-llm","definition":"A foundation model for language, usually served from a data centre behind an API. Because calls pass through a gateway, runtime controls (tracing, filtering, stopping) can sit centrally.","url":"/glossary/large-language-model-llm","anchor":"/bok/glossary#t-large-language-model-llm","chapters":["11"]},{"term":"Latent disclosure","slug":"t-latent-disclosure","definition":"Under California's AI Transparency Act, provenance information embedded in AI-generated image, video or audio so that it persists and can be read by a detection tool, as opposed to a visible label shown to the user.","url":"/glossary/latent-disclosure","anchor":"/bok/glossary#t-latent-disclosure","chapters":["21"]},{"term":"Lawful basis","slug":"t-lawful-basis","definition":"One of the six grounds in GDPR Article 6 that make processing of personal data lawful: consent, contract, legal obligation, vital interests, public task and legitimate interests.","url":"/glossary/lawful-basis","anchor":"/bok/glossary#t-lawful-basis","chapters":["19"]},{"term":"Least agency","slug":"t-least-agency","definition":"The principle, in the OWASP agentic list, of giving an agent no more autonomy than its task needs: agentic behaviour deployed where it is not needed widens the attack surface without adding value.","url":"/glossary/least-agency","anchor":"/bok/glossary#t-least-agency","chapters":["23"]},{"term":"Legitimate-interest assessment (LIA)","slug":"t-legitimate-interest-assessment-lia","definition":"The documented three-step test for relying on legitimate interests: a lawful, precise and present interest; processing necessary for it; and a balance not overridden by people's rights and reasonable expectations.","url":"/glossary/legitimate-interest-assessment-lia","anchor":"/bok/glossary#t-legitimate-interest-assessment-lia","chapters":["19"]},{"term":"LIME","slug":"t-lime","definition":"Local Interpretable Model-agnostic Explanations: explains one prediction by fitting a simple interpretable model to the black box's behaviour on perturbed samples around the input; vulnerable to off-manifold manipulation.","url":"/glossary/lime","anchor":"/bok/glossary#t-lime","chapters":["16"]},{"term":"Localisation (by jurisdiction)","slug":"t-localisation-by-jurisdiction","definition":"Controlling where an AI system runs and which features it offers in each jurisdiction, with per-jurisdiction rule sets as code, regional instances where residency requires them and feature flags by region, so one market can be switched off…","url":"/glossary/localisation-by-jurisdiction","anchor":"/bok/glossary#t-localisation-by-jurisdiction","chapters":["05","12","15"]},{"term":"Loss of control","slug":"t-loss-of-control","definition":"One of the systemic risks the GPAI Code of Practice specifies: risks from humans losing the ability to reliably direct, modify or shut down a model, which may emerge from misalignment, self-replication, deception, resistance to goal…","url":"/glossary/loss-of-control","anchor":"/bok/glossary#t-loss-of-control","chapters":["08","23"]},{"term":"Machine learning","slug":"t-machine-learning","definition":"The branch of AI in which a system improves at a task by learning patterns from data rather than by following rules people wrote. ISO/IEC 22989 groups its approaches into supervised, unsupervised, semi-supervised and reinforcement learning.","url":"/glossary/machine-learning","anchor":"/bok/glossary#t-machine-learning","chapters":["11"]},{"term":"Machine unlearning","slug":"t-machine-unlearning","definition":"Techniques that remove a training record's influence from a model without full retraining.","url":"/glossary/machine-unlearning","anchor":"/bok/glossary#t-machine-unlearning","chapters":["05","19"]},{"term":"Machine-readable evidence","slug":"t-machine-readable-evidence","definition":"Evidence a machine can query, diff and aggregate (OSCAL artefacts, structured eval results, signed logs), as opposed to screenshots and exported spreadsheets.","url":"/glossary/machine-readable-evidence","anchor":"/bok/glossary#t-machine-readable-evidence","chapters":["03","04","05"]},{"term":"Major ICT-related incident (DORA)","slug":"t-major-ict-related-incident-dora","definition":"Under the EU Digital Operational Resilience Act, an ICT-related incident at a financial entity that meets the classification criteria for a major incident.","url":"/glossary/major-ict-related-incident-dora","anchor":"/bok/glossary#t-major-ict-related-incident-dora","chapters":["17"]},{"term":"Manufacturing defect","slug":"t-manufacturing-defect","definition":"In product liability, a departure of a unit from its own design. For AI: the wrong model version, corrupted weights, a misconfigured guardrail or a broken data pipeline in the deployed system.","url":"/glossary/manufacturing-defect","anchor":"/bok/glossary#t-manufacturing-defect","chapters":["20"]},{"term":"Market surveillance authority","slug":"t-market-surveillance-authority","definition":"The national authority designated to enforce the AI Act for products placed on its market, with powers to investigate, demand documentation and require corrective action.","url":"/glossary/market-surveillance-authority","anchor":"/bok/glossary#t-market-surveillance-authority","chapters":["08","18"]},{"term":"Maturity floor","slug":"t-maturity-floor","definition":"The single overall maturity level of an AI governance function: the level of its weakest stack layer. It is a floor for planning, not a verdict on the whole function.","url":"/glossary/maturity-floor","anchor":"/bok/glossary#t-maturity-floor","chapters":["07"]},{"term":"MCP","slug":"t-mcp","definition":"Model Context Protocol: an open protocol for connecting AI applications to tools and data sources; its 2026 specification adds OAuth 2.1 resource-server patterns and issuer-bound credentials for agent authorisation.","url":"/glossary/mcp","anchor":"/bok/glossary#t-mcp","chapters":["04","05","23"]},{"term":"Membership inference","slug":"t-membership-inference","definition":"An attack that determines whether a specific person's record was in a model's training set from the model's behaviour. The EDPB counts resistance to it among the evidence for claiming a model is anonymous.","url":"/glossary/membership-inference","anchor":"/bok/glossary#t-membership-inference","chapters":["19"]},{"term":"Memory poisoning","slug":"t-memory-poisoning","definition":"An injection that writes to an agent's long-term memory, a retrieval corpus, a vector store or a hosted memory service, and so taints every later session that reads from that