Glossary
AI governance, in plain language
Definitions of the terms that show up when boards, auditors, customers, and CFOs start asking about AI. Use them in your own policy and reports: that's the point.
Glossary / Index
- Agent (AI)
- An AI agent is a workflow or service that uses AI to perform tasks, potentially without a person approving each step. Its owner should define the allowed work, the required human reviews, and the controls available on the paths it uses.
- AI actor
- An AI actor is a person, app, or agent associated with AI activity in Tallin. An actor can have an accountable owner and related records. Gateway model scopes, budgets, and shutdown controls apply to the requests routed through keys bound to that actor.
- AI exposure assessment
- An AI exposure assessment reviews AI use, available evidence, ownership, and policy gaps within an agreed scope. The collection period, deliverables, and implementation plan depend on the engagement; an assessment is not a guarantee of complete visibility or compliance.
- AI governance program
- An AI governance program combines policies, ownership, technical controls, recurring reviews, and supporting evidence. Its scope and maturity depend on the organization's AI uses, available sources, obligations, and operating process.
- AI ledger
- An AI ledger brings AI usage and cost records together with their source, period, provider, and available ownership context. Tallin can draw on connected provider, Gateway, identity, and imported records. The evidence and cost basis remain attached to each record.
- AI policy
- An AI policy defines approved uses, data handling, responsibilities, review processes, and controls for an organization's AI activity. Some requirements can map to a supported technical control; others require a document, review, or owner decision.
- Board pack
- A board pack is an executive summary of AI spending, use, governance findings, open questions, and decisions. Tallin's report draws on available records and can include an administrator-reviewed AI draft. The audience and reporting period determine which details belong in the final report.
- Coverage score
- A coverage score is a percentage calculated against a defined population and evidence standard. It is interpretable only when the denominator, sources, period, and exclusions are stated. It should not imply that unknown AI activity has been measured.
- DDQ
- A DDQ (due diligence questionnaire) is a set of questions used to assess a vendor or business relationship. AI-related questions may cover approved uses, data handling, provider relationships, access, and review records. The requesting organization decides which evidence it requires.
- Enforced
- Enforced describes a configured control applied through a supported execution path. Tallin Gateway controls apply to routed requests. Provider and identity access actions have their own permissions, evidence, and scope; connection alone does not establish enforcement.
- EU AI Act
- The EU AI Act is a 2024 regulation phasing into effect through 2026 that requires companies operating in the EU to inventory AI systems, classify them by risk, and demonstrate appropriate governance for higher-risk uses. For mid-market SaaS companies, the relevant articles typically map to general-purpose AI deployment, transparency, and the documentation requirements that operationalize them.
- Gateway enforcement
- Gateway enforcement is the policy-application step that runs at request time when an AI actor's traffic flows through a routed gateway. Per-actor budget caps, model-tier and provider allow-lists, rate limits, and the kill switch are checked at the gateway, applied while the request is happening and producing audit-grade evidence that a policy was actually enforced, not just written.
- Honest coverage
- Honest coverage is Tallin's term for keeping direct observations, inferred conclusions, applied controls, and missing coverage distinct. A record should explain its source and scope so readers can judge what it supports.
- Inferred
- Inferred describes a conclusion drawn from supporting signals rather than directly established by the source. An expense record may establish a purchase while only suggesting AI use. The underlying observation and the inference should remain separate.
- ISO 42001
- ISO 42001 is the international management-system standard for AI, published in late 2023, that gives companies a certifiable framework for AI governance program design and evidence. Certification is rare in mid-market today but increasingly cited in enterprise customer DDQs and bank-partner questionnaires.
- Kill switch
- A kill switch disables new model requests through Tallin Gateway keys bound to an actor, with a record of the action. It does not stop direct provider calls outside the Gateway, undo completed actions, or halt tool and MCP side effects outside that control path. Direct provider activity may still be observed through a connected API.
- NIST AI RMF
- The NIST AI Risk Management Framework is a voluntary US-government framework published in January 2023 that organizes AI risk-management activities into Govern, Map, Measure, and Manage functions. Many US mid-market AI policies cite NIST AI RMF as their foundation; auditors increasingly expect the cited framework to map to actual practice.
- Not covered
- Not covered identifies activity or actions for which no configured source or control supplies the relevant coverage. Missing Gateway routing does not imply missing observation: connected provider APIs may still supply records. Unmanaged surfaces and external tool actions need their own source and control assessment.
- Observed
- Observed describes a fact captured directly from a connected source, such as a Gateway event, provider usage record, or managed-browser hostname observation. The source determines what is established. A hostname observation does not establish prompt content or which provider account was active.
- Shadow AI
- Shadow AI is the AI activity happening inside a company without IT or security visibility: personal ChatGPT accounts, embedded AI features in approved SaaS, AI subscriptions on personal cards. Shadow AI is the gap a credible AI governance program names and shrinks, not one it claims to have already eliminated. (Not to be confused with shadow mode, a Tallin policy-simulation setting.)
- Shadow mode
- Shadow mode is the Tallin setting that evaluates a policy against an AI actor's real traffic and records what would have been blocked, without blocking the request. Turn it on for a new agent to see what it would have violated before enforcement is live, then switch to enforcement mode once the rules are right, so a control is never flipped on blind.
- SOC 2 AI controls
- SOC 2 AI controls are the emerging set of control criteria SOC 2 auditors are using to evaluate how AI tools handle confidential data, even when the SOC 2 framework itself doesn't yet formally require it. Auditors typically probe whether the AI policy is enforced, whether usage is logged, and whether data classes have been classified for AI exposure.
Also: AI agent · Autonomous agent · Agent actor
See also: AI actor · Kill switch · Shadow mode · Gateway enforcement
Also: AI identity · AI consumer
See also: Agent (AI) · Kill switch · AI ledger · Enforced
Also: AI risk assessment
See also: AI ledger · Honest coverage · Shadow AI
See also: AI policy · AI actor · Board pack
Also: AI usage ledger · AI spend ledger
See also: AI actor · Honest coverage · Observed · Inferred
See also: AI actor · Enforced · Gateway enforcement · AI governance program
Also: AI board report
See also: AI actor · AI ledger · DDQ · Honest coverage
See also: Observed · Inferred · Not covered
Also: Due diligence questionnaire · customer DDQ
See also: Board pack · AI policy · Honest coverage
See also: Honest coverage · Observed · Gateway enforcement · Kill switch
See also: NIST AI RMF · ISO 42001 · AI governance program
See also: Enforced · AI actor · Kill switch · Shadow mode · AI policy
See also: Observed · Inferred · Enforced · Not covered
See also: Honest coverage · Observed · Shadow AI
See also: NIST AI RMF · EU AI Act · AI governance program
Also: Model-access kill switch · Disable actor · AI off switch
See also: AI actor · Agent (AI) · Enforced · Not covered
Also: NIST AI Risk Management Framework
See also: Honest coverage · Shadow AI · Coverage score · Kill switch
See also: Honest coverage · Inferred · AI ledger
Also: Shadow AI usage · Unsanctioned AI
See also: Not covered · AI exposure assessment · Inferred · Shadow mode
Also: Policy simulation · Dry-run policy · Would-block mode
See also: AI actor · Agent (AI) · Enforced · Gateway enforcement
See also: DDQ · AI policy · Honest coverage
Want these terms backed by real evidence?
Tallin turns the definitions on this page into measurable signals: observed, inferred, enforced, not covered, across your company's actual AI usage.