Cordrey Knowledge

The AI jargon glossary

Every term a vendor might say at you, in plain English, with a second definition for what it means when it appears in a sales demo.

76 terms · last updated 7 September 2026 Updated weekly: new terms are added as they start appearing in vendor pitches

# AEO / GEO

also: answer engine optimisation · generative engine optimisation · GEO

Answer engine optimisation: making your content the source AI assistants cite when they answer questions in your field, the successor discipline to SEO.

Why traffic falls while influence needn’t: AI answers increasingly sit where the ten blue links were, and they cite sources that carry real, liftable facts. The buying caution: the field is young and vendor promises outrun evidence, so judge AEO services by the citations they can show, not the acronyms.

# Agent-washing

also: digital employee · digital worker

Marketing ordinary automation or a chatbot as an autonomous "AI agent" or "digital employee" to borrow the category's shine.

The 2026 sequel to AI-washing. The test is one question: what does it decide for itself, and what is just a fixed workflow with an AI step? Fixed workflows are often exactly what you want; paying agent prices for them is the part to avoid.

# Agentic AI / AI agent

also: AI agents · autonomous agents

Software that uses an AI model to decide for itself which steps to take towards a goal (reading, choosing tools and acting in sequence) rather than following a fixed script.

When a vendor says their platform is “agentic”, ask what the agent is actually allowed to decide. Much of what is sold as agentic is a fixed workflow with one AI step in the middle, which is often exactly what you want, but is not autonomy and should not be priced like it. Where genuine autonomy exists, your first questions are about control: what can it do without a human approving, and where is the log of what it did?

# Agentic browsing

also: AI browser · computer use

An AI operating a web browser on your behalf: navigating, filling forms, comparing and buying, rather than just answering about pages.

The frontier of assistant capability and of risk: a browser agent inherits your logged-in sessions, so its permissions are your permissions. For business use, treat it like any agent: narrow tasks, watched runs, and never unattended near payments or client systems yet.

# AI content detectors

also: AI writing detectors

Tools claiming to identify whether text or images were AI-generated.

Unreliable in both directions, with documented false accusations of human writers, and no serious lab claims otherwise for text. Do not build hiring, academic or client decisions on them; provenance standards and disclosure practices are the grown-up alternative.

# AI Overviews

also: AI Mode · SGE

The AI-generated answer Google now shows above the classic links for many searches, synthesised from sources it cites.

Two business meanings: your staff read them (verify before relying, as ever), and your customers read them about you, which is why being cited in AI answers is the new version of ranking. The AEO entry covers what to do about the second.

# AI slop

also: slop

Low-effort AI-generated content published at volume without human judgement: generic posts, padded articles, inbox spam with a synthetic sheen.

The reason “written by AI” is becoming a quality slur, and the reason disciplined firms disclose process rather than hide it. The line that matters is not AI involvement but human judgement: drafted-with-review is publishing; generated-and-posted is slop, and audiences and answer engines increasingly filter it.

# AI wrapper

also: wrapper

A product that is mostly a thin interface over a frontier model's API, with little proprietary capability of its own.

Not automatically bad: a well-designed wrapper with good workflow fit can be worth paying for. The pricing question is the honest one: if the product is a prompt and a coat of paint over the same API you could call directly, the margin should be modest and the exit easy. The demo questions guide shows how to tell.

# AI-washing

Marketing that overstates or invents a product's AI capabilities: rebadging old rules-based features, or claiming AI where little exists.

Regulators now treat this as a live enforcement area: the SEC has charged investment advisers over false AI claims, and the FCA’s Consumer Duty work points the same direction for firms repeating vendor claims to clients. The practical defence is simple: for every AI claim in a pitch, ask what the model actually does, on what data, with what failure rate. Vendors with real capability answer specifically; AI-washers answer with adjectives.

# Anonymisation vs pseudonymisation

also: pseudonymisation · de-identification

Anonymised data can no longer identify anyone even indirectly and falls outside data protection law; pseudonymised data has identifiers replaced but remains personal data.

Vendors say “anonymised” loosely, and the difference carries legal weight: if the vendor or anyone can re-link the data, it is pseudonymised and still regulated. Ask which one they mean and how they would prove it.

