Reference
Sovereign Intelligence Glossary
Updated 2026-10-06 · 100 terms · 7 categories
What this is:Plain definitions of the 100 terms used when organisations plan, build and govern AI they control. Laws and standards are described for what they are. A definition here never says that any product meets them; for what Swfte does and does not claim, see the trust centre.
Categories
Showing all 100 terms.
Sovereignty
- Data localisation
- A legal or contractual requirement that certain data be stored or processed inside a given country or region. It is narrower than data sovereignty, which also covers who can access the data and under which law.Read: Data sovereignty
- Data residency
- The physical or regional location where data is stored and processed. Residency is one input to data sovereignty, but a resident dataset can still be reachable by a foreign provider or a foreign court.Read: Data sovereignty
- Data sovereignty
- The ability to decide where data lives, who can access it, how it is processed, whether it moves and how long it is retained. It covers location, access, processing, transfer and retention.Read: Data sovereigntyAI sovereignty on the platform
- Digital sovereignty
- The broader capacity of a state, a region or an organisation to control its digital infrastructure, data and technology choices. AI sovereignty is the part of it that concerns models, agents and the intelligence built on an organisation's own data.Read: What is Sovereign Intelligence?
- Exit and portability
- The practical ability to move data, models, context, policies and workflows to another provider or environment without rebuilding them. If you cannot leave at a known cost and in a known time, you do not fully control what you run.Read: Supply-chain sovereigntyRead: Infrastructure sovereignty
- Extraterritoriality
- When a country's law reaches data or companies outside its borders, for example by compelling a domestic provider to hand over data it holds abroad. It is why the location of a server does not settle who can lawfully demand access to it.Read: Data sovereigntyRead: Sovereign AI vs Sovereign Intelligence
- Governance sovereignty
- Control over the policies, permissions, oversight, audit trail and evidence that govern AI. The rules and the proof stay with the organisation, not with a vendor.Read: Governance sovereignty
- Infrastructure sovereignty
- Control over where AI runs and what it depends on: compute, hosting, deployment model and critical dependencies. It spans public cloud, private cloud, on-premises and hybrid.Read: Infrastructure sovereigntySovereign infrastructure layer
- Intelligence sovereignty
- Ownership and control of what the organisation knows, remembers and learns: proprietary knowledge, agent memory and derived insight. It stays an asset the organisation owns and can move.Read: Intelligence sovereignty
- Jurisdiction
- The legal system whose courts and regulators can compel a provider or an organisation. For AI, the relevant jurisdictions include where the provider is incorporated, where the data sits and where the people it concerns live.Read: Data sovereigntyRead: Supply-chain sovereignty
- Model sovereignty
- Control over which models are approved, where they are deployed, how they are customised and when they are retired. It covers selection, deployment, customisation and lifecycle.Read: Model sovereigntyIntelligence and models layer
- Operational sovereignty
- Control over what AI is allowed to do on the organisation's behalf: its agents, workflows, decisions and actions, and the limits placed on them.Read: Operational sovereignty
- Sovereign AI
- A common but narrower term, usually meaning AI that is hosted in a chosen country or run on models and compute that a nation or organisation controls. Sovereign intelligence extends the idea from where the model runs to the whole AI estate.Read: Sovereign AI vs Sovereign Intelligence
- Sovereign cloud
- A cloud offering designed so that data, operations and legal exposure sit under a chosen jurisdiction. What the label guarantees varies by provider, so ask for the specific controls rather than relying on the name.Read: Infrastructure sovereignty
- Sovereign Intelligence
- The category Swfte builds for: organisations turn their data into intelligence, intelligence into AI, and AI into secure, governed action, while retaining meaningful control over their whole AI estate.Read: What is Sovereign Intelligence?Sovereign Intelligence pillar
- Sovereignty
- The organisation's ability to retain meaningful control over its AI estate. It is about control, not just where a server sits.Read: What is Sovereign Intelligence?Read: Sovereign AI vs Sovereign Intelligence