store.","url":"/glossary/memory-poisoning","anchor":"/bok/glossary#t-memory-poisoning","chapters":["23"]},{"term":"Mitigation hierarchy","slug":"t-mitigation-hierarchy","definition":"The order in which risk treatments are tried: eliminate, substitute, engineer, administrative, then accept and monitor.","url":"/glossary/mitigation-hierarchy","anchor":"/bok/glossary#t-mitigation-hierarchy","chapters":["13"]},{"term":"Model anonymity","slug":"t-model-anonymity","definition":"The EDPB's test for when a trained model falls outside the GDPR: both direct extraction of training subjects' data and obtaining it through queries must be insignificant, given all means reasonably likely to be used.","url":"/glossary/model-anonymity","anchor":"/bok/glossary#t-model-anonymity","chapters":["19"]},{"term":"Model card","slug":"t-model-card","definition":"Structured, versioned documentation of a model (provenance, intended use, capabilities, evaluations and known failure modes) maintained as code.","url":"/glossary/model-card","anchor":"/bok/glossary#t-model-card","chapters":["04","05","14"]},{"term":"Model inversion","slug":"t-model-inversion","definition":"An attack that reconstructs features of training subjects, such as a face, from a model's outputs and confidence scores. It can turn a deployed model into a channel for disclosing personal data.","url":"/glossary/model-inversion","anchor":"/bok/glossary#t-model-inversion","chapters":["19"]},{"term":"Model risk management","slug":"t-model-risk-management","definition":"The banking-supervision practice of validating models for conceptual soundness, monitoring and outcomes analysis under effective challenge.","url":"/glossary/model-risk-management","anchor":"/bok/glossary#t-model-risk-management","chapters":["01","02","13","14","21"]},{"term":"Model signing","slug":"t-model-signing","definition":"Signing a model's files at build: a manifest lists every file with its cryptographic digest and a detached signature covers the manifest, so any changed file fails verification.","url":"/glossary/model-signing","anchor":"/bok/glossary#t-model-signing","chapters":["05","14","15"]},{"term":"Multimodal model","slug":"t-multimodal-model","definition":"A model that takes or produces more than one modality (text, image, audio, video).","url":"/glossary/multimodal-model","anchor":"/bok/glossary#t-multimodal-model","chapters":["11"]},{"term":"Near miss","slug":"t-near-miss","definition":"A hazard that a control, or luck, interrupted before harm occurred: the guardrail blocked the exfiltration, the reviewer caught the invented dosage.","url":"/glossary/near-miss","anchor":"/bok/glossary#t-near-miss","chapters":["17"]},{"term":"Negative space","slug":"t-negative-space","definition":"The uses an AI system is explicitly not for, written into its Deployment Decision Record.","url":"/glossary/negative-space","anchor":"/bok/glossary#t-negative-space","chapters":["15"]},{"term":"Neural data","slug":"t-neural-data","definition":"Information generated by measuring the activity of a person's central or peripheral nervous system.","url":"/glossary/neural-data","anchor":"/bok/glossary#t-neural-data","chapters":["19"]},{"term":"NHI","slug":"t-nhi","definition":"Non-human identity: the identity of an agent, service account or machine actor. Every NHI gets a registry entry, an owner and a scope before it is allowed to act.","url":"/glossary/nhi","anchor":"/bok/glossary#t-nhi","chapters":["04","05","23"]},{"term":"NIST AI RMF","slug":"t-nist-ai-rmf","definition":"The NIST Artificial Intelligence Risk Management Framework 1.0 (NIST AI 100-1, January 2023): voluntary guidance organised as a Core of four functions (Govern, Map, Measure, Manage) with categories and subcategories, plus profiles and a…","url":"/glossary/nist-ai-rmf","anchor":"/bok/glossary#t-nist-ai-rmf","chapters":["08","22"]},{"term":"Notified body","slug":"t-notified-body","definition":"A conformity assessment body designated under the EU AI Act to carry out third-party conformity assessment of high-risk AI systems.","url":"/glossary/notified-body","anchor":"/bok/glossary#t-notified-body","chapters":["14","18"]},{"term":"OECD AI Principles","slug":"t-oecd-ai-principles","definition":"The five values-based principles (inclusive growth and well-being; human rights, fairness and privacy; transparency and explainability; robustness, security and safety; accountability) and five policy recommendations of the OECD…","url":"/glossary/oecd-ai-principles","anchor":"/bok/glossary#t-oecd-ai-principles","chapters":["11","22"]},{"term":"OECD Framework for the Classification of AI Systems","slug":"t-oecd-framework-for-the-classification-of-ai-systems","definition":"An OECD tool (2022) for characterising an AI system from a policy perspective along five dimensions: People & Planet, Economic Context, Data & Input, AI Model, and Task & Output.","url":"/glossary/oecd-framework-for-the-classification-of-ai-systems","anchor":"/bok/glossary#t-oecd-framework-for-the-classification-of-ai-systems","chapters":["22"]},{"term":"OPA/Rego","slug":"t-opa-rego","definition":"The Open Policy Agent and its Rego policy language, a general-purpose policy-as-code engine that evaluates governance rules in CI/CD and at runtime admission; the canonical example of executable policy-as-code.","url":"/glossary/opa-rego","anchor":"/bok/glossary#t-opa-rego","chapters":["04","05","06"]},{"term":"Opacity","slug":"t-opacity","definition":"The inability of a person to follow how a system reached an output. It has three sources (secrecy, technical illiteracy, and the nature and scale of machine learning), each with a different fix: disclosure, literacy, and explanation…","url":"/glossary/opacity","anchor":"/bok/glossary#t-opacity","chapters":["11"]},{"term":"Open-weight model","slug":"t-open-weight-model","definition":"A model whose trained weights are published for download under a licence that may be permissive, copyleft, use-restricted or custom.","url":"/glossary/open-weight-model","anchor":"/bok/glossary#t-open-weight-model","chapters":["15","18"]},{"term":"Operator (EU AI Act)","slug":"t-operator-eu-ai-act","definition":"The umbrella term for the actors the AI Act binds: provider, product manufacturer, deployer, authorised representative, importer and distributor. The same organisation can be several operators for different systems, or for the same one.","url":"/glossary/operator-eu-ai-act","anchor":"/bok/glossary#t-operator-eu-ai-act","chapters":["18"]},{"term":"OSCAL","slug":"t-oscal","definition":"The Open Security Controls Assessment Language, a NIST