trail is now part of
Read more

Responsible AI Glossary

Definitions of key responsible AI, AI governance, and EU AI Act terms. Search the glossary to find your concept.

Sort by
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

High-Risk AI System

EU AI Act classification (Annex III / Art. 6) triggering the strictest pre- and post-market obligations short of prohibition.

Further resources →

Prompt Injection

Risk that occurs when an adversary manipulates model behavior via crafted input that overrides intended instructions.

Compliance Management

Core AI governance function of ensuring AI systems and processes meet applicable legal, regulatory, and framework requirements on an ongoing basis – a key pillar of the AI governance operating model and a subset of GRC.

Further resources →

ISO/IEC 27001

International standard for information security management systems (ISMS); in AI governance it underpins the security of data and models and is often pursued alongside ISO/IEC 42001.

Real-Time Remote Biometric Identification

Live biometric identification in public spaces by law enforcement; heavily restricted under the EU AI Act.

Control

A policy, process, or technical safeguard put in place to manage a specific risk to an acceptable level; the basic building block of any GRC program.

Explainability / Explainable AI (XAI)

Techniques and practices that make an AI system's decisions understandable to humans.

Adversarial Robustness

A system's resilience to adversarial attacks or manipulated inputs.

AI Agent / Agentic AI

AI system that can autonomously plan, decide, and take actions (often by calling tools or other systems) to pursue goals with limited human intervention; its autonomy raises distinct responsible-AI challenges around oversight, accountability, traceability, and scope control.

Further resources →

Existential Risk (X-Risk)

Category of risk in the MIT AI Risk Repository referring to AI's potential to cause human extinction or permanent civilizational collapse.

Trustworthy AI

Describes AI usage, development, etc. that is valid, reliable, safe, secure, accountable, transparent, explainable, privacy-enhanced, and fair.

Further resources →

AI Regulatory Sandbox

Controlled environment allowing testing of innovative AI systems under regulatory supervision before market entry (EU AI Act Art. 57–63).

GPAI Model with Systemic Risk

GPAI model meeting a high-impact capability threshold, subject to additional EU AI Act obligations (Art. 51–55).

AI Policy

Formal internal document that sets the rules, principles, roles, and responsibilities for how an organization develops, procures, and uses AI — the practical formalization of an AI governance program that makes guidelines actionable for employees.

Further resources →

Model Risk Management (MRM)

Discipline (rooted in financial services, now applied to AI) governing model validation, monitoring, and controls.

Incident Response Plan

Predefined procedure for detecting, escalating, and remediating AI system failures or harms.

AI Governance Committee

Cross-functional body that steers an organization's AI governance program — bringing together stakeholders such as legal, security, data protection, risk, and technical teams to set direction, prioritize, and oversee decisions (broader in remit than an AI ethics board).

AI Safety

Field focused on preventing unintended, harmful, or catastrophic behavior from AI systems.

MLOps / ModelOps

Practices and tooling for operationalizing, deploying, and monitoring machine learning models at scale.

AI Governance Framework

Structured foundation of standards, requirements, and best practices an organization adopts and adapts to govern AI – often built on established frameworks (e.g., NIST AI RMF, ISO/IEC 42001) plus legal obligations and industry practices.

Further resources →

Watermarking

Embedding detectable markers in AI-generated content to indicate its synthetic origin.

Model Validation

Independent testing confirming a model performs as intended and within acceptable risk limits.

Model Denial of Service

Risk of resource-exhaustion attacks against a hosted model.

Sandbagging

AI safety concern where a model deliberately underperforms during evaluation to conceal true capabilities.

RACI / Roles & Responsibilities Matrix

Tool for assigning ownership and accountability across AI governance tasks (Responsible, Accountable, Consulted, Informed), clarifying who does what across the AI lifecycle and enabling governance as a joint, traceable effort.

Misinformation / Disinformation

Category in the MIT AI Risk Repository covering AI-generated false or misleading content, distinguishing unintentional (mis-) from intentional (dis-) spread.

Shadow AI

Unauthorized or unsanctioned use of AI tools within an organization, outside governance oversight.

Further resources →

Conformity Assessment

Process of verifying that a high-risk AI system meets applicable EU AI Act requirements before market placement.

Further resources →

Black Box (Model)

An AI model whose internal decision logic is not interpretable to users or auditors.

AI Management System (AIMS)

Formal system of policies and processes for governing AI per ISO/IEC 42001.

AI Actor

Any entity involved in an AI system's lifecycle: designer, developer, deployer, operator, evaluator (NIST AI RMF terminology).

