Reference

Sovereign Intelligence Glossary

Updated 2026-10-06 · 100 terms · 7 categories

What this is:Plain definitions of the 100 terms used when organisations plan, build and govern AI they control. Laws and standards are described for what they are. A definition here never says that any product meets them; for what Swfte does and does not claim, see the trust centre.

Categories

Showing all 100 terms.

Sovereignty

Data localisation
A legal or contractual requirement that certain data be stored or processed inside a given country or region. It is narrower than data sovereignty, which also covers who can access the data and under which law.Read: Data sovereignty
Data residency
The physical or regional location where data is stored and processed. Residency is one input to data sovereignty, but a resident dataset can still be reachable by a foreign provider or a foreign court.Read: Data sovereignty
Data sovereignty
The ability to decide where data lives, who can access it, how it is processed, whether it moves and how long it is retained. It covers location, access, processing, transfer and retention.Read: Data sovereigntyAI sovereignty on the platform
Digital sovereignty
The broader capacity of a state, a region or an organisation to control its digital infrastructure, data and technology choices. AI sovereignty is the part of it that concerns models, agents and the intelligence built on an organisation's own data.Read: What is Sovereign Intelligence?
Exit and portability
The practical ability to move data, models, context, policies and workflows to another provider or environment without rebuilding them. If you cannot leave at a known cost and in a known time, you do not fully control what you run.Read: Supply-chain sovereigntyRead: Infrastructure sovereignty
Extraterritoriality
When a country's law reaches data or companies outside its borders, for example by compelling a domestic provider to hand over data it holds abroad. It is why the location of a server does not settle who can lawfully demand access to it.Read: Data sovereigntyRead: Sovereign AI vs Sovereign Intelligence
Governance sovereignty
Control over the policies, permissions, oversight, audit trail and evidence that govern AI. The rules and the proof stay with the organisation, not with a vendor.Read: Governance sovereignty
Infrastructure sovereignty
Control over where AI runs and what it depends on: compute, hosting, deployment model and critical dependencies. It spans public cloud, private cloud, on-premises and hybrid.Read: Infrastructure sovereigntySovereign infrastructure layer
Intelligence sovereignty
Ownership and control of what the organisation knows, remembers and learns: proprietary knowledge, agent memory and derived insight. It stays an asset the organisation owns and can move.Read: Intelligence sovereignty
Jurisdiction
The legal system whose courts and regulators can compel a provider or an organisation. For AI, the relevant jurisdictions include where the provider is incorporated, where the data sits and where the people it concerns live.Read: Data sovereigntyRead: Supply-chain sovereignty
Model sovereignty
Control over which models are approved, where they are deployed, how they are customised and when they are retired. It covers selection, deployment, customisation and lifecycle.Read: Model sovereigntyIntelligence and models layer
Operational sovereignty
Control over what AI is allowed to do on the organisation's behalf: its agents, workflows, decisions and actions, and the limits placed on them.Read: Operational sovereignty
Sovereign AI
A common but narrower term, usually meaning AI that is hosted in a chosen country or run on models and compute that a nation or organisation controls. Sovereign intelligence extends the idea from where the model runs to the whole AI estate.Read: Sovereign AI vs Sovereign Intelligence
Sovereign cloud
A cloud offering designed so that data, operations and legal exposure sit under a chosen jurisdiction. What the label guarantees varies by provider, so ask for the specific controls rather than relying on the name.Read: Infrastructure sovereignty
Sovereign Intelligence
The category Swfte builds for: organisations turn their data into intelligence, intelligence into AI, and AI into secure, governed action, while retaining meaningful control over their whole AI estate.Read: What is Sovereign Intelligence?Sovereign Intelligence pillar
Sovereignty
The organisation's ability to retain meaningful control over its AI estate. It is about control, not just where a server sits.Read: What is Sovereign Intelligence?Read: Sovereign AI vs Sovereign Intelligence
Supply-chain sovereignty
Visibility into the vendors, models, infrastructure and critical dependencies behind your AI, and the ability to change them without rebuilding. It covers vendors, models, infrastructure and critical dependencies.Read: Supply-chain sovereignty

