Reference
AI Governance Glossary
Definitions for the terms that appear in AI law, in governance standards, and in the operating controls behind them, written for people running consumer goods companies.
How to read this page
Regulatory entries state what the rule requires and where it reaches an AI system. Effective dates are given where an obligation has one. Where a term is treated at length in The Governed Enterprise, the entry links to the chapter that covers it.
A
15Accountability
The requirement that every AI system have a named human owner, meaning one identified individual answerable for what the system does, how it performs, and what happens when it fails. Ownership is the element most often missing in consumer goods AI programs, and a system no one owns is a system no one registers, monitors, or stops.
Action Risk
Risk arising from autonomous AI actions that cause financial, operational, or legal harm without per-action human review. It covers unauthorized spend commitments, contractual obligations created by an agent, and pricing behavior that creates antitrust exposure. Action risk is distinct from content risk because the harm occurs before any person reads the output.
Agent
A software process that uses a model to select and carry out steps toward a goal, calling tools, querying systems, and writing to them. An agent differs from a chat assistant in that it holds credentials and takes action against production systems. Because it authenticates as something rather than someone, it raises identity, authorization, and logging questions that user-facing AI does not.
Agentic AI
AI systems able to take autonomous action without per-action human review. These systems commit resources, issue communications, make purchasing decisions, and take other consequential steps within programmed parameters. The distinction from generative AI is the ability to act rather than to produce content that a person then approves.
Aggregation Control
A limit applied to the cumulative effect of many individually authorized AI actions. Per-transaction thresholds do not catch a system that stays under the limit on every action and breaches the intended exposure in total. An aggregation control sets a ceiling on spend, volume, or commitment across a window of time and across counterparties, then halts the system when the ceiling is reached.
AI Governance Council
A standing cross-functional body with defined decision rights and a meeting cadence, responsible for reviewing AI deployments, setting enterprise AI policy, and maintaining oversight of the risk posture. Membership draws at minimum on IT, Legal, Risk, Quality, Operations, Commercial, and HR. Monthly work covers new deployments against risk criteria, changes to running systems, incident investigation, and the risk register; quarterly reporting goes to the board or the audit committee. Authority to approve, modify, or block a deployment is what separates a governing council from an advisory one.
AI Governance Lead
The individual holding primary accountability for an organization's AI governance program, whatever the title. Depending on structure, the role sits with a Chief AI Officer reporting to the CEO or with a VP of AI Risk and Governance reporting to the Chief Risk Officer or the CFO. The Lead owns the AI inventory, chairs or directs the governance council, maintains the risk register, and answers for whether systems operate within approved parameters.
AI Inventory
The register of every AI system operating in the enterprise, recording what each one is, what data it touches, who owns it, and what authority it holds. Most organizations cannot produce a complete one, and the reason usually turns out to be ownership rather than tooling. An inventory that omits AI embedded in already-licensed platforms and AI built by business users is incomplete in the two places it matters most.
AI Literacy
An obligation under Article 4 of the EU AI Act requiring providers and deployers to take measures ensuring a sufficient level of AI literacy among staff and others operating AI systems on their behalf. The obligation applied from February 2, 2025, ahead of most of the Act. It is scaled to the technical knowledge, experience, and context of the people involved, and it reaches any organization deploying AI in the European Union rather than only high-risk deployers.
AI System
The threshold definition in the EU AI Act, covering a machine-based system designed to operate with varying levels of autonomy, that may show adaptiveness after deployment, and that infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions influencing physical or virtual environments. Whether a tool meets this definition determines whether any of the Act's obligations attach to it, which makes classification the first governance question rather than a technicality.
Amazon Business Solutions Agreement (BSA)
The commercial agreement governing the relationship between Amazon and third-party marketplace sellers. Amazon's March 2026 update introduced an Agent Policy requiring companies that use automated tools to manage their seller presence, including repricing software, listing automation, inventory management, and AI-assisted content tools, to have those systems identify themselves as automated agents, comply with defined behavioral parameters, and support kill switch capability that lets Amazon halt their access on demand. Non-compliance carries account suspension. For a brand selling through the marketplace, this is a current contractual obligation rather than a future consideration.
Americans with Disabilities Act (ADA)
Federal law prohibiting discrimination against individuals with disabilities in employment and other areas. Applied to AI, the ADA requires that scheduling, workforce management, and employment decision systems treat documented accommodations as hard constraints rather than as cost variables to minimize. A scheduling system that optimizes around an accommodation violates the ADA whether or not any person intended to discriminate, and the employer cannot transfer that liability to an AI vendor.
Association of American Feed Control Officials (AAFCO)
The body that sets definitions, ingredient standards, nutrient profiles, and labeling requirements for animal feed and pet food. State feed control officials enforce those standards, and violations can trigger FDA feed safety enforcement. For a pet food manufacturer, AI operating in formulation, quality documentation, or labeling creates direct AAFCO obligations. A quality documentation system that auto-populates a guaranteed analysis panel from formulation targets rather than from tested values on finished product breaches AAFCO standards in the same way it would breach FSMA for human food, because the distinction between a modeled value and an analyzed one is legally significant. Logistics systems must also treat cross-contamination requirements as hard constraints rather than as optimization variables.
