H0 direct answers on AI security and AI governance, each with how Govern360 handles it.">
Glossary

Enterprise AI governance, defined.

29 terms used across AI governance, agent security and AI exposure — each with a definition that stands on its own, what it is commonly confused with, and how Govern360 treats it.

Last reviewed 2026-09-27 · Govern360 Research · 29 terms

The category

#AI Exposure Management

AI Exposure Management is the practice of continuously discovering, governing, protecting, controlling and proving an organisation’s entire AI estate, and measuring its exposure to AI risk as a single explainable score. It treats ungoverned AI the way attack surface management treats ungoverned infrastructure: as a measurable, reducible exposure rather than a once-a-year audit. The distinction from AI governance is continuity and breadth - governance asks whether rules exist, exposure management asks how exposed the organisation is right now and whether that is improving.

Govern360 is the control plane for it, across five dimensions: Discover, Govern, Protect, Control and Prove.

AI Exposure Management

#AI governance

AI governance is the practice of knowing which AI systems an organisation operates, who is accountable for each, what each is permitted to do, and being able to evidence that this is true. It is distinct from AI ethics, which concerns what should be built, and from AI safety, which concerns model behaviour. Governance is the operational layer: inventory, ownership, permission, review and evidence.

Govern360 treats governance as one of five scored dimensions rather than the whole discipline, weighted at 20% of the AI Exposure Score.

How governance works

#AI governance platform

An AI governance platform is the system of record for every AI system an organisation operates, holding what exists, who is accountable, what each may do, and the evidence that this is true. The property that separates a platform from a register is the source of the inventory. If the system depends on teams declaring what they built, it is stale from the first week. If it reads the estate from the platforms AI is built in, it stays true between reviews.

Govern360 reads from platform control planes and compiles decisions back into the enforcement planes already in place.

AI governance platform

#AI-SPM (AI security posture management)

AI security posture management, or AI-SPM, is the security-configuration view of an AI estate: which AI systems exist, how they are configured, and where the misconfigurations are. It applies the shape of cloud security posture management to AI. Governance is the larger frame around it, adding ownership, purpose, approval, cost and evidence - the questions a regulator or a board asks, which a posture tool alone does not hold.

Govern360 covers posture as one part of a governance control plane, which is why each record carries owner, purpose and cost beside the security attributes.

AI-SPM

#AI control plane

An AI control plane is a layer that decides AI policy centrally and pushes it into the systems that enforce it, rather than enforcing policy itself. The separation is the same one networking makes between policy and enforcement, and it matters operationally: a control plane can be added to an estate without becoming a dependency in the data path, so an outage degrades governance rather than stopping work.

Govern360 is a control plane in exactly that sense, and marks each enforcement plane verified, compiled or planned according to what has actually been confirmed.

The architecture

Measurement

#AI Exposure Score

An AI exposure score is a single measure of how governed and how exposed an AI estate is, decomposed into dimensions so the number is actionable rather than decorative. Two properties decide whether such a score is an instrument or a grade: whether it is computed from measured facts rather than self-assessment, and whether every point can be traced back to the finding that produced it.

The Govern360 AI Exposure Score is a weighted geometric mean of AI Discovery (25%), Protection (25%), Governance (20%), Control (15%) and Compliance (15%), published with the share of the estate it rests on and traceable from score to dimension to module to finding to task.

The AI Exposure Score

#Not measured

Not measured is the state of a control or domain for which no signal is available, and which is therefore excluded from a score rather than counted as zero. The two common alternatives are both wrong. Scoring an unmeasured control as zero publishes a worse number than the evidence supports and teaches people to distrust the score; dropping it silently publishes a better one and hides the gap. The defensible treatment is to exclude it, state that it was excluded, and show what connecting a source would change.

Govern360 labels these domains ’not measured - earns nothing’, draws them dashed on the derivation map, and redistributes the weight across the domains that were measured.

How the score is built

#Evidence states: configured, declared, observed, verified, compiled

Evidence states are labels that record how a fact about an AI estate is known: configured means read from a configuration, declared means asserted by a person, observed means seen in telemetry, verified means read back from the enforcing platform, and compiled means emitted to a platform that exposes no read path. The distinction that matters most is applied versus verified. Applied means the instruction was sent; verified means the destination confirmed it holds that state. A dashboard showing both as green is asserting something it has not checked.

Govern360 reserves verified for a platform read-back of live state, and there are no false greens anywhere in the product.

How evidence works

#Stale evidence decay

Stale evidence decay is the reduction of a governance score when the evidence underlying a control has aged beyond its review period. A control verified eight months ago and never rechecked is not in the same state as one verified this morning, and a score treating them identically rewards standing still. The requirement is that the decay is explainable: a named deduction with a cause and a fix.

Govern360 shows the deduction as a labelled badge on the affected edge of the derivation map rather than absorbing it into the total.

How the score is built

#Coverage (score confidence)

Coverage is the share of an AI estate that has actually been connected and measured, published alongside a governance score so the score’s confidence is visible. An 82 at 20% coverage and an 82 at 95% coverage describe very different organisations. A score published without its coverage cannot be interpreted, and incomplete telemetry producing an artificially good number is the failure mode the figure exists to prevent.

