AI governance lexicon: 34 terms in plain language

In brief

Short definitions of the terms used across this site, with links to the official source where a term comes from a standard or a law.

A

Adversarial testing
Deliberately trying to make an AI system break its rules, using crafted inputs, to find weaknesses before others do.

See: Lesson 9: Red team results as governance evidence

Agentic AI
AI systems that take actions, such as calling tools, changing records or invoking other agents, rather than only producing text.

See: Lesson 2: Agentic AI governance: what changes when AI takes actions

AI-BOM (AI bill of materials)
A list of the models, datasets, libraries and services that make up an AI system. SPLX and Lasso name AI-BOM modules.

See: Lesson 3: AI inventory and registers: knowing what AI you run

AI governance platform
Software that carries an organization's AI policies through registration, control, evidence and reporting.

See: Lesson 1: What is an AI governance platform?

AI impact assessment
A documented review of an AI system's possible effects on people and groups. ISO/IEC 42001 includes AI system impact assessment in planning.

Source: ISO/IEC 42001 on iso.org

AI management system (AIMS)
The policies, roles, processes and records an organization uses to govern AI, as specified by ISO/IEC 42001.

Source: ISO/IEC 42001 on iso.org

AI register
A maintained list of AI systems in use, each with an owner, purpose, risk level, controls and evidence.

See: Lesson 3: AI inventory and registers: knowing what AI you run

Annex A controls
The reference control objectives and controls listed in Annex A of ISO/IEC 42001.

Source: ISO/IEC 42001 on iso.org

Audit trail
A time-ordered record of decisions and actions that lets someone reconstruct what a system did and why.

C

Conformity assessment
Under the EU AI Act, the process of showing that a high-risk AI system meets the Act's requirements before it is placed on the market.

Source: EU Artificial Intelligence Act

Control
A measure that enforces a policy, such as a runtime guardrail or an approval step.

See: Control maps

Control map
This site's four-step view of each platform: policy, control, evidence and report, showing what the vendor documents at each step.

See: Control maps

D

Deployer
Under the EU AI Act, a person or organization using an AI system under its authority, other than for personal non-professional use.

Source: EU Artificial Intelligence Act

Drift detection
Checking whether an AI system's behavior changes over time, for example after a model update. Alice's WonderCheck describes drift and regression detection.

E

Evidence
Records that prove a control worked: logs, test results, retests and reviews.
Excessive agency
An entry in the OWASP Top 10 for LLM Applications describing an LLM-based system that is given more functionality, permissions or autonomy than it needs.

Source: OWASP Top 10 for LLM Applications

G

General-purpose AI model
Under the EU AI Act, a model that can perform a wide range of tasks and be built into many systems; its providers have separate obligations.

Source: EU Artificial Intelligence Act

Guardrail
A runtime control that checks AI inputs, outputs or actions against a policy and allows, blocks, rewrites or escalates them.

See: Lesson 8: From AI policy to runtime control

H

High-risk AI system
Under the EU AI Act, an AI system used in a listed area such as employment or credit, or as a safety component of a regulated product; most detailed obligations apply to these.

Source: EU Artificial Intelligence Act

Human oversight
Measures that let people monitor, interpret, override or stop an AI system. Required for high-risk systems under the EU AI Act.

Source: EU Artificial Intelligence Act

J

Jailbreak
An input designed to make an AI model ignore its instructions or safety rules.

M

MITRE ATLAS
A knowledge base of adversary tactics and techniques against AI systems, maintained by MITRE and modeled on MITRE ATT&CK.

Source: MITRE ATLAS

Multi-turn attack
An attack spread over several messages, where each step looks harmless and the failure appears later in the conversation.

N

NIST AI RMF
The voluntary AI Risk Management Framework from the U.S. National Institute of Standards and Technology, organized into Govern, Map, Measure and Manage.

Source: NIST AI Risk Management Framework

O

OWASP Top 10 for LLM Applications
A ranked list of the most important security risks for applications built on large language models, published by the OWASP GenAI Security Project.

Source: OWASP Top 10 for LLM Applications

P

Policy
A written rule for AI use, specific enough that a control can enforce it and a test can check it.
Post-market monitoring
Under the EU AI Act, a provider's ongoing collection and review of data on how a high-risk system performs after it is placed on the market.

Source: EU Artificial Intelligence Act

Prompt injection
An attack that places instructions in an input, or in content the AI reads, to make it act against its instructions. It is the first entry in the OWASP Top 10 for LLM Applications.

Source: OWASP Top 10 for LLM Applications

Provider
Under the EU AI Act, the person or organization that develops an AI system, or has it developed, and places it on the market or puts it into service under its own name.

Source: EU Artificial Intelligence Act

R

Red teaming
Structured adversarial testing of an AI system by people or automated tools acting as attackers.

See: Lesson 9: Red team results as governance evidence

Regression detection
Retesting after a change to confirm that a previously fixed weakness has not returned.
Regulatory intelligence
A maintained source of laws, standards and guidance, mapped to obligations and controls. Credo AI describes a Knowledge Graph of regulatory intelligence.

S

Statement of applicability
In ISO management systems, the document listing which reference controls apply, which do not, and why.

Source: ISO/IEC 42001 on iso.org

T

Third-party AI
AI supplied by vendors, including AI features inside SaaS tools and models reached through APIs.

See: Lesson 10: Third-party AI risk: governing AI you did not build