Join our Newsletter — 33% off our NHI Course
Home› Guides› Agentic AI Glossary
Glossary Agentic AI Security

Agentic AI Glossary

← All guides
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 16 min read
On this page

Agentic AI has brought a wave of new terms, and many are used loosely or inconsistently. This glossary gives short, precise definitions of the terms that matter for identity, access and security in agentic AI, written for IAM practitioners, security architects and risk teams. Where a term is defined by a standard or specification, we say which. Terms link to our detailed guides where relevant.

A

Agent (AI agent)
An agent is software that can take an open-ended task, decide which tools to use, and act across multiple steps without a fixed script for every branch. In identity and security terms, the key issue is that an agent can change state in real systems, so its permissions and boundaries must be tightly governed. See AI Agents vs Agentic AI.
Agent Card
An Agent Card is a machine-readable description of an agent’s capabilities, endpoint, and invocation details. In A2A-style systems it helps other agents discover and call the agent at runtime, which makes the card a governance object as much as a technical descriptor. See the Multi-Agent and A2A Security Guide.
Agent hijacking
Agent hijacking is the repurposing of an AI agent or agent runtime by an attacker for their own activity. The original owner may lose visibility into the session while the system continues executing tasks, scanning targets, or chaining actions on behalf of the adversary. See the Agentic AI Security Guide.
Agent identity
An agent identity is the set of attributes, credentials and permissions assigned to an autonomous software entity. It is treated as a non-human identity because it can authenticate, act on systems and accumulate access over time, which creates governance, audit and lifecycle obligations similar to other production identities. See the Agentic AI Identity Guide.
Agent registry
An agent registry is a central catalog of sanctioned and shadow AI agents, including their identities, permissions, and lifecycle state. Its value depends on whether it feeds broader governance, because a registry without telemetry, ownership, and offboarding can become another silo. See the Agentic AI Identity Guide.
Agent sprawl
Agent sprawl is the uncontrolled growth of AI agents, scripts, and automation identities across teams and environments. It creates governance strain because each agent can introduce its own permissions, secrets, and ownership gaps, making revocation, review, and accountability harder to sustain. See the Shadow AI Discovery Guide.
Agent2Agent (A2A)
A2A, or agent-to-agent communication, describes interactions where one AI agent delegates work to another agent. These flows can be stateful, multi-step, and policy sensitive, so organisations need authentication, tracing, and guardrails to prevent uncontrolled delegation, unsafe data sharing, and opaque decision chains. See the Multi-Agent and A2A Security Guide.
Agentic AI
Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services. See AI Agents vs Agentic AI.
Agentic commerce
Agentic commerce is a buying and transaction model where software agents act on behalf of a person. The identity challenge is not just proving who owns the account, but constraining what the agent may do, for how long, and under what revocation and audit rules. See the Agentic Commerce Identity Guide.
AI-BOM (AI bill of materials)
An AI bill of materials is a structured inventory of the components that define an AI agent, including the model, prompt, tools, retrieval sources, and dependencies. In practice, it is the evidence base for review, change control, and risk assessment when the agent evolves after deployment. See the AI Supply Chain and AI-BOM Guide.
AI gateway
A control point that sits between AI applications and the models, tools, or data they call. In practice, it can authenticate requests, enforce policy, inspect runtime behaviour, and stop unsafe actions before they spread into connected systems. See the LLMjacking Guide.
AI red teaming
AI red teaming is the practice of simulating hostile behaviour against models, applications, and agents to expose weaknesses before real attackers do. In AI programmes, it is most useful when results can be turned into controls, monitoring, and governance evidence rather than left as a one-time test report. See Red Teaming AI Agents for Identity Abuse.
AI-SPM (AI security posture management)
AI Security Posture Management extends security visibility into AI models, prompts, outputs, and supporting workflows. It gives teams a way to identify risky AI usage, check policy alignment, and monitor how AI systems interact with data and identity controls over time. See the AI Security Platform Buyer's Guide.
Attestation
Attestation is verifiable evidence about a workload’s execution context, such as where it is running, who started it, and whether it matches policy. In agent governance, attestation can be used to bootstrap enrollment and to justify access decisions that need to change as the workload behaves differently. See the NHI Authentication Guide.
Autonomy level
A measure of how independently an AI agent can decide, select tools, and execute actions. In practice, autonomy level determines how much approval, monitoring, and rollback capability the organisation needs before the agent is allowed to touch business systems. See the AI Agent Authorisation Guide.

