AI regulatory glossary

What each term of the EU AI Act and the GDPR means, with the article that supports it and from when it applies.

What you find in each entry

What the term means, which article supports it and from when it applies.

Why a definition on its own is not enough

In Regulation (EU) 2024/1689 almost no term binds everyone in the same way. The same word changes consequence depending on who reads it — whoever builds the system or whoever deploys it in their organisation — and on when they read it, because the obligations did not all start to apply at once.

That is why each entry states the role and the date in words, inside the text. You will not see a loose label: a label is a status, and a status expires.

What sets an entry apart from a summary

Not everything that is recommended binds, and not everything worth doing is mandated by a rule. Each entry separates four things that are usually presented mixed together: what the articles impose and already applies; what they impose with a future date already set; what is only recommended by frameworks such as ISO 42001, NIST AI RMF or the guidance of ENISA, the OECD and the Spanish AI supervisory agency (AESIA) — which guide, but do not bind —; and what no rule mandates but is needed to be able to demonstrate what you did.

And it says so tied to whom and to when, inside the sentence and not in a label: the same obligation may fall on whoever builds the system and not on whoever deploys it in their organisation. The AI Act dates, one by one, are in the calendar.

How it is written

The definitions the Regulation lays down are quoted verbatim, with their article and point. The rest is explained in our own prose, with the article alongside so that anyone can go to the official text and check it.