What matters in AI.

Subscribe

Learn / Category

Learn

AI governance

20 topics in this category.

Guides

1 guide

  • How to use LLMs securely in regulated industries

    To use an LLM securely in a regulated industry, treat the provider like any outside service that handles regulated data. Four questions about each use, not the brand of model, decide the controls.

Definitions, A to Z

19 definitions

  • AI Office

    The European Commission function that helps implement and supervise the EU AI Act, enforcing the rules for general-purpose AI models and, since the Digital Omnibus on AI, supervising some AI systems' providers directly.

  • AI risk management

    The NIST framework for identifying, assessing and treating the risks of AI systems, organised around four functions and seven trustworthiness characteristics.

  • AI system impact assessment

    A documented study of how an AI system and its foreseeable uses could affect individuals and societies, the subject of ISO/IEC 42005:2025 and required in its own form for Canadian federal automated systems that make or support administrative decisions about clients.

  • Automation bias

    The tendency to accept an automated system's output instead of checking for yourself, first studied in aviation and now named in the EU AI Act's human oversight rules.

  • Conformity assessment

    The EU AI Act check that a high-risk AI system meets the Act's requirements before it reaches the market, run by the provider itself, by a notified body, or under the procedure of a product law.

  • Cyber Resilience Act

    The EU regulation that sets cybersecurity requirements for connected hardware and software products, and makes their manufacturers fix vulnerabilities and report actively exploited ones.

  • Datasheets for datasets

    A document that travels with a machine learning dataset and answers a fixed set of questions about how it was built and what it may be used for.

  • Digital Omnibus on AI

    Regulation (EU) 2026/1744, the 2026 EU law that amends the AI Act, delaying its high-risk rules, adding two bans, and changing how notified bodies and the AI Office work.

  • Digital Services Act

    Regulation (EU) 2022/2065, the EU law on online intermediaries, which puts its heaviest duties, yearly assessment and mitigation of systemic risks, such as the spread of illegal content, and an independent audit, on the very large online platforms and search engines the European Commission designates.

  • EU AI Act

    The European Union regulation that sets binding rules for AI systems and general-purpose AI models, scaled to the use an AI system is put to.

  • EU AI Act Article 15

    The EU AI Act's requirement that high-risk AI systems be accurate, robust and secure, including against named attacks such as data poisoning.

  • EU AI Act Article 6

    The EU AI Act rule that decides which AI systems count as high-risk, through the Annex I product route or the Annex III use-case route.

  • Fundamental rights impact assessment

    The assessment EU AI Act Article 27 requires from public bodies, private entities providing public services, and deployers scoring people's credit or pricing their life and health insurance, before they first use a high-risk AI system listed in Annex III.

  • General-purpose AI model

    The EU AI Act's legal term for an AI model general enough to perform a wide range of distinct tasks and to be built into many downstream systems, with its own set of provider duties.

  • Human oversight

    The EU AI Act's Article 14 requirement that people can understand, override and stop a high-risk AI system while it is in use, and the older principle of the same name.

  • ISO/IEC 42001

    The international standard, published in December 2023, for an AI management system, the policies and processes an organisation uses to govern how it develops, provides or uses AI. Organisations can be audited and certified against it.

  • Model card

    A short document published with a trained model stating its intended use, how it was evaluated and where it fails.

  • Notified body

    An independent conformity assessment body that an EU Member State has approved and notified to the Commission, which checks certain high-risk AI systems against the EU AI Act before they reach the market.

  • Zero data retention

    An arrangement with an LLM provider under which it does not store prompts or outputs after returning the response, subject to exceptions each provider documents.