B–D

Browser agent
A browser agent is software that can navigate websites and complete browser-based tasks on behalf of a person or system. In identity terms, it is an execution identity that may inherit access, session state, and trust boundaries that were previously assumed to belong only to humans. See the Browser and Computer-Use Agent Guide.
CIBA (Client-Initiated Backchannel Authentication)
CIBA is a backchannel approval pattern for situations where the user is not in a browser at the point of decision. In identity programmes, it gives teams a way to capture out-of-band approval for sensitive actions without forcing the agent or application to fake a normal interactive login flow. See the OAuth 2.0 and OpenID Connect Guide.
Coding agent
A coding agent is a software system that can plan, generate, and modify code with limited human prompting. In governance terms, it is not just a tool but an actor whose permissions, tool access, and rollback path must be managed as part of the delivery process. See the AI Coding Agents Security Guide.
Computer-use agent
An AI system that can observe a user interface and take actions across software on behalf of a task. In practice, it extends identity governance beyond API access because the agent can navigate live applications, combine steps, and adapt to changing state during the session. See the Browser and Computer-Use Agent Guide.
Confused deputy
A confused deputy is a privileged system that is tricked into performing an action on behalf of an untrusted requester. In agentic AI, the agent may misread malicious input as legitimate intent and then use its own authority to act, which turns a logic problem into a security incident. See the MCP Security Guide.
Context window
The context window is the text a model receives at one time, including prompts, retrieved documents, and conversation history. Security teams care about it because it becomes the practical boundary between trusted instructions and untrusted content, especially when the application assembles that text automatically. See the AI Agent Memory Security Guide.
Delegation (on-behalf-of)
A token or session pattern where one identity acts for another while preserving evidence of delegation. For agents, the value is not just access propagation. It is the ability to show that the action was performed under a specific authority and within a specific scope. See the AI Agent Authorisation Guide.
Delegation chain
A delegation chain is the sequence of identities, credentials, and tool calls an agent uses to complete a task across systems. It matters because each step may appear acceptable on its own while the combined path produces an outcome no reviewer would have approved directly. See the Multi-Agent and A2A Security Guide.
DPoP (Demonstrating Proof of Possession)
Demonstrating Proof of Possession is an HTTP-layer method that attaches a signed proof to each request. The proof ties the token to a client-held key and to the specific request details, which makes replay harder even when TLS terminates at gateways or proxies. It suits browsers and mobile clients better than transport-bound methods. See the Token and Session Security Guide.

E–H

Excessive agency
A condition where an AI system is given more operational authority than its task requires. The risk is not just poor output. It is that mistakes, manipulation, or compromise can produce destructive actions at machine speed across the systems the agent can reach. See Top 10 Agentic AI Identity Issues.
Goal hijack
A failure mode where an agent is steered away from its approved objective and begins pursuing a different one, often through manipulated inputs or chained context. For autonomous or semi-autonomous systems, the risk is not only misuse of a tool but the redefinition of the mission itself. See the OWASP Agentic Applications Top 10 guide.
Guardrail
Guardrails are policy controls that inspect prompts and model outputs against defined safety, privacy, and compliance rules. In AI operations, they reduce harmful language and disclosure risk, but they do not replace entitlement management, logging, or identity governance for the systems that call the model. See the AI Security Platform Buyer's Guide.
Human-in-the-loop (HITL)
A governance pattern requiring human approval before an AI agent takes high-impact, irreversible, or out-of-scope actions. HITL is a critical control for agentic AI identity governance. See the AI Agent Authorisation Guide.

