Glossary
AI regulation glossary: EU AI Act vs. USA, Canada and China
Definitions of the key terms of the EU AI Act — AI system, risk categories, providers and deployers, high-risk obligations, technical documentation, general-purpose AI models and transparency — set against the AI rules of the United States, Canada and China, from the NIST AI Risk Management Framework and US state laws to Canada’s Directive on Automated Decision-Making and China’s generative AI, deep synthesis and labeling rules. Each entry explains how the approaches differ and what they mean for technical documentation.
Overview
EU AI Act: foundations
- Updated
EU AI Act
Regulation (EU) 2024/1689German: KI-Verordnung
The EU AI Act, Regulation (EU) 2024/1689, is the European Union’s horizontal law on artificial intelligence. It sets harmonized rules for placing AI systems and general-purpose AI models on the EU market and using them, graded by risk: some practices are prohibited, high-risk systems must meet requirements before market entry, and certain systems carry transparency obligations.
AI regulation · EU
Definition and examples - Updated
Digital Omnibus on AI
Regulation (EU) 2026/1744The Digital Omnibus on AI, Regulation (EU) 2026/1744, is the first amendment of the EU AI Act. Proposed by the European Commission in November 2025 and in force since July 27, 2026, it postpones the high-risk obligations to December 2, 2027 (Annex III) and August 2, 2028 (Annex I Section A), moves machinery to the sector route of Annex I Section B, adds new prohibited practices and simplifies obligations for smaller companies.
AI regulation · EU · Omnibus · Machinery
Definition and examples AI system (AI Act)
Art. 3(1) AI ActUnder the EU AI Act, an AI system is a machine-based system designed to operate with varying levels of autonomy, which may exhibit adaptiveness after deployment and which, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.
AI regulation · EU
Definition and examplesRisk-based approach (AI Act)
Arts. 5, 6, 50 and 51 AI ActThe risk-based approach of the EU AI Act assigns obligations according to the risk an AI system poses to health, safety and fundamental rights: unacceptable-risk practices are prohibited, high-risk systems must meet mandatory requirements, certain systems carry transparency obligations, and all other systems remain largely unregulated.
AI regulation · EU
Definition and examplesProhibited AI practices (AI Act)
Art. 5 AI ActProhibited AI practices are the uses of AI that the EU AI Act bans outright because they pose an unacceptable risk to fundamental rights — among them manipulative techniques, exploitation of vulnerabilities, social scoring, untargeted scraping of facial images and emotion recognition at work and in education. The prohibitions apply since February 2, 2025.
AI regulation · EU
Definition and examples- Updated
AI literacy (AI Act)
Art. 4 AI ActAI literacy is the skills, knowledge and understanding that allow providers, deployers and affected persons to use AI systems in an informed way and to understand their opportunities, risks and possible harm. Under the EU AI Act as amended by Regulation (EU) 2026/1744, providers and deployers must take measures to support the development of AI literacy among their staff and other persons operating or using AI systems on their behalf. They do not have to guarantee a specific level of AI literacy for each individual.
AI regulation · EU
Definition and examples
EU AI Act: roles
Provider (AI Act)
Art. 3(3) AI ActUnder the EU AI Act, a provider is a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.
AI regulation · EU
Definition and examplesDeployer (AI Act)
Art. 3(4) and Art. 26 AI ActUnder the EU AI Act, a deployer is a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the system is used in the course of a personal, non-professional activity.
AI regulation · EU
Definition and examples
EU AI Act: high-risk AI
High-risk AI system (AI Act)
Art. 6, Annexes I and III AI ActGerman: Hochrisiko-KI-System
Under the EU AI Act, a high-risk AI system is an AI system that is a safety component of, or itself, a product covered by the EU harmonization legislation listed in Annex I, or that is used in one of the sensitive areas listed in Annex III, such as employment, education, credit scoring or law enforcement. High-risk systems must meet mandatory requirements and pass a conformity assessment before they are placed on the market.