machine-readable format for controls, assessments and evidence, used here as the format for audit-ready evidence.","url":"/glossary/oscal","anchor":"/bok/glossary#t-oscal","chapters":["04","05","10"]},{"term":"Output suppression","slug":"t-output-suppression","definition":"A filter around a model that stops it producing a person's data: the fast first answer to an erasure or objection request when the data sits in the weights and retraining is disproportionate.","url":"/glossary/output-suppression","anchor":"/bok/glossary#t-output-suppression","chapters":["05","19"]},{"term":"Paved path","slug":"t-paved-path","definition":"A supported, low-friction default route (a template, library or pipeline) that makes the governed way the easiest way to ship, so engineers adopt governance without asking permission.","url":"/glossary/paved-path","anchor":"/bok/glossary#t-paved-path","chapters":["03","06"]},{"term":"Personal data breach","slug":"t-personal-data-breach","definition":"A breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data, notified to the authority within 72 hours unless unlikely to result in a risk.","url":"/glossary/personal-data-breach","anchor":"/bok/glossary#t-personal-data-breach","chapters":["19"]},{"term":"PIPIA","slug":"t-pipia","definition":"China's personal information protection impact assessment under PIPL Articles 55 and 56, required in advance for sensitive data, automated decision-making, entrusted processing and cross-border provision, with the report kept for at least…","url":"/glossary/pipia","anchor":"/bok/glossary#t-pipia","chapters":["19"]},{"term":"Placing on the market","slug":"t-placing-on-the-market","definition":"Under the EU AI Act, the first making available of an AI system or general-purpose AI model on the Union market; later supplies in the course of a commercial activity are making available.","url":"/glossary/placing-on-the-market","anchor":"/bok/glossary#t-placing-on-the-market","chapters":["08","14","15","18","20"]},{"term":"Policy Card","slug":"t-policy-card","definition":"A JSON-schema, machine-readable governance artefact that declares an agent's allowed and forbidden behaviours for runtime enforcement.","url":"/glossary/policy-card","anchor":"/bok/glossary#t-policy-card","chapters":["04","05","10","23"]},{"term":"Policy verdict","slug":"t-policy-verdict","definition":"The structured record a policy engine emits each time it evaluates a rule: allow or deny, the versioned rule id, a hash of the input and a timestamp, signed and written to the evidence store.","url":"/glossary/policy-verdict","anchor":"/bok/glossary#t-policy-verdict","chapters":["04","05","12","23"]},{"term":"Policy-as-code","slug":"t-policy-as-code","definition":"Governance policy expressed in an executable policy language (OPA/Rego, Cedar) that evaluates in CI/CD and at admission; the narrower, pipeline subset of governance-as-code.","url":"/glossary/policy-as-code","anchor":"/bok/glossary#t-policy-as-code","chapters":["04","05","06"]},{"term":"Post-market monitoring","slug":"t-post-market-monitoring","definition":"The AI Act Article 72 duty to actively monitor a high-risk system's performance and risks after deployment, throughout its lifetime.","url":"/glossary/post-market-monitoring","anchor":"/bok/glossary#t-post-market-monitoring","chapters":["08","18"]},{"term":"Pre-determined changes","slug":"t-pre-determined-changes","definition":"Changes to a high-risk system that continues to learn, planned by the provider at the initial conformity assessment and described in the technical documentation; they are not substantial modifications.","url":"/glossary/pre-determined-changes","anchor":"/bok/glossary#t-pre-determined-changes","chapters":["14"]},{"term":"Predictive AI","slug":"t-predictive-ai","definition":"AI that outputs an estimate about something that exists: a score, class or forecast. Its harms are mostly allocation harms, and its evidence is accuracy, calibration and error rates by subgroup, with a decision threshold someone owns.","url":"/glossary/predictive-ai","anchor":"/bok/glossary#t-predictive-ai","chapters":["11"]},{"term":"Presumption of conformity","slug":"t-presumption-of-conformity","definition":"The legal effect under AI Act Article 40: a high-risk system or GPAI model that conforms with OJ-cited harmonised standards is presumed to meet the requirements those standards cover, and no others.","url":"/glossary/presumption-of-conformity","anchor":"/bok/glossary#t-presumption-of-conformity","chapters":["08","22"]},{"term":"Privacy by design and by default","slug":"t-privacy-by-design-and-by-default","definition":"The GDPR Article 25 duty to build data protection principles into processing through technical and organisational measures, and to process by default only the personal data each purpose needs.","url":"/glossary/privacy-by-design-and-by-default","anchor":"/bok/glossary#t-privacy-by-design-and-by-default","chapters":["19"]},{"term":"Privacy-enhancing technology (PET)","slug":"t-privacy-enhancing-technology-pet","definition":"A technique that reduces what an attacker, vendor or insider can learn from personal data, such as differential privacy, federated learning, synthetic data, masking or trusted execution.","url":"/glossary/privacy-enhancing-technology-pet","anchor":"/bok/glossary#t-privacy-enhancing-technology-pet","chapters":["19"]},{"term":"Product Liability Directive (PLD)","slug":"t-product-liability-directive-pld","definition":"Directive (EU) 2024/2853, which treats software, including AI, as a product; judges defect with learning and updates in view; lets courts order disclosure and presume defect; and applies to products placed on the market after 9 Dec 2026.","url":"/glossary/product-liability-directive-pld","anchor":"/bok/glossary#t-product-liability-directive-pld","chapters":["20"]},{"term":"Profiling override","slug":"t-profiling-override","definition":"The rule in the third subparagraph of AI Act Article 6(3) that an Annex III system which performs profiling of natural persons is always high-risk, whichever filter condition it meets.","url":"/glossary/profiling-override","anchor":"/bok/glossary#t-profiling-override","chapters":["08","18"]},{"term":"Progressive delivery","slug":"t-progressive-delivery","definition":"Releasing a change to a small, growing share of real traffic in stages (shadow, pilot, canary, general availability), each with rollback criteria registered before it starts and a tested path back to the previous version, so evidence