#
What is a large language model (LLM)?
A large language model is created through machine learning and trained on extensive text or multimodal data to predict and generate sequences such as language. It can summarise, classify, translate, reason over supplied context and produce new text, but its outputs remain probabilistic.
Why it matters
An LLM is a component, not a complete business solution. Reliability depends on the task, model, instructions, context, integrations, evaluation and controls wrapped around it.
#
What is generative AI?
Generative AI is a class of artificial intelligence that produces new content or representations in response to input, including text, images, audio, video, code or structured output. The output is generated from learned patterns and supplied context rather than copied from a single stored answer.
Why it matters
Generation enables flexible experiences, but it introduces uncertainty, provenance and governance questions. Organisations need testing for each use case rather than assuming that fluent output is accurate, original or appropriate.
#
What is agentic AI?
Agentic AI describes systems in which a model can plan or select steps, use tools and adapt its actions to pursue a goal for a person or organisation within defined permissions. Generative AI creates or synthesises outputs. Agentic AI goes further by using outputs, context and tools to complete a task. An AI agent is a concrete implementation of agentic behaviour.
Why it matters
Agentic systems can move from explanation to action, such as placing an order, booking an appointment or requesting a quote. The ability to act makes permissions, identity, confirmation, reversibility, audit records, spending limits and human authority central design requirements.
What Retoba recommends
Use the least autonomy needed for the task. Give every tool a clear purpose and minimum permissions, require confirmation before consequential actions and provide a safe path to stop, correct or hand control to a person.
For example
Retoba’s advertising operations agent uses performance data to guide actions across advertising platforms, with approval required for changes with major consequences.
#
What makes enterprise conversational AI different from a basic chatbot?
Enterprise conversational AI is a governed conversational system designed for organisational use where accuracy, security, integration, accountability and continuous operation matter. Unlike a basic chatbot that follows a limited script or provides isolated answers, it works with approved knowledge, defined permissions, business processes and clear ownership.
Why it matters
A production system may connect to internal or customer facing services, apply role and policy controls, support human handover, undergo evaluation and improve through lifecycle management. The distinction is not how human the interface sounds, but whether the complete system can be trusted to perform its intended role consistently and be maintained over time.
#
What is AI knowledge architecture?
AI knowledge architecture is the governed structure that determines which information an AI system may use, how it is organised and how it is retrieved, interpreted and kept current. It connects authoritative sources, entities, relationships, versions, permissions and rules for resolving uncertainty or conflicting information.
Why it matters
The architecture can combine approved brand content, operational data and public sources while defining provenance, access, grounding and update responsibilities. It does not guarantee a correct answer by itself, but clear ownership and structure help AI systems answer more precisely, reveal gaps and reduce dependence on improvised prompts or unverified material.
For example
Retoba’s engineering and real estate agent brings together public records and internal project information, keeping findings linked to their sources.
#
What is AI system evaluation?
AI system evaluation is the structured testing of a complete AI experience against defined quality, safety, reliability and business requirements in its intended context. It can combine automated tests, expert review, user research, adversarial scenarios and operational monitoring. The model is only one component of the system being evaluated.
Why it matters
A system can perform well on a general benchmark and still fail with the organisation’s knowledge, language, users or workflows. Evaluation should cover factual accuracy, groundedness, behaviour, tool use, refusal, escalation, accessibility and the outcome the experience is meant to improve.
What Retoba recommends
Define representative test cases and acceptance thresholds before launch, then repeat them after changes to models, prompts, knowledge or tools. Keep human review for qualities that automated scores cannot judge reliably. See the NIST AI Resource Center.
#
What is an AI agent?
An AI agent is a system that interprets a goal, plans or selects steps and uses tools to act for a person or organisation in a digital or physical environment within defined permissions. It may search, read, write, call services, update systems or coordinate specialised components.
An AI agent describes a system’s ability to carry out tasks, not whose interests it represents. A personal assistant may act as an agent for an individual, while an organisation may operate an agent for a defined business or service role.
Why it matters
The moment an AI can act, risk moves beyond the quality of an answer. Permissions, identity, confirmation, reversibility, audit trails, spending limits and human authority become central design requirements.
For example
Retoba’s leadership operations agent carries out authorised tasks and delegates follow-up work through connected business tools.
#
What is a personal AI assistant?
A personal AI assistant helps a person find information, compare options and manage tasks according to their goals and preferences. When it can select steps and use tools to carry out a task, it acts as an AI agent within the authority the person grants and the permissions the service enforces.
Why it matters
A person may use an assistant across shopping, finance, insurance, travel, healthcare administration and other everyday services. Tasks may include reviewing account information, understanding an offer or policy, arranging an appointment, managing a subscription or following up on an application or claim.
Access to information does not automatically authorise a payment, contract change or other consequential action. The assistant’s capabilities and limits must remain clear, including when a qualified professional or the person needs to take over.
