Explore Enzai’s full suite of AI governance products designed to help organizations manage, monitor, and scale AI with confidence. From structured intake and centralized AI inventories to automated assessments and real-time oversight, Enzai provides the building blocks to embed governance directly into everyday AI workflows - without slowing innovation.

Enzai

All

Whitepaper

AI Regulations

Podcasts

Product Updates

Press Coverage

Glossary

Join our podcast or collaborate on content

Reach out and we’ll see what we can produce together.

A

Acceptable Use Policy (AUP)

A set of rules applied by an organization that outlines the permitted and prohibited ways employees may interact with company-provided AI tools.

Accredited Certification

A certificate issued by a certification body that has been formally recognized by a national accreditation body (like ANAB or UKAS) as competent to audit against a specific standard.

Action Preview

A governance requirement where an AI agent must display exactly what an irreversible operation will do before a human provides final approval.

Action Whitelisting

A security and governance control that specifies the only permitted tools, APIs, and actions an AI agent is allowed to execute.

Adversarial Attack

Techniques that manipulate AI models by introducing deceptive inputs to cause incorrect outputs.

Agent Fabric

An integrated runtime substrate that hosts, orchestrates, and governs multiple AI agents alongside the models, tools, and data they depend on.

Agent Goal Hijack (ASI01)

A vulnerability where an attacker manipulates an agent's objectives or decision pathways to redirect its autonomous behavior toward unintended outcomes.

Agent Mesh

A networked topology in which AI agents discover, communicate with, and delegate work to one another through a shared infrastructure layer.

Agentic AI

A class of artificial intelligence systems designed to autonomously pursue complex goals and execute multi-step actions (such as software deployment or financial transactions) with minimal human intervention.

Agentic AI Governance

Agentic AI governance is the control of AI systems that plan and take actions on their own, as opposed to systems that only produce predictions or content. It covers what an agent is permitted to do, the limits on its autonomy, how its actions are logged, and who is accountable when an agent acts wrongly.

Agentic Policy Engine

A runtime software component that intercepts agent actions and evaluates them against a set of deterministic governance rules before execution.

AI Accountability

The obligation of AI system developers and operators to ensure their systems are designed and used responsibly, adhering to ethical standards and legal requirements.

AI Alignment

The process of ensuring AI systems' goals and behaviors are aligned with human values and intentions.

AI Assistant

A conversational AI system designed to help users complete tasks through natural language interaction, typically powered by a large language model.

AI Auditing

The systematic evaluation of AI systems to assess compliance with ethical standards, regulations, and performance metrics.

AI Bias

Systematic errors in AI outputs resulting from prejudiced training data or flawed algorithms, leading to unfair outcomes.

AI Bill of Materials (AIBOM)

A structured inventory listing the components that make up an AI system, including foundation models, training datasets, libraries, and dependencies - the AI equivalent of a Software Bill of Materials (SBOM).

AI Compliance

The adherence of AI systems to applicable laws, regulations, and ethical guidelines throughout their lifecycle.

AI Ethics

The field concerned with the moral implications and responsibilities associated with the development and deployment of AI technologies.

AI Explainability

The extent to which the internal mechanics of an AI system can be understood and interpreted by humans.

AI Footprint

The total set of AI systems, models, agents, and embedded AI features in use across an organization at any given time, including sanctioned and shadow systems.

AI Governance

The framework of policies, processes, and controls that guide the ethical and effective development and use of AI systems.

AI Governance for Financial Services

AI governance for financial services is the application of AI risk and compliance controls under the sector's supervisory regimes. The relevant rules differ by jurisdiction and by firm type: SR 26-2 for larger US banks, PRA SS1/23 for UK banks with internal model approval, MAS FEAT in Singapore, and the EU AI Act across all of them.

AI Governance Software

Specialized enterprise tools used to automate the inventory, risk assessment, and regulatory compliance of artificial intelligence systems.

AI Inventory

A comprehensive, centralized catalog of all AI systems, models, and agents in use across an organization, tracking their business purpose, risk level, and ownership.

EU AI Liability Directive

A proposed EU directive aimed at simplifying the process for claimants to seek damages caused by AI systems by introducing a rebuttable presumption of causality.

AI Literacy

The understanding of AI concepts, capabilities, and limitations, enabling informed interaction with AI technologies.

Artificial Intelligence Management System (AIMS)

A set of interrelated or interacting elements of an organization to establish policies, objectives, and processes for the responsible development or use of AI.

AI Monitoring

AI monitoring is the continuous observation of AI systems in production to detect degradation, drift, unsafe behavior and control failures. It covers model performance, input and output distributions, fairness metrics, cost and latency, and for agentic systems the actions the system takes.

AI Risk

The potential for AI systems to cause harm or unintended consequences, including ethical, legal, and operational risks.

AI Risk Management

The process of identifying, assessing, and mitigating risks associated with AI systems.

AI Sprawl

The uncontrolled expansion of AI systems across an organization, typically driven by easy access to AI tools and a lack of effective intake and inventory processes.

AI System Impact Assessment

A formal process to evaluate the potential consequences of an AI system's deployment on individuals, groups, and society at large.

AI Transparency

The principle that AI systems should be open and clear about their operations, decisions, and data usage.

AI TRiSM

An acronym coined by Gartner standing for AI Trust, Risk, and Security Management; a framework that unifies governance, trustworthiness, and security into a single operational strategy.

Artificial Intelligence and Data Act (AIDA)

Canada's federal regulatory framework (part of Bill C-27) aimed at ensuring high-impact AI systems are developed and used safely and without bias.

Algorithmic Bias

Bias that occurs when an algorithm produces results that are systemically prejudiced due to erroneous assumptions in the machine learning process.

Algorithmic Governance

The use of algorithms to manage and regulate societal functions, potentially impacting decision-making processes.

Amnesty Program

A time-limited governance initiative where employees are invited to disclose unsanctioned AI tool usage without fear of disciplinary action.

Annex I Products

A list of products already regulated by EU health and safety law (e.g., machinery, medical devices) where AI integrated under the EU AI Act is automatically classified as high-risk.

Annex III Categories

A specific list of high-risk AI application areas defined by the EU AI Act that trigger mandatory compliance obligations.

API Traffic Analysis

The technical process of monitoring and inspecting network calls made to external AI service providers.

Article 6(3) Exception

A self-determination mechanism under the EU AI Act allowing providers to classify an Annex III AI system as not high-risk if it poses no significant harm.

Article 25 (EU AI Act)

The EU AI Act provision creating a direct obligation chain between providers and deployers of high-risk AI systems, including responsibility transfer when systems are substantially modified.

Article 50 (EU AI Act)

The EU AI Act provision setting transparency obligations for AI systems that interact with people, generate synthetic content, or produce deepfakes.

Australia Safe & Responsible AI Policy

The Australian federal policy governing the use of AI within the public service and government agencies.

Automated AI Governance

The use of software and API integrations to perform continuous, real-time compliance checks and risk monitoring without manual intervention.

B

Bias Amplification

The phenomenon where AI systems exacerbate existing biases present in the training data, leading to increasingly skewed outcomes.

Bias Audit

An evaluation process to detect and mitigate biases in AI systems, ensuring fairness and compliance with ethical standards.

Bias Detection

The process of identifying biases in AI models by analyzing their outputs and decision-making processes.

Bias Mitigation

Techniques applied during AI development to reduce or eliminate biases in models and datasets.

Brazil AI Bill (PL 2338/2023)

PL 2338/2023 is Brazil's proposed legal framework for artificial intelligence. It classifies AI systems by risk, grants rights to explanation and human review, and creates a national oversight system coordinated by the data protection authority. The Senate approved it in December 2024 and it remains before the Chamber of Deputies, so it is not yet law.

Brussels Effect

The phenomenon whereby EU regulation becomes the global default through market access requirements, even for organizations headquartered outside the EU.

C

California AB 1008

An amendment to the CCPA clarifying that personal information includes data generated or output by AI systems.

California AB 3030

A California law requiring transparency when Generative AI is used to communicate with patients in a healthcare setting.

California ADMT Regulations

Rules under the California Consumer Privacy Act (CCPA) governing Automated Decision-Making Technology (ADMT).

California FEHA AI Regulations

State regulations under the Fair Employment and Housing Act (FEHA) targeting AI-driven discrimination in the workplace.

California AI Transparency Act (SB 942)

The California AI Transparency Act, SB 942 as amended by AB 853, requires providers of widely used generative AI systems to embed provenance disclosures in AI-generated image, video and audio content and to publish a free public detection tool. It became operative on August 2, 2026, and is enforced by the California Attorney General.

Cascading Failure (ASI08)

A failure mode where an error or malicious input in one AI agent's reasoning triggers a chain reaction of failures across multiple connected agents or systems.

CE Marking

A mandatory certification mark that indicates an AI system's conformity with health, safety, and environmental protection standards for products sold within the EEA.

Change Notification Window

A contractual period during which a vendor must inform a customer of material updates to an AI model before those updates are deployed in production.

China Interim GenAI Measures

Regulatory requirements for generative AI services provided to the Chinese public.

Council of Europe AI Convention

The first legally binding international treaty on AI, focusing on the protection of human rights, democracy, and the rule of law.

Colorado AI Act (SB 24-205, repealed 2026)

The Colorado AI Act (SB 24-205), the first broad U.S. state AI law, was repealed in May 2026 and replaced by Colorado SB 26-189, which takes effect January 1, 2027, with a narrower focus on automated decision-making technology.

Colorado AI Act (SB 26-189)

Colorado SB 26-189 is the 2026 replacement for the original Colorado AI Act (SB 24-205), taking effect January 1, 2027, with obligations focused on automated decision-making technology making consequential decisions about Coloradans.

Compliance Framework

A structured set of guidelines and best practices that organizations follow to ensure their AI systems meet regulatory and ethical standards.

Compliance Risk

The potential for legal or regulatory sanctions, financial loss, or reputational damage an organization faces when it fails to comply with laws, regulations, or prescribed practices.

Concept Drift

The change in the statistical properties of the target variable, which the model is trying to predict, over time, leading to model degradation.

Conformity Assessment

A process to determine whether an AI system meets specified requirements, standards, or regulations, often involving testing and certification.

Internal Control (Conformity Assessment)

A process under the EU AI Act where a provider self-verifies that their high-risk AI system meets all regulatory requirements without requiring a third-party audit.

Controllability

The extent to which humans can direct, influence, or override the decisions and behaviors of an AI system.

COREPER Mandate

The negotiating authority granted by EU member state ambassadors (Committee of Permanent Representatives) to the rotating Council Presidency for trilogue negotiations on EU legislation.

Cryptographic Agent Identity

A verifiable digital credential (often a Decentralized Identifier or DID) that uniquely identifies an AI agent and its authority level.

D

Data Drift

The change in model input data over time, which can lead to model performance degradation if not monitored and addressed.

Data Ethics

The branch of ethics that evaluates data practices with respect to the moral obligations of gathering, protecting, and using personally identifiable information.

Data Governance

The overall management of data availability, usability, integrity, and security in an enterprise, ensuring that data is handled properly throughout its lifecycle.

Data Ingestion Risk

The danger that sensitive or proprietary information will be permanently absorbed into an AI model's training set during a user's interaction.

Data Lifecycle Management

The policy-based management of data flow throughout its lifecycle: from creation and initial storage to the time it becomes obsolete and is deleted.

Data Minimization

The principle of collecting only the data that is necessary for a specific purpose, reducing the risk of misuse or breach.

Data Privacy

The aspect of information technology that deals with the ability to control what data is shared and with whom, ensuring personal data is handled appropriately.

Data Protection

The process of safeguarding important information from corruption, compromise, or loss, ensuring compliance with data protection laws and regulations.

Data Provenance

A documented record of the origin, ownership, and lifecycle of a dataset used to train or fine-tune an AI model.

Data Quality

The condition of data based on factors such as accuracy, completeness, reliability, and relevance, crucial for effective AI model performance.

Data Residency

Data residency is the requirement that data be stored and processed in a particular country or region. In AI systems it applies to training data, prompts, model outputs and inference logs, and it constrains which models a firm can call, since sending a prompt to a model hosted elsewhere is a cross-border transfer.

Data Sovereignty

The concept that data is subject to the laws and governance structures within the nation it is collected, stored, or processed.

Data Subject

An individual whose personal data is collected, held, or processed, particularly relevant in the context of data protection laws like GDPR.

De-identification

The process of removing or obscuring personal identifiers from data sets, making it difficult to identify individuals, used to protect privacy.

Deepfake

Synthetic media in which a person in an existing image or video is replaced with someone else's likeness, created using deep learning techniques.

Differential Privacy

A system for publicly sharing information about a dataset by describing patterns of groups within the dataset while withholding information about individuals.

EU Digital Omnibus on AI

A 2025/2026 legislative package designed to streamline and harmonize technical standards, conformity assessments, and enforcement timelines across the EU AI Act and related digital safety laws.

Discrimination

In AI, refers to unfair treatment of individuals or groups based on biases in data or algorithms, leading to unequal outcomes.

Dual-Use Foundation Model

An AI model that is trained on a vast amount of data and has high-level performance that could be used for both civilian and harmful or military purposes.

Dynamic Risk Assessment

The continuous process of identifying and evaluating risks in real-time, allowing for timely responses to emerging threats in AI systems.

E

Edge Analytics

The analysis of data at the edge of the network, near the source of data generation, reducing latency and bandwidth usage.

Enzai

An enterprise AI governance platform that enables organizations to inventory, assess, and control their AI systems, ensuring maxmize AI adoption while minimizing AI risk.

Escalation Logic

A set of predefined rules and triggers that force an AI agent to stop autonomous operation and hand control back to a human operator.

ESMA AI/ML Governance Expectations

ESMA's AI and machine learning expectations set out how EU investment firms must apply MiFID II obligations when using AI. The European Securities and Markets Authority issued guidance on AI in retail investment services in May 2024, followed by a supervisory briefing on algorithmic trading on February 26, 2026, that addresses AI and its interaction with the EU AI Act.

Ethical AI

The practice of designing, developing, and deploying AI systems in a manner that aligns with ethical principles and values, ensuring fairness, accountability, and transparency.

Ethical AI Auditing

The process of systematically evaluating AI systems to ensure they comply with ethical standards and do not cause harm.

Ethical AI Certification

A formal recognition that an AI system adheres to established ethical standards and guidelines.

Ethical AI Governance

The framework of policies, procedures, and practices that ensure AI systems are developed and used responsibly and ethically.

Ethical Frameworks

Structured sets of principles and guidelines designed to guide the ethical development and deployment of AI systems.

Ethical Impact Assessment

A systematic evaluation process to identify and address the ethical implications and potential societal impacts of AI systems before deployment.

Ethical Risk

The potential for an AI system to cause harm due to unethical behavior, including bias, discrimination, or violation of privacy.

Ethics Guidelines for Trustworthy AI

A set of guidelines developed by the European Commission's High-Level Expert Group on AI to promote trustworthy AI, focusing on human agency, technical robustness, privacy, transparency, diversity, societal well-being, and accountability.

