Glossary
Plain-language definitions of the terms this bundle uses. It grows as the bundle does.
AI Security Lead. The person accountable for adversarial testing and model-level security — prompt injection, jailbreaks, data exfiltration, and agentic tool-abuse. Distinct from a CISO's infrastructure/network scope.
Prompt injection. Manipulating a model's input to override its intended instructions — the top-ranked category in OWASP's Top 10 for LLM Applications.
Jailbreak. A prompt or technique designed to bypass a model's safety training or content restrictions.
Excessive agency. An agentic AI system granted more autonomy, permissions, or tool access than its actual task requires — the risk category specific to systems that can take actions, not just generate text.
Red team. A function or engagement that tests a system by actively trying to break it, using an attacker's objectives rather than a checklist.
Capability threshold. A pre-committed line, defined before testing, that triggers increased security controls once a model's capability crosses it — set in advance so the decision isn't made under launch pressure.