DENQ
DEContact
Home / Glossary

Glossary: terms relating to AI agents, automation and AI governance.

Short definitions of the terms that come up again and again in corporate AI projects. As of September 2026.

AI agentAgent systemAgentic AIAI automationProcess automationLanguage model (LLM)Use caseInterface (API)Tool callingModel Context Protocol (MCP)Retrieval-Augmented Generation (RAG)OrchestrationSystem integrationHallucinationPrompt injectionAI governanceAgent BoardAutonomy levelsHuman-in-the-loopPrinciple of least privilegeLoggingData classificationEU AI ActGDPRCo-determination and AIAI Operating ReviewAI readinessSuitability checkDay-to-day operationBusiness caseValue trackingCorrection rate
Basic terms01

AI agents and automation

AI agent

An AI agent is a software system that uses a language model to evaluate information, prepare decisions and carry out actions in other systems via interfaces. In a company, every agent needs defined permissions, approvals and a responsible person.

Agent system

An agent system is the combination of one or more AI agents, the connected systems, data sources, approval steps and logging. The term describes the entire operating environment, not just the individual agent.

Agentic AI

Agentic AI is the English umbrella term for AI applications that do not just generate text but independently plan multi-step tasks and carry them out with tools. In German, people usually speak of AI agents or agent-based systems.

AI automation

AI automation refers to the automation of workflows in which a language model reads, classifies or drafts content. It complements conventional automation where fixed rules are not enough, for example with emails, documents or free text.

Process automation

Process automation is the execution of recurring work steps by software according to fixed rules, for example transferring data between two systems. It is reliable and cost-effective as long as a workflow requires no discretion.

Language model (LLM)

A language model, or large language model (LLM), is an AI model that understands and generates text. It forms the basis for AI agents, but on its own it makes no decisions in company systems.

Use case

A use case is a specific application of AI in a company, for example checking incoming invoices against purchase orders. Use cases are assessed and prioritised by business value, feasibility and risk profile.

Technology02

Technology and integration

Interface (API)

An interface, or application programming interface (API), is the technical access point through which software exchanges data with other systems. AI agents read and change data in CRM, ERP or ticketing systems exclusively through such interfaces.

Tool calling

Tool calling refers to a language model's ability to call defined tools, such as a search in the CRM or creating a ticket. Which tools an agent may use is defined for each agent.

Model Context Protocol (MCP)

The Model Context Protocol is an open standard for connecting AI applications to tools and data sources in a uniform way. Anthropic published it in November 2024; it is now supported by numerous providers.

Retrieval-Augmented Generation (RAG)

Retrieval-Augmented Generation is a method in which a language model retrieves relevant content from approved sources, such as policies or manuals, before answering. This way, the answer is based on company knowledge rather than only on the model's training.

Orchestration

Orchestration is the control of several steps, agents or tools in the right order, including retries, error handling and handovers to people.

System integration

System integration is the connection of an AI agent to a company's existing system landscape, such as CRM, ERP, ticketing, email and document repositories, including permissions and data flows.

Hallucination

A hallucination is a factually incorrect statement by a language model that is phrased convincingly. Approved sources, source references, spot checks and human approvals reduce the risk.

Prompt injection

Prompt injection is an attack in which hidden instructions in emails, documents or web pages are meant to induce a language model to take unwanted actions. Protection includes separating content that is read from permissions to act, and approvals before external actions.

Governance03

Governance, security and law

AI governance

AI governance comprises the rules, roles and procedures a company uses to steer its use of AI: who approves use cases, which permissions a system receives, how results are checked and logged, and who is responsible.

Agent Board

An Agent Board is a cross-functional body made up of management, process owners, IT, information security, data protection and employee representatives. It decides on the approval, permissions and autonomy level of each agent, as well as on its expansion or decommissioning.

Autonomy levels

Autonomy levels define how independently an AI agent may act: Level 1 Assist, Level 2 Prepare, Level 3 Execute after approval, Level 4 Autonomous execution within defined limits. The Agent Board decides on each higher level based on KPIs.

Human-in-the-loop

Human-in-the-loop means that a person checks and decides at defined points in an automated workflow before the system continues. Typical examples are approvals before payments, external messages or changes to master data.

Principle of least privilege

Under the principle of least privilege, a system receives only the permissions its task requires. For AI agents, read, write and execute permissions are granted and documented separately for each system.

Logging

Logging is the complete and traceable recording of all of an agent's actions, tool calls, decisions and approvals, each assigned to a responsible person.

Data classification

Data classification defines which data a language model may process, where it is processed and which storage and deletion periods apply.

EU AI Act

The EU AI Act, Regulation (EU) 2024/1689, governs the use of AI in the European Union based on a risk-based approach. The obligations apply in stages from 2025. The legal classification of a specific system is carried out by the legal department or external legal counsel.

GDPR

The General Data Protection Regulation (GDPR) governs the processing of personal data in the EU. For AI agents, purpose limitation, data minimisation, data processing agreements and deletion periods are particularly relevant.

Co-determination and AI

In Germany, the works council has co-determination rights when technical systems are capable of monitoring employees' behaviour or performance. AI initiatives should therefore involve employee representatives early, with a clear description of the scope of functions and of the evaluations that are excluded.

Approach04

Approach and management

AI Operating Review

The AI Operating Review is DENQ's entry engagement and takes two to three weeks. It produces a prioritised use case portfolio, business cases, an assessment of existing initiatives, a governance framework and an implementation recommendation.

AI readiness

AI readiness describes how well prepared a company is to use AI in day-to-day business: target state and priorities, documented processes and available data, governance, responsibilities and measurement.

Suitability check

Before any recommendation, the suitability check clarifies whether a process needs an AI agent. It examines repetition and volume, need for judgement, available data, clear ownership and an acceptable risk profile.

Day-to-day operation

Day-to-day operation means that an AI application runs permanently in day-to-day business, with fixed owners, KPIs, monitoring and a defined procedure for changes, unlike a time-limited pilot.

Business case

A business case sets the effort and expected impact of a use case against the KPIs by which success is measured. It is the basis for approval by management or the Agent Board.

Value tracking

Value tracking is the ongoing measurement of an AI application's impact, for example through processing volume, lead time, correction rate and exceptions. The KPIs feed into decisions on autonomy levels and scaling.

Correction rate

The correction rate is the share of an agent's results that had to be corrected by people. It is a key metric for deciding on a higher autonomy level.

Which of these topics affect your company?

The AI Readiness Check shows where you stand in about four minutes.

Start the check