Skip to content

THE WORDS THAT DECIDE THE COST AND THE LIABILITY

AI terms.

Thirty-four AI terms that mean something different in the EU AI Act and on the invoice than they do in a vendor's sales material. What they mean, what they get confused with, and the decision each one leads to.

01AI governanceSv. AI-styrningThe decision order that settles who may approve, stop and answer for an AI system. An allocation of authority, not a document and not a tool.
Confused with
An AI policy. The policy describes what applies; governance decides who rules when something is unclear. An organisation can have an excellent policy and no governance at all.
Where it sits
Nowhere. The word does not appear in the AI Act. What the Act actually requires is named accountability: Article 4 on AI literacy, Article 26 on deployer obligations, Article 27 on impact assessment.
Your decision
Who may say no to an AI system already in operation, and what has to happen for that person to learn the system exists? If you cannot answer both in one sentence, you have no governance.
02TokenThe unit you are billed inThe unit your AI consumption is measured and billed in. A fragment of text rather than a word: every prompt, every answer and every document is broken into tokens and priced accordingly.
Confused with
Words or characters. A Swedish word often becomes two or three tokens where an English one becomes one. The same work therefore costs more in Swedish than in English on the same system, which rarely appears in the quote.
Where it sits
In the price list, not in the law. But unit cost decides whether a pilot can scale, and that question belongs in the business case before the pilot starts rather than in the first invoice after go-live.
Your decision
Who sees consumption before it passes budget, and per which system? A pilot rarely gets expensive slowly. It gets expensive the week somebody automates a flow that runs ten thousand times a day.
03Provider and deployerSv. leverantör och tillhandahållareThe provider develops the system or puts it on the market under its own name. The deployer uses it in its own operations. The duties differ, and one role can turn into the other.
Confused with
Buyer and seller. The role does not follow the invoice. Put your own name on a bought system, or substantially change its intended purpose, and you become the provider with the provider's full duty load.
Where it sits
Article 3 (definitions), Article 25 (when responsibility moves), Article 26 (deployer obligations).
Your decision
Is there any system you have built on, branded, or use for something other than what it was sold for? Every such case has to be tested against Article 25 before the high-risk duties apply on 2 December 2027.
04Shadow AISv. skugg-AIAI tooling in use across the organisation without being known, approved or procured. Not a technical phenomenon but an inventory problem: the systems exist, just not on any list.
Confused with
Rule-breaking. Most shadow AI is well-meant work in tools the organisation already pays for. The problem is not disobedience but that duties follow the use even when leadership does not know about it.
Where it sits
Nowhere, and that is the point. Article 4 requires AI literacy of everyone working with AI on your behalf, whether or not you know they are. Not knowing a system exists does not release you from the duty.
Your decision
Do you inventory by asking or by measuring? Surveys consistently undercount. Invoice analysis and outbound network traffic give a different number, and it is that number a supervisor will compare against.
05Context windowSv. kontextfönsterHow much text a model can hold at once: instructions, attached material and the whole case so far. When the space runs out the oldest part falls away, usually without anyone being told.
Confused with
Memory. The model remembers nothing between cases. What looks like memory is the text being sent again every time, which is also why a long case costs more per answer than a short one.
Where it sits
Not in the regulation. But Article 14 requires the person exercising human oversight to understand the system's capacities and limitations, and this is one of the limitations that never shows in the interface.
Your decision
In which of your flows does the material grow over time: long casework, customer history, contract reviews? That is where quality degrades quietly, and they need a limit set in advance rather than discovered afterwards.
06High-risk systemSv. högrisksystemAI either used in one of the areas listed in Annex III, or acting as a safety component in a product already regulated under Annex I. The list is closed. Something is not high-risk because it feels important.
Confused with
Business-critical. A system the whole operation depends on can sit entirely outside the rules, while a small recruitment tool sits inside. The test is the use area, not what it means to you.