I–L

Indirect prompt injection
Indirect prompt injection is an attack where malicious instructions are hidden inside content that an AI system reads later. The model may treat that content as context rather than as hostile input, which can influence tool use, data access, or workflow actions if controls are weak. See How to Prevent Prompt Injection in AI Agents.
Just-in-time (JIT) access
A security approach that grants access permissions only for the duration needed to complete a specific task, then automatically revokes them. JIT access eliminates standing privileges for NHIs, dramatically reducing attack surface. See the JIT Access Guide.
Kill switch
A kill switch is an emergency control used to stop an autonomous system from taking further action. In security practice, it is a containment mechanism, not a governance strategy, because it does not prevent prior overreach or replace least-privilege design. See the AI Agent Observability and Incident Response Guide.
Least agency
The agentic equivalent of least privilege, the principle that AI agents should be granted only the minimum level of autonomy necessary to complete their designated task, and no more. Coined in the OWASP Top 10 for Agentic Applications 2026. See the AI Agent Authorisation Guide.
LLM firewall
A control layer that inspects or governs prompts, responses, plugin use, and API calls around a large language model. It aims to manage data movement within the AI interaction itself, not only at the surrounding endpoint or SaaS boundary. See the AI Security Platform Buyer's Guide.
LLMjacking
Abuse of cloud AI services through stolen machine credentials rather than human user accounts. The attacker uses valid non-human identities such as API keys or tokens to enumerate model access, invoke endpoints, and create cost, data, or policy exposure under the victim's tenancy. See the LLMjacking Guide.

M

MCP client
An MCP client is the application or agent that connects to a Model Context Protocol server to request tools, data, or prompts. It manages the session, sends structured requests, and receives responses in a standard format. In identity terms, it is the calling party that may need authentication, authorization, and audit controls. See the MCP Security Guide.
MCP gateway
The control layer that relays assistant intent to tools and data sources through the Model Context Protocol. In practice, it becomes a policy boundary, not just a transport layer. If it trusts model output too early, it can turn unverified reasoning into real-world execution or disclosure. See the MCP Security Guide.
MCP server
An MCP server is a tool endpoint that connects an AI agent to external systems and data sources through Model Context Protocol. Because it extends what the agent can reach, it becomes part of the identity and access surface and must be reviewed like any other privileged connector. See the MCP Security Guide.
Memory poisoning
An attack where malicious content is injected into an AI agent's memory or context, causing it to alter its behaviour in subsequent tasks, potentially exfiltrating secrets, escalating privileges, or acting against its intended purpose. See the AI Agent Memory Security Guide.
Model Context Protocol (MCP)
Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources. It expands what an agent can reach, so governance has to cover not only the model and its prompts, but also every system that can receive or return agent-driven data. See the MCP Security Guide.
Multi-agent system
An environment in which multiple autonomous AI agents interact, collaborate, and delegate tasks. MAS dramatically increases NHI complexity, each agent requires a managed identity, and a single compromise can propagate across the entire mesh. See the Multi-Agent and A2A Security Guide.

N–P

Non-human identity (NHI)
A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times. See The Ultimate Guide to NHIs.
Orchestrator
The control plane that routes messages, stores workflow state, and manages tool access across multiple AI agents. Because it concentrates delegation and logging in one place, it becomes the highest-value identity surface in the system and needs privileged-service treatment, not ordinary application handling. See the Multi-Agent and A2A Security Guide.
Permission-aware retrieval
Permission-aware retrieval is the practice of enforcing access control before data reaches the model. It ensures the model only sees documents, records, or context that the requesting identity is allowed to access. In multi-tenant or sensitive environments, this control is more important than post-processing filters. See the Permission-Aware RAG Guide.
Policy enforcement point (PEP) / policy decision point (PDP)
A policy enforcement point is the control that applies an authorization decision at the place where an action occurs. In distributed systems, it may sit inside an API gateway, application, or workflow engine, and it depends on a consistent decision format to avoid bespoke integrations. See the Authorisation Models Guide.
Principal
The user or system on whose behalf an agent acts. See the Agentic AI Identity Guide.
Prompt injection
LLM prompt injection is an attack that uses crafted input to override or redirect a model's intended behaviour. It becomes dangerous when the model can call tools, access data, or trigger actions, because the injected instruction can turn into a real operational change. See How to Prevent Prompt Injection in AI Agents.

