RETIRED/SUPERSEDED BY VOCAB FILE AI KR CG — Agentic AI Vocabulary: Walkthrough & Tutorial
W3C AI Knowledge Representation Community Group · Working draft, June 2026
Status: Working draft, open for evaluation and feedback. Not a normative specification.
Purpose: The vocabulary listend in the table below, and as visual artefact in this repo https://w3c-cg.github.io/aikr/VOCAB.%2029%20june/ is a — a controlled vocabulary intended to help populate a semantic map of the agentic-AI ecosystem, as part of the landscaping of that ecosystem. Definitions are proposed, not settled. Provenance is given per term so each can be traced to a primary source and independently verified. Relations are expressed informally, in a SKOS-like style (broader / narrower / part-of / related / regulates / mitigates), to support mapping rather than to assert a finished ontology.
Note on sources: the "Source" column gives the primary or canonical origin of each term (the originating paper, standards instrument, statute, or protocol owner).
Corrections in this version: PPSI corrected to "Permitted Payment Stablecoin Issuer"; GAIE and RAILS acronym expansions marked unconfirmed pending verification against source papers; GENIUS Act dating reduced to year of enactment; x402 description tightened; Source column re-pointed to canonical origins; a Relations column added throughout.
Section 1 — Agentic commerce, oversight & reflexivity
| Term | Proposed Definition | Source (canonical) | Relations | Relevance to Agentic AI |
|---|---|---|---|---|
| agentic clearing | The operational layer that evaluates whether an autonomous AI agent has fulfilled its transaction obligations, assigns liability, and determines the subsequent settlement action — distinct from payment and from settlement execution. | de Valois-Franklin & Bogdan, RAILS, arXiv 2606.08790 | broader: settlement; related: clearing function, settlement determination | Prevents agent-to-agent transactions from failing without a mechanism to assign liability or reverse value. |
| clearing function | A deterministic process that consumes reliability scores and records to dictate which settlement or dispute consequence follows an agent's output. | RAILS, arXiv 2606.08790 | partOf: RAILS; related: per-output reliability score, settlement determination | The actionable control rule that tells the payment rails how to adjust based on agent performance. |
| verification-native clearing | A design in which clearing checks are embedded within a system's verification phase rather than added post-hoc. | RAILS, arXiv 2606.08790 | related: agentic clearing, RAILS | Couples an agent's output to its verification record, supporting automated auditability before value moves. |
| per-output reliability score | A discrete metric attached to each agent output, quantifying a measured judgement of its quality and adherence to constraints. | RAILS, arXiv 2606.08790 | partOf: RAILS; related: published reliability record, clearing function | Lets multi-agent workflows weigh the risk of an individual contribution before committing capital or code. |
| published reliability record | A durable, inspectable log of historical reliability scores and output judgements. | RAILS, arXiv 2606.08790 | partOf: RAILS; related: per-output reliability score, evidence artifacts | The foundational audit trail for defending autonomous agent activity to supervisors. |
| settlement determination | The authoritative decision on how assets should move, distinct from the physical execution of that transfer. | RAILS, arXiv 2606.08790 | related: agentic clearing, settlement model | Isolates dispute resolution from payment plumbing, protecting capital from rogue agent behaviour. |
| RAILS | A three-part architectural framework (reliability score, reliability record, clearing function) treating clearing as an independent layer in agentic commerce. Acronym expansion ("Real-Time Agent Integrity & Ledger Settlement") proposed but not yet confirmed against the source paper. | arXiv 2606.08790 | hasPart: per-output reliability score, published reliability record, clearing function; related: x402, AP2 | Framework enabling traditional networks (e.g. Visa, Mastercard) to scale safer agentic commerce. |