- Supply-chain sovereignty
- Visibility into the vendors, models, infrastructure and critical dependencies behind your AI, and the ability to change them without rebuilding. It covers vendors, models, infrastructure and critical dependencies.Read: Supply-chain sovereignty
AI infrastructure
- Air-gapped deployment
- A deployment with no network connection to the public internet or to other untrusted networks. Models, updates and data have to be moved in and out by controlled, usually manual, processes.Read: Infrastructure sovereignty
- Confidential computing
- Hardware-backed isolation that keeps data protected while it is being processed, not only at rest or in transit. It narrows who, including the infrastructure operator, can see workloads in memory.Read: Infrastructure sovereigntyRead: Data sovereignty
- Continuous batching
- A scheduling technique in which an inference server adds and removes requests from a running batch at every generation step instead of waiting for a whole batch to finish. It raises GPU utilisation and is separate from PagedAttention.Read: Infrastructure sovereigntyvLLM continuous batching deep dive
- Dedicated cloud
- An isolated deployment, in a virtual private cloud or on bare metal, in a public cloud or in your own data centre, used by one organisation rather than shared with other tenants. Swfte scopes dedicated deployments per engagement.Read: Infrastructure sovereigntyDedicated cloud
- GPU
- A graphics processing unit, the parallel processor most commonly used to train and serve large language models. Availability, memory size and location of GPUs shape what you can run and where.Read: Infrastructure sovereigntyGPU reference
- Hybrid deployment
- An arrangement that places different AI workloads in different environments, for example sensitive workloads on private infrastructure and others on a public cloud, under one set of controls.Read: Infrastructure sovereigntyRead: Reference architecture
- Inference
- Running a trained model to produce an output from an input, as opposed to training it. Most enterprise AI spend and risk sit in inference, because every prompt, document and tool result passes through it.Read: Infrastructure sovereignty
- Inference server
- Software that loads a model onto accelerators and serves requests to it, handling batching, memory and scheduling. Open source examples include vLLM. Choice of inference server affects cost, latency and portability.Read: Infrastructure sovereignty
- KV cache
- The key-value cache a transformer keeps for the tokens it has already processed, so it does not recompute them for each new token. It grows with context length and is often the limit on how many requests a GPU can serve at once.Read: Infrastructure sovereignty
- On-premises
- Infrastructure owned or leased and operated inside the organisation's own facilities. It gives the most direct control over hardware and network boundaries, and also puts capacity planning and operations on the organisation.Read: Infrastructure sovereignty
- PagedAttention
- A way of managing the KV cache in non-contiguous memory blocks, inspired by operating-system paging, introduced with vLLM by Kwon and colleagues at SOSP 2023. It reduces wasted GPU memory.Read: Infrastructure sovereigntyPagedAttention paper (arXiv) (opens in a new tab)
- Private cloud
- Cloud-style infrastructure dedicated to one organisation, whether hosted by a provider or run in the organisation's own data centre. It keeps the operating model of cloud while narrowing who shares the environment.Read: Infrastructure sovereignty
- VRAM
- Video memory on a GPU. Model weights and the KV cache must fit in it, so VRAM, together with quantisation, largely decides which models a given machine can serve.Read: Infrastructure sovereigntyRead: Model sovereignty
Models
- Context window
- The maximum amount of text, measured in tokens, a model can consider in a single request, including instructions, retrieved documents and its own output. It limits how much context an agent can use at once.Read: Model sovereignty
- Distillation
- Training a smaller model to reproduce the behaviour of a larger one on a target task. It can make a model cheap enough to run on infrastructure you control, subject to the licence terms of the source model.Read: Model sovereignty
- Evals
- Repeatable tests that measure how a model or agent performs on tasks that matter to the organisation, such as accuracy, refusal behaviour and policy adherence. Evals are how a model is approved, compared and re-checked after changes.Read: Model sovereigntyRead: The closed intelligence loop
- Fine-tuning
