Reference · 32 terms
Glossary
Plain definitions of the terms that matter for responsible use of AI in 2026. Every term has its own address, so you can link to it.
Jump to a letter
A
- AI agent
-
An AI system that takes actions to complete a task, such as sending messages, updating records, making purchases or asking other agents for help.
Agents act with the access they’re given, which is why the standard limits their permissions to what each task needs.
Related principles: 1. Human oversight of AI · 4. Limited permissions for AI agents
Sources: Model AI Governance Framework for Agentic AI; OWASP Top 10 for LLM Applications, 2026 edition
- AI assistant
-
An AI tool that works with you in a chat window or inside an application, producing drafts, answers and suggestions for you to use. When it can also take actions, it becomes an agent.
Related principles: 1. Human oversight of AI
- AI literacy
-
The skills, knowledge and understanding that let people use AI well and be aware of its opportunities, risks and possible harms.
The EU AI Act defines the term and requires organizations that provide or use AI systems to take measures to support their staff’s AI literacy.
Related principles: 5. Independent judgment and skills
Sources: Regulation (EU) 2024/1689 (Artificial Intelligence Act); Regulation (EU) 2026/1744 (AI Omnibus)
- Anchoring
-
The tendency to rely too heavily on the first answer, number or idea you see when you make a judgment. Forming your own estimate before you ask AI reduces it.
Related principles: 5. Independent judgment and skills · 6. Challenge and bias awareness
- Anonymization
-
Processing data so that people can no longer be identified, by anyone, using the means reasonably likely to be used. Removing names alone is rarely enough.
Related principles: 3. Confidentiality of information shared with AI
- Automation bias
-
The tendency to over-rely on an automated system: accepting its output instead of checking it, following wrong advice or missing problems it didn’t flag.
It affects experts as well as novices. The EU AI Act requires high-risk AI systems to be built so the people overseeing them stay aware of it.
Related principles: 1. Human oversight of AI · 6. Challenge and bias awareness
Sources: Automation bias: a systematic review of frequency, effect mediators, and mitigators; Complacency and Bias in Human Use of Automation: An Attentional Integration; Regulation (EU) 2024/1689 (Artificial Intelligence Act)
C
- Checkpoint
-
A point in a workflow where a person must approve a specific action before it happens. An effective checkpoint shows the actual action, gives the reviewer the time and power to say no, and never treats silence as approval.
Related principles: 1. Human oversight of AI
- Confabulation (hallucination)
-
When an AI system produces confident, plausible content that is false or unsupported, sometimes with invented reasoning or citations that make it look justified.
NIST uses the word confabulation. Many people call it hallucination.
Related principles: 7. Verification proportionate to the stakes
- Confirmation bias
-
The tendency to look for, favor and remember information that confirms what you already believe. A leading question to an AI assistant invites an answer that confirms it.
Related principles: 6. Challenge and bias awareness
Sources: Confirmation bias: A ubiquitous phenomenon in many guises
- Connector
-
A link that lets an AI assistant read from, or act in, another system such as your email, calendar, file storage or CRM. A connector usually gives the assistant what you can see.
Related principles: 2. A single source of truth for AI · 3. Confidentiality of information shared with AI
D
- Data traffic light
-
A team rule that sorts information into green (public), amber (internal, approved tools only) and red (personal, confidential or regulated, only in tools and processes cleared for it). A term used in this standard.
Related principles: 3. Confidentiality of information shared with AI
- Deepfake
-
AI-generated or manipulated image, audio or video that resembles real people, places or events and would falsely appear to be authentic.
This follows the EU AI Act’s definition. Since August 2026, deployers in the EU must disclose deepfakes they create.
Related principles: 7. Verification proportionate to the stakes · 9. Transparency about the use of AI
Sources: Regulation (EU) 2024/1689 (Artificial Intelligence Act)
- Deskilling
-
The loss of skills that happens when people stop practicing work that a machine now does for them.
Aviation has long encouraged manual flying to keep skills sharp, and early research suggests similar effects in medicine.
Related principles: 5. Independent judgment and skills
Sources: Safety Alert for Operators 13002: Manual Flight Operations; Endoscopist deskilling risk after exposure to artificial intelligence in colonoscopy: a multicentre, observational study
E
- Excessive agency
-
An AI system with more functions, permissions or autonomy than its task needs, so that a mistake or a manipulation can do real damage. A risk named by OWASP.
Related principles: 4. Limited permissions for AI agents
G
- Grounding
-
Giving an AI system specific sources to base its answer on, such as approved documents, and asking it to show which ones it used.
Related principles: 2. A single source of truth for AI · 7. Verification proportionate to the stakes
H
- Human in command
-
Oversight of an AI system’s overall activity, including the decision whether, when and how to use it at all.
One of three kinds of oversight described by the EU’s High-Level Expert Group on AI in 2019. Choosing the level of oversight for each task is the everyday version.
