# AgenticOpenFinance

> Agent-native infrastructure for open finance: guides, analysis, podcasts and a glossary on AI agents acting in finance, with mandates, limits, human approval and evidence.

AgenticOpenFinance is agent-native infrastructure for open finance: identity for AI agents, mandates and limits, human approval, payments and sealed evidence. This site publishes guides, analysis, podcasts and a glossary on agentic finance, each with its official or specification sources. English, Gregorian dates, UTC. All demo companies, people, agents and amounts are fictional.

Language: en-GB (ltr). Site: https://agenticopenfinance.com

## Pages
- [Blog](https://agenticopenfinance.com/blog/): A weekly topic every Monday, the parallel series on their own weekdays and a monthly report with the UK, US and euro-area business days, each with its official or specification sources. (RSS: https://agenticopenfinance.com/blog/feed.xml)
- [Podcast](https://agenticopenfinance.com/podcasts/): Agent Minute, the AgenticOpenFinance podcast (feed: https://agenticopenfinance.com/podcasts/daily/feed.xml); Two Minutes of Agentic Finance, the AgenticOpenFinance podcast (feed: https://agenticopenfinance.com/podcasts/feed.xml); Licences, Plainly, the AgenticOpenFinance podcast (feed: https://agenticopenfinance.com/podcasts/licensing/feed.xml); On the Wire, the AgenticOpenFinance podcast (feed: https://agenticopenfinance.com/podcasts/protocols/feed.xml); Rulebook for Agents, the AgenticOpenFinance podcast (feed: https://agenticopenfinance.com/podcasts/regulation/feed.xml); Agentic Commerce, the AgenticOpenFinance podcast (feed: https://agenticopenfinance.com/podcasts/commerce/feed.xml); Orchestration and Use Cases, the AgenticOpenFinance podcast (feed: https://agenticopenfinance.com/podcasts/orchestration/feed.xml)
- [Glossary](https://agenticopenfinance.com/glossary/): 164 terms in 14 categories, each with a plain definition.
- [Events](https://agenticopenfinance.com/events/): Hands-on sessions in the lab, protocol walk-throughs and conversations with banks, payment firms and regulators' innovation teams. Register and add each event to your calendar here.
- [Terminal](https://agenticopenfinance.com/terminal/): Every governed agent action in one place: an interactive demo with fictional data.
- [Lab](https://agenticopenfinance.com/lab/): Missions that run the agent, mandate, approval and evidence flow in the browser, on fictional data.
- [Academy](https://agenticopenfinance.com/academy/): Learning paths, workshops and webinars on agentic finance.
- [Sectors](https://agenticopenfinance.com/sectors/): What agents may do in each sector, who is in the chain and how each action is checked.
- [Directory](https://agenticopenfinance.com/directory/): Regulators, standards bodies and protocol publishers of agentic finance, each with its official source.
- [Partners](https://agenticopenfinance.com/partners/): Partner programmes for banks, payment firms, agent builders and integrators.
- [Calendar](https://agenticopenfinance.com/calendar/): Bank holidays and business days for the UK, US and euro area, from their official sources.

## APIs
- [Blog JSON](https://agenticopenfinance.com/api/blog/posts)
- [Podcast JSON](https://agenticopenfinance.com/api/podcasts)
- [Glossary JSON](https://agenticopenfinance.com/api/glossary)
- [Term of the day](https://agenticopenfinance.com/api/glossary/today)
- [Events JSON](https://agenticopenfinance.com/api/events)

