These definitions are the handbook's operational vocabulary. Legal and protocol definitions should be taken from the applicable versioned source. The entries explain the language used in the main chapters without requiring prior AI knowledge.
ACS. Agent Control Standard, a voluntary runtime-control interface inspected in chapter 6. Local adapter hooks and effect-route coverage must be demonstrated.
Action class. A group of operations with the same permission, consequence, and oversight rules. Reading a public file and initiating a payment are different action classes.
Action digest. Integrity value derived from a normalized proposed action. It helps bind review to what executes; normalization and field coverage must be tested.
Adaptive attack. An attack refined after observing defenses or feedback, under a stated search and retry budget.
ADMT. Automated decision-making technology. The legal definition and covered uses depend on the relevant jurisdiction and instrument.
Agent. Task-directed system that selects successive observations and actions using a model and supporting software.
Agent identity. Identity of an agent service or instance used for attribution. Identity alone does not establish permission for an action.
Agentic AI. AI used in systems that select and execute steps toward a task, often through tools, state, and delegation. This book uses an operational definition.
AISI. UK AI Security Institute, the source of the incident, simulation, and monitor-research reports discussed in this handbook.
API. Application programming interface, a software route for invoking a service. An alternate API can become an authorization bypass if it is not controlled.
Approval. A decision by an authorized reviewer to permit a specific action or explicitly bounded batch, with scope and expiry.
ARIA. Governance architecture discussed in source S23, illustrated through constructed multi-agent finance simulations rather than established production outcomes.
Artifact. An output retained or reused by a workflow, such as a summary, file, plan, skill, ticket, or proposed transaction.
Assurance case. Structured argument linking a bounded control claim to its mechanism, owner, tests, evidence, limitations, and operating decision.
Attack success rate. Successful attacks divided by evaluated attack opportunities under the reported success definition, selection, and attacker budget.
Audit trail. Record used to reconstruct decisions and effects. Its completeness, integrity, access, and retention need their own controls.
AUROC. Area under the receiver operating characteristic curve, summarizing score discrimination across thresholds. It is not recall or prevention at a chosen operating threshold.
Authorization. Decision that a subject may perform a particular operation on a resource under current scope, purpose, and policy.
Autonomy. Permission for a system to select or execute actions without a new human decision at each step. It is specified by action class.
Baseline. Reference configuration or process used for comparison. A simpler workflow can be a business baseline; a prior release can be a change baseline.
Bernoulli trial. An observation with a binary event outcome. The exact zero-event bound in chapter 9 assumes independent, identically distributed trials.
Business postcondition. External state that must be true for a claimed business outcome, such as a matched receipt and ledger status.
Canary. Limited production exposure used to observe a validated configuration under bounded consequence and rollback conditions.
CCPA / CPPA. California Consumer Privacy Act / California Privacy Protection Agency. Covered-business and processing scope must be established separately.
Chain of thought. Internal or generated reasoning text associated with a model. Availability and evidentiary meaning differ from resource effects and provider summaries.
Claim. Specific assertion about a control outcome. A claim should name its operating conditions and exclusions.
Collusion / coordinated violation. Multiple agents cooperating or combining actions to violate the overall mandate. Tests can be constructed without attributing human intent.
Commit boundary. Point at which an operation can produce a consequential resource effect. Checks must cover the real effect route and asynchronous behavior.
Compaction. Reduction or summarization of context. Safety state and provenance can be lost unless independently preserved.
Compensation. A corrective business action after an effect that cannot literally be undone, such as a refund or remedial notice.
Confabulation / hallucination. Plausible generated content that is inaccurate, unsupported, or fabricated. The consequence depends on how the output is used.
Configuration digest. Integrity value identifying a deployment manifest. It joins the approved, evaluated, and operating configuration.
Consequence. Effect on people, business resources, rights, security, or continuity if an action or failure occurs.
Contestability. Ability to challenge a consequential outcome through an accessible process that can consider evidence and correct the result.
Control. Mechanism or operating practice intended to constrain a risk or establish an outcome.
Control plane. Components governing permissions, policy, routing, and operation. The reference architecture separates critical controls from agent-editable state.
Correlation / lineage. Links among workflows, agents, actions, source artifacts, and derivatives. Correlation IDs do not by themselves prove causal attribution.
