Glossary
The agentic finance glossary
164 terms in 14 categories, in plain English, each with its official or specification source. One term a day is explained in «Agent Minute». Nothing here is legal advice.
Agents and autonomy 14 terms
AI systemA machine-based system that infers from its inputs how to generate outputs such as predictions, content, recommendations or decisions.AI agentSoftware built on an AI model that pursues a set goal by planning steps and acting through tools or APIs, not only by answering.Large language modelA model trained on very large amounts of text to predict likely text, used by most agents to interpret instructions and choose steps.PrincipalThe person or organisation on whose behalf an agent acts and whose authority the agent exercises.Tool useA model asking its host application to run a named function with structured arguments, then receiving the result.Electronic agentUnder US E-SIGN, a program or automated means that acts or responds without a person reviewing it at the time.Level of autonomyHow far an agent acts without a person reviewing each step, from suggesting actions to acting alone within limits.Multi-agent systemSeveral agents that divide a task between them and exchange work through a protocol.Retrieval-augmented generationRetrieving relevant documents or records first and giving them to the model, so its answer rests on current material.System promptThe standing instructions an operator gives a model before any user input, describing its role, rules and tools.Agent frameworkA software library for building and running agents: the model loop, tools, delegation, approvals and tracing.Supervisor agentAn agent that owns a task and calls specialist agents for bounded subtasks, then combines their results.Agent handoffPassing control of a conversation from one agent to a specialist agent, which then takes over the turn.Agent trajectoryThe sequence of steps an agent takes to reach a result, such as which tools it called and in what order.
Mandates and authorisation 10 terms
MandateA checkable statement of what an agent may do for a principal: which action, how much, with whom and until when.OAuth scopeA value in an OAuth request naming the range of access a client asks for; the server may grant all, part or none of it.Spend limitA cap on how much an agent may pay, enforced by the system that executes the payment, not by the agent.Mandate expiryThe point after which a mandate no longer authorises anything, as a fixed end time or on completion of a task.RevocationThe principal withdrawing a mandate or consent before it expires, after which no one may act on it.Variable recurring paymentA series of payments made under one standing consent, within limits such as a maximum per payment and per period.Open mandateIn AP2, a mandate not yet bound to one action, carrying the user's constraints for the agent to act within.Closed mandateIn AP2, a mandate bound to one specific action, such as a finalised checkout or a specific amount.Rich Authorization RequestsAn OAuth extension that carries structured details of the action being authorised, such as amount and payee.Token exchangeAn OAuth protocol for swapping one security token for another, recording when one party acts on behalf of another.
Consent and data rights 11 terms
Personal dataAny information relating to an identified or identifiable living person.ConsentA freely given, specific, informed and unambiguous indication of a person's agreement to the processing of their data.Lawful basisOne of the six grounds in the GDPR that make processing personal data lawful, of which consent is only one.Purpose limitationCollecting personal data for specified, explicit and legitimate purposes and not reusing it in incompatible ways.Data minimisationUsing personal data that is adequate, relevant and limited to what is necessary for the purpose.Withdrawal of consentA person's right to withdraw consent at any time, as easily as they gave it.Authorized third partyUnder the US data rights rule, a third party that has met the authorisation procedure to access a consumer's data.Permission dashboardA place where a customer sees and withdraws the data-access permissions they have granted.Data portabilityA person's right to receive their data in a structured, machine-readable format and have it sent to another controller.Automated individual decision-makingA decision about a person made solely by automated means that has legal or similarly significant effects.Authorization disclosure (Section 1033)The signed disclosure through which a US consumer gives a third party express informed consent to access their data.
