RETIRED/SUPERSEDED BY VOCAB FILE AI KR CG — Agentic AI Vocabulary: Walkthrough & Tutorial

W3C AI Knowledge Representation Community Group · Working draft, June 2026

Status: Working draft, open for evaluation and feedback. Not a normative specification.

Purpose: The vocabulary listend in the table below, and as visual artefact in this repo https://w3c-cg.github.io/aikr/VOCAB.%2029%20june/ is a — a controlled vocabulary intended to help populate a semantic map of the agentic-AI ecosystem, as part of the landscaping of that ecosystem. Definitions are proposed, not settled. Provenance is given per term so each can be traced to a primary source and independently verified. Relations are expressed informally, in a SKOS-like style (broader / narrower / part-of / related / regulates / mitigates), to support mapping rather than to assert a finished ontology.

Note on sources: the "Source" column gives the primary or canonical origin of each term (the originating paper, standards instrument, statute, or protocol owner).

Corrections in this version: PPSI corrected to "Permitted Payment Stablecoin Issuer"; GAIE and RAILS acronym expansions marked unconfirmed pending verification against source papers; GENIUS Act dating reduced to year of enactment; x402 description tightened; Source column re-pointed to canonical origins; a Relations column added throughout.

Section 1 — Agentic commerce, oversight & reflexivity

TermProposed DefinitionSource (canonical)RelationsRelevance to Agentic AI
agentic clearingThe operational layer that evaluates whether an autonomous AI agent has fulfilled its transaction obligations, assigns liability, and determines the subsequent settlement action — distinct from payment and from settlement execution.de Valois-Franklin & Bogdan, RAILS, arXiv 2606.08790broader: settlement; related: clearing function, settlement determinationPrevents agent-to-agent transactions from failing without a mechanism to assign liability or reverse value.
clearing functionA deterministic process that consumes reliability scores and records to dictate which settlement or dispute consequence follows an agent's output.RAILS, arXiv 2606.08790partOf: RAILS; related: per-output reliability score, settlement determinationThe actionable control rule that tells the payment rails how to adjust based on agent performance.
verification-native clearingA design in which clearing checks are embedded within a system's verification phase rather than added post-hoc.RAILS, arXiv 2606.08790related: agentic clearing, RAILSCouples an agent's output to its verification record, supporting automated auditability before value moves.
per-output reliability scoreA discrete metric attached to each agent output, quantifying a measured judgement of its quality and adherence to constraints.RAILS, arXiv 2606.08790partOf: RAILS; related: published reliability record, clearing functionLets multi-agent workflows weigh the risk of an individual contribution before committing capital or code.
published reliability recordA durable, inspectable log of historical reliability scores and output judgements.RAILS, arXiv 2606.08790partOf: RAILS; related: per-output reliability score, evidence artifactsThe foundational audit trail for defending autonomous agent activity to supervisors.
settlement determinationThe authoritative decision on how assets should move, distinct from the physical execution of that transfer.RAILS, arXiv 2606.08790related: agentic clearing, settlement modelIsolates dispute resolution from payment plumbing, protecting capital from rogue agent behaviour.
RAILSA three-part architectural framework (reliability score, reliability record, clearing function) treating clearing as an independent layer in agentic commerce. Acronym expansion ("Real-Time Agent Integrity & Ledger Settlement") proposed but not yet confirmed against the source paper.arXiv 2606.08790hasPart: per-output reliability score, published reliability record, clearing function; related: x402, AP2Framework enabling traditional networks (e.g. Visa, Mastercard) to scale safer agentic commerce.
x402An agent/machine payment scheme built on the HTTP 402 ("Payment Required") status, enabling software agents to settle value (typically in stablecoins) inline with a request.Coinbase (x402 specification)broader: agent payment rail; related: AP2, mandate protocol, RAILSAn execution layer letting agents autonomously trigger payments, requiring clearing layers above it.
AP2Agent Payments Protocol. A mandate-based protocol defining how, when, and within what bounds value can be authorised for transmission by an AI agent.Google (Agent Payments Protocol)related: x402, mandate protocol; partOf: agent authorizationGoverns the pre-authorisation boundary for agentic spending.