## Glossary: Agents and autonomy
- [AI system](https://agenticopenfinance.com/glossary/ai-system.md): A machine-based system that infers from its inputs how to generate outputs such as predictions, content, recommendations or decisions.
- [AI agent](https://agenticopenfinance.com/glossary/ai-agent.md): Software built on an AI model that pursues a set goal by planning steps and acting through tools or APIs, not only by answering.
- [Large language model](https://agenticopenfinance.com/glossary/large-language-model.md): A model trained on very large amounts of text to predict likely text, used by most agents to interpret instructions and choose steps.
- [Principal](https://agenticopenfinance.com/glossary/principal.md): The person or organisation on whose behalf an agent acts and whose authority the agent exercises.
- [Tool use](https://agenticopenfinance.com/glossary/tool-use.md): A model asking its host application to run a named function with structured arguments, then receiving the result.
- [Electronic agent](https://agenticopenfinance.com/glossary/electronic-agent.md): Under US E-SIGN, a program or automated means that acts or responds without a person reviewing it at the time.
- [Level of autonomy](https://agenticopenfinance.com/glossary/agent-autonomy.md): How far an agent acts without a person reviewing each step, from suggesting actions to acting alone within limits.
- [Multi-agent system](https://agenticopenfinance.com/glossary/multi-agent-system.md): Several agents that divide a task between them and exchange work through a protocol.
- [Retrieval-augmented generation](https://agenticopenfinance.com/glossary/retrieval-augmented-generation.md): Retrieving relevant documents or records first and giving them to the model, so its answer rests on current material.
- [System prompt](https://agenticopenfinance.com/glossary/system-prompt.md): The standing instructions an operator gives a model before any user input, describing its role, rules and tools.
- [Agent framework](https://agenticopenfinance.com/glossary/agent-framework.md): A software library for building and running agents: the model loop, tools, delegation, approvals and tracing.
- [Supervisor agent](https://agenticopenfinance.com/glossary/supervisor-agent.md): An agent that owns a task and calls specialist agents for bounded subtasks, then combines their results.
- [Agent handoff](https://agenticopenfinance.com/glossary/agent-handoff.md): Passing control of a conversation from one agent to a specialist agent, which then takes over the turn.
- [Agent trajectory](https://agenticopenfinance.com/glossary/agent-trajectory.md): The sequence of steps an agent takes to reach a result, such as which tools it called and in what order.

## Glossary: Mandates and authorisation
- [Mandate](https://agenticopenfinance.com/glossary/mandate.md): A checkable statement of what an agent may do for a principal: which action, how much, with whom and until when.
- [OAuth scope](https://agenticopenfinance.com/glossary/oauth-scope.md): A value in an OAuth request naming the range of access a client asks for; the server may grant all, part or none of it.
- [Spend limit](https://agenticopenfinance.com/glossary/spend-limit.md): A cap on how much an agent may pay, enforced by the system that executes the payment, not by the agent.
- [Mandate expiry](https://agenticopenfinance.com/glossary/mandate-expiry.md): The point after which a mandate no longer authorises anything, as a fixed end time or on completion of a task.
- [Revocation](https://agenticopenfinance.com/glossary/mandate-revocation.md): The principal withdrawing a mandate or consent before it expires, after which no one may act on it.
- [Variable recurring payment](https://agenticopenfinance.com/glossary/variable-recurring-payment.md): A series of payments made under one standing consent, within limits such as a maximum per payment and per period.
- [Open mandate](https://agenticopenfinance.com/glossary/open-mandate.md): In AP2, a mandate not yet bound to one action, carrying the user's constraints for the agent to act within.
- [Closed mandate](https://agenticopenfinance.com/glossary/closed-mandate.md): In AP2, a mandate bound to one specific action, such as a finalised checkout or a specific amount.
- [Rich Authorization Requests](https://agenticopenfinance.com/glossary/rich-authorization-request.md): An OAuth extension that carries structured details of the action being authorised, such as amount and payee.
- [Token exchange](https://agenticopenfinance.com/glossary/token-exchange.md): An OAuth protocol for swapping one security token for another, recording when one party acts on behalf of another.