What this means for organisations
Organisations need to make their information and permitted digital services understandable and dependable for these assistants. This does not require building the user’s personal assistant or making private account data public. It requires clear information, controlled access and reliable outcomes for the tasks the service supports.
#
What are tool use and function calling?
Tool use and function calling allow an AI system to request a defined external operation instead of trying to produce every result from language alone. A tool may retrieve account data, search a catalogue, calculate a value, create a record or perform an authorised action. Application code validates the request and controls execution.
Why it matters
Tools connect conversation with current information and real business processes. They also introduce consequences. Each tool needs a clear purpose, validated inputs, minimum permissions, reliable error handling, audit records and confirmation before sensitive or irreversible actions.
Source and scope
The MCP tools specification describes how models can discover and invoke external functions while applications retain control over authorisation and user confirmation.
#
What is Model Context Protocol (MCP)?
Model Context Protocol (MCP) is an open standard that connects AI applications with external information and tools. It provides a common way for an AI assistant or agent to discover available functions, retrieve information and request permitted actions.
In a customer interaction, the user is the person asking for help. The provider is the business offering a product or service. The customer’s personal AI assistant or agent can use an authorised MCP connection to access information and functions the provider makes available. A business can also use MCP to connect its own AI assistant to internal systems.
Why it matters
As people delegate more tasks to personal AI assistants and agents, providers need to make their products and services understandable and usable by those systems. An agent may need current prices, availability, delivery options or appointment times, together with a reliable way to request a quote, book a service or place an order.
MCP is one possible interface for these interactions. Providers still need accurate data, clearly defined functions, appropriate permissions and confirmation rules. The interfaces they support should reflect their services and the AI applications their customers use.
Practical example
A customer asks their personal AI agent to find an available car service appointment next Tuesday. Through a connected MCP service, the agent could check the garage’s appointment times and service details. Making a reservation requires a booking tool, the necessary permissions and any required customer confirmation.
How Retoba applies it
Retoba helps product and service providers prepare the foundations for agentic commerce: verified knowledge, clearly structured offerings and digital services that personal AI assistants and agents can understand and use.
Through external AI readiness and Agent Experience (AX) work, Retoba assesses customer tasks, available interfaces, access requirements and reliable task completion. This identifies where MCP or other integrations could help customers move from a question to an authorised action.
Sources and scope
See the official MCP documentation. MCP connects AI applications with tools and data; A2A supports communication between independent agents. MCP is one integration option, and publishing a website alone does not establish an MCP connection.
#
What is Agent2Agent Protocol (A2A)?
Agent2Agent Protocol (A2A) is an open standard that enables independent AI agents to discover each other’s capabilities, exchange information and coordinate tasks. It allows agents built by different providers to work together without sharing their internal memory, reasoning or implementation.
In a customer interaction, a personal AI agent represents the person requesting a product or service. A provider’s AI agent represents the business within its defined responsibilities. A2A gives these agents a common way to exchange requests, clarify requirements and return progress updates or results.
Why it matters
Some customer requests require coordination between systems and organisations. A personal AI agent may need a provider’s agent to assess a requirement, propose suitable options or manage a task that takes time to complete.
Providers preparing for these interactions need clearly described capabilities, agreed information exchange and explicit responsibility for each action. A2A can support that coordination, while permissions, commercial terms and customer confirmation remain essential.
Practical example
A customer asks their personal AI agent to arrange a car service next Tuesday. Using A2A, it could send the vehicle details and requested work to the garage’s service agent. The garage’s agent assesses the request, asks for missing information and returns suitable appointments and a quote. A confirmed booking depends on the customer’s authority and the garage’s acceptance rules.
How Retoba applies it
Retoba helps providers define how their AI services should respond to requests from customers’ personal agents: which tasks they can accept, what information they require, what they may disclose and when a person must approve or take over.
This extends agentic commerce readiness from accessible information to coordinated service delivery, with clear outcomes, progress reporting and recovery when a task cannot be completed.
Sources and scope
See the official A2A documentation. A2A supports communication between independent agents. MCP connects an AI application with tools and data, including systems an agent may use to fulfil a request. The protocols can work together; neither automatically grants permission to act or guarantees a completed transaction.
#
What is retrieval augmented generation (RAG)?
Retrieval augmented generation is an architecture that retrieves relevant material at request time and supplies it to a generative model as context for the response. Retrieval may use keyword search, semantic similarity, metadata filters, graph relationships or a hybrid approach.
Why it matters
RAG lets organisations use current, private or specialised knowledge without training a new foundation model. Its quality depends on content preparation, retrieval, permissions, context selection and evaluation. Storing documents in a vector database is not enough.
#
What is a vector embedding?
A vector embedding is a numerical representation of content designed so semantically related items are located near one another in a multidimensional space. Text, images and other data can be embedded to support similarity search, clustering and recommendation.
