Glossary (EU AI Act)

Last reviewed: June 2026Source regulation: Regulation (EU) 2024/1689

Plain-language definitions of the terminology you will encounter when reading, implementing, or advising on the EU AI Act. Where a term is formally defined in the regulation, the relevant Article is cited. Where a term is used in practice but not formally defined, that is noted.

A

Accuracy (Article 15)

The degree to which a high-risk AI system produces correct outputs relative to its intended purpose. Providers must ensure systems achieve an appropriate level of accuracy (defined in the accompanying instructions for use) and declare the relevant accuracy metrics. Accuracy must be maintained throughout the system's operational life, not merely at deployment.

AI Literacy (Article 4)

The knowledge, skills, and understanding needed to make informed decisions about AI systems, including awareness of AI capabilities, limitations, and associated risks. Both providers and deployers must ensure that staff working with or overseeing AI systems have sufficient AI literacy appropriate to their role. In force since 2 February 2025.

AI Office

The EU-level body established within the European Commission to supervise general-purpose AI models, enforce Chapter V obligations, coordinate with national competent authorities, and develop guidance, codes of practice, and standardisation support. The AI Office has direct enforcement powers for GPAI providers, including the ability to conduct investigations and issue fines.

AI Regulatory Sandbox (Articles 57–63)

A controlled environment established by a national competent authority that allows providers and prospective providers to develop, test, and validate AI systems under real or near-real conditions before bringing them to market. Participants receive guidance, regulatory advice, and limited flexibility to process personal data that would not otherwise be permitted. Intended to support innovation, particularly for SMEs and start-ups.

AI System (Article 3(1))

A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from inputs how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Standard deterministic software (rule-based systems with no inferential capacity) is generally outside this definition.

AI Value Chain (Article 25)

The sequence of actors involved in the development, distribution, and deployment of an AI system; from the original provider through importers, distributors, and downstream deployers. The regulation distributes obligations across this chain and sets out what happens when actors assume multiple roles or modify a system.

Annex I

The list of Union harmonisation legislation covering safety-critical product categories (including medical devices, vehicles, aviation systems, and machinery) whose products may incorporate AI systems. AI that functions as a safety component of an Annex I product is classified as high-risk under Article 6(1).

Annex III

The list of eight high-risk AI application areas whose standalone AI systems are classified as high-risk under Article 6(2): biometric identification, critical infrastructure, education, employment and workers management, access to essential private and public services, law enforcement, migration and border control, and administration of justice. Annex III can be amended by the Commission by delegated act.

Annex IV

The technical documentation requirements for high-risk AI systems. Sets out the eleven categories of information providers must prepare and maintain, including a general description of the system, design specifications, training data documentation, risk management records, performance metrics, and instructions for use.

Authorised Representative (Article 3(5))

A natural or legal person established in the EU who has been appointed in writing by a provider of a high-risk AI system or GPAI model located outside the EU, and who acts on the provider's behalf in relation to the provider's obligations under the regulation. Mandatory for non-EU providers placing systems on the EU market.

B

Biometric Categorisation System (Article 3(40))

An AI system used to assign natural persons to specific categories based on biometric data, such as facial features, gait, or voice. Categorisation by sensitive attributes (including race, political opinion, religion, sexual orientation, or trade union membership) is prohibited under Article 5(1)(g). Biometric categorisation used as part of an employment or law enforcement decision context is classified as high-risk under Annex III.

Biometric Data

Biometric data is personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics of a natural person that allow or confirm the unique identification of that person (such as facial images, fingerprints, iris scans, or gait patterns). As a special category under GDPR, its processing requires a specific legal basis. AI systems that process biometric data for identification or categorisation purposes are subject to specific restrictions under the AI Act.

Biometric Identification System (Article 3(42))

An AI system used to identify a natural person by comparing biometric data against a reference database. Real-time remote biometric identification in publicly accessible spaces is prohibited under Article 5(1)(h), subject to narrow law enforcement exceptions. Post-remote (after-the-fact) biometric identification for law enforcement is classified as high-risk under Annex III.

C

CE Marking (Article 48)

The conformity marking that providers must affix to high-risk AI systems that have successfully completed the applicable conformity assessment procedure and comply with the regulation's requirements. CE marking indicates that the provider declares the system meets EU regulatory standards and takes responsibility for that declaration. Required before placing a high-risk AI system on the EU market.

