Company

AI Governance Glossary

Comprehensive definitions of AI governance terms for enterprise security, compliance, and technology teams.

Comprehensive definitions of the terms enterprise security, compliance, and technology teams encounter when evaluating AI governance infrastructure.

Agent Authority Scope

The set of actions an autonomous agent is permitted to take, held by the agent itself rather than inherited from whoever launched it. Covers reachable systems, permitted data classifications, transaction limits and expiry, and must narrow rather than widen as work is delegated. Full definition

Agentic AI

Systems that pursue a goal across multiple steps, choosing their own actions along the way. The governance shift is not autonomy in the abstract but that the system takes actions, and actions have consequences a response does not. Full definition

AI Agent

An autonomous software program that can take actions on behalf of a user or organization, including executing API calls, accessing databases, sending messages, and interacting with other systems. AI agents operate through protocols like MCP and A2A and require governance controls including identity, authorization, and audit logging.

AI Control Plane

The governance layer that sits between enterprise applications and AI models, deciding how AI traffic flows, which policies apply, and how to audit every interaction. Analogous to the control plane in networking. Smartflow is an AI control plane. AI control plane guide

AI Bill of Materials

An inventory of what an AI system is made of: models and versions, data sources, frameworks, prompts and the tools it can reach. Exists to answer one question fast — when something is compromised, what of ours is affected. Full definition

AI Firewall

A security component that inspects AI traffic in real-time to prevent prompt injection, data exfiltration, PII leakage, and toxic output. Unlike a traditional WAF, an AI firewall understands prompt semantics and model-specific attack vectors. Enterprise AI firewall guide

AI Guardrails

Controls that inspect what goes into a model and what comes back, and act on it. Distinct from model alignment, which cannot be versioned and produces no record an auditor can read. Full definition

AI Gateway

Infrastructure that sits between applications and LLM providers, providing routing, load balancing, failover, caching, and observability. Differs from a traditional API gateway because AI traffic requires semantic understanding and token-level metering. Enterprise AI gateway guide

AI Incident Response

Detecting, containing and reporting incidents involving AI systems. Has no signature to match, a wider containment blast radius than expected, and cannot be reconstructed unless the records were made at the time. Full definition

AI Governance

The policies, processes, and infrastructure that ensure AI systems operate within defined boundaries for security, compliance, cost, and performance. Spans policy documentation, enforcement, and audit.

AI Red Teaming

Adversarial testing to find what a system does under attack rather than in normal use. A result is a statement about a configuration on a date, not a property of the system. Full definition

AI Sovereignty

The principle that an organization maintains complete control over its AI infrastructure, including where AI traffic flows, how models are accessed, and where data resides. Requires on-premises or private cloud deployment. Full definition

Air-Gapped AI Deployment

A deployment in which the model, the control plane and the record of its decisions all run inside a network with no outbound path at request time. Distinct from on-premises and from private cloud, both of which may retain external dependencies. Full definition

AIDA (AI Agent Identity and Delegated Authority)

A cryptographic protocol developed by APERION that binds AI agents to human principals with exact action scopes, transaction limits, and account allowlists. Answers the question: who authorized this agent and did it stay within boundaries? AIDA agent identity guide

A2A (Agent-to-Agent Protocol)

A standardized protocol for AI agents to communicate and collaborate with other agents. Requires governance to ensure both agents are authorized and data exchange complies with policies. Full definition

Data Poisoning

Deliberate corruption of the data a model learns from. Enters through pre-training data, fine-tuning sets, feedback loops or retrieval corpora — and a runtime control bounds the consequence rather than detecting the cause. Full definition

Data Loss Prevention (DLP) for AI

Controls that prevent sensitive data from being transmitted to AI models through prompts or file uploads. AI-specific DLP requires semantic understanding of prompts, not just pattern matching. Full definition

EU AI Act

The European Union's comprehensive AI regulation, effective August 2025, classifying AI systems by risk level with requirements for high-risk systems including documentation, human oversight, and record-keeping. Applies extraterritorially. EU AI Act approach

FFIEC

The Federal Financial Institutions Examination Council, an interagency body that prescribes uniform examination standards. It does not regulate, its guidance does not carry the force of law, and it sunset the Cybersecurity Assessment Tool in August 2025 without a replacement. Full definition

FINRA Rule 3110

A FINRA rule requiring broker-dealers to maintain supervisory systems. In the AI context, requires supervision of AI-assisted communications, automated decision-making, and AI agent actions. Full definition

Human in the Loop

A design in which a person must act before the system proceeds. Distinct from human on the loop, where a person monitors and can intervene. The difference decides what an organization can claim about control. Full definition

Forward Deployed Engineer (FDE)

An APERION engineer who works embedded with a customer's team to configure Smartflow, integrate with identity providers, and optimize governance policies.

GLBA (Gramm-Leach-Bliley Act)

Governs how financial institutions handle nonpublic personal information, through privacy obligations and a data security mandate. Which rule applies depends on the institution: Interagency Guidelines for banks, the FTC Safeguards Rule for non-banks. Full definition

HIPAA Security Rule and AI

The Security Rule governs any AI system that creates, receives, maintains or transmits ePHI, under text unchanged since 2013. The January 2025 proposal to strengthen it has not been finalized, and OCR has issued no AI-specific guidance. Full definition

Indirect Prompt Injection

An attack where the instruction is planted in content the model retrieves and trusts — a document, a web page, a tool response. Nobody typed it, and no filter on the user’s prompt will see it. Full definition

ISO/IEC 42001

The certifiable international management system standard for AI, published December 2023. Annex B is normative, not informative — and it confers no presumption of conformity under the EU AI Act. Full definition

Information Barrier (Chinese Wall)

A governance control preventing the flow of material non-public information between business units. Smartflow enforces barriers at the AI gateway using group identity combined with real-time content classification. Full definition

Jailbreak

An input crafted to make a model disregard its own trained constraints. Targets the model, where a prompt injection targets the application — which decides who is able to fix it. Full definition

Kubernetes-Native

Software designed to run natively on Kubernetes, using pods, services, Helm charts for deployment and scaling. Smartflow deploys via Helm chart with cert-manager TLS validation.