EU AI Act

The world's first comprehensive horizontal legal framework for AI, establishing a risk-based classification system for systems deployed or used within the European Union.

EU AI Act High-Risk Categories

The two classifications of high-risk AI systems under the EU AI Act: standalone systems listed in Annex III (covering biometrics, critical infrastructure, employment, education, law enforcement, and other named uses), and AI embedded in regulated products listed in Annex I (covering medical devices, vehicles, machinery, and other regulated product categories).

EU AI Act Risk Classification

The mandatory process of assigning one of four risk levels (Unacceptable, High, Limited, Minimal) to an AI system under the EU AI Act.

EU AI Office

The European Commission body established to oversee implementation and enforcement of the EU AI Act, particularly for general-purpose AI models with systemic risk.

EU Digital Omnibus

The European Union's broader 2025-2026 legislative simplification package addressing multiple digital regulations including the AI Act, GDPR provisions, the Cyber Resilience Act, and Data Act amendments.

Excessive Agency

A vulnerability where an AI system is granted too much autonomy, too many tools, or over-privileged access relative to its intended function.

Executive Order 14110

The Biden administration directive (signed October 2023, rescinded January 2025) that established U.S. national standards for AI safety, security, and privacy and created the U.S. AI Safety Institute at NIST.

Explainability Techniques

Methods used to interpret and understand the decisions made by AI models, such as LIME, SHAP, and saliency maps.

Explainability vs. Interpretability

While both aim to make AI decisions understandable, explainability focuses on the reasoning behind decisions, whereas interpretability relates to the transparency of the model's internal mechanics.

Explainable AI (XAI)

AI systems designed to provide human-understandable justifications for their decisions and actions, enhancing transparency and trust.

Explainable Machine Learning

Machine learning models designed to provide clear and understandable explanations for their predictions and decisions.

F

Fairness Metrics

Quantitative measures (e.g., demographic parity, equalized odds) used to evaluate how fair an AI model’s predictions are across groups.

False Negative

When an AI model incorrectly predicts a negative class for an instance that is actually positive (Type II error).

False Positive

When an AI model incorrectly predicts a positive class for an instance that is actually negative (Type I error).

Fault Tolerance

The ability of an AI system to continue operating correctly even when some components fail or produce errors.

Federated AI Governance

A governance model where central policy and oversight are paired with distributed decision-making by business units or regional offices, balancing consistency with operational flexibility.

Feedback Loop

A process where AI outputs are fed back as inputs, which can amplify model behavior - for better (reinforcement learning) or worse (bias reinforcement).

FS AI RMF (Financial Services AI Risk Management Framework)

The Financial Services AI Risk Management Framework (FS AI RMF) is a voluntary, sector-specific framework published in February 2026 by the US Treasury with the Cyber Risk Institute. It aligns to the NIST AI RMF and provides a matrix of 230 control objectives across the AI lifecycle, covering banks, credit unions, insurers, investment firms and their third-party providers.

Functional Safety

Ensuring AI systems operate safely under all conditions, especially in industries like automotive or healthcare, often via redundancy and checks.

Fundamental Rights Impact Assessment (FRIA)

A mandatory evaluation under the EU AI Act for certain deployers to determine how the use of a high-risk AI system might impact civil liberties and human rights.

G

Gap Analysis

The process of comparing current AI governance practices against desired standards or regulations to identify areas needing improvement.

GDPR

The EU’s General Data Protection Regulation, establishing strict requirements for personal data collection, processing, and individual rights.

Goal Drift

A phenomenon where an AI agent's internal sub-goals or reasoning pathways gradually move away from the original human-provided objective.

Governance Body

A cross-functional group (e.g., legal, ethics, technical) tasked with overseeing AI governance policies and their execution within an organization.

Governance Framework

A structured model outlining how AI governance components (risk management, accountability, oversight) fit together to ensure compliance and ethical use.

Governance Maturity Model

A governance maturity model is a staged scale for assessing how developed an organization's AI governance is, typically running from ad hoc practice through to measured and continuously improved. It is used to benchmark a starting position, set a realistic target and sequence investment, not to certify compliance.

Governance Policy

A formal document that codifies rules, roles, and procedures for AI development and oversight within an organization.

Governance Scorecard

A dashboard or report card that tracks key metrics (e.g., bias incidents, compliance audits) to measure AI governance effectiveness over time.

GPAI Code of Practice

The detailed regulatory instrument outlining specific transparency, safety testing, and risk mitigation obligations for providers of General-Purpose AI (GPAI) models under the EU AI Act.

GPAI Model

A general-purpose artificial intelligence model capable of performing a wide range of distinct tasks and integrating into various applications.

Granular Consent

A data-privacy approach allowing individuals to grant or deny specific permissions for each type of data use, enhancing transparency and control.

Guardrails

Predefined constraints or checks (technical and policy) embedded in AI systems to prevent unsafe or non-compliant behavior at runtime.

Guideline (Ethical AI)

A non-binding recommendation or best-practice document issued by organizations (e.g., IEEE, EU) to shape responsible AI development and deployment.

H

Hallucination

When generative AI produces incorrect or fabricated information that appears plausible but has no basis in the training data.

Harm Assessment

Evaluating potential negative impacts (physical, psychological, societal) of AI systems and defining mitigation strategies.

Harmonization

Aligning AI policies, standards, and regulations across jurisdictions to reduce conflicts and enable interoperability.

Harmonized Structure

A standardized template for all ISO management system standards, formerly known as Annex SL, ensuring consistency in terminology and clause numbering.

Heuristic Evaluation

A usability inspection method where experts judge an AI system against established usability principles to identify potential issues.

High-Risk AI System

AI applications that have a significant potential to harm the health, safety, or fundamental rights of individuals, triggering the most stringent compliance requirements under the EU AI Act.

High-Stakes AI

AI applications whose failures could cause significant harm (e.g., medical diagnosis, autonomous vehicles), requiring heightened governance and oversight.

Human-in-the-Loop

Involving human judgment within AI processes (training, validation, decision review) to improve accuracy and accountability.

Human Oversight

Mechanisms that allow designated individuals to monitor, intervene, or override AI system decisions to ensure ethical and legal compliance.

Human Rights Impact Assessment

A process to evaluate how AI systems affect fundamental rights (privacy, expression, non-discrimination) and identify mitigation measures.

I

Impact Assessment

A structured evaluation to identify, analyze, and mitigate potential ethical, legal, and societal impacts of an AI system before deployment.

Implementing Acts

Secondary EU legislation adopted by the European Commission to set uniform conditions for implementing primary legislation, with binding legal effect across all Member States.

Incentive Alignment

The design of reward structures and objectives so that AI systems’ goals remain consistent with human values and organizational priorities.

Inductive Bias

The set of assumptions a learning algorithm uses to generalize from observed data to unseen instances.

Information Governance

The policies, procedures, and controls that ensure data quality, privacy, and usability across an organization’s data assets, including AI training datasets.

Information Privacy

The right of individuals to control how their personal data are collected, used, stored, and shared by AI systems.

Inherited Data Risk

The regulatory and ethical liability an organization assumes when using an AI system trained on data they did not collect or vet themselves.

Intake Workflow

The standardized process and series of checks that a new AI system must pass through before being built or procured.

Intent Validation

The process of verifying that an AI agent's planned sub-actions remain consistent with the original human-provided objective.

Interoperability

The ability of diverse AI systems and components to exchange, understand, and use information seamlessly, often via open standards or APIs.

Interpretability

The degree to which a human can understand the internal mechanics or decision rationale of an AI model.

ISO/IEC 42001

The international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS).

ISO/IEC 42005

The international standard providing guidance on performing AI system impact assessments.

ISO/IEC JTC 1/SC 42

The joint ISO/IEC committee on Artificial Intelligence standardization, developing international AI standards for governance, risk, and interoperability.

J

Jailbreak Attack

A type of prompt‐injection where users exploit vulnerabilities to bypass safeguards in generative AI models, potentially leading to unsafe or unauthorized outputs.

Japan Act on Promotion of AI

A Japanese law (enacted 2025) establishing basic principles for AI promotion and risk mitigation.

Joint Liability

Legal principle where multiple parties (e.g., developers, deployers) share responsibility for AI‐related harms, influencing contract and governance structures.

Joint Modeling

Building AI systems that jointly learn multiple tasks (e.g., speech recognition + translation), with governance needed for complexity and auditability.

Jurisdiction

The legal authority over data, AI operations, and liability, which varies by geography and impacts compliance with regional regulations (e.g., GDPR, CCPA).

K

Key Performance Indicator

A quantifiable metric (e.g., model accuracy drift, bias remediation time) used to monitor and report on AI governance and compliance objectives.

Key Risk Indicator

A leading metric (e.g., frequency of out-of-scope predictions, rate of unexplainable decisions) that signals emerging AI risks before they materialize.

Knowledge Management

Practices and tools for capturing, organizing and sharing organizational knowledge (e.g., model documentation, audit logs) to ensure reproducibility and oversight.

L

Least Agency

A security and governance principle stating that AI agents should only be granted the minimum level of autonomy and tool-access necessary to complete a specific task.

Least Privilege

A security principle where AI components and users are granted only the minimal access rights necessary to perform their functions, reducing risk of misuse.

Legal Compliance

The practice of ensuring AI systems adhere to applicable laws, regulations, and industry standards throughout their entire lifecycle.

Liability Framework

A structured approach defining who is responsible for AI-related harms or failures, including developers, deployers, and operators.

Lifecycle Management

The coordinated processes for development, deployment, monitoring, maintenance, and retirement of AI systems to ensure ongoing compliance and risk control.

Localization

Adapting AI systems to local languages, regulations, cultural norms, and data residency requirements in different jurisdictions.

M

Market Surveillance Authority

The national regulatory body in each EU member state responsible for monitoring AI systems to ensure they comply with the EU AI Act.

MAS FEAT Principles

The MAS FEAT Principles are four principles covering Fairness, Ethics, Accountability and Transparency, published by the Monetary Authority of Singapore on November 12, 2018, to guide the responsible use of artificial intelligence and data analytics in Singapore's financial sector. They are non-binding guidance, not enforceable rules, and are supported by the Veritas assessment methodology.

Meaningful Human Control

A regulatory and operational standard ensuring that humans retain the ability to oversee, intervene in, and override AI decision-making processes.

Metadata Management

The practice of capturing and maintaining descriptive data (e.g., data provenance, feature definitions, model parameters) to support traceability and audits.

Metrics & KPIs

Quantitative measures (e.g., accuracy drift, fairness scores, incident response time) used to monitor AI system health, risk, and compliance objectives.

Mexico Federal Law on AI and Algorithms

A draft Mexican federal law on AI and algorithms proposing a risk-based classification system, the National AI Commission (CONAIA), and watermarking requirements for AI-generated content.

Mitigation Strategies

Planned actions (e.g., bias remediation, retraining, feature re-engineering) to address identified AI risks and compliance gaps.

Minnesota CDPA (AI Provisions)

The AI-specific components of the Minnesota Consumer Data Privacy Act.

Model Card

A short, standardized document providing essential information about a machine learning model's performance, limitations, and intended use cases.

Model Disgorgement

A regulatory remedy requiring a company to delete AI models or algorithms that were developed using improperly or unlawfully acquired data.

Model Drift

The degradation of an AI model's predictive performance over time due to changes in real-world data or the environment.

Model Explainability

Techniques and documentation that make an AI model’s decision logic understandable to stakeholders and auditors.

Model Governance

The policies, roles, and controls that ensure AI models are developed, approved, and used in line with organizational standards and regulatory requirements.

Model Monitoring

Continuous tracking of an AI model’s performance, data drift, and operational metrics to detect degradation or emerging risks.

Model Retraining

The process of updating an AI model with new or refreshed data to maintain performance and compliance as data distributions evolve.

Model Risk Management

Model risk management is the discipline of identifying, measuring and controlling the risk that a model produces incorrect or misused output. In US banking it is set by SR 26-2, issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026, which supersedes SR 11-7 and expressly excludes generative and agentic AI from its scope.

Model Validation

The evaluation activities (e.g., testing against hold-out data, stress scenarios) that confirm an AI model meets its intended purpose and performance criteria.

Multi-Stakeholder Engagement

Involving diverse groups (e.g., legal, ethics, operations, end users) in AI governance processes to ensure balanced risk oversight and alignment with business goals.

N

NIST AI Risk Management Framework

A voluntary guidance from the U.S. National Institute of Standards and Technology outlining best practices for mitigating risks across AI system lifecycles.

NIST AI RMF Profiles

NIST AI RMF Profiles are tailored implementations of the NIST AI Risk Management Framework. NIST defines three types: use-case profiles for specific applications, cross-sectoral profiles that apply across industries, and temporal profiles describing an organization's Current and Target state. The first cross-sectoral profile, the Generative AI Profile (NIST AI 600-1), was published in July 2024.

Non-Human Identity (NHI)

A digital credential used by an AI agent, bot, or service to authenticate and interact with enterprise systems.

Notified Body

An independent third-party organization designated by an EU member state to assess the conformity of certain high-risk AI systems under the EU AI Act.

NYC Local Law 144

A New York City law requiring annual bias audits for AI tools used in employment decisions.

O

Observability

The capability to infer an AI system’s internal state and behavior through collection and analysis of logs, metrics, and outputs for effective monitoring and troubleshooting.

OMB Memorandum M-25-21

OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, directs US federal agencies to appoint a Chief AI Officer, publish an AI use case inventory, and apply minimum risk management practices to "high-impact AI". Issued in April 2025, it replaced M-24-10 and is paired with M-25-22 on AI acquisition.

Ongoing Monitoring

Continuous tracking of AI system performance, data drift, bias metrics, and security events to detect and address emerging risks over time.

Operational Autonomy

The ability of an AI system to perform multi-step tasks and make decisions without human intervention at each stage.

Operational Resilience

The ability of AI systems and their supporting infrastructure to anticipate, withstand, recover from, and adapt to disruptions or adverse events.

Output Risk

The operational, legal, and reputational danger arising from the use of incorrect, biased, or harmful content generated by an AI system.

Oversight

The structured process of review, approval, and accountability for AI development and deployment, typically involving cross-functional governance bodies.

OWASP Agentic Top 10

The OWASP Top 10 for Agentic Applications is a peer-reviewed list of the ten most critical security risks in autonomous AI agents, published by the OWASP Gen AI Security Project on December 10, 2025. Its entries are coded ASI01 to ASI10, from Agent Goal Hijack through to Rogue Agents.

P

Paved Road Governance

A strategy that encourages compliance by making sanctioned, secure workflows easier to follow than unsanctioned alternatives.

Permissioning

The management of user and system access rights to AI data and functions, ensuring least-privilege and preventing unauthorized use.

Pilot Testing

A limited-scope trial of an AI system in a controlled environment to assess performance, risks, and governance controls before full-scale deployment.

