Glossary
A plain-English AI glossary for professional firms
This plain-English AI glossary defines the terms partners and practice managers hear once their firm starts using AI, from retrieval-augmented generation and hallucination to data residency and lock-up. Each definition is short, says what the term means first, and gives an example from a law, accounting or advisory firm. For fuller guides, see the knowledge base.
A
- AI acceptable use policy
- An AI acceptable use policy is a short internal document that sets out which AI tools staff may use, what they may use them for, and what information must never be entered into them.
- AI agent
- An AI agent is software that uses a large language model to work towards a goal by taking actions, not just answering questions.
- Answer engine optimisation (AEO)
- Answer engine optimisation (AEO) is the work of making a website easy for AI answer engines, such as ChatGPT search, Perplexity, and Google's AI Overviews and AI Mode, to find, understand and cite when they answer a question.
- API (application programming interface)
- An API (application programming interface) is a published set of rules that lets one piece of software ask another for data, or ask it to do something, without a person copying information between screens.
- Audit log
- An audit log is a time-stamped record of who did what in a system, and when.
- Australian Privacy Principles (APPs)
- The Australian Privacy Principles (APPs) are the 13 legally binding rules in the Privacy Act 1988 that govern how covered organisations collect, use, disclose, secure and correct personal information.
C
- Conflict check
- A conflict check is the search a firm runs before taking on a new client or matter, to confirm that acting would not create a conflict of interest.
- Context window
- A context window is the maximum amount of text, measured in tokens, that an AI model can consider at one time.
- Core Web Vitals
- Core Web Vitals are three measurements Google uses to judge how a web page feels to real visitors: Largest Contentful Paint (LCP) for loading, Interaction to Next Paint (INP) for responsiveness, and Cumulative Layout Shift (CLS) for visual stability.
D
- Data residency
- Data residency is the physical location where data is stored and processed, usually stated as a country or a cloud region such as Microsoft Azure's Australia East.
- Data sovereignty
- Data sovereignty is the idea that data is governed by the laws of a particular country, and those laws decide who can access it, compel its disclosure or restrict its transfer.
E
- Embedding
- An embedding is a list of numbers that represents the meaning of a piece of text, so software can measure how similar two passages are.
- Essential Eight
- The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate (ASD) through its Australian Cyber Security Centre (ACSC).
F
- Fine-tuning
- Fine-tuning is further training of an existing AI model on a set of your own examples, so it consistently follows a particular style, format or task.
G
- Generative AI
- Generative AI is artificial intelligence that creates new content, such as text, images, audio or code, in response to an instruction called a prompt.
- Guardrails
- Guardrails are the rules and technical controls that limit what an AI system can see, say and do, so it stays within what an organisation has approved.
H
- Hallucination
- A hallucination is an answer from an AI model that sounds confident and plausible but is false or has no support in any source, such as a case citation that does not exist or a figure that appears in no document.
- Human-in-the-loop
- Human-in-the-loop means a person reviews, approves or corrects an AI system's work at set points before it takes effect.
K
- Knowledge assistant
- A knowledge assistant is an AI tool that answers staff questions from an organisation's own documents, such as precedents, policies, procedures and past advice, and shows which documents each answer came from.
L
- Large language model (LLM)
- A large language model (LLM) is an AI system trained on vast amounts of text to predict the next piece of text in a sequence, which lets it write, summarise, translate and answer questions in plain language.
- llms.txt
- llms.txt is a proposed plain-text file, written in Markdown and placed at the root of a website (for example, /llms.txt), that gives large language models a short summary of the site and links to its most useful pages.
- Lock-up
- Lock-up is the money a firm has earned but not yet collected: work in progress (WIP) that has not been billed, plus invoices that have not been paid.
M
- Multi-factor authentication (MFA)
- Multi-factor authentication (MFA) is a login check that asks for two or more different kinds of proof before granting access: something you know, such as a password; something you have, such as a phone or security key; or something you are, such as a fingerprint.
N
- Notifiable Data Breaches (NDB) scheme
- The Notifiable Data Breaches (NDB) scheme is the part of the Privacy Act 1988 that requires covered organisations to tell affected individuals and the Office of the Australian Information Commissioner (OAIC) about an eligible data breach.
P
- Practice management system (PMS)
- A practice management system is the software a professional firm uses to run client work: client records, jobs or matters, time recording, work in progress, billing and the reports partners rely on.
- Private AI
- Private AI is an AI system set up for one organisation's exclusive use, so its prompts, documents and outputs are not processed through shared public AI tools.
- Prompt
- A prompt is the instruction, question or material you give an AI model to get a response.
- Prompt injection
- Prompt injection is an attack in which text an AI system reads contains instructions that override the ones it was given.
R
- Recoverability
- Recoverability is the share of the value of recorded time that a firm actually bills, shown as a percentage.
- Retrieval-augmented generation (RAG)
- Retrieval-augmented generation (RAG) is a way of making an AI model answer from a chosen set of documents rather than from what it learned in training alone.
- Role-based access control (RBAC)
- Role-based access control (RBAC) is a way of managing permissions in which access is granted to roles, such as partner, solicitor, accountant or administrator, rather than to each person one by one.
S
- Shadow AI
- Shadow AI is the use of AI tools at work without the firm's knowledge or approval, such as staff pasting client emails into a personal ChatGPT account, installing an AI browser extension or letting an AI note-taker join client meetings.
- Single sign-on (SSO)
- Single sign-on (SSO) is a login method that lets staff use one work account to sign in to many applications, instead of keeping a separate password for each.
- Structured data
- Structured data is code added to a web page that states facts about the page in a standard vocabulary, so search engines can read them without guessing: a firm's name, address and services, an article's author and dates, or a page's place in the site.
T
- Token
- A token is the small unit of text an AI model reads and writes, usually a whole word, part of a word, a number or a punctuation mark.
- Trust accounting
- Trust accounting is how a law practice receives, records and pays out money it holds for clients, such as money paid in advance for legal costs.
U
- Utilisation
- Utilisation is the share of a person's available working hours spent on chargeable client work, shown as a percentage.
V
- Vector database
- A vector database stores information as embeddings: long lists of numbers that capture what a passage of text means, so software can find content by meaning rather than by exact keywords.
W
- Work in progress (WIP)
- Work in progress (WIP) is the value of time recorded and disbursements incurred on client jobs or matters that have not yet been billed.
Z
- Zero data retention (ZDR)
- Zero data retention (ZDR) is an arrangement in which an AI provider agrees not to store your prompts or the model's responses once each request has been answered.
Secure by design. Set up correctly. Fully managed.
Talk to us before you commit to anything
Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.