Data minimization. Limiting collected and retained data to what is necessary for an approved purpose and applicable obligations.
Delegation. Granting a child agent a bounded task and authority that cannot exceed the applicable parent and resource limits.
Deployment manifest. Versioned inventory of business mandate, model, harness, tools, permissions, memory, monitors, fallback, and relevant dependencies.
Deterministic enforcement. A rule check whose decision does not depend on the agent generating a compliant narrative. Its inputs and routes still need testing.
DevSecOps. Software development, security, and operations practices integrated across delivery and runtime. NIST identity demonstrations discussed here initially emphasize this setting.
Drift. Change in configuration, data, task mix, population, policy, or operating capacity that may invalidate earlier evidence.
Effect oracle. Independent method for determining what actually happened, such as resource state, transaction receipt, or adjudicated factual rubric.
Egress. Information or network traffic leaving a boundary. Destination and content policy are separate from successful authentication.
Eligible cohort. Population meeting a defined entry condition for a stage or analysis. Changing denominators can conceal earlier exclusion.
Evidence expiry. Reopening of a control claim when relevant conditions, components, or operating evidence change.
Fairness. Assessment and management of unjustified or harmful differences in treatment or outcomes, within the domain, law, and affected population.
Fallback. Alternative model, tool, process, or human route used when the primary path fails. It requires its own permitted scope and evidence.
False negative. A labeled harmful or relevant case that a detector misses under a defined threshold and labeling protocol.
False positive. A labeled benign or irrelevant case flagged under the detector protocol. It can create interruption or review burden.
FinFIRST. Financial search-agent evaluation benchmark discussed in S22, emphasizing retrieval, sourcing, and traceability. It does not establish suitability or production assurance.
GenAI. Generative artificial intelligence, producing content such as text, code, images, or structured outputs.
Global budget. Limit maintained across the entire workflow and its descendants, rather than separately reset by every worker or retry.
Grant. Scoped authorization context identifying subject, purpose, resources, operations, limits, expiry, and revocation conditions.
HARDE. Research system in S12 that jointly optimizes risk triggering, monitoring, and feedback in an agent harness. Reported results are configuration- and benchmark-specific.
Harness. Software coordinating model calls, context, tools, retries, routing, and workflow state.
Holdout. Evaluation data withheld from optimization or tuning. Repeated feedback can compromise its independence.
HTML. Hypertext Markup Language, used for the portable web edition. Its browser behavior requires rendered interaction and accessibility checks.
HTTP. Hypertext Transfer Protocol. A successful HTTP response does not necessarily establish a completed business effect.
Human oversight. Human ability to understand relevant evidence, intervene, correct, or stop within an effective time window.
Idempotency. Property that retrying the same operation does not create an additional unintended effect. It depends on the resource implementation and key scope.
Impact assessment. Documented examination of purpose, affected people, benefits, risks, alternatives, legal context, and controls.
Independent evidence. Evidence not controlled solely by the component whose behavior is being assessed. Independence has architectural and organizational dimensions.
Invariant. Condition intended to hold across every permitted execution, such as no commit with revoked authority.
Issuer / audience. Token issuer and intended recipient. Correct checks help prevent accepting a token from the wrong authority or for the wrong service.
JSON. JavaScript Object Notation, a structured data format used for manifests, example events, and schemas in the supplementary files.
Least privilege. Granting only the resources, operations, duration, and scope needed for the approved task.
LLM. Large language model, a component that generates language or structured outputs from context. It is not the entire agent deployment.
Mandate. Approved business purpose, permitted actions, limits, exclusions, owner, and oversight for a workflow.
Material change. Change likely to affect a relevant risk, authority path, outcome, or assurance assumption. Materiality should be defined locally.
MCP. Model Context Protocol, a versioned integration protocol. Protocol authentication does not establish business authorization for every action.
Memory. Retained information influencing future execution. It can include stored facts, summaries, skills, caches, and workflow state.
Monitor. Component observing signals and producing risk assessments or intervention requests. Its coverage and effective enforcement must be distinguished.
Multi-agent system. Workflow with multiple agents exchanging messages or artifacts, sharing state, or delegating tasks.
