AI Security Glossary: Key Terms Explained in Plain English
Updated · EraseAI
Definitions of the terms that come up most when securing AI use. Each links to a deeper guide where we have one.
A–D
- AI agent: an AI system that can take actions, such as browsing, sending emails or calling APIs, not just answer questions.
- AI DLP (AI data loss prevention): controls that stop sensitive data leaving through AI tools. See AI data loss prevention.
- AI firewall: a check between a person or app and an AI model that inspects what is sent and blocks or redacts sensitive data. See AI firewall.
- AI governance: the policies, roles and processes an organization uses to decide how AI may be used.
- API key: a secret string that grants access to a service. Anyone who has it can usually act as you.
- BAA (business associate agreement): the contract HIPAA requires before a vendor may handle protected health information.
- CASB: cloud access security broker; a tool that monitors and controls use of cloud apps.
- Data exfiltration: moving data out of an organization without authorization.
- Data minimization: sending or keeping only the data a task needs; a GDPR principle.
- Data residency: where data is physically stored and processed.
- DLP (data loss prevention): tools and processes that stop sensitive data leaving an organization.
- DPA (data processing agreement): the contract GDPR requires between a controller and a processor.
E–P
- Embedding: a numeric representation of text used for search and retrieval; embeddings can leak information about the text they came from.
- Fine-tuning: further training a model on your own data; anything in that data may be reproduced by the model.
- Guardrails: rules and filters around a model that limit what it accepts or produces.
- Hallucination: a confident but false model output.
- Jailbreak: a prompt that gets a model to ignore its safety rules.
- LLM (large language model): a model trained on large amounts of text to predict and generate language, such as the models behind ChatGPT, Claude and Gemini.
- Masking: hiding part of a value, such as all but the last four digits of a card number.
- Model training opt-out: a setting that stops a provider using your conversations to improve its models.
- PHI (protected health information): health data linked to a person, protected under HIPAA.
- PII (personally identifiable information): data that identifies a person, directly or in combination.
- Prompt: the text and files sent to an AI model.
- Prompt injection: text that overrides a model's instructions. See prompt injection explained.
- Pseudonymization: replacing identifiers with consistent stand-ins that can be reversed with a separate key.
R–Z
- RAG (retrieval-augmented generation): feeding a model documents retrieved from your own data so it can answer from them.
- Redaction: removing or replacing sensitive values before text is shared. See PII redaction for AI.
- Secret scanning: automatically finding credentials in code, logs or messages.
- Shadow AI: AI tools used without IT approval. See shadow AI.
- System prompt: hidden instructions that set a model's behaviour in an application.
- Tokenization: in security, replacing sensitive data with a non-sensitive token; in AI, splitting text into units a model processes.
- Zero data retention: a provider commitment not to store prompts and outputs beyond processing.
Check every message before it reaches AI
EraseAI stops API keys, passwords, card numbers and personal data in ChatGPT, Claude and Gemini. Free in Chrome, no account needed.
Related guides
AI Data Loss Prevention (AI DLP): How to Stop Data Leaks to ChatGPT and Other AIWhat AI data loss prevention is, why classic DLP misses data sent to ChatGPT, Claude and Gemini, and how to put AI DLP in place for yourself or a whole organization.LLM Data Security: Risks, Controls and a Practical ChecklistHow data moves through large language models, where it can leak (prompts, logs, training, outputs, integrations) and the controls that protect it, with a checklist you can use today.Prompt Injection Explained: How It Works and How to Defend Against ItPrompt injection tricks an AI model into ignoring its instructions. See direct and indirect examples, why it can leak data, and the defenses that reduce the risk.Shadow AI: What It Is, Why It's Risky, and How to Manage ItShadow AI is the use of AI tools without IT approval. Learn why it happens, what it costs when it goes wrong, and a five-step plan to bring it under control without banning AI.