AI strategy glossary: 30 terms in one sentence each

The thirty strategy, governance and investment terms that come up when a business plans its AI work, each explained in one plain sentence.

5 minread 1,148words last updated

The short answer

Planning AI work mixes two vocabularies: the technology terms that describe what the systems do, and the governance, risk and investment terms that describe what a business has to decide. The second half is where most confusion sits, because the technology is easy to acquire and the obligations are not obvious. The thirty terms below cover planning, governance, risk, money and measurement, each in one plain sentence. When one appears in a proposal or a board paper, ask what decision it changes; the useful ones always change one, and the rest are decoration.

Planning

TermIn one sentence
AI strategyA short written statement of where AI will and will not be used in your business, in what order, with measures and owners.
Register of AI usesThe list of every AI use in the business, with its owner, its data and its safeguards, which is the foundation of any governance.
ReadinessWhether a process, its data, its systems and its people can support automation yet, assessed before any building.
Maturity stageWhere a business sits on the path from scattered personal use to a managed, measured capability.
RoadmapThe ordered sequence of AI projects with dates and dependencies, usually twelve months ahead.
PilotA small, time-boxed deployment with a defined success measure, which either earns production or is stopped.
Proof of conceptA test of whether something is technically possible, which proves nothing about whether it is worth doing.
Exclusion listThe written record of what you will not do with AI, which is what makes a strategy a strategy.
Willing ownerA named person who wants a given AI use to exist and will look after it, without whom projects fail.
BaselineThe measured state before a project starts, without which no claim of improvement can be checked.

Governance and risk

TermIn one sentence
Human oversightA person with the information, time and authority to decide differently from a system’s suggestion, and who is accountable.
High-risk systemThe EU AI Act’s category for AI in sensitive uses such as employment, credit, education and essential services, bringing specific obligations.
Prohibited practiceUses the AI Act forbids outright, such as social scoring and certain manipulation and biometric practices.
Transparency obligationThe duty to tell people when they are interacting with AI or receiving AI-generated content.
Data processing agreementThe contract under which a provider processes personal data for you, required before customer data reaches any AI service.
Data protection impact assessmentA structured assessment of privacy risk required before certain processing, including much AI use on personal data.
Risk registerThe list of what could go wrong with each AI use, how likely, how bad, and what you are doing about it.
BiasSystematic difference in outcomes between groups, arising from data, design or deference, detected by outcome testing.
ExplainabilityThe ability to tell an affected person what was decided, on what basis, by whom and how to challenge it.
Shadow AITools staff adopt without approval, which is where most small business data exposure actually happens.
IncidentAny case where an AI system caused harm, exposed data or produced a materially wrong result, which should be logged and reviewed.

Money and measurement

TermIn one sentence
Total cost of ownershipEverything an AI use costs over its life: licences, usage, build, integration, maintenance, review and the people’s time.
Cost per taskWhat one unit of work costs through the AI system, which is the number to compare with doing it by hand.
Return on automationThe honest comparison of hours and errors saved against total cost, measured rather than estimated.
Usage-based costBilling that scales with how much you use, which requires caps, monitoring and forecasting to stay predictable.
Evaluation setA collection of real examples with known good answers, used to judge a system before and after every change.
DriftThe decline in an AI system’s accuracy over time as data, behaviour or models change, found by monitoring.
AdoptionThe share of the people it was built for who actually use it, which decides whether any other measure matters.
Vendor lock-inThe cost of leaving a provider, created mostly by where your data, prompts and workflows live rather than by the model.
Quarterly reviewThe rhythm of checking each AI use against its measure and retiring what does not earn its place.

Using the glossary

  1. Read any AI proposal or board paper with the glossary open and mark each term as planning, governance or money.
  2. For each claim, find the decision it changes; if there is none, ask.
  3. Check the governance terms first: register, owner, oversight, high-risk classification, processing agreement.
  4. Then the money terms: total cost, cost per task, usage exposure.
  5. Then the measurement terms: baseline, evaluation set, review rhythm.

What this means for you

Thirty terms cover the planning, governance, risk and money vocabulary of AI strategy. Use them to read proposals and board papers for the decisions they contain, check that every planned use has an owner, a baseline, a measure, data terms and an error path, and treat any term that names no decision as decoration. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Which of these terms matter most?

Register, owner and baseline, because without them nothing can be governed or measured; human oversight and high-risk, because they determine your legal obligations; total cost of ownership and cost per task, because they determine whether a use is worth keeping; and evaluation, because it is how you know whether anything changed for the better.

Why is governance vocabulary so prominent in AI?

Because the technology is easy to acquire and the obligations are not obvious. Anyone can start using a model in minutes; knowing whether you may use it on this data, who is accountable, what happens when it is wrong and whether it is working requires the governance vocabulary. The terms exist because businesses kept getting caught by the questions they name.

A consultant used a term not on this list. What should we do?

Ask what decision it changes for you. Strategy vocabulary multiplies quickly and much of it is repackaging. A useful term names a decision, a risk or a measure; if it names none of those, it is probably decoration on a slide.