Glossary

Every abbreviation, spelled out.

Every entry follows the same structure: the full form, a plain definition, then the context — why it matters and how it relates to the laws and frameworks this app covers.

AI Act

EU Artificial Intelligence Act

The European Union's horizontal, risk-tiered regulation for AI systems — sorting them into unacceptable-risk (banned), high-risk (heavily regulated), limited-risk (transparency duties), and minimal-risk categories, with obligations scaled to each tier.

It is the first comprehensive AI-specific law of its kind and the central statute the AIGP exam is built around; unlike GDPR, which regulates personal data, the AI Act regulates the AI system itself, regardless of whether personal data is involved.

AIGP

Artificial Intelligence Governance Professional

The IAPP certification this app is built to prepare you for — it tests whether you can operationalize AI governance: mapping laws and standards to concrete controls across a system's lifecycle.

The exam blueprint underlying this app (its four domains and every performance indicator) is drawn directly from IAPP's official AIGP Body of Knowledge, so 'passing the exam' and 'covering every performance indicator here' are meant to be the same target.

API

Application Programming Interface

A defined way for one piece of software to request functionality or data from another — commonly how organizations access a third-party AI model without hosting it themselves.

Governance-relevant because consuming a model via API (rather than building or hosting it) still carries deployer obligations under laws like the EU AI Act — you don't escape accountability just because you didn't train the model.

BIPA

Illinois Biometric Information Privacy Act

A US state law giving individuals a private right to sue over the collection or use of their biometric data — including facial-recognition templates — without informed consent.

Notable because, unlike most US privacy law, BIPA lets individuals (not just regulators) sue directly, which has produced some of the largest AI-related privacy settlements in the US and made it a frequently-cited cautionary example for any AI system using facial or voice recognition.

CBRN

Chemical, Biological, Radiological, and Nuclear

A category of catastrophic-harm risk used in AI safety discussions — the concern that a sufficiently capable general-purpose model could meaningfully assist someone in creating a weapon in one of these categories.

CBRN risk is one of the named 'systemic risks' that trigger extra obligations for the most capable GPAI models under the EU AI Act, reflecting a harm category with no equivalent in earlier data-protection-focused regulation.

CE

Conformité Européenne (CE marking)

The mark required on products sold in the EU to indicate compliance with applicable EU health, safety, and (for in-scope AI systems) AI Act requirements.

Under the EU AI Act, high-risk AI systems generally need CE marking before being placed on the market — extending a product-safety concept with decades of history in physical goods into the AI regulatory space.

CFPB

Consumer Financial Protection Bureau

The US federal agency overseeing consumer financial products, including guidance clarifying that lenders using AI/ML credit models must still give specific, accurate adverse-action reasons under ECOA — 'the algorithm decided' is not an acceptable explanation.

A useful example of a sector regulator applying old rules to new technology: the CFPB didn't need a new AI law to reach this position, it simply confirmed that existing lending-law explainability duties don't relax just because the model is more complex.

CJEU

Court of Justice of the European Union

The EU's highest court, responsible for interpreting EU law and ensuring it is applied consistently across all member states.

The CJEU's rulings bind how GDPR and other EU law are actually applied in practice. Its SCHUFA decision, for example, determined that automated credit scoring itself can count as a 'decision' under GDPR Article 22 — expanding the practical reach of that article well beyond what the bare statutory text alone would suggest.

CSAM

Child Sexual Abuse Material

Illegal content depicting the sexual abuse of children — including AI-generated synthetic depictions, which many jurisdictions now treat as equally illegal to depictions of real children.

A key case study in AI content-generation governance: several laws have been updated specifically to close the 'but it's not a real child' loophole that generative AI briefly opened, and providers face safety-by-design obligations to prevent misuse of image and video generation tools for this purpose.

DPIA

Data Protection Impact Assessment

A structured, documented assessment of the privacy risks a data-processing activity poses to individuals, required before undertaking processing likely to result in high risk to people's rights and freedoms.

Required under GDPR Article 35 for systematic profiling and large-scale processing of special-category data — a description that fits most consequential AI systems. In a mature AI governance program, a DPIA functions as a standing gate in the intake process, not a one-time form filed after the system is already built.

DPIAs

Data Protection Impact Assessments (plural)

The plural form of DPIA — see the DPIA entry for the full definition.

Referenced in the curriculum wherever an organization needs to run more than one, e.g. across multiple AI systems or after a material change to an existing one.

ECOA

Equal Credit Opportunity Act

A US federal law prohibiting credit discrimination based on protected characteristics, and requiring lenders to give applicants specific reasons when credit is denied.

Directly relevant to AI-driven credit scoring: an algorithmic denial still must produce an ECOA-compliant adverse-action notice with genuine reasons, which is difficult if the underlying model is a low-explainability black box.

EEOC

Equal Employment Opportunity Commission

The US federal agency enforcing anti-discrimination law in employment, including its guidance on how AI-driven hiring tools can trigger liability under existing civil-rights statutes.