about…","url":"/glossary/progressive-delivery","anchor":"/bok/glossary#t-progressive-delivery","chapters":["05","14","15","23"]},{"term":"Prohibited practice","slug":"t-prohibited-practice","definition":"An AI practice banned outright by AI Act Article 5, such as manipulative techniques that cause significant harm, social scoring, untargeted scraping of facial images, emotion recognition at work or school, and most real-time remote…","url":"/glossary/prohibited-practice","anchor":"/bok/glossary#t-prohibited-practice","chapters":["18"]},{"term":"Prompt injection","slug":"t-prompt-injection","definition":"An input that alters a model's behaviour or output in ways its designers did not intend. It is direct when the user supplies it and indirect when it arrives inside content the model processes, such as a web page, file or tool result.","url":"/glossary/prompt-injection","anchor":"/bok/glossary#t-prompt-injection","chapters":["01","04","17","23"]},{"term":"Proportionate governance","slug":"t-proportionate-governance","definition":"Running the same risk loop at an intensity set by organisation size, sector, maturity and risk tolerance, above a floor of controls that never tailors away.","url":"/glossary/proportionate-governance","anchor":"/bok/glossary#t-proportionate-governance","chapters":["13"]},{"term":"Provider","slug":"t-provider","definition":"Under the EU AI Act, whoever develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free.","url":"/glossary/provider","anchor":"/bok/glossary#t-provider","chapters":["15","18"]},{"term":"Proxy label","slug":"t-proxy-label","definition":"A training target that stands in for the construct a decision is meant to capture, such as health-care cost standing in for health need.","url":"/glossary/proxy-label","anchor":"/bok/glossary#t-proxy-label","chapters":["16"]},{"term":"Proxy scan","slug":"t-proxy-scan","definition":"A test that trains a model to predict a protected attribute from a system's features; features that predict it strongly are flagged as proxies to justify or remove, and the result is recorded in the data card.","url":"/glossary/proxy-scan","anchor":"/bok/glossary#t-proxy-scan","chapters":["05","16"]},{"term":"Proxy variable","slug":"t-proxy-variable","definition":"A feature that carries the information of a protected characteristic, such as postcode for ethnicity, so that a model can discriminate without using the attribute itself. Proxy tests look for features that predict the protected attribute.","url":"/glossary/proxy-variable","anchor":"/bok/glossary#t-proxy-variable","chapters":["16","20"]},{"term":"Pseudonymisation","slug":"t-pseudonymisation","definition":"Processing personal data so it can no longer be attributed to a person without additional information kept separately and protected.","url":"/glossary/pseudonymisation","anchor":"/bok/glossary#t-pseudonymisation","chapters":["19"]},{"term":"Purpose limitation","slug":"t-purpose-limitation","definition":"The GDPR principle that personal data collected for a specified purpose may not be further processed in an incompatible way; Article 6(4) sets the compatibility test.","url":"/glossary/purpose-limitation","anchor":"/bok/glossary#t-purpose-limitation","chapters":["19"]},{"term":"Putting into service","slug":"t-putting-into-service","definition":"Under the EU AI Act, the supply of an AI system for first use directly to the deployer, or for the provider's own use, in the Union for its intended purpose.","url":"/glossary/putting-into-service","anchor":"/bok/glossary#t-putting-into-service","chapters":["15","18"]},{"term":"QMS (Art. 17)","slug":"t-qms-art-17","definition":"The quality management system that AI Act Article 17 requires of high-risk providers; distinct from an ISO/IEC 42001 AIMS, which certifies a management system but is not harmonised.","url":"/glossary/qms-art-17","anchor":"/bok/glossary#t-qms-art-17","chapters":["08","18"]},{"term":"RAISE Act","slug":"t-raise-act","definition":"New York's Responsible AI Safety and Education Act, a frontier-AI safety law binding large frontier developers to publish a safety framework and every frontier developer to report critical safety incidents; signed 19 December 2025 and…","url":"/glossary/raise-act","anchor":"/bok/glossary#t-raise-act","chapters":["08","21"]},{"term":"Realised risk reduction","slug":"t-realised-risk-reduction","definition":"The measured drop in a named failure mode's rate or blast radius in production; one of the two tests of the discipline, against framework coverage.","url":"/glossary/realised-risk-reduction","anchor":"/bok/glossary#t-realised-risk-reduction","chapters":["01","03"]},{"term":"Reason code","slug":"t-reason-code","definition":"A stable, human-readable statement of a principal factor behind an adverse decision, mapped from the factors the model actually scored and versioned with the model; required in substance by US adverse-action rules.","url":"/glossary/reason-code","anchor":"/bok/glossary#t-reason-code","chapters":["05","16","20"]},{"term":"Reasonably foreseeable misuse","slug":"t-reasonably-foreseeable-misuse","definition":"Use of an AI system not in accordance with its intended purpose that may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems.","url":"/glossary/reasonably-foreseeable-misuse","anchor":"/bok/glossary#t-reasonably-foreseeable-misuse","chapters":["14","15"]},{"term":"Records of processing activities (ROPA)","slug":"t-records-of-processing-activities-ropa","definition":"The GDPR Article 30 record of each processing activity: purposes, categories of data and people, recipients, transfers, retention and security.","url":"/glossary/records-of-processing-activities-ropa","anchor":"/bok/glossary#t-records-of-processing-activities-ropa","chapters":["19"]},{"term":"Recourse","slug":"t-recourse","definition":"The ability of a person to obtain a different decision by changing inputs they can actually act on, such as income rather than age.","url":"/glossary/recourse","anchor":"/bok/glossary#t-recourse","chapters":["16","21"]},{"term":"Red teaming","slug":"t-red-teaming","definition":"Structured adversarial testing of a model or agent to elicit failures (jailbreaks, injection, tool misuse) before an attacker does; treated here as an evidence-producing control.","url":"/glossary/red-teaming","anchor":"/bok/glossary#t-red-teaming","chapters":["04","05","15"]},{"term":"Regurgitation","slug":"t-regurgitation","definition":"A model reproducing memorised training data verbatim, including personal data, whether prompted deliberately (training-data extraction) or not. Detected by output checks and canaries, and tested by