Glossary

AI governance, in plain language

Definitions of the terms that show up when boards, auditors, customers, and CFOs start asking about AI. Use them in your own policy and reports: that's the point.

Glossary / Index

Agent (AI)

Also: AI agent · Autonomous agent · Agent actor

An AI agent is a workflow or service that uses AI to perform tasks, potentially without a person approving each step. Its owner should define the allowed work, the required human reviews, and the controls available on the paths it uses.

See also: AI actor · Kill switch · Shadow mode · Gateway enforcement

AI actor

Also: AI identity · AI consumer

An AI actor is a person, app, or agent associated with AI activity in Tallin. An actor can have an accountable owner and related records. Gateway model scopes, budgets, and shutdown controls apply to the requests routed through keys bound to that actor.

See also: Agent (AI) · Kill switch · AI ledger · Enforced

AI exposure assessment

Also: AI risk assessment

An AI exposure assessment reviews AI use, available evidence, ownership, and policy gaps within an agreed scope. The collection period, deliverables, and implementation plan depend on the engagement; an assessment is not a guarantee of complete visibility or compliance.

See also: AI ledger · Honest coverage · Shadow AI

AI governance program
An AI governance program combines policies, ownership, technical controls, recurring reviews, and supporting evidence. Its scope and maturity depend on the organization's AI uses, available sources, obligations, and operating process.

See also: AI policy · AI actor · Board pack

AI ledger

Also: AI usage ledger · AI spend ledger

An AI ledger brings AI usage and cost records together with their source, period, provider, and available ownership context. Tallin can draw on connected provider, Gateway, identity, and imported records. The evidence and cost basis remain attached to each record.

See also: AI actor · Honest coverage · Observed · Inferred

AI policy
An AI policy defines approved uses, data handling, responsibilities, review processes, and controls for an organization's AI activity. Some requirements can map to a supported technical control; others require a document, review, or owner decision.

See also: AI actor · Enforced · Gateway enforcement · AI governance program

Board pack

Also: AI board report

A board pack is an executive summary of AI spending, use, governance findings, open questions, and decisions. Tallin's report draws on available records and can include an administrator-reviewed AI draft. The audience and reporting period determine which details belong in the final report.

See also: AI actor · AI ledger · DDQ · Honest coverage

Coverage score
A coverage score is a percentage calculated against a defined population and evidence standard. It is interpretable only when the denominator, sources, period, and exclusions are stated. It should not imply that unknown AI activity has been measured.

See also: Observed · Inferred · Not covered

DDQ

Also: Due diligence questionnaire · customer DDQ

A DDQ (due diligence questionnaire) is a set of questions used to assess a vendor or business relationship. AI-related questions may cover approved uses, data handling, provider relationships, access, and review records. The requesting organization decides which evidence it requires.

See also: Board pack · AI policy · Honest coverage

Enforced
Enforced describes a configured control applied through a supported execution path. Tallin Gateway controls apply to routed requests. Provider and identity access actions have their own permissions, evidence, and scope; connection alone does not establish enforcement.

See also: Honest coverage · Observed · Gateway enforcement · Kill switch

EU AI Act
The EU AI Act is a 2024 regulation phasing into effect through 2026 that requires companies operating in the EU to inventory AI systems, classify them by risk, and demonstrate appropriate governance for higher-risk uses. For mid-market SaaS companies, the relevant articles typically map to general-purpose AI deployment, transparency, and the documentation requirements that operationalize them.

See also: NIST AI RMF · ISO 42001 · AI governance program

Gateway enforcement
Gateway enforcement is the policy-application step that runs at request time when an AI actor's traffic flows through a routed gateway. Per-actor budget caps, model-tier and provider allow-lists, rate limits, and the kill switch are checked at the gateway, applied while the request is happening and producing audit-grade evidence that a policy was actually enforced, not just written.

See also: Enforced · AI actor · Kill switch · Shadow mode · AI policy

Honest coverage
Honest coverage is Tallin's term for keeping direct observations, inferred conclusions, applied controls, and missing coverage distinct. A record should explain its source and scope so readers can judge what it supports.

See also: Observed · Inferred · Enforced · Not covered

Inferred
Inferred describes a conclusion drawn from supporting signals rather than directly established by the source. An expense record may establish a purchase while only suggesting AI use. The underlying observation and the inference should remain separate.

See also: Honest coverage · Observed · Shadow AI

ISO 42001
ISO 42001 is the international management-system standard for AI, published in late 2023, that gives companies a certifiable framework for AI governance program design and evidence. Certification is rare in mid-market today but increasingly cited in enterprise customer DDQs and bank-partner questionnaires.

See also: NIST AI RMF · EU AI Act · AI governance program

Kill switch

Also: Model-access kill switch · Disable actor · AI off switch

A kill switch disables new model requests through Tallin Gateway keys bound to an actor, with a record of the action. It does not stop direct provider calls outside the Gateway, undo completed actions, or halt tool and MCP side effects outside that control path. Direct provider activity may still be observed through a connected API.

See also: AI actor · Agent (AI) · Enforced · Not covered

NIST AI RMF

Also: NIST AI Risk Management Framework

The NIST AI Risk Management Framework is a voluntary US-government framework published in January 2023 that organizes AI risk-management activities into Govern, Map, Measure, and Manage functions. Many US mid-market AI policies cite NIST AI RMF as their foundation; auditors increasingly expect the cited framework to map to actual practice.

See also: EU AI Act · ISO 42001 · AI policy

Not covered
Not covered identifies activity or actions for which no configured source or control supplies the relevant coverage. Missing Gateway routing does not imply missing observation: connected provider APIs may still supply records. Unmanaged surfaces and external tool actions need their own source and control assessment.

See also: Honest coverage · Shadow AI · Coverage score · Kill switch

Observed
Observed describes a fact captured directly from a connected source, such as a Gateway event, provider usage record, or managed-browser hostname observation. The source determines what is established. A hostname observation does not establish prompt content or which provider account was active.

See also: Honest coverage · Inferred · AI ledger

Shadow AI

Also: Shadow AI usage · Unsanctioned AI

Shadow AI is the AI activity happening inside a company without IT or security visibility: personal ChatGPT accounts, embedded AI features in approved SaaS, AI subscriptions on personal cards. Shadow AI is the gap a credible AI governance program names and shrinks, not one it claims to have already eliminated. (Not to be confused with shadow mode, a Tallin policy-simulation setting.)

See also: Not covered · AI exposure assessment · Inferred · Shadow mode

Shadow mode

Also: Policy simulation · Dry-run policy · Would-block mode

Shadow mode is the Tallin setting that evaluates a policy against an AI actor's real traffic and records what would have been blocked, without blocking the request. Turn it on for a new agent to see what it would have violated before enforcement is live, then switch to enforcement mode once the rules are right, so a control is never flipped on blind.

See also: AI actor · Agent (AI) · Enforced · Gateway enforcement

SOC 2 AI controls
SOC 2 AI controls are the emerging set of control criteria SOC 2 auditors are using to evaluate how AI tools handle confidential data, even when the SOC 2 framework itself doesn't yet formally require it. Auditors typically probe whether the AI policy is enforced, whether usage is logged, and whether data classes have been classified for AI exposure.

See also: DDQ · AI policy · Honest coverage

Want these terms backed by real evidence?

Tallin turns the definitions on this page into measurable signals: observed, inferred, enforced, not covered, across your company's actual AI usage.

AI governance glossary | Tallin