## Glossary: Consent and data rights
- [Personal data](https://agenticopenfinance.com/glossary/personal-data.md): Any information relating to an identified or identifiable living person.
- [Consent](https://agenticopenfinance.com/glossary/consent.md): A freely given, specific, informed and unambiguous indication of a person's agreement to the processing of their data.
- [Lawful basis](https://agenticopenfinance.com/glossary/lawful-basis.md): One of the six grounds in the GDPR that make processing personal data lawful, of which consent is only one.
- [Purpose limitation](https://agenticopenfinance.com/glossary/purpose-limitation.md): Collecting personal data for specified, explicit and legitimate purposes and not reusing it in incompatible ways.
- [Data minimisation](https://agenticopenfinance.com/glossary/data-minimisation.md): Using personal data that is adequate, relevant and limited to what is necessary for the purpose.
- [Withdrawal of consent](https://agenticopenfinance.com/glossary/consent-withdrawal.md): A person's right to withdraw consent at any time, as easily as they gave it.
- [Authorized third party](https://agenticopenfinance.com/glossary/authorised-third-party.md): Under the US data rights rule, a third party that has met the authorisation procedure to access a consumer's data.
- [Permission dashboard](https://agenticopenfinance.com/glossary/permission-dashboard.md): A place where a customer sees and withdraws the data-access permissions they have granted.
- [Data portability](https://agenticopenfinance.com/glossary/data-portability.md): A person's right to receive their data in a structured, machine-readable format and have it sent to another controller.
- [Automated individual decision-making](https://agenticopenfinance.com/glossary/automated-individual-decision.md): A decision about a person made solely by automated means that has legal or similarly significant effects.
- [Authorization disclosure (Section 1033)](https://agenticopenfinance.com/glossary/authorization-disclosure.md): The signed disclosure through which a US consumer gives a third party express informed consent to access their data.

## Glossary: Agent identity (KYA)
- [Digital identity](https://agenticopenfinance.com/glossary/digital-identity.md): The unique representation of a subject, such as a person or organisation, engaged in an online transaction.
- [Identity proofing](https://agenticopenfinance.com/glossary/identity-proofing.md): Collecting, validating and verifying information about a person to establish that they are who they claim to be.
- [Know Your Agent (KYA)](https://agenticopenfinance.com/glossary/know-your-agent.md): Checking which agent is acting, who operates it and whom it acts for, before letting it act.
- [Agent card](https://agenticopenfinance.com/glossary/agent-card.md): In A2A, a published description of an agent's identity, skills, endpoint and authentication requirements.
- [Identity assurance level](https://agenticopenfinance.com/glossary/identity-assurance-level.md): A NIST measure of how rigorously a person's claimed identity was proofed.
- [Authenticator assurance level](https://agenticopenfinance.com/glossary/authenticator-assurance-level.md): A NIST measure of how strongly an authentication process confirms that the same subject is returning.
- [Verifiable credential](https://agenticopenfinance.com/glossary/verifiable-credential.md): A tamper-evident set of claims by an issuer, held by a holder and cryptographically checkable by a verifier.
- [Decentralized identifier (DID)](https://agenticopenfinance.com/glossary/decentralized-identifier.md): A W3C identifier the controller creates and controls, resolving to a document that lists keys and endpoints.
- [European Digital Identity Wallet](https://agenticopenfinance.com/glossary/digital-identity-wallet.md): An EU wallet app, provided under the European Digital Identity Regulation, for storing and presenting identity data and attestations.
- [HTTP Message Signatures](https://agenticopenfinance.com/glossary/http-message-signatures.md): An IETF standard for signing selected parts of an HTTP request or response so the receiver can verify them.
- [Beneficial owner](https://agenticopenfinance.com/glossary/beneficial-owner.md): Under the US CDD rule, an individual who owns a quarter or more of a legal entity, or who controls it.
- [Legal Entity Identifier (LEI)](https://agenticopenfinance.com/glossary/legal-entity-identifier.md): A unique twenty-character code that identifies a legal entity and links to verified reference data about it.

