AI Risk (Risk Vectors)
The potential for data exposure, privacy violation, or non-compliance created when sensitive information is processed by AI without safeguards.
Related terms
Confidential Data
The broader category that PII and PHI both sit inside — anything an organization has a legal, contractual, or competitive obligation to keep from being disclosed, which makes it the thing AI risk controls ultimately exist to protect, whatever specific name the data happens to carry.
LLM (Large Language Model)
The underlying technology behind most modern AI tools — a model trained on vast amounts of text to predict and generate language — and the reason nearly every AI risk in this glossary traces back to the same basic fact: an LLM processes whatever text it's given, sensitive or not, without knowing the difference on its own.
NIST (National Institute of Standards and Technology)
The U.S. federal agency whose voluntary cybersecurity, privacy, and AI risk management frameworks — while not legally binding on their own — have become the reference standard that regulators, auditors, and enterprise customers expect organizations to demonstrate alignment with.
Access Control
The rules that decide who — and what, including an AI model — is allowed to see a given piece of data, and the boundary that keeps everyone else out.
Agentic Workflows
When AI stops answering one question at a time and starts chaining actions together on its own — which is exactly when data exposure stops being a single event and starts being a sequence of them.
AI Act (EU AI Act)
European Union legislation regulating AI systems by risk level — the first comprehensive, binding AI-specific law of its kind, and the reason "AI compliance" now means something distinct from general data protection compliance for any organization whose AI systems touch people in the EU.
See AI Risk (Risk Vectors) in practice
Questa AI anonymizes sensitive data before it reaches any AI model — across documents and live prompts, with governance and data-residency control.