Glossary
EU AI Act and AI agent assurance: the terms, defined
Forty-three terms a risk, compliance or security officer meets in the EU AI Act, in DORA and in an AI agent evidence pack, each defined in one paragraph from the regulation text or in the sense Vidimus gives it.
- Adversarial testing
- Testing that tries to make the agent fail rather than confirm that it works: insisting it is human, building rapport over several turns before asking it to break a rule, pushing a payment above a threshold. A checklist trusts your answers; an adversarial test catches the agent that says it escalates and does not.
- AI agent
- An AI system that acts, not only answers: it pursues a goal over several steps, calls tools and services (search, payments, records, messaging) and decides what to do next from what it observes. The AI Act does not use the word; an agent is an AI system, classified by its use like any other, and its tool calls are where the risk sits.
- AI literacy
- The duty on providers and deployers, since 2 February 2025, to take measures so that the people operating and using AI systems on their behalf have a sufficient level of understanding, taking their technical knowledge, the context and the people affected into account. The Digital Omnibus made it an obligation of means.
- AI Office
- The Commission’s function for implementing the Act at Union level: it supervises general-purpose AI models, coordinates the national authorities, and issues guidelines and codes of practice, such as the Article 50 Guidelines of 20 July 2026 and the Code of Practice on AI-Generated Content of 10 June 2026.
- AI system
- A machine-based system designed to operate with some autonomy, that may adapt after deployment, and that infers from its inputs how to produce outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments. The definition is about what the system does, not how it is built.
- Annex I
- The list of Union product legislation (machinery, medical devices, vehicles, lifts and the rest) whose products become high-risk AI systems when AI is their safety component. Their AI Act duties apply from 2 August 2028 and travel with the product’s own conformity assessment.
- Annex III
- The list of high-risk use cases: biometrics, critical infrastructure, education and vocational training, employment, access to essential private and public services (including creditworthiness and life or health insurance pricing), law enforcement, migration and border control, and the administration of justice and democratic processes.
- Annex IV
- The technical documentation a provider of a high-risk system must draw up under Article 11: a description of the system, its development and design, its monitoring and control, its performance, its risk management system, changes over its lifetime, standards applied, and the declaration of conformity. An evidence pack is shaped to it.
- Article 50 transparency duties
- The duties, in force since 2 August 2026, that people be told they are interacting with an AI system, that AI-generated content be marked in a machine-readable way, that people exposed to emotion recognition or biometric categorisation be informed, that deep fakes and AI-written public-interest text be disclosed, and that the information be clear and given at the first interaction.
- Audit trail
- The record of who did what, when and why: approvals, overrides, exports and decisions, each entry chained to the previous one and never edited or deleted, so that a reviewer can reconstruct how a conclusion was reached.
- Classification record
- A separate immutable document that states the legal classification of an agent: operator role, Article 5 screening, Article 50 transparency duties and, where relevant, the Article 6(3) derogation, with its own content hash on the first page.
- Conformity assessment
- The process of demonstrating that a high-risk AI system meets the Chapter III requirements, either by the provider’s internal control or by a notified body, depending on the use case. Vidimus does not perform conformity assessments; it produces the evidence a provider or deployer uses in its own.
- Corpus
- The set of obligations extracted from a regulation’s text, each with the verbatim passage it comes from, the party it binds and the way it is checked, by running the agent or by reading documents. One corpus per regulation, versioned, with the counts published on the methodology page.
- Critical or important function
- A function whose disruption would materially impair a financial entity’s financial performance, the soundness or continuity of its services, or its compliance with the conditions of its authorisation. Claims handling, KYC onboarding, underwriting and payments typically qualify; the entity makes and documents the determination.
- Deep fake
- AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. A deployer must disclose that the content has been artificially generated or manipulated (Article 50(4)).
- Deployer
- The person or organisation that uses an AI system under its own authority, except in a personal non-professional activity. A bank that puts a vendor’s chatbot in front of its customers is the deployer; it carries the use-side duties, including Article 50(3) and 50(4) and, from December 2027, Article 26.
- Digital Omnibus
- The regulation, in force since 27 July 2026, that amended the AI Act: it deferred the high-risk obligations for Annex III systems to 2 December 2027 and for Annex I systems to 2 August 2028, gave existing systems until 2 December 2026 for machine-readable marking, added two Article 5 prohibitions and reframed Article 4. It moved dates, not expectations.
- DORA
- The Digital Operational Resilience Act, in application since 17 January 2025 for banks, insurers, investment firms and the other financial entities it lists: ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. An AI agent in a critical or important function is ICT risk under it today.
- Evidence pack
- The versioned, signed document a review produces: classification, obligations with their quotes, every test with its answer and grade, the reviewer’s decision with reasons, and the audit trail. It cannot be edited; a re-issue is a new version, and anyone holding it can verify its hash and signature.
- Fundamental rights impact assessment (FRIA)
- The assessment some deployers of high-risk systems must complete before first use: bodies governed by public law, private entities providing public services, and deployers of creditworthiness, credit scoring and life or health insurance pricing systems. It describes the process, the period and frequency of use, the people affected, the risks of harm and the oversight and mitigation measures.