Concept Drift

Not a term defined in the regulation, but used in practice to describe the phenomenon where the statistical relationship between input features and correct outputs changes over time in a deployed model. For example, when the behaviour of the population the model was trained on changes. Concept drift can cause a model's performance to degrade without any change to the model itself. Under Article 9(7) and Article 72, providers and deployers must monitor for and respond to performance degradation including that caused by drift.

Conformity Assessment (Article 3(20), Article 43)

The process through which a provider demonstrates that a high-risk AI system meets the requirements set out in Chapter III, Section 2. For most Annex III systems, providers may conduct a self-assessment. For certain biometric identification systems and systems embedded in Annex I regulated products, assessment by an accredited notified body is required. Conformity must be reassessed after any substantial modification.

Conformity Assessment Body (Article 3(21))

An independent body designated by a Member State to carry out third-party conformity assessments of high-risk AI systems where self-assessment is not permitted. Also known as a notified body once officially designated and listed by the Commission. Must meet accreditation requirements including technical competence, independence, and impartiality.

D

Data Drift

Not a term defined in the regulation, but widely used to describe a shift in the statistical distribution of input data in production compared to the data used to train and validate the model. Data drift can cause a model's outputs to become less reliable even without changes to the model weights. Monitoring for data drift is an operational necessity for meeting post-market monitoring requirements under Article 72 and the continuous risk management obligations under Article 9(7).

Data Governance (Article 10)

The practices and policies governing the collection, preparation, use, and management of training, validation, and test data for high-risk AI systems. Article 10 requires that data is relevant, representative, free of errors insofar as possible, and examined for potential biases. Data governance documentation forms a required component of the technical file under Annex IV.

Declaration of Conformity (Article 47)

A formal document drawn up by the provider of a high-risk AI system in which the provider declares, under sole responsibility, that the system meets the requirements of the regulation. The declaration must be kept updated, made available to authorities on request, and drawn up in one of the official languages of the EU.

Deep Fake (Article 3(60))

AI-generated or AI-manipulated image, audio, or video content that falsely depicts real persons, objects, places, events, or documents, and would falsely appear to a person to be authentic. Providers and deployers of systems that generate deep fakes are required under Article 50(4) to disclose that the content has been artificially generated or manipulated, with limited exceptions for satire or artistic expression where appropriate disclosure is made.

Deployer (Article 3(4))

Any natural or legal person, public authority, agency, or other body that uses an AI system under its own authority in a professional context, except where the system is used solely for personal non-professional activity. Deployers of high-risk AI systems carry obligations under Article 26 including human oversight, operational monitoring, log retention, incident reporting, and (for qualifying public-sector and regulated-context deployers) a Fundamental Rights Impact Assessment.

Digital Omnibus on AI

A package of targeted legislative amendments to the EU AI Act proposed by the European Commission on 19 November 2025. The most significant change is the deferral of high-risk Annex III compliance obligations from 2 August 2026 to 2 December 2027 (standalone systems) and from 2 August 2027 to 2 August 2028 (Annex I product-embedded systems). A provisional political agreement between the European Parliament, Council, and Commission was reached on 7 May 2026, pending formal adoption and Official Journal publication.

Distributor (Article 3(7))

Any natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the EU market without altering its properties. Distributors carry obligations to verify CE marking and declaration of conformity, not to supply systems known to be non-compliant, and to cooperate with market surveillance authorities.

E

Emotion Recognition System (Article 3(39))

An AI system used to identify or infer the emotions or intentions of natural persons based on their biometric data (including facial expressions, voice tone, body language, or physiological signals). The use of emotion recognition systems in the workplace and in educational institutions is prohibited under Article 5(1)(f), with narrow exceptions for medical and safety purposes.

EU AI Database (Article 71)

A publicly accessible EU-level register in which providers must register high-risk AI systems before placing them on the market or putting them into service. The database contains information about the system, its intended purpose, the conformity assessment carried out, and the provider's contact details. Maintained by the Commission, it allows market surveillance authorities, deployers, and the public to verify registered systems.

F

Fairness

Not a legally defined term in the regulation, but a substantive compliance concept. Article 10 requires training data to be examined for potential biases that could lead to discriminatory outputs. Article 9 requires risk management to cover harms including those arising from discriminatory treatment of protected groups. In practice, fairness requires ongoing monitoring of model outputs across demographic subgroups, not just at training time.

