Best AI Security markBest AI Security

GLOSSARY · SEPTEMBER 2026

AI agent security glossary

The verdict

46 terms that come up when companies roll out AI agents, coding assistants and MCP servers, in alphabetical order. Each entry is one to three sentences, with a link to the standard it comes from where there is one.

A

Action layer
The point where an agent's decision becomes a real action, such as a shell command, a file write or an API call. Bay's Ghostjacking write-up argues for enforcing policy there. See indirect prompt injection and the action layer.

Source: Bay · Reviewed Sep 2026

Agent Control Standard (ACS)
An open standard for transparency and control of enterprise AI agents. In September 2026 the OWASP GenAI Security Project said it had been donated to the project to extend guidance toward runtime enforcement.

Source: OWASP GenAI Security Project · Reviewed Sep 2026

Agent hooks
Points in an AI agent's lifecycle, such as before a tool call runs, where an administrator's code or policy can inspect and allow, change or block the action. Several tools on this site enforce policy for coding agents through hooks. See where AI agent controls sit.
Agent identity
The identity an agent acts under, as distinct from the person who started it. The MCP roadmap published on 22 August 2026 lists agent identity and enterprise security as a priority area.

Source: The New MCP Roadmap · Reviewed Sep 2026

Agent skills
Packaged instructions and scripts that extend what an agent can do. Noma Security discovers skills alongside MCP servers, and Bloom Security blocks policy-violating packages and skills.
Agentic endpoint security
A product name rather than a category this site uses. Palo Alto Networks sells its Koi-based offering as Cortex Agentic Endpoint Security, and Bay describes itself on bay.io as endpoint security for the agentic era. This site describes the category as AI agent security on employee devices. See the rankings.
Agentless deployment
A rollout that adds no resident software to the device. Bay describes itself as agentless: an ephemeral binary runs through existing EDR or MDM and exits. See the Bay review.
AI agent
Software that uses a model to plan and take actions, such as running commands, editing files or calling APIs, usually with the permissions of the person who started it. See what is AI agent security.
AI detection and response (AIDR)
Runtime monitoring of AI applications and agents that flags or stops malicious or policy-breaking activity as it happens, by analogy with EDR for endpoints.
AI gateway
A proxy that AI traffic is routed through so it can be inspected, governed and logged. Palo Alto Networks completed its acquisition of the AI gateway company Portkey in May 2026.

Source: Palo Alto Networks · Reviewed Sep 2026

AI red teaming
Adversarial testing of AI apps and agents, often over several turns, to find prompt injection, data leakage and unsafe actions before attackers do. Noma Security, Onyx Security and Lasso Security list it.
AI security posture management (AI-SPM)
Continuous checks for misconfigurations and excessive permissions across AI models, agents and their connections, before anything goes wrong at runtime.
AI usage control
Gartner's name for technology that discovers, assesses and controls employees' use of AI tools. Harmonic Security and Lasso Security both reference Gartner's 2026 Market Overview for AI Usage Control.

Source: Harmonic Security · Reviewed Sep 2026

AI-BOM
An AI bill of materials: a list of the models, agents, tools and data sources an organization's AI use depends on. Lasso Security uses the term for its discovery output.
Allow, ask or deny
The three answers an agent action policy can give: run the action, pause and ask the user to confirm, or block it. See how to write an allow, ask or deny policy.

C

Client ID Metadata Document (CIMD)
A way for an MCP client to identify itself to an authorization server with a URL that hosts its metadata. The 2026-07-28 MCP specification prefers it over Dynamic Client Registration.

Source: MCP specification · Reviewed Sep 2026

Coding agent
An AI agent built for software work, such as Claude Code, Codex or Cursor, that can read and edit code, run shell commands and install packages on a developer's machine.
Confused deputy
An attack in which a trusted intermediary is tricked into using its authority for someone else. The MCP specification describes it for MCP proxy servers that connect to third-party APIs and requires per-client consent to prevent it.

Source: MCP Security Best Practices · Reviewed Sep 2026

D

Data loss prevention (DLP)
Controls that detect and stop sensitive data leaving the organization. In AI use it often means masking or blocking sensitive text before a prompt reaches a third-party model; Lasso Security lists DLP with masking.
DPoP (Demonstrating Proof of Possession)
An OAuth mechanism, defined in RFC 9449, that binds a token to a key held by the client, so a stolen token alone is not enough to use it. The MCP roadmap names DPoP for agent identity.

Source: RFC 9449 · Reviewed Sep 2026

E

EDR (endpoint detection and response)
Security software on devices that detects and responds to malware and intrusion at the level of processes, files and network connections. AI agent controls work alongside it. See AI agent security and EDR.
Enterprise-Managed Authorization
An MCP authorization extension aimed at enterprise deployments. The MCP roadmap of 22 August 2026 says it is now stable.

