On this page6 sections
This AI agent glossary defines 100 terms you meet when you use or build AI agents, from A2A to zero-shot, each in one or two plain sentences. Where we have a full guide on a term, the definition links to it.
Three terms explain most of the rest. An AI agent is a model that uses tools in a loop to reach a goal. “Agentic” describes AI that plans and acts with some independence. And a workflow follows steps a developer fixed in advance, while an agent chooses its own.
- An AI agent is a model plus tools plus a loop plus a goal. Most other terms describe one part of that picture.
- Tools, MCP and skills are how agents reach other software and learn procedures.
- Tokens, the context window and memory decide what an agent knows at each step.
- Approvals, sandboxes and least privilege keep an agent’s mistakes small.
- Benchmarks and evals are how you check whether an agent actually works.
Terms A to C
A2A (Agent2Agent protocol)
An open standard that lets AI agents from different vendors discover each other, hand off tasks and share results. Google created it and donated it to the Linux Foundation; it complements MCP, which connects agents to tools rather than to other agents. More in A2A explained.
Accessibility tree
The structured list of buttons, fields and labels that an app exposes for screen readers. Computer use agents can read it instead of screenshots, which is faster and cheaper than working from pixels. More in computer use AI.
Agent (AI agent)
A system that pursues a goal by running a model in a loop with tools, choosing its own next step until the goal is met. A chatbot answers; an agent acts. More in what is an AI agent?
Agent harness
The software around a model that turns it into an agent: it runs the loop, passes tool calls to real tools, manages the context and enforces permissions. OpenAI, for example, says its cloud tasks run “the Codex harness”. More in build your first AI agent.
Agent loop
The cycle an agent repeats until a task is done: look at the situation, choose an action, act, then check the result. Each pass through the loop is one step. More in what is an AI agent?
Agent memory
Information an agent keeps between steps or sessions, such as notes, decisions and preferences. It is stored outside the model, so it survives a full context window or a new conversation. More in how AI agents remember.
Agent skills
Folders of instructions, scripts and resources, each anchored by a SKILL.md file, that an agent loads only when a task calls for them. Anthropic developed the format and released it as an open standard. More in agent skills explained.
Agentic AI
AI that pursues goals by planning and taking actions with some independence, instead of answering one prompt at a time. “Agentic” describes a range, from assistants that suggest to agents that act alone. More in what is an AI agent?
Agentic browser
A web browser with a built-in agent that can read pages, click, type and fill in forms for you, often while signed in to your accounts. Also called an AI browser. More in AI browsers in 2026.
Agentic coding
Software development in which an AI agent plans changes, edits files, runs commands and tests, and iterates, while a person sets the goal and reviews the result. More in vibe coding vs agentic coding.
Agentic workflow
A multi-step process in which an AI agent handles some or all of the steps, often mixing fixed steps with steps where the agent decides what to do. More in 10 agentic workflows.
AGENTS.md
A plain Markdown file in a code repository that tells coding agents how to build, test and follow the project’s conventions. Its site calls it “a README for agents”. More in the AGENTS.md guide.
Allowlist
A list of the sites, commands or apps an agent may use, where anything not on the list is blocked. It is one of the simplest ways to limit what a confused or hijacked agent can do. More in computer use AI.
API (application programming interface)
A defined way for one program to request data or actions from another. Agents reach many services through APIs, either directly or through tools such as MCP servers. More in MCP vs API vs function calling.
Approval
A checkpoint where an agent stops and asks a person before an action, such as running a command, sending an email or paying for something. Most agents let you choose which actions need one. More in desktop AI agents.
Autonomy level
How much an agent may do without asking: suggest only, act with your approval, or act alone. Many products let you set it per task or per tool. More in what is an AI agent?
Background agent
An agent that works on a task on remote servers while you do something else, then reports back, often with a pull request for code. Also called a cloud agent. More in the best AI coding agents.
Benchmark
A fixed set of tasks used to score and compare AI models or agents, such as SWE-bench for coding or OSWorld for computer use. Scores depend on the exact test and setup, so compare only like with like. More in AI benchmarks explained.
Chain of thought
The intermediate reasoning steps a model writes before its final answer. A 2022 paper showed that prompting for these steps improves results on arithmetic, commonsense and symbolic reasoning tasks. More in reasoning models explained.
Chatbot
An AI app that replies to messages. Unlike an agent, it does not act in other tools or run multi-step tasks on its own. More in AI agent vs chatbot.
CI (continuous integration)
Automated checks, such as tests and linting, that run on every code change before it is merged. Coding agents can also run inside CI to review or fix code. More in run a coding agent in CI.