| x402 | An agent/machine payment scheme built on the HTTP 402 ("Payment Required") status, enabling software agents to settle value (typically in stablecoins) inline with a request. | Coinbase (x402 specification) | broader: agent payment rail; related: AP2, mandate protocol, RAILS | An execution layer letting agents autonomously trigger payments, requiring clearing layers above it. |
| AP2 | Agent Payments Protocol. A mandate-based protocol defining how, when, and within what bounds value can be authorised for transmission by an AI agent. | Google (Agent Payments Protocol) | related: x402, mandate protocol; partOf: agent authorization | Governs the pre-authorisation boundary for agentic spending. |
| mandate protocol | A framework defining and enforcing pre-approved operational boundaries and financial caps delegated to a software agent. | Agent-payments literature (cf. AP2) | related: AP2, x402 | The sandbox shielding corporate wallets from runaway or exploited agent logic. |
| graduated human oversight | A governance pattern that adjusts the necessity, depth, and timing of human review according to the risk profile and "blast radius" of an agentic action. | GAIE, arXiv 2606.22484 | definedBy: GAIE; hasPart: blast-radius oversight; related: regulatory risk profile; regulatedBy: EU AI Act Art. 14, prEN 18283 | Scales deployment for low-risk tasks while gating high-consequence actions. |
| GAIE | A framework for enforcing proportionate human oversight on agentic actions in regulated domains. Acronym expansion unconfirmed; the source paper centres on "graduated" oversight, so the earlier "Governed AI-Assisted Engineering" reading should be verified before use. | arXiv 2606.22484 | hasPart: graduated human oversight, regulatory risk profile, blast-radius oversight, evidence artifacts; related: DORA | A playbook for safely scaling code-generating and code-executing agents. |
| regulatory risk profile | A classification of an agentic task by its compliance implications, domain sensitivity, and potential for systemic or financial harm. | GAIE, arXiv 2606.22484 | partOf: GAIE; related: graduated human oversight | Determines whether an output can self-deploy or must be gated by sign-off. |
| blast-radius oversight | A control pattern mapping review intensity to the reach and severity of what an agent's change could disrupt if flawed. | GAIE, arXiv 2606.22484 | partOf: graduated human oversight | Lets cosmetic changes bypass heavy review while ledger changes trigger strong authorisation. |
| generation-to-deployment lifecycle | The end-to-end pipeline governing code from initial AI generation to production. | GAIE, arXiv 2606.22484 | related: development-pipeline governance, GAIE | The path an agent-written artefact must traverse before it runs live. |
| development-pipeline governance | The policies, access controls, and programmatic gates embedded in delivery pipelines to monitor agent activity. | GAIE, arXiv 2606.22484 | partOf: GAIE; hasPart: evidence artifacts; related: generation-to-deployment lifecycle | The external cage ensuring governance cannot be altered by the agent itself. |
| evidence artifacts | Verified logs, signatures, and decision records produced by governance workflows to prove compliance. | GAIE, arXiv 2606.22484 | partOf: development-pipeline governance; related: published reliability record | Turns agent traces into proof for regulatory reporting. |
| agent-as-judge | A pattern in which a constrained secondary model audits, evaluates, or filters a primary agent's outputs. | Zhuge et al., "Agent-as-a-Judge", 2024; applied in Co-Investigator AI, arXiv 2509.08380 | related: GAIE, AML, deceptive alignment; mitigates: hallucination | An automated second line of defence against hallucination and policy violations. |
| reflexivity | The theory that participants' biased expectations actively alter market reality, creating a self-reinforcing feedback loop. | Soros, The Alchemy of Finance (1987); operationalised in arXiv 2606.00061 | hasPart: participative function, cognitive function; related: directional forecasting accuracy, model drift | Forces models to anticipate how their own recommendations move the prices they predict. |