AI infrastructure

Air-gapped deployment
A deployment with no network connection to the public internet or to other untrusted networks. Models, updates and data have to be moved in and out by controlled, usually manual, processes.Read: Infrastructure sovereignty
Confidential computing
Hardware-backed isolation that keeps data protected while it is being processed, not only at rest or in transit. It narrows who, including the infrastructure operator, can see workloads in memory.Read: Infrastructure sovereigntyRead: Data sovereignty
Continuous batching
A scheduling technique in which an inference server adds and removes requests from a running batch at every generation step instead of waiting for a whole batch to finish. It raises GPU utilisation and is separate from PagedAttention.Read: Infrastructure sovereigntyvLLM continuous batching deep dive
Dedicated cloud
An isolated deployment, in a virtual private cloud or on bare metal, in a public cloud or in your own data centre, used by one organisation rather than shared with other tenants. Swfte scopes dedicated deployments per engagement.Read: Infrastructure sovereigntyDedicated cloud
GPU
A graphics processing unit, the parallel processor most commonly used to train and serve large language models. Availability, memory size and location of GPUs shape what you can run and where.Read: Infrastructure sovereigntyGPU reference
Hybrid deployment
An arrangement that places different AI workloads in different environments, for example sensitive workloads on private infrastructure and others on a public cloud, under one set of controls.Read: Infrastructure sovereigntyRead: Reference architecture
Inference
Running a trained model to produce an output from an input, as opposed to training it. Most enterprise AI spend and risk sit in inference, because every prompt, document and tool result passes through it.Read: Infrastructure sovereignty
Inference server
Software that loads a model onto accelerators and serves requests to it, handling batching, memory and scheduling. Open source examples include vLLM. Choice of inference server affects cost, latency and portability.Read: Infrastructure sovereignty
KV cache
The key-value cache a transformer keeps for the tokens it has already processed, so it does not recompute them for each new token. It grows with context length and is often the limit on how many requests a GPU can serve at once.Read: Infrastructure sovereignty
On-premises
Infrastructure owned or leased and operated inside the organisation's own facilities. It gives the most direct control over hardware and network boundaries, and also puts capacity planning and operations on the organisation.Read: Infrastructure sovereignty
PagedAttention
A way of managing the KV cache in non-contiguous memory blocks, inspired by operating-system paging, introduced with vLLM by Kwon and colleagues at SOSP 2023. It reduces wasted GPU memory.Read: Infrastructure sovereigntyPagedAttention paper (arXiv) (opens in a new tab)
Private cloud
Cloud-style infrastructure dedicated to one organisation, whether hosted by a provider or run in the organisation's own data centre. It keeps the operating model of cloud while narrowing who shares the environment.Read: Infrastructure sovereignty
VRAM
Video memory on a GPU. Model weights and the KV cache must fit in it, so VRAM, together with quantisation, largely decides which models a given machine can serve.Read: Infrastructure sovereigntyRead: Model sovereignty