NIST. US National Institute of Standards and Technology. Its AI RMF is a voluntary risk-management framework; the identity work discussed here is a project and consultation output.
OECD. Organisation for Economic Co-operation and Development, publisher of the intergovernmental AI Principles used as a high-level values reference.
OpenTelemetry. Open-source observability specifications and tooling. GenAI attribute stability and enterprise semantic mappings should be versioned.
Optimal interruption window. Study-defined interval between an annotated earliest risk signal and trigger. It is distinct from a direct measure of realized harm prevention.
ORBIT. Multi-agent safety and security evaluation framework in S14. Its results motivate testing threats and architectures together.
Outcome. Business or human result of the workflow, independently assessed where possible rather than inferred from a success message.
OWASP. Open Worldwide Application Security Project. Its agent-security guidance and ACS are voluntary technical references, not laws or enterprise-effectiveness certificates.
PASTABench. Research benchmark in S11 using curated synthetic trajectories to assess risk attribution and intervention timing. Its timing metric is not realized harm.
Percentile. Value at or below which a stated percentage of observations falls. p50 is the median; p95 and p99 identify higher-delay portions of a latency distribution.
Policy engine. Component applying current authorization or business rules to a normalized proposed operation.
Prompt injection. Attempt by lower-trust or attacker-controlled content to redirect behavior beyond the authority of that content.
Provenance. Record of origin, version, transformation, and permitted use of information or an artifact.
RACI. Responsibility matrix identifying who is responsible, accountable, consulted, and informed. Assign local roles and avoid conflicting accountability.
RAG. Retrieval-augmented generation, supplying retrieved material to a model. Retrieval does not establish the truth or authority of the material.
Reconciliation. Comparison of expected, recorded, and actual resource states to resolve missing, partial, duplicated, or uncertain effects.
Red team. Structured adversarial testing under a stated threat model, scope, environment, and attack budget.
Residual risk. Risk remaining after controls, including observed failures and uncertainty. Acceptance must be bounded and attributable.
Revocation. Withdrawal of permission or reusable influence. It must propagate to descendants, pending work, and relevant retained artifacts.
RMF. Risk Management Framework. AI RMF refers here to the inspected NIST 1.0 framework, with its scope and revision status identified.
Rollback. Restoring an earlier configuration or state where supported. Some business effects instead require compensation.
Safe Success. The HARDE study metric averaging per-run task utility multiplied by attack non-success. It differs from a binary enterprise safe-completion rate when utility is fractional.
Safe task completion. Authorized successful task outcomes with no defined prohibited effect, measured from paired outcomes in the same runs.
Safety state. Persistent limits, denials, revocation, pending approvals, quarantine, and unresolved hazards needed across execution boundaries.
SDK. Software development kit, providing libraries or integration helpers. SDK adoption does not establish that all effect routes are mediated.
Shadow mode. Operation that produces proposals or comparisons while independently preventing the tested agent from making production effects.
Skill. Reusable procedure, code, or instruction set affecting future agent behavior. Updating it is a configuration and change-governance event.
SR 26-2. US interagency revised model-risk guidance, inspected in chapter 16. Its scope expressly excludes generative and agentic AI.
SSRF. Server-side request forgery, where a service is induced to fetch an unintended destination. Metadata-fetch routes need destination restrictions.
TACIT. Internal-state readout approach discussed in S21. Instrumentation availability and configuration-specific empirical results constrain its use.
Telemetry. Recorded operational events and measurements. Business-control meaning requires more than transport-level tracing.
Tenant isolation. Separation of customer or organizational data, state, authority, and effects across tenancy boundaries.
Three lines. Operating responsibilities, independent risk and compliance challenge, and independent internal audit. Local assignments must preserve audit independence.
TOL. The Observability Layer, publisher context for this handbook and the earlier Agentic Responsible AI Compendium.
Tool. Callable capability that reads information, invokes a service, or changes a resource state.
Trajectory. Sequence of observations, model outputs, actions, artifacts, and effects within a workflow.
Trust boundary. Boundary across which information or authority changes its permitted interpretation or privileges.
Utility. Useful authorized business performance, measured against the task and eligible population rather than merely fluent output.
Zero-event bound. Upper confidence limit for a binary event probability after zero observed events under stated sampling assumptions.