AI Governance Glossary
The vocabulary of AI governance, defined precisely. Terms are used consistently across every article on this site in the senses given here.
- AI Human Proof
An AI system, and the organisation operating it, that has implemented the full set of governance controls required to deploy AI responsibly: pre-deployment risk assessment, named operational accountability, continuous performance measurement, and tested incident response. "Human Proof" means proof by humans — verification, by people, that a system's behaviour is understood, monitored and controllable.
Read more →- Algorithmic accountability
The principle that a specific, identifiable person or body is answerable for the decisions an automated system produces — including the obligation to explain those decisions and the authority to suspend the system. Accountability that rests with a committee or a policy document rather than a named individual is not operational accountability.
- Automation bias
The documented human tendency to over-trust automated output, accepting a system's recommendation without independent scrutiny. It is the principal failure mode of human-in-the-loop designs: a reviewer who approves 99% of recommendations is providing the appearance of oversight, not oversight.
Read more →- Conformity assessment
Under the EU AI Act, the procedure by which a provider demonstrates that a high-risk AI system meets the regulation's requirements before it is placed on the market. Depending on the system category this is either an internal control procedure or an assessment involving a notified body.
Read more →- Deployer
In EU AI Act terminology, the natural or legal person using an AI system under its own authority — distinct from the provider, who develops or places the system on the market. Deployers carry their own obligations, including human oversight, input data relevance and monitoring. Most organisations buying commercial AI are deployers, not providers.
Read more →- GPAI (general-purpose AI model)
An AI model displaying significant generality, capable of competently performing a wide range of distinct tasks, that can be integrated into a variety of downstream systems. Under the EU AI Act, GPAI providers carry transparency, documentation and copyright-policy obligations that have applied since 2 August 2025.
Read more →- High-risk AI system
Under the EU AI Act, an AI system either used as a safety component of a regulated product (Annex I) or falling within the listed use cases in Annex III — including employment, education, credit scoring, essential services, biometrics, law enforcement and migration. High-risk status triggers the Act's most substantial obligations.
Read more →- Human-in-the-loop (HITL)
A design in which a human reviews, approves or can override an AI system's output before it takes effect. Genuine HITL requires that the reviewer has the information, time, authority and incentive to disagree — otherwise the loop is decorative.
Read more →- Model card
A structured document describing an AI model's intended use, training data characteristics, evaluation results, limitations and known failure modes. Model cards are a transparency artefact produced by model developers; a System Card, by contrast, documents a specific deployment.
- NIST AI RMF
The US National Institute of Standards and Technology AI Risk Management Framework (NIST AI 100-1), a voluntary, sector-agnostic framework organised around four functions — GOVERN, MAP, MEASURE and MANAGE. It defines a risk management process rather than a fixed control set.
Read more →- Proxy variable
An input feature that correlates with a protected characteristic without naming it — postcode standing in for ethnicity, or a university name for socioeconomic background. Removing protected attributes from training data does not remove their influence when proxies remain.
Read more →- System Card
A deployment-level record of a specific AI system in a specific organisation: its purpose, the populations it affects, its risk tier, its evaluation cadence, its escalation path and the named individual accountable for it. Where a model card documents a model, a System Card documents a deployment.
Read more →