| participative function | The vector in a reflexive loop where expectations are translated into capital allocations, altering prices. | Soros (1987); arXiv 2606.00061 | partOf: reflexivity | The trade-execution side of an agent: its orders shift order-book depth and pricing. |
| cognitive function | The vector in a reflexive loop where prices and trends are observed to form imperfect expectations. | Soros (1987); arXiv 2606.00061 | partOf: reflexivity | The data-intake side of an agent as it interprets markets to update strategy. |
| memorization control | Parameters and tests that prevent a model from regurgitating exact training sequences, used here to control benchmark contamination. | arXiv 2606.00061 | related: reflexivity, model drift | Stops trading agents from copying a historical pattern without checking present conditions. |
| directional forecasting accuracy | The share of times a system correctly predicts the sign (up/down) of a move, independent of magnitude. | arXiv 2606.00061 | related: Sharpe ratio, reflexivity | A primary validation anchor for trend-following or hedging agents. |
| Sharpe ratio | Risk-adjusted performance: excess return divided by volatility. | Sharpe (1966) | related: tail risk, directional forecasting accuracy | A common optimisation target and reward metric for portfolio-management agents. |
Section 2 — EU regulatory frameworks (AI Act & technical standards)
| Term | Proposed Definition | Source (canonical) | Relations | Relevance to Agentic AI |
|---|---|---|---|---|
| GPAI | General-Purpose AI. Models with significant generality, able to perform a broad range of distinct tasks across domains. | Regulation (EU) 2024/1689 (AI Act); EC GPAI guidelines | narrower: systemic-risk GPAI (Art. 51); hasPart: GPAI enforcement, GPAI Code of Practice; related: 10^25 FLOP threshold | Sets the baseline compliance and reporting that upstream providers pass to agent developers. |
| GPAI enforcement | The auditing protocols and penalty frameworks by which authorities compel GPAI compliance (enforcement from 2 August 2026). | EC GPAI guidelines; Regulation (EU) 2024/1689 | partOf: EU AI Act; related: AI Office, GPAI Code of Practice | Marks the shift from voluntary ethics to legal mandates backed by fines. |
| AI Office | The European Commission body coordinating AI policy and supervising GPAI compliance. | Regulation (EU) 2024/1689 | related: GPAI enforcement, EU AI Act | The body reviewing frontier providers and imposing compliance criteria. |
| GPAI Code of Practice | A regulator-backed operational manual of technical steps, risk assessments, and mitigations for GPAI providers. | EC GPAI guidelines | related: alternative adequate means, GPAI; partOf: EU AI Act compliance | A compliance blueprint frontier agent backends can follow to operate in the EU. |
| alternative adequate means | A provision allowing providers to demonstrate compliance via internal frameworks achieving equivalent outcomes to the Code. | EC GPAI guidelines | related: GPAI Code of Practice | Lets advanced teams design custom safety controls rather than follow the Code verbatim. |
| Article 51 | The AI Act provision defining when a GPAI model is classified as presenting systemic risk. | Regulation (EU) 2024/1689 | partOf: EU AI Act; related: 10^25 FLOP threshold | Triggers mandatory red-teaming and adversarial testing for the largest models. |
| Article 53 | The AI Act provision detailing documentation, transparency, and copyright obligations for GPAI providers. | Regulation (EU) 2024/1689 | partOf: EU AI Act; related: GPAI | Forces transparency trails on data provenance and model documentation. |
| 10^25 FLOP threshold | A training-compute trigger used to flag potential systemic capability. | Regulation (EU) 2024/1689 | related: Article 51 | Defines which models powering agents attract the highest tier of scrutiny. |
| prEN 18286 | Draft European harmonised standard on quality management for AI systems. | CEN-CENELEC JTC 21 | partOf: CEN-CENELEC suite; related: EU AI Act | Sets how enterprises organise risk boards and sign-off gates for agent loops. |
| prEN 18228 | Draft harmonised standard on robustness, accuracy, and predictability of AI systems. | CEN-CENELEC JTC 21 | related: model risk, EU AI Act | The validation criteria an agent must clear to prove it won't act unpredictably. |