extraction evals.","url":"/glossary/regurgitation","anchor":"/bok/glossary#t-regurgitation","chapters":["19","20"]},{"term":"Reinforcement learning","slug":"t-reinforcement-learning","definition":"Learning to maximise a reward signal through trial and feedback. Its characteristic failure is reward hacking, so the reward is recorded as the system's objective and evals look for unintended strategies.","url":"/glossary/reinforcement-learning","anchor":"/bok/glossary#t-reinforcement-learning","chapters":["11"]},{"term":"Reinforcement learning from human feedback (RLHF)","slug":"t-reinforcement-learning-from-human-feedback-rlhf","definition":"A way to align a pre-trained model: supervised fine-tuning on human demonstrations, then reinforcement learning against a reward model trained on human rankings of outputs.","url":"/glossary/reinforcement-learning-from-human-feedback-rlhf","anchor":"/bok/glossary#t-reinforcement-learning-from-human-feedback-rlhf","chapters":["11"]},{"term":"Reporting clock","slug":"t-reporting-clock","definition":"A statutory deadline for an incident notification, defined by its trigger (awareness, classification, causal link or determination), recipient, content and follow-ups, as in AI Act Article 73.","url":"/glossary/reporting-clock","anchor":"/bok/glossary#t-reporting-clock","chapters":["17"]},{"term":"Residual risk","slug":"t-residual-risk","definition":"What is left of a risk once treatment is applied. The EU AI Act requires residual risk per hazard and overall to be judged acceptable for high-risk systems. A residual rating credits only controls whose evidence is current.","url":"/glossary/residual-risk","anchor":"/bok/glossary#t-residual-risk","chapters":["13"]},{"term":"Responsible-AI licence (OpenRAIL)","slug":"t-responsible-ai-licence-openrail","definition":"A licence that grants open, royalty-free access to an AI artefact while attaching prohibited uses that every redistribution and derivative must carry forward.","url":"/glossary/responsible-ai-licence-openrail","anchor":"/bok/glossary#t-responsible-ai-licence-openrail","chapters":["15"]},{"term":"Responsible-AI principle set","slug":"t-responsible-ai-principle-set","definition":"A published set of normative targets for AI, such as the OECD AI Principles, the UNESCO Recommendation, the HLEG requirements or the G7 Hiroshima principles.","url":"/glossary/responsible-ai-principle-set","anchor":"/bok/glossary#t-responsible-ai-principle-set","chapters":["11"]},{"term":"Retrieval-augmented generation (RAG)","slug":"t-retrieval-augmented-generation-rag","definition":"A system that combines a model's learned memory with a retrievable store of documents at answer time.","url":"/glossary/retrieval-augmented-generation-rag","anchor":"/bok/glossary#t-retrieval-augmented-generation-rag","chapters":["11","16"]},{"term":"Reward hacking","slug":"t-reward-hacking","definition":"A system finding an unintended way to maximise its reward or objective without doing what its designers meant. Answered by recording the objective and testing for unintended strategies, not only for the intended task.","url":"/glossary/reward-hacking","anchor":"/bok/glossary#t-reward-hacking","chapters":["11"]},{"term":"Right to explanation (AI Act Art. 86)","slug":"t-right-to-explanation-ai-act-art-86","definition":"The right of a person affected by a deployer's decision based on an Annex III high-risk system's output, with legal or similarly significant adverse effects, to clear and meaningful explanations of the system's role and the main elements…","url":"/glossary/right-to-explanation-ai-act-art-86","anchor":"/bok/glossary#t-right-to-explanation-ai-act-art-86","chapters":["16","18","19"]},{"term":"Rights reservation (TDM opt-out)","slug":"t-rights-reservation-tdm-opt-out","definition":"A rightholder's express reservation of text and data mining under Article 4(3) of the DSM Directive, which takes the content out of the general mining exception; for content made publicly available online it must be made in an appropriate…","url":"/glossary/rights-reservation-tdm-opt-out","anchor":"/bok/glossary#t-rights-reservation-tdm-opt-out","chapters":["05","08","12","20"]},{"term":"Risk acceptance","slug":"t-risk-acceptance","definition":"A named, signed and expiring decision by someone with the authority a residual band requires, that a risk may remain for a bounded period under named compensating controls and a monitoring signal that voids it.","url":"/glossary/risk-acceptance","anchor":"/bok/glossary#t-risk-acceptance","chapters":["12","13"]},{"term":"Risk appetite","slug":"t-risk-appetite","definition":"How much risk, and of which kinds, an organisation is prepared to take on in pursuit of its objectives. In this book it is compiled from an approved statement into a versioned data file that gates read, rather than left in a board paper.","url":"/glossary/risk-appetite","anchor":"/bok/glossary#t-risk-appetite","chapters":["13"]},{"term":"Risk management","slug":"t-risk-management","definition":"The organised practice of steering an organisation's decisions with its risks in view: identify, assess, treat and monitor, in a loop. For high-risk systems the AI Act requires a documented risk management system across the lifecycle.","url":"/glossary/risk-management","anchor":"/bok/glossary#t-risk-management","chapters":["13"]},{"term":"Risk matrix","slug":"t-risk-matrix","definition":"A grid that turns a likelihood rating and a severity rating, each on defined scales, into a band that triggers a treatment, a gate and a review cadence. Useful for consistency, not precision; keep the numbers behind each cell.","url":"/glossary/risk-matrix","anchor":"/bok/glossary#t-risk-matrix","chapters":["13"]},{"term":"Risk register","slug":"t-risk-register","definition":"The evidence record of the risk loop: one versioned file per risk, keyed to a registry id, with ratings, treatment, controls that resolve to evidence, owner, acceptance, review cadence and links to evals, incidents and obligations.","url":"/glossary/risk-register","anchor":"/bok/glossary#t-risk-register","chapters":["13"]},{"term":"Risk source","slug":"t-risk-source","definition":"Anything that can give rise to risk alone or in combination, such as a dataset, a tool grant, an adversary or a user group.","url":"/glossary/risk-source","anchor":"/bok/glossary#t-risk-source","chapters":["13"]},{"term":"Risk tier","slug":"t-risk-tier","definition":"An organisation's own rating of an AI use case, computed at intake by a versioned policy from declared profile fields such as autonomy, decision