Agent identity (KYA) 12 terms
Digital identityThe unique representation of a subject, such as a person or organisation, engaged in an online transaction.Identity proofingCollecting, validating and verifying information about a person to establish that they are who they claim to be.Know Your Agent (KYA)Checking which agent is acting, who operates it and whom it acts for, before letting it act.Agent cardIn A2A, a published description of an agent's identity, skills, endpoint and authentication requirements.Identity assurance levelA NIST measure of how rigorously a person's claimed identity was proofed.Authenticator assurance levelA NIST measure of how strongly an authentication process confirms that the same subject is returning.Verifiable credentialA tamper-evident set of claims by an issuer, held by a holder and cryptographically checkable by a verifier.Decentralized identifier (DID)A W3C identifier the controller creates and controls, resolving to a document that lists keys and endpoints.European Digital Identity WalletAn EU wallet app, provided under the European Digital Identity Regulation, for storing and presenting identity data and attestations.HTTP Message SignaturesAn IETF standard for signing selected parts of an HTTP request or response so the receiver can verify them.Beneficial ownerUnder the US CDD rule, an individual who owns a quarter or more of a legal entity, or who controls it.Legal Entity Identifier (LEI)A unique twenty-character code that identifies a legal entity and links to verified reference data about it.
Agent payments 15 terms
Payment service providerA firm authorised to provide payment services, such as a bank, an e-money institution or a payment institution.Payment accountAn account held in the name of one or more payment service users and used to execute payment transactions.Payment initiation serviceA service that initiates a payment order at the user's request from an account held at another provider.Account servicing payment service providerThe provider that provides and maintains the payer's payment account, typically the customer's bank.Credit transferA payment pushed from the payer's account to the payee's account on the payer's instruction.Direct debitA payment collected by the payee from the payer's account on the basis of the payer's prior consent.Instant paymentA credit transfer executed within seconds, at any time of day, every day of the year.Payment tokenA substitute value that replaces a card number, usable only in a defined domain such as one device or merchant.Agent tokenA payment credential issued for use by a specific agent, which can be limited and revoked without replacing the card.Settlement finalityThe point at which a transfer becomes irrevocable and unconditional, so it cannot be unwound.Verification of payeeA check, before a credit transfer, that the payee's name matches the account the money will go to.Confirmation of PayeeThe UK account name-checking service, run by Pay.UK, that compares the payee name with the receiving account.SweepingAutomatically moving money between a customer's own accounts, for example surplus funds into savings.Remittance transferIn US Regulation E, an electronic transfer of funds from a consumer to a recipient abroad through a provider.Preauthorized transferIn US Regulation E, an electronic transfer authorised in advance to recur at substantially regular intervals.
Agent protocols 12 terms
Model Context Protocol (MCP)An open protocol for connecting AI applications to external tools and data through servers that expose them.MCP serverA service that exposes resources, prompts and tools to AI applications through the Model Context Protocol.MCP resourceContext or data that an MCP server exposes, identified by a URI, for the user or the model to read.Agent2Agent protocol (A2A)An open protocol for independent agents to discover each other and exchange tasks, messages and results.A2A taskThe fundamental unit of work in A2A, with a unique ID and a defined lifecycle of states.Agent Payments Protocol (AP2)An open protocol for agent payments built on signed mandates, available as an extension to A2A.Agentic Commerce Protocol (ACP)An open specification for checkout between buyers, their AI agents and sellers, with delegated payment tokens.x402An open standard for requesting and making payment inside an HTTP exchange, using the Payment Required status.Trusted Agent ProtocolVisa's specification for signals that let merchants recognise trusted commerce agents and the consumer behind them.Web Bot AuthIETF work on cryptographically authenticating automated clients, including agents, to websites.MCP authorizationThe MCP specification's OAuth-based framework for protecting servers reached over HTTP.MCP elicitationAn MCP client feature that lets a server ask the user for information, by form or by sending them to a URL.
Authentication and security 11 terms
Strong customer authenticationAuthentication using two or more independent elements from knowledge, possession and inherence.Dynamic linkingBinding an authentication code to a specific amount and payee so it cannot authorise a different payment.OAuth 2.0The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.DPoPAn OAuth mechanism that binds a token to a key the client holds, so a stolen token cannot be used alone.Client-Initiated Backchannel Authentication (CIBA)An OpenID flow where an app requests a user's approval, and the user approves on a separate device.FAPI 2.0 Security ProfileAn OpenID Foundation profile of OAuth for high-value APIs, such as open banking, with stricter security.PasskeyA phishing-resistant sign-in credential based on FIDO standards, unlocked with the device's biometrics or PIN.Secure Payment ConfirmationA W3C web standard for confirming a payment's details with a WebAuthn credential, producing signed evidence.EMV 3-D SecureThe EMVCo protocol for authenticating cardholders in online card payments, with frictionless and challenge flows.Idempotency keyA unique value sent with a request so that a retry is recognised and not carried out twice.