| prEN 18229-1 / 18229-2 | Draft harmonised standards on lifecycle engineering and cybersecurity for high-risk AI. | CEN-CENELEC JTC 21 | related: indirect prompt injection, information-flow control | Mandates security controls around prompt injection, tool-calling, and memory. |
| prEN 18282 | Draft harmonised standard on recording, logging, and tracing AI operations. | CEN-CENELEC JTC 21 | related: evidence artifacts, published reliability record | Demands an immutable audit trail for every tool-call and sub-decision. |
| prEN 18283 | Draft harmonised standard on human oversight (human-in/over-the-loop). | CEN-CENELEC JTC 21 | related: graduated human oversight, EU AI Act Art. 14 | Controls how dashboards present agent state so an operator can intervene. |
| prEN 18284 | Draft harmonised standard on information provision, transparency, and disclosure. | CEN-CENELEC JTC 21 | related: transparency disclosure | Forces customer-facing agents to output clear disclosure and source tags. |
Section 3 — Financial crime, stablecoin plumbing & asset tokenization
| Term | Proposed Definition | Source (canonical) | Relations | Relevance to Agentic AI |
|---|---|---|---|---|
| SAR | Suspicious Activity Report. A confidential compliance filing reporting known or suspected illicit activity to regulators. | US Treasury / FinCEN; agentic context: arXiv 2509.08380 | related: AML, FinCEN, crime-typology alignment; producedBy: agentic AML | Becomes an artefact drafted by compliance agents, demanding accuracy checks. |
| AML | Anti-Money Laundering. The framework of laws and procedures preventing disguise of illicit funds as legitimate income. | FATF standards; US BSA | broader: FCC; hasPart: KYC, sanctions; related: BSA, FATF | The ruleset transactional agents must satisfy before moving funds. |
| BSA | Bank Secrecy Act. US legislation requiring institutions to help detect and prevent money laundering. | US Bank Secrecy Act (31 U.S.C. 5311 et seq.) | related: AML, FinCEN, PPSI | Dictates reporting logic and data retention for US payment agents. |
| FATF | Financial Action Task Force. The intergovernmental body setting AML/CFT standards. | FATF | related: AML, Travel Rule | Sets the baselines (e.g. Travel Rule) cross-border payment routers must satisfy. |
| FinCEN | Financial Crimes Enforcement Network. The US Treasury bureau collecting and analysing financial-transaction data. | US Department of the Treasury (FinCEN) | related: SAR, BSA, PPSI | The enforcement audience agents report to when flagging suspicious activity. |
| AI-privacy guard layer | A software layer that strips or shields personally identifiable information before data enters AI pipelines. | Co-Investigator AI, arXiv 2509.08380 | partOf: agentic AML; related: information-flow control | Shields consumer identities from being ingested into model logs or weights. |
| crime-typology alignment | Matching suspicious transaction sequences against known structured patterns of criminal evasion. | Co-Investigator AI, arXiv 2509.08380 | related: SAR, AML | Lets compliance agents build accurate narratives for multi-hop laundering. |
| FCC | Financial Crime Compliance. The bank function and workflows enforcing AML and sanctions policy. | Industry usage (e.g. Everest Group) | hasPart: AML; related: sanctions false-positive classifier | The workflow being reshaped by agentic co-investigators. |
| sanctions false-positive classifier | A model that filters out incorrect name-matches from sanctions screening. | Industry usage (e.g. Everest Group) | partOf: FCC; related: AML | A front-end filter verifying context before escalating a match to a human. |
| par-value redemption | The right to exchange a stablecoin for fiat at 1:1 on demand. | arXiv 2604.17167 | related: reserve quality, redemption surge; partOf: stablecoin design | The liquidity rule asset-management agents rely on when converting tokens to cash. |
| reserve quality | The safety, liquidity, and creditworthiness of the assets backing a stablecoin. | arXiv 2604.17167 | related: par-value redemption, broker-dealer intermediation | A key data point for agents evaluating counterparty risk of holding an asset. |