MCP Security

Governing which MCP servers are permitted, which individual tools are enabled, what credential each call carries, and whether a call that bypasses the governed path fails rather than succeeds. Full definition

Maestro

Smartflow's policy engine and optimization console. Provides policy-as-code governance, A/B model routing, cost attribution, quality evaluation, and compliance enforcement from a single dashboard. Maestro

MCP (Model Context Protocol)

A standardized protocol enabling AI agents to invoke external tools. Each MCP tool invocation represents a data flow and permission decision requiring governance. Full definition

MITRE ATLAS

A public knowledge base of adversary tactics and techniques aimed at AI systems. Modeled after and complementary to ATT&CK, not part of it. Its 2026 releases are dominated by agentic techniques. Full definition

Model Allowlist and Deny-List

Which models a given team, application or agent may call, and which are forbidden regardless. The property that decides whether it holds is whether the list is evaluated before or after model rewrite. Full definition

MetaCache

Smartflow's four-phase semantic caching engine. Uses BERT-based semantic similarity matching to serve responses to semantically similar requests. Hit rates and token savings are workload-dependent.

Model Drift

Behavior changing with no change to the model as deployed. Data drift is the world moving; provider drift is the vendor changing the artifact underneath a model you already validated. Full definition

NIST AI RMF

Framework published by NIST providing guidelines for managing AI risks. Covers governance, mapping, measuring, and managing AI risk throughout the lifecycle. Full definition

NYDFS Part 500 (23 NYCRR 500)

The New York Department of Financial Services cybersecurity regulation — an enforceable rule rather than guidance. Every Second Amendment transitional deadline has now passed, the last on 1 November 2025. Its two AI letters impose no new requirements. Full definition

On-Premises Deployment

Running software within an organization's own data center or private cloud, ensuring data never leaves the organization's perimeter.

Policy-as-Code

Defining governance policies in machine-readable formats that can be version-controlled, tested, and automatically enforced. Smartflow's Maestro supports this with versioning and rollback. Full definition

Prompt Injection

An attack technique where malicious instructions are embedded in AI prompts to manipulate model behavior or extract sensitive information. Smartflow's AI firewall provides real-time detection and prevention. Full definition

Regulatory Examination Suite

Smartflow's capability to generate complete regulatory examination evidence packages with a single API call. Supports FINRA 3110, FFIEC, and EU AI Act. Examination readiness

Runtime Governance

Enforcement of AI policy at the moment a call is made, rather than documentation written beforehand or logs reviewed afterwards. Requires a position in the request path, versioned policy, and an identity for every caller including non-human ones. Full definition

Semantic Caching

A caching technique serving stored responses for queries that are semantically similar (not just identical). Uses embedding models to calculate cosine similarity between query vectors. Full definition

Shadow AI

The use of AI tools by employees outside sanctioned enterprise channels. Creates data security, compliance, and cost governance risks. Govern shadow AI

Smartflow

APERION's AI governance control plane. Sits inline between enterprise applications and AI providers, enforcing policy, governing agents, optimizing cost, and proving compliance. On-premises and Rust-based, with policy evaluated inline on the hop. Smartflow

Smartflow Halo

APERION's home agent firewall for self-hosted AI runtimes. A single binary runs on the machine hosting the agent, sits between that agent and its model providers, meters every call, enforces spend caps and a domain deny list, and reduces cost through the Smartflow cache stack. Users bring their own provider keys, held in the OS keychain. Distinct from Smartflow, which governs an organization's AI traffic from a control plane in the data center: Smartflow Halo answers for the agents on one machine and needs no deployment at all. Smartflow Halo

SR 11-7 and SR 26-2

The Federal Reserve's supervisory letter on model risk management, issued 2011. Superseded on 17 April 2026 by SR 26-2, which excludes generative and agentic AI from scope while requiring the institution's own governance to cover them. Often misattributed to the OCC, whose parallel document was Bulletin 2011-12. Full definition

Tamper-Evident Audit Log

A record constructed so that alteration after the fact is detectable, usually by chaining each entry to a hash of the one before. The difference between telemetry and evidence, and the reason a vendor retention ceiling is a governance constraint. Full definition

Tool Poisoning

An attack on the tool definitions an agent reads. A model treats descriptions as instructions, so text placed there executes rather than being displayed — including after approval was granted. Full definition

Virtual Key

A credential issued by Smartflow administrators that applications use to authenticate. Replaces direct API keys, keeping provider credentials server-side with per-user policy enforcement.

Zero-Knowledge Relay

An architecture where governance policies are enforced locally on the endpoint without the vendor having visibility into customer data. Used where the endpoint must enforce policy without the vendor gaining visibility into customer data.

Put this in the path of your own agents.

Policy enforced inline between your agents and every model and tool they reach, with a record bound to the human who owns it.

Request a Demo Read the docs