AI, in the words of those who decide.
Thirty essential entries, defined from the boardroom's point of view and anchored to the European regulatory framework, read with the United Kingdom's principles-based approach in mind. The terminology follows the English text of Regulation (EU) 2024/1689.
A
Accountability
Demonstrable responsibility: decision-makers must be able to account for the choices made with and about AI systems. Under both the UK and the European frameworks, responsibility rests with people and organisations, never with the system. For the board it means clear roles, traceable decisions and the ability to explain, after the fact, why a choice was delegated or retained.
AESIA
The Agencia Española de Supervisión de la Inteligencia Artificial, based in A Coruña: the first national agency in Europe dedicated to AI supervision, and Spain's designated market surveillance authority for the EU AI Act. Every member state designates its own authorities: for UK organisations serving several EU markets, the map of national authorities is part of the compliance picture.
AI agents (agentic systems)
AI systems designed to pursue goals with degrees of autonomy: they plan intermediate steps, use external tools and act without a human command for every single action. For those who govern, they shift the question from "what does the system answer" to "what can the system do": perimeters of action, limits and human oversight become decisions for the top.
AI literacy
The duty set by Article 4 of the EU AI Act: providers and deployers ensure, as far as possible, a sufficient level of AI literacy among staff operating AI systems, taking account of knowledge, experience and context of use. The duty is already in force and reaches UK organisations within the Act's scope; UK regulators, for their part, expect boards to understand the systems they oversee. Either way, literacy at the top is part of governance.
AI Office
The European Commission structure that oversees the application of the EU AI Act, with direct competence over general-purpose AI models. It coordinates national authorities, develops codes of practice and may request information from model providers. It is the counterpart that defines, in practice, how the European rules are applied.
AIO
Artificial Intelligence Optimization: the overall stewardship of an organisation's presence across the generative AI ecosystem — model answers, augmented search engines, conversational assistants. The term gives its title to Rafael Patron's book on the shift from searches to answers and its competitive consequences.
Algorithmic delegation
Entrusting a decision, or part of one, to an automatic system. The relevant question for the board is not whether to delegate but where the boundary runs: which decisions can be delegated under oversight, which need a human in the loop, which remain non-delegable. Drawing that boundary explicitly is an act of governance.
Alignment
The discipline that aims to have AI systems pursue the goals and values of those who deploy them, avoiding unwanted behaviour. For the board it is the technical version of an old governance question: how to ensure that an agent — human or artificial — pursues the mandate it was given, and not a distorted interpretation of it.
B
Bias
Systematic distortions in the data or the model that skew outcomes towards particular groups, categories or results. In processes that touch people — recruitment, credit, appraisal — bias is a legal and reputational risk before it is a technical one. The EU AI Act imposes data-quality requirements on high-risk systems on precisely this front; UK equality and data protection law reaches the same conduct.
D
Decision capital
An organisation's capacity to take good, timely, defensible decisions: experience at the top, quality of information, clarity of roles, a culture of dissent. In Antropic's reading it is the asset automation does not replace — and one that grows scarcer and more valuable as execution is automated.
Deployer
Under the EU AI Act, the natural or legal person using an AI system under its own authority in the course of a professional activity. Most companies are deployers, not providers: the duties — use consistent with the instructions, human oversight, control of input data, staff literacy — arise here.
E
EU AI Act
Regulation (EU) 2024/1689, the world's first comprehensive statute on artificial intelligence. It takes a risk-based approach: prohibited practices, high-risk systems under strict obligations, transparency duties for limited-risk uses and dedicated rules for general-purpose AI models. The United Kingdom is not bound by it, but UK organisations serving the European market fall within its reach.
Explainability
The ability to explain why an AI system produced a given output, in terms comprehensible to those who must use it or bear its effects. It is not an absolute requirement: the level of explainability needed depends on the use. A credit decision demands explanations that a draft text does not. Setting that level is a governance choice.
F
Fine-tuning
The additional training of an existing model on specific data to specialise its behaviour: tone, domain, formats. For decision-makers the relevant point is contractual and one of responsibility: whoever substantially modifies a model may take on provider duties under the EU AI Act, besides answering for the quality of the data used.