Automated Decision System (ADS)
A computational process that makes, or substantially assists a person in making, a decision about an individual. Terminology varies by jurisdiction. California uses automated decision system, while Colorado's 2026 law uses automated decision-making technology, defined as technology that processes personal data and uses computation to generate output. A system qualifies whether it runs on machine learning, statistical scoring, or other algorithmic logic. Classification is the threshold question in most state AI employment laws, because notice, anti-discrimination, and in some jurisdictions audit or human-review duties follow once a tool meets the definition. What the system does decides the question rather than how advanced it is.
Audit Trail
The retained record of what an AI system did, on what input, under whose authority, and with what result. An audit trail that captures the output but not the prompt, the retrieved context, the model version, or the acting identity cannot support a finding, a regulatory response, or a root cause analysis. Retention periods are set by the regimes that reach the decision rather than by the platform default.
B
2Business Associate Agreement (BAA)
A contract required under HIPAA between a covered entity, such as a self-funded employee health plan or an occupational health clinic, and a vendor that will handle protected health information on that entity's behalf. The BAA sets the vendor's safeguarding obligations, bars use of the data beyond the contracted service, and defines breach notification. A BAA must be in place before any AI vendor processes data from a HIPAA-covered function, and the agreement alone is not sufficient. The platform also needs zero data retention configured, and some AI features are unavailable under BAA restrictions. Coverage and exclusions vary by vendor and change often, so confirm current scope before enabling AI in wellness, benefits, or occupational health.
Business Email Compromise (BEC)
Fraud in which attackers impersonate executives, vendors, or trusted parties to induce employees to authorize transfers, disclose credentials, or take other harmful action. AI has amplified the risk by making convincing impersonation content cheap at scale and by allowing voice cloning from publicly available audio. The FBI's 2025 Internet Crime Report tracks AI-enabled BEC as a growing category. In consumer goods the two live vectors are impersonation of a CFO to authorize a transfer and impersonation of a procurement contact to redirect supplier payment.
C
16California AI Transparency Act
California legislation, SB 942 as amended by AB 853, requiring covered generative AI providers to make provenance and detection capability available for content their systems produce, and extending related duties to large online platforms and capture devices. Core obligations became operative August 2, 2026, with platform duties phasing later. The consumer goods question it raises is second order: provenance data is now being written into AI-generated content by law, and whether a brand's own publishing pipeline preserves that data through editing, resizing, and syndication is unresolved at most companies.
California ADS Employment Regulations
Regulations issued under the California Fair Employment and Housing Act and effective October 1, 2025, applying the state's anti-discrimination law to automated decision systems used in employment. They make it unlawful to use an ADS that discriminates on a protected basis through disparate treatment or disparate impact, and they extend liability to agents and vendors acting for the employer. Anti-bias testing, including its quality, its scope, and the employer's response to the results, is treated as relevant evidence in a claim or a defense. Records relating to ADS use must be retained, which makes documentation of testing and decision logic a compliance requirement rather than a good practice.
California Consumer Privacy Act (CCPA)
California law establishing the right to know what personal information is collected, the right to deletion, and the right to opt out of sale. It creates data governance obligations for AI processing California resident data, reaching consumer-facing AI in e-commerce, loyalty programs, and customer service. A system that synthesizes consumer data across touchpoints can trigger obligations even where no single data point would do so on its own.
California Privacy Rights Act (CPRA)
The 2020 amendment to the CCPA that expanded consumer protections and created the California Privacy Protection Agency as an independent enforcement body. It added requirements for consent, data minimization, and purpose limitation, a right to correct inaccurate personal information, and expanded restrictions on sensitive personal information. Those categories reach loyalty programs, health-adjacent products, and personalization AI directly. CPRA also extended protections to employees and job applicants in California, which creates obligations for HR AI that surface in system design and in employee privacy notices.
Certificate of Analysis (CoA)
A document certifying that a specific lot was tested and met specification, issued by a supplier or an internal laboratory. It is a record of measurement, which is what makes AI-assisted generation of one a governance question. A system that predicts, infers, or carries forward a value onto a CoA rather than reporting a test result produces a document that reads as evidence and is not.
Chief AI Officer (CAIO)
A C-suite title appearing with increasing frequency in larger enterprises, holding primary executive accountability for AI strategy, governance, and risk. Where the role exists it reports to the CEO and represents the highest-maturity oversight structure. In organizations that have not designated one, accountability rests with a VP of AI Risk and Governance reporting to the Chief Risk Officer or the CFO.
Circuit Breaker
A pre-programmed control that automatically pauses or stops an AI system's autonomous operation when a threshold condition is met. Spend limits, transaction volume caps, and error rate triggers are the common forms. A circuit breaker fires without waiting for a person to notice, which is what distinguishes it from monitoring.
Colorado Artificial Intelligence Act
The first comprehensive state AI statute, enacted in 2024 as Senate Bill 24-205 and substantially rewritten in 2026 by Senate Bill 26-189 before the original took effect. As revised, it regulates automated decision-making technology used to materially influence consequential decisions, including employment, and takes effect January 1, 2027. Deployers owe three duties: clear pre-use notice that ADMT will influence a consequential decision, an adverse-action process giving the affected person a right to correct inaccurate data and a right to meaningful human review where commercially reasonable, and retention of relevant records for at least three years. The 2024 duties to conduct impact assessments, maintain a risk management program, and affirmatively prevent algorithmic discrimination were removed. The attorney general holds exclusive enforcement authority and there is no private right of action. Screening, ranking, and evaluating Colorado candidates and employees fall in scope, while routine scheduling, administrative routing, and clerical tools are expressly excluded.
