AI Security Glossary
Explore definitions of the most important AI security, governance, and compliance terms in one place.
A2A
An A2A server is a specialized web server that hosts an AI agent and implements the A2A protocol by exposing standard HTTP and JSON-RPC endpoints. This allows other AI agents to discover its capabilities, exchange information, and collaborate on tasks across different frameworks. Because it exposes agent functionality to other systems, it can introduce security risks such as unauthorized access, sensitive data exposure, and limited visibility into agent interactions.
Accountability
Accountability is the principle that organizations remain responsible for the behavior, outputs, and business impact of AI systems, regardless of whether they’re developed internally or provided by third-party vendors. It requires clear ownership, documented governance decisions, and enforceable security controls throughout the AI system’s lifecycle.
Adversarial Attack
Adversarial attacks are malicious techniques designed to manipulate AI applications, prompts, models, outputs, or connected workflows. They can cause unintended behavior, expose sensitive data, bypass security controls, or trigger unauthorized actions across AI systems.
Agentic AI
Agentic AI refers to AI systems that can independently plan, make decisions, use tools, retrieve information, and execute multi-step tasks to achieve a goal with limited human intervention. Unlike traditional AI systems that generate responses to prompts, agentic AI can take actions across applications, enterprise data, APIs, and business workflows, introducing new security, governance, and compliance challenges that require continuous visibility and control.
AI Agent
An AI agent is an AI system that can make decisions, use tools, interact with data and systems, and execute multi-step workflows with varying levels of autonomy. As AI agents become more autonomous, organizations need visibility into their actions, permissions, connected systems, and workflows to identify risks, enforce governance, and prevent threats.
AI Agent Skills
AI agent skills are modular instruction sets, workflows, and scripts that extend an AI agent’s capabilities and enable it to perform specialized tasks. Because they can operate within the agent’s permission scope, compromised or malicious skills may introduce risks such as prompt injection, unauthorized actions, hidden instructions, and data leakage.
AI Assistants
AI assistants are AI-powered tools that help employees complete tasks such as generating content, summarizing information, answering questions, analyzing data, or supporting business workflows. They may access enterprise data, applications, and third-party services, creating risks related to sensitive data exposure, shadow AI, inaccurate outputs, unauthorized access, and compliance breaches.
AI Attack Surface
The AI attack surface includes the AI applications, agents, coding assistants, AI agent skills, MCP servers, models, prompts, integrations, endpoints, users, and connected systems that may introduce security risk. As organizations adopt more AI tools and connect them to enterprise data and systems, the attack surface expands, creating additional opportunities for unauthorized access, data exposure, policy violations, and malicious activity.
AI DLP
AI DLP is the practice of protecting sensitive information from exposure through AI prompts, outputs, applications, agents, and connected tools. It includes detecting sensitive data and applying redaction, blocking, or other policy-based restrictions to reduce the risk of unauthorized disclosure through AI usage.
AI Ecosystem
An enterprise AI ecosystem includes all AI applications, systems, agents, models, tools, integrations, users, and data flows across the organization. This includes public GenAI applications, homegrown AI applications, coding assistants, autonomous AI agents, embedded AI, MCP servers, AI agent skills, and third-party AI services. Securing the AI ecosystem requires full visibility into how these components interact with enterprise data, tools, and systems.
AI Inventory
An AI inventory is a centralized record of enterprise AI tools, applications, agents, MCP servers, models, coding assistants, AI agent skills, users, workflows, integrations, and data flows. It should also include each asset’s purpose, owner, permissions, connected systems, usage, and risk classification. Building a complete and reliable AI inventory requires a robust discovery engine that can continuously identify AI assets and activity across the enterprise.
AI Policy
An AI policy is a set of organizational rules and guidelines that define how AI technologies can be used securely, responsibly, and in compliance with business and regulatory requirements. An effective AI policy establishes approved AI tools, acceptable use, data handling requirements, governance responsibilities, and security controls to help reduce risks such as shadow AI, sensitive data exposure, compliance violations, and unauthorized AI usage.
AI Risk Classification
Categorizing AI applications and activity according to factors such as data sensitivity, permissions, compliance impact, business use, and potential security exposure.
AI Security and Governance Framework
An AI security and governance framework gives organizations a structured way to secure and manage AI across the enterprise. It's built on four core practices: discover AI usage, detect risks and policy violations, govern AI activity, and prevent threats before they cause damage. Together, these capabilities provide visibility into the enterprise AI environment, support continuous monitoring and regulatory compliance, and enable proactive risk mitigation and remediation. Organizations can't govern AI they can't see or prevent threats they're not detecting.
