The words, in English.

Compliance has a vocabulary, and most of it is written for lawyers. Here is what 63 of the terms you will actually meet mean, in the words you would use yourself. Where a term is something we build, there is a link to the page about it.

The basics

Accountability
The principle that it is not enough to comply — you must be able to demonstrate it. This is why a policy in a folder fails and a framework with records behind it does not.
AI compliance
Being able to show, on demand, that the way your business uses AI meets the law that applies to it. Not a single rule — a combination of data protection law, sector rules and, increasingly, AI-specific statutes. Read more
AI compliance framework
The policy plus the machinery that makes it real: the register of what you use, the training record, the risk assessment, the incident procedure. The difference between saying you are compliant and being able to show it. Read more
AI policy
A short internal document setting out how AI may and may not be used in your business, who is accountable, and what staff must do. It states the rules; it does not by itself prove you follow them. Read more
Controller
The organisation that decides why and how personal data is used. If you chose the AI tool and decided what to feed it, that is you — and the buck stops there.
Data subject
The person the data is about. Your customers, your staff, your applicants, and anyone whose details end up in a tool you pointed at your inbox.
Data subject access request DSAR
A person asking for a copy of the personal data you hold about them, and information about how it is used. Comes with a statutory deadline and no fee in most cases.
Lawful basis
The reason you are allowed to use someone's personal data at all. You must pick one before you start, be able to name it, and tell people which one you are relying on.
Legitimate interests
One lawful basis, and the one most often stretched. It requires you to weigh your purpose against the person's rights and to write that balancing down — an assessment you either have or you do not.
Personal data
Any information about a living person who can be identified from it, directly or with other information you hold. A name, an email address, an IP address, a customer reference — much wider than most businesses assume.
Processor
An organisation that handles personal data on a controller's instructions. Most AI vendors are processors; using one does not move your responsibility onto them.
Special category data
The sensitive subset — health, race, religion, sexual orientation, political opinion, trade union membership, genetic and biometric data. Needs a stronger justification than ordinary personal data, and AI tools trip over it constantly.
Transparency
Telling people, in plain language, that AI is involved and what it does. The single most common gap: the tool is disclosed nowhere the customer would ever look.

UK

Data (Use and Access) Act 2025 DUAA
The Act that amended UK data protection law, named for the year Parliament passed it. Its data protection provisions commenced later and changed the position on solely automated decisions — see the UK page for what changed and when. Read more
Data Protection Act 2018
The Act that sits alongside UK GDPR, filling in exemptions, criminal offences and the regulator's powers. Read more
ICO
The Information Commissioner's Office, the UK regulator for data protection. It enforces against AI uses under existing law and does not need a new statute to do so. Read more
Meaningful human involvement
A person with the authority and the information to actually change the outcome, who considers the case rather than approving a list. The test that decides whether a decision is "solely automated". Read more
PECR Privacy and Electronic Communications Regulations
The rules covering electronic marketing, cookies and similar tracking. Relevant the moment an AI tool is used to send marketing or to profile a visitor.
Solely automated decision
A decision about someone made by a machine with no meaningful human involvement. A human who rubber-stamps the output does not count. The UK position on these was changed by the Data (Use and Access) Act 2025 — the UK page carries what changed and when. Read more
UK GDPR
The UK's general data protection law. It already governs almost every business use of AI, because almost every business use of AI touches personal data. There is no separate UK AI statute waiting to switch on — this is the one that applies now. Read more

Europe

Annex I
The other high-risk route: AI embedded in products already covered by EU product safety law. A later deadline than Annex III. Read more
Annex III
The list in the EU AI Act naming the standalone high-risk uses — the one most professional services firms should read first, because recruitment and credit scoring are on it. Read more
Article 50
The EU AI Act's transparency duties: telling people when they are dealing with an AI, and marking synthetic content. The provision most likely to catch an ordinary business. Read more
Deployer
Under the EU AI Act, whoever uses an AI system in the course of their business. This is what most small firms are, and it carries real duties of its own. Read more
Digital Omnibus
The package that adjusted parts of the EU AI Act timetable. It moved deadlines; it did not remove duties. The EU page carries the dates as they now stand. Read more
EU AI Act
The European Union's AI regulation. It applies by where the AI has effect, not by where the company is registered, so it catches UK businesses with EU customers or staff. Its duties arrive in stages — the EU page carries the timetable. Read more
EU GDPR
The EU's data protection law. Separate from UK GDPR since Brexit, and the two have drifted — an assumption that they still match is a common and expensive mistake. Read more
GPAI General-purpose AI
General-purpose AI — a model that can do many things rather than one, which is what most familiar AI assistants are built on. The EU AI Act places duties on the model providers. Read more
High-risk AI system
The EU AI Act's heaviest category, covering AI used in recruitment, credit, education, essential services and similar. Brings documentation, human oversight, accuracy and record-keeping duties. Read more
Prohibited practice
Uses of AI the EU AI Act bans outright — such as social scoring and certain emotion inference at work. No risk assessment makes these acceptable. Read more
Provider
Under the EU AI Act, whoever develops an AI system or has one developed and puts it on the market under their own name. Rebrand a tool as your own and you may have become one. Read more
Regulatory sandbox
A supervised environment where a business can test an AI system with the regulator's involvement. Every Member State is required to run one. Read more