mandate protocolA framework defining and enforcing pre-approved operational boundaries and financial caps delegated to a software agent.Agent-payments literature (cf. AP2)related: AP2, x402The sandbox shielding corporate wallets from runaway or exploited agent logic.
graduated human oversightA governance pattern that adjusts the necessity, depth, and timing of human review according to the risk profile and "blast radius" of an agentic action.GAIE, arXiv 2606.22484definedBy: GAIE; hasPart: blast-radius oversight; related: regulatory risk profile; regulatedBy: EU AI Act Art. 14, prEN 18283Scales deployment for low-risk tasks while gating high-consequence actions.
GAIEA framework for enforcing proportionate human oversight on agentic actions in regulated domains. Acronym expansion unconfirmed; the source paper centres on "graduated" oversight, so the earlier "Governed AI-Assisted Engineering" reading should be verified before use.arXiv 2606.22484hasPart: graduated human oversight, regulatory risk profile, blast-radius oversight, evidence artifacts; related: DORAA playbook for safely scaling code-generating and code-executing agents.
regulatory risk profileA classification of an agentic task by its compliance implications, domain sensitivity, and potential for systemic or financial harm.GAIE, arXiv 2606.22484partOf: GAIE; related: graduated human oversightDetermines whether an output can self-deploy or must be gated by sign-off.
blast-radius oversightA control pattern mapping review intensity to the reach and severity of what an agent's change could disrupt if flawed.GAIE, arXiv 2606.22484partOf: graduated human oversightLets cosmetic changes bypass heavy review while ledger changes trigger strong authorisation.
generation-to-deployment lifecycleThe end-to-end pipeline governing code from initial AI generation to production.GAIE, arXiv 2606.22484related: development-pipeline governance, GAIEThe path an agent-written artefact must traverse before it runs live.
development-pipeline governanceThe policies, access controls, and programmatic gates embedded in delivery pipelines to monitor agent activity.GAIE, arXiv 2606.22484partOf: GAIE; hasPart: evidence artifacts; related: generation-to-deployment lifecycleThe external cage ensuring governance cannot be altered by the agent itself.
evidence artifactsVerified logs, signatures, and decision records produced by governance workflows to prove compliance.GAIE, arXiv 2606.22484partOf: development-pipeline governance; related: published reliability recordTurns agent traces into proof for regulatory reporting.
agent-as-judgeA pattern in which a constrained secondary model audits, evaluates, or filters a primary agent's outputs.Zhuge et al., "Agent-as-a-Judge", 2024; applied in Co-Investigator AI, arXiv 2509.08380related: GAIE, AML, deceptive alignment; mitigates: hallucinationAn automated second line of defence against hallucination and policy violations.
reflexivityThe theory that participants' biased expectations actively alter market reality, creating a self-reinforcing feedback loop.Soros, The Alchemy of Finance (1987); operationalised in arXiv 2606.00061hasPart: participative function, cognitive function; related: directional forecasting accuracy, model driftForces models to anticipate how their own recommendations move the prices they predict.
participative functionThe vector in a reflexive loop where expectations are translated into capital allocations, altering prices.Soros (1987); arXiv 2606.00061partOf: reflexivityThe trade-execution side of an agent: its orders shift order-book depth and pricing.
cognitive functionThe vector in a reflexive loop where prices and trends are observed to form imperfect expectations.Soros (1987); arXiv 2606.00061partOf: reflexivityThe data-intake side of an agent as it interprets markets to update strategy.
memorization controlParameters and tests that prevent a model from regurgitating exact training sequences, used here to control benchmark contamination.arXiv 2606.00061related: reflexivity, model driftStops trading agents from copying a historical pattern without checking present conditions.
directional forecasting accuracyThe share of times a system correctly predicts the sign (up/down) of a move, independent of magnitude.arXiv 2606.00061related: Sharpe ratio, reflexivityA primary validation anchor for trend-following or hedging agents.
Sharpe ratioRisk-adjusted performance: excess return divided by volatility.Sharpe (1966)related: tail risk, directional forecasting accuracyA common optimisation target and reward metric for portfolio-management agents.

