- AI agent
- An AI system that pursues goals by taking actions, calling tools, querying systems, communicating, rather than only generating content for a human to act on.
- MCP (Model Context Protocol)
- An open protocol through which AI models connect to tools, data sources and services; a widely adopted connective layer for agentic deployments.
- A2A (Agent2Agent)
- An open protocol for communication between agents, governed by the Linux Foundation since 2025.
- Tool call
- A single action an agent takes against an external system: run a query, send a message, write a file. The atomic unit of agent behaviour, and of agent audit.
- Prompt injection
- An attack in which instructions hidden in content the agent reads override the operator’s instructions. The signature vulnerability of systems that treat all text as potential instruction.
- Excessive agency
- An agent holding more authority (permissions, spend, autonomy) than its task requires, multiplying the impact of any error or manipulation.
- Vibe coding
- Building software by describing it to a model in plain language. The output is real, running code, produced without a traditional development process.
- End-user computing (EUC)
- Business-critical logic built and run outside IT by the people who use it. The term dates from the spreadsheet era.
- Assurance
- Independent, evidence-based confidence that a system meets a defined standard, distinct from the vendor’s own claims and from insurance, which transfers the residual risk assurance cannot remove.
- Conformance
- The demonstrated state of meeting a framework’s controls, ideally evidenced continuously rather than at an annual audit.
- Continuous assurance
- Monitoring that streams evidence against a control framework in real time, the agentic-era successor to point-in-time certification.
- MGA / coverholder
- A managing general agent: an underwriting business that prices and writes policies with delegated authority, renting balance sheet from insurers or reinsurers. The dominant structure in the young AI insurance market.
- Affirmative AI cover
- Insurance that explicitly covers AI-related failures, as opposed to "silent" cover, the ambiguous position of older policies that neither name nor exclude AI.