Co-Manufacturer (Co-Man)
A third-party manufacturer producing product under contract for a brand owner, typically to the brand's specifications and quality standards. AI deployed inside a co-manufacturer's quality, scheduling, or documentation systems sits outside the brand owner's direct control and inside the brand owner's regulatory exposure. When a co-manufacturer's AI quality system misjudges an allergen substitution, it is the brand owner's name on the recall notice.
Conformity Assessment
The process under the EU AI Act by which a high-risk AI system is demonstrated to meet the Act's requirements before it is placed on the market or put into service. Depending on the system, assessment runs through internal control or through a notified body. The obligation falls on the provider rather than on the deployer, which is why a consumer goods company buying a high-risk system asks for the assessment rather than performing it.
Consumer Packaged Goods (CPG)
Products consumed and replaced frequently, spanning food and beverage, personal care and cosmetics, household products, pet food and nutrition, and over-the-counter health. The category matters to AI governance because those five segments answer to different regulatory regimes on the same shelf, and a control designed for one of them may be insufficient for another.
Consumer Product Safety Commission (CPSC)
The federal agency responsible for protecting consumers from unreasonable risk of injury associated with consumer products. It enforces safety standards and recall requirements applicable to household products, durable goods, and packaging. Reporting duties attach when a company obtains information reasonably supporting the conclusion that a product presents a defect or a hazard, which reaches what an AI quality or complaint-triage system knows as much as what a person knows.
Content Provenance
Machine-readable data attached to a media file recording how it was created and edited, including whether a generative model was involved. The C2PA specification is the dominant technical standard. Provenance is becoming a legal artifact rather than a voluntary label, which puts a practical question to any brand with a content pipeline: whether resizing, format conversion, and syndication strip the data before publication.
Content Risk
Risk arising from what an AI system produces rather than from what it does. It covers unsubstantiated product claims, inaccurate regulatory documentation, biased or discriminatory language, and infringing material. Content risk is generally recoverable before publication and generally not recoverable afterward, which is why the control sits at the approval step.
Customer and Consumer PII
A data classification covering consumer names, contact information, purchase history, loyalty data, and the behavioral records built from them. In consumer goods the class is unusually broad because loyalty and e-commerce programs collect at household level over long periods. Classification governs which AI systems may ingest the data and under what retention terms.
Cyberspace Administration of China (CAC)
China's central internet regulator and the primary enforcer of its rules on generative AI services, algorithmic recommendation, deep synthesis, and cross-border data transfer. For a consumer goods company selling into China, CAC requirements reach consumer-facing AI, marketing content generation, and the movement of customer data out of the country. Filing and labeling obligations apply to services offered to the public in China regardless of where the model is hosted.
D
8Deepfake
Synthetic audio, image, or video generated to depict a real person saying or doing something they did not. In an enterprise setting the practical exposure is voice or video impersonation of an executive to authorize a payment or a disclosure, and brand impersonation in fraudulent advertising. Detection is unreliable enough that the durable control is process, meaning out-of-band verification for any instruction that moves money or data.
Data Classification and AI Ingestion Policy
The policy that establishes which categories of company data may be connected to which AI systems, and under what conditions. It is the instrument that turns an abstract data classification scheme into an operating rule an employee and a system can both follow. Without it, the question of whether a given dataset may be pasted into a given tool is answered case by case, which means it is answered inconsistently.
Data Loss Prevention (DLP)
Technical controls that monitor, detect, and in some configurations block the movement of sensitive data out of approved systems. Policy defines what is prohibited and DLP enforces it. A DLP deployment that does not inspect traffic to AI endpoints, browser-based assistants, and AI features embedded in already-licensed platforms enforces the policy everywhere except where it is being breached.
Data Poisoning
An attack in which training data or retrieval sources are manipulated so a model learns or reports something the attacker chose. It can be carried out by a malicious insider or by an external attacker who reaches the data pipeline. Poisoning is difficult to detect after the fact because the model behaves normally except on the inputs the attacker cares about, which is why source integrity controls sit upstream of model testing.
Data Processing Addendum (DPA)
The contract annex governing a vendor's processing of personal data on a customer's behalf, required under GDPR Article 28 and used widely outside the European Union. It sets purpose limits, sub-processor terms, security obligations, transfer mechanisms, and deletion duties. When a vendor introduces an AI feature, the DPA is the document that determines whether customer data may be used to improve the vendor's models, and a change to that answer can arrive as a version update rather than as a signature.
Data Risk
Risk arising from what an AI system is given rather than from what it produces or does. It covers exposure of regulated data, exposure of trade secrets and formulations, retention by a vendor beyond the contracted purpose, and reconstruction of protected information from outputs. Data risk is the category that survives even where a system's outputs are reviewed by a person before use.
Deployer
Under the EU AI Act, a party using an AI system under its own authority in a professional capacity. A consumer goods company is almost always a deployer rather than a provider, which sets a narrower but real set of duties: use in line with the instructions supplied, human oversight assigned to competent people, input data relevance where the deployer controls it, log retention, and notice to affected persons in some categories. Building or substantially modifying a system can move a deployer into provider obligations.
Direct Store Delivery (DSD)
A distribution model in which product moves from the manufacturer or distributor to the retail store, bypassing the retailer's distribution center. Route, order, and merchandising decisions are made close to the shelf and increasingly by software. DSD operators are treated as a defined vendor governance category because AI in their routing and ordering systems commits the brand owner's inventory and touches the brand owner's customer data.