## Glossary: Agent payments
- [Payment service provider](https://agenticopenfinance.com/glossary/payment-service-provider.md): A firm authorised to provide payment services, such as a bank, an e-money institution or a payment institution.
- [Payment account](https://agenticopenfinance.com/glossary/payment-account.md): An account held in the name of one or more payment service users and used to execute payment transactions.
- [Payment initiation service](https://agenticopenfinance.com/glossary/payment-initiation-service.md): A service that initiates a payment order at the user's request from an account held at another provider.
- [Account servicing payment service provider](https://agenticopenfinance.com/glossary/account-servicing-psp.md): The provider that provides and maintains the payer's payment account, typically the customer's bank.
- [Credit transfer](https://agenticopenfinance.com/glossary/credit-transfer.md): A payment pushed from the payer's account to the payee's account on the payer's instruction.
- [Direct debit](https://agenticopenfinance.com/glossary/direct-debit.md): A payment collected by the payee from the payer's account on the basis of the payer's prior consent.
- [Instant payment](https://agenticopenfinance.com/glossary/instant-payment.md): A credit transfer executed within seconds, at any time of day, every day of the year.
- [Payment token](https://agenticopenfinance.com/glossary/payment-token.md): A substitute value that replaces a card number, usable only in a defined domain such as one device or merchant.
- [Agent token](https://agenticopenfinance.com/glossary/agent-token.md): A payment credential issued for use by a specific agent, which can be limited and revoked without replacing the card.
- [Settlement finality](https://agenticopenfinance.com/glossary/settlement-finality.md): The point at which a transfer becomes irrevocable and unconditional, so it cannot be unwound.
- [Verification of payee](https://agenticopenfinance.com/glossary/verification-of-payee.md): A check, before a credit transfer, that the payee's name matches the account the money will go to.
- [Confirmation of Payee](https://agenticopenfinance.com/glossary/confirmation-of-payee.md): The UK account name-checking service, run by Pay.UK, that compares the payee name with the receiving account.
- [Sweeping](https://agenticopenfinance.com/glossary/sweeping.md): Automatically moving money between a customer's own accounts, for example surplus funds into savings.
- [Remittance transfer](https://agenticopenfinance.com/glossary/remittance-transfer.md): In US Regulation E, an electronic transfer of funds from a consumer to a recipient abroad through a provider.
- [Preauthorized transfer](https://agenticopenfinance.com/glossary/preauthorized-transfer.md): In US Regulation E, an electronic transfer authorised in advance to recur at substantially regular intervals.

## Glossary: Agent protocols
- [Model Context Protocol (MCP)](https://agenticopenfinance.com/glossary/model-context-protocol.md): An open protocol for connecting AI applications to external tools and data through servers that expose them.
- [MCP server](https://agenticopenfinance.com/glossary/mcp-server.md): A service that exposes resources, prompts and tools to AI applications through the Model Context Protocol.
- [MCP resource](https://agenticopenfinance.com/glossary/mcp-resource.md): Context or data that an MCP server exposes, identified by a URI, for the user or the model to read.
- [Agent2Agent protocol (A2A)](https://agenticopenfinance.com/glossary/agent2agent-protocol.md): An open protocol for independent agents to discover each other and exchange tasks, messages and results.
- [A2A task](https://agenticopenfinance.com/glossary/a2a-task.md): The fundamental unit of work in A2A, with a unique ID and a defined lifecycle of states.
- [Agent Payments Protocol (AP2)](https://agenticopenfinance.com/glossary/agent-payments-protocol.md): An open protocol for agent payments built on signed mandates, available as an extension to A2A.
- [Agentic Commerce Protocol (ACP)](https://agenticopenfinance.com/glossary/agentic-commerce-protocol.md): An open specification for checkout between buyers, their AI agents and sellers, with delegated payment tokens.
- [x402](https://agenticopenfinance.com/glossary/x402.md): An open standard for requesting and making payment inside an HTTP exchange, using the Payment Required status.
- [Trusted Agent Protocol](https://agenticopenfinance.com/glossary/trusted-agent-protocol.md): Visa's specification for signals that let merchants recognise trusted commerce agents and the consumer behind them.
- [Web Bot Auth](https://agenticopenfinance.com/glossary/web-bot-auth.md): IETF work on cryptographically authenticating automated clients, including agents, to websites.
- [MCP authorization](https://agenticopenfinance.com/glossary/mcp-authorization.md): The MCP specification's OAuth-based framework for protecting servers reached over HTTP.
- [MCP elicitation](https://agenticopenfinance.com/glossary/mcp-elicitation.md): An MCP client feature that lets a server ask the user for information, by form or by sending them to a URL.