# API

The doorway software offers so other software can use it: how your CRM, inbox and AI tools connect to each other without a human copying data between screens.

“Has an API” is a genuinely important procurement checkbox, because it determines whether a tool can join your automations or becomes an island. The follow-ups matter though: is the API included in your plan or a pricier tier, does it cover the data you actually need, and is it rate-limited into uselessness? “API access on the Enterprise plan only” is a common quiet upsell.

# Automation vs AI

Automation follows rules you define in advance and is perfectly repeatable; AI interprets and generates, handling ambiguity at the cost of occasional confident errors. Most good systems combine both.

The distinction that prices and de-risks projects. Rules-based automation is cheap, testable and auditable: if a task can be written as rules, automate it that way and skip the AI premium. Use AI where judgement, language or messy input genuinely feature, and wrap it in review. A vendor who cannot tell you which parts of their product are rules and which are AI has told you something anyway.

# Autonomy levels

also: human oversight levels

The ladder of trust for AI agents: first everything is drafted for a person to approve, then routine actions run with consequences still gated, then the agent acts alone with everything logged.

The single most useful frame for deploying agents safely: every process starts with every output drafted for approval and climbs on evidence, never on enthusiasm. If a vendor cannot tell you which level their product runs at, and how you would move it down a level, it is at the wrong level.

# Canvas / artifacts

also: artifacts · canvas mode

The side-by-side working document some assistants open beside the chat: the draft lives in an editable pane while you direct changes in conversation.

The feature that turns chat from question-and-answer into actual co-writing, and the one to teach staff who edit documents all day: iterate in the canvas, not by pasting versions back and forth. Different vendors brand it differently; the pattern is the same.

# Context engineering

The craft of deciding exactly what a model sees for a task: instructions, examples, retrieved documents, history, in what order and how much.

The 2026 successor-term to prompt engineering, and the honest name for where quality actually comes from in business systems: not magic words but the right information, curated. When output disappoints, the context is the first suspect, not the model.

# Context window

The amount of text an AI model can consider at once: its working memory for a single task, measured in tokens.

When a vendor says the tool “reads your whole client file”, the context window is the fine print. If the file is bigger than the window, something is being left out or summarised on the way in, and the tool’s answer only reflects what made it through. A fair question in a demo: what happens when the document set exceeds the window? Is anything silently dropped?

# Copilot

also: AI assistant

A marketing label for an AI assistant embedded in software you already use, suggesting and drafting alongside a human who stays in charge.

Originally a Microsoft product name, now a generic label, which is the point to be careful about: “copilot” tells you the interaction style, not the capability. Two products both called copilots can differ completely in what they access, what they retain, and whether output is checked. Look past the label to the specifics: what data does it see, where does it go, what is logged?

# Custom instructions

also: personalisation · preferences

Standing preferences an assistant applies to every conversation: your role, your tone, your formats, set once instead of repeated per chat.

The five minutes of setup that most improves everyday use, and most staff never do it. A firm-level version (shared instructions encoding house style and red lines) is the first rung of making a general tool behave like your tool.

# Data residency

also: data sovereignty

Where your data is physically processed and stored: which country's data centres, and therefore which laws and transfer rules apply.

The question behind “is it UK or EU hosted?”, and increasingly a tier feature the big providers sell. For a DPIA you need the specific answer for your tier, in writing, including backups and support access, not the vendor’s global marketing map.

# Deep research

also: research mode · research agent

An AI mode that plans and runs a multi-step investigation, searching, reading and synthesising for minutes before returning a structured, cited report.

Genuinely one of the most useful recent capabilities, and the cited-not-verified rule applies double: a twenty-source report reads authoritative whether or not the sources say what it claims. Spot-check the citations that carry the conclusions before the report travels.

# Deepfake

also: synthetic media · voice cloning

AI-generated audio, image or video that convincingly impersonates a real person.

A live business threat, not a novelty: cloned voices of executives authorising payments is a working fraud pattern. The defences are procedural, callback rules and verification for money movement, plus labelling duties in several jurisdictions when you publish synthetic media yourself.

# Distillation

Training a smaller, cheaper model to imitate a larger one, keeping most of the capability for a fraction of the running cost.