E
9Embedding
A numeric representation of text, an image, or another input, produced by a model so that similar items sit close together in vector space. Embeddings are what make retrieval work, and they are also a data governance object in their own right. An embedding derived from a regulated document is a derivative of that document, so the vector store inherits the classification, the retention rule, and the deletion obligation of its source.
Enterprise Resource Planning (ERP)
Integrated platforms managing core business processes including finance, procurement, inventory, production, and order management. ERP is where an agentic system's actions become financially and legally real, because a posted document is a commitment rather than a recommendation. Master data quality, authorization design, and audit logging in the ERP determine what governance of an agent is even possible.
Environmental Protection Agency (EPA)
The federal agency responsible for environmental protection, and for consumer goods the regulator of pesticidal claims under FIFRA. A household cleaning product that claims to kill germs, sanitize, or disinfect is making a pesticidal claim, which requires registration and permits only the claims the registration supports. An AI copy tool that generates efficacy language for a cleaning product can create FIFRA exposure in a single sentence.
Equal Employment Opportunity Commission (EEOC)
The federal agency enforcing laws against workplace discrimination. Its position is that an employer remains responsible for discriminatory outcomes produced by a selection tool it uses, including a tool built and operated by a vendor. Adverse impact analysis of AI-assisted selection is therefore an employer obligation rather than a vendor courtesy.
Escalation Path
The named route by which an AI issue reaches a person with authority to act on it, including who is contacted, in what time, and what that person is empowered to decide. An escalation path that ends at someone who can raise a concern rather than stop a system is not an escalation path. In incident conditions the useful test is whether the route works at three in the morning on a holiday weekend.
EU AI Act
The European Union's comprehensive AI regulation, classifying systems by risk level with corresponding obligations. Prohibited practices and the AI literacy duty applied from February 2, 2025, general-purpose AI model obligations from August 2, 2025, and Article 50 transparency obligations from August 2, 2026. The Digital Omnibus, Regulation (EU) 2026/1744, entered into force July 27, 2026 and moved the Annex III high-risk obligations to December 2, 2027 and the Annex I obligations to August 2, 2028, leaving Article 50 in place. The Act reaches non-EU companies whose systems or outputs are used in the Union, so a US brand owner can be a deployer under it without operating a European entity.
EU Cosmetics Regulation
Regulation (EC) No 1223/2009, governing the safety, composition, labeling, and claims of cosmetic products in the European Union, supported by common criteria for claim substantiation. It is stricter on claims than US practice, where cosmetic advertising falls under FTC standards rather than FDA pre-market review. A claim generated by an AI tool trained on US marketing copy may be permissible under FTC guidance and impermissible under the EU criteria at the same time, on the same label.
Explainability
The degree to which the basis for an AI output can be described to a person who has to act on it, contest it, or defend it. The operative standard is set by the audience rather than by the technique: a regulator asking why a batch was released, a rejected candidate asking why, and an auditor asking what evidence supports a control all need different depth. Where an explanation cannot be produced, the governance answer is usually to constrain the system's authority rather than to improve the explanation.
Fairness
The principle that an AI system should not produce unjustified differential outcomes across protected groups. Fairness has multiple formal definitions that cannot all be satisfied at once, so the governance work is choosing which definition applies to a given decision and documenting why. In employment and credit contexts the choice is partly made by law rather than left to the organization.
F
6Federal Insecticide, Fungicide, and Rodenticide Act (FIFRA)
The federal statute under which EPA registers pesticides and regulates pesticidal claims. Household cleaning and personal care products that claim antimicrobial efficacy fall within its reach, and the permitted language is bounded by what the registration supports. Marketing AI is the common exposure point, because efficacy phrasing that reads as ordinary copy can constitute an unregistered pesticidal claim.
Federal Trade Commission (FTC)
The federal agency protecting consumers from deceptive or unfair acts and practices, including advertising claims. Its substantiation doctrine requires that a claim be supported by evidence adequate to the claim before it is made, and it has brought actions over both AI-related product claims and unsupported claims produced with AI assistance. A generative tool that writes an anti-aging or clinical claim creates FTC exposure at the moment of publication rather than at the moment of complaint.
Fine-Tuning
Further training of a pre-trained model on a narrower dataset so it performs better on a specific task or in a specific voice. Fine-tuning writes the training data into the model's weights, which means it cannot be reversed by deleting the source file. Any dataset that carries a deletion obligation, a retention limit, or a licensing restriction is therefore a governance decision before it is a modeling decision.
Food and Drug Administration (FDA)
The federal agency regulating food, dietary supplements, cosmetics under MoCRA, over-the-counter drugs, and animal food. Its reach across consumer goods is wide and uneven, which is what makes classification so consequential. A single wellness product can sit under food labeling rules, supplement rules, or drug rules depending on the claim made about it, and an AI system that generates the claim can move the product across that line without anyone deciding to.
Food Safety Modernization Act (FSMA)
The 2011 statute shifting US food safety regulation from responding to contamination toward preventing it, through hazard analysis, preventive controls, supplier verification, and traceability. Its documentation requirements are where AI meets it directly. A record that reports a value the system modeled rather than a value that was measured is a false record under FSMA, whatever the model's accuracy, and the preventive control that catches it has to sit in the documentation workflow rather than in the model.
Fundamental Rights Impact Assessment (FRIA)
An assessment required under Article 27 of the EU AI Act of certain deployers of high-risk AI systems, covering the intended use, the categories of people affected, the risks of harm to them, the human oversight measures in place, and the governance arrangements if a risk materializes. The duty is narrower than the equivalent under privacy law and applies to defined deployer categories rather than to every deployer. It is distinct from a data protection impact assessment and can run alongside one.
