06 — moorai terms

Semantic escalation

A second, optional pass: when the fast deterministic detectors return nothing and the sample is still ambiguous, the text is handed to a local model for a semantic judgement. It is opt-in, environment-dependent (it needs a local model runtime present) and zero-egress, and it fails open — which is exactly why it is kept out of headline numbers and reported separately from the deterministic result.

Related terms

  • Detection vs prevention Testing & measurement

    Detection notices something and produces a record; prevention stops it from happening. They are routinely conflated in agent-security claims, and the gap…

  • Variance Testing & measurement

    How much a result moves when the same test is run again. Any figure involving a model is a sample from a distribution, not a constant — the same judge…

MoorAI terms

Product-specific vocabulary used across this site. The agent is open source (AGPL-3.0), so each of these is verifiable in the code rather than taken on trust.

Semantic escalation is term 4 of 5 in this part of the glossary.

Get started free Full glossary → How we test → Community agent on GitHub ↗

This page is one entry from the agentic AI security glossary, which defines 60 terms in the same style. Where a term belongs to a published taxonomy or standard — the HackAgent attack families, the OWASP lists, AMTSO's guidelines, MITRE ATLAS, ISO/IEC 42001, the NIST AI RMF, the EU AI Act — the authoritative wording is the source document's, not ours, and specifics should be verified there. "Lethal trifecta" is Simon Willison's term. OWASP® is a trademark of the OWASP Foundation; ATT&CK® and ATLAS™ are trademarks of The MITRE Corporation. Naming a framework here is description, not a claim of certification or endorsement.

glick.run — AGPL-3.0