CLI (command-line interface)
A text interface where you type commands, for example in the Terminal app on a Mac. Many coding agents, including Claude Code and Codex, run there. More in the terminal for beginners.
Coding agent
An AI agent built for software work: it reads a codebase, edits files, runs commands and tests, and proposes changes for review. More in the best AI coding agents.
Compaction
Shrinking a long conversation by summarizing its older parts, so an agent can keep working when its context window fills up. Details from early in a task can get lost in the summary. More in context engineering.
Computer use
An agent’s ability to operate software through its interface, by reading the screen and sending mouse and keyboard actions, instead of calling an API. More in computer use AI.
Connector
A ready-made link between an AI app and another service, such as Google Drive or Slack, that lets the AI read or act there. Claude’s connectors are built on MCP. More in what is MCP?
Context engineering
Deciding what goes into a model’s context at each step, such as instructions, files, tool results and memory, so an agent has what it needs and nothing that distracts it. More in context engineering.
Context window
The most text, measured in tokens, that a model can consider at once, including your prompt, any files and its own reply. More in tokens and context windows.
Copilot
An AI assistant that works alongside you inside an app, suggesting and drafting while you stay in control. It is also the brand name of Microsoft’s and GitHub’s assistants. More in AI agent vs chatbot.
Terms D to H
Deep research
An AI mode that plans many searches, reads dozens or hundreds of sources and writes a cited report, taking minutes instead of seconds. More in how to research anything with AI.
Desktop agent
An AI agent that runs as an app on your computer and can work with local files, apps and sometimes the terminal. More in desktop AI agents.
Diff
A view of exactly what changed between two versions of a file, line by line. Reading an agent’s diff is how you check its work before you accept it. More in how to review AI-written code.
Embedding
A list of numbers that represents the meaning of a piece of text or an image, so that similar meanings sit close together. Embeddings power semantic search, which matches by meaning rather than exact words. More in embeddings explained.
Eval
A repeatable test of an AI system on your own tasks, with a way to score the output. Evals tell you whether a change to the model or prompt made things better or worse. More in evals for beginners.
Few-shot prompting
Including a few worked examples in a prompt so the model follows their format and approach. More in the prompt engineering guide.
Fine-tuning
Further training a model on your own examples to change its style or behavior. It teaches patterns well, but it is a poor way to add facts that change often. More in fine-tuning vs RAG vs prompting.
Frontier model
One of the most capable models available at a given moment, usually from the largest labs. The label moves as new models ship. More in every AI model released in 2026.
Function calling
A model feature in which the model returns a structured request to run a named tool with specific arguments; your code runs the tool and sends back the result. Also called tool calling. More in MCP vs API vs function calling.
GEO (generative engine optimization)
Making web content easy for AI assistants and AI search to find, understand and cite. More in how to get cited by AI search.
Grounding
Tying a model’s answer to specific sources, such as search results or your documents, so its claims can be checked. More in RAG explained.
Guardrails
Checks and limits around an AI system, such as input filters, permission rules and approval steps, that stop it from doing harmful or unwanted things. Instructions alone are not guardrails, because a model can ignore them. More in is it safe to let AI control your computer?
Hallucination
When a model states something false or invented with confidence, such as a fake citation or a function that does not exist. More in why AI makes things up.
Handoff
Passing a task, with its context, from one agent to another, or from an agent to a person. More in multi-agent systems explained.
Hooks
Scripts that run automatically at set points in an agent’s work, such as before a tool call or after a file edit. Teams use them to enforce rules, for example blocking edits to test files. More in test-driven development with AI.
Human in the loop
A design in which a person reviews or approves key steps of an AI system’s work before it continues. It trades some speed for safety on actions that are hard to undo. More in AI customer support.
Terms I to M
Indirect prompt injection
A prompt injection hidden in content the AI reads, such as a web page, email or file, rather than typed by the user. It is the main injection risk for agents that browse or read inboxes. More in prompt injection explained.
Inference
Running a trained model to get an output. Every request you send is an inference call, and inference is what per-token API prices charge for. More in AI API pricing compared.
Jailbreak
A prompt crafted to make a model ignore its safety rules. OWASP classes it as a form of prompt injection. More in prompt injection explained.
Knowledge cutoff
The date after which a model has no training data, so it does not know about later events unless it searches the web or you tell it. More in why AI makes things up.
Large language model (LLM)
A model trained on huge amounts of text to predict the next token, which lets it write, summarize, translate, reason and code. It is the engine inside most AI agents. More in how large language models work.
Least privilege
Giving an agent only the access a task needs, such as one folder or one account, so that mistakes and attacks can do less damage. More in is it safe to let AI control your computer?