Policy Enforcement

The automated or manual mechanisms that ensure AI operations adhere to organizational policies, regulatory rules, and ethical guidelines.

Post-Deployment Monitoring

Ongoing observation of AI system behavior and environment after release to detect degradation, drift, or compliance breaches.

PRA SS1/23 (Model Risk Management)

PRA Supervisory Statement SS1/23 sets out the Bank of England's five model risk management principles for UK banks. Published on May 17, 2023, and effective from May 17, 2024, it applies to UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval. It covers AI and machine learning models, and it does not apply to insurers.

Presumption of Conformity

A legal mechanism under EU AI Act and other regimes whereby compliance with a harmonized standard (e.g., a published EN standard) provides a rebuttable assumption that the underlying regulation is satisfied.

Privacy by Design

An approach that embeds data protection and user privacy considerations into AI system architecture and processes from the outset.

Privacy Impact Assessment

A structured analysis to identify and mitigate privacy risks associated with AI systems, covering data collection, use, sharing, and retention.

Probabilistic System

A system where outputs are based on statistical likelihood rather than deterministic, fixed logic.

Q

Qualitative Assessment

The subjective review of AI system behaviors, decisions, and documentation by experts to identify ethical, legal, or reputational concerns not captured quantitatively.

Quality Assurance

The systematic processes and checks to ensure AI models and data pipelines meet defined standards for accuracy, reliability, and ethical compliance.

Quality Control

The ongoing verification of AI outputs and processes against benchmarks and test cases to catch defects, bias incidents, or policy violations.

Quantitative Risk Assessment

A data-driven evaluation of potential AI threats, estimating likelihoods and impacts numerically to prioritize mitigation efforts.

Query Privacy

Techniques and policies to protect sensitive information in user queries, ensuring that logged inputs do not compromise personal or proprietary data.

Questionnaire Framework

A structured set of governance-focused questions used during design, procurement, or deployment to ensure AI systems align with policy requirements.

Quorum for Governance Board

The minimum number of governance committee members required to be present to make official decisions on AI risk, policy approvals, or audit outcomes.

Quota Management

The controls and limits placed on AI resource usage (e.g., API calls, compute time) to enforce governance policies and prevent runaway costs or abuse.

R

Reasoning Chain

The multi-step logical process an AI agent follows to move from an initial objective to a final action or output.

Recourse

Mechanisms that allow affected individuals to challenge or seek remedy for AI-driven decisions that impact their rights or interests.

Red Teaming

A proactive testing approach where internal or external experts simulate attacks or misuse scenarios to uncover vulnerabilities in AI systems.

Regulatory Compliance

Ensuring AI systems adhere to applicable laws, regulations, and industry standards (e.g., GDPR, FDA, financial oversight) throughout their operation.

Responsibility Assignment Matrix

A tool (e.g., RACI) that clarifies roles and accountabilities for each governance activity - who’s Responsible, Accountable, Consulted, and Informed.

Responsible AI

The practice of designing, developing, and deploying AI systems in ways that are ethical, transparent, and accountable to stakeholders and society.

Risk Assessment

The process of identifying, analyzing, and prioritizing potential harms or failures in AI systems to determine appropriate mitigation strategies.

Risk Management Framework

A structured set of guidelines and processes for systematically addressing AI risks across the system lifecycle, from design through retirement.

Root Cause Analysis

A structured investigation to determine the underlying reasons for AI system failures or unexpected behaviors, guiding corrective actions.

S

Sanctioned Use Policy

Defined rules and controls that specify approved contexts, users, and purposes for AI system operation to prevent misuse.

Security by Design

Integrating security controls and best practices into AI systems from the earliest design phases to prevent vulnerabilities and data breaches.

Shadow Agents

Unsanctioned autonomous AI agents deployed within an organization without governance team awareness, capable of taking actions that affect business systems and external parties.

Shadow AI

The unsanctioned use of AI models, agents, or tools by employees without IT approval, creating hidden security vulnerabilities through data leakage and unauthorized autonomous actions.

Singapore Model AI Governance Framework

Singapore's Model AI Governance Framework is voluntary guidance issued by the IMDA for deploying AI responsibly. It now exists in three editions: the original framework first published in 2019, a generative AI edition released in 2024, and a Model AI Governance Framework for Agentic AI launched on January 22, 2026.

South Korea AI Basic Act

South Korea's comprehensive legal framework for AI development and trust.

Societal Impact Assessment

A structured evaluation of how an AI system affects social, economic, and cultural aspects of communities, identifying potential harms and benefits.

SR 11-7 (Model Risk Management)

SR 11-7 was the US Federal Reserve and OCC's supervisory guidance on model risk management, issued on April 4, 2011. For fifteen years it set the benchmark for model validation, model inventories and independent review in US banking. It was superseded on April 17, 2026, by SR 26-2, revised guidance issued jointly by the Federal Reserve, OCC and FDIC.

SR 26-2 (Revised Guidance on Model Risk Management)

SR 26-2 is the revised US supervisory guidance on model risk management, issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026. It supersedes SR 11-7 and SR 21-8, sets out a risk-based approach tailored to a banking organization's model risk profile, and expressly excludes generative and agentic AI from its scope.

Stakeholder Engagement

The process of involving affected parties (e.g., users, regulators, impacted communities) in AI development and oversight to ensure diverse perspectives and buy-in.

Statement of Applicability (SoA)

A document that identifies which ISO 42001 Annex A controls are relevant to an organization's AI Management System and explains why others were excluded.

Substantial Modification

A change to an AI system after it has been placed on the market that affects its compliance or intended purpose under the EU AI Act.

Surveillance Risk

The threat that AI systems may be exploited for invasive monitoring of individuals or groups, infringing on privacy and civil liberties.

System of Record

The authoritative data source for a given data element or piece of information within an organization.

Systemic Risk Threshold

The technical or capability-based limit (e.g., 10^25 FLOPs) that classifies a General-Purpose AI model as posing a high level of risk to society.

T

Tail Risk

The potential for rare, extreme outcomes in AI behavior or decision-making that fall outside normal expectations and require special mitigation planning.

Testing & Validation

The systematic process of evaluating AI models against benchmarks, edge cases, and stress conditions to ensure they meet performance, safety, and compliance criteria.

Third-Party Risk

The exposure arising from reliance on external data providers, model vendors, or service platforms that may introduce compliance or security vulnerabilities.

Threshold Setting

Defining boundaries or cut-off values in AI decision rules (e.g., confidence scores) to balance risks like false positives versus false negatives.

Trilogue

The informal three-way negotiation between the European Commission, the Council of the European Union, and the European Parliament used to reach political agreement on EU legislation before formal adoption.

Trustworthy AI

AI systems designed and operated in a manner that is ethical, reliable, safe, and aligned with human values and societal norms.

U

UK AI Opportunities Action Plan

The UK government's strategic roadmap for maximizing AI benefits while establishing targeted, binding safety rules.

Use Case Governance

The practice of defining, approving, and monitoring specific AI use cases to ensure each aligns with organizational policies, ethical standards, and risk appetite.

User Consent

The process of obtaining and recording explicit permission from individuals before collecting, processing, or using their personal data in AI systems.

V

Variance Monitoring

Tracking fluctuations in AI model outputs or performance metrics over time to detect drift and infer potential degradation or risk.

Vendor Risk Management

Assessing and monitoring third-party suppliers of AI components or services to identify and mitigate potential compliance, security, or ethical risks.

Version Pinning

The practice of locking an AI system to a specific, tested version of a foundation model to prevent silent updates from changing system behavior.

Veto Authority

The formal right held by a governance body or stakeholder to block or require changes to AI deployments that pose unacceptable risks.

Vigilance Monitoring

Continuous surveillance of AI behavior and external signals (e.g., regulatory updates) to promptly identify and respond to emerging risks or non-compliance.

Vision AI Oversight

The governance processes specific to computer vision systems, ensuring data quality, bias checks, and transparency in image/video-based decision-making.

W

Watchdog Monitoring

Independent runtime checks that observe AI decisions and trigger alerts or interventions when policies or thresholds are violated.

Watermarking

The practice of embedding detectable, machine-readable provenance markers in AI-generated output, such as images, audio, video, and synthetic text, so downstream consumers and platforms can identify content as AI-generated.

Weight Auditing

Examining model weights and structures for anomalies, backdoors, or biases that could indicate tampering or unintended behaviors.

Whitelist/Blacklist Policy

Governance rule defining allowed (whitelist) and disallowed (blacklist) inputs, features, or operations to enforce compliance and prevent misuse.

Whitelisting

Allowing only pre-approved data sources, libraries, or model components in AI pipelines to reduce risk from unvetted or malicious elements.

Workload Segregation

Separating AI compute environments (e.g., dev, test, prod) and data domains to limit blast radius of failures or security breaches.

Worst-Case Analysis

Evaluating the most extreme potential failures or abuses of an AI system to inform robust risk mitigation and contingency planning.

Write-Once Read-Many (WORM) Storage

Immutable storage ensuring logs, audit trails, and model artifacts cannot be altered once written, supporting non-repudiation and forensic review.

X

XAI Audit

A review process that evaluates whether AI explainability outputs meet internal policies and regulatory requirements, ensuring sufficient transparency.

XAI (Explainable AI)

Techniques and methods that make an AI model’s decision process transparent and understandable to humans, supporting accountability and compliance.

XAI Framework

A structured approach or set of guidelines that organizations use to implement, measure, and govern explainability practices across their AI systems.

XAI Metrics

Quantitative or qualitative measures (e.g., feature importance scores, explanation fidelity) used to assess the quality and reliability of AI explanations.

Y

Yearly Compliance Review

An annual evaluation of AI governance processes, policies, and systems to ensure continued alignment with regulations and internal standards.

Z

Zero Defect Tolerance

A governance principle aiming for no errors or policy violations in AI outputs, supported by rigorous testing, monitoring, and continuous improvement cycles.

Zone-Based Access Control

A network or data governance approach that divides resources into zones with distinct policies, restricting AI system access according to data sensitivity.

All

Whitepaper

AI Regulations

Podcasts

Product Updates

Press Coverage

Glossary

Join our podcast or collaborate on content

Reach out and we’ll see what we can produce together.

A

Acceptable Use Policy (AUP)

A set of rules applied by an organization that outlines the permitted and prohibited ways employees may interact with company-provided AI tools.

Accredited Certification

A certificate issued by a certification body that has been formally recognized by a national accreditation body (like ANAB or UKAS) as competent to audit against a specific standard.

Action Preview

A governance requirement where an AI agent must display exactly what an irreversible operation will do before a human provides final approval.

Action Whitelisting

A security and governance control that specifies the only permitted tools, APIs, and actions an AI agent is allowed to execute.

Adversarial Attack

Techniques that manipulate AI models by introducing deceptive inputs to cause incorrect outputs.

Agent Fabric

An integrated runtime substrate that hosts, orchestrates, and governs multiple AI agents alongside the models, tools, and data they depend on.

Agent Goal Hijack (ASI01)

A vulnerability where an attacker manipulates an agent's objectives or decision pathways to redirect its autonomous behavior toward unintended outcomes.

Agent Mesh

A networked topology in which AI agents discover, communicate with, and delegate work to one another through a shared infrastructure layer.

Agentic AI

A class of artificial intelligence systems designed to autonomously pursue complex goals and execute multi-step actions (such as software deployment or financial transactions) with minimal human intervention.

Agentic AI Governance

Agentic AI governance is the control of AI systems that plan and take actions on their own, as opposed to systems that only produce predictions or content. It covers what an agent is permitted to do, the limits on its autonomy, how its actions are logged, and who is accountable when an agent acts wrongly.

Agentic Policy Engine

A runtime software component that intercepts agent actions and evaluates them against a set of deterministic governance rules before execution.

AI Accountability

The obligation of AI system developers and operators to ensure their systems are designed and used responsibly, adhering to ethical standards and legal requirements.

AI Alignment

The process of ensuring AI systems' goals and behaviors are aligned with human values and intentions.

AI Assistant

A conversational AI system designed to help users complete tasks through natural language interaction, typically powered by a large language model.

AI Auditing

The systematic evaluation of AI systems to assess compliance with ethical standards, regulations, and performance metrics.

AI Bias

Systematic errors in AI outputs resulting from prejudiced training data or flawed algorithms, leading to unfair outcomes.

AI Bill of Materials (AIBOM)

A structured inventory listing the components that make up an AI system, including foundation models, training datasets, libraries, and dependencies - the AI equivalent of a Software Bill of Materials (SBOM).

AI Compliance

The adherence of AI systems to applicable laws, regulations, and ethical guidelines throughout their lifecycle.

AI Ethics

The field concerned with the moral implications and responsibilities associated with the development and deployment of AI technologies.

AI Explainability

The extent to which the internal mechanics of an AI system can be understood and interpreted by humans.

AI Footprint

The total set of AI systems, models, agents, and embedded AI features in use across an organization at any given time, including sanctioned and shadow systems.

AI Governance

The framework of policies, processes, and controls that guide the ethical and effective development and use of AI systems.

AI Governance for Financial Services

AI governance for financial services is the application of AI risk and compliance controls under the sector's supervisory regimes. The relevant rules differ by jurisdiction and by firm type: SR 26-2 for larger US banks, PRA SS1/23 for UK banks with internal model approval, MAS FEAT in Singapore, and the EU AI Act across all of them.

AI Governance Software

Specialized enterprise tools used to automate the inventory, risk assessment, and regulatory compliance of artificial intelligence systems.

AI Inventory

A comprehensive, centralized catalog of all AI systems, models, and agents in use across an organization, tracking their business purpose, risk level, and ownership.

EU AI Liability Directive

A proposed EU directive aimed at simplifying the process for claimants to seek damages caused by AI systems by introducing a rebuttable presumption of causality.

AI Literacy

The understanding of AI concepts, capabilities, and limitations, enabling informed interaction with AI technologies.

Artificial Intelligence Management System (AIMS)

A set of interrelated or interacting elements of an organization to establish policies, objectives, and processes for the responsible development or use of AI.

AI Monitoring

AI monitoring is the continuous observation of AI systems in production to detect degradation, drift, unsafe behavior and control failures. It covers model performance, input and output distributions, fairness metrics, cost and latency, and for agentic systems the actions the system takes.

AI Risk

The potential for AI systems to cause harm or unintended consequences, including ethical, legal, and operational risks.

AI Risk Management

The process of identifying, assessing, and mitigating risks associated with AI systems.

AI Sprawl

The uncontrolled expansion of AI systems across an organization, typically driven by easy access to AI tools and a lack of effective intake and inventory processes.

AI System Impact Assessment

A formal process to evaluate the potential consequences of an AI system's deployment on individuals, groups, and society at large.

AI Transparency

The principle that AI systems should be open and clear about their operations, decisions, and data usage.

AI TRiSM

An acronym coined by Gartner standing for AI Trust, Risk, and Security Management; a framework that unifies governance, trustworthiness, and security into a single operational strategy.