impact, exposure, reversibility, vulnerable groups, data class and third parties.","url":"/glossary/risk-tier","anchor":"/bok/glossary#t-risk-tier","chapters":["05","06","12","13"]},{"term":"Risk tolerance","slug":"t-risk-tolerance","definition":"The readiness to bear a given risk in order to achieve objectives. Engineered as the highest residual band a system tier may carry before a deploy gate requires a signed acceptance.","url":"/glossary/risk-tolerance","anchor":"/bok/glossary#t-risk-tolerance","chapters":["13"]},{"term":"Rollback criteria","slug":"t-rollback-criteria","definition":"The conditions, written into the rollout plan before a release stage starts, under which the pipeline returns to the previous version automatically: a floor breached against the control group, a disagreement or override rate above a…","url":"/glossary/rollback-criteria","anchor":"/bok/glossary#t-rollback-criteria","chapters":["05","15"]},{"term":"Root-cause analysis (RCA)","slug":"t-root-cause-analysis-rca","definition":"The review that answers why an incident happened and why the controls did not stop it, using techniques such as five whys, fault tree analysis and blameless post-mortems, and codes each confirmed cause against a taxonomy that names the…","url":"/glossary/root-cause-analysis-rca","anchor":"/bok/glossary#t-root-cause-analysis-rca","chapters":["17"]},{"term":"Runtime data path","slug":"t-runtime-data-path","definition":"The live connection between production and the governance function (discovery, telemetry and enforcement), without which a registry or dashboard describes the program but cannot see what is running.","url":"/glossary/runtime-data-path","anchor":"/bok/glossary#t-runtime-data-path","chapters":["02","04","07"]},{"term":"Safetensors","slug":"t-safetensors","definition":"A file format for storing a model's tensors safely, as opposed to Python pickle, whose loading can run arbitrary code and which the Python documentation calls not secure.","url":"/glossary/safetensors","anchor":"/bok/glossary#t-safetensors","chapters":["05","14"]},{"term":"Safety component","slug":"t-safety-component","definition":"Under the AI Act as amended in 2026, a component of a product or AI system whose intended purpose is to prevent or mitigate risks to the health and safety of persons or property, or whose failure endangers them.","url":"/glossary/safety-component","anchor":"/bok/glossary#t-safety-component","chapters":["18"]},{"term":"Sanctioned AI gateway","slug":"t-sanctioned-ai-gateway","definition":"The single approved route by which staff reach AI tools and model APIs: approved tools behind single sign-on and a gateway that classifies each request by data class, allows, redacts or blocks it under the acceptable-use policy, checks for…","url":"/glossary/sanctioned-ai-gateway","anchor":"/bok/glossary#t-sanctioned-ai-gateway","chapters":["05","12"]},{"term":"SB 53","slug":"t-sb-53","definition":"California's frontier-AI transparency law (TFAIA), in force 1 Jan 2026, covering frontier developers training models above 10^26 FLOP: all of them publish transparency reports and report critical safety incidents, and large frontier…","url":"/glossary/sb-53","anchor":"/bok/glossary#t-sb-53","chapters":["08","21"]},{"term":"Self-supervised learning","slug":"t-self-supervised-learning","definition":"Learning by predicting parts of the input itself, such as the next token, over large corpora; the AI Act's definition of a general-purpose model names self-supervision at scale.","url":"/glossary/self-supervised-learning","anchor":"/bok/glossary#t-self-supervised-learning","chapters":["11"]},{"term":"Serious incident","slug":"t-serious-incident","definition":"Under AI Act Article 3(49), an incident or malfunction of an AI system that directly or indirectly leads to (a) a death or serious harm to health, (b) serious and irreversible disruption of critical infrastructure, (c) infringement of…","url":"/glossary/serious-incident","anchor":"/bok/glossary#t-serious-incident","chapters":["04","08","17","18"]},{"term":"Shadow AI","slug":"t-shadow-ai","definition":"An AI system, model or agent running without registration, including staff use of unapproved AI tools; the failure mode that makes an inventory complete only for the honest.","url":"/glossary/shadow-ai","anchor":"/bok/glossary#t-shadow-ai","chapters":["05","07","12"]},{"term":"Shadow deployment","slug":"t-shadow-deployment","definition":"A release stage in which a new model or system receives live inputs but its outputs are not used, so its behaviour on real traffic can be compared with the incumbent or with human decisions before any exposure.","url":"/glossary/shadow-deployment","anchor":"/bok/glossary#t-shadow-deployment","chapters":["05","14","15"]},{"term":"SHAP","slug":"t-shap","definition":"SHapley Additive exPlanations: a feature-attribution method that assigns each input feature a share of a particular prediction, based on Shapley values; its explanations depend on the chosen baseline or background data.","url":"/glossary/shap","anchor":"/bok/glossary#t-shap","chapters":["16"]},{"term":"Small language model (SLM)","slug":"t-small-language-model-slm","definition":"A language model small enough to run close to the user, for example on a phone. Its controls must ship with it: guardrails on the device, a version inventory across the fleet and a kill switch delivered as a remote flag or app update.","url":"/glossary/small-language-model-slm","anchor":"/bok/glossary#t-small-language-model-slm","chapters":["11"]},{"term":"Small mid-cap enterprise (SMC)","slug":"t-small-mid-cap-enterprise-smc","definition":"An enterprise that has outgrown the SME definition but falls within the EU small mid-cap definition.","url":"/glossary/small-mid-cap-enterprise-smc","anchor":"/bok/glossary#t-small-mid-cap-enterprise-smc","chapters":["18"]},{"term":"Special category data","slug":"t-special-category-data","definition":"The GDPR Article 9 categories whose processing is prohibited unless a condition applies: data revealing racial or ethnic origin, political opinions, beliefs or union membership, and genetic, biometric (for identification), health, sex-life…","url":"/glossary/special-category-data","anchor":"/bok/glossary#t-special-category-data","chapters":["19"]},{"term":"Stakeholder mapping","slug":"t-stakeholder-mapping","definition":"Naming who is affected by or holds a view on an AI system (users, affected non-users, deployers, providers, internal functions, regulators, the governing body) and how each view enters the risk loop, with the consultation