G
8General Data Protection Regulation (GDPR)
The European Union regulation establishing comprehensive data protection requirements including lawful basis, purpose limitation, data minimization, and individual rights. Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects. GDPR reaches AI at the point of training data, at the point of inference on personal data, and at the point where a person exercises a deletion or correction right against a system that has already learned from their data.
General Services Administration Regulation (GSAR)
The acquisition regulation supplementing the Federal Acquisition Regulation for GSA contracts. It matters to consumer goods companies selling into federal channels including commissaries and exchanges, because contract clauses on data handling, supply chain security, and increasingly on AI use flow down to the supplier. A federal sales channel can impose AI requirements the commercial business has never had to meet.
General-Purpose AI Model (GPAI)
Under the EU AI Act, a model displaying significant generality and able to perform a wide range of distinct tasks, whatever the way it is placed on the market. Obligations for GPAI providers applied from August 2, 2025 and cover technical documentation, information to downstream providers, copyright policy, and a public summary of training content. Models presenting systemic risk carry additional duties. A deployer buying an application built on a GPAI model inherits the benefit of those disclosures rather than the obligations.
Generative AI
AI systems that create new content including text, images, code, audio, and video, in response to an instruction. The governance profile differs from agentic AI in that a person normally stands between the output and its use, which makes the approval step the control point. That advantage disappears when generated content flows into a system that publishes or files it automatically.
Global Food Safety Initiative (GFSI)
An industry body that benchmarks food safety certification schemes, including SQF and BRCGS, rather than certifying sites itself. Retailer requirements commonly specify a GFSI-benchmarked certification, which makes the scheme requirements contractually binding through the customer relationship even where no statute imposes them. AI in a certified operation is audited against the scheme's requirements for records, verification, and change control.
Goal Drift
The condition in which an autonomous system continues to optimize the objective it was given after that objective has stopped matching what the business intends. The system is working correctly by its own measure while producing results no one would authorize, which is why goal drift is rarely caught by error monitoring. Detection depends on measuring outcomes against business intent rather than against the system's own objective function.
Guaranteed Analysis
The panel on a pet food or animal feed label stating minimum or maximum levels of specified nutrients, enforced against tested values on finished product under AAFCO standards. It is a guarantee rather than an estimate, which is what makes automated population of the panel a regulatory question. A system that fills the panel from formulation targets is reporting what the product was designed to contain rather than what it contains.
Guardrail
A technical filter applied to a model's input or output to block prohibited content, prevent disclosure of sensitive data, or restrict the system to a defined scope. Guardrails are probabilistic and can be circumvented, so they belong in a control set alongside authorization limits and human review rather than in place of them. Described as a control, a guardrail has an owner, a test, and a record of what it blocked.
H
4Hallucination
Output that is fluent, plausible, and false. The governance significance is that a hallucination carries no signal distinguishing it from a correct answer, so detection depends on verification against a source rather than on reading the output carefully. In regulated documentation the exposure is that a fabricated value looks exactly like a measured one on the page.
Hazard Analysis and Critical Control Point (HACCP)
A systematic, science-based preventive approach to food safety that identifies hazards, establishes critical control points, sets limits at those points, and requires monitoring, corrective action, verification, and records. Introducing AI at or near a critical control point changes the monitoring and verification design, because the plan has to specify how the system is validated, what happens when it fails, and who confirms that a limit was met.
Health Insurance Portability and Accountability Act (HIPAA)
Federal legislation establishing privacy and security standards for protected health information. Consumer goods companies encounter it through self-funded health plans, occupational health clinics, and wellness programs rather than through their products. AI deployed in any of those functions requires a Business Associate Agreement with the vendor and configuration that prevents retention of the data.
Human-in-the-Loop (HITL)
An architecture requiring human review, approval, or intervention before an AI output takes effect. It counts as a control only when the reviewer has the information, the time, and the authority to reject, and when rejection is a normal outcome rather than an exception. A reviewer approving a hundred items an hour is providing a record of review rather than review.
I
3Illinois Artificial Intelligence Video Interview Act (AIVIA)
An Illinois law effective in 2020 governing employer use of AI to analyze video interviews. It requires notice to the applicant, an explanation of how the AI works and what it evaluates, consent before use, limits on sharing the recording, and destruction on request within a set period. Illinois separately amended its Human Rights Act to address AI in employment decisions, so an employer hiring in the state faces both.
Inference
The act of running a trained model on an input to produce an output, as distinct from training. The distinction carries contractual weight, because a vendor commitment not to train on customer data says nothing about what is logged, retained, or reviewed at inference time. Both questions have to be asked separately.
ISO/IEC 42001
The international standard specifying requirements for an AI management system, and the first AI governance framework a company can be certified against. Certification demonstrates that a management system exists and operates, which is a different claim from demonstrating that any particular system is safe. Its practical value in consumer goods is as evidence to a customer, an auditor, or a regulator that governance is a running function rather than a document.
K
1Kill Switch
The capability to stop an AI system immediately, together with the named authority to use it. Both halves are required. A technical stop no one is authorized to trigger produces a call chain during an incident, and an authority with no technical mechanism produces a request to a vendor. Survey evidence puts the share of organizations that both hold a documented shutdown process and test it in the low double digits.