- Further training of an existing model on organisation-specific examples to change its behaviour or style. It creates a derived model whose weights, training data and lifecycle the organisation must then manage.Read: Model sovereignty
- Foundation model
- A large model trained on broad data that can be adapted to many tasks. Large language models are the best-known kind.Read: Model sovereignty
- Hallucination
- Output that is fluent and confident but not supported by the model's inputs or by fact. Grounding answers in retrieved sources, evaluating outputs and requiring review for consequential actions reduce its impact.Read: Governance vs guardrailsRead: Capability plus control
- LLM
- A large language model: a neural network trained on large amounts of text that generates and transforms language, and can follow instructions and call tools. LLMs are the reasoning component inside most AI agents.Read: Model sovereignty
- Model card
- A short document describing a model's intended use, training approach, evaluation results and known limits. Teams use model cards to decide whether a model is approved for a given data class and task.Read: Model sovereigntySwfte model cards
- Model gateway
- A single access point through which applications and agents call models from many providers. It is where routing, failover, cost tracking and policy checks on model use can be applied consistently.Read: Model sovereigntyRead: Runtime governanceConnect
- Model lifecycle
- The stages a model passes through in the organisation: selection, evaluation, approval, deployment, customisation, monitoring and retirement. Model sovereignty includes deciding when a model is retired.Read: Model sovereignty
- Model routing
- Choosing, for each request, which model should handle it based on task, data classification, cost, latency and approval status. Routing is also how sensitive data is kept off models that are not approved for it.Read: Model sovereigntyRead: Runtime governanceAI model routing and cost optimisation
- Open-weight model
- A model whose trained weights can be downloaded and run on your own infrastructure under a licence. Open weights are not necessarily open source: licence terms, training data and permitted use still need to be read.Read: Model sovereignty
- Quantisation
- Storing a model's weights at lower numerical precision to cut memory use and speed up inference, usually at some cost in quality. It is a main reason larger models can run on smaller or on-premises hardware.Read: Model sovereigntyRead: Infrastructure sovereignty
Data and context
- Agent memory
- Information an agent keeps between steps or sessions, such as past decisions, user preferences and task state. Because memory accumulates organisational knowledge, it needs ownership, retention rules and access control.Read: Intelligence sovereignty
- Chunking
- Splitting documents into smaller passages before they are embedded and indexed for retrieval. Chunk size and boundaries affect whether retrieval returns the right passage with enough surrounding meaning.Read: Intelligence sovereigntyRAG architecture and implementation guide
- Context layer
- The second layer of the platform, Data and Context: how AI gets the context to understand the organisation, through retrieval, memory, knowledge structures and lineage. It sits between infrastructure and models.Read: Intelligence sovereigntyRead: Reference architectureData and Context layer
- Data classification
- Labelling data by sensitivity, such as public, internal, confidential or restricted, so that rules can follow it. Classification decides which models, locations and agents may touch each class of data.Read: Data sovereigntyRead: Governance sovereignty
- Embedding
- A list of numbers that represents the meaning of a piece of text, an image or other content, produced by an embedding model. Items with similar meaning end up close together, which is what makes semantic search work.Read: Intelligence sovereignty
- Knowledge graph
- A structure that stores entities such as customers, contracts and products, and the relationships between them. Agents use it to answer questions that depend on how things connect, which similarity search alone handles poorly.Read: Intelligence sovereignty
- Lineage
- A record of where data came from and what was done to it on the way to its current form. For AI, lineage lets you trace an output back to the sources and transformations behind it.Read: Intelligence sovereigntyRead: Governance sovereignty
- Permission-aware retrieval
- Retrieval that returns only what the person or agent making the request is already allowed to see in the source system. Without it, a search layer can reveal documents that existing access controls were meant to protect.Read: Data sovereigntyRead: Intelligence sovereigntyEnterprise AI workspace rollout checklist