LLM-as-a-judge
Using one model to grade another model’s output against a rubric. It makes evaluation faster, but people should spot-check its grades. More in evals for beginners.
Local model
A model that runs on your own computer instead of a vendor’s servers. It keeps your data on your machine, but your hardware limits its size and speed. More in how to run AI models locally.
MCP (Model Context Protocol)
An open-source standard for connecting AI applications to external systems such as files, databases and tools. Its official site compares it to a USB-C port for AI applications. More in what is MCP?
MCP host and client
The host is the AI application you use, such as Claude Desktop or VS Code. For each MCP server it connects to, the host creates a client that keeps a dedicated connection to that server. More in what is MCP?
MCP server
A program that provides context to AI applications over MCP, through tools to call, resources to read and prompts to reuse. It can run on your own machine or remotely. More in how to build an MCP server.
Mixture of experts (MoE)
A model design with many sub-networks, called experts, where a router runs only a few of them for each token. It lets very large models answer faster and more cheaply than their total size suggests. More in how to run AI models locally.
Model routing
Choosing a model for each request, usually sending easy requests to a cheap model and only hard ones to an expensive model. More in how to cut your AI bill.
Multi-agent system
Several AI agents working on one goal, each with its own role, usually coordinated by an orchestrator. It helps when work splits into independent parts, and it uses more tokens. More in multi-agent systems explained.
Multimodal model
A model that can take in or produce more than one kind of data, such as text, images, audio or video. Computer use agents rely on one to read screenshots. More in computer use AI.
Terms N to R
Non-deterministic
Able to give different outputs for the same input. Most AI agents behave this way, which is why you should test them several times on the same task. More in how large language models work.
Observability
Recording each step an agent takes, such as prompts, tool calls, results, timing and cost, so you can see why it did what it did. The record of one run is often called a trace. More in build your first AI agent.
Open-weight model
A model whose trained weights anyone can download and run, usually under a license with conditions. Open weights are not always fully open source, because the training data and code may stay private. More in open-weight vs closed AI models.
Orchestrator
The agent or program in a multi-agent system that breaks a task into parts, hands them to worker agents and combines their results. More in multi-agent systems explained.
OSWorld
A benchmark that tests computer use agents on real tasks in real desktop apps and scores whether they finish them. More in computer use AI.
Parameters
The learned numbers inside a model, also called weights. Their count, such as 27 billion, is a rough guide to a model’s size and the memory it needs. More in how large language models work.
Permission mode
A setting that decides what an agent may do without asking, from read-only, to asking before edits, to full access. Some tools call the no-prompts setting “yolo mode”. More in desktop AI agents.
Plan mode
A mode in which an agent investigates a task and writes a plan for you to approve before it changes anything. More in spec-driven development.
Prompt caching
Reusing the processed form of a repeated prompt prefix, such as long instructions or documents, so later requests cost less and return faster. More in how to cut your AI bill.
Prompt chaining
Splitting a task into fixed steps, where each model call works on the output of the previous one. Anthropic lists it as a basic workflow pattern. More in 10 agentic workflows.
Prompt engineering
Writing and refining the instructions you give a model so it does what you want reliably. More in the prompt engineering guide.
Prompt injection
When text an AI reads changes its behavior in ways its user did not intend, such as hidden instructions on a web page. OWASP ranks it first among the risks for LLM applications. More in prompt injection explained.
Quantization
Storing a model’s numbers at lower precision, such as 4-bit instead of 16-bit, so it needs less memory, at a small cost in quality. It is how large models fit on laptops. More in how to run AI models locally.
RAG (retrieval-augmented generation)
Fetching relevant passages from your documents or the web at question time and giving them to the model, so its answer draws on those sources. More in RAG explained.
Rate limit
A cap on how many requests or tokens you can use in a period, set by an API or a plan. Hitting it pauses you until the window resets. More in AI usage limits explained.
ReAct
An agent pattern, from a 2022 paper, in which the model alternates between reasoning about what to do and taking an action, then uses the result to decide the next step. Many agent loops follow the same idea. More in build your first AI agent.
Reasoning model
A model trained to work through a problem step by step before answering, trading speed and cost for accuracy on hard tasks. More in reasoning models explained.
Terms S to Z
Sandbox
An isolated environment, such as a container or virtual machine, where an agent can run code without touching the rest of your system. More in is it safe to let AI control your computer?
Scheduled task
A task an agent runs automatically on a timetable, such as a weekly report every Monday morning. More in 10 agentic workflows.
Slopsquatting
Registering a software package under a name that AI coding tools tend to invent, so that code installing the made-up name pulls in the attacker’s package. More in slopsquatting explained.