L
1Large Language Model (LLM)
A model trained on large volumes of text that generates language, and increasingly other modalities, in response to an instruction. From a governance standpoint the properties that matter are that outputs vary across runs on the same input, that the model has no inherent access to a source of truth, and that its behavior can change when the provider updates it without notice to the customer.
M
7Manufacturing Execution System (MES)
Software that manages, monitors, and controls production on the plant floor, holding batch records, work instructions, and the genealogy that links finished goods to their inputs. AI reaching into an MES touches records that are regulatory evidence, so change control and record integrity requirements apply to the AI the same way they apply to the system it writes into.
Maryland Facial Recognition Interview Law
A Maryland statute prohibiting an employer from using facial recognition technology during an interview without the applicant's signed consent on a prescribed waiver. The consent requirement is specific in form rather than general, which means a broad AI disclosure in an application packet does not satisfy it.
Model Context Protocol (MCP)
An open protocol for connecting AI models to external tools and data sources through a standard interface. It lowers the cost of giving a model reach into enterprise systems, which is a productivity gain and an inventory problem in the same movement. Each connected server is an access path that inherits the credentials it was given, so the governance question is what the connection is authorized to do rather than what the model was asked to do.
Model Card
Structured documentation of a model's intended use, training data characteristics, evaluation results, limitations, and known failure modes. For a company deploying a purchased model, the model card is the closest available substitute for a specification, and its absence is itself a finding in a third-party assessment.
Model Drift
Degradation of a model's performance over time as the world it was trained on diverges from the world it now operates in. In consumer goods the common causes are a reformulation, a new supplier, a packaging change, or a shift in consumer behavior. Drift is gradual and does not raise an error, so it is found by monitoring outcome quality against a baseline rather than by watching the system run.
Modernization of Cosmetics Regulation Act (MoCRA)
The 2022 statute giving FDA expanded authority over cosmetics, including facility registration, product listing, adverse event reporting, safety substantiation, and mandatory recall authority. It moved cosmetics from a category with light federal oversight into one with record-keeping and substantiation duties, which changes what an AI system generating claims or safety documentation is producing.
Monograph (OTC Drug Monograph)
The FDA framework setting permitted active ingredients, concentrations, labeling, and claims for a category of over-the-counter drug. A product formulated and labeled within its monograph may be marketed without pre-market approval, and a departure moves it outside that path. Because the boundary is defined by concentration and by claim language together, AI operating on either one can move a product across it.
N
3NIST AI Risk Management Framework
A voluntary framework published by the National Institute of Standards and Technology, organized around four functions: govern, map, measure, and manage. It is not certifiable and imposes no obligation, which makes it useful as a structure for an internal program and weak as evidence to a third party. A Generative AI Profile extends it to that class of system.
New York City Local Law 144
A New York City law in effect since July 2023 requiring that an automated employment decision tool used to screen candidates or employees for a position in the city undergo an independent bias audit within the prior year, that a summary of the audit results be published, and that candidates receive notice before use. The audit is annual rather than one-time, and the publication requirement makes non-compliance visible from outside the company.
Non-Human Identity (NHI)
A credential belonging to a service, a workload, or an agent rather than to a person, including service accounts, API keys, tokens, and certificates. Agentic AI multiplies these, and they are often created outside the joiner-mover-leaver process that governs human accounts. The governance questions are ownership, scope, rotation, and revocation, and an inventory that covers people but not workloads answers none of them.
O
4Occupational Safety and Health Administration (OSHA)
The federal agency setting and enforcing workplace safety standards. AI reaches OSHA obligations through scheduling and workload systems that can push staffing below safe levels, through computer vision safety monitoring that creates records of observed hazards, and through autonomous equipment on the plant floor. A system that records a hazard creates knowledge the employer is then expected to have acted on.
Operational Secrets
A data classification covering formulations, specifications, supplier terms, cost structures, pricing models, and production plans. The class is restricted to approved internal AI systems under contract terms that prohibit retention and training. Consumer goods companies carry unusually high exposure here because a formulation is often the whole of the competitive advantage.
Operational Technology (OT)
Hardware and software that monitor and control physical processes and equipment, including plant floor control systems, process historians, and building systems. OT environments run on long lifecycles, tolerate downtime poorly, and were designed before network exposure was assumed. AI introduced into that environment inherits those constraints, and a control that assumes a system can be patched or restarted on demand does not survive contact with a production line.
Override Protocol
The defined procedure by which a person overrides an AI decision, recording who overrode it, on what authority, and why, against a logged reason code. The reason code is what turns overrides into evidence, because a pattern of overrides on one condition is the earliest available signal that a model has drifted or that its objective no longer matches the business. Overrides that are permitted but not recorded produce neither accountability nor data.
P
8Personally Identifiable Information (PII)
Information that identifies an individual, alone or in combination with other available data. The combination clause is what matters for AI, because a system that joins purchase history, location, and household composition can produce an identification from inputs that were individually non-identifying. Classification therefore attaches to what the system can derive rather than only to what it was given.
Post-Market Monitoring
The EU AI Act duty on providers of high-risk systems to collect and analyze performance data after a system is in use, and to act on what it shows. The parallel for a deployer is the internal obligation to monitor a system it did not build, since the provider's monitoring covers the product rather than the deployment. Where a system is deployed in a way the provider did not anticipate, only the deployer is positioned to see the drift.
Pre-Authorization
The practice of defining in advance the actions an autonomous system may take without further approval, expressed as bounded conditions rather than as a general permission. Pre-authorization scales where per-action review does not, and it fails where the boundaries were written against transactions rather than against cumulative exposure.