Models

Context window
The maximum amount of text, measured in tokens, a model can consider in a single request, including instructions, retrieved documents and its own output. It limits how much context an agent can use at once.Read: Model sovereignty
Distillation
Training a smaller model to reproduce the behaviour of a larger one on a target task. It can make a model cheap enough to run on infrastructure you control, subject to the licence terms of the source model.Read: Model sovereignty
Evals
Repeatable tests that measure how a model or agent performs on tasks that matter to the organisation, such as accuracy, refusal behaviour and policy adherence. Evals are how a model is approved, compared and re-checked after changes.Read: Model sovereigntyRead: The closed intelligence loop
Fine-tuning
Further training of an existing model on organisation-specific examples to change its behaviour or style. It creates a derived model whose weights, training data and lifecycle the organisation must then manage.Read: Model sovereignty
Foundation model
A large model trained on broad data that can be adapted to many tasks. Large language models are the best-known kind.Read: Model sovereignty
Hallucination
Output that is fluent and confident but not supported by the model's inputs or by fact. Grounding answers in retrieved sources, evaluating outputs and requiring review for consequential actions reduce its impact.Read: Governance vs guardrailsRead: Capability plus control
LLM
A large language model: a neural network trained on large amounts of text that generates and transforms language, and can follow instructions and call tools. LLMs are the reasoning component inside most AI agents.Read: Model sovereignty
Model card
A short document describing a model's intended use, training approach, evaluation results and known limits. Teams use model cards to decide whether a model is approved for a given data class and task.Read: Model sovereigntySwfte model cards
Model gateway
A single access point through which applications and agents call models from many providers. It is where routing, failover, cost tracking and policy checks on model use can be applied consistently.Read: Model sovereigntyRead: Runtime governanceConnect
Model lifecycle
The stages a model passes through in the organisation: selection, evaluation, approval, deployment, customisation, monitoring and retirement. Model sovereignty includes deciding when a model is retired.Read: Model sovereignty
Model routing
Choosing, for each request, which model should handle it based on task, data classification, cost, latency and approval status. Routing is also how sensitive data is kept off models that are not approved for it.Read: Model sovereigntyRead: Runtime governanceAI model routing and cost optimisation
Open-weight model
A model whose trained weights can be downloaded and run on your own infrastructure under a licence. Open weights are not necessarily open source: licence terms, training data and permitted use still need to be read.Read: Model sovereignty
Quantisation
Storing a model's weights at lower numerical precision to cut memory use and speed up inference, usually at some cost in quality. It is a main reason larger models can run on smaller or on-premises hardware.Read: Model sovereigntyRead: Infrastructure sovereignty

Data and context

Agent memory
Information an agent keeps between steps or sessions, such as past decisions, user preferences and task state. Because memory accumulates organisational knowledge, it needs ownership, retention rules and access control.Read: Intelligence sovereignty
Chunking
Splitting documents into smaller passages before they are embedded and indexed for retrieval. Chunk size and boundaries affect whether retrieval returns the right passage with enough surrounding meaning.Read: Intelligence sovereigntyRAG architecture and implementation guide
Context layer
The second layer of the platform, Data and Context: how AI gets the context to understand the organisation, through retrieval, memory, knowledge structures and lineage. It sits between infrastructure and models.Read: Intelligence sovereigntyRead: Reference architectureData and Context layer
Data classification
Labelling data by sensitivity, such as public, internal, confidential or restricted, so that rules can follow it. Classification decides which models, locations and agents may touch each class of data.Read: Data sovereigntyRead: Governance sovereignty
Embedding
A list of numbers that represents the meaning of a piece of text, an image or other content, produced by an embedding model. Items with similar meaning end up close together, which is what makes semantic search work.Read: Intelligence sovereignty
Knowledge graph
A structure that stores entities such as customers, contracts and products, and the relationships between them. Agents use it to answer questions that depend on how things connect, which similarity search alone handles poorly.Read: Intelligence sovereignty
Lineage
A record of where data came from and what was done to it on the way to its current form. For AI, lineage lets you trace an output back to the sources and transformations behind it.Read: Intelligence sovereigntyRead: Governance sovereignty
Permission-aware retrieval
Retrieval that returns only what the person or agent making the request is already allowed to see in the source system. Without it, a search layer can reveal documents that existing access controls were meant to protect.Read: Data sovereigntyRead: Intelligence sovereigntyEnterprise AI workspace rollout checklist
RAG
Retrieval-augmented generation: the system finds relevant passages from approved sources and gives them to the model along with the question, so the answer is grounded in the organisation's own content.Read: Intelligence sovereigntyRAG architecture and implementation guide
Vector database
A database built to store embeddings and find the closest matches quickly. It holds a searchable index of the organisation's knowledge, so where it runs and who can read it matter for sovereignty.Read: Intelligence sovereigntyRead: Data sovereignty