R–S

RAG (retrieval-augmented generation)
Retrieval-augmented generation is a pattern where a model queries external content before answering. In security terms, it creates a second control plane that can widen exposure if retrieval scope, source trust, and output filtering are not tightly governed. See the Permission-Aware RAG Guide.
Rogue agent
An AI agent that has been compromised, manipulated, or misaligned and now operates outside its intended purpose, potentially exfiltrating data, escalating privileges, or sabotaging systems, while appearing superficially legitimate. See the AI Agent Observability and Incident Response Guide.
Sender-constrained token
A sender-constrained token is tied to a specific client or cryptographic proof, rather than being usable by anyone who steals it. This reduces replay risk and is especially important where tokens can reach automation, services, or agents with broad API access. See the Token and Session Security Guide.
Shadow agent
An AI agent deployed without formal registration, identity governance, or security oversight, the agentic equivalent of shadow IT. Shadow agents are more dangerous than typical shadow NHIs because they actively take actions using their credentials. See the Shadow AI Discovery Guide.
Shadow AI
AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources. See the Shadow AI Discovery Guide.
SPIFFE
Secure Production Identity Framework for Everyone (SPIFFE) and its reference implementation SPIRE, an open standard for providing cryptographic identities to workloads in dynamic cloud environments without relying on network location. See the Guide to SPIFFE and SPIRE.

T–Z

Task-scoped access
Task-scoped access is permission granted for one defined purpose and removed once the task is complete or the session expires. For non-human identities, it reduces standing privilege and limits how long an attacker can exploit a stolen credential. See the AI Agent Authorisation Guide.
Token exchange
Token exchange is an OAuth pattern that swaps one credential or token for another with narrower scope or different trust context. In NHI governance, it is useful when a workload must cross boundaries without carrying broad, reusable privileges into downstream systems. See the Agentic AI Identity Guide.
Token passthrough
Token passthrough is the practice of forwarding an authentication token through intermediaries instead of validating it at each trust boundary. In MCP this is prohibited because it prevents the server from proving who is actually authorised to act. The result is weaker accountability and a larger attack surface for stolen or replayed credentials. See the MCP Security Guide.
Tool
A tool is an MCP-exposed action that the model can choose to call at runtime. It is the equivalent of an executable privilege boundary, because its name, description, and schema influence what the agent believes it may do and what backend actions it can trigger. See the MCP Security Guide.
Tool misuse
Tool misuse occurs when an agent uses an allowed integration in a way that exceeds its intended task, scope, or risk tolerance. The problem is often not access alone but the combination of valid credentials, broad permissions, and unbounded action sequencing. See the Agentic AI Security Guide.
Tool poisoning
Tool poisoning is an attack in which malicious instructions are hidden inside tool descriptions, examples, or schemas that an AI agent reads when deciding what to do. The danger is not only in the tool's code, but in the metadata that shapes the agent's behaviour and trust decisions. See the MCP Security Guide.
Workload identity federation
A mechanism allowing workloads in one environment to authenticate to another using short-lived tokens rather than stored credentials, based on mutual trust between identity providers. See the Cloud Workload Identity Guide.
Zero standing privilege
A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access. See the JIT Access Guide.

For identity, IAM and non-human identity terms, see the NHI and IAM Glossary, and for the wider vocabulary the NHI Mgmt Group Glossary. Related resources: Top 10 Agentic AI Identity Issues · Agent Identity Standards Tracker · Agentic AI Security Guide

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org