Artificial Intelligence and Data Act (AIDA)

Canada's federal regulatory framework (part of Bill C-27) aimed at ensuring high-impact AI systems are developed and used safely and without bias.

Algorithmic Bias

Bias that occurs when an algorithm produces results that are systemically prejudiced due to erroneous assumptions in the machine learning process.

Algorithmic Governance

The use of algorithms to manage and regulate societal functions, potentially impacting decision-making processes.

Amnesty Program

A time-limited governance initiative where employees are invited to disclose unsanctioned AI tool usage without fear of disciplinary action.

Annex I Products

A list of products already regulated by EU health and safety law (e.g., machinery, medical devices) where AI integrated under the EU AI Act is automatically classified as high-risk.

Annex III Categories

A specific list of high-risk AI application areas defined by the EU AI Act that trigger mandatory compliance obligations.

API Traffic Analysis

The technical process of monitoring and inspecting network calls made to external AI service providers.

Article 6(3) Exception

A self-determination mechanism under the EU AI Act allowing providers to classify an Annex III AI system as not high-risk if it poses no significant harm.

Article 25 (EU AI Act)

The EU AI Act provision creating a direct obligation chain between providers and deployers of high-risk AI systems, including responsibility transfer when systems are substantially modified.

Article 50 (EU AI Act)

The EU AI Act provision setting transparency obligations for AI systems that interact with people, generate synthetic content, or produce deepfakes.

Australia Safe & Responsible AI Policy

The Australian federal policy governing the use of AI within the public service and government agencies.

Automated AI Governance

The use of software and API integrations to perform continuous, real-time compliance checks and risk monitoring without manual intervention.

B

Bias Amplification

The phenomenon where AI systems exacerbate existing biases present in the training data, leading to increasingly skewed outcomes.

Bias Audit

An evaluation process to detect and mitigate biases in AI systems, ensuring fairness and compliance with ethical standards.

Bias Detection

The process of identifying biases in AI models by analyzing their outputs and decision-making processes.

Bias Mitigation

Techniques applied during AI development to reduce or eliminate biases in models and datasets.

Brazil AI Bill (PL 2338/2023)

PL 2338/2023 is Brazil's proposed legal framework for artificial intelligence. It classifies AI systems by risk, grants rights to explanation and human review, and creates a national oversight system coordinated by the data protection authority. The Senate approved it in December 2024 and it remains before the Chamber of Deputies, so it is not yet law.

Brussels Effect

The phenomenon whereby EU regulation becomes the global default through market access requirements, even for organizations headquartered outside the EU.

C

California AB 1008

An amendment to the CCPA clarifying that personal information includes data generated or output by AI systems.

California AB 3030

A California law requiring transparency when Generative AI is used to communicate with patients in a healthcare setting.

California ADMT Regulations

Rules under the California Consumer Privacy Act (CCPA) governing Automated Decision-Making Technology (ADMT).

California FEHA AI Regulations

State regulations under the Fair Employment and Housing Act (FEHA) targeting AI-driven discrimination in the workplace.

California AI Transparency Act (SB 942)

The California AI Transparency Act, SB 942 as amended by AB 853, requires providers of widely used generative AI systems to embed provenance disclosures in AI-generated image, video and audio content and to publish a free public detection tool. It became operative on August 2, 2026, and is enforced by the California Attorney General.

Cascading Failure (ASI08)

A failure mode where an error or malicious input in one AI agent's reasoning triggers a chain reaction of failures across multiple connected agents or systems.

CE Marking

A mandatory certification mark that indicates an AI system's conformity with health, safety, and environmental protection standards for products sold within the EEA.

Change Notification Window

A contractual period during which a vendor must inform a customer of material updates to an AI model before those updates are deployed in production.

China Interim GenAI Measures

Regulatory requirements for generative AI services provided to the Chinese public.

Council of Europe AI Convention

The first legally binding international treaty on AI, focusing on the protection of human rights, democracy, and the rule of law.

Colorado AI Act (SB 24-205, repealed 2026)

The Colorado AI Act (SB 24-205), the first broad U.S. state AI law, was repealed in May 2026 and replaced by Colorado SB 26-189, which takes effect January 1, 2027, with a narrower focus on automated decision-making technology.

Colorado AI Act (SB 26-189)

Colorado SB 26-189 is the 2026 replacement for the original Colorado AI Act (SB 24-205), taking effect January 1, 2027, with obligations focused on automated decision-making technology making consequential decisions about Coloradans.

Compliance Framework

A structured set of guidelines and best practices that organizations follow to ensure their AI systems meet regulatory and ethical standards.

Compliance Risk

The potential for legal or regulatory sanctions, financial loss, or reputational damage an organization faces when it fails to comply with laws, regulations, or prescribed practices.

Concept Drift

The change in the statistical properties of the target variable, which the model is trying to predict, over time, leading to model degradation.

Conformity Assessment

A process to determine whether an AI system meets specified requirements, standards, or regulations, often involving testing and certification.

Internal Control (Conformity Assessment)

A process under the EU AI Act where a provider self-verifies that their high-risk AI system meets all regulatory requirements without requiring a third-party audit.

Controllability

The extent to which humans can direct, influence, or override the decisions and behaviors of an AI system.

COREPER Mandate

The negotiating authority granted by EU member state ambassadors (Committee of Permanent Representatives) to the rotating Council Presidency for trilogue negotiations on EU legislation.

Cryptographic Agent Identity

A verifiable digital credential (often a Decentralized Identifier or DID) that uniquely identifies an AI agent and its authority level.

D

Data Drift

The change in model input data over time, which can lead to model performance degradation if not monitored and addressed.

Data Ethics

The branch of ethics that evaluates data practices with respect to the moral obligations of gathering, protecting, and using personally identifiable information.

Data Governance

The overall management of data availability, usability, integrity, and security in an enterprise, ensuring that data is handled properly throughout its lifecycle.

Data Ingestion Risk

The danger that sensitive or proprietary information will be permanently absorbed into an AI model's training set during a user's interaction.

Data Lifecycle Management

The policy-based management of data flow throughout its lifecycle: from creation and initial storage to the time it becomes obsolete and is deleted.

Data Minimization

The principle of collecting only the data that is necessary for a specific purpose, reducing the risk of misuse or breach.

Data Privacy

The aspect of information technology that deals with the ability to control what data is shared and with whom, ensuring personal data is handled appropriately.

Data Protection

The process of safeguarding important information from corruption, compromise, or loss, ensuring compliance with data protection laws and regulations.

Data Provenance

A documented record of the origin, ownership, and lifecycle of a dataset used to train or fine-tune an AI model.

Data Quality

The condition of data based on factors such as accuracy, completeness, reliability, and relevance, crucial for effective AI model performance.

Data Residency

Data residency is the requirement that data be stored and processed in a particular country or region. In AI systems it applies to training data, prompts, model outputs and inference logs, and it constrains which models a firm can call, since sending a prompt to a model hosted elsewhere is a cross-border transfer.

Data Sovereignty

The concept that data is subject to the laws and governance structures within the nation it is collected, stored, or processed.

Data Subject

An individual whose personal data is collected, held, or processed, particularly relevant in the context of data protection laws like GDPR.

De-identification

The process of removing or obscuring personal identifiers from data sets, making it difficult to identify individuals, used to protect privacy.

Deepfake

Synthetic media in which a person in an existing image or video is replaced with someone else's likeness, created using deep learning techniques.

Differential Privacy

A system for publicly sharing information about a dataset by describing patterns of groups within the dataset while withholding information about individuals.

EU Digital Omnibus on AI

A 2025/2026 legislative package designed to streamline and harmonize technical standards, conformity assessments, and enforcement timelines across the EU AI Act and related digital safety laws.

Discrimination

In AI, refers to unfair treatment of individuals or groups based on biases in data or algorithms, leading to unequal outcomes.

Dual-Use Foundation Model

An AI model that is trained on a vast amount of data and has high-level performance that could be used for both civilian and harmful or military purposes.

Dynamic Risk Assessment

The continuous process of identifying and evaluating risks in real-time, allowing for timely responses to emerging threats in AI systems.

E

Edge Analytics

The analysis of data at the edge of the network, near the source of data generation, reducing latency and bandwidth usage.

Enzai

An enterprise AI governance platform that enables organizations to inventory, assess, and control their AI systems, ensuring maxmize AI adoption while minimizing AI risk.

Escalation Logic

A set of predefined rules and triggers that force an AI agent to stop autonomous operation and hand control back to a human operator.

ESMA AI/ML Governance Expectations

ESMA's AI and machine learning expectations set out how EU investment firms must apply MiFID II obligations when using AI. The European Securities and Markets Authority issued guidance on AI in retail investment services in May 2024, followed by a supervisory briefing on algorithmic trading on February 26, 2026, that addresses AI and its interaction with the EU AI Act.

Ethical AI

The practice of designing, developing, and deploying AI systems in a manner that aligns with ethical principles and values, ensuring fairness, accountability, and transparency.

Ethical AI Auditing

The process of systematically evaluating AI systems to ensure they comply with ethical standards and do not cause harm.

Ethical AI Certification

A formal recognition that an AI system adheres to established ethical standards and guidelines.

Ethical AI Governance

The framework of policies, procedures, and practices that ensure AI systems are developed and used responsibly and ethically.

Ethical Frameworks

Structured sets of principles and guidelines designed to guide the ethical development and deployment of AI systems.

Ethical Impact Assessment

A systematic evaluation process to identify and address the ethical implications and potential societal impacts of AI systems before deployment.

Ethical Risk

The potential for an AI system to cause harm due to unethical behavior, including bias, discrimination, or violation of privacy.

Ethics Guidelines for Trustworthy AI

A set of guidelines developed by the European Commission's High-Level Expert Group on AI to promote trustworthy AI, focusing on human agency, technical robustness, privacy, transparency, diversity, societal well-being, and accountability.

EU AI Act

The world's first comprehensive horizontal legal framework for AI, establishing a risk-based classification system for systems deployed or used within the European Union.

EU AI Act High-Risk Categories

The two classifications of high-risk AI systems under the EU AI Act: standalone systems listed in Annex III (covering biometrics, critical infrastructure, employment, education, law enforcement, and other named uses), and AI embedded in regulated products listed in Annex I (covering medical devices, vehicles, machinery, and other regulated product categories).

EU AI Act Risk Classification

The mandatory process of assigning one of four risk levels (Unacceptable, High, Limited, Minimal) to an AI system under the EU AI Act.

EU AI Office

The European Commission body established to oversee implementation and enforcement of the EU AI Act, particularly for general-purpose AI models with systemic risk.

EU Digital Omnibus

The European Union's broader 2025-2026 legislative simplification package addressing multiple digital regulations including the AI Act, GDPR provisions, the Cyber Resilience Act, and Data Act amendments.

Excessive Agency

A vulnerability where an AI system is granted too much autonomy, too many tools, or over-privileged access relative to its intended function.

Executive Order 14110

The Biden administration directive (signed October 2023, rescinded January 2025) that established U.S. national standards for AI safety, security, and privacy and created the U.S. AI Safety Institute at NIST.

Explainability Techniques

Methods used to interpret and understand the decisions made by AI models, such as LIME, SHAP, and saliency maps.

Explainability vs. Interpretability

While both aim to make AI decisions understandable, explainability focuses on the reasoning behind decisions, whereas interpretability relates to the transparency of the model's internal mechanics.

Explainable AI (XAI)

AI systems designed to provide human-understandable justifications for their decisions and actions, enhancing transparency and trust.

Explainable Machine Learning

Machine learning models designed to provide clear and understandable explanations for their predictions and decisions.

F

Fairness Metrics

Quantitative measures (e.g., demographic parity, equalized odds) used to evaluate how fair an AI model’s predictions are across groups.

False Negative

When an AI model incorrectly predicts a negative class for an instance that is actually positive (Type II error).

False Positive

When an AI model incorrectly predicts a positive class for an instance that is actually negative (Type I error).

Fault Tolerance

The ability of an AI system to continue operating correctly even when some components fail or produce errors.

Federated AI Governance

A governance model where central policy and oversight are paired with distributed decision-making by business units or regional offices, balancing consistency with operational flexibility.

Feedback Loop

A process where AI outputs are fed back as inputs, which can amplify model behavior - for better (reinforcement learning) or worse (bias reinforcement).

FS AI RMF (Financial Services AI Risk Management Framework)

The Financial Services AI Risk Management Framework (FS AI RMF) is a voluntary, sector-specific framework published in February 2026 by the US Treasury with the Cyber Risk Institute. It aligns to the NIST AI RMF and provides a matrix of 230 control objectives across the AI lifecycle, covering banks, credit unions, insurers, investment firms and their third-party providers.

Functional Safety

Ensuring AI systems operate safely under all conditions, especially in industries like automotive or healthcare, often via redundancy and checks.

Fundamental Rights Impact Assessment (FRIA)

A mandatory evaluation under the EU AI Act for certain deployers to determine how the use of a high-risk AI system might impact civil liberties and human rights.

G

Gap Analysis

The process of comparing current AI governance practices against desired standards or regulations to identify areas needing improvement.

GDPR

The EU’s General Data Protection Regulation, establishing strict requirements for personal data collection, processing, and individual rights.

Goal Drift

A phenomenon where an AI agent's internal sub-goals or reasoning pathways gradually move away from the original human-provided objective.

Governance Body

A cross-functional group (e.g., legal, ethics, technical) tasked with overseeing AI governance policies and their execution within an organization.

Governance Framework

A structured model outlining how AI governance components (risk management, accountability, oversight) fit together to ensure compliance and ethical use.

Governance Maturity Model

A governance maturity model is a staged scale for assessing how developed an organization's AI governance is, typically running from ad hoc practice through to measured and continuously improved. It is used to benchmark a starting position, set a realistic target and sequence investment, not to certify compliance.

Governance Policy

A formal document that codifies rules, roles, and procedures for AI development and oversight within an organization.

Governance Scorecard

A dashboard or report card that tracks key metrics (e.g., bias incidents, compliance audits) to measure AI governance effectiveness over time.

GPAI Code of Practice

The detailed regulatory instrument outlining specific transparency, safety testing, and risk mitigation obligations for providers of General-Purpose AI (GPAI) models under the EU AI Act.

GPAI Model

A general-purpose artificial intelligence model capable of performing a wide range of distinct tasks and integrating into various applications.

Granular Consent

A data-privacy approach allowing individuals to grant or deny specific permissions for each type of data use, enhancing transparency and control.

Guardrails

Predefined constraints or checks (technical and policy) embedded in AI systems to prevent unsafe or non-compliant behavior at runtime.

Guideline (Ethical AI)

A non-binding recommendation or best-practice document issued by organizations (e.g., IEEE, EU) to shape responsible AI development and deployment.

H

Hallucination

When generative AI produces incorrect or fabricated information that appears plausible but has no basis in the training data.

Harm Assessment

Evaluating potential negative impacts (physical, psychological, societal) of AI systems and defining mitigation strategies.

Harmonization

Aligning AI policies, standards, and regulations across jurisdictions to reduce conflicts and enable interoperability.

