← All resources

AI governance glossary

Plain-English definitions of the terms you’ll meet across AI governance.

AI use case
A specific application of an AI tool to a business task — for example, drafting support replies with a chat assistant. Governance happens at the use-case level because the same tool can be low-risk for one task and high-risk for another.
AI use register
The system of record that inventories an organization's AI tools and use cases, along with their owners, data, risk tiers, and approval status. The foundation of any AI governance program.
Audit trail
An append-only record of governance actions — who did what and when — that lets you reconstruct and defend decisions after the fact.
Automation level
How much an AI system is trusted to act on its own: advisory, human-in-the-loop, human-on-the-loop, or fully automated. It drives the oversight a use case requires.
DPIA
A Data Protection Impact Assessment — a structured evaluation of privacy risk, expected under laws like the GDPR when processing (including AI processing) is likely to result in high risk to individuals.
EU AI Act
The European Union's regulation on artificial intelligence (Regulation (EU) 2024/1689). It imposes binding, risk-based obligations on AI systems that reach the EU market or affect people in the EU.
Framework mapping
A descriptive mapping of your governance records to standards like NIST AI RMF, ISO/IEC 42001, and the EU AI Act, showing per-category coverage. It demonstrates alignment; it is not a compliance certification.
High-risk AI
AI use that warrants enhanced governance — for example decisions affecting employment, credit, or access to services, processing of sensitive data, or highly automated decisions about people.
Human oversight
Meaningful human control over AI-assisted decisions — a competent person with the authority, information, and time to understand, question, and override the AI.
Human-in-the-loop
An oversight model where a human reviews and approves each AI action before it takes effect. Expected for decisions that materially affect individuals.
ISO/IEC 42001
An international standard for an AI Management System (AIMS). It describes how to establish, run, and continually improve AI governance, and organizations can be certified against it.
Model card
Vendor or developer documentation describing an AI model's intended use, performance, limitations, and evaluations — useful input to procurement and risk assessment.
NIST AI RMF
The NIST AI Risk Management Framework — a voluntary framework organized around four functions (Govern, Map, Measure, Manage) for building and operating trustworthy AI.
Periodic review
Scheduled re-assessment of an approved AI use case, so governance stays current as tools, data, and regulations change. AI governance is not one-and-done.
Prohibited practice
An AI use that an organization (or the law) does not permit under any circumstances — such as unlawful discrimination or exposing regulated data to unapproved tools.
Risk tier
A consistent rating (e.g., Low, Moderate, High, Prohibited) assigned to an AI use case based on factors like data sensitivity, decision impact, and automation level. Good risk tiers are explainable and reproducible.
Safeguard
A required control or condition attached to an AI use case — often to a conditional approval — with an owner and verification, to reduce its risk to an acceptable level.
Shadow AI
The use of AI tools without the knowledge, approval, or oversight of those responsible for risk and compliance — the AI equivalent of shadow IT.

See these concepts in action.

Explore a fully populated AI governance workspace — no signup required.

Stay ahead of AI governance.

Get new guides and product updates in your inbox. Occasional, no spam.