Algorithmic Bias

Systematic and repeatable errors in a system that create unfair outcomes for particular groups.

Agent Registry

Specialized inventory of an organization's AI agents recording each agent's configuration, permissions, connected tools, and risk classification — extending the AI registry concept to autonomous systems that get deployed quickly and at scale.

Further resources →

Overreliance

Risk of users trusting AI outputs without sufficient verification or oversight.

AI Alignment

Ensuring an AI system's goals and behaviors match human intentions and values.

General-Purpose AI (GPAI) Model

EU AI Act category for models displaying significant generality and capable of competently performing a wide range of tasks.

AI Risk Management

The end-to-end discipline of identifying, assessing, treating, and monitoring risks arising from AI systems across their lifecycle — the practice that frameworks like NIST AI RMF and ISO 42001 structure and formalize.

Further resources →

Interpretability

Degree to which a human can understand the cause of a model's decision or prediction.

Deployer

EU AI Act term for an entity using an AI system under its authority, other than in personal non-professional use.

Sensitive Information Disclosure

Risk of models leaking confidential or personal data through outputs.

Control Assessment / Control Effectiveness

Evaluation of whether a control has been implemented and is actually working to mitigate the AI risk it targets; increasingly automated by analyzing connected sources and evidence to judge effectiveness.

Further resources →

Key Risk Indicator (KRI)

Metric used to signal increasing risk exposure ahead of an actual control failure.

Audit Trail

Tamper-evident, chronological record of the actions, decisions, and changes across an AI system's governance lifecycle (who did what, when), enabling accountability, review, and evidence for internal and external audits.

Algorithmic Auditing

Independent examination of an algorithm's design, data, and outputs for bias, safety, or compliance issues.

Scope Violation / Scope Management

Practice of defining, monitoring, and enforcing the boundaries of what an AI agent may do (the tools, data, and actions within its remit), and detecting scope violations where an agent exceeds those permissions.

Traceability

Ability to reconstruct and follow an AI system's decisions, data, and actions back to their sources — models, datasets, prompts, and human approvals — a prerequisite for accountability, debugging, and audits, and an especially acute challenge for autonomous agents.

Importer (EU AI Act)

Entity established in the EU that places on the market an AI system from a non-EU provider.

Membership Inference Attack

Attack determining whether a specific data record was used in a model's training set.

AI Incident

An event where an AI system causes or nearly causes harm, tracked in resources like the OECD AI Incidents Monitor and MIT AI Risk Repository.

AI Literacy

Skills, knowledge, and understanding enabling providers, deployers, and users to make informed decisions about AI (explicit EU AI Act obligation, Art. 4).

Further resources →

AI System Life Cycle

Stages from design and data collection through deployment, monitoring, and retirement (ISO 42001, NIST AI RMF).

AI Use Case Management

The ongoing practice of identifying, collecting, mapping, and governing an organization's AI use cases across their lifecycle — the foundation for inventory, risk classification, and EU AI Act compliance.

Further resources →

Stakeholder Mapping

Identifying and analyzing parties affected by or influencing an AI system's development and deployment.

Model Inversion Attack

Attack that reconstructs training data or sensitive attributes from a model's outputs.

Model Extraction / Theft / Model Stealing

Attack that reconstructs or steals a proprietary model's functionality or parameters via repeated queries against its API.

Responsible Scaling Policy (RSP)

Frontier AI lab commitment to gate model capability increases behind corresponding safety and security measures.

Privacy by Design

Principle of embedding privacy protections into system architecture from the outset rather than retrofitting.

Three Lines of Defense

GRC model separating operational management, risk/compliance oversight, and independent audit functions.

Risk

The effect of uncertainty on objectives, typically expressed as a function of likelihood and impact (ISO 31000 / ISO 42001 framing, adapted for AI harms).

Harmonised Standard

European standard, once adopted, that provides a presumption of conformity with EU AI Act requirements.

Data Lineage

Traceable record of data's origin, movement, and transformations through a system.

Copy-on-Write (Agent Governance)

Governance pattern where an AI agent's proposed changes are staged in a safe copy rather than written directly to live systems, so a human can review, edit, and approve them before they take effect — keeping humans in the loop without sacrificing automation.

Further resources →

Provider (EU AI Act)

Entity that develops an AI system/GPAI model and places it on the market under its own name.

Data Drift

Change in the statistical distribution of input data over time relative to training data, a common cause of model performance decay (distinct from concept drift, which is a change in input-output relationships).

Distributor (EU AI Act)

Entity in the supply chain, other than provider or importer, that makes an AI system available on the market.