## Glossary: Authentication and security
- [Strong customer authentication](https://agenticopenfinance.com/glossary/strong-customer-authentication.md): Authentication using two or more independent elements from knowledge, possession and inherence.
- [Dynamic linking](https://agenticopenfinance.com/glossary/dynamic-linking.md): Binding an authentication code to a specific amount and payee so it cannot authorise a different payment.
- [OAuth 2.0](https://agenticopenfinance.com/glossary/oauth-2.md): The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.
- [Access token](https://agenticopenfinance.com/glossary/access-token.md): A credential a client presents to access protected resources, representing a specific, limited authorisation.
- [DPoP](https://agenticopenfinance.com/glossary/dpop.md): An OAuth mechanism that binds a token to a key the client holds, so a stolen token cannot be used alone.
- [Client-Initiated Backchannel Authentication (CIBA)](https://agenticopenfinance.com/glossary/ciba.md): An OpenID flow where an app requests a user's approval, and the user approves on a separate device.
- [FAPI 2.0 Security Profile](https://agenticopenfinance.com/glossary/fapi-2.md): An OpenID Foundation profile of OAuth for high-value APIs, such as open banking, with stricter security.
- [Passkey](https://agenticopenfinance.com/glossary/passkey.md): A phishing-resistant sign-in credential based on FIDO standards, unlocked with the device's biometrics or PIN.
- [Secure Payment Confirmation](https://agenticopenfinance.com/glossary/secure-payment-confirmation.md): A W3C web standard for confirming a payment's details with a WebAuthn credential, producing signed evidence.
- [EMV 3-D Secure](https://agenticopenfinance.com/glossary/emv-3-d-secure.md): The EMVCo protocol for authenticating cardholders in online card payments, with frictionless and challenge flows.
- [Idempotency key](https://agenticopenfinance.com/glossary/idempotency-key.md): A unique value sent with a request so that a retry is recognised and not carried out twice.

## Glossary: Governance and model risk
- [Model risk](https://agenticopenfinance.com/glossary/model-risk.md): The potential for adverse consequences from decisions based on model outputs, including misuse of a sound model.
- [Model validation](https://agenticopenfinance.com/glossary/model-validation.md): Evaluating whether a model performs as expected, including its reliability and its limitations.
- [Effective challenge](https://agenticopenfinance.com/glossary/effective-challenge.md): Critical, objective analysis of a model by experts with the independence and standing to force changes.
- [Ongoing monitoring](https://agenticopenfinance.com/glossary/ongoing-monitoring.md): Continuing checks that a model or agent is still performing as intended as data, use and conditions change.
- [Model inventory](https://agenticopenfinance.com/glossary/model-inventory.md): A firm-wide record of the models in development or in use, with enough detail to understand their risks.
- [Human oversight](https://agenticopenfinance.com/glossary/human-oversight.md): Measures that let people understand, monitor and, when needed, override or stop a high-risk AI system.
- [Change management](https://agenticopenfinance.com/glossary/change-management.md): Controlling changes to a model or agent so each change is assessed, approved, recorded and reversible.
- [Third-party risk management](https://agenticopenfinance.com/glossary/third-party-risk-management.md): Managing the risks of relying on outside providers across the relationship, from due diligence to exit.
- [AI Risk Management Framework](https://agenticopenfinance.com/glossary/ai-risk-management-framework.md): NIST's voluntary framework for managing AI risks, organised into the functions Govern, Map, Measure and Manage.
- [AI management system](https://agenticopenfinance.com/glossary/ai-management-system.md): An organisation's policies, processes and controls for developing or using AI responsibly, as specified by ISO/IEC 42001.
- [Register of information (DORA)](https://agenticopenfinance.com/glossary/ict-third-party-register.md): DORA's required record of every contract for ICT services from third-party providers, by function.