The EEOC's position is that using an AI tool doesn't create a new legal standard or a shield from liability — an employer is just as responsible for a discriminatory outcome produced by an algorithm as one produced by a human recruiter.

FCRA

Fair Credit Reporting Act

A US federal law regulating the accuracy, fairness, and privacy of information used in consumer credit reports and background checks.

Increasingly applied to AI-driven tenant-screening and background-check tools, which courts and regulators have found can qualify as 'consumer reports' subject to FCRA's accuracy and dispute-resolution obligations even when the vendor is a tech company rather than a traditional credit bureau.

FRIA

Fundamental Rights Impact Assessment

An assessment the EU AI Act requires certain deployers of high-risk AI systems to conduct, evaluating the system's impact on fundamental rights before it is put into use — distinct from, and often layered alongside, a GDPR DPIA.

Illustrates how the AI Act and GDPR create parallel, non-identical documentation duties: a system may need both a DPIA (data-protection risk) and a FRIA (fundamental-rights risk generally), and doing one does not substitute for the other.

FTC

Federal Trade Commission

The primary US federal regulator for unfair and deceptive business practices, which has used this existing authority to police AI harms — biased algorithms, deceptive AI marketing claims, inadequate data security — in the absence of a dedicated federal AI law.

The FTC has repeatedly signaled that overstating what an AI system can do, or deploying one you know to be biased, can itself count as an unfair or deceptive practice — meaning organizations face real US federal exposure well before any AI-specific statute applies.

GDPR

General Data Protection Regulation

The European Union's comprehensive regulation governing how organizations collect, process, and store personal data — information that can identify a living person.

Adopted by the EU in 2016 and enforceable since 2018, GDPR applies to any organization processing the personal data of people in the EU, regardless of where that organization is headquartered. It is the single most consequential 'AI law that isn't an AI law' — almost every AI system that touches real people's data runs into its requirements before any AI-specific statute even applies.

GPAI

General-Purpose AI (model)

Under the EU AI Act, a model trained to perform a broad range of tasks and displaying significant generality — such as large language models — rather than being built for one narrow purpose, subject to its own dedicated obligations separate from the Act's risk tiers.

GPAI models above a systemic-risk compute threshold (10^25 FLOPs) face extra obligations — model evaluation, adversarial testing, and incident reporting — because a single foundation model's failure can propagate into every downstream system built on top of it.

IEC

International Electrotechnical Commission

The international standards body that co-develops many AI-relevant standards jointly with ISO, most visibly the ISO/IEC 42001 AI management system standard.

It rarely appears alone in AI governance contexts — almost always paired as 'ISO/IEC' — reflecting a joint technical committee structure rather than two separate, competing standards.

ISO

International Organization for Standardization

An international body that publishes voluntary consensus standards — including ISO/IEC 42001, the first certifiable AI management system standard, and ISO/IEC 23894 on AI risk management.

ISO standards are voluntary but frequently become de facto requirements once customers or regulators start asking for certification as proof of a working governance program, similar to how ISO 27001 became an expected baseline for information security.

LIME

Local Interpretable Model-agnostic Explanations

An explainability technique that approximates a complex model's behavior near one specific prediction with a simpler, human-readable model, in order to explain that single decision.

Commonly paired with SHAP as practical tooling for meeting explainability requirements — 'local' meaning it explains one prediction at a time rather than claiming to fully explain the model's overall logic.

LLM

Large Language Model

A type of GPAI model trained on vast amounts of text to generate and reason about language, underlying tools like chatbots and writing assistants.

LLMs are the most common real-world example of a 'general-purpose AI model' under the EU AI Act, which is why so many of that regulation's GPAI-specific obligations were written with systems like LLMs specifically in mind.

ML

Machine Learning

A branch of AI in which systems learn patterns from data rather than following rules explicitly written by a programmer.

Most consequential AI systems governed under laws like GDPR and the EU AI Act are ML systems — their learned, probabilistic behavior is exactly what makes GDPR's fixed, rule-based compliance concepts (a single 'lawful basis,' a fixed 'purpose') awkward to apply cleanly.

NIST

National Institute of Standards and Technology

A US federal agency that publishes voluntary technical standards and frameworks, including the widely adopted AI Risk Management Framework (AI RMF), rather than binding law.

Because the US has no single comprehensive federal AI statute, NIST's AI RMF has become the de facto common vocabulary US organizations use to structure AI governance programs — voluntary in name, but often referenced or required indirectly through contracts and sector regulators.

OECD

Organisation for Economic Co-operation and Development

An intergovernmental economic organization whose 2019 AI Principles — the first intergovernmental AI policy commitment — established widely-adopted values like transparency, robustness, and accountability that later hard laws would build on.

The OECD AI Principles are non-binding, but their language shows up almost verbatim inside binding regulations like the EU AI Act — making them a useful 'origin story' for why certain AI governance concepts are now considered baseline expectations worldwide.

