Blog Post

Two New Glossaries for AI and Cyber Risk

May 10, 2026

Table of Contents

The language around AI risk moves faster than the definitions do. Ask five vendors what shadow AI means, or where AI governance ends and AI security begins, and you will get five different answers. The same problem runs through cyber risk quantification and GRC, where terms like loss exceedance curve or single loss expectancy carry exact meanings that rarely survive a hallway explanation. When definitions drift, so does the work built on top of them. A board report that calls every AI tool shadow AI, or a risk assessment that treats quantification as a synonym for scoring, sends teams in the wrong direction before the analysis even starts. Kovrr built two reference glossaries so security and GRC teams can work from definitions that hold up under an auditor's questions.

The AI Security and Governance Glossary

The AI Security and Governance glossary covers the vocabulary now showing up in board decks and audit requests. It defines shadow AI, the difference between agentic and generative AI, what AI asset discovery actually involves, and the frameworks enterprises answer to, including the EU AI Act, NIST AI RMF, ISO 42001, and the Colorado AI Act. The entries stay short enough to read in a meeting and specific enough to settle a debate about scope. Every one links across to related terms and to the parts of the AI Security and Governance Platform that put those concepts into operation.

The Cyber Risk Quantification and GRC Glossary

The cyber glossary goes deep on the language of measurement. It explains cyber risk quantification as a practice and walks through the mechanics behind a loss exceedance curve and Monte Carlo simulation. The regulatory entries cover how enterprises report exposure under DORA, NIST CSF 2.0, the SEC cyber disclosure rule, and NIS2, while the operational entries define what belongs in a cyber risk register and how materiality gets determined after an incident. Each definition traces the term back to how it affects a number a CFO or regulator will read.

Both glossaries stay current as new terms enter the market and older ones settle into agreed definitions.

To see how Kovrr connects these concepts into one operational view of enterprise AI and cyber risk, book a demo.

Hannah Yacknin-Dawson

Cybersecurity Marketing Writer

AI and Cyber Glossary FAQs

Speak to an Expert

What is the difference between AI security and AI governance?

Is AI risk quantification the same as cyber risk quantification?

What is a loss exceedance curve?