Glossary

The 29 terms the framework documents use, each defined once. This is the package's own glossary, printed here as it appears in the appendix of Document 1; each term links to itself, so its address can be copied.

AI-SAF / AI-SAF-C / AI-SAF-N
The AI Strategic Autonomy Framework and its business and national variants; eight shared pillars at different weights; AI-SAF-C adds a ninth (Culture).
Base model
A large language model trained from scratch on trillions of tokens (GPT, Claude, Gemini, Gemma, Llama, DeepSeek, Qwen).
Branch-and-Merge
INSAIT’s training method (EMNLP 2024) for adapting a model to a new language without catastrophic forgetting.
CADA / Cloud Sovereignty Framework
The EU Cloud and AI Development Act (proposed 3 June 2026); its Cloud Sovereignty Framework grades cloud services on four assurance levels, from EU data location (L1) to full supply-chain control free of third-country interference (L4).
Capability × commitment
Splitting every sub-score into what is actually in place today versus what has been promised.
Chokepoint exposure
Vulnerability at the make-or-break steps of the chip supply chain (EUV lithography, leading-edge logic, HBM, EDA software, key chemicals).
CLOUD Act
The US Clarifying Lawful Overseas Use of Data Act (2018), authorising federal access to data held abroad by US companies.
CUDA
NVIDIA’s software layer for its chips; the de facto standard for AI training and the main switching barrier away from NVIDIA.
Data Act Chapter VII
The EU Data Act provisions (fully applicable September 2025) aimed at third-country access.
Data egress
The flow of a subject’s own data out to a third-party model at inference time — prompts, retrieved context, tool calls, fine-tuning sets, logs.
Digital Omnibus on AI
The EU amending package (in force 27 July 2026) deferring the AI Act’s high-risk obligations to December 2027 / August 2028 while leaving GPAI enforcement on schedule.
DORA
The EU Digital Operational Resilience Act for the financial sector, applicable from January 2025.
FRIA
Fundamental Rights Impact Assessment, AI Act Article 27.
GAIA-X
European certification of cloud and data services against sovereignty criteria at three levels; L3 requires SecNumCloud-grade immunity from foreign-reach laws.
ISA
Instruction Set Architecture — the command set a processor understands (x86, ARM, RISC-V).
ISO/IEC 42001
The certifiable international AI-management standard (December 2023); nine Annex A control groups; a stepping stone to AI Act Articles 53/55.
MoE
Mixture of Experts — a model design activating different specialist sub-models per input.
MRM / SR 11-7
Model Risk Management; the US supervisory standard widely adopted in EU banking — challenger models, monitoring, model inventory, documentation.
NIST AI RMF
The US AI risk-management framework (Govern, Map, Measure, Manage); backbone of the AI-SAF-C crosswalk.
No-train clause
A contract clause barring a model provider from using your inputs or outputs to train its models.
Open-weights
A model whose trained weights can be freely downloaded and run (Llama, Mistral, Gemma, Qwen, DeepSeek); not always fully open-source.
Restoration risk
The error of reading a supplier-side reversal (a lifted directive, an extended support window) as evidence of the subject’s own recoverability. See Framework §3.5.
RISC-V
An open, royalty-free ISA; the strategic alternative to x86 and ARM (Tenstorrent, EU DARE, Meta MTIA).
SecNumCloud
France’s ANSSI certification (v3.2) — the established scheme requiring a cloud service to be beyond the reach of foreign laws such as the CLOUD Act and FISA.
Strategic interdependence
Deliberately depending on several partners so no single one can dictate — the realistic alternative to autarky for small and mid-sized economies.
Synthetic collapse
The effect shown by Shumailov et al. (Nature, 2024): repeatedly training on AI-generated data permanently strips away rare cases.
TEE
Trusted Execution Environment — hardware-isolated execution (Intel TDX, AMD SEV-SNP, NVIDIA Confidential Computing) enabling private inference on clouds you do not control.
Version Deadlock
The state in which a subject loses the capacity to evolve technologically because access to the next version of a key technology has been interrupted.
vLLM / SGLang / llama.cpp
Open-source inference engines; alternatives to NVIDIA’s TensorRT-LLM that run models without CUDA dependence.