Agents

A2A
Agent-to-Agent, an open protocol that lets agents built by different vendors discover each other and exchange tasks. It addresses agent-to-agent communication, where MCP addresses agent-to-tool connections.Read: Operational sovereignty
Agent identity
A distinct, known identity for each agent, separate from the human who started it, to which permissions, policies and audit records are attached. Without it you cannot say who acted.Read: Operational sovereigntyRead: Runtime governanceGoverned agents layer
Agentic workflow
A multi-step process in which an AI model decides some of the steps, such as which tool to call next, rather than following a fixed script. Governed workflows embed such steps in the way the organisation operates.Read: Operational sovereigntyGoverned workflows layer
AI agent
Software that uses an AI model to pursue a goal by reading information, deciding on steps and calling tools to act. Because it acts, an agent needs an identity, permissions and limits, as any employee does.Read: Operational sovereigntyRead: Runtime governance
Human-in-the-loop
A design in which a person reviews or approves an AI action before it takes effect. In the brief's terms, it is the Require human approval verb and the L2 Approve level.Read: Operational sovereigntyRead: Governance vs guardrails
L1 Assist
Autonomy level 1: AI recommends. A person does the work and makes every decision.Read: Operational sovereigntyControlled autonomy
L2 Approve
Autonomy level 2: the AI prepares an action and a human approves it before anything happens.Read: Operational sovereigntyControlled autonomy
L3 Supervise
Autonomy level 3: AI acts within defined limits and is monitored. Exceptions above the limits go to a human.Read: Operational sovereigntyControlled autonomy
L4 Autonomous
Autonomy level 4: AI works independently within strict policy and risk bounds that are enforced at runtime. It is earned through evidence, and many agents should never need it.Read: Operational sovereigntyControlled autonomy
L5 Adaptive
Autonomy level 5: AI improves its own behaviour within controlled boundaries, and changes to that behaviour are gated and recorded. The boundaries themselves cannot be changed by the agent.Read: Operational sovereigntyRead: The closed intelligence loopControlled autonomy
MCP
Model Context Protocol, an open standard for connecting AI applications to tools and data sources. Anthropic donated it to the Agentic AI Foundation, a Linux Foundation directed fund, on 9 December 2025.Read: Runtime governanceRead: Operational sovereigntyMCP joins the Agentic AI Foundation (opens in a new tab)
Multi-agent system
A set of agents that divide a task, hand work to each other and combine results. Each agent keeps its own identity and limits, so authority does not quietly accumulate as work passes between them.Read: Operational sovereigntyMulti-agent AI systems for the enterprise
Orchestration
The coordination of models, agents, tools and people across a process: sequencing steps, passing context, handling failures and applying approvals. It is the control logic of a governed workflow.Read: Operational sovereigntyRead: Reference architecture
Prompt injection
An attack in which instructions hidden in content an agent reads, such as a web page or an email, try to override its real instructions. Least-privilege permissions and policy checks on tool calls limit the damage if it succeeds.Read: Runtime governanceRead: Governance vs guardrails
Tool call
A request from an AI model to run a defined function, such as querying a database, sending an email or creating a purchase order draft. Tool calls are where an agent's decisions turn into actions, so they are the natural place to enforce policy.Read: Runtime governanceRead: Operational sovereignty

