EU AI Act glossary — 46 terms, Hungarian & EU legal status
The core terms of Regulation (EU) 2024/1689 in one place, with article citations and links to related knowledge-base questions. Every definition is derived from primary legal sources — where a term is not separately defined in the Regulation, or the law is uncertain, this is flagged explicitly.
Foundational concepts
- AI system An AI system is a machine-based system that operates with varying levels of autonomy and, from the input it receives, infers how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. The decisive test is inferential capability — a deterministic, human-authored rule set is not an AI system merely because it automates a task.
- AI literacy AI literacy means the skills, knowledge and understanding that allow a person to make an informed use of AI systems and to be aware of AI's opportunities, risks and possible harm. Under Article 4, providers and deployers must take measures to support the AI literacy of their staff — regardless of the risk category involved.
- Intended purpose The intended purpose is the use for which the provider intends an AI system, including the specific context and conditions of use, as specified in the instructions for use, promotional or sales materials, and the technical documentation. Classification — including the high-risk determination — attaches to the intended purpose, not to the underlying technology.
- Reasonably foreseeable misuse Reasonably foreseeable misuse means the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems. Providers must account for this in risk management and design, not only for the intended use.
Actors in the supply chain
- Provider A provider is a natural or legal person that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Providers bear the Regulation's most extensive package of obligations: risk management, data governance, documentation, conformity assessment, CE marking.
- Deployer A deployer is a person that uses an AI system under its own authority in the course of a professional activity — unless the system is used in the course of a purely personal, non-professional activity. Mere use, however intensive, does not make a company a provider; deployers are subject to the far narrower Article 26.
- Importer An importer is a person established in the Union that places on the market an AI system that bears the name or trademark of a third-country provider. Before placing it on the market, the importer must verify that the provider has carried out the conformity assessment and prepared the required documentation.
- Distributor A distributor is any actor in the supply chain, other than the provider or importer, that makes an AI system available on the Union market without affecting its properties. Distributors carry a narrower, but not negligible, verification duty before and during distribution.
- Authorised representative An authorised representative is a person established in the Union and mandated in writing by a third-country provider to act on the provider's behalf towards Union authorities. A non-EU provider typically must appoint such a representative — as a condition of entering the Union market — before placing its system on the market.
AI models
- General-purpose AI (GPAI) A general-purpose AI model (GPAI) is a model that displays significant generality, is capable of competently performing a wide range of distinct tasks, and can be integrated into a variety of downstream systems. The model itself is a component: it becomes an AI system once combined with a user interface. GPAI models are governed by Articles 51–56; systems built on top of them by Article 50.
- Foundation model "Foundation model" is a term widely used in industry and literature, but it is not separately defined in the text of the AI Act. The Regulation's official concept instead is the "general-purpose AI model" (GPAI model), defined in Article 3(63). The two terms are largely used as synonyms in practice, but for legal citation purposes, GPAI model is the precise concept.
- GPAI model with systemic risk A GPAI model with systemic risk is a general-purpose AI model that may have a significant impact on public health, safety, public security or fundamental rights, due to its scale. This is presumed where the cumulative computation used for its training exceeds 10^25 floating point operations; in that case the provider is subject to the four additional obligations of Article 55.
Risk categories
- High-risk AI system An AI system is high-risk if it is a safety component of, or is itself, a product covered by the Union product-safety legislation listed in Annex I, or if it falls within one of the eight areas and listed use cases of Annex III. Classification attaches to the intended purpose, not to the underlying technology.
- Prohibited AI practice Article 5(1) prohibits eight AI practices outright: subliminal or deceptive manipulation, exploitation of vulnerabilities, social scoring, predicting criminal offending from profiling alone, untargeted scraping of facial images, emotion recognition in the workplace and education, biometric categorisation to infer protected characteristics, and real-time remote biometric identification in public spaces. There is no compliance pathway for these.
- Critical infrastructure Critical infrastructure is one of the eight high-risk areas listed in Annex III: an AI system used as a safety component in the management and operation of critical digital infrastructure, road traffic, or the supply of water, gas, heating or electricity is classified as high-risk. In these sectors, disruption can directly endanger human life or health.
Prohibited and restricted practices
- Deepfake A deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places or events and would falsely appear to a person to be authentic or truthful. A deployer that publishes such content must disclose its artificial origin in a manner that is perceptible to humans.
- Real-time remote biometric identification Real-time remote biometric identification in publicly accessible spaces for law enforcement purposes is, as a general rule, prohibited. It may exceptionally be permitted for three exhaustively listed purposes — such as averting a terrorist threat — but only where the Member State has enacted enabling national legislation and prior judicial or independent administrative authorisation has been obtained for each individual use.