Why “mini” and “lite” models exist and why they are often the right buy: for routine tasks the distilled model is indistinguishable and several times cheaper. A well-built system routes easy work to small models and saves the expensive one for the hard cases.

# DPIA

also: data protection impact assessment

A data protection impact assessment: the structured, written assessment UK GDPR requires before high-risk processing of personal data, which AI on client files usually is.

The document regulators actually ask to see. The failing version is generic (“we use AI, risks are mitigated”); the passing version names the tool, the data fields, the training terms and what happens when the output is wrong about a person. An afternoon’s work with the right template.

# Embeddings / vector database

also: vector search · semantic search

A way of turning text into lists of numbers that capture meaning, so a system can find passages that are about the same thing even when they use different words; a vector database stores and searches those numbers.

This is the machinery behind “search that understands meaning” and most RAG systems. Two things worth knowing in a procurement conversation: embeddings of your documents are still your client data and belong inside the same data-protection perimeter, and “semantic search” quality varies enormously. Insist on a trial against your own documents, not the vendor’s demo set.

# Evals

also: evaluations · benchmarks

Structured tests that measure how well an AI system performs a specific task: fixed inputs, expected qualities, scored outputs, repeated whenever anything changes.

The difference between “it seems good” and “we know it works”. When a vendor quotes benchmark scores, remember those measure exam questions, not your workload; the evals that matter are five of your own real tasks, run before you buy and re-run when the vendor ships an update.

# Explainability

also: interpretability · XAI

The degree to which you can say why an AI system produced a particular output, in terms a client, auditor or regulator would accept.

Regulators ask for it, vendors claim it, and for large language models genuine mechanistic explanation remains limited. What a firm can honestly provide instead: the inputs, the instructions, the output and the human decision, all logged, which is usually what the auditor actually needs.

# Few-shot prompting

also: few-shot examples

Improving an AI's output by including a handful of worked examples in the prompt, so it imitates the pattern rather than guessing at instructions.

The single highest-leverage everyday technique: three good examples of your best letters outperform a page of adjectives about tone. If output quality is inconsistent, add examples before blaming the model.

# Fine-tuning

Further training an existing AI model on your own examples so it picks up your formats, tone or domain patterns, changing the model itself rather than just what you feed it.

Vendors sometimes say “trained on your data” when they mean the much lighter (and usually better) options: retrieval or careful prompting. True fine-tuning is expensive, needs curated examples, and locks you to a model version. If a vendor claims it, ask what specifically was fine-tuned, on how many examples, and, critically, whether your firm’s data is used to train models that serve other customers.

# Foundation model / frontier model

The handful of very large, general-purpose AI models (built by companies like Anthropic, OpenAI and Google) that almost all AI products are constructed on top of.

“Frontier” simply means one of the current best. The practical significance for your firm is concentration risk: if the same provider sits behind your transcription tool, your report writer and your CRM’s AI features, one upstream outage, price change or model update touches all three at once. Your vendor due diligence should ask what model each tool runs on, and what the vendor does when it changes.

# Frontier model

also: frontier AI

One of the most capable AI models available at a given moment, from the handful of labs training at the largest scale.

A moving label: this year’s frontier is next year’s mid-tier, which is why building your systems to swap models matters more than picking today’s winner. Reserve frontier pricing for work that measurably needs it.

# GPAI (general-purpose AI)

also: general-purpose AI model · foundation model (EU term)

The EU AI Act's term for models trained for broad capability, your ChatGPTs and Claudes, which carry their own transparency and copyright duties aimed mainly at the providers.

Mostly the model-makers’ problem rather than yours: the obligations attach to those training the models, with a code of practice steering compliance. Deployers meet the term when vendors cite “GPAI compliance” as reassurance; it means the provider’s homework, not yours, is done.

# Grounding / citations

Techniques that tie an AI's answers to identifiable sources (your documents, cited passages, linked references) so claims can be checked rather than taken on trust.

“Every answer is grounded with citations” is a strong claim worth testing, because citation display and citation accuracy are different things: models can cite a real document for a claim it does not support. In a demo, click the citations and read them. A tool whose citations check out is materially safer for regulated work than one that merely looks referenced.

# Guardrails

Technical controls placed around an AI system to stop it doing unwanted things: leaking data, giving advice it shouldn't, acting outside its remit.