Harmonized Structure

A standardized template for all ISO management system standards, formerly known as Annex SL, ensuring consistency in terminology and clause numbering.

Heuristic Evaluation

A usability inspection method where experts judge an AI system against established usability principles to identify potential issues.

High-Risk AI System

AI applications that have a significant potential to harm the health, safety, or fundamental rights of individuals, triggering the most stringent compliance requirements under the EU AI Act.

High-Stakes AI

AI applications whose failures could cause significant harm (e.g., medical diagnosis, autonomous vehicles), requiring heightened governance and oversight.

Human-in-the-Loop

Involving human judgment within AI processes (training, validation, decision review) to improve accuracy and accountability.

Human Oversight

Mechanisms that allow designated individuals to monitor, intervene, or override AI system decisions to ensure ethical and legal compliance.

Human Rights Impact Assessment

A process to evaluate how AI systems affect fundamental rights (privacy, expression, non-discrimination) and identify mitigation measures.

I

Impact Assessment

A structured evaluation to identify, analyze, and mitigate potential ethical, legal, and societal impacts of an AI system before deployment.

Implementing Acts

Secondary EU legislation adopted by the European Commission to set uniform conditions for implementing primary legislation, with binding legal effect across all Member States.

Incentive Alignment

The design of reward structures and objectives so that AI systems’ goals remain consistent with human values and organizational priorities.

Inductive Bias

The set of assumptions a learning algorithm uses to generalize from observed data to unseen instances.

Information Governance

The policies, procedures, and controls that ensure data quality, privacy, and usability across an organization’s data assets, including AI training datasets.

Information Privacy

The right of individuals to control how their personal data are collected, used, stored, and shared by AI systems.

Inherited Data Risk

The regulatory and ethical liability an organization assumes when using an AI system trained on data they did not collect or vet themselves.

Intake Workflow

The standardized process and series of checks that a new AI system must pass through before being built or procured.

Intent Validation

The process of verifying that an AI agent's planned sub-actions remain consistent with the original human-provided objective.

Interoperability

The ability of diverse AI systems and components to exchange, understand, and use information seamlessly, often via open standards or APIs.

Interpretability

The degree to which a human can understand the internal mechanics or decision rationale of an AI model.

ISO/IEC 42001

The international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS).

ISO/IEC 42005

The international standard providing guidance on performing AI system impact assessments.

ISO/IEC JTC 1/SC 42

The joint ISO/IEC committee on Artificial Intelligence standardization, developing international AI standards for governance, risk, and interoperability.

J

Jailbreak Attack

A type of prompt‐injection where users exploit vulnerabilities to bypass safeguards in generative AI models, potentially leading to unsafe or unauthorized outputs.

Japan Act on Promotion of AI

A Japanese law (enacted 2025) establishing basic principles for AI promotion and risk mitigation.

Joint Liability

Legal principle where multiple parties (e.g., developers, deployers) share responsibility for AI‐related harms, influencing contract and governance structures.

Joint Modeling

Building AI systems that jointly learn multiple tasks (e.g., speech recognition + translation), with governance needed for complexity and auditability.

Jurisdiction

The legal authority over data, AI operations, and liability, which varies by geography and impacts compliance with regional regulations (e.g., GDPR, CCPA).

K

Key Performance Indicator

A quantifiable metric (e.g., model accuracy drift, bias remediation time) used to monitor and report on AI governance and compliance objectives.

Key Risk Indicator

A leading metric (e.g., frequency of out-of-scope predictions, rate of unexplainable decisions) that signals emerging AI risks before they materialize.

Knowledge Management

Practices and tools for capturing, organizing and sharing organizational knowledge (e.g., model documentation, audit logs) to ensure reproducibility and oversight.

L

Least Agency

A security and governance principle stating that AI agents should only be granted the minimum level of autonomy and tool-access necessary to complete a specific task.

Least Privilege

A security principle where AI components and users are granted only the minimal access rights necessary to perform their functions, reducing risk of misuse.

Legal Compliance

The practice of ensuring AI systems adhere to applicable laws, regulations, and industry standards throughout their entire lifecycle.

Liability Framework

A structured approach defining who is responsible for AI-related harms or failures, including developers, deployers, and operators.

Lifecycle Management

The coordinated processes for development, deployment, monitoring, maintenance, and retirement of AI systems to ensure ongoing compliance and risk control.

Localization

Adapting AI systems to local languages, regulations, cultural norms, and data residency requirements in different jurisdictions.

M

Market Surveillance Authority

The national regulatory body in each EU member state responsible for monitoring AI systems to ensure they comply with the EU AI Act.

MAS FEAT Principles

The MAS FEAT Principles are four principles covering Fairness, Ethics, Accountability and Transparency, published by the Monetary Authority of Singapore on November 12, 2018, to guide the responsible use of artificial intelligence and data analytics in Singapore's financial sector. They are non-binding guidance, not enforceable rules, and are supported by the Veritas assessment methodology.

Meaningful Human Control

A regulatory and operational standard ensuring that humans retain the ability to oversee, intervene in, and override AI decision-making processes.

Metadata Management

The practice of capturing and maintaining descriptive data (e.g., data provenance, feature definitions, model parameters) to support traceability and audits.

Metrics & KPIs

Quantitative measures (e.g., accuracy drift, fairness scores, incident response time) used to monitor AI system health, risk, and compliance objectives.

Mexico Federal Law on AI and Algorithms

A draft Mexican federal law on AI and algorithms proposing a risk-based classification system, the National AI Commission (CONAIA), and watermarking requirements for AI-generated content.

Mitigation Strategies

Planned actions (e.g., bias remediation, retraining, feature re-engineering) to address identified AI risks and compliance gaps.

Minnesota CDPA (AI Provisions)

The AI-specific components of the Minnesota Consumer Data Privacy Act.

Model Card

A short, standardized document providing essential information about a machine learning model's performance, limitations, and intended use cases.

Model Disgorgement

A regulatory remedy requiring a company to delete AI models or algorithms that were developed using improperly or unlawfully acquired data.

Model Drift

The degradation of an AI model's predictive performance over time due to changes in real-world data or the environment.

Model Explainability

Techniques and documentation that make an AI model’s decision logic understandable to stakeholders and auditors.

Model Governance

The policies, roles, and controls that ensure AI models are developed, approved, and used in line with organizational standards and regulatory requirements.

Model Monitoring

Continuous tracking of an AI model’s performance, data drift, and operational metrics to detect degradation or emerging risks.

Model Retraining

The process of updating an AI model with new or refreshed data to maintain performance and compliance as data distributions evolve.

Model Risk Management

Model risk management is the discipline of identifying, measuring and controlling the risk that a model produces incorrect or misused output. In US banking it is set by SR 26-2, issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026, which supersedes SR 11-7 and expressly excludes generative and agentic AI from its scope.

Model Validation

The evaluation activities (e.g., testing against hold-out data, stress scenarios) that confirm an AI model meets its intended purpose and performance criteria.

Multi-Stakeholder Engagement

Involving diverse groups (e.g., legal, ethics, operations, end users) in AI governance processes to ensure balanced risk oversight and alignment with business goals.

N

NIST AI Risk Management Framework

A voluntary guidance from the U.S. National Institute of Standards and Technology outlining best practices for mitigating risks across AI system lifecycles.

NIST AI RMF Profiles

NIST AI RMF Profiles are tailored implementations of the NIST AI Risk Management Framework. NIST defines three types: use-case profiles for specific applications, cross-sectoral profiles that apply across industries, and temporal profiles describing an organization's Current and Target state. The first cross-sectoral profile, the Generative AI Profile (NIST AI 600-1), was published in July 2024.

Non-Human Identity (NHI)

A digital credential used by an AI agent, bot, or service to authenticate and interact with enterprise systems.

Notified Body

An independent third-party organization designated by an EU member state to assess the conformity of certain high-risk AI systems under the EU AI Act.

NYC Local Law 144

A New York City law requiring annual bias audits for AI tools used in employment decisions.

O

Observability

The capability to infer an AI system’s internal state and behavior through collection and analysis of logs, metrics, and outputs for effective monitoring and troubleshooting.

OMB Memorandum M-25-21

OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, directs US federal agencies to appoint a Chief AI Officer, publish an AI use case inventory, and apply minimum risk management practices to "high-impact AI". Issued in April 2025, it replaced M-24-10 and is paired with M-25-22 on AI acquisition.

Ongoing Monitoring

Continuous tracking of AI system performance, data drift, bias metrics, and security events to detect and address emerging risks over time.

Operational Autonomy

The ability of an AI system to perform multi-step tasks and make decisions without human intervention at each stage.

Operational Resilience

The ability of AI systems and their supporting infrastructure to anticipate, withstand, recover from, and adapt to disruptions or adverse events.

Output Risk

The operational, legal, and reputational danger arising from the use of incorrect, biased, or harmful content generated by an AI system.

Oversight

The structured process of review, approval, and accountability for AI development and deployment, typically involving cross-functional governance bodies.

OWASP Agentic Top 10

The OWASP Top 10 for Agentic Applications is a peer-reviewed list of the ten most critical security risks in autonomous AI agents, published by the OWASP Gen AI Security Project on December 10, 2025. Its entries are coded ASI01 to ASI10, from Agent Goal Hijack through to Rogue Agents.

P

Paved Road Governance

A strategy that encourages compliance by making sanctioned, secure workflows easier to follow than unsanctioned alternatives.

Permissioning

The management of user and system access rights to AI data and functions, ensuring least-privilege and preventing unauthorized use.

Pilot Testing

A limited-scope trial of an AI system in a controlled environment to assess performance, risks, and governance controls before full-scale deployment.

Policy Enforcement

The automated or manual mechanisms that ensure AI operations adhere to organizational policies, regulatory rules, and ethical guidelines.

Post-Deployment Monitoring

Ongoing observation of AI system behavior and environment after release to detect degradation, drift, or compliance breaches.

PRA SS1/23 (Model Risk Management)

PRA Supervisory Statement SS1/23 sets out the Bank of England's five model risk management principles for UK banks. Published on May 17, 2023, and effective from May 17, 2024, it applies to UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval. It covers AI and machine learning models, and it does not apply to insurers.

Presumption of Conformity

A legal mechanism under EU AI Act and other regimes whereby compliance with a harmonized standard (e.g., a published EN standard) provides a rebuttable assumption that the underlying regulation is satisfied.

Privacy by Design

An approach that embeds data protection and user privacy considerations into AI system architecture and processes from the outset.

Privacy Impact Assessment

A structured analysis to identify and mitigate privacy risks associated with AI systems, covering data collection, use, sharing, and retention.

Probabilistic System

A system where outputs are based on statistical likelihood rather than deterministic, fixed logic.

Q

Qualitative Assessment

The subjective review of AI system behaviors, decisions, and documentation by experts to identify ethical, legal, or reputational concerns not captured quantitatively.

Quality Assurance

The systematic processes and checks to ensure AI models and data pipelines meet defined standards for accuracy, reliability, and ethical compliance.

Quality Control

The ongoing verification of AI outputs and processes against benchmarks and test cases to catch defects, bias incidents, or policy violations.

Quantitative Risk Assessment

A data-driven evaluation of potential AI threats, estimating likelihoods and impacts numerically to prioritize mitigation efforts.

Query Privacy

Techniques and policies to protect sensitive information in user queries, ensuring that logged inputs do not compromise personal or proprietary data.

Questionnaire Framework

A structured set of governance-focused questions used during design, procurement, or deployment to ensure AI systems align with policy requirements.

Quorum for Governance Board

The minimum number of governance committee members required to be present to make official decisions on AI risk, policy approvals, or audit outcomes.

Quota Management

The controls and limits placed on AI resource usage (e.g., API calls, compute time) to enforce governance policies and prevent runaway costs or abuse.

R

Reasoning Chain

The multi-step logical process an AI agent follows to move from an initial objective to a final action or output.

Recourse

Mechanisms that allow affected individuals to challenge or seek remedy for AI-driven decisions that impact their rights or interests.

Red Teaming

A proactive testing approach where internal or external experts simulate attacks or misuse scenarios to uncover vulnerabilities in AI systems.

Regulatory Compliance

Ensuring AI systems adhere to applicable laws, regulations, and industry standards (e.g., GDPR, FDA, financial oversight) throughout their operation.

Responsibility Assignment Matrix

A tool (e.g., RACI) that clarifies roles and accountabilities for each governance activity - who’s Responsible, Accountable, Consulted, and Informed.

Responsible AI

The practice of designing, developing, and deploying AI systems in ways that are ethical, transparent, and accountable to stakeholders and society.

Risk Assessment

The process of identifying, analyzing, and prioritizing potential harms or failures in AI systems to determine appropriate mitigation strategies.

Risk Management Framework

A structured set of guidelines and processes for systematically addressing AI risks across the system lifecycle, from design through retirement.

Root Cause Analysis

A structured investigation to determine the underlying reasons for AI system failures or unexpected behaviors, guiding corrective actions.

S

Sanctioned Use Policy

Defined rules and controls that specify approved contexts, users, and purposes for AI system operation to prevent misuse.

Security by Design

Integrating security controls and best practices into AI systems from the earliest design phases to prevent vulnerabilities and data breaches.

Shadow Agents

Unsanctioned autonomous AI agents deployed within an organization without governance team awareness, capable of taking actions that affect business systems and external parties.

Shadow AI

The unsanctioned use of AI models, agents, or tools by employees without IT approval, creating hidden security vulnerabilities through data leakage and unauthorized autonomous actions.

Singapore Model AI Governance Framework

Singapore's Model AI Governance Framework is voluntary guidance issued by the IMDA for deploying AI responsibly. It now exists in three editions: the original framework first published in 2019, a generative AI edition released in 2024, and a Model AI Governance Framework for Agentic AI launched on January 22, 2026.

South Korea AI Basic Act

South Korea's comprehensive legal framework for AI development and trust.

Societal Impact Assessment

A structured evaluation of how an AI system affects social, economic, and cultural aspects of communities, identifying potential harms and benefits.

SR 11-7 (Model Risk Management)

SR 11-7 was the US Federal Reserve and OCC's supervisory guidance on model risk management, issued on April 4, 2011. For fifteen years it set the benchmark for model validation, model inventories and independent review in US banking. It was superseded on April 17, 2026, by SR 26-2, revised guidance issued jointly by the Federal Reserve, OCC and FDIC.

SR 26-2 (Revised Guidance on Model Risk Management)

SR 26-2 is the revised US supervisory guidance on model risk management, issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026. It supersedes SR 11-7 and SR 21-8, sets out a risk-based approach tailored to a banking organization's model risk profile, and expressly excludes generative and agentic AI from its scope.

Stakeholder Engagement

The process of involving affected parties (e.g., users, regulators, impacted communities) in AI development and oversight to ensure diverse perspectives and buy-in.

Statement of Applicability (SoA)

A document that identifies which ISO 42001 Annex A controls are relevant to an organization's AI Management System and explains why others were excluded.