Prompt Injection
An attack in which instructions are placed in content the model will read, causing it to act on the attacker's instruction instead of the operator's. The indirect form is the one that reaches consumer goods, where the malicious text arrives inside a supplier document, an email, a product review, or a web page the system retrieves. Because a model has no reliable way to separate instruction from data, the durable controls are limiting what the system is authorized to do and validating its actions rather than filtering its inputs.
Proprietary Intellectual Property
A data classification covering owned material whose value depends on control: brand assets, product designs, licensed content, source code, and creative work under contract. AI raises two distinct questions against it. Whether company IP may be submitted to a third-party system, and whether output generated from that system can itself be owned or is encumbered by the terms under which it was produced.
Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a HIPAA covered entity or its business associate. In consumer goods it appears in self-funded health plans, occupational health records, and some wellness programs. PHI may not enter an AI system without a Business Associate Agreement in place and retention disabled.
Provider
Under the EU AI Act, a party that develops an AI system or has one developed and places it on the market or puts it into service under its own name or trademark. Providers of high-risk systems carry the heavier obligations, covering risk management, data governance, technical documentation, logging, accuracy and robustness, conformity assessment, and post-market monitoring. A deployer that puts its own name on a system, or substantially modifies one, can become a provider without intending to.
Prompt, System
The standing instruction supplied to a model ahead of user input, defining its role, its scope, and its constraints. A system prompt is configuration rather than code in most deployments, which means it often sits outside change control while doing the work of a control. Where it encodes a compliance boundary, it belongs under version control with a documented approver.
R
4Red-Teaming
Structured adversarial testing in which a team attempts to make an AI system produce prohibited output, disclose protected data, or take unauthorized action. It differs from quality testing in that the objective is failure rather than accuracy, and it differs from a penetration test in that the attack surface includes the model's behavior rather than only the infrastructure. Findings are useful only where there is a route for them to change the deployment.
Regulated Data
A data classification covering records that a regulator can compel, inspect, or act on, including batch records, test results, safety documentation, label substantiation, and financial records under SOX. Regulated data requires human review before AI output is used in any regulatory submission or record, because a system that infers a value produces a document that reads as evidence and is not one.
Retrieval-Augmented Generation (RAG)
An architecture in which relevant documents are retrieved at query time and supplied to the model as context, rather than being trained into it. RAG is generally the better governance answer because sources can be permissioned, updated, and deleted, and outputs can be traced to a document. It introduces its own exposures: the retrieval index inherits the classification of what it indexes, and retrieved content is a route for indirect prompt injection.
Risk Tier
The classification that determines what approval, testing, and oversight a given AI deployment requires, so that a low-consequence tool does not consume the review a consequential one needs. Tiering is what makes a governance council workable at scale, since it defines which decisions reach the council and which stay with the business unit. Tiers are set by consequence of failure rather than by technical sophistication.
S
13Safe Quality Food (SQF)
A GFSI-benchmarked food safety and quality certification scheme administered by FMI, widely required by retailers as a condition of supply. Certification is audited against documented systems, so AI introduced into a certified process becomes an auditable element: its validation, its change control, and the records it produces all fall inside the audit scope.
Safety
The principle that an AI system should not cause physical, financial, or legal harm to consumers, employees, or the business. In consumer goods the physical dimension is concrete rather than abstract, since AI touches formulation, allergen management, batch release, and equipment control. Safety is assessed against what the system can cause rather than against what it was designed to do.
Safety and Compliance Risk
Risk arising where AI touches a process governed by a safety or regulatory regime, including batch release, allergen control, label generation, and adverse event handling. It is separated from general operational risk because the consequence includes recall, enforcement action, and criminal exposure for responsible individuals rather than cost alone.
Sarbanes-Oxley Act (SOX)
The 2002 statute requiring public companies to maintain and attest to internal control over financial reporting. AI operating in accounting, procurement, revenue recognition, or close processes sits inside that control environment, which means its design, its access, its change control, and its evidence trail are in scope for the audit. An AI system that posts entries without a testable control around it is a control deficiency waiting to be documented.
Secretariat of Anti-Corruption and Good Governance (SABG)
The Mexican federal authority that enforces personal data protection obligations for the public sector and holds a role in the current data protection enforcement structure following the reorganization of the previous regulator. Companies with Mexican operations or Mexican consumer data should confirm the current enforcement authority and its guidance before relying on prior arrangements.
Serious Incident
Under the EU AI Act, an incident or malfunction of an AI system leading directly or indirectly to death or serious harm to health, serious and irreversible disruption of critical infrastructure, breach of obligations intended to protect fundamental rights, or serious harm to property or the environment. Providers of high-risk systems must report to the market surveillance authority within defined deadlines, and deployers have a duty to inform the provider. Meeting that deadline requires an internal detection and escalation route that already exists when the incident occurs.
Shadow AI
AI in use inside the enterprise that never passed procurement, architecture review, or change management. It arrives three ways: embedded in software already licensed, signed up for by an employee, and built by a business user with an AI coding assistant. Enforcement alone drives it further out of view, which is why an amnesty and registration program with a defined window and a small set of registration questions surfaces more than a prohibition does.
Spend Authority Matrix
The document defining what financial commitment each role and each system may make without further approval. Extending it to autonomous systems is where most organizations find the gap, because a matrix written for people assumes a human judgment behind every transaction and sets per-transaction limits accordingly. An agent operating inside those limits can commit an amount no person at any level was authorized to commit.