“Enterprise-grade guardrails” is doing heavy lifting in many pitches. Guardrails are real and worth having, but they are probabilistic filters, not guarantees: determined misuse and unlucky phrasing get through. Ask the vendor to name the specific guardrails relevant to your risk (client data leaving the tenant, advice-like output, actions taken without approval) and how failures are detected and reported to you.

# Hallucination

also: confabulation

When an AI model confidently produces information that is false: invented citations, fabricated figures, plausible-sounding claims with no source.

Every LLM does this; the question is only how often and with what safeguards. Treat any vendor who says their product “doesn’t hallucinate” as having failed a basic honesty test; the honest version is “we reduce and catch hallucinations, like this”. For regulated work, the practical control is a human verification gate on anything citable before it leaves the firm.

# High-risk AI system (EU AI Act)

also: Annex III system

The EU AI Act's category for AI uses with serious rights or safety stakes, listed uses like credit scoring, insurance pricing and recruitment, carrying the Act's heaviest duties.

The classification that decides whether the EU AI Act merely touches a firm or lands on it. Most everyday drafting and admin use is not high-risk; using AI to score credit or screen candidates is. If a vendor’s product operates in a listed area, ask which obligations they cover and which stay with you as the deployer.

# Human in the loop

also: HITL

A system design where a person reviews or approves the AI's output before it takes effect, the control regulators most consistently expect for client-facing work.

The phrase to probe in any compliance conversation, because there is a wide gap between a human genuinely reviewing output and a human clicking an approve button at speed. The ICO has signalled attention to rubber-stamping, and a nominal check may not count as meaningful human involvement. Design reviews so the reviewer can realistically catch AI-specific failures, and can show they did.

# Inference

Running an already-trained AI model to get an answer, as opposed to training, which is building the model in the first place. Every query your staff make is inference.

Inference is where the ongoing cost lives: every use of an AI feature costs the vendor compute, which is why AI add-ons carry per-seat or usage pricing and why “unlimited” plans have fair-use clauses buried in them. When a vendor’s AI feature is suspiciously cheap, the interesting question is what corners the inference is cutting: a smaller model, heavier caching, or your data subsidising something.

# Intelligent document processing

also: IDP · document AI

Extracting structured data from documents, PDFs, scans, forms, using OCR plus AI models, with confidence scores and human review on the uncertain cases.

The grown-up version of “our AI reads your documents”. The buying questions: what accuracy on YOUR document types (demand a pilot on your real samples), what happens below the confidence threshold, and does a human see the uncertain fields or does the system guess?

# Knowledge cutoff

also: training cutoff

The date after which an AI model knows nothing, because its training data ended there; anything later must come from search or your own documents.

Why a chatbot can be eloquent about last year and wrong about last week. Products bolt on live search to bridge the gap; when currency matters, ask whether an answer came from the model’s memory or from retrieval, because only the second has a date on it.

# Large language model (LLM)

also: language model

The core AI technology behind tools like ChatGPT and Claude: a model trained on vast amounts of text that predicts likely continuations, which makes it remarkably good at reading, summarising and drafting.

Almost every AI feature you are shown in 2026 is an LLM with product design around it. The vendor rarely built the model; they buy access from one of a handful of providers. That matters practically: ask whose model sits underneath, what happens to your data on its way there, and what happens to the product when the underlying model changes.

# Latency

How long an AI system takes to respond, from instant autocomplete to minutes for deep research tasks.

Different jobs tolerate different waits: a customer-facing chatbot needs seconds, an overnight report pipeline does not care. Vendors quote best-case numbers; test at your volume, in your region, on your tasks, before promising response times to anyone else.

# MCP (Model Context Protocol)

An open standard that lets AI assistants connect to other systems (files, CRMs, databases) through one common plug rather than custom integrations for each.

Increasingly name-dropped in 2026 demos as “supports MCP”. The genuine benefit is less lock-in: tools speaking a common protocol are easier to rewire when you change vendors. The governance angle is access: each MCP connection is a door from an AI system into a business system, so somebody in your firm should be able to list which doors exist and what each one can reach.

# Memory (assistant memory)

An assistant's ability to remember facts about you between conversations, from your job to your preferences, and use them unprompted.