Synthetic Data

Artificially generated data used to train or test models, often to preserve privacy or augment datasets.

Adversarial Example

Input deliberately crafted to cause a model to make a mistake (OWASP ML Top 10).

Differential Privacy

Mathematical technique that adds calibrated noise to protect individual privacy in datasets or outputs.

MCP Gateway

Control point that mediates and monitors the tools, data, and systems an AI agent can reach via the Model Context Protocol (MCP), enforcing permission boundaries and flagging out-of-scope actions before they occur.

Prompt Leaking

Attack that extracts a system's hidden prompt, instructions, or confidential context through crafted user input.

Emergent Capability

Ability that appears in a model unpredictably as scale increases, not present in smaller versions.

Guardrails

Technical or procedural controls constraining an AI system's outputs or actions within acceptable bounds.

Chief AI Officer (CAIO)

Emerging executive role responsible for enterprise AI strategy, ethics, and governance.

Substantial Modification

EU AI Act term for a change to an AI system significant enough to require reassessment of conformity.

Model Tampering

Unauthorized modification of a model's weights, architecture, or configuration after training, whether via supply chain compromise or insider action.

Serious Incident

EU AI Act–defined event (Art. 3(49)) involving death, serious harm, infrastructure disruption, or fundamental rights infringement linked to an AI system, triggering mandatory reporting.

Risk Register

Documented log of identified risks, owners, likelihood/impact ratings, and mitigation status.

Content Provenance

Metadata or cryptographic proof documenting the origin and history of AI-generated or edited content (e.g., C2PA).

Use Case Card

Standardized document capturing the key details of a specific AI use case (purpose, data, stakeholders, risks, controls) to support inventory, transparency, and governance – complementing model and system cards at the application level.

AI Act (EU AI Act)

Regulation (EU) 2024/1689 establishing harmonised rules on AI in the EU, using a risk-based, tiered approach.

Further resources →

AI Ethics Board / Committee

Internal governance body reviewing AI systems for ethical risk and compliance.

Residual Risk

Risk remaining after controls and mitigations have been applied.

Data Protection Impact Assessment (DPIA)

GDPR-mandated assessment of privacy risks for high-risk processing activities, often paired with AI risk assessments.

Biometric Categorization

Classifying individuals based on biometric data into categories such as race, gender, or political opinion; restricted under the EU AI Act.

Training Data Extraction

Attack that recovers verbatim or near-verbatim training examples (including sensitive data) directly from a model's outputs.

Insecure Output Handling

LLM risk from failing to validate/sanitize LLM outputs before downstream use.

Copyright / IP Infringement

Risk that an AI system reproduces or generates content that violates third-party copyright or intellectual-property rights, via training data or model outputs — a growing responsible-AI and legal concern.

Evasion Attack

Attack that crafts inputs at inference time to cause a deployed model to misclassify or malfunction, without altering the model itself.

AI Office

EU body responsible for AI Act implementation, particularly oversight of general-purpose AI models.

Third-Party Risk Management (TPRM)

Process of assessing and monitoring risks introduced by vendors, suppliers, or AI model providers.

Further resources →

Red Teaming

Adversarial testing exercise simulating attacks or misuse to uncover a system's vulnerabilities.

RoPA (Records of Processing Activities)

GDPR-mandated inventory documenting how personal data is processed (purposes, data categories, recipients, safeguards); in AI governance it complements the AI registry and DPIAs for data-driven systems.

Automated Decision-Making (ADM)

Decisions made by an AI system with little or no human involvement, often subject to explanation/opt-out rights (cf. GDPR Art. 22).

Mechanistic Interpretability

Research field aiming to reverse-engineer neural network internals into human-understandable algorithms.

Deepfake

Synthetic media generated or manipulated by AI that falsely depicts a real person's likeness or actions.

Meaningful Human Control

Standard requiring humans retain real, informed influence over an AI system's consequential decisions.

AI Security

The subset of AI risk management focused on protecting AI systems, models, and data from malicious attacks (e.g., data poisoning, model theft, adversarial manipulation) — distinct from AI safety's broader focus on unintended harm.

Risk Tolerance

Acceptable variation around risk appetite for specific objectives or risk types (NIST AI RMF term).

Data Poisoning

Attack that corrupts training data to manipulate model behavior (OWASP LLM/ML Top 10).

Evaluation (Model Eval)

Structured testing of a model's capabilities, safety properties, or risks against benchmarks.

Cookies
By clicking “Yes”, you agree to the storing of cookies on your device to enhance site navigation, and to improve our marketing. View our Privacy Policy for more information.
trailis now part of