Source: The New MCP Roadmap · Reviewed Sep 2026

Ephemeral binary
A program that runs a task, such as a scan, and then exits instead of staying resident on the device. Bay describes its Wave component this way.
Excessive agency
An agent having more tools, permissions or autonomy than its task needs, so a manipulated or mistaken agent can do real damage. It ranks third in the OWASP 2026 Top 10 for LLM Applications.

Source: OWASP GenAI Security Project · Reviewed Sep 2026

G

Guardian agent
An AI agent whose job is to supervise other agents and enforce boundaries on them at runtime. Gartner uses the term; Onyx Security was named a representative vendor in Gartner's 2026 Market Guide for Guardian Agents.

Source: Onyx Security · Reviewed Sep 2026

H

Human in the loop
A design in which a person can approve or deny an agent's action before it runs. The MCP tools specification says there should always be a human in the loop with the ability to deny tool invocations.

Source: MCP tools specification · Reviewed Sep 2026

I

Indirect prompt injection
Instructions hidden in content an agent reads, such as a web page, document or ticket, that steer the agent into actions its user did not ask for. Bay's "Ghostjacking" write-up describes this pattern against trusted agents.

Source: Bay · Reviewed Sep 2026

L

Local MCP server
An MCP server that runs on the user's own machine, launched by the AI app. The MCP specification warns that such servers run with the same privileges as the client.

Source: MCP Security Best Practices · Reviewed Sep 2026

M

Managed settings
Configuration for an AI agent that an administrator sets centrally and the user cannot override, such as permission rules, hooks and the list of allowed MCP servers.
MCP (Model Context Protocol)
An open-source standard for connecting AI applications to external systems. An MCP server exposes tools and data; an MCP client inside the AI app calls them.

Source: modelcontextprotocol.io · Reviewed Sep 2026

MCP allow list
A list of approved MCP servers, and sometimes approved tools on them, that an agent may load; everything else is blocked. See MCP security.
MCP gateway
A proxy between MCP clients and MCP servers that can discover, filter, block or log tool calls. It sees traffic routed through it, which usually excludes local servers talking over stdio. See MCP security.
MDM (mobile device management)
Tools such as Intune, JAMF and Kandji that IT teams use to configure company devices and deploy software to them. Several AI agent controls on this site roll out through MDM.
Multi round-trip requests (MRTR)
The 2026-07-28 MCP pattern in which a server that needs more input returns an input_required result and the client retries the request with the answers, replacing server-initiated requests.

Source: MCP specification · Reviewed Sep 2026

P

Posture alert
A finding about a risky configuration rather than an attack in progress, such as an MCP server with broad permissions. Bay's home page cites 160+ posture alerts (vendor-stated).
Prompt injection
Input written to override a model's instructions. Direct injection comes from the user; indirect injection hides in content the model or agent reads.

S

Scope minimization
Granting an MCP client only the permissions an operation needs and asking for more when a privileged operation is first attempted. The MCP specification lists broad up-front scopes as a way to widen the damage of a stolen token.

Source: MCP Security Best Practices · Reviewed Sep 2026

Session context
What an agent did earlier in the same session, who started it and what data it touched, used to decide on its next action. Bay and Noma Security describe session-aware decisions.
Shadow AI
AI tools, agents, extensions or MCP servers used without the organization's approval or visibility. See what is shadow AI.
Shadow MCP
MCP servers that employees configure for their agents without approval. Several tools on this site say they discover them.
Simulation mode
Running a new policy rule without enforcing it, to see what it would have allowed, asked about or denied. Bay documents a Simulation Mode; see question 11 in the buyer's checklist.
Stateless MCP
The 2026-07-28 MCP design with no initialize handshake and no protocol session: each request carries its own version, capabilities and client details. See what the 2026-07-28 specification changes.

Source: MCP specification · Reviewed Sep 2026

stdio transport
The MCP transport in which a local server talks to the client through standard input and output on the same machine, so network gateways do not see the traffic. The MCP specification says servers meant to run locally should use stdio or restrict HTTP access.

Source: MCP Security Best Practices · Reviewed Sep 2026

T

Token passthrough
An MCP server accepting a token not issued for it and forwarding it to a downstream API. The MCP specification forbids it because it bypasses controls and breaks audit trails.

Source: MCP Security Best Practices · Reviewed Sep 2026

Tool call
A single request from an AI agent to use a tool, such as running a command or calling an MCP server's tool with arguments. It is the unit most agent policies evaluate. See how an MCP tool call works.

W

Workload Identity Federation
A way for a workload to prove its identity with a short-lived token from its own platform instead of a long-lived secret. The MCP roadmap names it, with DPoP, as a basis for agent identity.

Source: The New MCP Roadmap · Reviewed Sep 2026