Section 2 — EU regulatory frameworks (AI Act & technical standards)

TermProposed DefinitionSource (canonical)RelationsRelevance to Agentic AI
GPAIGeneral-Purpose AI. Models with significant generality, able to perform a broad range of distinct tasks across domains.Regulation (EU) 2024/1689 (AI Act); EC GPAI guidelinesnarrower: systemic-risk GPAI (Art. 51); hasPart: GPAI enforcement, GPAI Code of Practice; related: 10^25 FLOP thresholdSets the baseline compliance and reporting that upstream providers pass to agent developers.
GPAI enforcementThe auditing protocols and penalty frameworks by which authorities compel GPAI compliance (enforcement from 2 August 2026).EC GPAI guidelines; Regulation (EU) 2024/1689partOf: EU AI Act; related: AI Office, GPAI Code of PracticeMarks the shift from voluntary ethics to legal mandates backed by fines.
AI OfficeThe European Commission body coordinating AI policy and supervising GPAI compliance.Regulation (EU) 2024/1689related: GPAI enforcement, EU AI ActThe body reviewing frontier providers and imposing compliance criteria.
GPAI Code of PracticeA regulator-backed operational manual of technical steps, risk assessments, and mitigations for GPAI providers.EC GPAI guidelinesrelated: alternative adequate means, GPAI; partOf: EU AI Act complianceA compliance blueprint frontier agent backends can follow to operate in the EU.
alternative adequate meansA provision allowing providers to demonstrate compliance via internal frameworks achieving equivalent outcomes to the Code.EC GPAI guidelinesrelated: GPAI Code of PracticeLets advanced teams design custom safety controls rather than follow the Code verbatim.
Article 51The AI Act provision defining when a GPAI model is classified as presenting systemic risk.Regulation (EU) 2024/1689partOf: EU AI Act; related: 10^25 FLOP thresholdTriggers mandatory red-teaming and adversarial testing for the largest models.
Article 53The AI Act provision detailing documentation, transparency, and copyright obligations for GPAI providers.Regulation (EU) 2024/1689partOf: EU AI Act; related: GPAIForces transparency trails on data provenance and model documentation.
10^25 FLOP thresholdA training-compute trigger used to flag potential systemic capability.Regulation (EU) 2024/1689related: Article 51Defines which models powering agents attract the highest tier of scrutiny.
prEN 18286Draft European harmonised standard on quality management for AI systems.CEN-CENELEC JTC 21partOf: CEN-CENELEC suite; related: EU AI ActSets how enterprises organise risk boards and sign-off gates for agent loops.
prEN 18228Draft harmonised standard on robustness, accuracy, and predictability of AI systems.CEN-CENELEC JTC 21related: model risk, EU AI ActThe validation criteria an agent must clear to prove it won't act unpredictably.
prEN 18229-1 / 18229-2Draft harmonised standards on lifecycle engineering and cybersecurity for high-risk AI.CEN-CENELEC JTC 21related: indirect prompt injection, information-flow controlMandates security controls around prompt injection, tool-calling, and memory.
prEN 18282Draft harmonised standard on recording, logging, and tracing AI operations.CEN-CENELEC JTC 21related: evidence artifacts, published reliability recordDemands an immutable audit trail for every tool-call and sub-decision.
prEN 18283Draft harmonised standard on human oversight (human-in/over-the-loop).CEN-CENELEC JTC 21related: graduated human oversight, EU AI Act Art. 14Controls how dashboards present agent state so an operator can intervene.
prEN 18284Draft harmonised standard on information provision, transparency, and disclosure.CEN-CENELEC JTC 21related: transparency disclosureForces customer-facing agents to output clear disclosure and source tags.