| redemption surge | A sudden mass demand to redeem stablecoins for fiat, often driven by panic. | arXiv 2604.17167 | related: par-value redemption, stress testing | The crisis scenario stress-testing agents model for portfolio survival. |
| broker-dealer intermediation | Reliance on licensed market makers to buy, sell, and redeem the securities backing a digital asset. | arXiv 2604.17167 | related: hierarchy of money, reserve quality | The access point where execution agents route large liquidation orders. |
| hierarchy of money | A classification of instruments by liquidity and counterparty risk, from central-bank reserves down to private credit. | Economic literature (Mehrling; cf. arXiv 2604.17167) | related: par-value redemption, reserve quality | Informs allocation agents prioritising high-tier liquidity during stress. |
| GENIUS Act | Guiding and Establishing National Innovation for U.S. Stablecoins Act. US federal legislation enacted 2025 establishing a framework for dollar payment stablecoins. | GENIUS Act (US, enacted 2025) | regulates: PPSI; related: MiCA, BSA | The primary legal framework US payment/settlement agents operate under. |
| PPSI | Permitted Payment Stablecoin Issuer. Under the GENIUS Act, an entity authorised to issue payment stablecoins; under the FinCEN/OFAC proposed rule, subject to BSA/AML obligations and a sanctions-compliance programme. | FinCEN/OFAC NPRM, Docket FINCEN-2026-0100 | regulatedBy: GENIUS Act, FinCEN; related: BSA, sanctions | Defines the regulated issuer category agentic stablecoin flows depend on. |
| MiCA | Markets in Crypto-Assets Regulation. The EU framework governing crypto-asset and stablecoin issuance and trading. | Regulation (EU) 2023/1114 | related: GENIUS Act, RWA; regulates: crypto-assets | The EU compliance boundary digital-asset agents must respect. |
| real-world asset tokenization | Representing rights to a physical or traditional financial asset as tokens on a blockchain ledger. | arXiv 2606.08534 | hasPart: settlement model, whitelist transferability, rebasing; related: oracle risk, platform concentration | Turns off-chain assets into programmable primitives agents can trade and manage. |
| RWA | Real-World Asset. A physical or traditional financial asset that has been tokenised. | arXiv 2606.08534 | broader: real-world asset tokenization; related: oracle risk | The portfolio components investment agents buy, sell, or pledge as collateral. |
| oracle risk | The risk that an external data feed supplies inaccurate, delayed, or manipulated data to a smart contract. | arXiv 2606.08534 | related: RWA, platform concentration; threatens: settlement | A primary failure point risk-monitoring agents must audit. |
| platform concentration | Systemic risk from most tokenisation relying on a single underlying protocol or provider. | arXiv 2606.08534 | related: oracle risk, systemic risk | Informs diversification agents avoiding over-exposure to one network. |
| whitelist transferability | A feature where tokens transfer only between addresses that have cleared identity checks. | arXiv 2606.08534 | partOf: RWA; related: KYC, sanctions | A hard boundary preventing agents swapping with non-compliant counterparties. |
| rebasing | An automated mechanism adjusting circulating token supply to reflect yield or price changes. | arXiv 2606.08534 | partOf: RWA token mechanics | Requires tracking agents to adjust valuation for shifting token quantities. |
| settlement model | The technical and legal framework (e.g. atomic, deferred net settlement) finalising ownership transfer. | arXiv 2606.08534 | related: settlement determination, RWA | Defines execution parameters trading agents optimise for cost and safety. |
Section 4 — Quantitative engineering, biotech & applied coding
| Term | Proposed Definition | Source (canonical) | Relations | Relevance to Agentic AI |
|---|---|---|---|---|
| parametric synthetic benchmark | A generated testing environment producing simulated financial time-series with controllable parameters. | FinStressTS, arXiv 2606.03184 | related: stress testing, tail risk; usedFor: model validation | The synthetic track for validating trading agents before they manage capital. |
