The AI regulation glossary
The 53 terms of art the statutes lean on, defined the way regulators use them, each linked to the jurisdiction or topic where it does the most work.
AI law has a vocabulary problem: the same word carries different legal weight in different statutes, and half the compliance mistakes in this field start with a definition. These are working definitions grounded in how the instruments actually use the terms, from the EU AI Act's categories to the terms US state law turns on.
ADMT
Automated decision-making technology, the term of art in Colorado's replacement statute and California's privacy regulations for systems that decide or substantially assist deciding consequential outcomes.
AG enforcement
Enforcement reserved to a state attorney general, with no private suits. Texas TRAIGA and Colorado's ADMT law use this model, which caps exposure relative to private-action regimes.
AI literacy
The EU AI Act's requirement that providers and deployers ensure staff have sufficient AI understanding, in force since February 2, 2025 and widely underestimated.
AI system
The regulated unit in most modern AI law: a machine-based system that infers from inputs how to generate outputs such as predictions, recommendations, decisions, or content. The EU AI Act definition has become the template that Vietnam, Chile, Brazil, and others borrow.
AIDA
Canada's Artificial Intelligence and Data Act, the AI part of Bill C-27, which died when Parliament was prorogued in January 2025 and left Canada without an AI statute.
Algorithmic impact assessment
A structured pre-deployment review of an AI system's risks and effects. Required for high-risk systems in the EU model; Nigeria's pending bill would require them annually.
Article 50
The EU AI Act's transparency article: chatbot disclosure, synthetic-content marking, and deepfake labeling, applying from August 2, 2026.
Automated decision-making (ADM)
Decisions made by systems without meaningful human involvement. Privacy laws worldwide attach rights to it, and Colorado's 2027 law regulates it as its central category.
Bias audit
An independent evaluation of whether an automated tool produces disparate outcomes. New York City's Local Law 144 made annual bias audits mandatory for automated employment decision tools.
Biometric identifier
A biological measurement that identifies a person: faceprint, voiceprint, fingerprint, iris scan. The trigger term in BIPA and biometric provisions worldwide.
BIPA
The Illinois Biometric Information Privacy Act: written consent before collecting biometric identifiers, statutory damages per violation, and a private right of action that has produced the largest AI-adjacent settlements in the country.
Brussels effect
The pattern where EU rules become de facto global standards because multinationals build to the strictest regime they face. Vietnam's EU-styled law is the clearest 2026 example.
Chatbot disclosure
Telling users they are talking to a machine. Required by the EU from August 2026, by California's companion-chatbot rules, and by a fast-growing set of state bills.
Code of Practice on Transparency
The EU's voluntary code operationalizing Article 50's marking and labeling duties for AI-generated content; its second draft arrived March 5, 2026. Formally binding only on signatories, who gain a facilitated route to demonstrating compliance, it is expected to function as the practical benchmark for everyone in scope.
Conformity assessment
The pre-market process proving a high-risk system meets legal requirements, borrowed from EU product safety law. It is the machinery behind CE marking for AI.
Content credentials
The consumer-facing label built on provenance metadata, showing origin and edit history for media.
Content provenance
Metadata recording how a piece of content was made and altered, the C2PA approach. Washington's 2026 provenance bill is the first state statute built on it.
Deepfake
AI-generated or manipulated content that convincingly depicts real people or events. Regulated through labeling duties (EU, China), election statutes (many US states), and likeness rights (Tennessee's ELVIS Act).
Deployer
The party using an AI system in a professional capacity, as distinct from building it. Deployer duties typically cover oversight, monitoring, and disclosure to affected people.
Developer
In US state bills, the party that creates or substantially modifies an AI system. Colorado's repealed act and Virginia's vetoed bill both split duties between developers and deployers.
Digital Omnibus
The EU's 2026 simplification package that deferred the AI Act's high-risk deadlines to December 2027 and August 2028 and added a generation ban on non-consensual intimate imagery from December 2026.
Effective date
When obligations actually apply, as distinct from enactment or entry into force. The gap matters: the EU AI Act entered into force in 2024, but its high-risk duties arrive in 2027.
Emotion recognition
AI inferring emotional state from faces, voices, or physiology. The EU bans it in workplaces and schools; scientific validity remains contested.
Extraterritoriality
A law reaching conduct outside its borders. The EU AI Act binds foreign providers whose outputs are used in the EU; Vietnam's law reaches foreign providers serving Vietnamese users; most US state laws follow the resident.
Foundation model
A large model trained on broad data and adapted to many downstream uses. Regulatory drafts use it interchangeably with GPAI; California's SB 53 regulates the largest ones as frontier models.
