Blog Post
Two New Glossaries for AI and Cyber Risk
May 10, 2026
The language around AI risk moves faster than the definitions do. Ask five vendors what shadow AI means, or where AI governance ends and AI security begins, and you will get five different answers. The same problem runs through cyber risk quantification and GRC, where terms like loss exceedance curve or single loss expectancy carry exact meanings that rarely survive a hallway explanation. When definitions drift, so does the work built on top of them. A board report that calls every AI tool shadow AI, or a risk assessment that treats quantification as a synonym for scoring, sends teams in the wrong direction before the analysis even starts. Kovrr built two reference glossaries so security and GRC teams can work from definitions that hold up under an auditor's questions.
The AI Security and Governance Glossary
The AI Security and Governance glossary covers the vocabulary now showing up in board decks and audit requests. It defines shadow AI, the difference between agentic and generative AI, what AI asset discovery actually involves, and the frameworks enterprises answer to, including the EU AI Act, NIST AI RMF, ISO 42001, and the Colorado AI Act. The entries stay short enough to read in a meeting and specific enough to settle a debate about scope. Every one links across to related terms and to the parts of the AI Security and Governance Platform that put those concepts into operation.
The Cyber Risk Quantification and GRC Glossary
The cyber glossary goes deep on the language of measurement. It explains cyber risk quantification as a practice and walks through the mechanics behind a loss exceedance curve and Monte Carlo simulation. The regulatory entries cover how enterprises report exposure under DORA, NIST CSF 2.0, the SEC cyber disclosure rule, and NIS2, while the operational entries define what belongs in a cyber risk register and how materiality gets determined after an incident. Each definition traces the term back to how it affects a number a CFO or regulator will read.
Both glossaries stay current as new terms enter the market and older ones settle into agreed definitions.
To see how Kovrr connects these concepts into one operational view of enterprise AI and cyber risk, book a demo.
AI and Cyber Glossary FAQs
Speak to an ExpertWhat is the difference between AI security and AI governance?
AI security and AI governance solve related problems from different angles. AI security protects AI systems from attacks like prompt injection and data poisoning, while AI governance sets the policies, accountability, and oversight that decide how AI gets used in the first place. The AI security entry defines the protective side, and the governance entry covers the oversight side. Most enterprises need both, since a well-governed system with weak security still leaks data, and a hardened system with no governance still runs without approval or an audit trail.
Is AI risk quantification the same as cyber risk quantification?
They share a method and differ in scope. AI risk quantification applies financial modeling to exposure that originates in AI systems like shadow AI and autonomous agents. Cyber risk quantification does the same for the wider universe of cyber threats such as ransomware and data breaches. Kovrr's AI risk quantification is built on the insurance-grade CRQ modeling the company has refined for years, so the two run on the same statistical foundation while answering different questions about where loss originates.
What is a loss exceedance curve?
A loss exceedance curve shows the probability that losses will exceed a given dollar amount over a set period, which turns a vague sense of risk into a number leadership can plan against. It comes out of a Monte Carlo simulation that runs thousands of possible loss events to produce a full distribution instead of a single worst-case guess. Security and finance teams read the curve to set risk appetite and decide how much exposure to accept and how much to offload through insurance or controls. The cyber glossary walks through how each point on the curve should be read.
.webp)



