Learn / Category
Learn
AI governance
20 topics in this category.
Guides
1 guide
- How to use LLMs securely in regulated industries
To use an LLM securely in a regulated industry, treat the provider like any outside service that handles regulated data. Four questions about each use, not the brand of model, decide the controls.
Definitions, A to Z
19 definitions
- AI Office
The European Commission function that helps implement and supervise the EU AI Act, enforcing the rules for general-purpose AI models and, since the Digital Omnibus on AI, supervising some AI systems' providers directly.
- AI risk management
The NIST framework for identifying, assessing and treating the risks of AI systems, organised around four functions and seven trustworthiness characteristics.
- AI system impact assessment
A documented study of how an AI system and its foreseeable uses could affect individuals and societies, the subject of ISO/IEC 42005:2025 and required in its own form for Canadian federal automated systems that make or support administrative decisions about clients.
- Automation bias
The tendency to accept an automated system's output instead of checking for yourself, first studied in aviation and now named in the EU AI Act's human oversight rules.
- Conformity assessment
The EU AI Act check that a high-risk AI system meets the Act's requirements before it reaches the market, run by the provider itself, by a notified body, or under the procedure of a product law.
- Cyber Resilience Act
The EU regulation that sets cybersecurity requirements for connected hardware and software products, and makes their manufacturers fix vulnerabilities and report actively exploited ones.
- Datasheets for datasets
A document that travels with a machine learning dataset and answers a fixed set of questions about how it was built and what it may be used for.
- Digital Omnibus on AI
Regulation (EU) 2026/1744, the 2026 EU law that amends the AI Act, delaying its high-risk rules, adding two bans, and changing how notified bodies and the AI Office work.
- Digital Services Act
Regulation (EU) 2022/2065, the EU law on online intermediaries, which puts its heaviest duties, yearly assessment and mitigation of systemic risks, such as the spread of illegal content, and an independent audit, on the very large online platforms and search engines the European Commission designates.
- EU AI Act
The European Union regulation that sets binding rules for AI systems and general-purpose AI models, scaled to the use an AI system is put to.
- EU AI Act Article 15
The EU AI Act's requirement that high-risk AI systems be accurate, robust and secure, including against named attacks such as data poisoning.
- EU AI Act Article 6
The EU AI Act rule that decides which AI systems count as high-risk, through the Annex I product route or the Annex III use-case route.
- Fundamental rights impact assessment
The assessment EU AI Act Article 27 requires from public bodies, private entities providing public services, and deployers scoring people's credit or pricing their life and health insurance, before they first use a high-risk AI system listed in Annex III.
- General-purpose AI model
The EU AI Act's legal term for an AI model general enough to perform a wide range of distinct tasks and to be built into many downstream systems, with its own set of provider duties.
- Human oversight
The EU AI Act's Article 14 requirement that people can understand, override and stop a high-risk AI system while it is in use, and the older principle of the same name.
- ISO/IEC 42001
The international standard, published in December 2023, for an AI management system, the policies and processes an organisation uses to govern how it develops, provides or uses AI. Organisations can be audited and certified against it.
- Model card
A short document published with a trained model stating its intended use, how it was evaluated and where it fails.
- Notified body
An independent conformity assessment body that an EU Member State has approved and notified to the Commission, which checks certain high-risk AI systems against the EU AI Act before they reach the market.
- Zero data retention
An arrangement with an LLM provider under which it does not store prompts or outputs after returning the response, subject to exceptions each provider documents.