Where it sits
Article 6 with Annex I and Annex III. Annex III applies from 2 December 2027, Annex I from 2 August 2028.
Your decision
Classify the whole portfolio once and write down the reasoning for every no. An undocumented no is in practice not a classification, and it is the reasoning a supervisor asks for, not the conclusion.
07AI policyAcceptable use policyThe internal document setting out what staff may and may not do with AI tools. A communication instrument, not evidence of compliance.
Confused with
Compliance. A policy discharges no duty in the AI Act on its own. It can be a means of meeting Article 4, but only if someone can show it has been read, understood and followed.
Where it sits
Not in the Act. The duty to promote AI literacy in Article 4 is the closest thing, and it speaks of measures rather than documents.
Your decision
What happens when someone breaches the policy? Without an answer the document is a notice board, and a notice board is not a measure in the sense of Article 4.
08Inference and trainingOne-off cost against running costTraining builds the model once. Inference runs it, every time somebody asks a question. Training is a one-off cost somebody else has usually already taken. Inference is your running cost, and it never stops.
Confused with
The idea that AI is expensive to build and cheap to use. For nearly every organisation it is the other way round: you train nothing, you pay per run.
Where it sits
Not in the regulation as a cost concept. But the distinction decides who is the provider: training or substantially modifying a model takes on the provider's duties under Article 25.
Your decision
Is your AI budget written as an investment or as an operating cost? A capital line that grows every month is a miscoding, and it is usually spotted only once the volume is already a fact.
09Human oversightHuman in the loopA named person with both the authority and the actual capacity to intervene in or stop an AI system's decision. The capacity is the part that is usually missing.
Confused with
An approval button. A caseworker approving four hundred AI suggestions a day exercises no oversight in the Act's sense. Automation bias is a documented problem, and Article 14 names it explicitly.
Where it sits
Article 14 for high-risk systems, Article 26(2) for the deployer's duty to assign people with the necessary competence and authority.
Your decision
How many cases per person per day is compatible with real oversight, and what does that limit cost in headcount? It is a budget question before it is a compliance question, and it is settled in the leadership team.
10Prompt injectionSv. promptinjektionInstructions hidden in material the system reads — an email, a CV, a web page, an invoice — which the model then follows as if they came from you. The attack requires no code.
Confused with
An ordinary security hole that can be patched. It cannot. As long as a system both reads incoming text and holds authority to act, the risk remains, and it grows with every new permission you give an agent.
Where it sits
Article 15 on robustness and cybersecurity for high-risk systems. For everything else it is your own risk assessment, and NIS2 may apply in parallel depending on the business.
Your decision
Which actions may an AI system take without human approval? Reading is rarely dangerous. Sending, paying, deleting and granting are, and the line has to be drawn before an agent goes live.
11Fundamental rights impact assessmentFRIA. Not the same as a DPIAAn assessment of how a high-risk system affects people's fundamental rights, carried out by the party using the system. The duty catches two groups, and one of them is private.
Confused with
A data protection impact assessment. They overlap but do not replace each other: a DPIA is about personal data processing, a FRIA about rights impact more broadly. You may need both for the same system.
Where it sits
Article 27, applicable from 2 December 2027. It binds bodies governed by public law and private entities providing public services across Annex III apart from critical infrastructure, and separately every deployer of creditworthiness or life and health insurance pricing systems, commercial ones included.
Your decision
Do you provide a public service, whatever your ownership? A private company with a municipal mandate in health, education or care is caught exactly as the administration is. The exemption follows use, not ownership.
12RAG and fine-tuningRetrieval-augmented generationTwo ways to make a model know your business. RAG lets the model look things up in your documents at each question. Fine-tuning bakes the knowledge in beforehand. The choice is a cost and lock-in decision, not a technical one.
Confused with
The idea that fine-tuning is the better answer because it sounds more advanced. For most business cases RAG is cheaper, updates the moment a document changes, and lets you switch models without redoing the work. A fine-tuned model is a commitment to a vendor.