AI regulation · EU
Definition and examplesTechnical documentation (AI Act)
Art. 11 and Annex IV AI ActUnder the EU AI Act, technical documentation is the documentation a provider must draw up before a high-risk AI system is placed on the market, demonstrating that the system meets the requirements of the Act. It contains at least the elements of Annex IV and must be kept up to date and made available to national authorities and notified bodies.
AI regulation · EU · Technical documentation
Definition and examplesInstructions for use (AI Act)
Art. 13 AI ActUnder the EU AI Act, instructions for use are the information a provider must supply with a high-risk AI system so that deployers can interpret its output and use it appropriately. They must be concise, complete, correct and clear, and include the system’s intended purpose, accuracy, limitations, human oversight measures and maintenance.
AI regulation · EU · Technical documentation
Definition and examplesConformity assessment (AI Act)
Art. 43 AI ActUnder the EU AI Act, conformity assessment is the process of demonstrating that a high-risk AI system meets the requirements of the Act before it is placed on the market or put into service. Depending on the system, it is carried out by the provider through internal control or with a notified body, and it ends with an EU declaration of conformity and CE marking.
AI regulation · EU
Definition and examples- Working term
AI risk planning
Art. 9 AI ActGerman: KI-Risikomanagement
In AI governance, AI risk planning is the structured identification, evaluation, control, monitoring and documentation of risks arising from AI use. Under the EU AI Act, it takes the form of the risk management system that providers of high-risk AI systems must establish, document and maintain as a continuous, iterative process across the system’s lifecycle.
AI regulation · EU
Definition and examples Fundamental rights impact assessment (AI Act)
Art. 27 AI ActUnder the EU AI Act, a fundamental rights impact assessment (FRIA) is an assessment that certain deployers of high-risk AI systems must carry out before first use, describing how the system will be used, who may be affected, the specific risks of harm and the measures taken to mitigate them.
AI regulation · EU
Definition and examplesHuman oversight (AI Act)
Art. 14 AI ActGerman: Menschliche Aufsicht
Under the EU AI Act, human oversight is the requirement that a high-risk AI system be designed so that natural persons can effectively oversee it while it is in use. The people assigned to oversight must be able to understand its capacities and limitations, interpret its output, decide not to use it, override or reverse its output, and interrupt it.
AI regulation · EU
Definition and examples
EU AI Act: general-purpose AI and transparency
General-purpose AI model (AI Act)
Art. 3(63) and Arts. 51–55 AI ActUnder the EU AI Act, a general-purpose AI (GPAI) model is an AI model, including one trained with a large amount of data using self-supervision at scale, that displays significant generality, is capable of competently performing a wide range of distinct tasks and can be integrated into a variety of downstream systems or applications. Models used only for research, development or prototyping before being placed on the market are excluded.
AI regulation · EU · Technical documentation
Definition and examplesGPAI Code of Practice
Art. 56 AI ActThe General-Purpose AI Code of Practice is a voluntary code, published by the European Commission on July 10, 2025 and developed by independent experts with stakeholders, that helps providers of general-purpose AI models show compliance with their obligations under the EU AI Act in three chapters: transparency, copyright, and safety and security.
AI regulation · EU
Definition and examplesTransparency obligations (AI Act)
Art. 50 AI ActThe transparency obligations of the EU AI Act require that people are informed when they interact with an AI system, that synthetic audio, image, video and text content is marked in a machine-readable way as artificially generated, and that deepfakes and certain AI-generated texts are disclosed as such. They apply from August 2, 2026.
AI regulation · EU · Technical documentation
Definition and examples
EU AI Act: machinery and Annex I
- Working term
Machinery AI timeline: 2027 vs. 2028
Art. 8 and 20(10) Regulation (EU) 2023/1230; Annex I Section B AI ActThe machinery AI timeline describes when AI-related functions of machinery are assessed under EU law after the Digital Omnibus on AI: under the Machinery Regulation from January 20, 2027, with additional AI-specific requirements added to its Annex III by delegated acts that are to apply by August 2, 2028.
