Glossary category
Safety and governance
Keeping AI within bounds.
38 terms
South Korea's framework law for AI, which pairs promoting the industry with preventing its risks and places duties for transparency, safety and operator responsibility.
Tools claiming to identify machine-written text, which are unreliable enough that decisions about people should not rest on them.
Telling readers that content was produced with AI, sometimes a legal duty and increasingly an expectation regardless.
The rules and roles an organisation sets for how AI may be used, who approves it and who answers for what it does.
An occasion where an AI system causes or nearly causes harm, which some regimes now expect to be recorded and reported.
The working understanding needed to use AI tools responsibly, which European law turns from a good idea into a duty on providers and deployers to take measures supporting it among their staff.
The written document telling staff what they may and may not do with AI tools, usually the cheapest first control to put in place.
The specific ways an AI use could cause harm or loss, assessed case by case rather than treated as one general worry.
The work of making AI systems behave predictably and within bounds, covering both everyday failures and longer-term concerns.
The problem of getting a system to pursue what people actually intended rather than the literal instruction it was given.
Systematic unfairness in a system's outputs, learnt from its training data or its design, showing up as worse results for some groups.
California's consumer privacy law, giving residents rights over their personal data and reaching many companies outside the state.
- China's generative AI measures
China's interim rules for generative AI, which govern providers offering such services to the public in China.
A popular name rather than an official title for Colorado's AI law, whose commencement was extended and whose provisions were then repealed and reenacted with different requirements.
The check that a regulated system meets its legal requirements before it goes to market, which for higher-risk AI happens before launch rather than after.
Filtering what goes into or comes out of a system against a policy, the control behind a product refusing certain requests.
A record travelling with a file describing how it was made and edited, aimed at showing where an image or document came from.
Noticing when results get worse because the world or the inputs have changed, even though nothing about the system was altered.
Structured tests that measure whether an AI system actually does its job, and the honest answer to how you would know if it stopped.
How far you can tell why a system produced a particular answer, which matters most where a decision has to be justified to someone.
The European rules for providers of general-purpose AI models, which is why a business building on a foundation model should check whether its supplier publishes the required technical documentation and training-data summary.
Constraining what a model may produce while it produces it, rather than checking and discarding the answer afterwards.
Rules and filters wrapped around a model to keep its output within bounds: refusing harmful requests, staying on topic, not revealing private data.
A category under European legislation covering uses such as employment and worker management or access to essential services, carrying the heaviest obligations before deployment.
- HIPAA
United States legislation governing health information, whose obligations fall on specific categories of organisation rather than on everyone holding health data.
An international certification for running an AI management system, the AI counterpart to the security certification many buyers already ask for.
A request crafted to get a model to ignore its own rules, and the reason guardrails are treated as a control rather than a guarantee.
Using one model to score another's output at scale, cheaper than human review and needing its own checking before it is trusted.
Singapore's published AI governance guidance, extended with editions for generative and agentic AI, whose nine named dimensions a business can use to benchmark its own governance.
The whole path a model takes in your organisation, from selection and testing through live use to eventual replacement.
Watching a live system's outputs over time so quality problems are noticed from evidence rather than from complaints.
Corrupting a model by tampering with what it learns from, which is a supply-chain concern wherever training data or a model is sourced externally.
A United States framework for identifying and managing AI risk, intended for voluntary use and organised around four functions that give an organisation ready-made headings.
Deliberately attacking an AI system before its users do: probing for ways to make it leak data, produce harmful content or ignore its instructions.
A model declining to answer, sometimes correctly and sometimes not, and a common source of complaints when the boundary is drawn poorly.
An organisation's stated commitments on fairness, safety and accountability in how it builds and buys AI, and the practices meant to deliver them.
A legal requirement to tell people they are dealing with an AI system or looking at generated content, separate from any duty about how well it works.
Marking generated content so it can later be recognised as machine-made, more reliable in some formats than in others.