Where it sits
Not in the regulation as a technology choice. But the consequences are regulated: fine-tuning means processing your data in training, and substantially modifying a model can make you the provider under Article 25.
Your decision
How often does the knowledge the system needs change? If it changes more often than you are willing to retrain, RAG is the only durable choice, and access to your documents becomes the real problem to solve.
13Vendor lock-inSv. leverantörsinlåsningThe cost of switching vendor, measured in the work that has to be redone. It is rarely built deliberately; it emerges out of choices that were each reasonable on their own.
Confused with
A contract clause. The lock-in usually does not sit in the agreement but in the work: fine-tuned models, prompt libraries built around one model's quirks, and integrations against an interface nobody else has.
Where it sits
Not in the regulation. But Article 25 sharpens it: if you have built on a system far enough to become the provider, you have also locked yourself into that role along with its duties.
Your decision
What does switching models cost today, measured in working days? If nobody can answer, the answer is probably higher than you think, and that is the figure that belongs on the table before the next integration is built.
14AI literacyThe Act's own term for AI competenceThe Act's word for the competence required of those working with AI on your behalf. It covers every AI system regardless of risk level, and it has bound you since 2 February 2025.
Confused with
A completed course. Regulation (EU) 2026/1744 turned Article 4 into a duty to take measures rather than to guarantee a result. That makes documenting the measures more important, not less: a course with no follow-up is hard to call a measure.
Where it sits
Article 4, in force since 2 February 2025. It sits with leadership and covers every risk level, including AI embedded in software you already use.
Your decision
Who counts as someone working with AI on your behalf? If the answer is only the IT department, you have probably undercounted by an order of magnitude, and those roles are also the first to meet the requirements.
15Model version and deprecationSv. modellversion och deprekeringVendors retire models. A model you have built a workflow around can be withdrawn on a few months' notice, and the successor does not behave identically even when it is better.
Confused with
An ordinary software update. A new model version can change the outcome in cases where you validated quality against the old one. The testing you did at rollout does not automatically hold after a switch.
Where it sits
In the vendor contract, if you negotiated it in. In the regulation, closest to Article 72 on post-market monitoring, with the plan forming part of the technical documentation in Annex IV. The Digital Omnibus removed the mandatory template and instead requires Commission guidance by 2 September 2027, which puts the design back with you.
Your decision
What notice period have you contracted, and who tests whether the outcome changed when a version is swapped? Without both, your quality assurance depends on the vendor not doing something you do not control.
17AI due diligencePre-transaction AI reviewThe review of a company's AI use ahead of an acquisition or investment: which systems exist, which duties they trigger, what data they rest on, and what happens to the valuation if any of that does not hold.
Confused with
A technical review. The decisive finding is rarely the code. It is undocumented use, licence terms that do not permit commercial reuse, and training data with no traceable legal basis.
Where it sits
Not in the AI Act. But the duties travel with the company in an acquisition, and an unclassified portfolio becomes the buyer's problem the day the high-risk requirements apply.
Your decision
Should AI be its own workstream in the review, or a line under IT? As a line under IT, shadow AI rarely surfaces, and that is where the expensive surprises tend to sit.
18GuardrailsTechnical constraints on a systemThe technical constraints that stop an AI system doing certain things: filtering content, blocking actions, requiring approval above a threshold. They are conditional and they can be circumvented.
Confused with
Human oversight. A guardrail is a technical control the model can be induced to work around, prompt injection among the routes. Article 14 requires a person with authority, not a filter.
Where it sits
Not as a term of its own. The risk management, robustness and cybersecurity requirements in Chapter III for high-risk systems are what the guardrails must answer to, and an untested guardrail is not evidence of compliance.
Your decision
Who tests that the guardrails hold, and how often? A guardrail never tested after go-live is a hope, and it gets tested for the first time in the case where it was needed.