Fine-Tuning

The process of further training a pre-trained AI or GPAI model on a more specific dataset, typically to adapt it to a particular task or domain. Fine-tuning is a common practice when deploying GPAI models such as large language models. Under Article 25, extensive fine-tuning that materially changes the intended purpose or performance characteristics of a high-risk AI system may reclassify the organisation doing the fine-tuning as a provider, with full provider obligations.

FLOPs (Floating Point Operations)

A measure of the computational resources used to train an AI model, expressed as the number of floating point operations performed. The EU AI Act uses 10²⁵ FLOPs as the presumptive threshold above which a GPAI model is classified as presenting systemic risk under Article 51(1)(a). Models trained using this level of compute or above must comply with the additional obligations for systemic-risk GPAI providers under Article 55.

Foundation Model

Not a defined term in the regulation. In practice, used interchangeably with GPAI model to refer to large models trained on broad data at scale that can be adapted to many downstream tasks. The regulation uses "general-purpose AI model" as its formal term. See: GPAI Model.

FRIA (Fundamental Rights Impact Assessment) (Article 27)

A structured assessment that certain deployers must carry out before putting a high-risk AI system into operation. The FRIA evaluates the system's potential impact on the fundamental rights of affected persons, including the rights to non-discrimination, privacy, human dignity, and effective remedy. Required for deployers that are public bodies, provide public services, or operate in specific Annex III sectors. The completed assessment must be sent to the relevant market surveillance authority.

G

General-Purpose AI Model (GPAI Model) (Article 3(63))

An AI model trained on large amounts of data using self-supervision at scale, that displays significant generality and can perform a wide range of distinct tasks, and that can be integrated into various downstream systems or applications. Examples include large language models such as GPT-4, Claude, Gemini, Llama, and Mistral. GPAI models are regulated under Chapter V, which applies separately from the high-risk framework in Chapter III.

GPAI Code of Practice (Article 56)

A voluntary framework finalised in July 2025 by independent experts convened by the AI Office, structured across three chapters: Transparency, Copyright, and Safety and Security. GPAI model providers who sign and comply with the Code benefit from a presumption of conformity with Articles 53 and 55. Non-signatories must demonstrate compliance through alternative means, which carries greater legal uncertainty and enforcement exposure.

GPAI Model with Systemic Risk (Article 3(65), Article 51)

A GPAI model that presents significant risks to public health, safety, security, or fundamental rights due to its capabilities or widespread use. Presumptively classified as systemic when cumulative training compute exceeds 10²⁵ FLOPs, or when designated by the Commission based on other criteria. Subject to additional obligations under Article 55 including model evaluations, adversarial testing, serious incident reporting, and cybersecurity protections.

H

Harmonised Standard (Article 40)

A European standard developed by CEN, CENELEC, or ETSI upon a mandate from the European Commission, aligned with the technical requirements of the regulation. AI systems that comply with a harmonised standard (once published in the Official Journal) benefit from a "presumption of conformity" with the specific requirements covered by that standard. Harmonised standards for the EU AI Act are still being developed, with publication of the first wave delayed into late 2026.

High-Risk AI System (Article 6)

An AI system classified as high-risk under either Article 6(1) (by virtue of being a safety component of a regulated product listed in Annex I) or Article 6(2) (by virtue of falling within a use case listed in Annex III).

High-risk systems must comply with the requirements in Articles 9–15 (risk management, data governance, transparency, logging, human oversight, accuracy/robustness) and the provider/deployer obligations in Articles 16–27.

Human Oversight (Article 14)

The requirement that high-risk AI systems be designed and deployed in a way that allows responsible natural persons to understand the system's capabilities and limitations, monitor its operation, detect and correct errors or unexpected outputs, and intervene, override, or halt the system where necessary. Deployers must designate a specific person with the authority and capability to exercise this oversight. Human oversight does not require every decision to be reviewed by a human; it requires that an override is always feasible and that the oversight person is genuinely equipped to exercise it.

I

Importer (Article 3(6))

Any natural or legal person established in the EU that places on the EU market a high-risk AI system bearing the name or trademark of a person established outside the EU. Importers are responsible for verifying that the provider has carried out the required conformity assessment, that the system bears CE marking, and that required documentation is available.