Convenient and worth a policy line: memory means information from one chat resurfaces in another, which matters the moment client details are involved. Know how to view and clear it on your tier, and whether it is on by default for staff accounts.

# Model drift

also: drift

The behaviour of an AI system changing over time, because the vendor updated the underlying model or your inputs shifted, without anyone deciding it.

Why a workflow that tested perfectly in March misbehaves in June with no one having touched it. The defence is boring and effective: re-run your evals on a schedule and after any vendor update, and keep the approval gate on consequential outputs.

# Multimodal

An AI model that works with more than text: reading images and documents, hearing audio, sometimes producing them too.

The practically useful version for a service firm is usually document vision: reading scanned PDFs, handwritten forms and screenshots without separate OCR software. In a demo, test it with your worst real documents (a skewed scan, a fax-quality statement), not the vendor’s clean samples. That is where multimodal claims earn or lose their keep.

# No-code / low-code

Tools that let non-programmers build workflows and automations through visual interfaces (Zapier, Make, Power Automate), with low-code adding small amounts of scripting.

Genuinely useful, and the backbone of sensible first automation projects. The caution is sprawl: no-code makes it easy for automations to accumulate with no owner, no documentation and no offboarding when their creator leaves. Treat no-code automations as real systems (inventoried, owned and reviewed) or you are quietly building shadow infrastructure with a friendly interface.

# OCR

also: optical character recognition

Optical character recognition: turning images of text, scans, photos, PDFs, into machine-readable characters.

Decades old, now dramatically better because AI models read layout and context, not just letter shapes. It is the first step of intelligent document processing rather than the whole of it: OCR gets you the characters; the extraction, checking and filing around it is where products differ and prices diverge.

# Open-weight model

also: open-source model · open model

An AI model whose trained weights are published for anyone to download and run on their own hardware, as opposed to models only reachable through a vendor's service.

Not the same as open source: the training data and code usually stay private, and licences range from genuinely permissive to custom terms with conditions. When a vendor says “open source model”, the useful questions are which licence exactly, and who is hosting it for you under what terms.

# Orchestration

Coordinating several AI steps, tools or agents into one workflow, deciding what runs, in what order, and what happens when a step fails.

Vendors use it to make a product sound sophisticated. The checkable substance is error handling: ask what happens when step three fails at 2am. Real orchestration has retries, alerts and a log; the marketing version has a diagram.

# Prompt / prompt engineering

The instructions given to an AI model; prompt engineering is writing and refining those instructions so the model produces reliable, correctly-formatted output.

Much of a polished AI product’s value lives in its prompts, which also means one badly-written prompt template can misfire systematically across every client it touches, unlike a human error which is usually one-off. Ask vendors how prompt changes are tested and rolled out; ask internally who owns the prompts your firm relies on and where they are versioned.

# Prompt injection

also: indirect prompt injection

An attack where malicious instructions are hidden in content an AI reads (an email, a webpage, a document) so the AI follows the attacker's instructions instead of yours.

This is the signature security risk of AI that reads untrusted content, and it is why an agent’s permissions matter more than its intelligence. If a vendor’s product reads external content and can also take actions, ask directly how they defend against injected instructions; a blank look is a finding.

# Quantisation

also: quantization

Compressing a model's numbers into lower precision so it runs faster and on cheaper hardware, at a small cost to quality.

The trick that lets serious models run on modest machines, and a word you will meet the moment anyone proposes self-hosting. The buyer’s question is only ever the same one: was the quality checked on our tasks after compression, or just assumed?

# RAG (retrieval-augmented generation)

also: retrieval

A technique where the AI first looks up relevant passages from your own documents, then writes its answer from what it found, grounding responses in your material rather than the model's general training.

“We use RAG on your knowledge base” is one of the most common vendor sentences of the past two years. It is a genuinely useful pattern, but its quality depends almost entirely on the retrieval step, which is the part demos hide. Ask to see it fail: pose a question whose answer is not in your documents and watch whether the tool says so or improvises.

# Rate limit

also: quota · throttling

The ceiling a provider places on how many requests or tokens you can use per minute or day, by tier.

