Skip to main content
Home
  • Home
  • Defining Responsible Agentic AI
  • Principle 1: Define a Clear Purpose and Measure Success
  • Principle 2: Provide Oversight and Ownership
  • Principle 3: Minimize Known Risks
  • Principle 4: Create an Accessible Audit Trail
  • Deploying Agentic AI
  • Practical Guide to Internal-Facing AI Agents
  • Practical Guide to External-Facing AI Agents
  • Governing Responsible AI
  • Governance Approach
  • Change Types and Review Path
  • Glossary and Additional Resources
  • Glossary
  • Additional Resources
  • Acknowledgments
  • Glossary

    Accountable owner: The person responsible for ensuring the generative AI agent is deployed and governed responsibly; they make final decisions on major changes and exceptions to the agent.

    Agentic generative AI: An artificial intelligence system, preconfigured with instructions and relevant background information, that can autonomously interpret goals and constraints, plan or select steps, call tools or take actions in systems, and iterate based on user or retrieved input.

    Bias gap: The extent to which subgroup members report that an AI agent perpetuates any stereotypes or prejudices based on their identity—for example, whether users from one subgroup report that the agent’s language, tone, or assumptions feel more stigmatizing, judgmental, or stereotype-reinforcing than other users do.

    Builder: An IT specialist who creates a new agentic generative AI tool or a new application of an existing tool to resolve a specific business or policy problem.

    Change proposal: A structured request to add, revise, or retire an agentic tool component (e.g., rubric criteria, test set, documentation template, required approval).

    Completeness: How well an AI system’s response covers all necessary elements of the request—no key steps, constraints, or required details omitted.

    Contributor: Any staff member who proposes a change, submits a test scenario, improves documentation, or provides feedback on an AI tool.

    Correctness: Whether an AI system’s response is factually accurate, and how well it avoids introducing errors.

    Decision gap: Any discrimination against subgroups evident in an AI agent’s recommendations or decisions—for example, if the agent is much more likely to recommend additional documentation or human review for users with limited English proficiency than for otherwise similar English-speaking users.

    Evaluation lead: The person responsible for defining the AI agent’s purpose and measuring its success; they own the evaluation criteria, evidence plans, rubrics, and scoring guidance.

    Evidence tiering: A system for classifying evidence, with tier 1 used for the highest evidence:

    • Tier 1—Randomized controlled evaluation: System owners have performed strong statistical analyses with counterfactuals determined through randomized trials or random assignment.
    • Tier 2—Quasi-experimental evaluation: System owners have performed strong statistical analyses with credible counterfactuals based on best practices in the literature, but where full randomization was not possible.
    • Tier 3—Correlational evidence with controls: System owners have performed credible observational data analysis and compared outcomes with relevant statistical controls where possible.
    • Tier 4—Design evidence: System owners have a documented and well-defined logic model or theory of action with clearly defined assumptions.

    Explainability and clarity: How well an AI agent provides evidence for its output that is clear, well-formatted, and actionable; accurately reflects the system’s process for generating the answer; and clearly communicates the agent’s knowledge limits.

    Generative AI (Gen AI) committee: A cross-functional forum that decides on high-impact changes to an agentic AI tool and resolves tradeoffs; it advises the accountable owner.

    Governance: The rules, roles, and decisionmaking processes that determine who can propose, review, approve, and publish changes to an AI agent or tool.

    Groundedness: How well an AI agent’s response is supported by the allowed sources or context, cites sources, and does not invent unsupported claims.

    Independent reviewer: A person who is neither a contributor nor part of the AI governance structure and is asked to assess high-impact updates to an AI agent (e.g., peer reviewer, auditor, or designated subject-matter expert).

    Indirect injection: Whether hidden instructions in sources can redirect an AI agent to perform malicious actions.

    Knowledge-source poisoning: Whether an agentic AI system treats external sources as untrusted input.

    Maintainers: A small group (typically the accountable owner, evaluation lead, responsible agentic AI lead, security lead, and transparency lead) that triages, reviews, and approves low- and medium-impact changes to an AI tool.

    Non-experts: Users who lack the subject matter expertise necessary to review and determine the correctness, reliability, groundedness, and completeness of a generative AI tool or application’s output.

    Outcome gap: The difference in AI-agent-driven-outcomes between subgroups—for example, whether people with disabilities are less likely to complete a benefit application process or receive benefits.

    Prompt injection resistance (direct + indirect): Attempts to override instructions, leak system prompts, or manipulate tool use—especially via retrieved documents or external content.

    Release artifact/audit trail: A consistent, reviewable record of each update to an AI agent or system that summarizes what changed, what was tested, what passed/failed, and what risks were mitigated versus accepted.

    Reliability under variation: How consistently an AI agent performs across reasonable variations in phrasing, order, multi‑turn context, or scenario path.

    Responsible agentic AI lead: The person working with members of the target population and ensuring both harms and opportunities are identified, measured, mitigated, and monitored; they own the stakeholder input and feedback mechanisms.

    Risk-based review: A change-control approach that scales scrutiny based on the change’s likely impact on safety, equity, security, transparency, or decision outcomes.

    Security lead: The person responsible for minimizing known risk; they own the security and misuse-resistance tests.

    Sensitive information disclosure: Leakage of private or confidential data, cross-session leakage (one user’s session information provided to another user), and unintended disclosure of internal instructions or operational details of the agent. Proper data classification (personally identifiable information, sensitive data, non-sensitive data, etc.) is an essential foundation to protect against sensitive information disclosure.

    Toolkit: The versioned set of evaluation rubrics, test scenarios, scoring guidance, security checks, transparency artifacts, and templates used to help an organization (and its partners) assess the readiness of agentic generative AI systems for a specific task and audience.

    Transparency lead: The person responsible for the release artifact, public communications, and human-in-the-loop monitoring; they own documentation requirements, release artifacts, auditability expectations, and human-in-the-loop monitoring.

    Unauthorized actions/excessive agency: Whether an AI agent can be induced to take actions beyond its authorization boundaries, such as changing system instructions or data or communicating externally when not permitted to do so.

     


     

    Next section: Additional Resources