Instructions for Use (Article 13)

Information provided by the provider of a high-risk AI system to deployers, explaining the system's intended purpose, capabilities, limitations, performance metrics, known biases, conditions for safe use, maintenance requirements, and any other information necessary for deployers to use the system appropriately and exercise human oversight. Must be concise, complete, and kept up to date. A critical document for deployers who must evidence compliance at audit.

Intended Purpose (Article 3(12))

The use for which an AI system is intended by the provider, including the specific context and conditions of use, the category of users, and the foreseeable inputs. Classification as high-risk is determined by intended purpose rather than the technology itself. Changes to intended purpose (for example, deploying a general-purpose LLM in a recruitment screening context) can change the system's risk classification.

L

Large Language Model (LLM)

Not a defined term in the regulation. In practice, a type of GPAI model trained on large volumes of text data using transformer architectures, capable of generating, translating, summarising, and reasoning about language. Examples include GPT-4, Claude, Gemini, and Llama. Most commercial LLMs meet the definition of GPAI model under the regulation and are regulated under Chapter V.

Limited Risk AI System

An informal grouping of AI systems that are not high-risk but are subject to specific transparency obligations under Article 50. These include chatbots, deep fake generators, AI-generated text systems, and emotion recognition systems (in contexts not covered by the prohibition). Providers and deployers must ensure users are informed they are interacting with or receiving outputs from an AI system.

M

Market Surveillance Authority (Article 70)

The national competent authority designated by each Member State to monitor and enforce compliance with the regulation for AI systems (other than GPAI models) placed on or used in the market of that Member State. Powers include requesting information and documentation, conducting audits, ordering corrective measures, and issuing fines. For GPAI models, the AI Office, not the national authority, is the primary enforcement body.

Minimal Risk AI System

An informal grouping of AI systems that are not prohibited, not high-risk, and not subject to Article 50 transparency obligations. Examples include AI-powered spam filters, inventory management systems, and video game AI. No mandatory obligations apply, though providers are encouraged to comply with voluntary codes of conduct. Represents the large majority of AI systems currently deployed in commercial contexts.

Model Card

Not a defined term in the regulation, but widely used in practice to refer to a standardised document that describes an AI model's intended use, training data, performance characteristics, known limitations, and fairness properties. Model cards serve as a practical vehicle for satisfying elements of the Article 11 and Annex IV technical documentation requirements, and for providing the Article 13 information to deployers.

Model Drift

Not a defined term in the regulation, but used in practice to refer collectively to forms of performance degradation in deployed AI models, including data drift, concept drift, and changes in model behaviour due to fine-tuning or updates. Under Articles 9(7) and 72, providers and deployers must maintain systems capable of detecting and responding to model drift throughout the operational life of a high-risk AI system.

N

National Competent Authority (Article 70)

The authority or authorities designated by each EU Member State to be responsible for applying and implementing the regulation at national level. Each Member State must designate at least one market surveillance authority and a notifying authority. Multiple authorities may be designated for different sectors (for example, a financial supervisor and a data protection authority may each have AI Act competence in their respective domains).

Notified Body (Article 3(22))

A conformity assessment body officially designated by a Member State and notified to the European Commission as competent to carry out third-party conformity assessments of high-risk AI systems where self-assessment is not sufficient. Must be accredited for independence, technical competence, and impartiality. Notified bodies issue conformity certificates and are listed in the NANDO database. As of mid-2026, the number of designated notified bodies for the AI Act remains limited.

O

Operator (Article 3(8))

A collective term used in the regulation to refer to providers, product manufacturers, authorised representatives, importers, distributors, and deployers; all actors in the AI value chain who carry obligations under the regulation.

P

Personal Non-Professional Activity

An exemption category under Article 2(2). AI systems used by natural persons exclusively in the course of personal non-professional activity are outside the regulation's scope. This includes personal use of consumer AI tools; a household using a smart home device, for example. The exemption does not apply to professional or commercial deployment, regardless of scale.

Post-Market Monitoring (Article 72)

The ongoing, systematic process by which providers of high-risk AI systems collect, document, and analyse data on system performance after deployment. Must cover real-world performance against intended purpose, new risks arising from use, and data that enables deployers to carry out their own operational monitoring. Providers must prepare and document a post-market monitoring plan before placing the system on the market.

Presumption of Conformity (Article 42)

A legal mechanism under which compliance with a harmonised standard or other approved specification creates a presumption that the corresponding requirements of the regulation are met. Reduces the burden of proof in enforcement proceedings. Available to high-risk AI system providers who comply with relevant harmonised standards (when published), and to GPAI model providers who comply with the GPAI Code of Practice.