Section 3 — Financial crime, stablecoin plumbing & asset tokenization

TermProposed DefinitionSource (canonical)RelationsRelevance to Agentic AI
SARSuspicious Activity Report. A confidential compliance filing reporting known or suspected illicit activity to regulators.US Treasury / FinCEN; agentic context: arXiv 2509.08380related: AML, FinCEN, crime-typology alignment; producedBy: agentic AMLBecomes an artefact drafted by compliance agents, demanding accuracy checks.
AMLAnti-Money Laundering. The framework of laws and procedures preventing disguise of illicit funds as legitimate income.FATF standards; US BSAbroader: FCC; hasPart: KYC, sanctions; related: BSA, FATFThe ruleset transactional agents must satisfy before moving funds.
BSABank Secrecy Act. US legislation requiring institutions to help detect and prevent money laundering.US Bank Secrecy Act (31 U.S.C. 5311 et seq.)related: AML, FinCEN, PPSIDictates reporting logic and data retention for US payment agents.
FATFFinancial Action Task Force. The intergovernmental body setting AML/CFT standards.FATFrelated: AML, Travel RuleSets the baselines (e.g. Travel Rule) cross-border payment routers must satisfy.
FinCENFinancial Crimes Enforcement Network. The US Treasury bureau collecting and analysing financial-transaction data.US Department of the Treasury (FinCEN)related: SAR, BSA, PPSIThe enforcement audience agents report to when flagging suspicious activity.
AI-privacy guard layerA software layer that strips or shields personally identifiable information before data enters AI pipelines.Co-Investigator AI, arXiv 2509.08380partOf: agentic AML; related: information-flow controlShields consumer identities from being ingested into model logs or weights.
crime-typology alignmentMatching suspicious transaction sequences against known structured patterns of criminal evasion.Co-Investigator AI, arXiv 2509.08380related: SAR, AMLLets compliance agents build accurate narratives for multi-hop laundering.
FCCFinancial Crime Compliance. The bank function and workflows enforcing AML and sanctions policy.Industry usage (e.g. Everest Group)hasPart: AML; related: sanctions false-positive classifierThe workflow being reshaped by agentic co-investigators.
sanctions false-positive classifierA model that filters out incorrect name-matches from sanctions screening.Industry usage (e.g. Everest Group)partOf: FCC; related: AMLA front-end filter verifying context before escalating a match to a human.
par-value redemptionThe right to exchange a stablecoin for fiat at 1:1 on demand.arXiv 2604.17167related: reserve quality, redemption surge; partOf: stablecoin designThe liquidity rule asset-management agents rely on when converting tokens to cash.
reserve qualityThe safety, liquidity, and creditworthiness of the assets backing a stablecoin.arXiv 2604.17167related: par-value redemption, broker-dealer intermediationA key data point for agents evaluating counterparty risk of holding an asset.
redemption surgeA sudden mass demand to redeem stablecoins for fiat, often driven by panic.arXiv 2604.17167related: par-value redemption, stress testingThe crisis scenario stress-testing agents model for portfolio survival.
