The words we use, defined plainly.
Thirty-eight terms from AI ethics, governance, compliance, and safety, explained in our own words. Where a term is drawn from a named external standard, we say so; where it is broader usage, we say that too.
AI ethicist
The named individual inside an organisation who specialises in examining and addressing the ethical implications of its AI systems, testing whether they actually hold up against what the organisation says it values, and escalating when they do not. That means keeping what gets built aligned with fairness, transparency, accountability, and respect for human rights: advising on responsible AI strategy, managing risk around bias and privacy, and keeping the organisation compliant with relevant law and standards along the way. The title varies, but the value work is the same wherever it is done properly: judgement made by one accountable person, not a committee, with the authority and independence to say no and make it stick, which is what actually builds trust and integrity in an AI system, not a policy stating that it should exist.
AI governance
The structures, roles, and decision rights an organisation puts in place to control how it builds, buys, and operates AI systems. Distinct from AI strategy, which is about what to do with AI. On its own, governance is plumbing: necessary, but silent on whether what runs through it is any good. The value work is deciding what that machinery should actually enforce, then making sure it does.
AI governance maturity
How far an organisation’s ethics or governance function has moved from ad hoc (no named owner, no evidence) through informal and defined, to established: a named owner, a charter, an independent reporting line, and evidence that survives being asked a hard question by a board or a regulator. The bands describe capability, not paperwork; an organisation can hold every document and still score low if nobody would actually use them under pressure.
AI literacy
The working knowledge staff need to use, oversee, or be affected by an AI system responsibly. It is the subject of the EU AI Act’s Article 4 obligation, which requires it without specifying how much of it counts as sufficient, which is the gap most of the market is currently guessing at.
AI safety
The work of preventing an AI system from causing serious, often irreversible harm, whether through technical failure, misuse, or an outcome nobody intended. We treat safety as one of the values ethics-for-AI work is built from, not a separate specialism bolted on afterwards.
AI stewardship
The stage after harm reduction. Responsible AI asks how to minimise harm; AI stewardship asks what the system is actually for, and whether that purpose is worth pursuing at all, for the people who will live with it. It judges a system by what it is built to achieve, not only by what it manages to avoid doing wrong.
Algorithmic impact assessment (AIA)
A structured review of an AI system’s likely effects on the people and groups it touches, carried out before or during deployment so foreseeable harms are named and owned rather than discovered after the fact. It is a working document, not a one-off form: it gets revisited when the system or its use changes.
Article 4 (EU AI Act)
The provision of the EU AI Act requiring providers and deployers of AI systems to ensure a sufficient level of AI literacy among their staff and anyone else operating the systems on their behalf. In force since February 2025, it carries no attached benchmark, so organisations have to define and evidence competence and capability themselves.
Board oversight
The board’s active, evidenced engagement with a risk area, distinct from having merely approved a budget for it once. Several of the statistics on this site describe exactly how rare genuine board oversight of AI still is: investment is easy to approve, scrutiny is not.
Compliance
Meeting a specific legal, regulatory, or contractual requirement. Narrower than governance, which is the machinery that makes compliance, and everything an organisation does beyond the legal minimum, possible in the first place.
Compliance officer
The role responsible for an organisation meeting its legal and regulatory obligations. It overlaps with an AI ethicist’s remit but is not the same job: a compliance officer asks whether a rule was followed; an AI ethicist asks whether the outcome is right, including in the many places no rule yet exists.
Conflict of interest (COI) register
A maintained, dated record of interests that could compromise an ethics or governance finding, financial, personal, or professional, disclosed and reviewed before a judgement is made rather than produced defensively after it is challenged.
Coverage and exposure
Whether the AI-related duties an organisation actually carries, assessment, oversight, escalation, documentation, are matched by named people with the competence to carry them. Coverage is what’s matched; exposure is what isn’t. An AI Ethics Coverage & Exposure Review measures the gap, and it is usually wider than the org chart suggests.
Data controller / data processor
GDPR roles: the controller decides why and how personal data is processed; the processor acts only on the controller’s documented instructions. An AI governance finding needs to state which one an organisation is for a given system, since the two carry sharply different obligations.
Data Protection Impact Assessment (DPIA)
The GDPR-specific assessment required before processing likely to result in high risk to individuals’ data rights. Distinct from an algorithmic impact assessment, which looks at a system’s wider ethical and societal effects, not only its data protection risk; the two are often needed together, not interchangeably.
EN 18274
A European Standard from CEN-CENELEC’s Technical Committee JTC 21, defining competence requirements for people working in AI ethics and governance roles. It has passed its final vote and is expected to publish in 2026.
Escalation route (protected disclosure)
A defined path for raising a serious ethical concern about an AI system that does not run through the person who has a reason to suppress it, with protection for whoever raises it. Without one, an AI ethicist’s independence is a claim rather than a fact.
Ethical frameworks (utilitarian, deontological, virtue)
The three lenses that dominate Western AI ethics writing. Utilitarian reasoning judges a system by its net outcomes and asks who is invisible to that calculation. Deontological reasoning judges it by duties and rights regardless of outcome, and treats some protections, dignity, due process, non-discrimination, as non-negotiable. Virtue ethics asks what an organisation of good character would do, and whether it would be proud to explain how the system was built. It is also, not coincidentally, where our own name comes from: virtue is the character question, and voltage is what happens the moment that character meets a live system.
Ethics by design
Building an AI system’s purpose, data, architecture, and governance gates so ethical judgement is engineered in before it ships, not patched on after. Distinct from ethics in use, which is what happens once the system is live; a mature practice needs both, since no amount of upstream design anticipates every context a system will actually meet.