- Biometric categorisation A biometric categorisation system that individually categorises natural persons based on their biometric data in order to infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation is prohibited. The prohibition targets inference of protected characteristics.
- Emotion recognition Inferring emotions or intentions from biometric data is prohibited in the workplace and in educational institutions, except for medical or safety purposes — the concept of "workplace" extends to the recruitment process and the probationary period. In other contexts an emotion-recognition system is not prohibited, but under Article 50(3) the deployer must inform the individuals concerned about how the system operates.
- Social scoring An AI system that evaluates or classifies natural persons based on their social behaviour or known, inferred or predicted personal characteristics, leading to detrimental treatment that is unrelated to the context or disproportionate, is prohibited. The prohibition applies regardless of whether the system or the score is provided or used by a public or private actor.
Market process and conformity
- Placing on the market Placing on the market means the first making available of an AI system or a general-purpose AI model on the Union market. Making available on the market is a broader concept, denoting repeated, ongoing commercial activity, whereas placing on the market marks that first act, to which numerous obligations — CE marking, conformity assessment — attach.
- Putting into service Putting into service means the first supply of an AI system, in accordance with its intended purpose, directly to the deployer, or for own use, in the Union. This concept captures in-house developed systems used solely within the developing company that never enter commercial circulation.
- Substantial modification A substantial modification is a change to an AI system after it has been placed on the market or put into service, which is not foreseen or planned in the initial conformity assessment, and which affects compliance with the high-risk requirements or modifies the intended purpose for which it was assessed. Anyone who makes a substantial modification to a system already on the market becomes a provider under Article 25.
- Conformity assessment Conformity assessment is the procedure by which a provider demonstrates that a high-risk AI system meets the requirements laid down in Section 2 of Chapter III of the Regulation — risk management, data governance, documentation, human oversight, and the rest. For systems falling under points 2–8 of Annex III, internal control suffices; involvement of a notified body is typically mandatory only for biometric systems.
- CE marking The CE marking is the high-risk AI system provider's declaration that the system complies with the Regulation's requirements. It must be affixed, after the conformity assessment procedure is completed, visibly, legibly and indelibly to the system or its packaging, or — where this is not possible — to the accompanying documentation.
- EU declaration of conformity The EU declaration of conformity is the provider's written statement that a high-risk AI system meets the applicable requirements of the Regulation. It must be drawn up per system, made available to the market surveillance authority, and kept for at least ten years after the system is withdrawn from the market.
- Notified body A notified body is an independent third party designated by a Member State to take part in the conformity assessment of certain high-risk AI systems. For systems falling under points 2–8 of Annex III — HR, education, creditworthiness assessment, essential services — internal control always suffices; a notified body is practically relevant only for biometric systems, and even there it is mandatory only in the absence of a harmonised standard.
- Harmonised standard A harmonised standard is a technical standard developed on the basis of a Union standardisation request, whose application creates a presumption of conformity: a provider that follows it is presumed to meet the corresponding requirement. As of mid-2026, harmonised standards covering the AI Act's high-risk requirements had not yet been finalised, so the presumption of conformity is not currently available.
Obligations
- Human oversight Under Article 14, human oversight does not require a human to be in the loop, but requires that a high-risk AI system be designed to enable genuine oversight. The person exercising oversight must understand the system's limitations, be aware of automation bias, and have a real right to override, disregard the output of, or halt the system.
- Transparency obligation (Article 50) Article 50 lays down four separate transparency obligations, regardless of risk category: the provider must disclose when a user is interacting with AI and must mark generated content in a machine-readable format; the deployer must inform individuals about emotion recognition and must disclose the artificial origin of deepfake content. All four have applied since 2 August 2026.
- Risk management system The risk management system is a continuous, documented, testing-based process spanning the entire lifecycle of a high-risk AI system, which identifies, evaluates and mitigates the risks the system poses to the health, safety and fundamental rights of third persons. It does not manage organisational risk — it protects a different interest than ISO 31000 or ISO/IEC 42001, and neither creates a presumption of conformity, since neither is a harmonised standard.
- Data governance Data governance covers eight practices applicable to the training, validation and testing data sets of a high-risk AI system, and the substantive standard that data sets be relevant, sufficiently representative, and, to the best extent possible, free of errors and complete. The legislator does not demand flawless data sets, but documented diligence proportionate to the intended purpose.
- Logging Logging is the automatic recording of events during the operation of a high-risk AI system, enabling traceability and regulatory oversight. Providers must design the system to have logging capabilities, while deployers are subject to a duty to retain the resulting logs for at least six months.