AISP
An AI Security Platform (AISP), as defined by Gartner, is a consolidated platform that centralizes security controls across third-party AI services and custom-built AI applications. It provides visibility, governance, policy enforcement, and protection across the enterprise AI ecosystem.
AI Sprawl
AI sprawl is the uncontrolled growth of AI applications, agents, coding assistants, embedded AI, MCP servers, AI agent skills, models, and third-party AI tools across the enterprise. As AI adoption expands without centralized visibility and governance, organizations can lose track of what AI is being used, who owns it, what data and systems it can access, and which risks it introduces. Managing AI sprawl requires continuous discovery, a complete AI inventory, risk classification, and consistent policy enforcement.
AI TRiSM
AI TRiSM is a framework developed by Gartner for managing AI trust, risk, security, governance, and compliance. It helps organizations establish oversight and technical controls across the AI lifecycle to improve reliability, fairness, transparency, data protection, and resilience against threats such as prompt injection, data poisoning, and other adversarial attacks.
Autonomous Business
An autonomous business uses AI-powered systems and agents to automate decision-making, execute business processes, and continuously optimize operations with minimal human intervention. It depends on continuous governance, security, compliance, and operational integrity to ensure autonomous systems remain trustworthy and under control.
Autonomous System
Autonomous systems are AI-driven systems that make decisions, execute actions, and continuously improve with limited human intervention. They form the foundation of the autonomous business and require continuous visibility, governance, and security controls to operate safely and reliably.
Coding Agents
Coding agents are AI systems that can plan and complete software development tasks with limited human intervention. Beyond generating code, they may inspect repositories, modify files, run commands, use developer tools, and execute multi-step workflows. Their ability to take actions introduces risks such as insecure code changes, excessive permissions, secret exposure, unauthorized tool use, and policy violations.
Coding Assistants
Coding assistants are AI tools that help developers generate, review, explain, or modify code within the development environment. They can improve productivity, but may also expose source code, credentials, intellectual property, or sensitive business data. Organizations need visibility and policy enforcement to manage how these tools access code, data, and enterprise systems.
Compliance Breaches (AI)
Compliance breaches occur when AI applications, AI agents, or AI users violate regulatory requirements, industry standards, or internal organizational policies. These breaches can result from unauthorized AI usage, sensitive data exposure, inadequate governance, insecure AI configurations, or the use of unapproved AI tools, increasing legal, financial, and reputational risk.
Data Exposure
Sensitive information being accessed, processed, shared, or revealed through AI prompts, outputs, agents, applications, or connected systems without adequate controls.
Discovery (AI)
AI discovery is the process of identifying AI applications, agents, coding assistants, users, workflows, and interactions across the organization. It establishes visibility into approved and unapproved AI usage, reduces security blind spots, and provides the foundation for AI inventory, risk assessment, governance, and policy enforcement.
Embedded AI
Embedded AI refers to artificial intelligence capabilities integrated directly into software, SaaS platforms, business applications, or devices. Because these capabilities may operate within tools already used across the organization, they can introduce hidden AI usage, sensitive data exposure, third-party risk, and governance gaps without clear visibility or security controls.
Endpoint Security (AI)
The practice of discovering, monitoring, governing, and controlling AI applications, coding assistants, AI agents, and other AI technologies running on enterprise-managed employee devices to reduce AI-related security risk.
Enterprise AI Security
Enterprise AI security is the practice of discovering AI usage, identifying and classifying risks, governing AI activity, and preventing threats across the enterprise AI ecosystem. It covers public GenAI tools, homegrown AI applications, coding assistants, embedded AI, autonomous agents, MCP servers, skills, models, data, integrations, and workflows. Effective AI security requires continuous visibility, policy enforcement, data protection, and runtime controls to address risks such as shadow AI, prompt injection, sensitive data exposure, insecure actions, compliance violations, and excessive agency.
EU AI Act Compliance
EU AI Act compliance is the process of ensuring AI systems meet the governance, transparency, risk management, and security requirements established by the European Union's AI Act. It requires organizations to implement appropriate policies, oversight, documentation, and technical controls to support the safe, responsible, and compliant development, deployment, and use of AI across the enterprise.