Invisible until the day your automation scales and suddenly everything queues. Check the limits for your actual tier before building anything high-volume, and design workflows to batch and back off rather than hammer and fail.

# Reasoning model

A newer class of AI model that works through problems step by step before answering: slower and more expensive per query, but markedly better at multi-step analysis.

“Now with reasoning” is the current premium tier in many products. The honest trade-off: reasoning models are better at genuinely hard tasks (reconciliations, multi-document analysis, edge-case logic) and unnecessary for routine drafting and summarising. If a vendor charges extra for it, ask which of your actual tasks need it; paying reasoning prices for email drafting is buying a lorry to deliver letters.

# Red-teaming

Deliberately attacking your own AI system, with adversarial prompts, injection attempts and abuse cases, to find failures before someone else does.

When a vendor says their model is “extensively red-teamed”, that describes the lab’s testing of the base model, not your deployment of it. Your configuration, your data and your connected tools create new attack surface the lab never saw, which is why serious deployments get their own adversarial pass.

# RPA

also: robotic process automation · desktop flows

Robotic process automation: software that replays recorded clicks and keystrokes against applications that have no better way in.

The last resort that predates modern AI and still has a job where legacy systems lack APIs. It works and it is brittle: screens change, flows break. Treat every RPA flow as technical debt with an owner and a payback date, not as a solved problem.

# Semantic layer

A translation layer that maps your business's terms (revenue, active client, churn) onto the underlying data, so people and AI tools query in business language and get consistent answers.

The unglamorous reason “chat with your data” products disappoint or delight: without an agreed semantic layer, the AI guesses what “revenue” means and two questions get three answers. If a vendor demos natural-language analytics, ask where the business definitions live and who maintains them.

# Shadow AI

Staff using AI tools the firm hasn't approved or doesn't know about: usually personal accounts on consumer tools, often with real client data.

Research suggests over 80% of workers use unapproved AI tools, and senior people are the heaviest users; a ban does not stop the use, it stops the reporting. Shadow AI is why an AI register and an approved-tools list are the first governance controls worth building: you cannot review, contract for, or defend processing you do not know is happening.

# Small language model (SLM)

also: small model

A compact AI model, from millions to a few billion parameters, cheap and fast enough to run on ordinary hardware, best at narrow well-defined tasks.

The counter-trend to ever-bigger models, and often the honest answer for classification, extraction and routing. When a vendor insists everything needs a frontier model, they are describing their margin, not your requirement.

# Software factory

also: AI software factory · agentic software factory

A repeatable system for producing software: standardised inputs (written specifications), a defined build path with automated quality control, and consistent outputs, now commonly with AI agents doing the construction under human supervision.

A term with fifty years of history (Hitachi ran one from 1969) that AI made newly literal: agents now do the assembly-line work while humans hold the reviews and gates. When a supplier claims one, the checkable substance is the system, not the slogan: written specs, security gates, logs and monitoring. It is also, in full disclosure, what this site sells; judge ours by the same test.

# Speech-to-text / text-to-speech

also: STT · TTS · transcription

The engines that turn audio into transcripts (STT) and text into natural-sounding voice (TTS), the plumbing under meeting notetakers and voice assistants.

Mature, cheap and commoditised, which is worth knowing when a product’s price implies otherwise. The differentiators worth paying for sit around the engine: speaker labelling, accuracy on your accents and jargon, and what happens to the audio afterwards.

# Structured output

also: JSON mode · schema-constrained output

Forcing a model to answer in an exact machine-readable format, typically JSON matching a schema, instead of free text.

The difference between AI you can wire into systems and AI that writes essays about your data. If a vendor’s product feeds other software, ask whether outputs are schema-enforced or merely requested; our own testing found even frontier models occasionally decorating “JSON only” answers when the format is not enforced.

# Synthetic data

Artificial data generated to resemble real data, used for testing or training when the real thing is sensitive, scarce or regulated.

Legitimately useful for testing systems without touching client records. The caution runs in both directions: synthetic data can quietly encode the biases of whatever generated it, and “trained on synthetic data” is not automatically a privacy guarantee; ask what the generator saw.

# System prompt

The standing instructions a product gives its AI model before your text arrives, defining its role, rules and tone. Users don't see it, but it shapes every answer.