Governance

AI estate
Everything an organisation runs or depends on for AI: its models, agents, workflows, data flows, infrastructure and vendors, including what teams adopted without central approval. You cannot control what you have not inventoried.Read: What is Sovereign Intelligence?Read: Supply-chain sovereigntyInventorying models, agents and data flows
Audit trail
A record of what happened, who or what acted and under which policy, kept so it can be reviewed later. For AI it should include the identity, data accessed, model used, output, tools called, policy applied, decision, approval, action and outcome.Read: Governance sovereigntyRead: Runtime governance
Capability plus control
The principle that AI capability without control is not enterprise-ready, and control without intelligence is not valuable. Sovereign intelligence needs both at once.Read: Capability plus control
Closed intelligence loop
The cycle in which control leads to intelligence, agency, execution and outcomes, and the evidence from outcomes flows back into data and context. The organisation gets smarter through AI while staying in control.Read: The closed intelligence loop
Compliance-by-design
Building the technical controls, governance mechanisms and evidence into the system, so an organisation can deploy AI within its applicable regulatory, security and policy requirements. The exact posture depends on use case, jurisdiction, deployment and configuration.Read: Governance sovereigntyRead: Runtime governanceAI governance
Controlled autonomy
Increasing what AI may do in five steps, from Assist to Approve, Supervise, Autonomous and Adaptive, based on evidence and risk. It replaces a simple switch from manual to autonomous.Read: Operational sovereigntyControlled autonomy
Evidence
Records you can hand to a reviewer, an auditor or a regulator to show what an AI system did and under which controls. Evidence is the product of auditability and traceability, kept in a form others can inspect.Read: Governance sovereignty
Guardrails
Filters and rules that answer one question: should this input or output be blocked? They are useful, and they are narrower than governance, which also asks who is acting, under which policy and whether it can be proved.Read: Governance vs guardrails
Human oversight
Approval, escalation and review points where people stay in charge of consequential AI actions. It is one of the thirteen facets of the trust fabric and is set per action, not per system.Read: Operational sovereigntyRead: Governance vs guardrails
Policy decision point
The component that evaluates a request against policy and returns a decision such as allow, deny, warn, filter, escalate or require human approval. It is the policy engine's decision step, separate from the point that carries it out.Read: Runtime governance
Policy enforcement point
The component that sits in the path of an action, asks the policy decision point what to do and applies the answer. For agents it is typically placed on tool calls, model calls and data access.Read: Runtime governance
Policy engine
Software that stores policies as rules and evaluates them against a request, using context such as identity, data class, risk and action. A policy engine changes what an agent can actually do, rather than what a document says it should do.Read: Runtime governanceRead: Governance sovereignty
Risk tiering
Classifying each AI system by the harm it could cause, so that higher-risk systems get stricter approval, monitoring and evidence. The risk level is recorded in the system's Trust Profile.Read: Runtime governanceRead: Operational sovereignty
Runtime governance
Governance that runs inside AI, at the moment of each action, instead of in a document beside it. Policy changes what the agent can actually do. Governance is runtime, not paperwork.Read: Runtime governanceWhy AI governance must run at runtime
Shadow AI
AI tools, models and agents that employees or teams use without the organisation's knowledge or approval. Shadow AI is the part of the AI estate nobody has inventoried or governed.Read: What is Sovereign Intelligence?Read: Supply-chain sovereigntyShadow AI and enterprise security
Traceability
The chain from data to model to agent to decision to action to outcome, so any result can be followed back to what produced it. It is one facet of the trust fabric.Read: Governance sovereigntyRead: Runtime governance
Trust fabric
The governance layer that runs through all six platform layers rather than sitting beside them as a seventh. Its thirteen facets are identity, access, data controls, policy, security, privacy, compliance, risk, human oversight, auditability, traceability, evidence and monitoring.Read: Governance sovereigntyRead: Runtime governanceTrust and governance
Trust Profile
A record attached to every AI system that states its identity, owner, risk level, approved models, data classification, data residency, permitted systems, allowed and restricted actions, human approval rule, retention, audit and policy set.Read: Runtime governanceRead: Operational sovereigntyTrust Profile