Ethics for AI
The practical work of judging whether an organisation’s structure, culture, and stated virtue actually hold up when its AI systems put them under pressure: assessing whether AI decisions are fair, accountable, and explainable, and building the role, evidence, and escalation route that let an organisation prove that rather than assert it. AI governance, AI compliance, and AI safety are the threads it draws together, not separate disciplines. It is distinct from AI literacy training, which builds general staff awareness, and from certification, which tests individuals against a scheme.
Ethics in use
Monitoring an AI system once it is deployed, escalating what monitoring finds, and feeding it back into the next design cycle, rather than treating launch as the end of the ethical work. Distinct from ethics by design, the upstream half of the same job; a system built well and never watched again still fails, just later.
Ethics theatre
The appearance of ethical practice without the authority behind it: a values statement, a review board, or an audit with no named owner, no reporting line, and no evidence a board or regulator could actually check. Closely related to what the academic literature calls ethics washing, principles that cost nothing and change nothing because nobody has the power to act on them. It is the exact failure mode this practice exists to catch.
Ethics-washing
Adopting the language of ethical review, a title, a policy, a checklist, without the practice that would make a finding survive contact with a deadline or a budget. The same pattern that hollowed out corporate sustainability commitments and diversity statements, now arriving in AI. The structure existing is not evidence against it; what matters is what happens the first time the structure produces an answer nobody wanted.
Governance competence
The group of competences concerned with running the ethics or governance function itself: independence, confidentiality, conflict-of-interest handling, escalation, as distinct from life-cycle competence, which is about applying judgement to a specific system at a specific stage.
Governance, risk, and compliance (GRC)
The umbrella term covering all three functions together, more usually applied enterprise-wide than to AI specifically. We treat governance, risk, and compliance, alongside safety, as values that ethics-for-AI work is built from and puts into practice, not a separate discipline running alongside it.
Human dignity
The specific test of whether an AI decision would still hold up explained face to face to the exact person it affects, not just to a regulator, a board, or whoever is asking on their behalf. Distinct from fairness, which asks whether people were treated consistently with each other, and from transparency, which asks whether reasoning was documented at all: dignity asks whether the person on the other end of the decision was treated as a person, not only processed as a case.
Life-cycle competence
The group of competences concerned with applying ethical judgement at a specific stage of an AI system’s life: design, deployment, audit, or review, as distinct from governance competence, which is about running the function that does that work.
Materiality
The threshold at which an issue is significant enough that it must be escalated, disclosed, or acted on, rather than noted and left. A governance function with no working definition of materiality either escalates everything, and gets ignored, or escalates nothing, and gets blindsided.
Moral responsibility gap
The situation where an AI system causes real harm but no single person or role has a clean claim to being the one responsible, because the decision passed through many hands. In practice, the gap tends to close around whichever named role has a job title and no protected authority, rather than around whoever actually had the power to stop it.
Product Liability Directive (EU) 2024/2853
The recast EU product liability regime, due in national law across Member States by 9 December 2026, which for the first time treats standalone software and AI systems as products subject to strict liability, not only physical goods. Where a claimant faces the technical complexity of an AI system often described as a black box, courts can presume the product was defective and the burden shifts to the organisation to show otherwise, which makes documented risk assessment and decision evidence a liability shield, not only a governance nicety.
Publicity principle
A test for whether a decision is genuinely defensible: would you be willing to explain the reasoning, face to face, to everyone it affects, not only to whoever commissioned it. We apply it as a final check before signing any finding, and a finding that fails it goes back to our own desk before anyone else sees it.
Relational ethical traditions (Ubuntu, Confucian, Buddhist, dharmic)
A family of traditions that put the relationship or the community, rather than the isolated individual, at the centre of the moral question. Ubuntu, the Southern African tradition holding that a person is a person through other persons, asks what a system does to a community’s capacity to trust itself, not only whether one person consented to it. Confucian role ethics and Buddhist accounts of interdependence make a related point: a model is not a discrete artefact, it sits inside a network of the people who labelled it, use it, and live with what it decides. Dharmic traditions add that what is right can be role- and context-sensitive rather than fixed.
Reporting line
Who an AI ethicist or governance lead answers to. It is the single fact that determines whether a role has real authority or is decorative, regardless of title, budget, or how the job description reads. An ethicist reporting to the person who owns the launch date has no independence to exercise.
Responsible AI
The practice of designing and deploying an AI system carefully: testing for bias, documenting limitations, building in safeguards, monitoring after launch. It answers how to build the thing well. It does not answer whether the thing should be built at all, which is the question AI ethics asks first. A system can be built entirely responsibly and still be the wrong system to have built.
Responsible AI / trustworthy AI
Umbrella terms used across UNESCO, OECD, and EU material (with some variation in emphasis) for AI developed and used in line with rights, fairness, transparency, and accountability. Some of the literature now talks about the field moving on again, from Responsible AI toward AI stewardship, and we build our own work to survive that shift rather than needing a rename when it lands.
Shadow AI
AI tools adopted and used inside an organisation without going through any governance, procurement, or risk review, so nobody with oversight responsibility knows they are there. An AI Ethics Coverage & Exposure Review typically surfaces more of this than anyone expected.
Six-question test
A fast diagnostic for whether an AI decision has actually been thought through: who benefits, who is harmed, who decided, who can challenge the decision, at what scale, and whether the person affected would recognise the decision as having treated them as a person, not just processed them. A finding that cannot answer all six in plain language is not finished yet, whatever the paperwork says.
Three lines of defence
A standard governance model: operational management (first line) owns a risk directly; a risk or compliance function (second line) sets policy and monitors it; internal audit (third line) independently tests whether the first two are actually working. Where an AI ethicist sits across these three lines is exactly what a role design engagement resolves.
No terms match that filter.