Substantial Modification

A change to an AI system after it has been placed on the market that affects its compliance or intended purpose under the EU AI Act.

Surveillance Risk

The threat that AI systems may be exploited for invasive monitoring of individuals or groups, infringing on privacy and civil liberties.

System of Record

The authoritative data source for a given data element or piece of information within an organization.

Systemic Risk Threshold

The technical or capability-based limit (e.g., 10^25 FLOPs) that classifies a General-Purpose AI model as posing a high level of risk to society.

T

Tail Risk

The potential for rare, extreme outcomes in AI behavior or decision-making that fall outside normal expectations and require special mitigation planning.

Testing & Validation

The systematic process of evaluating AI models against benchmarks, edge cases, and stress conditions to ensure they meet performance, safety, and compliance criteria.

Third-Party Risk

The exposure arising from reliance on external data providers, model vendors, or service platforms that may introduce compliance or security vulnerabilities.

Threshold Setting

Defining boundaries or cut-off values in AI decision rules (e.g., confidence scores) to balance risks like false positives versus false negatives.

Trilogue

The informal three-way negotiation between the European Commission, the Council of the European Union, and the European Parliament used to reach political agreement on EU legislation before formal adoption.

Trustworthy AI

AI systems designed and operated in a manner that is ethical, reliable, safe, and aligned with human values and societal norms.

U

UK AI Opportunities Action Plan

The UK government's strategic roadmap for maximizing AI benefits while establishing targeted, binding safety rules.

Use Case Governance

The practice of defining, approving, and monitoring specific AI use cases to ensure each aligns with organizational policies, ethical standards, and risk appetite.

User Consent

The process of obtaining and recording explicit permission from individuals before collecting, processing, or using their personal data in AI systems.

V

Variance Monitoring

Tracking fluctuations in AI model outputs or performance metrics over time to detect drift and infer potential degradation or risk.

Vendor Risk Management

Assessing and monitoring third-party suppliers of AI components or services to identify and mitigate potential compliance, security, or ethical risks.

Version Pinning

The practice of locking an AI system to a specific, tested version of a foundation model to prevent silent updates from changing system behavior.

Veto Authority

The formal right held by a governance body or stakeholder to block or require changes to AI deployments that pose unacceptable risks.

Vigilance Monitoring

Continuous surveillance of AI behavior and external signals (e.g., regulatory updates) to promptly identify and respond to emerging risks or non-compliance.

Vision AI Oversight

The governance processes specific to computer vision systems, ensuring data quality, bias checks, and transparency in image/video-based decision-making.

W

Watchdog Monitoring

Independent runtime checks that observe AI decisions and trigger alerts or interventions when policies or thresholds are violated.

Watermarking

The practice of embedding detectable, machine-readable provenance markers in AI-generated output, such as images, audio, video, and synthetic text, so downstream consumers and platforms can identify content as AI-generated.

Weight Auditing

Examining model weights and structures for anomalies, backdoors, or biases that could indicate tampering or unintended behaviors.

Whitelist/Blacklist Policy

Governance rule defining allowed (whitelist) and disallowed (blacklist) inputs, features, or operations to enforce compliance and prevent misuse.

Whitelisting

Allowing only pre-approved data sources, libraries, or model components in AI pipelines to reduce risk from unvetted or malicious elements.

Workload Segregation

Separating AI compute environments (e.g., dev, test, prod) and data domains to limit blast radius of failures or security breaches.

Worst-Case Analysis

Evaluating the most extreme potential failures or abuses of an AI system to inform robust risk mitigation and contingency planning.

Write-Once Read-Many (WORM) Storage

Immutable storage ensuring logs, audit trails, and model artifacts cannot be altered once written, supporting non-repudiation and forensic review.

X

XAI Audit

A review process that evaluates whether AI explainability outputs meet internal policies and regulatory requirements, ensuring sufficient transparency.

XAI (Explainable AI)

Techniques and methods that make an AI model’s decision process transparent and understandable to humans, supporting accountability and compliance.

XAI Framework

A structured approach or set of guidelines that organizations use to implement, measure, and govern explainability practices across their AI systems.

XAI Metrics

Quantitative or qualitative measures (e.g., feature importance scores, explanation fidelity) used to assess the quality and reliability of AI explanations.

Y

Yearly Compliance Review

An annual evaluation of AI governance processes, policies, and systems to ensure continued alignment with regulations and internal standards.

Z

Zero Defect Tolerance

A governance principle aiming for no errors or policy violations in AI outputs, supported by rigorous testing, monitoring, and continuous improvement cycles.

Zone-Based Access Control

A network or data governance approach that divides resources into zones with distinct policies, restricting AI system access according to data sensitivity.

Whitepaper

All

AI Regulations

Podcasts

Product Updates

Press Coverage

Glossary

A

Acceptable Use Policy (AUP)

A set of rules applied by an organization that outlines the permitted and prohibited ways employees may interact with company-provided AI tools.

Accredited Certification

A certificate issued by a certification body that has been formally recognized by a national accreditation body (like ANAB or UKAS) as competent to audit against a specific standard.

Action Preview

A governance requirement where an AI agent must display exactly what an irreversible operation will do before a human provides final approval.

Action Whitelisting

A security and governance control that specifies the only permitted tools, APIs, and actions an AI agent is allowed to execute.

Adversarial Attack

Techniques that manipulate AI models by introducing deceptive inputs to cause incorrect outputs.

Agent Fabric

An integrated runtime substrate that hosts, orchestrates, and governs multiple AI agents alongside the models, tools, and data they depend on.

Agent Goal Hijack (ASI01)

A vulnerability where an attacker manipulates an agent's objectives or decision pathways to redirect its autonomous behavior toward unintended outcomes.

Agent Mesh

A networked topology in which AI agents discover, communicate with, and delegate work to one another through a shared infrastructure layer.

Agentic AI

A class of artificial intelligence systems designed to autonomously pursue complex goals and execute multi-step actions (such as software deployment or financial transactions) with minimal human intervention.

Agentic AI Governance

Agentic AI governance is the control of AI systems that plan and take actions on their own, as opposed to systems that only produce predictions or content. It covers what an agent is permitted to do, the limits on its autonomy, how its actions are logged, and who is accountable when an agent acts wrongly.

Agentic Policy Engine

A runtime software component that intercepts agent actions and evaluates them against a set of deterministic governance rules before execution.

AI Accountability

The obligation of AI system developers and operators to ensure their systems are designed and used responsibly, adhering to ethical standards and legal requirements.

AI Alignment

The process of ensuring AI systems' goals and behaviors are aligned with human values and intentions.

AI Assistant

A conversational AI system designed to help users complete tasks through natural language interaction, typically powered by a large language model.

AI Auditing

The systematic evaluation of AI systems to assess compliance with ethical standards, regulations, and performance metrics.

AI Bias

Systematic errors in AI outputs resulting from prejudiced training data or flawed algorithms, leading to unfair outcomes.

AI Bill of Materials (AIBOM)

A structured inventory listing the components that make up an AI system, including foundation models, training datasets, libraries, and dependencies - the AI equivalent of a Software Bill of Materials (SBOM).

AI Compliance

The adherence of AI systems to applicable laws, regulations, and ethical guidelines throughout their lifecycle.

AI Ethics

The field concerned with the moral implications and responsibilities associated with the development and deployment of AI technologies.

AI Explainability

The extent to which the internal mechanics of an AI system can be understood and interpreted by humans.

AI Footprint

The total set of AI systems, models, agents, and embedded AI features in use across an organization at any given time, including sanctioned and shadow systems.

AI Governance

The framework of policies, processes, and controls that guide the ethical and effective development and use of AI systems.

AI Governance for Financial Services

AI governance for financial services is the application of AI risk and compliance controls under the sector's supervisory regimes. The relevant rules differ by jurisdiction and by firm type: SR 26-2 for larger US banks, PRA SS1/23 for UK banks with internal model approval, MAS FEAT in Singapore, and the EU AI Act across all of them.

AI Governance Software

Specialized enterprise tools used to automate the inventory, risk assessment, and regulatory compliance of artificial intelligence systems.

AI Inventory

A comprehensive, centralized catalog of all AI systems, models, and agents in use across an organization, tracking their business purpose, risk level, and ownership.

EU AI Liability Directive

A proposed EU directive aimed at simplifying the process for claimants to seek damages caused by AI systems by introducing a rebuttable presumption of causality.

AI Literacy

The understanding of AI concepts, capabilities, and limitations, enabling informed interaction with AI technologies.

Artificial Intelligence Management System (AIMS)

A set of interrelated or interacting elements of an organization to establish policies, objectives, and processes for the responsible development or use of AI.

AI Monitoring

AI monitoring is the continuous observation of AI systems in production to detect degradation, drift, unsafe behavior and control failures. It covers model performance, input and output distributions, fairness metrics, cost and latency, and for agentic systems the actions the system takes.

AI Risk

The potential for AI systems to cause harm or unintended consequences, including ethical, legal, and operational risks.

AI Risk Management

The process of identifying, assessing, and mitigating risks associated with AI systems.

AI Sprawl

The uncontrolled expansion of AI systems across an organization, typically driven by easy access to AI tools and a lack of effective intake and inventory processes.

AI System Impact Assessment

A formal process to evaluate the potential consequences of an AI system's deployment on individuals, groups, and society at large.

AI Transparency

The principle that AI systems should be open and clear about their operations, decisions, and data usage.

AI TRiSM

An acronym coined by Gartner standing for AI Trust, Risk, and Security Management; a framework that unifies governance, trustworthiness, and security into a single operational strategy.

Artificial Intelligence and Data Act (AIDA)

Canada's federal regulatory framework (part of Bill C-27) aimed at ensuring high-impact AI systems are developed and used safely and without bias.

Algorithmic Bias

Bias that occurs when an algorithm produces results that are systemically prejudiced due to erroneous assumptions in the machine learning process.

Algorithmic Governance

The use of algorithms to manage and regulate societal functions, potentially impacting decision-making processes.

Amnesty Program

A time-limited governance initiative where employees are invited to disclose unsanctioned AI tool usage without fear of disciplinary action.

Annex I Products

A list of products already regulated by EU health and safety law (e.g., machinery, medical devices) where AI integrated under the EU AI Act is automatically classified as high-risk.

Annex III Categories

A specific list of high-risk AI application areas defined by the EU AI Act that trigger mandatory compliance obligations.

API Traffic Analysis

The technical process of monitoring and inspecting network calls made to external AI service providers.

Article 6(3) Exception

A self-determination mechanism under the EU AI Act allowing providers to classify an Annex III AI system as not high-risk if it poses no significant harm.

Article 25 (EU AI Act)

The EU AI Act provision creating a direct obligation chain between providers and deployers of high-risk AI systems, including responsibility transfer when systems are substantially modified.

Article 50 (EU AI Act)

The EU AI Act provision setting transparency obligations for AI systems that interact with people, generate synthetic content, or produce deepfakes.

Australia Safe & Responsible AI Policy

The Australian federal policy governing the use of AI within the public service and government agencies.

Automated AI Governance

The use of software and API integrations to perform continuous, real-time compliance checks and risk monitoring without manual intervention.

B

Bias Amplification

The phenomenon where AI systems exacerbate existing biases present in the training data, leading to increasingly skewed outcomes.

Bias Audit

An evaluation process to detect and mitigate biases in AI systems, ensuring fairness and compliance with ethical standards.

Bias Detection

The process of identifying biases in AI models by analyzing their outputs and decision-making processes.

Bias Mitigation

Techniques applied during AI development to reduce or eliminate biases in models and datasets.

Brazil AI Bill (PL 2338/2023)

PL 2338/2023 is Brazil's proposed legal framework for artificial intelligence. It classifies AI systems by risk, grants rights to explanation and human review, and creates a national oversight system coordinated by the data protection authority. The Senate approved it in December 2024 and it remains before the Chamber of Deputies, so it is not yet law.

Brussels Effect

The phenomenon whereby EU regulation becomes the global default through market access requirements, even for organizations headquartered outside the EU.

C

California AB 1008

An amendment to the CCPA clarifying that personal information includes data generated or output by AI systems.

California AB 3030

A California law requiring transparency when Generative AI is used to communicate with patients in a healthcare setting.

California ADMT Regulations

Rules under the California Consumer Privacy Act (CCPA) governing Automated Decision-Making Technology (ADMT).

California FEHA AI Regulations

State regulations under the Fair Employment and Housing Act (FEHA) targeting AI-driven discrimination in the workplace.

California AI Transparency Act (SB 942)

The California AI Transparency Act, SB 942 as amended by AB 853, requires providers of widely used generative AI systems to embed provenance disclosures in AI-generated image, video and audio content and to publish a free public detection tool. It became operative on August 2, 2026, and is enforced by the California Attorney General.

Cascading Failure (ASI08)

A failure mode where an error or malicious input in one AI agent's reasoning triggers a chain reaction of failures across multiple connected agents or systems.

CE Marking

A mandatory certification mark that indicates an AI system's conformity with health, safety, and environmental protection standards for products sold within the EEA.

Change Notification Window

A contractual period during which a vendor must inform a customer of material updates to an AI model before those updates are deployed in production.

China Interim GenAI Measures

Regulatory requirements for generative AI services provided to the Chinese public.

Council of Europe AI Convention

The first legally binding international treaty on AI, focusing on the protection of human rights, democracy, and the rule of law.

Colorado AI Act (SB 24-205, repealed 2026)

The Colorado AI Act (SB 24-205), the first broad U.S. state AI law, was repealed in May 2026 and replaced by Colorado SB 26-189, which takes effect January 1, 2027, with a narrower focus on automated decision-making technology.

Colorado AI Act (SB 26-189)

Colorado SB 26-189 is the 2026 replacement for the original Colorado AI Act (SB 24-205), taking effect January 1, 2027, with obligations focused on automated decision-making technology making consequential decisions about Coloradans.

Compliance Framework

A structured set of guidelines and best practices that organizations follow to ensure their AI systems meet regulatory and ethical standards.

Compliance Risk

The potential for legal or regulatory sanctions, financial loss, or reputational damage an organization faces when it fails to comply with laws, regulations, or prescribed practices.

Concept Drift

The change in the statistical properties of the target variable, which the model is trying to predict, over time, leading to model degradation.

Conformity Assessment

A process to determine whether an AI system meets specified requirements, standards, or regulations, often involving testing and certification.

Internal Control (Conformity Assessment)

A process under the EU AI Act where a provider self-verifies that their high-risk AI system meets all regulatory requirements without requiring a third-party audit.

Controllability

The extent to which humans can direct, influence, or override the decisions and behaviors of an AI system.

COREPER Mandate

The negotiating authority granted by EU member state ambassadors (Committee of Permanent Representatives) to the rotating Council Presidency for trilogue negotiations on EU legislation.

Cryptographic Agent Identity

A verifiable digital credential (often a Decentralized Identifier or DID) that uniquely identifies an AI agent and its authority level.

D

Data Drift

The change in model input data over time, which can lead to model performance degradation if not monitored and addressed.