OWASP

Open Worldwide Application Security Project

A nonprofit best known for its security vulnerability lists, including the OWASP Top 10 for LLM Applications, which catalogues AI-specific security risks like prompt injection and training-data poisoning.

Bridges traditional cybersecurity practice and AI governance — showing that many 'new' AI security risks are AI-specific variants of well-understood application-security categories, not entirely novel problems requiring an entirely new discipline.

PETs

Privacy-Enhancing Technologies

Technical methods — such as differential privacy, federated learning, and synthetic data — that reduce privacy risk while still allowing useful data analysis or model training.

Increasingly treated as an expected mitigation, not just a nice-to-have: regulators and standards like ISO/IEC 42001 point to PETs as concrete evidence that 'privacy by design' has actually been implemented rather than just claimed in a policy document.

PII

Personally Identifiable Information

Information that can identify a specific individual — the US legal-privacy analogue to what GDPR calls 'personal data.'

The two terms aren't perfectly interchangeable: GDPR's 'personal data' is broader and covers anything relating to an identifiable person, while PII in US law is often defined narrowly per-statute — a distinction that matters when a single AI system must comply with both regimes at once.

RAG

Retrieval-Augmented Generation

A technique where an LLM's answer is grounded by first retrieving relevant documents from an external knowledge source, rather than relying solely on what the model memorized during training.

Governance-relevant because RAG changes where accountability sits: an inaccurate output might stem from the retrieved source document rather than the model itself, complicating standard AI-accountability and explainability analysis.

RLHF

Reinforcement Learning from Human Feedback

A training technique that fine-tunes a model's behavior using human ratings of its outputs, commonly used to make LLMs more helpful and less harmful.

Relevant to governance because RLHF embeds human (and organizational) value judgments directly into a model's behavior — raising documentation questions about whose values were used, and whether that process itself needs auditing.

RMF

Risk Management Framework

NIST's structured approach to AI risk management, organized around four functions — Govern, Map, Measure, Manage — that together form a repeatable cycle rather than a one-time checklist.

Used throughout the curriculum as shorthand for the 'NIST AI RMF'; its four-function structure recurs as a mental model for organizing almost any AI governance program, not just US-regulated ones.

SCHUFA

Schufa Holding AG (a German credit-reporting agency; the CJEU case is commonly referred to by this name)

A landmark 2023 CJEU ruling holding that automated credit scoring itself can constitute a 'decision' under GDPR Article 22, even when a separate party (such as a bank) makes the final lending decision based on that score.

Named for the German credit bureau involved, the case matters because it closed a common loophole: organizations could no longer argue that only the party making the final human-facing decision was bound by Article 22 — the scoring system generating the number that drives that decision is itself in scope.

SHAP

SHapley Additive exPlanations

A widely-used explainability technique that assigns each input feature a numeric 'contribution' to a model's specific prediction, based on game-theory concepts.

One of the two most common tools (alongside LIME) organizations use to satisfy explainability and transparency obligations for otherwise black-box models — cited as evidence that a 'right to explanation' can be operationalized, not just promised.

SOC

System and Organization Controls (report)

An independent audit report (e.g. SOC 2) attesting that a service organization's controls meet defined trust-service criteria such as security and availability.

Frequently requested as third-party assurance when procuring an AI vendor or model API — a SOC 2 report is one of the few externally-verified signals a customer can point to when they can't audit the vendor's model internals directly.

SR 11-7

Supervisory Guidance on Model Risk Management (Federal Reserve/OCC)

US bank-regulatory guidance, issued in 2011, that predates AI-specific law but established the model-risk-management pattern much of today's AI governance borrows directly: independent model validation, an 'effective challenge' function empowered to say no, and treating a model's whole lifecycle — not just its launch — as something requiring ongoing oversight.

Cited across AI governance literature as the origin of ideas like 'independent validation' and 'effective challenge' that now show up, in generalized form, in AI-specific testing and evaluation practice — worth recognizing by name even though it's a banking-sector document, not an AI law.

TDM

Text and Data Mining

The automated analysis of text or data (including scraping content to train an AI model) to extract patterns — the activity at the center of the EU's copyright exception that permits it by default unless a rightsholder opts out.

Under the EU's Digital Single Market Copyright Directive, rightsholders can block TDM over their published works via a machine-readable opt-out; AI developers training on EU-accessible content are expected to respect that opt-out, making TDM compliance a live diligence question for any generative-AI training pipeline.

TEVV

Test, Evaluation, Verification, and Validation

The umbrella term for the full set of activities that turn a claim about an AI system's performance into actual evidence — not just accuracy testing, but disaggregated fairness checks, robustness under stress, privacy testing, and real-context validity.

Used throughout the NIST AI RMF (it's the substance of the 'Measure' function) and referenced directly by the EU AI Act's testing requirements — a system that only ran accuracy tests has not done TEVV, it's done a fraction of it.