When an AI tool behaves oddly (refusing reasonable requests, adopting a strange persona, ignoring your instructions), the system prompt is often why. For firms building their own AI workflows, the system prompt is where your compliance rules belong (“never state performance figures without a source”, “always flag uncertainty”), which also makes it a document compliance should have sight of.

# Temperature

A setting controlling how predictable an AI model's output is: low temperature gives consistent, conservative answers; high temperature gives varied, more creative ones.

Mostly invisible in finished products, but worth knowing when someone technical says a tool is “non-deterministic”, meaning the same question can produce different answers on different days. For regulated outputs you generally want low temperature and consistency; if a vendor’s tool gives materially different suitability wording on identical inputs, that is a question to raise, and temperature is the vocabulary to raise it in.

# Token

The unit AI models read and write text in (roughly three-quarters of a word in English) and the unit AI usage is metered and billed in.

Tokens appear in pricing conversations. “Token limits” and “per-token pricing” are how vendors pass on their own model costs, and generous-sounding allowances can be smaller than they look once documents are involved: a fifty-page PDF is tens of thousands of tokens before anyone asks a question. If a quote is usage-based, ask for the assumed monthly token volume in plain terms: how many documents, how many queries.

# Tool use / function calling

also: function calling · tool calling

The mechanism that lets an AI model operate other software: reading your inbox, updating a record, running a search, rather than only producing text.

When a vendor says their AI “integrates with everything”, this is the machinery they mean, and the question that matters is which tools it may use and with whose permissions. Tool access defines what an AI can actually do to your systems, which makes it the real product and the real risk. Ask for the list.

# Transformer

The neural-network architecture behind modern AI models: introduced by Google researchers in 2017, it processes language by weighing how every word relates to every other, and is the T in GPT.

You never need to configure one, but the word explains the family resemblance between every modern AI tool: they are almost all transformers at different scales. When a vendor claims a “proprietary architecture”, the honest question is what they changed and what it measurably does.

# Vector database

also: vector store

A database that stores content by meaning rather than keywords, so a search for "late payment" also finds "overdue invoice".

The plumbing under most “chat with your documents” products. It matters to a buyer for one reason: this is where a copy of your documents lives, so the usual questions apply, where is it hosted, who can read it, and what happens to it when you leave.

# Vibe coding

Building software by describing what you want to an AI and iterating on what appears, without reading the code it writes.

Fine for prototypes and personal tools, and the fastest way ever invented to hand a business system security holes nobody has looked at. The professional version keeps the speed and adds review, tests and gates; if a supplier’s process IS vibe coding, that is your finding.

# Voice mode

Talking to an AI assistant and hearing it answer, in real time conversation rather than typed prompts.

Genuinely useful for capture on the move and hands-busy work, and the same rules apply as for typing: it is still a prompt, the tier’s data terms still govern it, and dictating client details into a personal account is the same incident as pasting them.

# Webhook

A message one system sends another the moment something happens, the plumbing that lets "when X occurs, do Y" work in real time.

The word that appears the moment automations get real. If a product supports webhooks, it can trigger and be triggered by your other systems; if it does not, your “integration” is a scheduled import wearing a nicer name.

# Zero data retention

also: ZDR

A vendor commitment that your prompts and outputs are not stored after processing completes, usually offered on API and enterprise tiers.

One of the strongest data commitments you can get, and worth asking for by name for sensitive workloads. Check the boundaries: it typically excludes abuse monitoring buffers, and it is a tier feature, not a default, so get it in the contract rather than the sales call.

# Zero-shot / few-shot

Zero-shot: an AI model doing a task from instructions alone, with no examples. Few-shot: giving it a handful of examples in the prompt to copy the pattern of.

Useful mainly as a reality check on capability claims. “Works out of the box on your documents” is a zero-shot claim, and quality usually jumps when a system is shown a few of your firm’s real examples instead. In evaluation, test tools on your formats with your examples; a few-shot setup that fits your templates beats a zero-shot demo that fits the vendor’s.

Missing a term you've been pitched? Tell me and it will be in next week's update. For how these terms play out in practice, the AI governance series is the companion reading.

Get the weekly journal

One email a week on AI and automation for financial services firms. No spam, unsubscribe anytime.

Got a question instead?