- RAG
- Retrieval-augmented generation: the system finds relevant passages from approved sources and gives them to the model along with the question, so the answer is grounded in the organisation's own content.Read: Intelligence sovereigntyRAG architecture and implementation guide
- Vector database
- A database built to store embeddings and find the closest matches quickly. It holds a searchable index of the organisation's knowledge, so where it runs and who can read it matter for sovereignty.Read: Intelligence sovereigntyRead: Data sovereignty
Agents
- A2A
- Agent-to-Agent, an open protocol that lets agents built by different vendors discover each other and exchange tasks. It addresses agent-to-agent communication, where MCP addresses agent-to-tool connections.Read: Operational sovereignty
- Agent identity
- A distinct, known identity for each agent, separate from the human who started it, to which permissions, policies and audit records are attached. Without it you cannot say who acted.Read: Operational sovereigntyRead: Runtime governanceGoverned agents layer
- Agentic workflow
- A multi-step process in which an AI model decides some of the steps, such as which tool to call next, rather than following a fixed script. Governed workflows embed such steps in the way the organisation operates.Read: Operational sovereigntyGoverned workflows layer
- AI agent
- Software that uses an AI model to pursue a goal by reading information, deciding on steps and calling tools to act. Because it acts, an agent needs an identity, permissions and limits, as any employee does.Read: Operational sovereigntyRead: Runtime governance
- Human-in-the-loop
- A design in which a person reviews or approves an AI action before it takes effect. In the brief's terms, it is the Require human approval verb and the L2 Approve level.Read: Operational sovereigntyRead: Governance vs guardrails
- L1 Assist
- Autonomy level 1: AI recommends. A person does the work and makes every decision.Read: Operational sovereigntyControlled autonomy
- L2 Approve
- Autonomy level 2: the AI prepares an action and a human approves it before anything happens.Read: Operational sovereigntyControlled autonomy
- L3 Supervise
- Autonomy level 3: AI acts within defined limits and is monitored. Exceptions above the limits go to a human.Read: Operational sovereigntyControlled autonomy
- L4 Autonomous
- Autonomy level 4: AI works independently within strict policy and risk bounds that are enforced at runtime. It is earned through evidence, and many agents should never need it.Read: Operational sovereigntyControlled autonomy
- L5 Adaptive
- Autonomy level 5: AI improves its own behaviour within controlled boundaries, and changes to that behaviour are gated and recorded. The boundaries themselves cannot be changed by the agent.Read: Operational sovereigntyRead: The closed intelligence loopControlled autonomy
- MCP
- Model Context Protocol, an open standard for connecting AI applications to tools and data sources. Anthropic donated it to the Agentic AI Foundation, a Linux Foundation directed fund, on 9 December 2025.Read: Runtime governanceRead: Operational sovereigntyMCP joins the Agentic AI Foundation (opens in a new tab)
- Multi-agent system
- A set of agents that divide a task, hand work to each other and combine results. Each agent keeps its own identity and limits, so authority does not quietly accumulate as work passes between them.Read: Operational sovereigntyMulti-agent AI systems for the enterprise
- Orchestration
- The coordination of models, agents, tools and people across a process: sequencing steps, passing context, handling failures and applying approvals. It is the control logic of a governed workflow.Read: Operational sovereigntyRead: Reference architecture
- Prompt injection
- An attack in which instructions hidden in content an agent reads, such as a web page or an email, try to override its real instructions. Least-privilege permissions and policy checks on tool calls limit the damage if it succeeds.Read: Runtime governanceRead: Governance vs guardrails
- Tool call
- A request from an AI model to run a defined function, such as querying a database, sending an email or creating a purchase order draft. Tool calls are where an agent's decisions turn into actions, so they are the natural place to enforce policy.Read: Runtime governanceRead: Operational sovereignty
Governance
- AI estate