Framework Convention on AI
The Council of Europe's 2024 treaty on AI, human rights, democracy, and the rule of law, the first binding international AI treaty. Switzerland's coming bill implements it.
Frontier model
The most capable class of models, typically defined by training compute or capability thresholds. California and New York both regulate frontier developers through transparency and safety-framework duties.
General-purpose AI (GPAI)
A model trained for broad capability rather than one task, such as a large language model. The EU regulates GPAI providers directly, with duties that began August 2, 2025.
High-risk AI
The category carrying the heaviest obligations in risk-based regimes: uses affecting safety or consequential decisions such as hiring, credit, education, and law enforcement. The EU's high-risk obligations arrive December 2, 2027.
Horizontal regulation
One law covering AI across the whole economy, the EU and South Korean model, as against sectoral regulation, where existing regulators handle AI inside their own remits, the UK, Israeli, and Swiss model.
ISO/IEC 42001
The international management-system standard for AI, the certification companies use to evidence governance where no statute tells them what enough looks like.
Latent disclosure
A hidden, machine-readable marker of AI generation that survives ordinary edits, as required by California's AI Transparency Act from August 2, 2026.
Legal force status
Whether an instrument binds: in force, partially in force, proposed, or repealed. This register encodes it on every law, including in machine-readable form.
Local Law 144
New York City's rule for automated employment decision tools: annual bias audits, published results, and candidate notice, in force since July 2023.
NIST AI RMF
The US National Institute of Standards and Technology's AI Risk Management Framework, the voluntary reference standard American enforcement and procurement keep pointing back to.
Preemption
A higher level of government displacing lower-level law. The live US question: the December 2025 executive order directs challenges to state AI laws, but displacing them generally requires Congress or a court ruling.
Private right of action
The ability of individuals, not just regulators, to sue for violations. The single biggest driver of exposure in US state law: BIPA and Washington's My Health My Data Act both have one.
Prohibited practices
Uses banned outright rather than regulated: social scoring, exploitative manipulation, and certain biometric uses under the EU AI Act; unauthorized mass surveillance and predictive policing under Peru's regulation.
Provider
The party that develops an AI system or has it developed and places it on the market under its own name. Providers carry the primary obligations in the EU model and its descendants.
Real-time remote biometric identification
Live identification of people in public spaces, typically by facial recognition. The most restricted use in the EU framework, with narrow law-enforcement exceptions.
Regulatory sandbox
A supervised environment for testing AI systems with regulatory flexibility. Required of member states by the EU AI Act; used by Utah, Peru, and Singapore.
Right of publicity
Control over commercial use of one's identity: name, image, likeness, and now voice. Tennessee's ELVIS Act extended it explicitly against AI cloning.
Risk-based approach
Scaling obligations to potential harm rather than regulating the technology as such. The EU's four-tier structure is the reference implementation; Vietnam, Peru, and most pending bills follow it.
Safety framework
A frontier developer's published protocol for assessing and managing catastrophic risks. California SB 53, New York's frontier law, and, since July 2026, Illinois' Safety Measures Act all require one; Illinois alone requires an independent audit of it.
Statutory damages
Fixed damages per violation without proving actual harm. Under BIPA they stack per scan or collection, which is how nine-figure settlements happen.
Synthetic media
Any AI-generated audio, image, video, or text. The regulatory questions are provenance, labeling, and consent, answered differently in every jurisdiction.
Systemic risk
The EU's category for the most capable GPAI models, presumed at very large training scale, carrying evaluation, incident-reporting, and cybersecurity duties.
TFAIA
California's Transparency in Frontier Artificial Intelligence Act (SB 53), effective January 1, 2026: safety frameworks, incident reporting, and whistleblower protection for frontier developers.
TRAIGA
The Texas Responsible Artificial Intelligence Governance Act, effective January 1, 2026: intent-based prohibitions on harmful uses, attorney-general enforcement only, fines from $10,000 to $200,000.
Training-data disclosure
Documentation of what data trained a model. California's AB 2013 requires public summaries; the EU requires a sufficiently detailed summary under a template.
Transparency obligations
Duties to tell people they are dealing with AI or AI-generated content: chatbot disclosure, deepfake labeling, and machine-readable marking. The EU's arrive August 2, 2026 under Article 50.
Watermarking
Embedding a machine-detectable signal in AI-generated content. China requires both visible and embedded marks; California's Transparency Act requires latent disclosure from large generative providers.
Artificial Intelligence Regulations, "AI Regulation Glossary," reviewed July 28, 2026, https://artificialintelligenceregulations.com/glossary.html.
Entries state the position as of the review date and link to the primary text for verification.
Social scoring
Rating people across contexts in ways that produce detrimental treatment. Banned by the EU AI Act and prohibited in Saudi Arabia's SDAIA principles.