Skip to content

Glossary of Terms

Version: 1.0 | Updated: December 2024

This glossary contains technical terms used in the AI-Native Entry Framework™ documentation.



TermDefinition
AI ActEU Regulation 2024/1689 - The European Artificial Intelligence Act, world’s first comprehensive regulation of AI systems
GDPRGeneral Data Protection Regulation (EU 2016/679) - EU regulation governing processing of personal data
NIS2Network and Information Security Directive 2 (EU 2022/2555) - EU cybersecurity regulation for critical infrastructure
EDPBEuropean Data Protection Board - Independent EU body ensuring consistent application of GDPR
NÚKIBNational Cyber and Information Security Agency (Czech Republic)
ÚOOÚCzech Data Protection Authority (Úřad pro ochranu osobních údajů)

TermDefinition
Access ControlSecurity mechanism regulating who can view or use resources
AccountabilityGDPR principle requiring demonstration of compliance
AccuracyDegree of correctness of AI system outputs
AI SystemSystem utilizing artificial intelligence technologies
AnnexAppendix to a regulation or directive
Annex IIIList of high-risk AI application areas in AI Act
AnonymizationIrreversible removal of identifying information from data
AuditSystematic review of processes or systems
Audit LogChronological record of all activities in a system
Audit TrailChronological record documenting sequence of activities
Automated Decision-MakingDecision-making performed by AI without human intervention
TermDefinition
BackupCopy of data stored separately for recovery purposes
Balancing TestAssessment of legitimate interest vs. data subject rights
BCMBusiness Continuity Management - processes ensuring operations during disruptions
BiasSystematic error in AI model leading to unfair outcomes
Bias TestingEvaluation of AI system for discriminatory outcomes across groups
Biometric DataPhysical or behavioral characteristics used for identification
BoardBoard of Directors - governing body providing oversight
BreachSecurity incident with unauthorized access to personal data
Business ContinuityAbility to continue operations during incidents
TermDefinition
CE MarkingMark confirming compliance with EU legislation
ChatbotAI-powered conversational interface
ChecklistStructured list for tracking compliance requirements
CISOChief Information Security Officer - executive responsible for information security
ClassificationCategorization according to risk level
C-levelExecutive leadership (CEO, CTO, CISO, CFO, etc.)
Cloud ComputingIT services delivered over the internet
ComplianceAdherence to legal requirements
Conformity AssessmentVerification that AI system meets requirements
ConsentFreely given, specific, informed agreement to data processing
ControllerEntity determining purposes and means of personal data processing
Critical InfrastructureInfrastructure essential for society functioning
CryptographyProtection of data using mathematical algorithms
CTOChief Technology Officer - executive responsible for technology strategy
TermDefinition
DashboardVisual display of key metrics and status
Data BreachSecurity incident resulting in unauthorized access to personal data
Data ControllerOrganization determining purpose of data processing
Data MappingProcess of identifying what data organization processes
Data MinimizationPrinciple of processing only necessary data
Data Processing Agreement (DPA)Contract between controller and processor
Data ProcessorEntity processing data on behalf of controller
Data Protection Impact Assessment (DPIA)Risk assessment for personal data processing
Data Protection Officer (DPO)Person responsible for GDPR compliance
Data SubjectIndividual whose personal data is being processed
Data Subject Access Request (DSAR)Individual’s request to access their personal data
DeadlineFinal date for meeting a requirement
DeepfakeAI-generated synthetic media appearing authentic
DeployerEntity that uses AI system under its authority
Disaster RecoveryProcess of restoring systems after catastrophic event
Drift DetectionMonitoring AI system performance changes over time
Due DiligenceThorough investigation of partner or supplier
TermDefinition
EncryptionProtection of data using cryptography
Encryption at RestEncryption of stored data on disk
Encryption in TransitEncryption of data during transfer (TLS)
Endpoint ProtectionAntivirus and other protection on devices
Essential EntityCategory under NIS2 with higher obligations (Annex I sectors)
TermDefinition
Fail-safeMechanism for safe system failure
FirewallNetwork perimeter protection
Fraud DetectionAI system for detecting fraudulent activity
FrameworkStructured approach or methodology
TermDefinition
General Purpose AI (GPAI)AI models like GPT, Claude usable for multiple purposes
Global TurnoverTotal worldwide annual revenue of organization
GovernanceSystem of rules, practices, and processes for direction and control
TermDefinition
HallucinationAI-generated output that is factually incorrect
High-Risk AIAI systems classified under AI Act Annex III with significant impact on rights
Human OversightAbility of humans to intervene in AI decision-making
Human-in-the-loopRequirement for human approval of AI decisions
TermDefinition
Important EntityCategory under NIS2 with moderate obligations (Annex II sectors)
Incident ManagementProcess of responding to security incidents