Why it matters
Embeddings help retrieve relevant material even when wording differs, but similarity is not truth or permission. Metadata, access controls, exact matching and evaluation for the relevant domain are often needed alongside vector search.
#
What is prompt engineering?
Prompt engineering is the design and testing of instructions, context and examples that shape how a generative model performs a task. In production, prompts work with data, tools, policies, output schemas, model settings and evaluation. They are not isolated verbal tricks.
Why it matters
Clear instructions improve consistency and maintainability, but prompts cannot guarantee factual accuracy or security. Critical constraints should also be enforced through architecture, permissions, validation and human processes.
How Retoba applies it
Retoba combines prompt engineering with proprietary knowledge, character design, safeguards and continuous testing. See how these layers work together in the Kotányi AI Chef.
#
What is prompt injection?
Prompt injection is an attempt to manipulate an AI system through instructions contained in user input, retrieved content or connected data. In an indirect attack, the harmful instruction may be hidden in a web page, document, message or tool result that the system reads while completing another task.
Why it matters
A manipulated agent may reveal data, ignore policy or misuse a connected tool. Prompt wording alone cannot provide a reliable defence. Systems need separation between trusted instructions and untrusted content, minimum permissions, input and output validation, confirmation for consequential actions and monitoring for unusual behaviour.
Source and scope
OWASP guidance on prompt injection explains direct and indirect attacks and why layered controls are required.
#
What is conversational interface jailbreaking?
Conversational interface jailbreaking is a deliberate attempt to make an AI system ignore or bypass its intended rules, safety boundaries or assigned role. Attackers may use role play, misleading context, encoded instructions, repeated pressure or combinations of languages and formats. Jailbreaking is a direct form of prompt injection.
Why it matters
A successful jailbreak can cause an interface to produce inappropriate content, make unsupported claims, expose protected instructions or misuse connected tools and data. No prompt, model or filter can guarantee complete protection, so safeguards must also limit what the system can access and do.
How Retoba protects conversational interfaces
Retoba uses layered safeguards adapted to the purpose and risk of each implementation. These may include clear role and topic boundaries, controlled access to approved knowledge, checks on user input and generated output, restricted permissions for connected tools, confirmation or human handover for consequential requests, adversarial testing and monitoring after launch. The precise combination depends on the use case because no single protection is sufficient. See also AI guardrails and the OWASP guidance.
#
What are AI guardrails?
AI guardrails are technical and organisational controls that keep a system within defined boundaries. They can restrict topics, data access, tools, claims, output formats and actions; detect risky input or output; require confirmation; and route cases to people.
Why it matters
No single filter is sufficient. Effective guardrails are layered, tested against realistic failure modes, monitored after launch and paired with clear accountability for incidents and exceptions.
#
What is agent experience (AX)?
Agent experience (AX) describes how effectively and reliably an AI agent can understand and use a digital product or service on behalf of a person or organisation. It includes finding relevant information, navigating interfaces, using available tools, understanding results and recovering from errors within defined permissions.
Why it matters
A person may ask their personal AI assistant to find and book a flight, order groceries online, understand an insurance policy, review a bill or arrange an appointment. Across these tasks, the agent must understand the relevant information, the person’s preferences, applicable benefits and the limits of its authority.
Good AX means that permitted tasks can be completed accurately and efficiently, with clear results and a dependable route back to the person when needed. A successful login alone does not establish a good agent experience.
How Retoba applies it
AX complements human user experience across websites, applications, online shops and customer, patient, member, citizen and business portals. Retoba assesses agreed tasks, authorised access, accurate interpretation of account information and confirmed task outcomes, alongside completion time, repeated attempts and error recovery. Results depend on the agent, available interfaces and test conditions, not simply on whether a system is familiar or custom built.
Sources and scope
Netlify's AX measurement approach illustrates evaluation through tasks and recovery. Chrome's WebMCP guidance describes clear tool semantics, results and error handling. These are implementation examples, not a universal certification or a guarantee of compatibility.
#
What is an agent ready website?
An agent ready website is designed so authorised AI agents can understand its information, identify available actions and interact with important workflows safely. It uses accessible content, meaningful labels, stable structures, explicit states and secure action interfaces.
Why it matters
Agent readiness applies wherever people or organisations use a digital service, whether as customers, patients, members, citizens or business buyers. Within the access granted, agents need to understand relevant products, contracts, account information, entitlements and the current status of a task.
Depending on the service, this may include a bank statement, insurance cover or claim, a bill or subscription, an order or booking, an appointment or application. Clear navigation, meaningful labels and explicit results help agents distinguish information they may read from actions they may prepare, submit or change.
These principles apply across commercial, professional and public services, while permissions, risks and applicable requirements differ. Consequential actions need appropriate authentication, clear consequences, required confirmations, error recovery and protection against abuse.