AI regulation · EU · Machinery · Omnibus
Definition and examples Annex I Section A and Section B (AI Act)
Art. 2(2), Art. 6(1), Annex I AI ActAnnex I of the EU AI Act lists the EU product legislation whose products can contain high-risk AI. For products under Section A, the AI Act's high-risk requirements apply directly; for products under Section B, they are brought in through amendments of the sector legislation. Since Regulation (EU) 2026/1744, machinery is listed in Section B.
AI regulation · EU · Machinery · Omnibus
Definition and examplesSafety component (AI Act)
Art. 3(14), Art. 6 AI ActUnder the EU AI Act as amended by Regulation (EU) 2026/1744, an AI system is a safety component of a product when its intended purpose is to prevent or mitigate risks to the health and safety of persons or property, or when its failure or malfunctioning would endanger health and safety. Mere integration into a regulated product is not enough.
AI regulation · EU · Machinery
Definition and examplesMachinery Regulation Article 8 delegated acts
Art. 8 Regulation (EU) 2023/1230, as amended by Regulation (EU) 2026/1744The Article 8 delegated acts are acts of the European Commission that amend Annex III of the Machinery Regulation to reflect AI-specific requirements of the AI Act — Chapter III Section 2 and Articles 17, 19, 72 and 73. According to Recital 42 of Regulation (EU) 2026/1744 they are to apply by August 2, 2028.
AI regulation · EU · Machinery · Omnibus
Definition and examplesTransitional presumption of conformity (Machinery Regulation Art. 20(10))
Art. 20(10) Regulation (EU) 2023/1230, as amended by Regulation (EU) 2026/1744Article 20(10) of the Machinery Regulation, added by Regulation (EU) 2026/1744, is a transitional rule: as long as no machinery-specific harmonized standards or common specifications cover the AI-related requirements, a presumption of conformity can be drawn from the harmonized standards or common specifications of the AI Act that cover them.
AI regulation · EU · Machinery · Omnibus
Definition and examples- Working term
AI-enabled machine function
An AI-enabled machine function is a function of machinery whose output or control behavior depends on training data, inference or ongoing adaptation — such as learning perception, adaptive control loops, predictive safety functions or model-based decision logic. Where it affects safety or control, it is examined under the Machinery Regulation from January 20, 2027.
AI regulation · EU · Machinery · Technical documentation
Definition and examples
United States
NIST AI Risk Management Framework
NIST AI 100-1The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is a voluntary framework published by the US National Institute of Standards and Technology in January 2023 to help organizations manage the risks of AI systems throughout their lifecycle. It is organized in four functions — Govern, Map, Measure and Manage — and describes the characteristics of trustworthy AI.
AI regulation · USA
Definition and examplesExecutive Order 14179
EO 14179, 90 FR 8741Executive Order 14179, “Removing Barriers to American Leadership in Artificial Intelligence”, signed on January 23, 2025, sets the US federal policy of sustaining and enhancing America’s global AI dominance. It replaced the AI safety policy of Executive Order 14110, which had been revoked three days earlier, and ordered the development of an AI action plan.
AI regulation · USA
Definition and examplesAmerica’s AI Action Plan
America’s AI Action Plan (“Winning the Race”) is the US government’s AI policy agenda, published by the White House on July 23, 2025 as ordered by Executive Order 14179. It sets out more than 90 federal policy actions in three pillars: accelerating AI innovation, building American AI infrastructure, and leading in international AI diplomacy and security.
AI regulation · USA
Definition and examplesExecutive Order 14365
EO 14365, 90 FR 58499Executive Order 14365, “Ensuring a National Policy Framework for Artificial Intelligence”, signed on December 11, 2025, directs US federal agencies to counter state AI laws considered burdensome — through litigation, funding conditions and federal standards — and calls for federal legislation establishing a uniform national AI framework that preempts conflicting state laws.
AI regulation · USA
Definition and examplesCalifornia SB 53 (Transparency in Frontier AI Act)
California SB 53 (2025)California SB 53, the Transparency in Frontier Artificial Intelligence Act, is a California law, signed on September 29, 2025 and in effect since January 1, 2026, that requires developers of frontier AI models to publish safety frameworks and transparency reports, report critical safety incidents to the state and protect whistleblowers.