Provider (Article 3(3))

Any natural or legal person, public authority, agency, or other body that develops an AI system or GPAI model (or has one developed) and places it on the market or puts it into service under its own name or trademark.

Providers of high-risk AI systems carry the heaviest obligations under the regulation, including the quality management system, technical documentation, conformity assessment, CE marking, EU database registration, and post-market monitoring plan.

Putting into Service (Article 3(11))

The first use of a high-risk AI system by a deployer or by the provider themselves for their own purposes. Distinct from placing on the market, which describes the first commercial transaction.

Both placing on the market and putting into service trigger the provider's obligations. An organisation that builds and deploys an AI system for internal use only is both placing into service and deploying.

Q

Quality Management System (QMS) (Article 17)

A documented management framework that providers of high-risk AI systems must establish, implement, document, and maintain. The QMS must cover the system's development strategy, design and development processes, testing and validation procedures, data management practices, risk management procedures, post-market monitoring, incident management, and documentation handling. The requirements overlap substantially with ISO 9001 and ISO 42001.

R

Real-World Testing (Article 60)

Testing of AI systems under real-world conditions outside a regulatory sandbox, subject to specific conditions and safeguards. Providers may conduct real-world testing to gather data relevant to conformity assessment provided they register the testing, obtain informed consent from affected persons where required, and comply with applicable data protection law.

Reasonably Foreseeable Misuse (Article 9(2))

Use of an AI system in a way not intended by the provider but which can reasonably be expected to occur. Providers must include reasonably foreseeable misuse scenarios in their risk assessment under Article 9, identify associated risks, and adopt appropriate mitigation measures. This extends the compliance obligation beyond strictly intended use cases.

Recall (Article 3(16))

A measure requiring the return of a high-risk AI system to its provider, or the taking out of service or disabling of the system, typically ordered by a market surveillance authority when the system poses an unacceptable risk. Equivalent to a product recall in product safety regulation.

Remote Biometric Identification (Article 3(42))

The automated identification of natural persons at a distance by comparing their biometric data against a reference database, without the persons being aware that they are being identified. Real-time remote biometric identification in publicly accessible spaces is prohibited under Article 5(1)(h), except for narrowly defined law enforcement purposes subject to judicial or administrative authorisation.

Risk Management System (Article 9)

A continuous, iterative process established and maintained by providers of high-risk AI systems throughout the system's lifecycle. Must identify and analyse all known and reasonably foreseeable risks, estimate and evaluate those risks under normal and foreseeable misuse conditions, adopt appropriate risk management measures, and review residual risks. Article 9(7) extends the obligation to post-deployment, requiring continuous monitoring for new risks emerging from real-world use.

Robustness (Article 15)

The ability of a high-risk AI system to maintain its level of performance under adversarial conditions, including attempts to manipulate inputs to cause incorrect outputs, technical faults, and variations in the operating environment. Providers must ensure systems include appropriate technical measures to address robustness, including backup plans and fail-safes for critical applications.

S

Self-Assessment

The conformity assessment procedure carried out by the provider without the involvement of a third-party notified body. Permitted for most high-risk AI systems under Annex III. Requires the provider to document evidence of compliance against each applicable requirement and draw up a declaration of conformity. For AI used in biometric identification by law enforcement, and for some Annex I product safety systems, third-party assessment is required.

Serious Incident (Article 3(49))

Any incident or malfunction of a high-risk AI system that directly or indirectly results in the death of a person, serious damage to health, a serious and irreversible disruption of critical infrastructure, violation of fundamental rights obligations under EU law, or serious damage to property or the environment. Must be reported to the market surveillance authority within 15 working days of the provider or deployer becoming aware. Immediate risk to health and safety triggers a two-working-day notification deadline.

Shadow AI

Not a defined regulatory term, but used in practice to describe AI tools or systems deployed by individuals or teams within an organisation without the knowledge or oversight of IT, legal, or compliance functions.

Shadow AI creates compliance exposure because the organisation is operating (potentially high-risk) AI systems without the required governance, classification, logging, or oversight in place. Market surveillance authorities will not accept ignorance as a defence.