EU regulation and standards

CLOUD Act
A 2018 US law under which US authorities can compel US-based providers to disclose data in their possession, custody or control, wherever it is stored. It is why European organisations ask who operates their cloud, not only where it sits.Read: Data sovereigntyRead: Supply-chain sovereigntyCSIS: The CLOUD Act and transatlantic trust (opens in a new tab)
Data Act
Regulation (EU) 2023/2854, applicable from 12 September 2025. Its cloud-switching rules require providers to remove barriers to switching, and prohibit switching charges, including egress charges for switching, from 12 January 2027.Read: Infrastructure sovereigntyRead: Supply-chain sovereigntyData Act cloud switching explained (opens in a new tab)
Digital Omnibus on AI
Regulation (EU) 2026/1744, in force since 27 July 2026, which amended the EU AI Act. It moved stand-alone Annex III high-risk obligations from 2 August 2026 to 2 December 2027 and Annex I product-embedded systems to 2 August 2028.Read: Governance sovereigntyGibson Dunn: Omnibus agreement (opens in a new tab)
DORA
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, applying from 17 January 2025 to EU financial entities. It requires management of ICT third-party risk, including a register of information on ICT service arrangements.Read: Supply-chain sovereigntyDORA on EUR-Lex (opens in a new tab)
EU AI Act
Regulation (EU) 2024/1689, the European Union's risk-based law on AI. It bans some practices, sets obligations for high-risk systems and for general-purpose AI models, and sets transparency duties.Read: Governance sovereigntyRead: Runtime governanceEU AI Act
EU Cloud Sovereignty Framework
A European Commission method for assessing how sovereign a cloud service is, scored against eight sovereignty objectives from strategic and legal to operational, supply chain, technology and security. Each objective is graded on SEAL levels 0 to 4.Read: Infrastructure sovereigntyRead: Supply-chain sovereigntyCommission Cloud Sovereignty Framework (opens in a new tab)
GDPR
The General Data Protection Regulation, Regulation (EU) 2016/679. It governs the processing of personal data of people in the EU, including limits on transfers outside the EU and rules on foreign court orders.Read: Data sovereignty
GPAI model
A general-purpose AI model under the EU AI Act: a model that can serve many tasks and be built into many systems. Obligations on providers of such models have applied since 2 August 2025.Read: Model sovereigntyRead: Governance sovereignty
High-risk AI system
An AI system the EU AI Act places in its strictest permitted tier, such as those used in employment, essential services or critical infrastructure. Following the Digital Omnibus, stand-alone Annex III obligations apply from 2 December 2027.Read: Governance sovereignty
ISO/IEC 42001
ISO/IEC 42001:2023, the international standard for an AI management system, published in December 2023. Organisations can adopt it as a framework and have a management system audited against it.Read: Governance sovereigntyISO/IEC 42001 (opens in a new tab)
NIS2
Directive (EU) 2022/2555, the EU's updated cybersecurity law. It requires risk-management measures and incident reporting from essential and important entities across many sectors.Read: Supply-chain sovereignty
NIST AI RMF
The US National Institute of Standards and Technology AI Risk Management Framework 1.0, released 26 January 2023. It is voluntary and organised into four functions: Govern, Map, Measure and Manage.Read: Governance sovereigntyNIST AI RMF
SEAL
Sovereignty Effectiveness Assurance Level, the 0 to 4 scale in the EU Cloud Sovereignty Framework, from no sovereignty (SEAL-0) to full digital sovereignty (SEAL-4). Tenders can set a minimum level per objective.Read: Infrastructure sovereignty
Schrems II
The July 2020 Court of Justice of the EU judgment that invalidated the EU-US Privacy Shield and required organisations relying on standard contractual clauses to assess whether the destination country protects the data in practice.Read: Data sovereignty

From vocabulary to a working platform

Start with one entry point. Add intelligence, agents, workflows and infrastructure as you prove value. Or read the step-by-step build guide and take the readiness assessment.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.