AI agent governance, in plain English.
Plain English definitions of the AI agent governance terms that come up in board meetings, audits, and security reviews. If you can't explain a term to your board, you can't govern it.
Agent autonomy levels
Agent autonomy levels rank how much an AI agent may do on its own, from tightly supervised to fully independent. Josh Woodruff's Agentic Trust Framework maps four of them: Intern, Junior, Senior, and Principal. Each level earns more freedom by showing more proof of what the agent did.
Also called: agent maturity levels, agent trust levels, ATF levels, agent autonomy tiers
Updated
Agent inventory
An agent inventory is a current list of every AI agent running inside a company. A real inventory names the owner, the systems the agent can reach, the credentials it holds, and the date someone last checked. Most companies don't have one, so they can't protect what they can't see.
Also called: AI agent inventory, agent registry, AI inventory, agent census, agent catalog, AI asset inventory, agent discovery
Updated
Agent sprawl
Agent sprawl is the fast, unmanaged growth of AI agents across a company. Teams spin up agents quicker than security can track them, so nobody holds a full count. Many keep standing access long after their task ends. You cannot secure an agent you never counted.
Also called: AI agent sprawl, agent proliferation, agent spread, ungoverned agents, uncounted agents
Updated
Agent washing
Agent washing is when a vendor sells ordinary software as an AI agent to ride the hype. The product often runs on fixed rules or a chatbot, not an agent that plans and acts on its own. Buyers pay agent prices for automation they may already own, and the real risks get hidden.
Also called: Agentwashing, Agent-washing, AI washing
Updated
Agentic Trust Framework
The Agentic Trust Framework is a governance model for AI agents organized around five questions: who the agent is, where it can go, how its behavior is monitored, how its data is governed, and what happens during an incident. It gives security teams a structure to work from when no complete AI security reference architecture exists to buy.
Also called: ATF
Updated
AI agent identity
AI agent identity is the unique, verifiable name an AI agent uses to act in your systems, apart from any human login. It lets you tell one agent from another and check what each one may do. Without it, agents borrow human credentials and no one can tell which agent took an action.
Also called: Agent identity, Agentic identity, AI agent ID
Updated
Audit trail
An audit trail is a durable record of every action an AI agent took. A useful one names the tool the agent called, the data it read, the change it made, and the policy that approved the action. Chat logs aren't an audit trail. Logs show what the agent said, not what it did.
Also called: agent audit trail, audit log, agent activity log, action log, immutable log, evidence trail, AI agent logging
Updated
Blast radius
Blast radius is the full set of systems an AI agent can reach and actions it can take if something goes wrong. Measuring it means costing the worst plausible chain of actions rather than the worst single action, because agents work in sequences and the sequence is usually worse than any one step in it.
Also called: impact radius, exposure surface, reach
Updated
Data poisoning
Data poisoning is an attack that feeds an AI agent bad data on purpose so it learns the wrong thing or acts the wrong way. The poison can go into training data or into what the agent reads while it works. A poisoned agent looks normal, so the damage can spread before anyone notices.
Also called: Training data poisoning, Model poisoning, AI poisoning attack
Updated
Guardrails
Guardrails are the limits you put around an AI agent so it can work on its own without causing harm. They block risky actions and cap what the agent can reach or spend. Good guardrails let an agent do real work while keeping its blast radius small.
Also called: Agent guardrails, AI guardrails, Safety rails, Policy guardrails
Updated
Human in the loop
Human in the loop means a person must approve an AI agent's action before the action happens. The approval has to be real. If the reviewer sees a one-line summary and clicks yes forty times an hour, that's human-in-the-loop theater, and the agent is really running on its own.
Also called: HITL, human-in-the-loop, human oversight, human approval, approval gate, expert-in-the-loop, human review, human on the loop
Updated
Kill switch
A kill switch is a control that stops an AI agent on demand. A working one revokes the agent's credentials and ends any task already running. Closing the chat window isn't a kill switch. The agent's tokens stay live, so it keeps its access to every system it can reach.
Also called: agent kill switch, AI kill switch, emergency stop, circuit breaker, agent shutdown, big red button, revocation switch
Updated
Least privilege
Least privilege means giving an AI agent only the access it needs for the job in front of it, and nothing more. Most agents get far more. Teams grant broad access on day one to avoid breakage, then never trim it back, so the agent sits over-privileged at rest.
Also called: principle of least privilege, PoLP, minimum necessary access, least-privilege access, scoped access, right-sized access, need-to-know access
Updated
Model Context Protocol
The Model Context Protocol (MCP) is an open standard that lets AI agents reach tools and data through one shared interface. Instead of custom code for each system, an agent speaks a single protocol. Security teams treat each MCP server as a new door in, so it needs the same review any API gets.
Also called: MCP, Model Context Protocol server, MCP server
Updated
Non-human identity
A non-human identity is any account in a company that doesn't belong to a person. Service accounts, API keys, machine credentials, and AI agents all qualify. Every platform names them differently, which is why most organizations can't produce a single list of the non-human identities they run.
Also called: NHI, machine identity, workload identity, service principal, service account, managed identity, IAM role, M2M identity
Updated
Privilege escalation
Privilege escalation is when an AI agent gains more access than it was meant to have. The agent chains granted permissions or inherits a user's rights through a tool, then reaches data it should never touch. The extra access is often standing permission nobody removed.
Also called: privilege escalation attack, priv esc, escalation of privilege, permission escalation, excessive privilege
Updated
Prompt injection
Prompt injection is an attack that hides instructions inside content an AI system reads, so the system follows the attacker's instructions instead of its operator's. The content can arrive in a web page, a document, an email, or a tool response, which makes any untrusted input a possible delivery path.
Also called: indirect prompt injection, LLM injection, instruction injection, prompt hijacking
Updated
Reference architecture
A reference architecture is a proven blueprint for how AI agents should be built and governed. It sets standard patterns for identity, access, logging, and control, so every team starts from the same secure base instead of inventing its own. Security teams build these because no single vendor covers the whole stack.
Also called: AI reference architecture, agent reference architecture, reference arch, target architecture, governance blueprint
Updated
Shadow AI
Shadow AI is any AI tool, model, or agent running inside a company without security or IT approval. It covers unsanctioned chatbots, browser extensions, model downloads, and applications calling provider APIs directly. Network telemetry usually finds far more of it than the security team expected.
Also called: unsanctioned AI, ungoverned AI, rogue AI, shadow IT for AI, BYOAI
Updated
Zero Trust for AI agents
Zero Trust for AI agents applies the rule "never trust, always verify" to software agents. It checks every connection continuously, not once at login. John Kindervag named Zero Trust at Forrester in 2010. Agents need one more check on top: verifying each action the agent takes.
Also called: Zero Trust, ZT, Zero Trust Architecture, ZTA, never trust always verify, Zero Trust for agents
Updated
Let's figure out what you actually need.
No pitch. No pressure. Every conversation starts with a senior practitioner, not a sales team. We'll tell you straight where you stand and whether we're the right fit. If we're not, we'll point you to who is.