- General-purpose AI model
- An AI model trained on large amounts of data that displays significant generality and can perform a wide range of tasks, whatever the way it is placed on the market, and that can be integrated into many systems. Its provider carries the Chapter V duties, in force since 2 August 2025; the deployer of a system built on it relies on the provider’s documentation.
- Harmonised standard
- A European standard adopted at the Commission’s request and cited in the Official Journal; a high-risk system that conforms to it is presumed to conform to the requirements it covers. None has been cited for the AI Act yet, which is why no one can certify AI Act compliance today.
- High-risk AI system
- An AI system that is a safety component of a product covered by the Annex I legislation and subject to third-party conformity assessment, or that is used for one of the purposes listed in Annex III, unless the Article 6(3) derogation applies. High-risk systems carry the Chapter III requirements and obligations, from 2 December 2027 for Annex III and 2 August 2028 for Annex I.
- Human oversight
- The requirement that a high-risk system be designed so that natural persons can oversee it while it is in use: understand its capacities and limits, notice and address anomalies, decide not to use it, and intervene or stop it. For an agent, the test is whether the escalation it describes actually happens.
- ICT third-party service provider
- An undertaking providing ICT services to a financial entity. The model vendor behind an agent, its hosting provider and its observability tool are each one, and each belongs in the register of information; so does Vidimus, when a financial entity uses it.
- Judge model (grading model)
- The language model that grades each test against the expected behaviour. It sees the test, the expected behaviour, the agent’s answer and its tool calls, never the agent’s instructions or who built it; its model and prompt version are recorded on every verdict, and a human reviewer confirms the result.
- Machine-readable marking
- The mark a provider must put on synthetic audio, image, video or text so that it can be detected as artificially generated, through watermarks, metadata, cryptographic provenance or similar means, as far as technically feasible. For systems placed on the market before 2 August 2026, the grace period ends on 2 December 2026.
- Notified body
- A conformity assessment body designated by a Member State and notified to the Commission to carry out third-party conformity assessments under the Act. Vidimus is not one, and says so on every page that could be read otherwise.
- Operator
- The umbrella term for a provider, product manufacturer, deployer, authorised representative, importer or distributor. When a page asks for your "operator role", it asks which of these you are for the system in question, because the duties follow the role.
- Pattern bank
- The library of test designs the test plan draws from: how to ask, how to push, what counts as a pass. A pattern is written once and instantiated for each obligation it applies to, so the same pressure is applied the same way to every agent.
- Presumption of conformity
- The legal effect of following a harmonised standard or a common specification: the system is presumed to meet the requirement the standard covers, and the burden shifts to the authority to show otherwise. Without a cited standard there is no presumption, only evidence.
- Probe (test)
- One test: a message or event sent to your agent, the article it exercises, the behaviour expected, and the grade the answer received. "Test" and "probe" mean the same thing on this site; probe is the product’s own word.
- Prohibited practice
- One of the AI uses the Act bans outright, in force since 2 February 2025: manipulative or exploitative techniques that cause harm, social scoring, certain predictive policing, untargeted scraping of facial images, emotion recognition at work and in education, some biometric categorisation, and real-time remote biometric identification for law enforcement outside narrow exceptions. Two more apply from 2 December 2026.
- Provider
- The person or organisation that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. The provider carries the design-side duties, including Article 50(1) and 50(2).
- Record-keeping (logging)
- The automatic recording of events over the lifetime of a high-risk system, to a level that lets the system’s operation be traced, risks identified and post-market monitoring done. For an agent, the log that matters records what it did: which tools it called, with which inputs, and what came back.
- Red teaming
- A security exercise in which a team attacks a system as an adversary would, to find weaknesses before someone else does. Red-teaming platforms for AI find jailbreaks and data leaks; they do not map findings to the articles of a regulation, which is what a regulatory test plan adds.
- Register of information
- The register every financial entity keeps of its contractual arrangements with ICT third-party service providers, distinguishing those that support critical or important functions, with the fields the supervisor expects: provider identity and country, type of service, function supported, data location, contractual terms and exit provisions.
- Regulatory sandbox
- A controlled framework a national authority sets up so that providers can develop, train, validate and test an AI system under supervision before it is placed on the market. Member States must have at least one operational by 2 August 2027.
- Technical documentation
- The documentation a provider draws up before placing a high-risk system on the market and keeps up to date, containing at least the elements of Annex IV, so that authorities can assess compliance. It is documentation about the system; evidence is what shows the documentation is true.
- Threat-led penetration testing (TLPT)
- The advanced resilience test some financial entities must run at least every three years, on live production systems supporting critical or important functions, with qualified testers and a scope agreed with the supervisor. Testing an agent’s behaviour under adversarial prompts is a different exercise, and the two sit side by side.
- Tool call
- An action an agent takes through an interface rather than in words: issuing a payment, writing to a record, sending a message, calling a search. A test observes the calls on the wire, so an agent that says it escalated but never called the escalation tool is caught by the transcript.