- Everything an organisation runs or depends on for AI: its models, agents, workflows, data flows, infrastructure and vendors, including what teams adopted without central approval. You cannot control what you have not inventoried.Read: What is Sovereign Intelligence?Read: Supply-chain sovereigntyInventorying models, agents and data flows
- Audit trail
- A record of what happened, who or what acted and under which policy, kept so it can be reviewed later. For AI it should include the identity, data accessed, model used, output, tools called, policy applied, decision, approval, action and outcome.Read: Governance sovereigntyRead: Runtime governance
- Capability plus control
- The principle that AI capability without control is not enterprise-ready, and control without intelligence is not valuable. Sovereign intelligence needs both at once.Read: Capability plus control
- Closed intelligence loop
- The cycle in which control leads to intelligence, agency, execution and outcomes, and the evidence from outcomes flows back into data and context. The organisation gets smarter through AI while staying in control.Read: The closed intelligence loop
- Compliance-by-design
- Building the technical controls, governance mechanisms and evidence into the system, so an organisation can deploy AI within its applicable regulatory, security and policy requirements. The exact posture depends on use case, jurisdiction, deployment and configuration.Read: Governance sovereigntyRead: Runtime governanceAI governance
- Controlled autonomy
- Increasing what AI may do in five steps, from Assist to Approve, Supervise, Autonomous and Adaptive, based on evidence and risk. It replaces a simple switch from manual to autonomous.Read: Operational sovereigntyControlled autonomy
- Evidence
- Records you can hand to a reviewer, an auditor or a regulator to show what an AI system did and under which controls. Evidence is the product of auditability and traceability, kept in a form others can inspect.Read: Governance sovereignty
- Guardrails
- Filters and rules that answer one question: should this input or output be blocked? They are useful, and they are narrower than governance, which also asks who is acting, under which policy and whether it can be proved.Read: Governance vs guardrails
- Human oversight
- Approval, escalation and review points where people stay in charge of consequential AI actions. It is one of the thirteen facets of the trust fabric and is set per action, not per system.Read: Operational sovereigntyRead: Governance vs guardrails
- Policy decision point
- The component that evaluates a request against policy and returns a decision such as allow, deny, warn, filter, escalate or require human approval. It is the policy engine's decision step, separate from the point that carries it out.Read: Runtime governance
- Policy enforcement point
- The component that sits in the path of an action, asks the policy decision point what to do and applies the answer. For agents it is typically placed on tool calls, model calls and data access.Read: Runtime governance
- Policy engine
- Software that stores policies as rules and evaluates them against a request, using context such as identity, data class, risk and action. A policy engine changes what an agent can actually do, rather than what a document says it should do.Read: Runtime governanceRead: Governance sovereignty
- Risk tiering
- Classifying each AI system by the harm it could cause, so that higher-risk systems get stricter approval, monitoring and evidence. The risk level is recorded in the system's Trust Profile.Read: Runtime governanceRead: Operational sovereignty
- Runtime governance
- Governance that runs inside AI, at the moment of each action, instead of in a document beside it. Policy changes what the agent can actually do. Governance is runtime, not paperwork.Read: Runtime governanceWhy AI governance must run at runtime
- Shadow AI
- AI tools, models and agents that employees or teams use without the organisation's knowledge or approval. Shadow AI is the part of the AI estate nobody has inventoried or governed.Read: What is Sovereign Intelligence?Read: Supply-chain sovereigntyShadow AI and enterprise security
- Traceability
- The chain from data to model to agent to decision to action to outcome, so any result can be followed back to what produced it. It is one facet of the trust fabric.Read: Governance sovereigntyRead: Runtime governance
- Trust fabric
- The governance layer that runs through all six platform layers rather than sitting beside them as a seventh. Its thirteen facets are identity, access, data controls, policy, security, privacy, compliance, risk, human oversight, auditability, traceability, evidence and monitoring.Read: Governance sovereigntyRead: Runtime governanceTrust and governance
