The Defender’s Guide to AI Agents·Chapter 2

AI Agent Security Glossary for Defenders

Plain-English glossary

These are the words you will hear. Three short tables rather than one long one: the parts of the assistant, the things it plugs into, and the words people use in meetings. Nothing here requires you to remember it - the point is that you can come back.

The assistant itself

TermWhat it meansClosest thing you knowWhy you care
ModelThe brain. The part that reads and decides. Made by a vendor, delivered over the internet.A black-box appliance you rentYou cannot inspect it, patch it, or test it fully. You can only observe what it does.
Model version
(or snapshot)
A specific, frozen edition of that brain, usually with a date in the name.A firmware versionTwo versions with almost the same name can behave very differently. Chapter 8 is about this.
PromptThe words sent to the model. Everything is a prompt - your question, the document, the instructions.The whole request bodyThe attack lives in here, mixed in with the legitimate content.
System promptThe standing instructions: who it is, what it should and should not do.A job descriptionIt is pinned above the desk - but it is on the desk, in the same text, and can be argued with.
Context windowEverything the assistant can see at this moment. It has a fixed size.A desk with a fixed surface areaFill it and the oldest items fall off - including, sometimes, your safety instructions.
TokenHow the model counts text. Roughly three-quarters of a word.A billing unitIt is how you are charged, and a sudden spike is one of your better early signals.
InferenceOne run of the model. You send text, it sends text back.One API callThis is the unit you will end up logging.
HallucinationIt states something false with complete confidence.A confident junior who will not say "I don't know"It is not lying. It does not know that it does not know. So confidence tells you nothing.
AgentA model that can press buttons, not just answer.A service account that makes its own decisionsEverything in this guide is about the gap between talking and acting.

What it plugs into

TermWhat it meansClosest thing you knowWhy you care
ToolA button the assistant is allowed to press: send email, query a database, open a ticket.An API the account can callThe tools are the blast radius. Everything else is talk.
Tool callThe moment it presses one.The API request in your logsThis is your single most valuable event. Most companies do not record it.
MCPModel Context Protocol - a standard way of plugging tools into assistants.A driver or plugin standardAnyone can write one. It is a supply chain, and it is barely governed. See Chapter 3.
MCP serverOne of those plug-ins. Usually a small program, often from a public repository.A third-party plugin you installedIt can be updated after you approved it, without telling you.
MemoryNotes the assistant keeps and reads again later.A database that is also an inputPoison it once, and it is believed every day after. See Chapter 3.
RAG / vector storeA searchable store of your documents that the assistant looks things up in.A filing cabinet with a search boxWhoever can put paper into the cabinet can influence every answer that comes out.
Non-human identityThe account the assistant uses. Its own badge, not a person's.A service accountMost companies cannot say how many they have. See Chapter 3.
API keyA long string that proves the assistant is who it says it is.A key card with no photo and no expiryCopy it and you are the assistant. There is no second factor.
ScopeWhat that key is allowed to reach.Permissions on the accountAlmost always wider than anyone intended. Ask to see it rather than reading the policy.

Words you will hear in meetings

TermWhat it meansClosest thing you knowWhy you care
GuardrailA rule that stops the assistant before it does something.A till that needs a manager for refunds over a limitUseful and necessary. Not a wall - see Chapter 1.
Human in the loopA person approves before the action happens.Change approvalWorks until the volume makes people approve without reading - or until, as in Chapter 1, there is nothing to approve at all.
Eval setA fixed set of test cases you re-run to check it still behaves.A synthetic transaction, or a driving testYour only defense against silent decline. See Chapter 8.
PinningNaming the exact model version so you get the same one tomorrow.Pinning a package versionWithout it, the brain can be swapped under you. See Chapter 8.
Blast radiusIf this goes wrong, how much can it touch.Exactly what you already mean by itThe one number worth arguing about before launch.
OrchestrationOne assistant asking another assistant to do something.Service-to-service callsNobody is listening to that conversation. See Chapter 3.
Shadow AIAI being used in your company that nobody told you about.Shadow ITAlmost certainly already happening. It is where most people's real exposure sits.

Say this on Monday

"Can someone show me the list of tools our agent can call, and the permissions on the account it uses? Not the policy - the actual list."

About the author

Jessen Kurien is a cybersecurity leader and the author of The Defender’s Guide to AI Agents. His 18+ years in cybersecurity include nearly 15 years at Microsoft, work as part of the founding team of the Microsoft Threat Intelligence Center, and detection engineering leadership in Microsoft Defender XDR. His work connects investigations, detection engineering and security operations with the evidence and accountability needed for AI security and governance.

Meet Jessen

Connect with Jessen Speaking, workshops and training

This guide will go out of date.

Providers change how their logs work, models get retired, and new cases get disclosed. Ask to be told when this changes — no newsletter, just the updates.

Get told when it changes

Download the complete guide (PDF)

The telemetry contract, detection specifications, framework mappings and checklists are also published as files — the defender pack, CC BY 4.0, free to reuse.