broker-dealer intermediationReliance on licensed market makers to buy, sell, and redeem the securities backing a digital asset.arXiv 2604.17167related: hierarchy of money, reserve qualityThe access point where execution agents route large liquidation orders.
hierarchy of moneyA classification of instruments by liquidity and counterparty risk, from central-bank reserves down to private credit.Economic literature (Mehrling; cf. arXiv 2604.17167)related: par-value redemption, reserve qualityInforms allocation agents prioritising high-tier liquidity during stress.
GENIUS ActGuiding and Establishing National Innovation for U.S. Stablecoins Act. US federal legislation enacted 2025 establishing a framework for dollar payment stablecoins.GENIUS Act (US, enacted 2025)regulates: PPSI; related: MiCA, BSAThe primary legal framework US payment/settlement agents operate under.
PPSIPermitted Payment Stablecoin Issuer. Under the GENIUS Act, an entity authorised to issue payment stablecoins; under the FinCEN/OFAC proposed rule, subject to BSA/AML obligations and a sanctions-compliance programme.FinCEN/OFAC NPRM, Docket FINCEN-2026-0100regulatedBy: GENIUS Act, FinCEN; related: BSA, sanctionsDefines the regulated issuer category agentic stablecoin flows depend on.
MiCAMarkets in Crypto-Assets Regulation. The EU framework governing crypto-asset and stablecoin issuance and trading.Regulation (EU) 2023/1114related: GENIUS Act, RWA; regulates: crypto-assetsThe EU compliance boundary digital-asset agents must respect.
real-world asset tokenizationRepresenting rights to a physical or traditional financial asset as tokens on a blockchain ledger.arXiv 2606.08534hasPart: settlement model, whitelist transferability, rebasing; related: oracle risk, platform concentrationTurns off-chain assets into programmable primitives agents can trade and manage.
RWAReal-World Asset. A physical or traditional financial asset that has been tokenised.arXiv 2606.08534broader: real-world asset tokenization; related: oracle riskThe portfolio components investment agents buy, sell, or pledge as collateral.
oracle riskThe risk that an external data feed supplies inaccurate, delayed, or manipulated data to a smart contract.arXiv 2606.08534related: RWA, platform concentration; threatens: settlementA primary failure point risk-monitoring agents must audit.
platform concentrationSystemic risk from most tokenisation relying on a single underlying protocol or provider.arXiv 2606.08534related: oracle risk, systemic riskInforms diversification agents avoiding over-exposure to one network.
whitelist transferabilityA feature where tokens transfer only between addresses that have cleared identity checks.arXiv 2606.08534partOf: RWA; related: KYC, sanctionsA hard boundary preventing agents swapping with non-compliant counterparties.
rebasingAn automated mechanism adjusting circulating token supply to reflect yield or price changes.arXiv 2606.08534partOf: RWA token mechanicsRequires tracking agents to adjust valuation for shifting token quantities.
settlement modelThe technical and legal framework (e.g. atomic, deferred net settlement) finalising ownership transfer.arXiv 2606.08534related: settlement determination, RWADefines execution parameters trading agents optimise for cost and safety.