## Glossary: Liability and disputes
- [Unauthorised payment transaction](https://agenticopenfinance.com/glossary/unauthorised-payment-transaction.md): A payment the payer did not consent to; in the EU and UK the payer's provider must generally refund it promptly.
- [Unauthorized electronic fund transfer](https://agenticopenfinance.com/glossary/unauthorized-electronic-fund-transfer.md): Under US Regulation E, a transfer started by someone without actual authority, from which the consumer gets no benefit.
- [Error resolution](https://agenticopenfinance.com/glossary/error-resolution.md): Regulation E's procedure for a consumer to report an error on an account and for the institution to investigate.
- [Billing error](https://agenticopenfinance.com/glossary/billing-error.md): Under US Regulation Z, a credit card charge a consumer disputes, such as goods not delivered as agreed.
- [Chargeback](https://agenticopenfinance.com/glossary/chargeback.md): A card scheme process that reverses a card payment back to the cardholder's issuer after a valid dispute.
- [Gross negligence](https://agenticopenfinance.com/glossary/gross-negligence.md): A serious failure of care by a payer that can shift losses from unauthorised payments onto them.
- [APP fraud reimbursement](https://agenticopenfinance.com/glossary/app-fraud-reimbursement.md): UK rules requiring payment firms to reimburse victims of authorised push payment scams, within set conditions.
- [Consumer standard of caution](https://agenticopenfinance.com/glossary/consumer-standard-of-caution.md): The UK APP reimbursement exception for consumers who, with gross negligence, ignore specific expectations.
- [Defective execution](https://agenticopenfinance.com/glossary/defective-execution.md): A payment that is not executed, or executed late or incorrectly; the rules set which provider is liable.
- [Direct debit refund right](https://agenticopenfinance.com/glossary/direct-debit-refund.md): The EU payer's right to a refund of an authorised direct debit within a set period, under set conditions.
- [Stop-payment order](https://agenticopenfinance.com/glossary/stop-payment-order.md): A consumer's instruction to their bank not to make a scheduled preauthorized debit from their account.

## Glossary: AI regulation
- [EU AI Act](https://agenticopenfinance.com/glossary/eu-ai-act.md): The EU regulation that sets risk-based rules for AI systems and general-purpose AI models placed on the EU market.
- [AI literacy](https://agenticopenfinance.com/glossary/ai-literacy.md): The skills, knowledge and understanding needed to deploy AI in an informed way and to be aware of its risks.
- [Prohibited AI practice](https://agenticopenfinance.com/glossary/prohibited-ai-practice.md): An AI use the EU AI Act bans outright, such as harmful manipulation, exploiting vulnerabilities or social scoring.
- [High-risk AI system](https://agenticopenfinance.com/glossary/high-risk-ai-system.md): An AI system the EU AI Act classes as high-risk, such as credit scoring, which must meet strict requirements.
- [Provider (AI Act)](https://agenticopenfinance.com/glossary/ai-provider.md): Under the AI Act, whoever develops an AI system or model, or has it developed, and places it on the market under its name.
- [Deployer (AI Act)](https://agenticopenfinance.com/glossary/ai-deployer.md): Under the AI Act, a person or organisation using an AI system under its authority, outside purely personal use.
- [AI transparency obligation](https://agenticopenfinance.com/glossary/ai-transparency-obligation.md): The AI Act duty to tell people they are interacting with an AI system, and to mark certain AI-generated content.
- [General-purpose AI model](https://agenticopenfinance.com/glossary/general-purpose-ai-model.md): Under the AI Act, a model with significant generality that can perform a wide range of distinct tasks.
- [Conformity assessment](https://agenticopenfinance.com/glossary/conformity-assessment.md): The process of demonstrating that a high-risk AI system meets the AI Act's requirements before it is used.
- [Fundamental rights impact assessment](https://agenticopenfinance.com/glossary/fundamental-rights-impact-assessment.md): An assessment certain deployers must do before using a high-risk AI system, covering its impact on people's rights.
- [AI Omnibus](https://agenticopenfinance.com/glossary/ai-omnibus.md): The EU regulation that amended the AI Act's timeline for high-risk rules and simplified some of its duties.