Governance and model risk 11 terms
Model riskThe potential for adverse consequences from decisions based on model outputs, including misuse of a sound model.Model validationEvaluating whether a model performs as expected, including its reliability and its limitations.Effective challengeCritical, objective analysis of a model by experts with the independence and standing to force changes.Ongoing monitoringContinuing checks that a model or agent is still performing as intended as data, use and conditions change.Model inventoryA firm-wide record of the models in development or in use, with enough detail to understand their risks.Human oversightMeasures that let people understand, monitor and, when needed, override or stop a high-risk AI system.Change managementControlling changes to a model or agent so each change is assessed, approved, recorded and reversible.Third-party risk managementManaging the risks of relying on outside providers across the relationship, from due diligence to exit.AI Risk Management FrameworkNIST's voluntary framework for managing AI risks, organised into the functions Govern, Map, Measure and Manage.AI management systemAn organisation's policies, processes and controls for developing or using AI responsibly, as specified by ISO/IEC 42001.Register of information (DORA)DORA's required record of every contract for ICT services from third-party providers, by function.
Liability and disputes 11 terms
Unauthorised payment transactionA payment the payer did not consent to; in the EU and UK the payer's provider must generally refund it promptly.Unauthorized electronic fund transferUnder US Regulation E, a transfer started by someone without actual authority, from which the consumer gets no benefit.Error resolutionRegulation E's procedure for a consumer to report an error on an account and for the institution to investigate.Billing errorUnder US Regulation Z, a credit card charge a consumer disputes, such as goods not delivered as agreed.ChargebackA card scheme process that reverses a card payment back to the cardholder's issuer after a valid dispute.Gross negligenceA serious failure of care by a payer that can shift losses from unauthorised payments onto them.APP fraud reimbursementUK rules requiring payment firms to reimburse victims of authorised push payment scams, within set conditions.Consumer standard of cautionThe UK APP reimbursement exception for consumers who, with gross negligence, ignore specific expectations.Defective executionA payment that is not executed, or executed late or incorrectly; the rules set which provider is liable.Direct debit refund rightThe EU payer's right to a refund of an authorised direct debit within a set period, under set conditions.Stop-payment orderA consumer's instruction to their bank not to make a scheduled preauthorized debit from their account.
AI regulation 11 terms
EU AI ActThe EU regulation that sets risk-based rules for AI systems and general-purpose AI models placed on the EU market.AI literacyThe skills, knowledge and understanding needed to deploy AI in an informed way and to be aware of its risks.Prohibited AI practiceAn AI use the EU AI Act bans outright, such as harmful manipulation, exploiting vulnerabilities or social scoring.High-risk AI systemAn AI system the EU AI Act classes as high-risk, such as credit scoring, which must meet strict requirements.Provider (AI Act)Under the AI Act, whoever develops an AI system or model, or has it developed, and places it on the market under its name.Deployer (AI Act)Under the AI Act, a person or organisation using an AI system under its authority, outside purely personal use.AI transparency obligationThe AI Act duty to tell people they are interacting with an AI system, and to mark certain AI-generated content.General-purpose AI modelUnder the AI Act, a model with significant generality that can perform a wide range of distinct tasks.Conformity assessmentThe process of demonstrating that a high-risk AI system meets the AI Act's requirements before it is used.Fundamental rights impact assessmentAn assessment certain deployers must do before using a high-risk AI system, covering its impact on people's rights.AI OmnibusThe EU regulation that amended the AI Act's timeline for high-risk rules and simplified some of its duties.