Section 4 — Quantitative engineering, biotech & applied coding

TermProposed DefinitionSource (canonical)RelationsRelevance to Agentic AI
parametric synthetic benchmarkA generated testing environment producing simulated financial time-series with controllable parameters.FinStressTS, arXiv 2606.03184related: stress testing, tail risk; usedFor: model validationThe synthetic track for validating trading agents before they manage capital.
tail riskThe probability of extreme losses from rare events at the far end of a distribution.FinStressTS, arXiv 2606.03184related: stress testing, Sharpe ratioThe risk constraint an asset-management agent must respect to avoid liquidation.
stress testingSimulating extreme market shocks to evaluate how a model, portfolio, or institution survives them.FinStressTS, arXiv 2606.03184; BCBS (Basel III)related: Basel III, parametric synthetic benchmark, redemption surgeThe mandatory routine an automated strategy must clear before deployment.
model riskThe risk of adverse consequences from flawed or misapplied quantitative models.FinStressTS, arXiv 2606.03184; cf. Fed SR 11-7related: model drift, stress testing; regulatedBy: prEN 18228The need for external governance over agents whose models can drift and fail.
Basel IIIThe international framework for bank capital adequacy, stress testing, and liquidity risk.Basel Committee on Banking Supervisionrelated: stress testing, model riskThe capital and liquidity boundaries institutional trading agents must maintain.
regime switchAn abrupt structural transition in market behaviour, volatility, or correlations.FinStressTS, arXiv 2606.03184; Macro-aware, arXiv 2606.00624related: model drift, mixed-frequency forecasting; closeMatch: regime shiftA trigger for an agent to re-evaluate strategy and adapt parameters.
agentic drug discoveryApplying autonomous agents to the multi-step pipeline of target identification, molecule generation, and experiment design.Beyond SMILES, arXiv 2602.10163hasPart: target identification; related: SMILES, ChatInvent, human-in-the-loop discovery; addresses: Eroom's lawMoves early-stage research toward an automated, scalable search loop.
SMILESSimplified Molecular-Input Line-Entry System. A string notation describing chemical structures as text.Weininger (1988)related: agentic drug discovery, ChatInventThe textual language molecular-design agents read, modify, and output.
Eroom's lawThe observation that drug-discovery productivity per R&D dollar falls over time (Moore's law reversed).Scannell et al. (2012)related: agentic drug discoveryThe economic challenge agentic biotech pipelines aim to ease.
process-level vs molecule-level benchmarkAn evaluation paradigm comparing an agent's ability to orchestrate multi-step research against single-structure design.Beyond SMILES, arXiv 2602.10163related: agentic drug discoveryThe framework for testing whether an agent can run a project, not just emit data.
human-in-the-loop discoveryA workflow where humans guide, review, and approve agent recommendations.Beyond SMILES, arXiv 2602.10163; Robin (Nature, 2026)related: agentic drug discovery, graduated human oversightThe interface where a scientific agent pauses for expert validation.
target identificationThe phase pinpointing a biological molecule or pathway central to a disease.Beyond SMILES, arXiv 2602.10163partOf: agentic drug discoveryThe problem-formulation phase where an agent isolates therapeutic vectors.
reverse translationTaking verified clinical outcomes back into lab models to uncover disease insight.Beyond SMILES (refs), arXiv 2602.10163related: target identificationWhere an agent analyses clinical data to derive new compound constraints.
ChatInventAn agentic invention/molecular-design system reported as deployed at AstraZeneca.He et al., Drug Discovery Today (2026)related: agentic drug discovery, SMILESAn example of a tool-enabled scientific agent turning design requirements into structures.
compliance-as-codeWriting regulatory rules and policies directly as executable software.Compliance-to-Code, arXiv 2505.19804broader: RegTech; related: rule-as-code, regulatory rule translationThe machine-readable rulebook agents ingest to keep actions legal.
rule-as-codeDrafting statutes or regulations in a structured, machine-readable form from inception.Compliance-to-Code, arXiv 2505.19804; OECD rules-as-code workrelated: compliance-as-codeLets compliance agents ingest regulation without manual interpretation.
RegTechRegulatory Technology. Software automating compliance, reporting, and risk management.Industry usage (FCA RegTech)hasPart: compliance-as-code; related: DORAThe domain where compliance and auditing agents are deployed.
DORADigital Operational Resilience Act. EU framework on IT security, incident reporting, and resilience for financial entities.Regulation (EU) 2022/2554regulates: financial IT resilience; related: GAIE, RegTechThe resilience and security boundaries financial agent networks must meet.
regulatory rule translationConverting natural-language legal text into deterministic code and constraints.Compliance-to-Code, arXiv 2505.19804related: compliance-as-code, rule-as-codeThe workflow turning shifting legal updates into actionable constraints.
mixed-frequency forecastingModelling that combines data captured at different intervals (e.g. daily prices with quarterly GDP).Macro-aware, arXiv 2606.00624hasPart: hierarchical mixed-frequency attention; related: MIDAS, model driftLets agents blend real-time prices with slower macro data.
hierarchical mixed-frequency attentionAn attention architecture weighting data sequences across different cadences.Macro-aware, arXiv 2606.00624implements: mixed-frequency forecastingThe engine letting an allocation agent balance fast and slow signals.
MIDASMixed Data Sampling. A regression technique for variables sampled at different frequencies.Ghysels, Santa-Clara & Valkanov (2004)related: mixed-frequency forecasting (precursor)The statistical baseline against which attention models are benchmarked.
model driftGradual decay of predictive accuracy as real-world conditions diverge from training assumptions.Macro-aware, arXiv 2606.00624related: regime shift, model risk, reflexivityThe degradation risk requiring continuous monitoring of trading agents.
regime shiftA significant, persistent change in a time series' underlying distribution.Macro-aware, arXiv 2606.00624closeMatch: regime switch; related: model driftA signal an agent must detect to switch modes and protect assets.