## Glossary: Open banking and open finance
- [Open banking](https://agenticopenfinance.com/glossary/open-banking.md): Customers letting authorised third parties access their payment account data and initiate payments through secure APIs.
- [Open finance](https://agenticopenfinance.com/glossary/open-finance.md): Extending open banking's customer-permissioned data sharing beyond payment accounts to savings, credit, investments and insurance.
- [Account information service](https://agenticopenfinance.com/glossary/account-information-service.md): An online service providing consolidated information on a user's payment accounts held with other providers.
- [Third-party provider (TPP)](https://agenticopenfinance.com/glossary/third-party-provider.md): The common name for providers that access accounts held elsewhere, such as account information and payment initiation providers.
- [Data provider](https://agenticopenfinance.com/glossary/data-provider.md): Under the US data rights rule, a covered firm that must make consumer financial data available on request.
- [UK Open Banking Standard](https://agenticopenfinance.com/glossary/open-banking-standard.md): The UK's API specifications, security profile and customer experience guidelines for open banking.
- [NextGenPSD2](https://agenticopenfinance.com/glossary/nextgenpsd2.md): The Berlin Group's common API framework for access to accounts under PSD2, used widely in the European Union.
- [Financial data access framework (FIDA)](https://agenticopenfinance.com/glossary/financial-data-access.md): The European Commission's proposed regulation on customer-permissioned access to financial data beyond payment accounts.
- [Regulatory sandbox](https://agenticopenfinance.com/glossary/regulatory-sandbox.md): A supervised programme where firms test new financial products with real customers under agreed safeguards.
- [Screen scraping](https://agenticopenfinance.com/glossary/screen-scraping.md): A third party logging in with a customer's credentials to read data from the bank's customer interface.
- [Account aggregation](https://agenticopenfinance.com/glossary/account-aggregation.md): Bringing a customer's accounts from several providers into one view, ideally through regulated data access.

## Glossary: Evidence and audit
- [Audit trail](https://agenticopenfinance.com/glossary/audit-trail.md): A chronological record of who accessed a system and what operations they performed, enough to reconstruct events.
- [Automatic logging](https://agenticopenfinance.com/glossary/automatic-logging.md): Built-in recording of events while a high-risk AI system runs, so its operation can be traced afterwards.
- [Record retention](https://agenticopenfinance.com/glossary/record-retention.md): Keeping records that evidence compliance for a minimum period, so they are available to supervisors and in disputes.
- [Technical documentation](https://agenticopenfinance.com/glossary/technical-documentation.md): The AI Act file a provider must draw up and keep current to show a high-risk system meets the requirements.
- [Explainability](https://agenticopenfinance.com/glossary/explainability.md): The degree to which the mechanisms behind an AI system's output can be described in terms people understand.
- [Adverse action notice](https://agenticopenfinance.com/glossary/adverse-action-notice.md): A US notice telling a credit applicant about an adverse decision and the specific principal reasons for it.
- [Post-market monitoring](https://agenticopenfinance.com/glossary/post-market-monitoring.md): A provider's ongoing collection and review of experience from a deployed AI system, to find and fix problems.
- [Serious incident](https://agenticopenfinance.com/glossary/serious-incident.md): Under the AI Act, an AI malfunction leading to death or serious harm, infrastructure disruption, rights infringement or major damage.
- [Evidence pack](https://agenticopenfinance.com/glossary/evidence-pack.md): A bundle of records that reconstructs one agent action: identity, mandate, authentication, inputs, calls, outputs and approvals.
- [Tamper-evident log](https://agenticopenfinance.com/glossary/tamper-evident-log.md): A log built so that any later change, deletion or reordering of entries can be detected.
- [Agent trace](https://agenticopenfinance.com/glossary/agent-trace.md): A record of one agent run, made of spans for model calls, tool calls, handoffs and other steps.