United States

Algorithmic discrimination
Unlawful differential treatment produced by an automated system. The harm several US state AI laws are built around, and the reason testing your AI is a legal question and not only a technical one. Read more
California AI Transparency Act SB 942
California's law on disclosure and provenance for large generative AI providers, including a free detection tool. Commencement has moved — the US page carries the live date. Read more
Colorado AI Act
Colorado's law on automated decision-making technology used in consequential decisions, placing duties on both developers and deployers. See the US page for its current commencement. Read more
Consequential decision
A decision with a material effect on someone's life — a job, a loan, housing, insurance, education, healthcare. The trigger for the heavier US state duties. Read more
Impact assessment
A written assessment of what an automated system does, who it affects and how the risks are controlled. Required by several state laws, and the document firms most often do not have. Read more
State AI law
There is no general federal AI statute. Obligations come state by state, and they differ — which is why "we comply in the US" is not a sentence that means anything on its own. Read more
TRAIGA Texas Responsible AI Governance Act
Texas's Responsible Artificial Intelligence Governance Act, covering prohibited uses, government disclosure and Attorney General enforcement. Read more

Canada

AIDA Artificial Intelligence and Data Act
The Artificial Intelligence and Data Act, proposed in Bill C-27. It did not become law — the bill fell when Parliament was prorogued, and it has not returned. Canada is governed by privacy law, not by an AI statute. Read more
Law 25
Quebec's privacy law, the strictest in Canada. Includes rights around automated decisions and obligations that catch businesses outside Quebec serving Quebec residents. Read more
Ontario job posting disclosure
Ontario's requirement that a publicly advertised job posting says so when AI is used to screen, assess or select applicants — including where a third party does the screening for you. Read more
PIPEDA Personal Information Protection and Electronic Documents Act
Canada's federal private-sector privacy law, applying to personal information used in commercial activity — including by AI tools. Read more

What a framework contains

Acceptable Use Policy
The document that tells staff what they may put into an AI tool and what they must never put into one. The first thing to write and the one most often missing. Read more
AI Risk Register
The list of AI tools actually in use, what each one touches, what could go wrong and who owns it. The document a regulator asks for first, because it shows whether you know what you are running. Read more
Data Classification Matrix
A simple table sorting your information into tiers and stating which tiers may go near which tools. Turns "use your judgement" into a rule somebody can follow. Read more
Data Processing Agreement DPA
The contract terms required between a controller and a processor. Feeding client data to an AI vendor without one is a straightforward breach, and it is the single most common finding we make. Read more
DPIA Data Protection Impact Assessment
A written assessment of a processing activity's risk to people, done before you start. Required where the risk is high, which AI-driven profiling and screening frequently is. Read more
Employee acknowledgement
The signed record that staff were told the rules. Without it, training happened only in the sense that you remember doing it. Read more
Human oversight
Named points in a process where a person must look before the outcome takes effect — written into the process rather than left to judgement. Read more
Incident Response Procedure
What happens, and who does it, when an AI tool gets something wrong or leaks something. Written before you need it, because the clock on a reportable breach is short. Read more
Record of processing
The inventory of what personal data you hold, why, where it goes and how long you keep it. AI tools are notorious for being absent from it. Read more
Retention schedule
How long you keep each kind of record and what happens at the end. AI chat histories are records too, and almost nobody has decided how long theirs live. Read more

AI in practice

Bias testing
Checking whether a system produces worse outcomes for some groups than others, on real cases, and re-checking when the system changes. Most firms have never done it once.
Explainability
Being able to say what an AI was shown and what it produced for a particular decision. Not a philosophical problem — a record-keeping one, and you either kept the record or you did not.
Hallucination
When an AI states something false with complete confidence. Not a bug to be fixed at your end — a property to be controlled by checking output before it reaches a client.
Large language model LLM
The kind of AI behind text assistants: it predicts convincing text rather than looking anything up. Which is why it can be fluent and wrong at the same time.
Profiling
Using automated processing to evaluate someone — their performance, reliability, interests, behaviour. Triggers extra duties, and CV screening is squarely inside it.
Prompt
What you type into an AI tool. Worth knowing because whatever goes into it has left your building, and a prompt containing client details is a disclosure.
Shadow AI
AI tools your staff are using that you do not know about. Present in almost every business we assess, and the reason an inventory is the first job rather than a later one. Read more
Synthetic content
Text, images, audio or video generated by AI. Increasingly required to be marked as such, which is a labelling job rather than a technical one.
Training data
The material a model learned from. The question that matters for you is the narrower one: whether what YOU type is used to train the vendor's next model, which varies by plan and by settings.
Vendor due diligence
Checking what an AI supplier actually does with your data before you use it, and keeping the answer. Their marketing page is not the answer; their terms are. Read more

Knowing the words is not the same as being covered.

See what a framework contains →
Call Now Claim Your Free Audit