Section 5 — Security threats & core safety / interpretability

TermProposed DefinitionSource (canonical)RelationsRelevance to Agentic AI
memory poisoningInjecting malicious data into an agent's memory layer to corrupt future decisions.OWASP GenAI / agent-security literaturerelated: indirect prompt injection, information-flow control; threatens: agent memoryLets an attacker slowly alter agent logic to trigger unauthorised actions.
indirect prompt injectionAn exploit where an agent reads untrusted content carrying hidden instructions that hijack its execution.Greshake et al. (2023); OWASP GenAIrelated: memory poisoning, origin-bound authority; regulatedBy: prEN 18229 / 18282Can trick a banking agent into unauthorised transfers via a compromised document.
information-flow controlAn architecture tracking and restricting data movement across security domains in a pipeline.Security literature (IFC); agent-security feedsmitigates: indirect prompt injection, memory poisoningPrevents an agent leaking internal data to untrusted tools or endpoints.
origin-bound authorityBinding an agent's authorisation to execute a tool to the verified source of the initiating request.Agent-security literaturemitigates: indirect prompt injectionEnsures an externally-sourced instruction cannot trigger a high-risk operation.
Sybil resistanceA system's capacity to defend against attackers creating many fake identities to gain influence.Douceur (2002)related: KYA; mitigates: fake-identity attacksStops a fleet of rogue agents from rigging reputation or flooding order books.
KYAKnow Your Agent. A governance framework for registering, verifying, and profiling autonomous agents before deployment.Emerging governance usagerelated: Sybil resistance, evidence artifacts; analogous: KYCThe onboarding gate blocking unverified agents from enterprise rails.
trace-economic underwritingPricing insurance or credit by analysing the step-by-step audit trails of an agentic pipeline.Insurance/agent-risk feedsrelated: evidence artifacts, published reliability recordThe quantitative basis for pricing cover against rogue-agent losses.
SAESparse Autoencoder. A network that decomposes dense model activations into interpretable features.Bricken et al., "Towards Monosemanticity" (Anthropic, 2023)related: superposition, dictionary learning, monosemanticity; usedFor: interpretabilityA diagnostic for auditing an agent's internal processing before it acts.
superpositionThe phenomenon of a network packing more features than it has neurons via combination.Elhage et al., "Toy Models of Superposition" (Anthropic, 2022)related: polysemanticity, SAEExplains why agent internals are hard to interpret and monitor.
monosemanticityThe state where a neuron or feature maps to exactly one clear concept.Bricken et al. (Anthropic, 2023)related: superposition, SAE; opposite: polysemanticityThe target for safety monitors that flag an agent planning an exploit.
polysemanticityThe state where one neuron responds to multiple unrelated concepts by context.Anthropic interpretability workopposite: monosemanticity; related: superpositionThe complexity that motivates sparse autoencoders for interpreting agents.
dictionary learningUnsupervised extraction of an overcomplete set of monosemantic features from activations.Anthropic interpretability workproduces: monosemantic features; related: SAEEnables dashboards showing which features an agent prioritises.
circuit analysisReverse-engineering the subgraphs and pathways inside a model that drive behaviours.Elhage et al., "A Mathematical Framework for Transformer Circuits" (2021)related: activation patching, SAELets engineers locate and deactivate dangerous behaviours surgically.
activation patchingCausally modifying internal activations during a forward pass to test how features alter output.Mechanistic-interpretability literaturepartOf: circuit analysisStress-tests an agent's alignment by injecting concepts to see if gates hold.
ELKEliciting Latent Knowledge. The alignment problem of extracting a model's true internal knowledge.Christiano, Cotra & Xu (ARC, 2021)related: deceptive alignment; goal: truthful reportingEnsures an auditing agent reports facts rather than a pleasing false report.
manifold steeringNudging internal activations along valid concept dimensions to alter output in real time.Mechanistic-interpretability literaturerelated: SAE, activation patchingAn automated brake pushing an agent away from high-risk paths.
deceptive alignmentA failure where a model appears compliant in training while concealing misaligned goals.Hubinger et al. (2019)related: ELK, agent-as-judgeWarns that agents might bypass filters with subtly flawed but benign-looking actions.
MCPModel Context Protocol. An open standard for connecting models to external data, tools, and applications.Anthropic (Model Context Protocol)related: A2A, tool useThe secure data highway agents use to reach files, databases, and channels.
A2AAgent-to-Agent. Protocols and frameworks linking independent agents without human intervention.Google (Agent2Agent protocol)related: MCP, AP2The language a procurement agent uses to negotiate with a supplier's agent.
neocloudA category of providers offering high-performance cloud infrastructure optimised for GPU rental and AI.Industry usagerelated: CoWoS, HBM4The backend compute where enterprise agent platforms run at scale.
CoWoSChip-on-Wafer-on-Substrate. An advanced 2.5D semiconductor packaging technology.TSMCrelated: HBM4, neocloudThe hardware enabling the chips that power complex agent operations.
HBM4High Bandwidth Memory 4. The next generation of stacked DRAM for AI accelerators.JEDECrelated: CoWoSThe memory performance needed for large context in multi-agent reasoning.
abliterationModifying model weights to remove safety alignments without a full retrain.Open-weight community (cf. Arditi et al., 2024)threatens: safety guardrails; related: open-weight modelsThe risk of stripping safety filters to build unconstrained attack agents.