Foundation model
A model trained on vast quantities of data, able to perform very different tasks and to serve as the base for countless applications. The European legal rendering of the concept is the general-purpose AI model. For organisations it means strategic dependency: most of the tools in the business rest on a few models from a few providers.
G
General-purpose AI models
Under the EU AI Act, models able to perform a wide range of distinct tasks competently, typically trained on large volumes of data: the base of the generative systems in use across businesses. Their providers carry dedicated duties — documentation, copyright policies, transparency about training — already in force.
GEO (Generative Engine Optimization)
Optimising the presence of content and brands in generative engines: systems that answer by composing text instead of returning lists of links. GEO works on citable sources, authority and the structure of information. It is the functional successor to SEO in the shift from searches to answers, and sits alongside LLMO.
GPAI
The acronym for the general-purpose AI models of the EU AI Act. See the dedicated entry.
H
Hallucination
The production, by a language model, of false content presented with the form of certainty: invented facts, non-existent sources, plausible but wrong detail. It is a structural limit, not an occasional defect. Any decision process that uses generative output needs a step of human verification proportionate to what is at stake.
High-risk AI system
The central category of the EU AI Act: systems used in fields that touch safety and fundamental rights — recruitment, credit, education, critical infrastructure, justice — or as safety components of regulated products. They carry the strictest duties for providers and deployers: risk management, data quality, human oversight, registration.
Human oversight
The requirement of Article 14 of the EU AI Act: high-risk systems must be capable of effective oversight by natural persons able to understand their limits, interpret their output, decide not to use it or stop it. The deployer entrusts the function to people with the competence, training and authority required: an organisational choice before a technical one — and sound practice under the UK's principles-based approach too.
Human-in-the-loop
The common shorthand for keeping a person inside the decision circuit of an automatic system, with the authority to confirm, correct or stop its output. See the entry on Human oversight.
L
LLMO
Large Language Model Optimization: the discipline that keeps watch over how language models describe a brand, a company or a person in their answers. It covers analysis of the current representation, work on the sources the models consult and measurement over time. The first Italian book on the subject, "Fatti trovare da ChatGPT", was written by Rafael Patron with AIPIA.
P
Post-automation era
The phase in which automating execution stops being the competitive advantage, because it is available to everyone, and value moves to what does not automate: direction, judgement, accountability, trust. It is Antropic's research frame: when answers become a commodity, the advantage lies in asking the right questions.
Prohibited AI practices
The uses of AI the EU AI Act bans outright, already in force: harmful manipulation, exploitation of vulnerabilities, social scoring, emotion recognition in the workplace save for narrow exceptions, and the other cases listed in Article 5. They are the outer perimeter of the framework: before any risk assessment comes the check that the use is not prohibited.
Prompt
The natural-language instruction with which one asks something of a generative system. The quality of the output depends in large part on the quality of the request: context, constraints, expected format. In organisations the prompt stops being an individual gesture and becomes an artefact to design, share and maintain like any other working tool.
Provider
Under the EU AI Act, whoever develops an AI system or a general-purpose AI model and places it on the market under its own name or trademark. Providers carry the heaviest duties on high-risk systems: risk management, data quality, technical documentation, CE marking. Telling provider from deployer is the first step of any compliance analysis.
R
RAG
Retrieval-Augmented Generation: the architecture that connects a language model to external documentary sources, so that answers rest on retrieved, citable content rather than on the model's memory alone. It reduces hallucinations and keeps control over the sources: hence its wide use in business applications of generative AI.
Red teaming
Adversarial testing of an AI system: dedicated teams deliberately try to make it fail — circumvent its limits, extract data, produce harmful content — before and after release. Born in information security, it has become a practice of AI governance: for the board it is the difference between trusting a vendor's claims and holding evidence of one's own.
Regulatory sandbox
A controlled space for experimentation in which firms test new AI systems under the supervision of the authorities, with adjusted obligations and direct dialogue with the regulator. The EU AI Act requires each member state to establish at least one; in the United Kingdom, sector regulators run comparable testing services within their own remits. It is a channel for reducing regulatory uncertainty before going to market.