Data Ethics

The branch of ethics that evaluates data practices with respect to the moral obligations of gathering, protecting, and using personally identifiable information.

Data Governance

The overall management of data availability, usability, integrity, and security in an enterprise, ensuring that data is handled properly throughout its lifecycle.

Data Ingestion Risk

The danger that sensitive or proprietary information will be permanently absorbed into an AI model's training set during a user's interaction.

Data Lifecycle Management

The policy-based management of data flow throughout its lifecycle: from creation and initial storage to the time it becomes obsolete and is deleted.

Data Minimization

The principle of collecting only the data that is necessary for a specific purpose, reducing the risk of misuse or breach.

Data Privacy

The aspect of information technology that deals with the ability to control what data is shared and with whom, ensuring personal data is handled appropriately.

Data Protection

The process of safeguarding important information from corruption, compromise, or loss, ensuring compliance with data protection laws and regulations.

Data Provenance

A documented record of the origin, ownership, and lifecycle of a dataset used to train or fine-tune an AI model.

Data Quality

The condition of data based on factors such as accuracy, completeness, reliability, and relevance, crucial for effective AI model performance.

Data Residency

Data residency is the requirement that data be stored and processed in a particular country or region. In AI systems it applies to training data, prompts, model outputs and inference logs, and it constrains which models a firm can call, since sending a prompt to a model hosted elsewhere is a cross-border transfer.

Data Sovereignty

The concept that data is subject to the laws and governance structures within the nation it is collected, stored, or processed.

Data Subject

An individual whose personal data is collected, held, or processed, particularly relevant in the context of data protection laws like GDPR.

De-identification

The process of removing or obscuring personal identifiers from data sets, making it difficult to identify individuals, used to protect privacy.

Deepfake

Synthetic media in which a person in an existing image or video is replaced with someone else's likeness, created using deep learning techniques.

Differential Privacy

A system for publicly sharing information about a dataset by describing patterns of groups within the dataset while withholding information about individuals.

EU Digital Omnibus on AI

A 2025/2026 legislative package designed to streamline and harmonize technical standards, conformity assessments, and enforcement timelines across the EU AI Act and related digital safety laws.

Discrimination

In AI, refers to unfair treatment of individuals or groups based on biases in data or algorithms, leading to unequal outcomes.

Dual-Use Foundation Model

An AI model that is trained on a vast amount of data and has high-level performance that could be used for both civilian and harmful or military purposes.

Dynamic Risk Assessment

The continuous process of identifying and evaluating risks in real-time, allowing for timely responses to emerging threats in AI systems.

E

Edge Analytics

The analysis of data at the edge of the network, near the source of data generation, reducing latency and bandwidth usage.

Enzai

An enterprise AI governance platform that enables organizations to inventory, assess, and control their AI systems, ensuring maxmize AI adoption while minimizing AI risk.

Escalation Logic

A set of predefined rules and triggers that force an AI agent to stop autonomous operation and hand control back to a human operator.

ESMA AI/ML Governance Expectations

ESMA's AI and machine learning expectations set out how EU investment firms must apply MiFID II obligations when using AI. The European Securities and Markets Authority issued guidance on AI in retail investment services in May 2024, followed by a supervisory briefing on algorithmic trading on February 26, 2026, that addresses AI and its interaction with the EU AI Act.

Ethical AI

The practice of designing, developing, and deploying AI systems in a manner that aligns with ethical principles and values, ensuring fairness, accountability, and transparency.

Ethical AI Auditing

The process of systematically evaluating AI systems to ensure they comply with ethical standards and do not cause harm.

Ethical AI Certification

A formal recognition that an AI system adheres to established ethical standards and guidelines.

Ethical AI Governance

The framework of policies, procedures, and practices that ensure AI systems are developed and used responsibly and ethically.

Ethical Frameworks

Structured sets of principles and guidelines designed to guide the ethical development and deployment of AI systems.

Ethical Impact Assessment

A systematic evaluation process to identify and address the ethical implications and potential societal impacts of AI systems before deployment.

Ethical Risk

The potential for an AI system to cause harm due to unethical behavior, including bias, discrimination, or violation of privacy.

Ethics Guidelines for Trustworthy AI

A set of guidelines developed by the European Commission's High-Level Expert Group on AI to promote trustworthy AI, focusing on human agency, technical robustness, privacy, transparency, diversity, societal well-being, and accountability.

EU AI Act

The world's first comprehensive horizontal legal framework for AI, establishing a risk-based classification system for systems deployed or used within the European Union.

EU AI Act High-Risk Categories

The two classifications of high-risk AI systems under the EU AI Act: standalone systems listed in Annex III (covering biometrics, critical infrastructure, employment, education, law enforcement, and other named uses), and AI embedded in regulated products listed in Annex I (covering medical devices, vehicles, machinery, and other regulated product categories).

EU AI Act Risk Classification

The mandatory process of assigning one of four risk levels (Unacceptable, High, Limited, Minimal) to an AI system under the EU AI Act.

EU AI Office

The European Commission body established to oversee implementation and enforcement of the EU AI Act, particularly for general-purpose AI models with systemic risk.

EU Digital Omnibus

The European Union's broader 2025-2026 legislative simplification package addressing multiple digital regulations including the AI Act, GDPR provisions, the Cyber Resilience Act, and Data Act amendments.

Excessive Agency

A vulnerability where an AI system is granted too much autonomy, too many tools, or over-privileged access relative to its intended function.

Executive Order 14110

The Biden administration directive (signed October 2023, rescinded January 2025) that established U.S. national standards for AI safety, security, and privacy and created the U.S. AI Safety Institute at NIST.

Explainability Techniques

Methods used to interpret and understand the decisions made by AI models, such as LIME, SHAP, and saliency maps.

Explainability vs. Interpretability

While both aim to make AI decisions understandable, explainability focuses on the reasoning behind decisions, whereas interpretability relates to the transparency of the model's internal mechanics.

Explainable AI (XAI)

AI systems designed to provide human-understandable justifications for their decisions and actions, enhancing transparency and trust.

Explainable Machine Learning

Machine learning models designed to provide clear and understandable explanations for their predictions and decisions.

F

Fairness Metrics

Quantitative measures (e.g., demographic parity, equalized odds) used to evaluate how fair an AI model’s predictions are across groups.

False Negative

When an AI model incorrectly predicts a negative class for an instance that is actually positive (Type II error).

False Positive

When an AI model incorrectly predicts a positive class for an instance that is actually negative (Type I error).

Fault Tolerance

The ability of an AI system to continue operating correctly even when some components fail or produce errors.

Federated AI Governance

A governance model where central policy and oversight are paired with distributed decision-making by business units or regional offices, balancing consistency with operational flexibility.

Feedback Loop

A process where AI outputs are fed back as inputs, which can amplify model behavior - for better (reinforcement learning) or worse (bias reinforcement).

FS AI RMF (Financial Services AI Risk Management Framework)

The Financial Services AI Risk Management Framework (FS AI RMF) is a voluntary, sector-specific framework published in February 2026 by the US Treasury with the Cyber Risk Institute. It aligns to the NIST AI RMF and provides a matrix of 230 control objectives across the AI lifecycle, covering banks, credit unions, insurers, investment firms and their third-party providers.

Functional Safety

Ensuring AI systems operate safely under all conditions, especially in industries like automotive or healthcare, often via redundancy and checks.

Fundamental Rights Impact Assessment (FRIA)

A mandatory evaluation under the EU AI Act for certain deployers to determine how the use of a high-risk AI system might impact civil liberties and human rights.

G

Gap Analysis

The process of comparing current AI governance practices against desired standards or regulations to identify areas needing improvement.

GDPR

The EU’s General Data Protection Regulation, establishing strict requirements for personal data collection, processing, and individual rights.

Goal Drift

A phenomenon where an AI agent's internal sub-goals or reasoning pathways gradually move away from the original human-provided objective.

Governance Body

A cross-functional group (e.g., legal, ethics, technical) tasked with overseeing AI governance policies and their execution within an organization.

Governance Framework

A structured model outlining how AI governance components (risk management, accountability, oversight) fit together to ensure compliance and ethical use.

Governance Maturity Model

A governance maturity model is a staged scale for assessing how developed an organization's AI governance is, typically running from ad hoc practice through to measured and continuously improved. It is used to benchmark a starting position, set a realistic target and sequence investment, not to certify compliance.

Governance Policy

A formal document that codifies rules, roles, and procedures for AI development and oversight within an organization.

Governance Scorecard

A dashboard or report card that tracks key metrics (e.g., bias incidents, compliance audits) to measure AI governance effectiveness over time.

GPAI Code of Practice

The detailed regulatory instrument outlining specific transparency, safety testing, and risk mitigation obligations for providers of General-Purpose AI (GPAI) models under the EU AI Act.

GPAI Model

A general-purpose artificial intelligence model capable of performing a wide range of distinct tasks and integrating into various applications.

Granular Consent

A data-privacy approach allowing individuals to grant or deny specific permissions for each type of data use, enhancing transparency and control.

Guardrails

Predefined constraints or checks (technical and policy) embedded in AI systems to prevent unsafe or non-compliant behavior at runtime.

Guideline (Ethical AI)

A non-binding recommendation or best-practice document issued by organizations (e.g., IEEE, EU) to shape responsible AI development and deployment.

H

Hallucination

When generative AI produces incorrect or fabricated information that appears plausible but has no basis in the training data.

Harm Assessment

Evaluating potential negative impacts (physical, psychological, societal) of AI systems and defining mitigation strategies.

Harmonization

Aligning AI policies, standards, and regulations across jurisdictions to reduce conflicts and enable interoperability.

Harmonized Structure

A standardized template for all ISO management system standards, formerly known as Annex SL, ensuring consistency in terminology and clause numbering.

Heuristic Evaluation

A usability inspection method where experts judge an AI system against established usability principles to identify potential issues.

High-Risk AI System

AI applications that have a significant potential to harm the health, safety, or fundamental rights of individuals, triggering the most stringent compliance requirements under the EU AI Act.

High-Stakes AI

AI applications whose failures could cause significant harm (e.g., medical diagnosis, autonomous vehicles), requiring heightened governance and oversight.

Human-in-the-Loop

Involving human judgment within AI processes (training, validation, decision review) to improve accuracy and accountability.

Human Oversight

Mechanisms that allow designated individuals to monitor, intervene, or override AI system decisions to ensure ethical and legal compliance.

Human Rights Impact Assessment

A process to evaluate how AI systems affect fundamental rights (privacy, expression, non-discrimination) and identify mitigation measures.

I

Impact Assessment

A structured evaluation to identify, analyze, and mitigate potential ethical, legal, and societal impacts of an AI system before deployment.

Implementing Acts

Secondary EU legislation adopted by the European Commission to set uniform conditions for implementing primary legislation, with binding legal effect across all Member States.

Incentive Alignment

The design of reward structures and objectives so that AI systems’ goals remain consistent with human values and organizational priorities.

Inductive Bias

The set of assumptions a learning algorithm uses to generalize from observed data to unseen instances.

Information Governance

The policies, procedures, and controls that ensure data quality, privacy, and usability across an organization’s data assets, including AI training datasets.

Information Privacy

The right of individuals to control how their personal data are collected, used, stored, and shared by AI systems.

Inherited Data Risk

The regulatory and ethical liability an organization assumes when using an AI system trained on data they did not collect or vet themselves.

Intake Workflow

The standardized process and series of checks that a new AI system must pass through before being built or procured.

Intent Validation

The process of verifying that an AI agent's planned sub-actions remain consistent with the original human-provided objective.

Interoperability

The ability of diverse AI systems and components to exchange, understand, and use information seamlessly, often via open standards or APIs.

Interpretability

The degree to which a human can understand the internal mechanics or decision rationale of an AI model.

ISO/IEC 42001

The international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS).

ISO/IEC 42005

The international standard providing guidance on performing AI system impact assessments.

ISO/IEC JTC 1/SC 42

The joint ISO/IEC committee on Artificial Intelligence standardization, developing international AI standards for governance, risk, and interoperability.

J

Jailbreak Attack

A type of prompt‐injection where users exploit vulnerabilities to bypass safeguards in generative AI models, potentially leading to unsafe or unauthorized outputs.

Japan Act on Promotion of AI

A Japanese law (enacted 2025) establishing basic principles for AI promotion and risk mitigation.

Joint Liability

Legal principle where multiple parties (e.g., developers, deployers) share responsibility for AI‐related harms, influencing contract and governance structures.

Joint Modeling

Building AI systems that jointly learn multiple tasks (e.g., speech recognition + translation), with governance needed for complexity and auditability.

Jurisdiction

The legal authority over data, AI operations, and liability, which varies by geography and impacts compliance with regional regulations (e.g., GDPR, CCPA).

K

Key Performance Indicator

A quantifiable metric (e.g., model accuracy drift, bias remediation time) used to monitor and report on AI governance and compliance objectives.

Key Risk Indicator

A leading metric (e.g., frequency of out-of-scope predictions, rate of unexplainable decisions) that signals emerging AI risks before they materialize.

Knowledge Management

Practices and tools for capturing, organizing and sharing organizational knowledge (e.g., model documentation, audit logs) to ensure reproducibility and oversight.

L

Least Agency

A security and governance principle stating that AI agents should only be granted the minimum level of autonomy and tool-access necessary to complete a specific task.

Least Privilege

A security principle where AI components and users are granted only the minimal access rights necessary to perform their functions, reducing risk of misuse.

Legal Compliance

The practice of ensuring AI systems adhere to applicable laws, regulations, and industry standards throughout their entire lifecycle.

Liability Framework

A structured approach defining who is responsible for AI-related harms or failures, including developers, deployers, and operators.

Lifecycle Management

The coordinated processes for development, deployment, monitoring, maintenance, and retirement of AI systems to ensure ongoing compliance and risk control.

Localization

Adapting AI systems to local languages, regulations, cultural norms, and data residency requirements in different jurisdictions.

M

Market Surveillance Authority

The national regulatory body in each EU member state responsible for monitoring AI systems to ensure they comply with the EU AI Act.

MAS FEAT Principles

The MAS FEAT Principles are four principles covering Fairness, Ethics, Accountability and Transparency, published by the Monetary Authority of Singapore on November 12, 2018, to guide the responsible use of artificial intelligence and data analytics in Singapore's financial sector. They are non-binding guidance, not enforceable rules, and are supported by the Veritas assessment methodology.

Meaningful Human Control

A regulatory and operational standard ensuring that humans retain the ability to oversee, intervene in, and override AI decision-making processes.

Metadata Management

The practice of capturing and maintaining descriptive data (e.g., data provenance, feature definitions, model parameters) to support traceability and audits.

Metrics & KPIs

Quantitative measures (e.g., accuracy drift, fairness scores, incident response time) used to monitor AI system health, risk, and compliance objectives.

Mexico Federal Law on AI and Algorithms

A draft Mexican federal law on AI and algorithms proposing a risk-based classification system, the National AI Commission (CONAIA), and watermarking requirements for AI-generated content.