logged.","url":"/glossary/stakeholder-mapping","anchor":"/bok/glossary#t-stakeholder-mapping","chapters":["13"]},{"term":"STAR for AI","slug":"t-star-for-ai","definition":"CSA's security assurance and certification programme for AI, built on the AICM, with a self-assessment tier, an automated \"Valid-AI-ted\" tier and a Level 2 combining ISO/IEC 42001 with the validated assessment.","url":"/glossary/star-for-ai","anchor":"/bok/glossary#t-star-for-ai","chapters":["07","08"]},{"term":"STRIDE","slug":"t-stride","definition":"A threat-classification checklist from Microsoft's Security Development Lifecycle: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.","url":"/glossary/stride","anchor":"/bok/glossary#t-stride","chapters":["05","06","15"]},{"term":"Sub-processor","slug":"t-sub-processor","definition":"A processor that another processor engages to carry out processing for a controller, such as the model host behind an AI vendor.","url":"/glossary/sub-processor","anchor":"/bok/glossary#t-sub-processor","chapters":["08","12","15","19"]},{"term":"Substantial modification","slug":"t-substantial-modification","definition":"Under the EU AI Act, a change after placing on the market that the initial conformity assessment did not foresee and that affects compliance or changes the intended purpose.","url":"/glossary/substantial-modification","anchor":"/bok/glossary#t-substantial-modification","chapters":["14","15","18"]},{"term":"Supervised learning","slug":"t-supervised-learning","definition":"Learning from labelled examples. Labels encode past human decisions with their errors and bias, so the data card records label provenance and the eval gate tests error rates by subgroup.","url":"/glossary/supervised-learning","anchor":"/bok/glossary#t-supervised-learning","chapters":["11"]},{"term":"SVID","slug":"t-svid","definition":"SPIFFE Verifiable Identity Document: a short-lived cryptographic identity document, either an X.509 certificate or a JWT, that proves a workload's SPIFFE ID and is issued and rotated through the SPIFFE Workload API, which SPIRE implements.","url":"/glossary/svid","anchor":"/bok/glossary#t-svid","chapters":["23"]},{"term":"Synthetic data","slug":"t-synthetic-data","definition":"Data generated by a model or simulation rather than collected from people or events, used to augment training sets, test edge cases or reduce exposure of personal data.","url":"/glossary/synthetic-data","anchor":"/bok/glossary#t-synthetic-data","chapters":["14","19"]},{"term":"System card","slug":"t-system-card","definition":"Documentation of a deployed AI system as a whole (models, prompts, retrieval, tools, guardrails and oversight), where a model card documents one model.","url":"/glossary/system-card","anchor":"/bok/glossary#t-system-card","chapters":["14","15"]},{"term":"Systemic risk","slug":"t-systemic-risk","definition":"Under the AI Act, the risk posed by the most capable general-purpose AI models, triggering extra evaluation, adversarial-testing and incident-reporting duties on their providers.","url":"/glossary/systemic-risk","anchor":"/bok/glossary#t-systemic-risk","chapters":["08","18"]},{"term":"Tabletop exercise","slug":"t-tabletop-exercise","definition":"A scheduled, scored rehearsal of an incident playbook against a named failure mode, producing the same records a real incident would (record, clocks, draft reports, containment events) tagged as a drill.","url":"/glossary/tabletop-exercise","anchor":"/bok/glossary#t-tabletop-exercise","chapters":["17"]},{"term":"TC260","slug":"t-tc260","definition":"The National Technical Committee 260 on Cybersecurity of the Standardization Administration of China (全国网络安全标准化技术委员会), which drafts China's cybersecurity and AI national standards (GB and GB/T) and publishes the voluntary AI Safety…","url":"/glossary/tc260","anchor":"/bok/glossary#t-tc260","chapters":["08","21"]},{"term":"TDM exception","slug":"t-tdm-exception","definition":"Two EU copyright exceptions for text and data mining (DSM Directive). Article 3 covers scientific research by research organisations and cultural heritage institutions; no reservation or contract can override it (Article 7(1)).","url":"/glossary/tdm-exception","anchor":"/bok/glossary#t-tdm-exception","chapters":["20"]},{"term":"Technical documentation (Annex IV)","slug":"t-technical-documentation-annex-iv","definition":"The provider's technical file for a high-risk AI system, drawn up before placing on the market and kept up to date under Article 11: description, development process, data, testing, oversight, risk management, standards, declaration and…","url":"/glossary/technical-documentation-annex-iv","anchor":"/bok/glossary#t-technical-documentation-annex-iv","chapters":["14"]},{"term":"Test-set contamination","slug":"t-test-set-contamination","definition":"The presence of evaluation items in a model's training data, which inflates its scores; it can be demonstrated even for black-box language models. Mitigated with private held-out sets, rotated items and dated test items.","url":"/glossary/test-set-contamination","anchor":"/bok/glossary#t-test-set-contamination","chapters":["14"]},{"term":"Testing in real-world conditions","slug":"t-testing-in-real-world-conditions","definition":"Under the EU AI Act, temporary testing of an AI system for its intended purpose outside a laboratory, under a plan approved by the market surveillance authority, with registration, informed consent of subjects, effective oversight and…","url":"/glossary/testing-in-real-world-conditions","anchor":"/bok/glossary#t-testing-in-real-world-conditions","chapters":["18"]},{"term":"Threat model (AI)","slug":"t-threat-model-ai","definition":"A versioned record of what can go wrong with an AI system and what is done about it: data flows and trust boundaries, threats per element from STRIDE and AI-specific catalogues, a decision on each, and the test that proves each mitigation.","url":"/glossary/threat-model-ai","anchor":"/bok/glossary#t-threat-model-ai","chapters":["05","14","15","23"]},{"term":"Three Lines Model","slug":"t-three-lines-model","definition":"The Institute of Internal Auditors' 2020 update of the \"three lines of defense\": the governing body oversees; management holds first-line roles (delivering products and services) and second-line roles (risk expertise, support and…","url":"/glossary/three-lines-model","anchor":"/bok/glossary#t-three-lines-model","chapters":["12"]},{"term":"Token passthrough","slug":"t-token-passthrough","definition":"The anti-pattern in which a server accepts a token that was not issued to