AI Security Glossary: Key Terms Explained in Plain English

Updated · EraseAI

Definitions of the terms that come up most when securing AI use. Each links to a deeper guide where we have one.

A–D

  • AI agent: an AI system that can take actions, such as browsing, sending emails or calling APIs, not just answer questions.
  • AI DLP (AI data loss prevention): controls that stop sensitive data leaving through AI tools. See AI data loss prevention.
  • AI firewall: a check between a person or app and an AI model that inspects what is sent and blocks or redacts sensitive data. See AI firewall.
  • AI governance: the policies, roles and processes an organization uses to decide how AI may be used.
  • API key: a secret string that grants access to a service. Anyone who has it can usually act as you.
  • BAA (business associate agreement): the contract HIPAA requires before a vendor may handle protected health information.
  • CASB: cloud access security broker; a tool that monitors and controls use of cloud apps.
  • Data exfiltration: moving data out of an organization without authorization.
  • Data minimization: sending or keeping only the data a task needs; a GDPR principle.
  • Data residency: where data is physically stored and processed.
  • DLP (data loss prevention): tools and processes that stop sensitive data leaving an organization.
  • DPA (data processing agreement): the contract GDPR requires between a controller and a processor.

E–P

  • Embedding: a numeric representation of text used for search and retrieval; embeddings can leak information about the text they came from.
  • Fine-tuning: further training a model on your own data; anything in that data may be reproduced by the model.
  • Guardrails: rules and filters around a model that limit what it accepts or produces.
  • Hallucination: a confident but false model output.
  • Jailbreak: a prompt that gets a model to ignore its safety rules.
  • LLM (large language model): a model trained on large amounts of text to predict and generate language, such as the models behind ChatGPT, Claude and Gemini.
  • Masking: hiding part of a value, such as all but the last four digits of a card number.
  • Model training opt-out: a setting that stops a provider using your conversations to improve its models.
  • PHI (protected health information): health data linked to a person, protected under HIPAA.
  • PII (personally identifiable information): data that identifies a person, directly or in combination.
  • Prompt: the text and files sent to an AI model.
  • Prompt injection: text that overrides a model's instructions. See prompt injection explained.
  • Pseudonymization: replacing identifiers with consistent stand-ins that can be reversed with a separate key.

R–Z

  • RAG (retrieval-augmented generation): feeding a model documents retrieved from your own data so it can answer from them.
  • Redaction: removing or replacing sensitive values before text is shared. See PII redaction for AI.
  • Secret scanning: automatically finding credentials in code, logs or messages.
  • Shadow AI: AI tools used without IT approval. See shadow AI.
  • System prompt: hidden instructions that set a model's behaviour in an application.
  • Tokenization: in security, replacing sensitive data with a non-sensitive token; in AI, splitting text into units a model processes.
  • Zero data retention: a provider commitment not to store prompts and outputs beyond processing.

Check every message before it reaches AI

EraseAI stops API keys, passwords, card numbers and personal data in ChatGPT, Claude and Gemini. Free in Chrome, no account needed.

Related guides