Govern360 publishes coverage beside every score and names the next source to connect.

The AI Exposure Score

Agents

#AI agent

An AI agent is a software system that can invoke a model and then take actions in other systems, as distinct from a chatbot, which returns text. The practical boundary is whether it holds a connector, a tool or a permission that changes something outside the conversation. That boundary decides which controls apply: a chatbot is an accuracy and data-handling question, while an agent is additionally an identity, permission and accountability question.

Govern360 records the model, platform, connectors, identity, owner, purpose and autonomy tier for each agent on one record.

The Agent Map

#AI agent governance

AI agent governance is the continuous practice of identifying each autonomous agent, assigning an accountable owner, declaring its approved purpose, and controlling the identities, tools, data and actions available to it, with evidence that those controls remain in force. It differs from model governance in its unit of analysis. Model governance asks whether a model is fit for purpose; agent governance asks what a running system can reach and who answers for it. An organisation can validate every model it knows about and have no idea how many agents are operating.

Govern360 governs agents as the unit rather than attaching them to human processes - joiner-mover-leaver, access review and attestation - that were not designed for them.

AI agent and MCP governance

#Agent autonomy tier

An agent autonomy tier is a classification of how much an AI agent can do without a person in the loop, typically running from answers only, through assists and suggests, to acts but asks first and acts alone. The tier matters more than the sophistication of the model behind it, because the control load should follow the irreversibility of the action. An agent that can only answer needs a light touch however capable its model; an agent that can send mail outside the organisation needs review whatever model it runs.

Govern360 records the tier each agent holds today and treats an unread tier as not assessed rather than defaulting it to the safest value.

The Agent Map

#Agent sprawl

Agent sprawl is the uncontrolled accumulation of AI agents across an organisation, typically inside platforms that allow an agent to be published without a security review. Raw platform counts overstate it, because the same agent promoted through development, test and production appears three times. Those are replicas and are normal software lifecycle. Genuine duplication is two different agents doing the same job under different names, built by teams unaware of each other - one is housekeeping, the other is duplicated exposure and duplicated spend.

Govern360 separates replicas from duplication in the count and reports agents built in-tenant separately from vendor templates.

Agent sprawl benchmark

#Agent assurance

Agent assurance is the share of defined governance checks an AI agent passes, counted only against the checks that could actually be read. Typical checks include an accountable owner, a signed purpose, a recorded review by a person, a decision on record, an action policy, an assessed autonomy tier and a creator still present in the directory. Counting an unreadable check as a pass inflates the figure; counting it as a failure penalises the organisation for the product’s blind spot.

Govern360 excludes checks that could not be read from the ratio, so the percentage states what was examined rather than what was assumed.

Agent accountability

#Purpose register

A purpose register is the record of what each AI agent is approved to do, signed by a named person, against which the agent’s actual capability can be compared. Without a declared purpose there is no standard by which behaviour can be judged, so ’is this agent behaving badly’ stays an argument rather than a comparison. A purpose also gives review a stopping condition: an agent whose purpose no longer exists can be retired rather than maintained indefinitely.

The Govern360 Purpose Register proposes an owner and a purpose from platform data and requires a person to confirm or reject it; an unsigned purpose is reported as an accountability gap with a point value.

The Purpose Register

#Orphaned agent

An orphaned agent is an AI agent whose creator is no longer present in the organisation’s directory, and for which no other accountable owner has been recorded. Such agents do not stop when their creator leaves. An agent holding its own machine identity keeps authenticating; one running as its creator’s account fails silently when that account is disabled. Either way nobody remains who can explain what the agent is for.

Govern360 checks each agent’s creator against the directory and surfaces orphans as a named finding so they can be reassigned or retired by decision.

Agent accountability

Exposure paths

#The three legs of an exfiltration path

The three legs of an AI exfiltration path are untrusted content entering a system, private data the system can read, and a route by which data can leave the organisation; an agent holding all three has a complete path. Each leg is unremarkable alone. Untrusted content can carry an instruction, private data gives that instruction something worth taking, and an egress route gives it somewhere to go. Remove any one and a successful prompt injection has nowhere to go, which is why the combination is what an estate should be searched for.

Govern360 evaluates the three legs per agent and across agents, and reports a count of zero as a measured zero rather than an unmeasured one.

Cross-agent exposure

#Cross-agent exposure path

A cross-agent exposure path is an exfiltration route that completes between two or more AI agents, where no single agent holds all three legs but the combination does. One agent takes untrusted input and writes to a shared store; a different agent reads that store and can send data outside the organisation. Reviewed individually both pass, because the untrusted input and the egress never appear on the same record. The path exists only in the join, which makes per-agent review structurally blind to it.

Govern360 evaluates paths across agents and states how each link is known, so a join read from configuration is not presented as observed behaviour.