19Gap analysisSv. gap-analysThe comparison between what a defined requirement set demands and what you actually have in place. The output should be a list of differences, priced and dated, not a verdict on how you are doing.
Confused with
A readiness assessment. Readiness asks how well you can adopt and govern AI at all. A gap analysis asks what is missing against a chosen benchmark. They answer different questions and are often commissioned in the wrong order.
Where it sits
Not in the regulation as a term. But it is the working method behind Article 9 on risk management and Article 17 on the quality management system, and the evidence that the work started in time.
Your decision
Against which requirement set should the gap be measured: the AI Act, ISO/IEC 42001, or your own procurement standard? Without a chosen benchmark the list is a collection of opinions, and a collection of opinions does not hold up to scrutiny.
20AI readinessAI maturityHow well an organisation can adopt, govern and benefit from AI: data, competence, decision order and capacity for change. Four different things, and they are rarely equally developed.
Confused with
How much AI is already in use. An organisation with a hundred tools running and nobody who knows which they are has high usage and low readiness. It is the most common combination we meet.
Where it sits
Not in the regulation. But the readiness level decides how long compliance takes, and the runway to 2 December 2027 is only an advantage for those who know where the work starts.
Your decision
Are you measuring readiness to compare yourself with others, or to know what to do on Monday? A model that produces a score but no ordering of actions has cost money without moving anything.
21Model card and system cardThe vendor's own descriptionThe vendor's own account of what a model is trained for, how it has been tested and where it should not be used. Voluntary documents, but often the only basis you get for your own assessment.
Confused with
Technical documentation in the Act's sense. A model card is marketing-adjacent and written by the vendor. The technical documentation a high-risk system requires is your duty, not theirs.
Where it sits
Not as a requirement. But Article 53 with Annex XI places documentation duties on the model provider, and Annex XII governs precisely the information that must travel downstream to whoever builds on it. Your own technical documentation for a high-risk system is a different thing, in Article 11 with Annex IV.
Your decision
Does anyone on your side read the limitations section before a system goes live? That is where the vendor writes out exactly the use cases you will then answer for.
22Information classificationSv. informationsklassningThe decision about which data may be handled where, expressed in levels. It is the only practical basis for deciding what may be fed into an AI tool, and so it decides what AI may be used for.
Confused with
Access control. Permissions decide who may see something. Classification decides where it may exist. An AI tool rarely breaks permissions but it often moves data to a place the classification never allowed.
Where it sits
Not in the AI Act. GDPR Article 32 on security measures, NIS2 for the entities it covers, and for the public sector protective security legislation with its own analysis.
Your decision
What is the highest classification level that may be pasted into a public AI tool, and do staff know it without looking it up? A rule that requires a lookup is not followed in practice.
23Harmonised standardSv. harmoniserad standardA standard the European Commission has requested and referenced in the Official Journal, and which thereby acquires legal effect under a regulation. Follow it and you are presumed to meet the requirement.
Confused with
Any ISO standard. ISO/IEC 42001 is a useful management instrument but it is not harmonised under the AI Act, and it therefore carries no legal effect. The difference is decisive and it is frequently sold away.
Where it sits
Article 40 is what gives a standard legal effect under the Act. No harmonised standards under the Act have been published yet. Until they are, compliance is shown with your own documentation, and anyone selling you certainty today is selling something the law does not yet contain.
Your decision
Are you building documentation that can be mapped to a standard when it arrives, or certifying against a standard that carries no legal effect? The first is cheaper and keeps both routes open.
24Presumption of conformitySv. presumtion om överensstämmelseThe legal effect of following a harmonised standard: the authority proceeds on the basis that the requirement is met, and the burden of showing otherwise sits with whoever claims it.
Confused with
A certificate. A certificate from a certification body is not the same as a presumption in law. Without a harmonised standard there is no presumption to buy, whatever the certificate cost.