| tail risk | The probability of extreme losses from rare events at the far end of a distribution. | FinStressTS, arXiv 2606.03184 | related: stress testing, Sharpe ratio | The risk constraint an asset-management agent must respect to avoid liquidation. |
| stress testing | Simulating extreme market shocks to evaluate how a model, portfolio, or institution survives them. | FinStressTS, arXiv 2606.03184; BCBS (Basel III) | related: Basel III, parametric synthetic benchmark, redemption surge | The mandatory routine an automated strategy must clear before deployment. |
| model risk | The risk of adverse consequences from flawed or misapplied quantitative models. | FinStressTS, arXiv 2606.03184; cf. Fed SR 11-7 | related: model drift, stress testing; regulatedBy: prEN 18228 | The need for external governance over agents whose models can drift and fail. |
| Basel III | The international framework for bank capital adequacy, stress testing, and liquidity risk. | Basel Committee on Banking Supervision | related: stress testing, model risk | The capital and liquidity boundaries institutional trading agents must maintain. |
| regime switch | An abrupt structural transition in market behaviour, volatility, or correlations. | FinStressTS, arXiv 2606.03184; Macro-aware, arXiv 2606.00624 | related: model drift, mixed-frequency forecasting; closeMatch: regime shift | A trigger for an agent to re-evaluate strategy and adapt parameters. |
| agentic drug discovery | Applying autonomous agents to the multi-step pipeline of target identification, molecule generation, and experiment design. | Beyond SMILES, arXiv 2602.10163 | hasPart: target identification; related: SMILES, ChatInvent, human-in-the-loop discovery; addresses: Eroom's law | Moves early-stage research toward an automated, scalable search loop. |
| SMILES | Simplified Molecular-Input Line-Entry System. A string notation describing chemical structures as text. | Weininger (1988) | related: agentic drug discovery, ChatInvent | The textual language molecular-design agents read, modify, and output. |
| Eroom's law | The observation that drug-discovery productivity per R&D dollar falls over time (Moore's law reversed). | Scannell et al. (2012) | related: agentic drug discovery | The economic challenge agentic biotech pipelines aim to ease. |
| process-level vs molecule-level benchmark | An evaluation paradigm comparing an agent's ability to orchestrate multi-step research against single-structure design. | Beyond SMILES, arXiv 2602.10163 | related: agentic drug discovery | The framework for testing whether an agent can run a project, not just emit data. |
| human-in-the-loop discovery | A workflow where humans guide, review, and approve agent recommendations. | Beyond SMILES, arXiv 2602.10163; Robin (Nature, 2026) | related: agentic drug discovery, graduated human oversight | The interface where a scientific agent pauses for expert validation. |
| target identification | The phase pinpointing a biological molecule or pathway central to a disease. | Beyond SMILES, arXiv 2602.10163 | partOf: agentic drug discovery | The problem-formulation phase where an agent isolates therapeutic vectors. |
| reverse translation | Taking verified clinical outcomes back into lab models to uncover disease insight. | Beyond SMILES (refs), arXiv 2602.10163 | related: target identification | Where an agent analyses clinical data to derive new compound constraints. |
| ChatInvent | An agentic invention/molecular-design system reported as deployed at AstraZeneca. | He et al., Drug Discovery Today (2026) | related: agentic drug discovery, SMILES | An example of a tool-enabled scientific agent turning design requirements into structures. |
| compliance-as-code | Writing regulatory rules and policies directly as executable software. | Compliance-to-Code, arXiv 2505.19804 | broader: RegTech; related: rule-as-code, regulatory rule translation | The machine-readable rulebook agents ingest to keep actions legal. |
| rule-as-code | Drafting statutes or regulations in a structured, machine-readable form from inception. | Compliance-to-Code, arXiv 2505.19804; OECD rules-as-code work | related: compliance-as-code | Lets compliance agents ingest regulation without manual interpretation. |
