Defined terms — REGULATION (EU) 2024/1689 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (Text with EEA relevance)
European Union · 32024R1689 · 622 provisions
63 defined in this instrument, 5 borrowed from other acts.
AI literacy — skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause Article 3 — Definitions
AI Office — the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the Commission Article 3 — Definitions
AI regulatory sandbox — a controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real-world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision Article 3 — Definitions
AI system — a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments Article 3 — Definitions
authorised representative — a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation Article 3 — Definitions
biometric categorisation system — an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons Article 3 — Definitions
biometric data — personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data Article 3 — Definitions
biometric identification — the automated recognition of physical, physiological, behavioural, or psychological human features for the purpose of establishing the identity of a natural person by comparing biometric data of that individual to biometric data of individuals stored in a database Article 3 — Definitions
biometric verification — the automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data Article 3 — Definitions
CE marking — a marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing Article 3 — Definitions
common specification — a set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation Article 3 — Definitions
conformity assessment — the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled Article 3 — Definitions
conformity assessment body — a body that performs third-party conformity assessment activities, including testing, certification and inspection Article 3 — Definitions
critical infrastructure — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
deep fake — AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful Article 3 — Definitions
deployer — a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity Article 3 — Definitions
distributor — a natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market Article 3 — Definitions
downstream provider — a provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations Article 3 — Definitions
emotion recognition system — an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data Article 3 — Definitions
floating-point operation — any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base Article 3 — Definitions
general-purpose AI model — an AI model, including where such an AI model is trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market and that can be integrated into a variety of downstream systems or applications, except AI models that are used for research, development or prototyping activities before they are placed on the market Article 3 — Definitions
general-purpose AI system — an AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems Article 3 — Definitions
harmonised standard — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
high-impact capabilities — capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models Article 3 — Definitions
importer — a natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country Article 3 — Definitions
informed consent — a subject’s freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real-world conditions, after having been informed of all aspects of the testing that are relevant to the subject’s decision to participate Article 3 — Definitions
input data — data provided to or directly acquired by an AI system on the basis of which the system produces an output Article 3 — Definitions
instructions for use — the information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use Article 3 — Definitions
intended purpose — the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation Article 3 — Definitions
law enforcement — activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including safeguarding against and preventing threats to public security Article 3 — Definitions
law enforcement authority — (a)
any public authority competent for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; or
(b)
any other body or entity entrusted by Member State law to exercise public authority and public powers for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security Article 3 — Definitions
making available on the market — the supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge Article 3 — Definitions
market surveillance authority — the national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020 Article 3 — Definitions
national competent authority — a notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities in this Regulation shall be construed as references to the European Data Protection Supervisor Article 3 — Definitions
non-personal data — data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679 Article 3 — Definitions
notified body — a conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation Article 3 — Definitions
notifying authority — the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring Article 3 — Definitions
operator — a provider, product manufacturer, deployer, authorised representative, importer or distributor Article 3 — Definitions
performance of an AI system — the ability of an AI system to achieve its intended purpose Article 3 — Definitions
personal data — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
placing on the market — the first making available of an AI system or a general-purpose AI model on the Union market Article 3 — Definitions
post-market monitoring system — all activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions Article 3 — Definitions
post-remote biometric identification system — a remote biometric identification system other than a real-time remote biometric identification system Article 3 — Definitions
product presenting a risk — borrowed from another act; this instrument states no meaning of its own 1
profiling — borrowed from another act; this instrument states no meaning of its own Article 3 — Definitions
provider — a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or that has an AI system or a general-purpose AI model developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge Article 3 — Definitions
publicly accessible space — any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access may apply, and regardless of the potential capacity restrictions Article 3 — Definitions
putting into service — the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose Article 3 — Definitions
real-time remote biometric identification system — a remote biometric identification system, whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, comprising not only instant identification, but also limited short delays in order to avoid circumvention Article 3 — Definitions
real-world testing plan — a document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions Article 3 — Definitions
reasonably foreseeable misuse — the use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems Article 3 — Definitions
recall of an AI system — any measure aiming to achieve the return to the provider or taking out of service or disabling the use of an AI system made available to deployers Article 3 — Definitions
remote biometric identification system — an AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance through the comparison of a person’s biometric data with the biometric data contained in a reference database Article 3 — Definitions
risk — the combination of the probability of an occurrence of harm and the severity of that harm Article 3 — Definitions
safety component — a component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property Article 3 — Definitions
sandbox plan — a document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox Article 3 — Definitions
sensitive operational data — operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings Article 3 — Definitions
serious incident — an incident or malfunctioning of an AI system that directly or indirectly leads to any of the following:
(a)
the death of a person, or serious harm to a person’s health;
(b)
a serious and irreversible disruption of the management or operation of critical infrastructure;
(c)
the infringement of obligations under Union law intended to protect fundamental rights;
(d)
serious harm to property or the environment Article 3 — Definitions
special categories of personal data — the categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725 Article 3 — Definitions
substantial modification — a change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or results in a modification to the intended purpose for which the AI system has been assessed Article 3 — Definitions
systemic risk — a risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain Article 3 — Definitions
testing data — data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service Article 3 — Definitions
testing in real-world conditions — the temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory or otherwise simulated environment, with a view to gathering reliable and robust data and to assessing and verifying the conformity of the AI system with the requirements of this Regulation and it does not qualify as placing the AI system on the market or putting it into service within the meaning of this Regulation, provided that all the conditions laid down in Article 57 or 60 are fulfilled;
(58)
‘subject’, for the purpose of real-world testing, means a natural person who participates in testing in real-world conditions Article 3 — Definitions
training data — data used for training an AI system through fitting its learnable parameters Article 3 — Definitions
validation data — data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting Article 3 — Definitions
validation data set — a separate data set or part of the training data set, either as a fixed or variable split Article 3 — Definitions
widespread infringement — any act or omission contrary to Union law protecting the interest of individuals, which:
(a)
has harmed or is likely to harm the collective interests of individuals residing in at least two Member States other than the Member State in which:
(i)
the act or omission originated or took place;
(ii)
the provider concerned, or, where applicable, its authorised representative is located or established; or
(iii)
the deployer is established, when the infringement is committed by the deployer;
(b)
has caused, causes or is likely to cause harm to the collective interests of individuals and has common features, including the same unlawful practice or the same interest being infringed, and is occurring concurrently, committed by the same operator, in at least three Member States Article 3 — Definitions
withdrawal of an AI system — any measure aiming to prevent an AI system in the supply chain being made available on the market Article 3 — Definitions