Where it sits
Article 40(1): a high-risk system or model in conformity with a harmonised standard shall be presumed to comply with the requirements in Chapter III, Section 2. No such standards exist yet, which means no vendor today can sell you a presumption.
Your decision
What do you do in the meantime? The answer is your own documentation, built to hold up to scrutiny and structured so it can point at a standard later without the work being redone.
25Conformity assessmentSv. bedömning av överensstämmelseThe check that a high-risk system meets the requirements before it may be placed on the market. Depending on the system it is carried out internally by the provider or by a notified body.
Confused with
An external audit you commission. For most Annex III systems it is the provider assessing itself under a set procedure. A vendor saying the assessment has been done does not mean anyone outside reviewed it.
Where it sits
Article 43, applicable from 2 December 2027 for Annex III. The Digital Omnibus rewrote Article 43(3) and settled that a product does not require third-party assessment merely because it contains a high-risk AI system as a safety component. Notified bodies under Annex I Section A must apply for designation by 28 January 2028. In Sweden, Swedac carries out no market surveillance; it designates and notifies the bodies.
Your decision
If you are the deployer: do you ask to see the assessment, or accept that it exists? That is a contract question to settle at procurement, not at an inspection.
26Cyber Resilience ActCRA. Regulation (EU) 2024/2847Cybersecurity requirements for products with digital elements, software included, across the whole lifetime. It catches whoever places the product on the market, and an AI system may well be such a product.
Confused with
NIS2. NIS2 regulates how an entity protects its own operations. The Cyber Resilience Act regulates products placed on the market. Build software for others and both apply at once, with different recipients and different deadlines.
Where it sits
Regulation (EU) 2024/2847. Manufacturers' reporting obligations have applied since 11 September 2026 and the full requirements apply from 11 December 2027. The link to the AI Act is made in Article 12 of the CRA: a high-risk AI system meeting its essential cybersecurity requirements is deemed to comply with Article 15 of the AI Act to that extent.
Your decision
Do you sell, licence or distribute software containing AI, including as part of a service? Then you probably carry a product duty alongside the AI Act, and the two timetables do not coincide.
27Regulatory sandboxSv. regulatorisk sandlådaA controlled environment where the authority lets an operator develop and test an AI system under supervision, with guidance instead of sanction while the test runs.
Confused with
An exemption from the rules. The sandbox gives guidance and a controlled environment, not a dispensation. The duties still apply, and data protection still requires a legal basis exactly as outside.
Where it sits
Article 57. Every member state must have at least one operational by 2 August 2027, moved back a year by the Digital Omnibus. Sweden has not yet established its own.
Your decision
Do you have a use case too uncertain to deploy and too valuable to drop? That is the candidate, and it should be prepared now because the places will be few.
28Data sovereigntyRelated: digital sovereigntyThe question of which state's law can reach your data, which is settled not by where the server stands but by who controls the vendor.
Confused with
Data residency in the EU. A US vendor's subsidiary with servers in Sweden can still be caught by US law. Server location answers a different question from the one that was asked.
Where it sits
Not in the AI Act. Data protection law and third-country transfers govern it, with the CLOUD Act on the American side, and for the public sector protective security on top.
Your decision
Which data categories may never leave a European legal framework? The list needs to be short and written in advance, or the decision is in practice made by whoever picks the tool.
29Data processing agreementDPA. Sv. personuppgiftsbiträdesavtalThe agreement governing how a vendor may process personal data on your behalf. Without one the data may not be handed over, which makes an AI tool with no DPA unavailable to you at all.
Confused with
The vendor's terms of service. The terms govern the service. The DPA governs the processing and must contain specific points under Article 28(3). A free account usually lacks both the agreement and any way to sign one.
Where it sits
GDPR Article 28. Not in the AI Act, but it is the duty that breaks first when shadow AI appears, and it applied long before the AI Act existed.
Your decision
For which of your AI tools is a DPA signed, and who holds the list? Without the list the answer is in practice no, and it is the simplest check a supervisor makes.
