Home / Glossary
ReferenceGlossary
Defined terms used across the AIGS standards and the Framework. Where a term is defined in a standard, that definition governs.
- Agent (AI agent)
- An AI system that can take actions, such as calling tools, reading data or sending messages, with some degree of autonomy.
- Agent chain
- Two or more agents connected so that the output of one becomes the input of another.
- AI system
- Any model, copilot, agent, automated flow or service that uses artificial intelligence to produce outputs or take actions for the organization.
- AI system inventory
- The organization's register of AI systems, with owner, purpose, data classes and status. Required by AIGS 100.
- Attribution basis
- What a unit of AI consumption is attributed to: the AI system, the owner only, or nothing (AIGS 200).
- Basis for conclusions
- The section of a standard that explains the Board's reasoning, including alternatives it considered and rejected.
- Capability profile
- A record of what an agent can take in, read, write and send, the tools it can call, and how autonomously it acts (AIGS 500).
- Classification coverage
- The share of AI-reachable data sources that have a sensitivity classification (AIGS 400).
- Collection freshness
- How recently consumption or usage data was successfully collected, as distinct from when usage last occurred.
- Comment letter
- A written response to an exposure draft, submitted during the comment period and considered in redeliberation.
- Complete exposure path
- An agent or agent chain holding all four exposure legs.
- Consumption event
- A recorded unit of AI usage, such as tokens or credits, reported by a provider or platform.
- Coverage statement
- A statement, attached to any report, of which surfaces or sources were measured and which were not.
- Evidence strength
- How strongly a claim is known to be true: Declared, Configured, Observed or Verified (AIGS 600).
- Exposure draft
- A proposed standard published for public comment. It has no authority until issued by the Board.
- Exposure leg
- One of four capabilities that together make an agent exploitable: untrusted input, private data read, shared write, external send.
- False green
- A control or report shown as healthy when it is only configured, or when data collection failed. AIGS 600 prohibits it.
- Human approval
- A required human decision before an agent completes an action with material impact (AIGS 500.7).
- Leaver reassignment
- Transferring ownership of AI systems held by a departing person to a new owner of record (AIGS 100).
- Maturity level
- One of five stages in the Framework: Initial, Inventoried, Owned, Measured, Assured. Owned is the baseline.
- Non-human identity
- A service principal, API key, token or other credential used by software, including agents, rather than a person.
- Not measured
- The required label for a measure or surface where no data was collected. It must never be shown as zero or clean.
- Owner of record
- The named, current individual accountable for an AI system (AIGS 100).
- Owner unknown
- The required state for an AI system whose owner cannot be identified or has left. It is a finding, not a default.
- Permitted-use register
- A record of which data classes each AI system may access and for what purpose (AIGS 400).
- Prompt injection
- Instructions hidden in content an AI system reads, intended to make it act against its operator.
- Redeliberation
- The Board's public reconsideration of a draft in light of comment letters.
- Sanctioned AI
- An AI service, model or tool approved by the organization for stated purposes and data classes (AIGS 300).
- Technical Working Group (TWG)
- A volunteer group of members that drafts and maintains one standard.
- Tool server
- A service that exposes tools for agents to call, such as a Model Context Protocol (MCP) server (AIGS 500.6).
- Triage order
- A ranking used to decide what to review first. It is not a probability of wrongdoing (AIGS 300.6).
- Unaccountable spend
- AI consumption that cannot be linked to an AI system with an owner of record (AIGS 200).
- Unmeasured action
- A tool action that has not been classified. It must never be assumed to be read-only (AIGS 500.3).