Small language model (SLM)
A model small enough to run cheaply, or on a laptop or phone, that is often good enough for narrow, well-defined tasks. More in small language models.
Spec-driven development
Writing a clear specification first and having an agent build to it, so the spec, not the chat history, is the source of truth. More in spec-driven development.
Structured output
Model output constrained to a set format, such as JSON that matches a schema, so software can read it reliably. More in build your first AI agent.
Subagent
A helper agent that a main agent starts for one part of a task. It works with its own fresh context and reports back a summary. More in multi-agent systems explained.
SWE-bench
A family of benchmarks that ask AI models to fix real issues from open-source GitHub projects, checked by running each project’s own tests. More in AI benchmarks explained.
System prompt
Standing instructions, set by the app or developer, that shape how a model behaves for a whole conversation. More in the prompt engineering guide.
Temperature
A setting that controls how random a model’s word choices are. Lower values give more predictable output, and higher values more varied output. More in how large language models work.
Terminal-Bench
A benchmark that tests whether an AI agent can complete real tasks in a computer terminal. Its versions use different task sets, so compare scores only within one version. More in the coding agent leaderboard.
Test-driven development (TDD)
Writing a failing test first, then code that makes it pass. With agents, tests give the agent a clear finish line and catch it when it breaks something. More in test-driven development with AI.
Token
The unit of text a model reads and writes: a short word, part of a longer word, a digit or a punctuation mark. In English, a token averages about three quarters of a word. More in tokens and context windows.
Tool
A capability an agent can call to act or fetch information, such as web search, running code, reading a file or sending an email. Tools are what let an agent do more than write text. More in what is an AI agent?
Tool poisoning
An attack that hides malicious instructions in a tool’s description, the text an agent reads to learn what the tool does, so the agent is steered into harmful actions. More in MCP security risks.
Usage limit
How much AI use a subscription allows in a period, often measured over a rolling window of a few hours plus a weekly cap. More in AI usage limits explained.
Vector database
A database built to store embeddings and quickly find the ones closest to a query. It is the usual storage behind RAG. More in RAG explained.
Vibe coding
Building software by describing what you want to an AI and accepting its code largely without reading it, judging only by whether the result works. More in what is vibe coding?
Voice agent
An agent you talk to: it listens, reasons, speaks back and may take actions. More in voice AI explained.
Workflow
A system where models and tools follow steps a developer fixed in advance. Anthropic contrasts it with an agent, where the model directs its own process and tool use. More in 10 agentic workflows.
Worktree
A second working copy of the same Git repository, on its own branch. Worktrees let several agents work in parallel without overwriting each other’s changes. More in Git for AI coding.
Zero-click attack
An attack that succeeds without the victim doing anything beyond normal use, such as an agent reading a poisoned email or calendar invite. More in prompt injection explained.
Zero-shot prompting
Asking a model to do a task with instructions only and no examples. More in the prompt engineering guide.
FAQ
What does agentic mean?
Agentic describes AI that works toward a goal by planning and taking actions, such as searching, editing files or using apps, with some independence. It is a matter of degree: an assistant that suggests is slightly agentic, and one that runs a whole task alone is highly agentic.
What is the difference between an AI agent and a workflow?
In a workflow, a developer fixes the steps in advance and the model fills them in. In an agent, the model decides its own next step and which tools to use. Anthropic draws the line this way and recommends the simplest solution that works: a workflow for well-defined tasks, an agent when you need flexibility.
What is the difference between MCP and A2A?
MCP connects an agent to tools and data, such as a database or a file system. A2A connects agents to other agents, so they can discover each other and hand off tasks. The two are designed to work together.
What is the difference between an AI agent and a chatbot?
A chatbot turns your message into a reply. An agent turns your goal into actions, in a loop, until the goal is met. The same model can power both, and AI agent vs chatbot shows three requests handled each way.
Next, see the best AI agents by job, or start from the beginning with what an AI agent is.
- Building effective agents, Anthropic, December 2024
- What is the Model Context Protocol?, Model Context Protocol, accessed September 2026
- Architecture overview, Model Context Protocol, accessed September 2026
- Agent2Agent (A2A) Protocol, A2A Project, accessed September 2026
- Agent Skills overview, Agent Skills, accessed September 2026
- AGENTS.md, accessed September 2026
- LLM01:2025 Prompt injection, OWASP GenAI Security Project
- ReAct: Synergizing reasoning and acting in language models, arXiv, October 2022
- Chain-of-thought prompting elicits reasoning in large language models, arXiv, January 2022
- ChatGPT Work overview, OpenAI, accessed September 2026
- Security, Hermes Agent documentation, accessed September 2026