Incident ResponseProcedures during security incident occurrence
Incident Response Plan (IRP)Document describing incident procedures
Information Security Management System (ISMS)Systematic approach to security management per ISO 27001
InventoryList of all AI systems in organization
TermDefinition
Key Performance Indicator (KPI)Metric for measuring success
Knowledge CutoffDate beyond which AI model has no training data
TermDefinition
Law EnforcementPolice and judicial authorities
Legal BasisLawful justification for processing personal data
Legitimate InterestLegal basis under Article 6(1)(f) GDPR
Legitimate Interest Assessment (LIA)Test for legitimate interest justification
Limited Risk AIAI requiring transparency obligations (chatbots, deepfakes)
LoggingRecording of events in a system
TermDefinition
Machine Learning (ML)AI technology enabling systems to learn from data
Minimal Risk AIAI with no specific regulatory obligations
MitigationMeasures to reduce risk
Model CardTechnical documentation describing AI model
MonitoringContinuous observation of systems
Multi-Factor Authentication (MFA)Authentication using multiple verification methods
TermDefinition
72-hour RuleGDPR requirement to notify authority of breach within 72 hours
TermDefinition
OnboardingProcess of integrating new employees
Opt-inActive granting of consent (checkbox)
OversightControl and supervision
TermDefinition
Patch ManagementProcess of applying security updates
PenaltyFinancial punishment for violation
Penetration TestingSimulated attack for security testing
Personal DataAny information relating to identified individual
PIIPersonally Identifiable Information
PolicyFormal statement of organizational rules
Post-Market MonitoringMonitoring of AI system after deployment
Privacy by DesignPrinciple of incorporating protection from the start
Privacy PolicyDocument informing about data processing
ProcedureStep-by-step instructions for performing task
ProcessorEntity processing data on behalf of controller
Prohibited AIAI systems banned under Article 5 of AI Act
ProviderEntity developing or training AI system
PseudonymizationReplacing identifiers with pseudonyms
Purpose LimitationGDPR principle of processing only for specified purposes
TermDefinition
RBACRole-Based Access Control
Record KeepingObligation to maintain documentation
Records of Processing Activities (ROPA)List of all personal data processing activities
Recovery Point Objective (RPO)Maximum acceptable data loss
Recovery Time Objective (RTO)Maximum acceptable downtime
ResilienceSystem ability to handle problems
RetentionPeriod of data storage
Right to AccessData subject’s right to obtain copy of their data
Right to be ForgottenData subject’s right to erasure of data
Right to Data PortabilityRight to receive data in machine-readable format
Right to ObjectData subject’s right to object to processing
Right to RectificationRight to correct inaccurate data
Right to RestrictionRight to limit processing of data
Risk AssessmentIdentification and evaluation of risks
Risk ManagementSystematic approach to reducing risks
RobustnessSystem ability to function despite errors
TermDefinition
SaaSSoftware as a Service - cloud-based software delivery
SanctionPenalty for non-compliance
ScopeArea to which regulation applies
Security IncidentEvent threatening security
SIEMSecurity Incident and Event Management
SLAService Level Agreement
Social ScoringEvaluation of persons based on behavior (prohibited by AI Act)
Special Category DataSensitive data under Article 9 GDPR (health, biometric, race, religion, political opinions, genetic data, sex life, trade union membership)
Standard Contractual Clauses (SCCs)Mechanism for data transfer outside EU
Storage LimitationGDPR principle of retaining only as long as necessary
Sub-processorProcessor engaged by another processor
Supply Chain SecurityProtection of products throughout supply chain
TermDefinition
TemplatePrepared document format with placeholders
Terms of Service (ToS)Contractual conditions with provider
Third-partyExternal provider
ThreatPotential danger to system
TimelinePlan of deadlines and milestones
Training DataData used for training AI model
Transfer Impact Assessment (TIA)Risk analysis for data transfer outside EU
TransparencyOpenness and clarity
TermDefinition
VendorExternal service provider
Vendor ManagementProcess of selecting and managing suppliers
VulnerabilitySecurity weakness in system
Vulnerability ManagementProcess of identifying and fixing vulnerabilities
TermDefinition
WireframeVisual guide representing user interface structure
WorkflowDefined sequence of steps

AbbreviationFull NameDescription
AI ActArtificial Intelligence ActEU Regulation 2024/1689 on artificial intelligence
GDPRGeneral Data Protection RegulationEU Regulation 2016/679 on personal data protection
NIS2Network and Information Security Directive 2EU Directive 2022/2555 on cybersecurity
AbbreviationFull NameDescription
CEOChief Executive OfficerHighest-ranking executive
CFOChief Financial OfficerExecutive responsible for finances
CISOChief Information Security OfficerExecutive responsible for information security
CTOChief Technology OfficerExecutive responsible for technology
DPOData Protection OfficerPerson responsible for GDPR compliance

Last updated: December 2024