30Substantial modificationSv. väsentlig ändringA change to an AI system extensive enough that the system has to be assessed again. Whoever makes the change can thereby become the provider, with everything that entails.
Confused with
A major update. The test is not the effort but whether the intended purpose or the conformity of the system is affected. Adding one use area can weigh more than rebuilding half the solution.
Where it sits
The definition in Article 3(23), the consequence in Article 25 on when roles and responsibility move along the chain.
Your decision
Who decides in your organisation whether a change is substantial, and is the assessment documented? Made by the development team in passing, you have moved a legal responsibility without a decision.
31Level of autonomySv. autonomigradHow far a system may go without a human approving the next step. A scale from suggestion to execution, and every step up moves responsibility from the caseworker to the organisation.
Confused with
The system's technical capability. The level of autonomy is something you decide, not something the vendor delivers. An agent that can send email does not have to be allowed to.
Where it sits
Autonomy forms part of the Act's own definition of an AI system in Article 3, and the human oversight requirements in Article 14 tighten as the level rises. The Digital Omnibus gave agentic AI its own code in the new Annex XIV, which means notified bodies are now designated for it specifically.
Your decision
What level of autonomy have you actually decided for each system in operation, and is it written down anywhere? Undocumented autonomy always drifts upward, because each individual step feels small.
32General-purpose AI modelGPAIA model usable for many different things and embeddable in other systems. It is regulated separately, in a chapter of its own, with duties sitting on whoever provides the model.
Confused with
An AI system. The model is the component, the system is what you put in users' hands. One system can rest on several models, and the duties travel different routes.
Where it sits
The definition in Article 3(63), the duties in Chapter V with Article 53, in force since 2 August 2025. The duties sit with the model provider, but the information they must pass downstream under Annex XII is what you need for your own documentation.
Your decision
Do you know which models your systems actually rest on? Many business tools swap models without telling you, and documentation built around a named model ages faster than you think.
33Serious incident reportingSv. incidentrapporteringThe duty to report when an AI system has caused serious harm. It depends on somebody internally first recognising the event as an AI incident, which is where it usually breaks.
Confused with
Personal data breaches under the GDPR. Two regimes, different deadlines, different recipients. The same event can trigger both, and neither replaces the other.
Where it sits
Article 73. The report goes to the market surveillance authority in the country where the incident occurred, no later than fifteen days after becoming aware. For a widespread infringement or serious disruption the deadline is two days, for a death ten. The Digital Omnibus added Article 75(1a): for systems under the AI Office's exclusive competence the report goes there instead. In Sweden, penalties still await national legislation.
Your decision
Where does the word AI appear in your incident process today? If it does not appear at all, an AI incident will be handled as a processing error, and the clock starts running without anyone knowing.
34Market surveillanceSv. marknadskontrollThe authorities' supervision of AI systems on the market. In Sweden the responsibility is split across five authorities, and the split follows the point numbers in Annex III rather than sectors.
Confused with
The assumption that your usual sector regulator also becomes your AI regulator. That guess fails. A school and a waterworks have the same AI supervisor, and it is the telecoms regulator.
Where it sits
The market surveillance provisions have applied since 2 August 2026. The Swedish allocation was made by government decision on 4 June 2026, runs to 31 December 2026 and is not a statute. The Digital Omnibus also added Articles 75a to 75d, giving the AI Office its own supervisory powers with exclusive competence over systems built on the provider's own general-purpose model and over systems inside very large online platforms.
Your decision
Do you know which authority is yours, per system? With systems in several Annex III points you probably have more than one, and for systems built on a vendor's own model the answer may be Brussels rather than Stockholm.

Updated when the regulation changes. Last verified against primary sources 8 August 2026.

The words are simple. The allocation is not.

We go through your AI portfolio, classify each system and write down who carries which duty and what it costs. If the honest answer is that you have little to do, we will say so.