it and forwards it, unmodified, to a downstream API, which may then trust it as if the server had validated it.","url":"/glossary/token-passthrough","anchor":"/bok/glossary#t-token-passthrough","chapters":["23"]},{"term":"Tool allow-list","slug":"t-tool-allow-list","definition":"The deny-by-default list of tools an agent may call, each entry pinned by a hash of the tool's definition and bounded by resource scope, operation class, rate, egress destinations, data classes and a checkpoint rule, evaluated by the tool…","url":"/glossary/tool-allow-list","anchor":"/bok/glossary#t-tool-allow-list","chapters":["23"]},{"term":"Tool poisoning","slug":"t-tool-poisoning","definition":"Tampering with a tool an agent uses, through its model-visible definition (description, schema, metadata) or its behaviour, so the agent acts on false premises.","url":"/glossary/tool-poisoning","anchor":"/bok/glossary#t-tool-poisoning","chapters":["23"]},{"term":"Training-content summary","slug":"t-training-content-summary","definition":"The public summary of the content used to train a general-purpose AI model, required by AI Act Article 53(1)(d) on a mandatory Commission template covering data sources, including the most-scraped domains, and data processing.","url":"/glossary/training-content-summary","anchor":"/bok/glossary#t-training-content-summary","chapters":["14"]},{"term":"Training, validation and testing data","slug":"t-training-validation-and-testing-data","definition":"The three data sets the AI Act defines for high-risk systems: training data fits the model, validation data tunes it and guards against overfitting, and testing data gives an independent check before release.","url":"/glossary/training-validation-and-testing-data","anchor":"/bok/glossary#t-training-validation-and-testing-data","chapters":["14"]},{"term":"Trajectory (agent)","slug":"t-trajectory-agent","definition":"The sequence of plans, tool calls and memory operations that led an agent to an effect.","url":"/glossary/trajectory-agent","anchor":"/bok/glossary#t-trajectory-agent","chapters":["14","23"]},{"term":"Transaction token (Txn-Token)","slug":"t-transaction-token-txn-token","definition":"A short-lived, signed token, specified in an IETF OAuth working group draft, that carries user identity, workload identity and authorisation context through a call chain within one trusted domain, so downstream services can decide on…","url":"/glossary/transaction-token-txn-token","anchor":"/bok/glossary#t-transaction-token-txn-token","chapters":["23"]},{"term":"Transfer impact assessment (TIA)","slug":"t-transfer-impact-assessment-tia","definition":"The data exporter's assessment of whether the law of a third country lets the importer honour the transfer tool, such as standard contractual clauses, and which supplementary measures are needed.","url":"/glossary/transfer-impact-assessment-tia","anchor":"/bok/glossary#t-transfer-impact-assessment-tia","chapters":["19"]},{"term":"Transparency","slug":"t-transparency","definition":"In NIST's framing, how far information about an AI system and its outputs reaches the people who interact with it: what happened.","url":"/glossary/transparency","anchor":"/bok/glossary#t-transparency","chapters":["11","16"]},{"term":"Trustworthy AI","slug":"t-trustworthy-ai","definition":"A banner used by other people's frameworks, notably the EU High-Level Expert Group and NIST, whose seven trustworthy characteristics make it concrete.","url":"/glossary/trustworthy-ai","anchor":"/bok/glossary#t-trustworthy-ai","chapters":["01","22"]},{"term":"Trustworthy characteristics (NIST)","slug":"t-trustworthy-characteristics-nist","definition":"The seven characteristics of trustworthy AI in the NIST AI RMF: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; fair with harmful bias managed.","url":"/glossary/trustworthy-characteristics-nist","anchor":"/bok/glossary#t-trustworthy-characteristics-nist","chapters":["22"]},{"term":"UDAP","slug":"t-udap","definition":"Unfair or deceptive acts or practices, prohibited by section 5 of the FTC Act and by state laws. Deception is a material representation likely to mislead; unfairness is substantial, unavoidable injury not outweighed by benefits.","url":"/glossary/udap","anchor":"/bok/glossary#t-udap","chapters":["20"]},{"term":"Unsupervised learning","slug":"t-unsupervised-learning","definition":"Learning structure (clusters, anomalies) from data without labels. With no ground truth to test against, controls rely on stability tests and human review of the segments before they are used in decisions.","url":"/glossary/unsupervised-learning","anchor":"/bok/glossary#t-unsupervised-learning","chapters":["11"]},{"term":"Use-case record","slug":"t-use-case-record","definition":"The intake record for a proposed AI use: business context, intended purpose and the uses ruled out, affected persons, decision authority, success metrics and error appetite, stored as fields on the registry entry so classification…","url":"/glossary/use-case-record","anchor":"/bok/glossary#t-use-case-record","chapters":["05","06","14"]},{"term":"Version pinning","slug":"t-version-pinning","definition":"Fixing, in the registry entry, the exact versions of the model, prompts, retrieval corpus and guardrails a deployed system uses, so what ran is known and any unpinned change, including a vendor's model update, is detected and treated as a…","url":"/glossary/version-pinning","anchor":"/bok/glossary#t-version-pinning","chapters":["05","15"]},{"term":"Watermarking","slug":"t-watermarking","definition":"Embedding a signal in generated content (image, audio, video or text) that a detector can later read to identify it as AI-generated.","url":"/glossary/watermarking","anchor":"/bok/glossary#t-watermarking","chapters":["18","20"]},{"term":"Widespread infringement","slug":"t-widespread-infringement","definition":"Under AI Act Article 3(61), an act or omission contrary to Union law protecting individuals' interests that harms, or is likely to harm, the collective interests of individuals across several Member States.","url":"/glossary/widespread-infringement","anchor":"/bok/glossary#t-widespread-infringement","chapters":["17"]},{"term":"Workload identity","slug":"t-workload-identity","definition":"The attributable identity a workload such as an agent carries across every hop, under which its actions are logged and its access is revoked, typically a short-lived, attested credential such as an SVID.","url":"/glossary/workload-identity","anchor":"/bok/glossary#t-workload-identity","chapters":["03","04","05","23"]}]