| RegTech | Regulatory Technology. Software automating compliance, reporting, and risk management. | Industry usage (FCA RegTech) | hasPart: compliance-as-code; related: DORA | The domain where compliance and auditing agents are deployed. |
| DORA | Digital Operational Resilience Act. EU framework on IT security, incident reporting, and resilience for financial entities. | Regulation (EU) 2022/2554 | regulates: financial IT resilience; related: GAIE, RegTech | The resilience and security boundaries financial agent networks must meet. |
| regulatory rule translation | Converting natural-language legal text into deterministic code and constraints. | Compliance-to-Code, arXiv 2505.19804 | related: compliance-as-code, rule-as-code | The workflow turning shifting legal updates into actionable constraints. |
| mixed-frequency forecasting | Modelling that combines data captured at different intervals (e.g. daily prices with quarterly GDP). | Macro-aware, arXiv 2606.00624 | hasPart: hierarchical mixed-frequency attention; related: MIDAS, model drift | Lets agents blend real-time prices with slower macro data. |
| hierarchical mixed-frequency attention | An attention architecture weighting data sequences across different cadences. | Macro-aware, arXiv 2606.00624 | implements: mixed-frequency forecasting | The engine letting an allocation agent balance fast and slow signals. |
| MIDAS | Mixed Data Sampling. A regression technique for variables sampled at different frequencies. | Ghysels, Santa-Clara & Valkanov (2004) | related: mixed-frequency forecasting (precursor) | The statistical baseline against which attention models are benchmarked. |
| model drift | Gradual decay of predictive accuracy as real-world conditions diverge from training assumptions. | Macro-aware, arXiv 2606.00624 | related: regime shift, model risk, reflexivity | The degradation risk requiring continuous monitoring of trading agents. |
| regime shift | A significant, persistent change in a time series' underlying distribution. | Macro-aware, arXiv 2606.00624 | closeMatch: regime switch; related: model drift | A signal an agent must detect to switch modes and protect assets. |
Section 5 — Security threats & core safety / interpretability
| Term | Proposed Definition | Source (canonical) | Relations | Relevance to Agentic AI |
|---|---|---|---|---|
| memory poisoning | Injecting malicious data into an agent's memory layer to corrupt future decisions. | OWASP GenAI / agent-security literature | related: indirect prompt injection, information-flow control; threatens: agent memory | Lets an attacker slowly alter agent logic to trigger unauthorised actions. |
| indirect prompt injection | An exploit where an agent reads untrusted content carrying hidden instructions that hijack its execution. | Greshake et al. (2023); OWASP GenAI | related: memory poisoning, origin-bound authority; regulatedBy: prEN 18229 / 18282 | Can trick a banking agent into unauthorised transfers via a compromised document. |
| information-flow control | An architecture tracking and restricting data movement across security domains in a pipeline. | Security literature (IFC); agent-security feeds | mitigates: indirect prompt injection, memory poisoning | Prevents an agent leaking internal data to untrusted tools or endpoints. |
| origin-bound authority | Binding an agent's authorisation to execute a tool to the verified source of the initiating request. | Agent-security literature | mitigates: indirect prompt injection | Ensures an externally-sourced instruction cannot trigger a high-risk operation. |
| Sybil resistance | A system's capacity to defend against attackers creating many fake identities to gain influence. | Douceur (2002) | related: KYA; mitigates: fake-identity attacks | Stops a fleet of rogue agents from rigging reputation or flooding order books. |
| KYA | Know Your Agent. A governance framework for registering, verifying, and profiling autonomous agents before deployment. | Emerging governance usage | related: Sybil resistance, evidence artifacts; analogous: KYC | The onboarding gate blocking unverified agents from enterprise rails. |
| trace-economic underwriting | Pricing insurance or credit by analysing the step-by-step audit trails of an agentic pipeline. | Insurance/agent-risk feeds | related: evidence artifacts, published reliability record | The quantitative basis for pricing cover against rogue-agent losses. |