Stock Keeping Unit (SKU)
The unique identifier for a distinct sellable item, at the level of size, flavor, formulation, and pack configuration. Governance failures surface at SKU level, where a demand model that performs well in aggregate can be badly wrong on individual items, and where an allergen, a regulatory classification, or a claim attaches to one variant and not to its siblings. Monitoring that reports only portfolio accuracy will not see it.
Sub-Processor
A third party engaged by a vendor to process customer data on the vendor's behalf. AI features commonly introduce new sub-processors, since a platform may route requests to a model provider it does not own. Most agreements permit sub-processor changes on notice rather than on consent, so the practical control is monitoring the vendor's published list rather than relying on the contract to hold the position.
Substantial Modification
A change to an AI system after it has been placed on the market that was not foreseen in the provider's initial assessment and that affects compliance or alters the intended purpose. The concept matters to a deployer because making one can transfer provider obligations onto the company that made the change. Fine-tuning a purchased model, repurposing a system for a use the provider did not contemplate, or rebranding it can each raise the question.
Synthetic Content Marking
The requirement that AI-generated or manipulated content be marked in a machine-readable way and, in some cases, disclosed to the person encountering it. Article 50 of the EU AI Act imposes it on providers of generative systems and imposes separate disclosure duties on deployers in defined cases, and the California AI Transparency Act imposes a parallel US requirement. For a brand, the operational question is whether marking survives the content pipeline from generation to publication.
Systemic Risk
A designation under the EU AI Act for general-purpose AI models with high-impact capabilities, carrying additional provider obligations covering model evaluation, adversarial testing, incident tracking, and cybersecurity protection. The designation attaches to the model rather than to any application built on it, so a deployer's interest is in knowing whether the model underneath a purchased product carries it.
T
5Technical Documentation
The record a provider of a high-risk AI system must prepare before placing it on the market and keep current, covering the system's design, its development process, its data, its testing, and its risk management. A deployer cannot produce it and should not try. What a deployer can do is require access to it during procurement, since its absence is a signal about whether the vendor has assessed the system at all.
Texas Responsible AI Governance Act (TRAIGA)
Texas legislation enacted in 2025 regulating the development and deployment of AI systems, with obligations centered on intentional harmful uses, disclosure in defined contexts, and government use, and with enforcement by the attorney general following a cure period. Its structure differs from Colorado's in resting more on intent than on risk classification, which means a Texas analysis does not follow from a Colorado one.
Third-Party Logistics Provider (3PL)
An external company contracted to manage some or all of a brand owner's warehousing, transportation, and fulfillment. AI in a 3PL's routing, slotting, or temperature management systems affects product the brand owner is legally responsible for, and the visibility a brand owner has into those systems is set by the contract rather than by the risk. Cold chain and allergen segregation are where the exposure becomes concrete.
Traditional AI
Predictive and classification systems built for a defined task, including demand forecasting, quality inspection, and route optimization. These systems have been running in consumer goods for years under normal IT governance, and their outputs are testable against measured outcomes in a way generative outputs are not. Much of the current governance gap comes from treating the newer classes as though they behave like this one.
Transparency
Disclosure that AI is in use, to the people affected by it and to the parties who need it. Requirements differ by audience and by jurisdiction, covering candidates in employment, consumers in advertising and service interactions, and business customers in contract terms. Transparency is a disclosure obligation and explainability is a capability, and satisfying one does not satisfy the other.
U
2United States Department of Agriculture (USDA)
The federal department overseeing agriculture, and through FSIS the regulator of meat, poultry, and egg products, including label pre-approval for those categories. The pre-approval requirement is what distinguishes it from FDA-regulated food for AI purposes, since a label generated or modified by a system enters an approval process rather than a self-certification one. USDA also administers the organic program, where claim substantiation is documentary.
Utah Artificial Intelligence Policy Act
Utah legislation, effective in 2024 and amended since, addressing disclosure of generative AI use in consumer interactions and confirming that existing consumer protection law applies to conduct carried out through AI. Its central holding is that a company cannot defend a deceptive statement on the ground that a model produced it, which is the position most consumer protection regimes are converging on.
V
1VP of AI Risk and Governance
The governance leadership role as it appears in organizations that have not created a Chief AI Officer, reporting to the Chief Risk Officer or the CFO. The reporting line places AI governance inside the existing risk function rather than alongside the technology organization, which tends to strengthen independence and weaken proximity to the systems being governed.
Z
1Zero Data Retention
A configuration in which a vendor does not store inputs or outputs after a request is served, beyond what is needed to return the response. It is normally a setting or a contract term rather than a default, and it is often unavailable on lower service tiers. Zero retention is required before regulated data, protected health information, or operational secrets reach a third-party system, and the setting is confirmed on the account rather than assumed from the marketing page.
No term matches that search. Try a shorter word, or clear the filter.
On these definitions
Definitions are written for people who have to apply a rule rather than cite one. Where a term carries a formal legal definition, the entry says which instrument supplies it. Regulatory effective dates change, and an entry describing an obligation is a starting point for a decision rather than legal advice. See the disclaimer.
Related
AI Governance Regulatory Record, a tracked account of the laws, rules, and court rulings reaching consumer goods companies that use AI. AI use cases and controls, organized by function. Chapter reference for The Governed Enterprise.
Maintained by Robin Horstmann, author of The Governed Enterprise: An AI Governance Playbook for Consumer Goods. Terms drawn in part from the book's glossary and expanded to cover instruments outside it. Last reviewed September 2026.