- Trust Profile
- A record attached to every AI system that states its identity, owner, risk level, approved models, data classification, data residency, permitted systems, allowed and restricted actions, human approval rule, retention, audit and policy set.Read: Runtime governanceRead: Operational sovereigntyTrust Profile
EU regulation and standards
- CLOUD Act
- A 2018 US law under which US authorities can compel US-based providers to disclose data in their possession, custody or control, wherever it is stored. It is why European organisations ask who operates their cloud, not only where it sits.Read: Data sovereigntyRead: Supply-chain sovereigntyCSIS: The CLOUD Act and transatlantic trust (opens in a new tab)
- Data Act
- Regulation (EU) 2023/2854, applicable from 12 September 2025. Its cloud-switching rules require providers to remove barriers to switching, and prohibit switching charges, including egress charges for switching, from 12 January 2027.Read: Infrastructure sovereigntyRead: Supply-chain sovereigntyData Act cloud switching explained (opens in a new tab)
- Digital Omnibus on AI
- Regulation (EU) 2026/1744, in force since 27 July 2026, which amended the EU AI Act. It moved stand-alone Annex III high-risk obligations from 2 August 2026 to 2 December 2027 and Annex I product-embedded systems to 2 August 2028.Read: Governance sovereigntyGibson Dunn: Omnibus agreement (opens in a new tab)
- DORA
- The Digital Operational Resilience Act, Regulation (EU) 2022/2554, applying from 17 January 2025 to EU financial entities. It requires management of ICT third-party risk, including a register of information on ICT service arrangements.Read: Supply-chain sovereigntyDORA on EUR-Lex (opens in a new tab)
- EU AI Act
- Regulation (EU) 2024/1689, the European Union's risk-based law on AI. It bans some practices, sets obligations for high-risk systems and for general-purpose AI models, and sets transparency duties.Read: Governance sovereigntyRead: Runtime governanceEU AI Act
- EU Cloud Sovereignty Framework
- A European Commission method for assessing how sovereign a cloud service is, scored against eight sovereignty objectives from strategic and legal to operational, supply chain, technology and security. Each objective is graded on SEAL levels 0 to 4.Read: Infrastructure sovereigntyRead: Supply-chain sovereigntyCommission Cloud Sovereignty Framework (opens in a new tab)
- GDPR
- The General Data Protection Regulation, Regulation (EU) 2016/679. It governs the processing of personal data of people in the EU, including limits on transfers outside the EU and rules on foreign court orders.Read: Data sovereignty
- GPAI model
- A general-purpose AI model under the EU AI Act: a model that can serve many tasks and be built into many systems. Obligations on providers of such models have applied since 2 August 2025.Read: Model sovereigntyRead: Governance sovereignty
- High-risk AI system
- An AI system the EU AI Act places in its strictest permitted tier, such as those used in employment, essential services or critical infrastructure. Following the Digital Omnibus, stand-alone Annex III obligations apply from 2 December 2027.Read: Governance sovereignty
- ISO/IEC 42001
- ISO/IEC 42001:2023, the international standard for an AI management system, published in December 2023. Organisations can adopt it as a framework and have a management system audited against it.Read: Governance sovereigntyISO/IEC 42001 (opens in a new tab)
- NIS2
- Directive (EU) 2022/2555, the EU's updated cybersecurity law. It requires risk-management measures and incident reporting from essential and important entities across many sectors.Read: Supply-chain sovereignty
- NIST AI RMF
- The US National Institute of Standards and Technology AI Risk Management Framework 1.0, released 26 January 2023. It is voluntary and organised into four functions: Govern, Map, Measure and Manage.Read: Governance sovereigntyNIST AI RMF
- SEAL
- Sovereignty Effectiveness Assurance Level, the 0 to 4 scale in the EU Cloud Sovereignty Framework, from no sovereignty (SEAL-0) to full digital sovereignty (SEAL-4). Tenders can set a minimum level per objective.Read: Infrastructure sovereignty
- Schrems II
- The July 2020 Court of Justice of the EU judgment that invalidated the EU-US Privacy Shield and required organisations relying on standard contractual clauses to assess whether the destination country protects the data in practice.Read: Data sovereignty
From vocabulary to a working platform
Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value. Or read the step-by-step build guide and take the readiness assessment.