- Technical documentation Technical documentation is the record demonstrating a high-risk AI system's compliance, covering the nine points of Annex IV, which must be drawn up before placing on the market, kept up to date, and retained for ten years. It is the record from which a regulator can later reconstruct how the system and its classification decision came about.
- Fundamental Rights Impact Assessment (FRIA) The Fundamental Rights Impact Assessment (FRIA) is an obligation applying to a narrow set of actors — bodies governed by public law, private entities providing public services, and deployers of creditworthiness-assessment or insurance risk-assessment systems — that requires assessing a high-risk AI system's impact on fundamental rights before it is put into use. An average private company's HR use of AI does not fall within this category.
- Data Protection Impact Assessment (DPIA) The Data Protection Impact Assessment (DPIA) is a separate legal instrument under the GDPR — not the AI Act — which the data controller must carry out where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons. Many AI-based HR or credit-assessment solutions are typically subject to a DPIA, even where the AI Act's FRIA does not apply to the actor in question.
Oversight, legal status and transition
- Market surveillance authority The market surveillance authority is the Member State body responsible for enforcing the AI Act and acting on infringements of the Regulation. In Hungary this role belongs to the Minister for Economy and Energy, who also serves as the single point of contact; for high-risk systems in the financial sector, the Hungarian National Bank (MNB) acts instead. NAIH remains competent under the GDPR, not the AI Act.
- AI Office The AI Office is a Commission body responsible exclusively for the direct supervision, at Union level, of providers of general-purpose AI (GPAI) models. An average Hungarian company should approach the national market surveillance authority, not the AI Office — the AI Office does not act in individual company matters.
- Regulatory sandbox A regulatory sandbox is a controlled framework, established by a Member State authority, within which AI systems can be developed, tested and validated for a limited time, under regulatory supervision, before being placed on the market. The original deadline for establishing sandboxes was postponed by the Digital Omnibus to 2 August 2027.
- Penalty / fine The AI Act recognises three penalty tiers: EUR 35 million or 7% of total worldwide annual turnover for prohibited practices, EUR 15 million or 3% for infringements of provider, deployer and transparency obligations, and EUR 7.5 million or 1% for misleading the authority. The higher figure always applies — except for SMEs and startups, where the lower figure applies.
- Digital Omnibus on AI The Digital Omnibus on AI — (EU) 2026/1744 — is a simplification regulation amending the AI Act, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. The grace periods it introduced — such as the delay to the high-risk block and regulatory sandboxes, and the softening of Article 4 — are current law, not a proposal.
- Grandfathering Grandfathering refers to the rule under which the Regulation applies to AI systems already placed on the market before the application date of the high-risk block only if they undergo a substantial modification affecting their design. This protection does not extend to prohibited practices — the prohibition applies to those immediately, with no grace period.
- SME facilitation The most concretely documented SME facilitation measure in the Regulation is the fine-calculation method: for SMEs and startups, the lower — rather than the higher — of the fixed euro amount and the turnover percentage applies when calculating fines, in contrast to the general rule for large enterprises. The Regulation also contains other SME-oriented provisions, though the knowledge base does not provide a specific article reference for those.
- Code of Practice A code of practice — within the AI Act framework, best known in the form of the GPAI Code of Practice — is a legally non-binding soft-law document that serves as a voluntary means of demonstrating compliance pending the emergence of a harmonised standard. Signing it makes it easier for a provider to prove compliance, but non-signature is not, by itself, an infringement, provided the provider can present alternative, equivalent proof.
- Scope exclusion Article 2 excludes the AI Act's application in several distinct cases: systems developed and used exclusively for military, defence or national security purposes; systems developed and put into service exclusively for scientific research and development; research and testing activity prior to placing on the market; and a natural person's purely personal, non-professional use. Each exclusion must be interpreted narrowly and by reference to its specific purpose.
- Open-source exemption Article 2(12) exempts AI systems released under a free and open-source licence from the AI Act, but carves that exemption back for systems placed on the market as high-risk, and for those covered by Articles 5 and 50. For GPAI models, Article 53(2) grants a narrower exemption, covering only certain obligations — and even this exemption falls away where systemic risk is present.
Need documented AI-literacy training?
AI Work Fluency provides Article 4 AI-literacy training and the supporting documentation for EU SMEs, in five-minute modules.
Start the AI Act checkThis page is general information, not legal advice. It does not substitute for a legal assessment of a specific case and does not create a retainer or attorney-client relationship. The legal status was verified on 4 August 2026 against primary sources; where the law or regulatory practice is uncertain, this is flagged separately.