Excessive Agency
Excessive agency is the risk that an AI agent is granted more autonomy, permissions, or decision-making authority than intended. This can allow the agent to access enterprise systems, interact with sensitive data, execute workflows, or take actions beyond its approved business purpose, increasing operational, security, and compliance risk.
Governance (AI)
AI governance is the policies, controls, oversight, and accountability used to ensure AI is adopted securely, responsibly, and in line with organizational and regulatory requirements. It requires visibility into AI usage, clear ownership, continuous risk management, and policy enforcement across AI applications, agents, tools, and workflows.
Guardrails (AI)
AI guardrails are policy-based controls that keep AI systems operating within their intended boundaries. They help prevent unsafe or unauthorized behavior by enforcing restrictions on prompts, model outputs, tool usage, data access, and AI agent actions. Organizations use AI guardrails to reduce risks such as prompt injection, sensitive data exposure, policy violations, excessive agency, and compliance breaches while enabling the safe adoption of AI.
Hallucination
A hallucination occurs when an AI model generates false, inaccurate, or fabricated information while presenting it as factual. In enterprise environments, hallucinations can lead to poor decisions, compliance violations, security risks, and the spread of inaccurate business information.
HIPAA AI
HIPAA AI refers to the use of AI in environments where Protected Health Information (PHI) is processed, stored, or accessed. Organizations need visibility into which AI applications, agents, and tools handle PHI and must enforce appropriate access controls, encryption, audit logging, data-handling policies, and vendor requirements. Relevant AI vendors must sign a Business Associate Agreement (BAA), and standard consumer AI tools shouldn’t process PHI unless they’re configured, governed, and contractually approved for HIPAA-compliant use.
HITL
HITL is a governance model that requires a person to review and approve AI outputs before consequential actions are taken. It helps reduce operational, security, and compliance risks by adding human oversight before an AI system’s decision or recommendation is executed.
Homegrown AI Apps
Homegrown AI applications are developed internally to improve productivity, automate business processes, and deliver better customer experiences. They can retrieve enterprise data, connect to internal APIs, external tools, plugins, MCP servers, SaaS platforms, and business systems, and execute actions or trigger workflows. This introduces risks such as prompt injection, sensitive data leakage, insecure integrations, compliance violations, and excessive agency. Traditional application security tools aren't designed to address these AI-specific security challenges, which require continuous visibility, governance, and security throughout the application lifecycle.
Hooks
Hooks are predefined triggers that execute logic before, during, or after an AI agent performs an action, invokes a tool, or completes a workflow step. They can be used to validate inputs, transform data, enforce policies, or apply security controls, making them an important part of understanding and governing agent behavior.
HOTL
HOTL is a governance model in which AI systems operate autonomously while humans monitor performance and retain the ability to intervene, override, or stop the system when necessary.
Human-over-the-Loop
Human-over-the-loop is a governance model for lower-risk AI systems in which humans define policies and performance thresholds, monitor outcomes through periodic reviews, and intervene when the system operates outside those established parameters.
Indirect Prompt Injection
An indirect prompt injection attack occurs when malicious instructions are embedded in external content, such as a document, email, website, or data source, that an AI application or agent retrieves and processes. These instructions can manipulate the system into ignoring its intended behavior, exposing sensitive data, or performing unauthorized actions.
Jailbreaking
A jailbreak is a technique used to manipulate an AI model or application into bypassing its safeguards or restrictions. It can cause the system to generate unauthorized or unsafe outputs, ignore intended policies, disclose sensitive information, or perform unintended actions.
License Compliance (AI)
Ensuring employees use approved licensed business AI accounts instead of unmanaged personal accounts that fall outside organizational oversight.
LLM
LLM is an AI model trained on large datasets to understand, process, and generate human language. LLMs power many GenAI applications, AI assistants, coding tools, and AI agents, enabling tasks such as answering questions, summarizing content, generating code, and supporting multi-step workflows.
MAS
MAS is an architecture in which multiple AI agents interact, collaborate, or compete to accomplish tasks. MAS introduces security risks beyond those of individual agents, including malicious instructions spreading among agents, compromised trust relationships, and new attack surfaces across A2A interactions.
MCP Security
MCP security is the practice of protecting AI systems that use MCP servers to connect with enterprise data, tools, APIs, business systems, and external services. It helps secure access, permissions, data flows, and tool interactions while reducing risks such as unauthorized actions, sensitive data exposure, malicious instructions, and insecure integrations.