Open banking and open finance 11 terms
Open bankingCustomers letting authorised third parties access their payment account data and initiate payments through secure APIs.Open financeExtending open banking's customer-permissioned data sharing beyond payment accounts to savings, credit, investments and insurance.Account information serviceAn online service providing consolidated information on a user's payment accounts held with other providers.Third-party provider (TPP)The common name for providers that access accounts held elsewhere, such as account information and payment initiation providers.Data providerUnder the US data rights rule, a covered firm that must make consumer financial data available on request.UK Open Banking StandardThe UK's API specifications, security profile and customer experience guidelines for open banking.NextGenPSD2The Berlin Group's common API framework for access to accounts under PSD2, used widely in the European Union.Financial data access framework (FIDA)The European Commission's proposed regulation on customer-permissioned access to financial data beyond payment accounts.Regulatory sandboxA supervised programme where firms test new financial products with real customers under agreed safeguards.Screen scrapingA third party logging in with a customer's credentials to read data from the bank's customer interface.Account aggregationBringing a customer's accounts from several providers into one view, ideally through regulated data access.
Evidence and audit 11 terms
Audit trailA chronological record of who accessed a system and what operations they performed, enough to reconstruct events.Automatic loggingBuilt-in recording of events while a high-risk AI system runs, so its operation can be traced afterwards.Record retentionKeeping records that evidence compliance for a minimum period, so they are available to supervisors and in disputes.Technical documentationThe AI Act file a provider must draw up and keep current to show a high-risk system meets the requirements.ExplainabilityThe degree to which the mechanisms behind an AI system's output can be described in terms people understand.Adverse action noticeA US notice telling a credit applicant about an adverse decision and the specific principal reasons for it.Post-market monitoringA provider's ongoing collection and review of experience from a deployed AI system, to find and fix problems.Serious incidentUnder the AI Act, an AI malfunction leading to death or serious harm, infrastructure disruption, rights infringement or major damage.Evidence packA bundle of records that reconstructs one agent action: identity, mandate, authentication, inputs, calls, outputs and approvals.Tamper-evident logA log built so that any later change, deletion or reordering of entries can be detected.Agent traceA record of one agent run, made of spans for model calls, tool calls, handoffs and other steps.
Commerce and checkout 13 terms
Agentic commerceBuying and selling in which an AI agent finds, selects or pays for goods and services on a customer's behalf.Merchant of recordThe business legally selling to the customer and responsible for the payment, refunds, taxes and disputes.Card-not-present transactionA card payment where the card is not physically presented to the merchant, such as online or in-app.Merchant-initiated transactionA card payment the merchant initiates without the cardholder present, under an agreement made earlier.Agentic checkoutA checkout an agent completes through a structured API with the seller, instead of operating the seller's website.Checkout sessionIn ACP, the stateful object an agent and seller update together, from items and options to completion.Delegated paymentGiving an agent a payment token limited by an allowance, such as amount, currency, merchant and expiry.Checkout MandateIn AP2, the mandate that authorises completing a checkout, bound in its closed form to a merchant-signed cart.Payment MandateIn AP2, the mandate that authorises payment for a checkout, verified by the credential provider, network and processor.Human-not-present transactionA purchase an agent completes while the user is absent, relying on authority the user granted in advance.Trusted surfaceIn AP2, a secure, non-agentic interface that shows mandate content to the user for authorisation and consent.Credentials providerIn AP2, a secure entity such as a digital wallet that manages and executes the user's payment and identity credentials.Checkout receiptIn AP2, a record of a checkout's outcome that references the closed mandate it binds to.
AI risks and safety 11 terms
Prompt injectionAn attack that alters what a model receives so that it follows the attacker's instructions instead of its user's.Indirect prompt injectionPrompt injection hidden in content an AI system retrieves, such as a web page, document or email.JailbreakA prompting attack designed to get a model to bypass its safety rules or restrictions.ConfabulationConfidently stated but false or erroneous output from a generative AI system, often called hallucination.Automation biasThe tendency of people to rely, or over-rely, on the output of an automated system.Data poisoningAn attack that corrupts the data a model learns from or relies on, to change its behaviour.Excessive agencyGiving an LLM application more functions, permissions or autonomy than needed, so bad outputs cause harmful actions.Model driftA decline in a model's or agent's performance over time as data, users or conditions change.Sensitive information disclosureAn AI system revealing personal, confidential or security data through its outputs, logs or tool calls.Red-teamingStructured adversarial testing of an AI system to find flaws, harmful behaviours and vulnerabilities before attackers do.Unbounded consumptionExcessive, uncontrolled use of an AI service that degrades it or runs up costs, including denial of wallet.
No matching term.