EU AI Act Info

Resources

Glossary

The terms the regulations use, in plain language, each pointing at the article that defines it or the module that implements it.

Deployer (AI Act)
Whoever uses an AI system under their authority, other than for personal non-professional activity. Article 4 literacy applies to deployers.
AI Act Art 3(4)Open →
Essential entity
An organisation of an Annex I (high-criticality) type that exceeds the medium-sized enterprise ceilings, plus certain types regardless of size. The fullest NIS2 duties and ex-ante supervision.
NIS2 Art 3(1)Open →
Evidence record
The result of one check by a connector or one document on file: source, timestamp, confidence and a hash chained to the previous record. Never overwritten.
PlatformOpen →
Explanation chain
The path from a verdict back to its evidence: regulation, obligation, control, evidence, verdict. Every verdict on the dashboard shows one.
PlatformOpen →
General-purpose AI model
A model trained on large data with significant generality, capable of many tasks. Provider obligations have applied since 2 August 2025.
AI Act Art 3(63)Open →
Important entity
Any other Annex I or Annex II organisation that meets the size gate. The same security measures, lighter supervision.
NIS2 Art 3(2)Open →
Major ICT-related incident
DORA's counterpart: an incident meeting the classification criteria in the regulatory technical standards. Initial notification within four hours of classification.
DORA Art 19; Del. Reg. (EU) 2025/301Open →
Obligation
In this platform, one testable duty decomposed from a regulation, citing the article and the source line, with a severity and a proportionality band.
PROJECT-PLAN.md §3Open →
Personal data breach
A security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Controllers notify the supervisory authority within 72 hours.
GDPR Art 4(12), Art 33Open →
Product with digital elements
Software or hardware and its remote data-processing solutions, including components placed on the market separately. The Cyber Resilience Act attaches to the product, whatever the maker's size.
CRA Art 3(1)Open →
Proportionality band
NIS2 Art 21(1) requires measures proportionate to size and exposure. The platform bands organisations micro, small, medium or all, and pass thresholds depend on the band.
NIS2 Art 21(1)Open →
Provider (AI Act)
Whoever develops an AI system or has it developed and places it on the market or puts it into service under their own name.
AI Act Art 3(3)Open →
Significant incident
An incident that causes or can cause severe operational disruption or financial loss, or affects others by causing considerable damage. It starts the 24-hour early-warning clock.
NIS2 Art 23(3)Open →
Trust center
The public page where an organisation publishes what is true about its security and compliance, in tiers: public, restricted (business-email verified) and NDA-gated.
PlatformOpen →