We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
Glossary

AI Security Glossary

Key terms and concepts in AI security, governance, and compliance — explained for practitioners.

All36
A6
B
C1
D6
E1
F
G3
H2
I2
J
K
L1
M2
N1
O2
P4
Q
R1
S4
T
U
V
W
X
Y
Z

Agent Communication Protocol (ACP)

Agent Communication Protocol (ACP) is a REST-based standard for AI agent interoperability. Learn how ACP relates to MCP, A2A, and enterprise AI governance.

Read definition

Agentic AI Risk

Agentic AI risk is the category of security threats arising when autonomous AI systems act without direct human oversight. A complete guide.

Read definition

AI Agent Security

AI agent security governs what autonomous AI systems can do, access, and act on at runtime. Learn the threat model, core controls, and how agent security differs from traditional application security.

Read definition

AI Firewall

An AI firewall is a policy enforcement layer that controls what AI models can access, generate, and act on at runtime. Learn how AI firewalls work and why enterprises need them.

Read definition

AI Governance

AI governance is the set of policies, controls, and audit mechanisms that define how organizations use AI responsibly and compliantly. A complete guide.

Read definition

Authorised Representative (EU AI Act)

An Authorised Representative under the EU AI Act is an EU-based person mandated in writing by a non-EU provider to carry out obligations for its AI system.

Read definition

Chief Information Security Officer (CISO)

A Chief Information Security Officer (CISO) is the executive accountable for an organization's security strategy. Learn the role, reporting lines, and AI governance duties.

Read definition

Data Loss Prevention (DLP)

Data Loss Prevention (DLP) is a set of controls that detect and stop sensitive data from leaving an organization. Learn how DLP works, where it falls short for AI, and how AI-era data protection extends it.

Read definition

Data Processing Agreement (DPA)

A Data Processing Agreement (DPA) is a GDPR-required contract between a controller and processor. Learn what a DPA must contain and why AI tools trigger one.

Read definition

Data Protection Officer (DPO)

A Data Protection Officer (DPO) is an independent role required under GDPR to oversee data protection compliance. Learn the DPO's tasks, independence, and AI duties.

Read definition

Deployer (EU AI Act)

A deployer under the EU AI Act is any organization using an AI system under its own authority. Learn the deployer's duties, how it differs from a provider, and more.

Read definition

Digital Operational Resilience Act (DORA)

The Digital Operational Resilience Act (DORA) is an EU regulation that sets a unified ICT risk framework for the financial sector. Learn its pillars and AI scope.

Read definition

Distributor (EU AI Act)

A Distributor under the EU AI Act is a supply-chain party — neither provider nor importer — that makes an AI system available on the EU market.

Read definition

EU AI Act (Artificial Intelligence Act)

The EU AI Act is the EU's risk-based law for artificial intelligence. A plain-language summary of what it regulates, when it applies, and who must comply.

Read definition

General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) is the EU law governing how personal data is processed. Learn its principles, rights, and what it means for AI.

Read definition

Governance, Risk & Compliance (GRC)

Governance, Risk, and Compliance (GRC) is an integrated approach to directing an organization, managing risk, and meeting obligations. Learn how GRC works and why AI needs it.

Read definition

GPAI (General-Purpose AI)

GPAI (general-purpose AI) in the EU AI Act: the Article 3(63) definition, Chapter V provider duties, systemic-risk models — and why GPAI is no risk tier.

Read definition

HIPAA

HIPAA (the Health Insurance Portability and Accountability Act) sets US rules for protecting health data. Learn its Privacy and Security Rules, Business Associate requirements, and AI implications.

Read definition

Human-in-the-Loop (HITL)

Human-in-the-Loop (HITL) is a design pattern where a human reviews, approves, or vetoes an AI system's actions before they take effect. Learn how HITL works.

Read definition

Identity & Access Management (IAM)

Identity and Access Management (IAM) is the discipline of ensuring the right identities have the right access to the right resources. Learn how IAM works and why AI agents break it.

Read definition

Importer (EU AI Act)

An Importer under the EU AI Act is an EU-based person that places on the market an AI system bearing a non-EU provider's name. Learn the role, test, and duties.

Read definition

LLM Security

LLM security is the practice of protecting large language models from adversarial attacks, data leakage, and unauthorized access in production.

Read definition

Mobile Device Management (MDM)

Mobile Device Management (MDM) lets organizations enroll, configure, secure, and remotely manage iOS and Android devices from a central console. Learn how MDM works and its AI limits.

Read definition

Model Context Protocol (MCP)

Model Context Protocol (MCP) is an open standard for connecting AI models and agents to external tools and data. Learn how MCP works and its security implications.

Read definition

NIST AI Risk Management Framework

The NIST AI Risk Management Framework (AI RMF) is a voluntary framework for managing AI risks and building trustworthy AI. Learn its four core functions and how to apply it.

Read definition

Operator (EU AI Act)

An operator is the EU AI Act's umbrella term for any party in the AI value chain: provider, product manufacturer, deployer, authorised representative, importer, or distributor.

Read definition

OWASP Top 10 for LLMs

The OWASP Top 10 for LLM Applications is a community-driven list of the most critical security risks in apps built on large language models. Learn the categories and mitigations.

Read definition

Personally Identifiable Information (PII)

Personally Identifiable Information (PII) is any data that can identify a person directly or indirectly. Learn how PII differs from GDPR personal data and why it matters for AI.

Read definition

Product Manufacturer (EU AI Act)

Under the EU AI Act, a product manufacturer that embeds a high-risk AI safety component in an own-branded product counts as the provider (Article 25(3)).

Read definition

Prompt Injection

Prompt injection is an AI security attack where malicious instructions embedded in data cause an LLM to follow attacker commands instead of its system prompt. Learn how attacks work and how to defend against them.

Read definition

Provider (EU AI Act)

A Provider under the EU AI Act develops an AI system or GPAI model and places it on the market under its own name. Learn the definition, test, and duties.

Read definition

Retrieval-Augmented Generation (RAG)

Retrieval-Augmented Generation (RAG) grounds LLM answers in retrieved documents. Learn how the RAG pipeline works, how it differs from fine-tuning, and its security risks.

Read definition

Security Information and Event Management (SIEM)

Security Information and Event Management (SIEM) aggregates and correlates logs across the IT estate for real-time alerting, investigation, and compliance.

Read definition

Shadow AI

Shadow AI is the use of AI tools by employees without IT, security, or compliance approval. Learn what counts as shadow AI, why it is a risk, and how to govern it.

Read definition

Single Sign-On (SSO)

Single Sign-On (SSO) lets users access many applications with one set of credentials via a central identity provider. Learn how SSO works, its risks, and its limits for AI.

Read definition

SOC 2

SOC 2 is an attestation report on a service organization's controls against the AICPA Trust Services Criteria. Learn how SOC 2 applies to AI governance, Type I vs Type II, and why auditors now assess AI tools and controls.

Read definition

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·