Mitigation Strategies

Planned actions (e.g., bias remediation, retraining, feature re-engineering) to address identified AI risks and compliance gaps.

Minnesota CDPA (AI Provisions)

The AI-specific components of the Minnesota Consumer Data Privacy Act.

Model Card

A short, standardized document providing essential information about a machine learning model's performance, limitations, and intended use cases.

Model Disgorgement

A regulatory remedy requiring a company to delete AI models or algorithms that were developed using improperly or unlawfully acquired data.

Model Drift

The degradation of an AI model's predictive performance over time due to changes in real-world data or the environment.

Model Explainability

Techniques and documentation that make an AI model’s decision logic understandable to stakeholders and auditors.

Model Governance

The policies, roles, and controls that ensure AI models are developed, approved, and used in line with organizational standards and regulatory requirements.

Model Monitoring

Continuous tracking of an AI model’s performance, data drift, and operational metrics to detect degradation or emerging risks.

Model Retraining

The process of updating an AI model with new or refreshed data to maintain performance and compliance as data distributions evolve.

Model Risk Management

Model risk management is the discipline of identifying, measuring and controlling the risk that a model produces incorrect or misused output. In US banking it is set by SR 26-2, issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026, which supersedes SR 11-7 and expressly excludes generative and agentic AI from its scope.

Model Validation

The evaluation activities (e.g., testing against hold-out data, stress scenarios) that confirm an AI model meets its intended purpose and performance criteria.

Multi-Stakeholder Engagement

Involving diverse groups (e.g., legal, ethics, operations, end users) in AI governance processes to ensure balanced risk oversight and alignment with business goals.

N

NIST AI Risk Management Framework

A voluntary guidance from the U.S. National Institute of Standards and Technology outlining best practices for mitigating risks across AI system lifecycles.

NIST AI RMF Profiles

NIST AI RMF Profiles are tailored implementations of the NIST AI Risk Management Framework. NIST defines three types: use-case profiles for specific applications, cross-sectoral profiles that apply across industries, and temporal profiles describing an organization's Current and Target state. The first cross-sectoral profile, the Generative AI Profile (NIST AI 600-1), was published in July 2024.

Non-Human Identity (NHI)

A digital credential used by an AI agent, bot, or service to authenticate and interact with enterprise systems.

Notified Body

An independent third-party organization designated by an EU member state to assess the conformity of certain high-risk AI systems under the EU AI Act.

NYC Local Law 144

A New York City law requiring annual bias audits for AI tools used in employment decisions.

O

Observability

The capability to infer an AI system’s internal state and behavior through collection and analysis of logs, metrics, and outputs for effective monitoring and troubleshooting.

OMB Memorandum M-25-21

OMB Memorandum M-25-21, Accelerating Federal Use of AI through Innovation, Governance, and Public Trust, directs US federal agencies to appoint a Chief AI Officer, publish an AI use case inventory, and apply minimum risk management practices to "high-impact AI". Issued in April 2025, it replaced M-24-10 and is paired with M-25-22 on AI acquisition.

Ongoing Monitoring

Continuous tracking of AI system performance, data drift, bias metrics, and security events to detect and address emerging risks over time.

Operational Autonomy

The ability of an AI system to perform multi-step tasks and make decisions without human intervention at each stage.

Operational Resilience

The ability of AI systems and their supporting infrastructure to anticipate, withstand, recover from, and adapt to disruptions or adverse events.

Output Risk

The operational, legal, and reputational danger arising from the use of incorrect, biased, or harmful content generated by an AI system.

Oversight

The structured process of review, approval, and accountability for AI development and deployment, typically involving cross-functional governance bodies.

OWASP Agentic Top 10

The OWASP Top 10 for Agentic Applications is a peer-reviewed list of the ten most critical security risks in autonomous AI agents, published by the OWASP Gen AI Security Project on December 10, 2025. Its entries are coded ASI01 to ASI10, from Agent Goal Hijack through to Rogue Agents.

P

Paved Road Governance

A strategy that encourages compliance by making sanctioned, secure workflows easier to follow than unsanctioned alternatives.

Permissioning

The management of user and system access rights to AI data and functions, ensuring least-privilege and preventing unauthorized use.

Pilot Testing

A limited-scope trial of an AI system in a controlled environment to assess performance, risks, and governance controls before full-scale deployment.

Policy Enforcement

The automated or manual mechanisms that ensure AI operations adhere to organizational policies, regulatory rules, and ethical guidelines.

Post-Deployment Monitoring

Ongoing observation of AI system behavior and environment after release to detect degradation, drift, or compliance breaches.

PRA SS1/23 (Model Risk Management)

PRA Supervisory Statement SS1/23 sets out the Bank of England's five model risk management principles for UK banks. Published on May 17, 2023, and effective from May 17, 2024, it applies to UK-incorporated banks, building societies and PRA-designated investment firms that hold internal model approval. It covers AI and machine learning models, and it does not apply to insurers.

Presumption of Conformity

A legal mechanism under EU AI Act and other regimes whereby compliance with a harmonized standard (e.g., a published EN standard) provides a rebuttable assumption that the underlying regulation is satisfied.

Privacy by Design

An approach that embeds data protection and user privacy considerations into AI system architecture and processes from the outset.

Privacy Impact Assessment

A structured analysis to identify and mitigate privacy risks associated with AI systems, covering data collection, use, sharing, and retention.

Probabilistic System

A system where outputs are based on statistical likelihood rather than deterministic, fixed logic.

Q

Qualitative Assessment

The subjective review of AI system behaviors, decisions, and documentation by experts to identify ethical, legal, or reputational concerns not captured quantitatively.

Quality Assurance

The systematic processes and checks to ensure AI models and data pipelines meet defined standards for accuracy, reliability, and ethical compliance.

Quality Control

The ongoing verification of AI outputs and processes against benchmarks and test cases to catch defects, bias incidents, or policy violations.

Quantitative Risk Assessment

A data-driven evaluation of potential AI threats, estimating likelihoods and impacts numerically to prioritize mitigation efforts.

Query Privacy

Techniques and policies to protect sensitive information in user queries, ensuring that logged inputs do not compromise personal or proprietary data.

Questionnaire Framework

A structured set of governance-focused questions used during design, procurement, or deployment to ensure AI systems align with policy requirements.

Quorum for Governance Board

The minimum number of governance committee members required to be present to make official decisions on AI risk, policy approvals, or audit outcomes.

Quota Management

The controls and limits placed on AI resource usage (e.g., API calls, compute time) to enforce governance policies and prevent runaway costs or abuse.

R

Reasoning Chain

The multi-step logical process an AI agent follows to move from an initial objective to a final action or output.

Recourse

Mechanisms that allow affected individuals to challenge or seek remedy for AI-driven decisions that impact their rights or interests.

Red Teaming

A proactive testing approach where internal or external experts simulate attacks or misuse scenarios to uncover vulnerabilities in AI systems.

Regulatory Compliance

Ensuring AI systems adhere to applicable laws, regulations, and industry standards (e.g., GDPR, FDA, financial oversight) throughout their operation.

Responsibility Assignment Matrix

A tool (e.g., RACI) that clarifies roles and accountabilities for each governance activity - who’s Responsible, Accountable, Consulted, and Informed.

Responsible AI

The practice of designing, developing, and deploying AI systems in ways that are ethical, transparent, and accountable to stakeholders and society.

Risk Assessment

The process of identifying, analyzing, and prioritizing potential harms or failures in AI systems to determine appropriate mitigation strategies.

Risk Management Framework

A structured set of guidelines and processes for systematically addressing AI risks across the system lifecycle, from design through retirement.

Root Cause Analysis

A structured investigation to determine the underlying reasons for AI system failures or unexpected behaviors, guiding corrective actions.

S

Sanctioned Use Policy

Defined rules and controls that specify approved contexts, users, and purposes for AI system operation to prevent misuse.

Security by Design

Integrating security controls and best practices into AI systems from the earliest design phases to prevent vulnerabilities and data breaches.

Shadow Agents

Unsanctioned autonomous AI agents deployed within an organization without governance team awareness, capable of taking actions that affect business systems and external parties.

Shadow AI

The unsanctioned use of AI models, agents, or tools by employees without IT approval, creating hidden security vulnerabilities through data leakage and unauthorized autonomous actions.

Singapore Model AI Governance Framework

Singapore's Model AI Governance Framework is voluntary guidance issued by the IMDA for deploying AI responsibly. It now exists in three editions: the original framework first published in 2019, a generative AI edition released in 2024, and a Model AI Governance Framework for Agentic AI launched on January 22, 2026.

South Korea AI Basic Act

South Korea's comprehensive legal framework for AI development and trust.

Societal Impact Assessment

A structured evaluation of how an AI system affects social, economic, and cultural aspects of communities, identifying potential harms and benefits.

SR 11-7 (Model Risk Management)

SR 11-7 was the US Federal Reserve and OCC's supervisory guidance on model risk management, issued on April 4, 2011. For fifteen years it set the benchmark for model validation, model inventories and independent review in US banking. It was superseded on April 17, 2026, by SR 26-2, revised guidance issued jointly by the Federal Reserve, OCC and FDIC.

SR 26-2 (Revised Guidance on Model Risk Management)

SR 26-2 is the revised US supervisory guidance on model risk management, issued jointly by the Federal Reserve, OCC and FDIC on April 17, 2026. It supersedes SR 11-7 and SR 21-8, sets out a risk-based approach tailored to a banking organization's model risk profile, and expressly excludes generative and agentic AI from its scope.

Stakeholder Engagement

The process of involving affected parties (e.g., users, regulators, impacted communities) in AI development and oversight to ensure diverse perspectives and buy-in.

Statement of Applicability (SoA)

A document that identifies which ISO 42001 Annex A controls are relevant to an organization's AI Management System and explains why others were excluded.

Substantial Modification

A change to an AI system after it has been placed on the market that affects its compliance or intended purpose under the EU AI Act.

Surveillance Risk

The threat that AI systems may be exploited for invasive monitoring of individuals or groups, infringing on privacy and civil liberties.

System of Record

The authoritative data source for a given data element or piece of information within an organization.

Systemic Risk Threshold

The technical or capability-based limit (e.g., 10^25 FLOPs) that classifies a General-Purpose AI model as posing a high level of risk to society.

T

Tail Risk

The potential for rare, extreme outcomes in AI behavior or decision-making that fall outside normal expectations and require special mitigation planning.

Testing & Validation

The systematic process of evaluating AI models against benchmarks, edge cases, and stress conditions to ensure they meet performance, safety, and compliance criteria.

Third-Party Risk

The exposure arising from reliance on external data providers, model vendors, or service platforms that may introduce compliance or security vulnerabilities.

Threshold Setting

Defining boundaries or cut-off values in AI decision rules (e.g., confidence scores) to balance risks like false positives versus false negatives.

Trilogue

The informal three-way negotiation between the European Commission, the Council of the European Union, and the European Parliament used to reach political agreement on EU legislation before formal adoption.

Trustworthy AI

AI systems designed and operated in a manner that is ethical, reliable, safe, and aligned with human values and societal norms.

U

UK AI Opportunities Action Plan

The UK government's strategic roadmap for maximizing AI benefits while establishing targeted, binding safety rules.

Use Case Governance

The practice of defining, approving, and monitoring specific AI use cases to ensure each aligns with organizational policies, ethical standards, and risk appetite.

User Consent

The process of obtaining and recording explicit permission from individuals before collecting, processing, or using their personal data in AI systems.

V

Variance Monitoring

Tracking fluctuations in AI model outputs or performance metrics over time to detect drift and infer potential degradation or risk.

Vendor Risk Management

Assessing and monitoring third-party suppliers of AI components or services to identify and mitigate potential compliance, security, or ethical risks.

Version Pinning

The practice of locking an AI system to a specific, tested version of a foundation model to prevent silent updates from changing system behavior.

Veto Authority

The formal right held by a governance body or stakeholder to block or require changes to AI deployments that pose unacceptable risks.

Vigilance Monitoring

Continuous surveillance of AI behavior and external signals (e.g., regulatory updates) to promptly identify and respond to emerging risks or non-compliance.

Vision AI Oversight

The governance processes specific to computer vision systems, ensuring data quality, bias checks, and transparency in image/video-based decision-making.

W

Watchdog Monitoring

Independent runtime checks that observe AI decisions and trigger alerts or interventions when policies or thresholds are violated.

Watermarking

The practice of embedding detectable, machine-readable provenance markers in AI-generated output, such as images, audio, video, and synthetic text, so downstream consumers and platforms can identify content as AI-generated.

Weight Auditing

Examining model weights and structures for anomalies, backdoors, or biases that could indicate tampering or unintended behaviors.

Whitelist/Blacklist Policy

Governance rule defining allowed (whitelist) and disallowed (blacklist) inputs, features, or operations to enforce compliance and prevent misuse.

Whitelisting

Allowing only pre-approved data sources, libraries, or model components in AI pipelines to reduce risk from unvetted or malicious elements.

Workload Segregation

Separating AI compute environments (e.g., dev, test, prod) and data domains to limit blast radius of failures or security breaches.

Worst-Case Analysis

Evaluating the most extreme potential failures or abuses of an AI system to inform robust risk mitigation and contingency planning.

Write-Once Read-Many (WORM) Storage

Immutable storage ensuring logs, audit trails, and model artifacts cannot be altered once written, supporting non-repudiation and forensic review.

X

XAI Audit

A review process that evaluates whether AI explainability outputs meet internal policies and regulatory requirements, ensuring sufficient transparency.

XAI (Explainable AI)

Techniques and methods that make an AI model’s decision process transparent and understandable to humans, supporting accountability and compliance.

XAI Framework

A structured approach or set of guidelines that organizations use to implement, measure, and govern explainability practices across their AI systems.

XAI Metrics

Quantitative or qualitative measures (e.g., feature importance scores, explanation fidelity) used to assess the quality and reliability of AI explanations.

Y

Yearly Compliance Review

An annual evaluation of AI governance processes, policies, and systems to ensure continued alignment with regulations and internal standards.

Z

Zero Defect Tolerance

A governance principle aiming for no errors or policy violations in AI outputs, supported by rigorous testing, monitoring, and continuous improvement cycles.

Zone-Based Access Control

A network or data governance approach that divides resources into zones with distinct policies, restricting AI system access according to data sensitivity.

Join our newsletter

By signing up, you agree to the Enzai privacy policy

Join our newsletter

By signing up, you agree to the Enzai privacy policy

Join our newsletter

By signing up, you agree to the Enzai privacy policy

Join our newsletter

By signing up, you agree to the Enzai privacy policy

AI governance

AI governance

infrastructure

infrastructure

engineered for trust.

engineered for trust.

Empower your organization to adopt, govern, and monitor AI with enterprise-grade confidence. Built for regulated organizations operating at scale.

Seamlessly connect your existing systems, policies, and AI workflows - all in one unified platform.

Seamlessly connect your existing systems, policies, and AI workflows - all in one unified platform.