The Defender’s Guide to AI Agents·Chapter 2
AI Agent Security Glossary for Defenders
By Jessen Kurien · CISM, CISA, ISO/IEC 42001 Lead Implementer & Lead Auditor ·
Plain-English glossary
These are the words you will hear. Three short tables rather than one long one: the parts of the assistant, the things it plugs into, and the words people use in meetings. Nothing here requires you to remember it - the point is that you can come back.
The assistant itself
| Term | What it means | Closest thing you know | Why you care |
|---|---|---|---|
| Model | The brain. The part that reads and decides. Made by a vendor, delivered over the internet. | A black-box appliance you rent | You cannot inspect it, patch it, or test it fully. You can only observe what it does. |
| Model version (or snapshot) | A specific, frozen edition of that brain, usually with a date in the name. | A firmware version | Two versions with almost the same name can behave very differently. Chapter 8 is about this. |
| Prompt | The words sent to the model. Everything is a prompt - your question, the document, the instructions. | The whole request body | The attack lives in here, mixed in with the legitimate content. |
| System prompt | The standing instructions: who it is, what it should and should not do. | A job description | It is pinned above the desk - but it is on the desk, in the same text, and can be argued with. |
| Context window | Everything the assistant can see at this moment. It has a fixed size. | A desk with a fixed surface area | Fill it and the oldest items fall off - including, sometimes, your safety instructions. |
| Token | How the model counts text. Roughly three-quarters of a word. | A billing unit | It is how you are charged, and a sudden spike is one of your better early signals. |
| Inference | One run of the model. You send text, it sends text back. | One API call | This is the unit you will end up logging. |
| Hallucination | It states something false with complete confidence. | A confident junior who will not say "I don't know" | It is not lying. It does not know that it does not know. So confidence tells you nothing. |
| Agent | A model that can press buttons, not just answer. | A service account that makes its own decisions | Everything in this guide is about the gap between talking and acting. |
What it plugs into
| Term | What it means | Closest thing you know | Why you care |
|---|---|---|---|
| Tool | A button the assistant is allowed to press: send email, query a database, open a ticket. | An API the account can call | The tools are the blast radius. Everything else is talk. |
| Tool call | The moment it presses one. | The API request in your logs | This is your single most valuable event. Most companies do not record it. |
| MCP | Model Context Protocol - a standard way of plugging tools into assistants. | A driver or plugin standard | Anyone can write one. It is a supply chain, and it is barely governed. See Chapter 3. |
| MCP server | One of those plug-ins. Usually a small program, often from a public repository. | A third-party plugin you installed | It can be updated after you approved it, without telling you. |
| Memory | Notes the assistant keeps and reads again later. | A database that is also an input | Poison it once, and it is believed every day after. See Chapter 3. |
| RAG / vector store | A searchable store of your documents that the assistant looks things up in. | A filing cabinet with a search box | Whoever can put paper into the cabinet can influence every answer that comes out. |
| Non-human identity | The account the assistant uses. Its own badge, not a person's. | A service account | Most companies cannot say how many they have. See Chapter 3. |
| API key | A long string that proves the assistant is who it says it is. | A key card with no photo and no expiry | Copy it and you are the assistant. There is no second factor. |
| Scope | What that key is allowed to reach. | Permissions on the account | Almost always wider than anyone intended. Ask to see it rather than reading the policy. |
Words you will hear in meetings
| Term | What it means | Closest thing you know | Why you care |
|---|---|---|---|
| Guardrail | A rule that stops the assistant before it does something. | A till that needs a manager for refunds over a limit | Useful and necessary. Not a wall - see Chapter 1. |
| Human in the loop | A person approves before the action happens. | Change approval | Works until the volume makes people approve without reading - or until, as in Chapter 1, there is nothing to approve at all. |
| Eval set | A fixed set of test cases you re-run to check it still behaves. | A synthetic transaction, or a driving test | Your only defense against silent decline. See Chapter 8. |
| Pinning | Naming the exact model version so you get the same one tomorrow. | Pinning a package version | Without it, the brain can be swapped under you. See Chapter 8. |
| Blast radius | If this goes wrong, how much can it touch. | Exactly what you already mean by it | The one number worth arguing about before launch. |
| Orchestration | One assistant asking another assistant to do something. | Service-to-service calls | Nobody is listening to that conversation. See Chapter 3. |
| Shadow AI | AI being used in your company that nobody told you about. | Shadow IT | Almost certainly already happening. It is where most people's real exposure sits. |
Say this on Monday
"Can someone show me the list of tools our agent can call, and the permissions on the account it uses? Not the policy - the actual list."
About the author
Jessen Kurien is a cybersecurity leader and the author of The Defender’s Guide to AI Agents. His 18+ years in cybersecurity include nearly 15 years at Microsoft, work as part of the founding team of the Microsoft Threat Intelligence Center, and detection engineering leadership in Microsoft Defender XDR. His work connects investigations, detection engineering and security operations with the evidence and accountability needed for AI security and governance.
This guide will go out of date.
Providers change how their logs work, models get retired, and new cases get disclosed. Ask to be told when this changes — no newsletter, just the updates.
Download the complete guide (PDF)
The telemetry contract, detection specifications, framework mappings and checklists are also published as files — the defender pack, CC BY 4.0, free to reuse.