OptimaTrust

Glossary

Say AI assurance when you mean AI assurance.

Definitions this site uses so buyers, auditors, and assistants share the same language.

AI assurance

Independent, evidence-backed confidence that an AI system is the one you think it is, behaves within bounds, and can be shown to others.

AI governance

Accountability structures for AI — roles, policies, and decisions. Necessary, but not a substitute for testing the system.

Shadow AI

AI systems in use without a registered owner, intended use, or assurance record.

Agentic AI

Systems that plan, call tools, write memory, and loop toward a goal.

Model Context Protocol (MCP)

A protocol for exposing tools, resources, and prompts to models and agents.

AI bill of materials (AI BOM)

A point-in-time list of models, data, tools, and vendors that compose an AI system.

Explainable assurance score

A 0–100 score with named dimensions and listed deductions — not a mysterious trust badge.

EU AI Act

The European Union’s regulation on AI systems, with obligations that depend on use-case class.

ISO/IEC 42001

The AI management system standard.

NIST AI RMF

US National Institute of Standards and Technology AI Risk Management Framework: Govern, Map, Measure, Manage.

Prompt injection

An attack that causes a model or agent to follow hostile instructions inside content or tools.

Retrieval-augmented generation (RAG)

A pattern that retrieves documents or vectors before the model answers.

AI red teaming

Adversarial testing of models and agents to find harmful or insecure behavior.

Runtime enforcement

Blocking or allowing model/agent actions in the live request path.

AI assurance vs GRC

Assurance tests and evidences AI systems. GRC runs enterprise control programs.