NIST AI RMF
The NIST AI RMF is a voluntary framework that helps organizations identify, assess, govern, and manage AI-related risks throughout the AI lifecycle. It provides guidance for establishing trustworthy AI through governance, risk management, and continuous oversight.
Operational Integrity (AI)
AI operational integrity is the ability to ensure AI systems operate securely, reliably, and in accordance with organizational policies throughout their lifecycle. It combines continuous visibility, governance, security controls, and oversight to maintain trustworthy AI operations.
OWASP Top 10 for LLM Applications
The OWASP Top 10 for LLM Applications identifies the most significant security risks affecting applications powered by LLMs, including prompt injection, sensitive information disclosure, excessive agency, insecure output handling, and supply chain vulnerabilities. It provides security best practices for designing, building, and operating secure AI applications.
Process-Level Visibility
Process-level visibility provides visibility into complete AI workflows rather than isolated actions. It connects how AI agents make decisions, interact with systems and data, and execute multi-step workflows to reveal intent, identify risk patterns, enforce governance, and proactively prevent threats before they escalate. Process-level visibility enables organizations to apply out-of-the-box preventive policies and predictive security controls across the entire AI ecosystem.
Prompt Injection
A prompt injection attack uses malicious instructions to manipulate an AI model or application, override its intended instructions, alter its behavior, expose sensitive data, or trigger unauthorized actions. These instructions may be entered directly by a user or introduced through external content the AI system processes.
Real-Time AI Protection
Real-time AI protection continuously monitors AI applications and agents while they're operating and enforces security controls as actions occur. It's critical because AI systems can make decisions, access data, use tools, and execute workflows in seconds, leaving little time for manual intervention. Real-time protection enables organizations to immediately detect and prevent threats, policy violations, sensitive data exposure, and unauthorized actions before they cause damage to the business.
Red Teaming (AI)
AI red teaming is a structured security testing methodology that evaluates AI systems by simulating attacks such as prompt injection, jailbreaking, model extraction, and data leakage to identify weaknesses before they can be exploited.
Regulatory Compliance (AI)
AI regulatory compliance is the practice of operating AI systems in accordance with applicable laws, regulations, standards, and industry requirements. For enterprises, this may include obligations under the EU AI Act, GDPR, CCPA, HIPAA, NIST AI RMF, ISO/IEC 42001, and sector-specific frameworks. Maintaining compliance requires continuous governance that addresses how organizations uses AI, and how AI uses data, make decisions, and operate across the enterprise.
Responsible AI
Responsible AI is the development, deployment, and use of AI systems in ways that are secure, transparent, accountable, fair, and compliant with organizational policies and regulatory requirements. It requires appropriate governance, oversight, and controls throughout the AI lifecycle.
Shadow AI
Shadow AI refers to AI applications, accounts, agents, and tools used without IT or the security team's visibility, monitoring, governance, or approval. Because this activity operates outside established controls, it can increase the risk of sensitive data exposure, policy violations, compliance breaches, and unmanaged access to enterprise systems.
SIEM (AI)
AI SIEM refers to a security platform that combines traditional SIEM capabilities with artificial intelligence and machine learning. It helps automate data ingestion, accelerate threat detection, reduce false positives and alert fatigue, and support automated incident investigation and response.
Third-Party AI Risk
Third-party AI risk refers to the security, privacy, compliance, and operational risks introduced through external AI services, foundation model APIs, AI-enabled SaaS applications, and vendor-provided AI agents. These risks can include sensitive data exposure, limited visibility into vendor controls, insecure integrations, unauthorized model training, regulatory gaps, and dependencies on third-party systems.
Vibe Coding
Vibe coding is an AI-assisted software development approach where developers generate applications by describing desired outcomes in natural language. While it accelerates development, it can introduce risks related to code quality, security, governance, and data exposure.
Visibility (AI)
AI visibility means having full visibility across an organization’s entire AI ecosystem, including public GenAI tools, homegrown AI applications, coding assistants, AI agents, third-party AI tools, AI agent skills, MCP servers, and AI activity on employee endpoints. It enables organizations to discover and manage shadow AI, understand where AI is being used, see how it interacts with data, tools, and systems, and identify where security, governance, and compliance risks may exist.
See How Ovalix Secures Your AI Ecosystem in Minutes
Safeguard your AI applications and empower your team to adopt AI with confidence and ease