| SAE | Sparse Autoencoder. A network that decomposes dense model activations into interpretable features. | Bricken et al., "Towards Monosemanticity" (Anthropic, 2023) | related: superposition, dictionary learning, monosemanticity; usedFor: interpretability | A diagnostic for auditing an agent's internal processing before it acts. |
| superposition | The phenomenon of a network packing more features than it has neurons via combination. | Elhage et al., "Toy Models of Superposition" (Anthropic, 2022) | related: polysemanticity, SAE | Explains why agent internals are hard to interpret and monitor. |
| monosemanticity | The state where a neuron or feature maps to exactly one clear concept. | Bricken et al. (Anthropic, 2023) | related: superposition, SAE; opposite: polysemanticity | The target for safety monitors that flag an agent planning an exploit. |
| polysemanticity | The state where one neuron responds to multiple unrelated concepts by context. | Anthropic interpretability work | opposite: monosemanticity; related: superposition | The complexity that motivates sparse autoencoders for interpreting agents. |
| dictionary learning | Unsupervised extraction of an overcomplete set of monosemantic features from activations. | Anthropic interpretability work | produces: monosemantic features; related: SAE | Enables dashboards showing which features an agent prioritises. |
| circuit analysis | Reverse-engineering the subgraphs and pathways inside a model that drive behaviours. | Elhage et al., "A Mathematical Framework for Transformer Circuits" (2021) | related: activation patching, SAE | Lets engineers locate and deactivate dangerous behaviours surgically. |
| activation patching | Causally modifying internal activations during a forward pass to test how features alter output. | Mechanistic-interpretability literature | partOf: circuit analysis | Stress-tests an agent's alignment by injecting concepts to see if gates hold. |
| ELK | Eliciting Latent Knowledge. The alignment problem of extracting a model's true internal knowledge. | Christiano, Cotra & Xu (ARC, 2021) | related: deceptive alignment; goal: truthful reporting | Ensures an auditing agent reports facts rather than a pleasing false report. |
| manifold steering | Nudging internal activations along valid concept dimensions to alter output in real time. | Mechanistic-interpretability literature | related: SAE, activation patching | An automated brake pushing an agent away from high-risk paths. |
| deceptive alignment | A failure where a model appears compliant in training while concealing misaligned goals. | Hubinger et al. (2019) | related: ELK, agent-as-judge | Warns that agents might bypass filters with subtly flawed but benign-looking actions. |
| MCP | Model Context Protocol. An open standard for connecting models to external data, tools, and applications. | Anthropic (Model Context Protocol) | related: A2A, tool use | The secure data highway agents use to reach files, databases, and channels. |
| A2A | Agent-to-Agent. Protocols and frameworks linking independent agents without human intervention. | Google (Agent2Agent protocol) | related: MCP, AP2 | The language a procurement agent uses to negotiate with a supplier's agent. |
| neocloud | A category of providers offering high-performance cloud infrastructure optimised for GPU rental and AI. | Industry usage | related: CoWoS, HBM4 | The backend compute where enterprise agent platforms run at scale. |
| CoWoS | Chip-on-Wafer-on-Substrate. An advanced 2.5D semiconductor packaging technology. | TSMC | related: HBM4, neocloud | The hardware enabling the chips that power complex agent operations. |
| HBM4 | High Bandwidth Memory 4. The next generation of stacked DRAM for AI accelerators. | JEDEC | related: CoWoS | The memory performance needed for large context in multi-agent reasoning. |
| abliteration | Modifying model weights to remove safety alignments without a full retrain. | Open-weight community (cf. Arditi et al., 2024) | threatens: safety guardrails; related: open-weight models | The risk of stripping safety filters to build unconstrained attack agents. |