Related principles: 1. Human oversight of AI
Sources: Ethics Guidelines for Trustworthy AI
- Human in the loop (HITL)
-
A way of working in which a person reviews and approves an AI system’s output or action before it takes effect. In this standard, level 2: AI proposes, you approve.
The EU’s High-Level Expert Group on AI described it in 2019 as the capability for human intervention in every decision cycle, and noted that this is often neither possible nor desirable. That’s why the standard uses four levels of oversight.
Related principles: 1. Human oversight of AI
Sources: Ethics Guidelines for Trustworthy AI; Recommendation of the Council on Artificial Intelligence (OECD AI Principles)
- Human on the loop (HOTL)
-
A way of working in which AI acts within set limits while a person monitors it and can intervene or stop it. In this standard, level 3: AI acts within limits.
The 2019 guidelines of the EU’s High-Level Expert Group on AI tie it to human involvement in designing the system and monitoring how it operates.
Related principles: 1. Human oversight of AI
Sources: Ethics Guidelines for Trustworthy AI
- Human oversight
-
The ability of people to understand, monitor, intervene in and stop an AI system, and to decide whether to use it at all. Human in the loop, on the loop and in command are its three classic forms.
Related principles: 1. Human oversight of AI
Sources: Ethics Guidelines for Trustworthy AI; Regulation (EU) 2024/1689 (Artificial Intelligence Act); Recommendation of the Council on Artificial Intelligence (OECD AI Principles)
L
- Least privilege
-
Giving each person, system or agent only the minimum access and permissions it needs to do its job.
Related principles: 4. Limited permissions for AI agents
Sources: Least privilege (glossary entry)
- Lethal trifecta
-
The combination, in one AI agent, of access to private data, exposure to untrusted content and the ability to communicate externally, which makes it possible to trick the agent into leaking data. A term coined by Simon Willison.
Related principles: 4. Limited permissions for AI agents
Sources: The lethal trifecta for AI agents
N
- Near miss
-
A mistake caught before it caused harm. It’s worth reporting, because it shows where the next real problem is likely to come from.
Related principles: 10. Accountability for AI-assisted results
P
- Personal data
-
Any information relating to an identified or identifiable person. Under the GDPR the definition is broad: a name, an identification number, location data or a combination of details can all make someone identifiable.
Related principles: 3. Confidentiality of information shared with AI
Sources: Regulation (EU) 2016/679 (General Data Protection Regulation)
- Prompt injection
-
Text written to change an AI system’s behavior in ways its user didn’t intend. It can be typed directly or hidden in an email, web page or document the AI reads.
The UK’s National Cyber Security Centre warns it may never be fully fixed, so the defense is to limit what a tricked system can do.
Related principles: 4. Limited permissions for AI agents
Sources: OWASP Top 10 for LLM Applications, 2026 edition; Prompt injection is not SQL injection (it may be worse)
- Pseudonymization
-
Replacing names or other identifiers with codes, while the information needed to re-identify people still exists somewhere. Pseudonymized data is still personal data.
Related principles: 3. Confidentiality of information shared with AI
Sources: Pseudonymisation; Regulation (EU) 2016/679 (General Data Protection Regulation)
S
- Shadow AI
-
AI tools used for work without the organization’s approval, often on personal accounts.
In Microsoft’s 2024 Work Trend Index, 78% of people who used AI at work said they brought their own tools.
Related principles: 3. Confidentiality of information shared with AI
Sources: AI at Work Is Here. Now Comes the Hard Part (2024 Work Trend Index)
- Single source of truth (SSOT)
-
The one agreed, owned and dated home for each important fact, used by people and AI alike. It can span several systems, as long as each fact has one official home.
The standard’s five rules: one home per fact, an owner and a date for every home, AI pointed at the home, drafts that stay drafts and fixes made at the source. Principle 2 explains them.
Related principles: 2. A single source of truth for AI
- Source owner
-
The person responsible for keeping an official source current, approving changes and acting on reported mistakes.
Related principles: 2. A single source of truth for AI
- Sycophancy
-
An AI assistant’s tendency to tell people what they seem to want to hear: agreeing, flattering or dropping a correct answer when challenged.
Related principles: 6. Challenge and bias awareness
Sources: Towards Understanding Sycophancy in Language Models; Sycophancy in GPT-4o: what happened and what we’re doing about it
- Synthetic media
-
Images, audio, video or text generated or substantially changed by AI. When it realistically depicts real people or events, it becomes a deepfake.
Related principles: 9. Transparency about the use of AI
V
- Verification levels
-
A rule for matching verification to the stakes: a glance for internal drafts, spot checks for anything shared, and full verification for anything published, signed, sent to a client or used to decide. A term used in this standard.
Related principles: 7. Verification proportionate to the stakes
W
- Workslop
-
AI-generated work that looks polished but lacks the substance to move a task forward, so the person who receives it has to fix or redo it. A term from researchers at Stanford’s Social Media Lab and BetterUp.
Related principles: 8. Quality of AI-assisted work