AI regulation · USA · Technical documentation
Definition and examplesColorado AI Act
Colorado SB 24-205, replaced by SB 26-189The Colorado AI Act (SB 24-205, 2024) was the first comprehensive US state law on high-risk AI systems. It never took effect: in May 2026 Colorado repealed and replaced it with SB 26-189, a narrower law on automated decision-making technology in consequential decisions that requires notice, explanation of adverse outcomes and human review from January 1, 2027.
AI regulation · USA
Definition and examples
Canada
Artificial Intelligence and Data Act (AIDA)
Part 3 of Bill C-27 (44th Parliament)The Artificial Intelligence and Data Act (AIDA) was a proposed Canadian federal law, introduced in June 2022 as Part 3 of Bill C-27, that would have regulated the design, development and use of high-impact AI systems in international and interprovincial trade. It died on the order paper when Parliament was prorogued on January 6, 2025 and has not been reintroduced.
AI regulation · Canada
Definition and examplesDirective on Automated Decision-Making (Canada)
Treasury Board Directive on Automated Decision-MakingThe Directive on Automated Decision-Making is a Treasury Board of Canada policy that governs how federal institutions use automated systems to make or support administrative decisions. It requires an Algorithmic Impact Assessment before a system is used and applies requirements — such as notice, explanation, bias testing and human involvement — graded by impact level.
AI regulation · Canada · Technical documentation
Definition and examplesCanadian Voluntary Code of Conduct on Generative AI
The Voluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems is a code published by the Government of Canada in September 2023, in which signatory organizations commit to measures for accountability, safety, fairness, transparency, human oversight and robustness when developing or managing advanced generative AI systems.
AI regulation · Canada
Definition and examples
China
Interim Measures for Generative AI Services (China)
生成式人工智能服务管理暂行办法The Interim Measures for the Management of Generative Artificial Intelligence Services are Chinese regulations, issued by the Cyberspace Administration of China (CAC) with six other agencies and in effect since August 15, 2023, that govern generative AI services offered to the public in China — covering content, training data, labeling, user protection and, for influential services, security assessment and filing.
AI regulation · China
Definition and examplesAlgorithm filing (China)
算法备案Algorithm filing is the Chinese requirement that providers of algorithmic recommendation, deep synthesis and generative AI services with public opinion attributes or social mobilization capacity register their algorithms with the Cyberspace Administration of China through its algorithm filing system, submitting details of the algorithm and a self-assessment report.
AI regulation · China · Technical documentation
Definition and examplesDeep synthesis provisions (China)
互联网信息服务深度合成管理规定The Provisions on the Administration of Deep Synthesis of Internet-based Information Services are Chinese regulations in effect since January 10, 2023 that govern technologies generating or editing text, images, audio, video and virtual scenes with deep learning. They require providers to verify users’ identities, label synthetic content, obtain consent for editing biometric features and file their algorithms.
AI regulation · China
Definition and examplesAI-generated content labeling measures (China)
人工智能生成合成内容标识办法; GB 45438-2025The Measures for Labeling Artificial Intelligence-Generated Synthetic Content are Chinese regulations in effect since September 1, 2025 that require AI-generated text, images, audio, video and virtual scenes to carry explicit labels visible to users and implicit labels in the file metadata, and that oblige distribution platforms to detect and label such content.
AI regulation · China · Technical documentation
Definition and examples
From AI TechDoc Press
The analysis behind these terms
- Regulatory ambition of the EU AI ActThe EU AI Act as a systems law: risk classification, human oversight, monitoring and documentation as the evidence layer between law and practice.Read on Substack
- Machine AI regulation begins in 2027 — not 2028Why machinery-law assessment of AI functions begins on January 20, 2027, while the AI Act high-risk profile follows in 2028.Read on Substack
Updates in this glossary
Entries corrected or brought up to date after publication. Each ID refers to the previous version in the editors’ archive.
Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.