Cross-agent exposure

#Data-to-action path

A data-to-action path is the chain from an AI system through an identity and an application to a piece of data and then to an action taken outside the organisation. Inventory answers what exists; the path answers what could happen. Modelling it as a graph makes capability composable - the effective reach of an agent is the union of everything downstream of it, which no single record shows.

Govern360 draws the estate as a graph in which colour shows risk and line style shows how the relationship is known, and leaves out edges it cannot evidence rather than drawing a more complete-looking picture than the data supports.

The data-to-action graph

#Excessive agency

Excessive agency is the condition of an AI agent holding more capability than its declared purpose requires, such as a read-only summariser with write permissions or an internal assistant with an external send path. It is the most common finding in an agent estate and among the easiest to fix, because it is visible in configuration and requires nothing to have gone wrong first. It accumulates because permissions are granted at build time by people optimising for the thing working.

Govern360 compares granted capability against the signed purpose, so the gap is a finding with an owner rather than an observation.

OWASP Agentic Top 10

Identity, tools and data

#Non-human identity (NHI)

A non-human identity is a directory identity issued to software rather than to a person, such as a service principal or application identity, under which an AI agent authenticates. An agent without its own machine identity acts as whoever created it, so every call it makes appears in downstream logs as that person’s activity and an investigation cannot separate the two. There is also nothing to rotate and nothing to revoke: stopping the agent means disabling a human account or deleting the agent outright.

Govern360 inventories the machine identities behind AI systems alongside the agents, and reports agents holding no machine identity as a distinct finding.

Non-human identity

#Non-human identity sprawl

Non-human identity sprawl is the accumulation of machine identities beyond the point at which an organisation can attribute, rotate or retire them. AI accelerates it because every agent, connector and integration wants an identity while almost nothing retires them. Machine identities outlive their purpose silently: there is no leaver process for a service principal, and an unused credential attracts none of the attention an unused mailbox does.

Govern360 surfaces machine identities with no owner, no rotation and no recent use, and tracks credential expiry against the agents that depend on them.

Non-human identity sprawl

#MCP (Model Context Protocol)

The Model Context Protocol is an open protocol by which AI applications connect to external tools and data sources, with an MCP server declaring the operations it exposes to a calling agent. Because the server declares its operations and an agent’s configuration declares which servers it may reach, an agent’s tool capability is readable before a single call is made. The governance question is composition: a tool that reads private data plus a tool that sends outside the organisation is a path, even if neither is alarming alone.

Govern360 reads tool manifests and connector definitions to show what an agent can call, and reports tool calls themselves as not observable, because it is not in the call path and does not claim to be.

MCP and tool governance

#Shadow AI

Shadow AI is AI being used or built outside any approval path, and differs from shadow IT in that it is usually created inside tools the organisation already bought and already trusts. Shadow IT meant someone signed up for an unapproved product. Shadow AI is far more often an agent built in an approved platform, an OAuth grant to a personal AI account, or an AI feature switched on inside software approved years ago. Network blocking therefore finds very little of it, and the estate grows without anything appearing to be violated.

Govern360 correlates browser, endpoint, network, identity and platform signals, and presents findings for a decision rather than labelling them - nothing is shadow AI until a person says so.

Shadow AI discovery

#Shadow AI agent

A shadow AI agent is an autonomous agent or automated workflow created inside an approved platform without going through any review, often running with its own machine identity and no recorded owner. This is usually the larger half of a shadow AI problem and the half domain blocking cannot see. Such agents can run with no active user session, connect to enterprise applications, reach organisational data, execute on a schedule, and keep operating long after their creator stopped using them.

Govern360 enumerates them from the platform control planes rather than inferring them from traffic.

Shadow AI discovery

#AI bill of materials (AI-BOM)

An AI bill of materials is a record of the components an AI system is built from - models, data sources, tools, connectors and the identities involved. Its value is the same as an SBOM’s: when a component turns out to be a problem, the question becomes which systems are affected, and that is unanswerable without the mapping. For agents it matters more than for models, because the connectors are where the reach lives.

Govern360 holds model, platform, connectors, identity, data reach and owner on one record per system.

What gets discovered

Cost

#Token governance

Token governance is the practice of attributing AI model consumption to the identity, system and owner responsible for it, and reporting that against an expectation. Most AI bills arrive as a single platform line with no business dimension, which makes them impossible to challenge and easy to renew. The join that makes them legible - calling identity to agent to recorded owner - is the same join governance needs for accountability.

Govern360 carries cost on the same record as owner and purpose. Budgets alert; they do not block.

AI cost control

#Token sprawl

Token sprawl is AI model consumption that cannot be attributed to a team, a system or a business purpose. It typically accumulates in four places: licences assigned during a rollout and never used, duplicate agents built by teams unaware of each other, oversized models used for work a smaller one handles, and pilots that were never retired. None of these is visible on an invoice, because the invoice aggregates them.

Govern360 reports unused assignment, duplicate agents and unattributed consumption as findings with owners.

AI cost control

A term we have not defined?

Send it. If it belongs here it gets added, with the same treatment as the rest.

Contact Govern360