## Glossary: Commerce and checkout
- [Agentic commerce](https://agenticopenfinance.com/glossary/agentic-commerce.md): Buying and selling in which an AI agent finds, selects or pays for goods and services on a customer's behalf.
- [Merchant of record](https://agenticopenfinance.com/glossary/merchant-of-record.md): The business legally selling to the customer and responsible for the payment, refunds, taxes and disputes.
- [Card-not-present transaction](https://agenticopenfinance.com/glossary/card-not-present-transaction.md): A card payment where the card is not physically presented to the merchant, such as online or in-app.
- [Merchant-initiated transaction](https://agenticopenfinance.com/glossary/merchant-initiated-transaction.md): A card payment the merchant initiates without the cardholder present, under an agreement made earlier.
- [Agentic checkout](https://agenticopenfinance.com/glossary/agentic-checkout.md): A checkout an agent completes through a structured API with the seller, instead of operating the seller's website.
- [Checkout session](https://agenticopenfinance.com/glossary/checkout-session.md): In ACP, the stateful object an agent and seller update together, from items and options to completion.
- [Delegated payment](https://agenticopenfinance.com/glossary/delegated-payment.md): Giving an agent a payment token limited by an allowance, such as amount, currency, merchant and expiry.
- [Checkout Mandate](https://agenticopenfinance.com/glossary/checkout-mandate.md): In AP2, the mandate that authorises completing a checkout, bound in its closed form to a merchant-signed cart.
- [Payment Mandate](https://agenticopenfinance.com/glossary/payment-mandate.md): In AP2, the mandate that authorises payment for a checkout, verified by the credential provider, network and processor.
- [Human-not-present transaction](https://agenticopenfinance.com/glossary/human-not-present-transaction.md): A purchase an agent completes while the user is absent, relying on authority the user granted in advance.
- [Trusted surface](https://agenticopenfinance.com/glossary/trusted-surface.md): In AP2, a secure, non-agentic interface that shows mandate content to the user for authorisation and consent.
- [Credentials provider](https://agenticopenfinance.com/glossary/credentials-provider.md): In AP2, a secure entity such as a digital wallet that manages and executes the user's payment and identity credentials.
- [Checkout receipt](https://agenticopenfinance.com/glossary/checkout-receipt.md): In AP2, a record of a checkout's outcome that references the closed mandate it binds to.

## Glossary: AI risks and safety
- [Prompt injection](https://agenticopenfinance.com/glossary/prompt-injection.md): An attack that alters what a model receives so that it follows the attacker's instructions instead of its user's.
- [Indirect prompt injection](https://agenticopenfinance.com/glossary/indirect-prompt-injection.md): Prompt injection hidden in content an AI system retrieves, such as a web page, document or email.
- [Jailbreak](https://agenticopenfinance.com/glossary/jailbreak.md): A prompting attack designed to get a model to bypass its safety rules or restrictions.
- [Confabulation](https://agenticopenfinance.com/glossary/confabulation.md): Confidently stated but false or erroneous output from a generative AI system, often called hallucination.
- [Automation bias](https://agenticopenfinance.com/glossary/automation-bias.md): The tendency of people to rely, or over-rely, on the output of an automated system.
- [Data poisoning](https://agenticopenfinance.com/glossary/data-poisoning.md): An attack that corrupts the data a model learns from or relies on, to change its behaviour.
- [Excessive agency](https://agenticopenfinance.com/glossary/excessive-agency.md): Giving an LLM application more functions, permissions or autonomy than needed, so bad outputs cause harmful actions.
- [Model drift](https://agenticopenfinance.com/glossary/model-drift.md): A decline in a model's or agent's performance over time as data, users or conditions change.
- [Sensitive information disclosure](https://agenticopenfinance.com/glossary/sensitive-data-leakage.md): An AI system revealing personal, confidential or security data through its outputs, logs or tool calls.
- [Red-teaming](https://agenticopenfinance.com/glossary/red-teaming.md): Structured adversarial testing of an AI system to find flaws, harmful behaviours and vulnerabilities before attackers do.
- [Unbounded consumption](https://agenticopenfinance.com/glossary/unbounded-consumption.md): Excessive, uncontrolled use of an AI service that degrades it or runs up costs, including denial of wallet.

## Optional
- [Full text](https://agenticopenfinance.com/llms-full.txt)
- [Sitemap](https://agenticopenfinance.com/sitemap.xml)
