Skip to content
🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
Glossary

AI Security Glossary

Plain-language definitions of the AI and software supply-chain security terms that actually come up — from prompt injection and the lethal trifecta to AIBOM, MCP and Shai-Hulud. Search it, or link straight to any term.

Agentic AI
AI systems that do not just answer but take actions — calling tools, reading and writing data, and chaining steps toward a goal. Agency raises the stakes of every security weakness, because a compromised agent can act, not just mislead.
AIBOMAI Bill of Materials
A machine-readable inventory of everything an AI system is built from — every model, dataset and software dependency, each tagged with its license, version and provenance. It extends the SBOM idea to the model weights and training data that software bills of materials never captured.
CVECommon Vulnerabilities and Exposures
A public catalogue that assigns a unique identifier to each disclosed security vulnerability, so defenders and tools can refer to the same flaw unambiguously.
Fine-tuning
Further training a base model on domain- or task-specific data to specialise it. It creates a new model artifact whose training data and provenance belong in your MLBOM and AIBOM.
Guardrails
Controls placed around a model — input filters, output checks, tool-use policies — to keep its behaviour within bounds. Guardrails reduce risk but do not eliminate prompt injection or jailbreaks.
Hallucination
When a model produces confident, fluent output that is factually wrong or invented. A reliability and trust risk; in security contexts, never treat an AI finding as verified without checking it.
Jailbreak
A prompt crafted to bypass a model’s safety guardrails so it produces content it was trained to refuse. Distinct from prompt injection: a jailbreak targets the model’s policy, while injection hijacks an application’s instructions.
Lethal trifecta
A term for the dangerous combination in an AI agent of access to untrusted input, access to private data, and the ability to exfiltrate — e.g. send email or make web requests. When all three meet, a prompt injection can quietly steal data.
MCPModel Context Protocol
An open protocol that lets AI assistants connect to external tools and data sources through standardised servers. Powerful, but each MCP server is new attack surface that needs its config and permissions audited.
MLBOMMachine Learning Bill of Materials
A record of a specific machine-learning model’s composition — its architecture, training datasets, hyperparameters and weight provenance. Narrower than an AIBOM, which wraps the MLBOM together with the surrounding application software.
Model poisoning
Corrupting a model by tampering with its training data or weights so it behaves maliciously or carries a hidden backdoor, which then ships to everyone who uses the model.
Non-human identity
A distinct, verifiable identity for a machine actor — a service, workload or AI agent — instead of letting it borrow a human’s credentials. Central to governing agentic AI safely.
OWASP LLM Top 10
The OWASP project cataloguing the most critical security risks for applications built on large language models, led by prompt injection, insecure output handling and training-data poisoning.
Prompt injection
An attack where adversary-controlled text in an AI system’s input (a web page, an email, a document) overrides the developer’s instructions and makes the model do something unintended. The leading risk for any agent that reads untrusted content.
Provenance
Verifiable evidence of where an artifact came from and how it was built — for a package, a model or a dataset. Provenance proves origin; it does not prove the source was clean, as malicious releases with valid attestations have shown.
RAGRetrieval-Augmented Generation
A pattern where a model retrieves relevant documents at query time and uses them to ground its answer. It improves accuracy but ingests external content, which makes it a common prompt-injection pathway.
Red team
A group that attacks a system the way a real adversary would, to find weaknesses before an attacker does. For AI, red-teaming probes a model or agent for jailbreaks, injection and unsafe behaviour.
SBOMSoftware Bill of Materials
A formal, machine-readable list of the software components and dependencies in a build, each with its version and license. Expressed in SPDX or CycloneDX, it lets you answer "are we exposed to this vulnerable component?" quickly.
Shadow AI
AI tools and services used inside an organisation without the security team’s knowledge or approval, creating ungoverned data flows and credentials. The AI-era version of shadow IT.
Shai-Hulud
A family of self-replicating npm worms, first seen in 2025 and resurging through 2026. A malicious package steals developer and CI credentials on install and, with a stolen npm token, republishes itself into the victim’s own packages.
SLSASupply-chain Levels for Software Artifacts
A framework of graded levels for hardening a build and release pipeline against tampering, from basic provenance to fully reproducible, non-falsifiable builds.
SSRFServer-Side Request Forgery
An attack that tricks a server into making requests to places it should not — internal services, cloud metadata endpoints — often to reach credentials. A frequent goal of prompt injection against tool-using agents.
STRIDE
A threat-modelling framework covering Spoofing, Tampering, Repudiation, Information disclosure, Denial of service and Elevation of privilege. A structured way to enumerate how a system can be attacked.
Supply-chain attack
Compromising software by attacking something it depends on — a package, a build pipeline, a maintainer account — rather than the target directly. On npm and PyPI in 2026, self-replicating worms are the dominant form.
Typosquatting
Publishing a malicious package under a name close to a popular one (a misspelling or a plausible variant) so that a developer’s typo or an AI agent’s guess installs the attacker’s code.
Zero-day
A vulnerability that is exploited before the vendor has a patch available — defenders have had zero days to fix it. In 2026, AI is sharply shortening the time attackers need to find them.

26 of 26 terms shown.

Frequently asked questions

What is the difference between prompt injection and a jailbreak?

A jailbreak targets the model’s own safety policy, coaxing it to produce content it was trained to refuse. Prompt injection targets an application built on the model: adversary-controlled text in the input overrides the developer’s instructions so the app does something unintended. Jailbreaks are about the model; injection is about the system around it.

What is the "lethal trifecta" in AI agent security?

It is the dangerous combination of three capabilities in one agent: access to untrusted input, access to private data, and the ability to exfiltrate (for example, send email or make web requests). When all three are present, a single prompt injection can quietly turn the agent into a data-theft tool. Remove any one leg and the risk drops sharply.

Is this glossary kept up to date?

Yes. It covers the AI and software supply-chain security terms PlayCISO uses across its tools and analyses, and new terms are added as the field moves.

AI Security Glossary — Plain Definitions · PlayCISO