This concerns both the interface and the underlying data and operations. A visual redesign alone does not establish readiness.
See agent experience and delegated access.
#
What is a personal AI twin?
A personal AI twin is a personalised AI system configured with a person’s authorised knowledge, work patterns, language, preferences and decision principles to support defined tasks on that person’s behalf. It can help prepare analyses, draft communication, organise knowledge, simulate options and use approved tools while preserving relevant professional context.
A personal AI assistant does not need to model a person’s professional knowledge or working style to help with everyday tasks.
Why it matters
A carefully governed twin can extend individual capacity and help preserve institutional memory, but it is not the person and should never imply unrestricted authority. Its scope, data sources, permissions, review requirements, provenance and removal process must remain explicit.
#
What is a computer using agent (CUA)?
A computer using agent is an AI agent that operates graphical user interfaces through actions such as clicking, typing, navigating, reading screens and submitting forms. It can work with existing software in a way that resembles human interaction, including where a dedicated application programming interface is unavailable.
Why it matters
CUA can accelerate automation across familiar tools, but visual interfaces change and actions taken on screen can have real consequences. Grant only the minimum access required, use isolated environments where appropriate, confirm consequential actions, keep detailed logs and spending limits, and provide a recoverable path when the interface or agent behaves unexpectedly.
#
What is the agent economy?
The agent economy is an emerging environment in which AI agents discover information, compare options, coordinate services and execute tasks or transactions for people and organisations. Agents may interact with websites, applications, data services, other agents and the people responsible for decisions.
Why it matters
Some services already support parts of a journey carried out by agents, while others require a person to continue directly. Organisations need to support both: clear information for discovery and comparison, and dependable access to permitted actions where available. Product information, authority, identity, permissions, commercial terms and transaction states must be clear enough for agents to interpret without removing meaningful human control.
#
What is augmented intelligence?
Augmented intelligence is an approach in which AI extends human perception, analysis, creativity and judgement rather than removing the responsible human role. The system can organise evidence, generate alternatives, test assumptions and reveal patterns; people define purpose, values and the decision that follows.
Why it matters
The strongest use of AI is not always full automation. In strategic, creative and consequential work, value often comes from a partnership in which AI increases the range and speed of thought while people challenge the output, supply context and remain accountable.
How Retoba applies it
REWORK by Retoba examines where AI should automate, where it should augment people and how roles can be redesigned without losing judgement, clarity or human responsibility.
#
What is an AI first organisational culture?
An AI first organisational culture treats responsible AI use as a standard capability in everyday work rather than an isolated technology experiment. It provides people with approved tools, practical learning, time to test, shared methods, clear guardrails and accountability for outcomes.
Why it matters
AI adoption is primarily an organisational challenge. Licences alone do not change decisions or workflows. Teams need leadership, psychological safety for controlled experimentation, evidence of value and clarity about how roles evolve. A useful pattern is to begin with one bounded problem, learn quickly and expand from proven practice.
How Retoba applies it
Retoba’s REWORK approach begins with real work, decisions and constraints, then redesigns roles, workflows and collaboration between people and AI around measurable value.
#
When does a prompt become an organisational asset?
A prompt becomes an organisational asset when it codifies reusable domain knowledge, decision criteria, desired behaviours and evaluation standards in a tested and maintainable system. Its value may include instructions, examples, tool rules, source requirements, output structures, failure handling and the documented evidence that it improves a defined task.
Why it matters
A valuable prompt system should be versioned, protected by access controls, evaluated and assigned to an owner like other operational knowledge. Calling it an asset does not mean every prompt automatically receives intellectual property protection; legal protection depends on its content, originality, confidentiality, contracts and applicable law.
#
What is conversational AI lifecycle management?
Conversational AI lifecycle management is the continuous ownership, testing, monitoring, updating and improvement of a conversational system from initial design through operation and eventual retirement. It covers knowledge, prompts, models, integrations, character behaviour, safety controls, analytics, feedback and change records.
Why it matters
A conversational AI system is a living service, not a single implementation. Products, policies, language, user behaviour and model capabilities change. Organisations need a named owner, update cadence, quality thresholds, incident process and a way to turn real conversation evidence into controlled improvements.
#
What is data sovereignty in AI?
Data sovereignty in AI is an organisation’s ability to retain meaningful control over how its data is stored, accessed, processed, shared, activated and moved across systems and providers. It combines legal jurisdiction with practical questions of ownership, portability, security, dependency and the ability to create value from information collected directly through the organisation’s own channels.
Why it matters
An organisation that cannot retrieve, govern or reuse its own data may become dependent on external platforms and pay repeatedly to access value it helped create. Sovereignty does not mean isolating all data; it means making deliberate, lawful choices about infrastructure, permissions, retention, providers and exit paths.