Social Scoring (Article 5(1)(c))

The evaluation or classification of natural persons or groups based on their social behaviour or known, inferred, or predicted personal characteristics over a period of time, where the resulting score leads to detrimental or unfavourable treatment in contexts unrelated to the original scoring purpose. Prohibited for both public authorities and private actors under Article 5(1)(c). The prohibition applies to general-purpose social scoring; sector-specific scoring that does not carry over into unrelated life domains is typically outside scope.

Subliminal Technique (Article 5(1)(a))

A technique that operates below the threshold of a person's consciousness or perception and is designed to influence their behaviour in a way that subverts their rational decision-making. AI systems that deploy subliminal techniques to materially distort behaviour in a way that causes or is likely to cause harm are prohibited under Article 5(1)(a). This prohibition is in force since 2 February 2025.

Substantial Modification (Article 3(23))

A change to a high-risk AI system after it has been placed on the market or put into service that affects the system's compliance with the requirements of Chapter III, or alters its intended purpose in a way not foreseen in the original conformity assessment. A substantial modification restarts the conformity assessment process. Changes that do not affect compliance or intended purpose (routine bug fixes, security patches, minor UI updates) are generally not substantial modifications.

Systemic Risk (Article 3(65), Article 51)

A risk associated with the high-impact capabilities of a GPAI model that could cause significant negative effects at societal scale within the Union, including threats to critical infrastructure, democratic processes, or public safety. GPAI models trained with more than 10²⁵ FLOPs are presumed to present systemic risk. Additional obligations under Article 55 apply to their providers.

T

Technical Documentation (Article 11, Annex IV)

The comprehensive documentation that providers of high-risk AI systems must prepare before placing the system on the market or putting it into service. Must contain all information necessary to assess the system's compliance, including a system description, intended purpose, risk management documentation, training data description, performance metrics, and instructions for use. Must be kept updated throughout the system's lifetime and retained for at least ten years.

Testing Data (Article 10)

The portion of a dataset used to evaluate the final performance of a trained AI model before deployment, on data the model has not previously seen. Distinct from training data (used to train the model) and validation data (used to tune hyperparameters during training). The regulation requires testing data to be appropriate, representative of the intended deployment environment, and free from known errors insofar as possible.

Training Data (Article 3(27))

Data used for training an AI system by fitting its learnable parameters. Under Article 10, training data for high-risk AI systems must be subject to appropriate data governance practices, be relevant and representative of the deployment population, be as free of errors as reasonably possible, and be examined for potential biases that could produce discriminatory outcomes.

Transparency (Article 13, Article 50)

Two distinct obligations in the regulation. Article 13 concerns transparency between providers and deployers: providers must supply instructions for use that enable deployers to understand and operate the system appropriately. Article 50 concerns transparency towards end users: deployers of chatbots must inform users they are interacting with an AI system, and providers of AI-generated content must ensure outputs are machine-detectable and appropriately disclosed.

U

Unacceptable Risk

The informal description for AI practices that are prohibited outright under Article 5. These are practices where the potential harm to fundamental rights, democratic values, or human dignity is so severe that no commercial, safety, or public interest justification can outweigh it. The eight prohibited categories have been enforceable since 2 February 2025.

V

Validation Data (Article 3(29))

Data used to evaluate a trained AI model during the development process, typically to select between model variants, tune hyperparameters, or make early-stopping decisions. Distinct from training data and testing data. Under Article 10, validation data must meet the same quality and representativeness requirements as training and testing data.

Vulnerability Exploitation (Article 5(1)(b))

The use of an AI system to exploit the specific vulnerabilities of a person or group, arising from their age, disability, or socioeconomic situation, in a way that distorts their behaviour and causes or is likely to cause significant harm. Prohibited under Article 5(1)(b) since 2 February 2025. Distinct from the general subliminal manipulation prohibition in that it targets deliberate targeting of identifiable vulnerable characteristics rather than below-consciousness techniques.

W

Watermarking (Article 50)

The technical process of embedding signals or markers into AI-generated content that allow it to be identified as artificially generated. Under Article 50, providers of AI systems generating synthetic audio, image, video, or text content must ensure outputs include machine-detectable markers. The Digital Omnibus provisional agreement defers the technical watermarking obligation to 2 December 2026 to allow a six-month adaptation period.

Withdrawal (Article 3(17))

A measure aimed at preventing an AI system from being made available on the market, typically ordered by a market surveillance authority when the system does not comply with regulatory requirements. Withdrawal is prospective: it prevents further distribution. Recall is retrospective: it requires the return or disabling of systems already in use.

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one