All glossary terms
G Foundations Governance

Generative AI

Traditional predictive models could be approved before deployment, because every possible output could be identified and reviewed in advance. Generative models cannot be approved this way. Their range of possible outputs has no fixed limit. This single difference has reshaped how organizations oversee AI. Governance has moved from a one-time approval before launch to continuous oversight while the system operates.

Definition

Generative AI is the class of systems that produce new artifacts, whether text, code, images or structured output, rather than retrieving something that already exists or scoring something that does. That single property is both why it is useful and why it is difficult to govern: there is no source to check the output against unless you supply one.

What is generative AI?

Systems that produce artifacts rather than find or rate them. A search engine returns documents that exist. A classifier assigns a label from a fixed set. A generative model composes something that did not exist a moment earlier, which is a different kind of operation with different consequences.

The mechanism is prediction applied recursively: given everything so far, produce the next most probable element, then repeat. That is true of text, code and images alike, and it explains both the fluency and the failure modes.

What is worth holding onto is the operational distinction rather than the architecture. Retrieval and classification produce outputs you can trace to a source. Generation does not, by default. Whether an output is any good has to be established some other way, and the rest of this page is about what follows from that.

Your architecture treats this term as a hub anchor, and that is a reasonable call. Generative AI is the substrate rather than the subject: every page in this glossary assumes it. The three-wave lineage from predictive to generative to agentic is told in full at agentic AI, framed around the receding human reviewer. This page covers the one foundational consequence that page does not: why you stopped being able to sign the model off in advance.

Why could predictive AI be certified and generative AI cannot?

Because a predictive model's output space is finite and a generative model's is not. If a system can only return fraud or not fraud, you can measure its behaviour across every possible answer on a test set and sign it off. If it can return any sentence, no test set covers the space.

This is the shift that made every pre-deployment assurance practice insufficient, and it is rarely stated as plainly as it deserves.

Two output spaces compared. On the left, a predictive model with a small closed set of possible outputs, fully covered by a test set, so accuracy, false positive rate and disparate impact are all computable before deployment and the model can be signed off. On the right, a generative model whose output space is drawn as unbounded, with a small sampled region marked as everything a test set can reach, and the remainder marked as untested by construction. A caption states that assurance therefore had to move from certification to runtime.
Predictive and generative systems compared by output space and what assurance is possible
Question Predictive Generative
Output space Closed and enumerable. A label, a score, a class Unbounded. Any sequence the model can compose
What a test set proves Behaviour across the whole space, within sampling error Behaviour on the cases you thought of, and nothing about the rest
When assurance happens Before deployment. Certify once, monitor for drift At runtime, per output, continuously. There is no once
What failure looks like A measurable error rate you can hold to a threshold A fluent, plausible, specific output that happens to be wrong

The practical consequence is that model validation stopped being the control and became one input to it. An organization that has evaluated a model thoroughly and built nothing at runtime has assured the component and not the system. Which is why the rest of this glossary is largely about runtime apparatus: guardrails, tracing, evaluation on live traffic, and an audit record.

Is generative AI an alternative to agentic AI?

No, and the comparison is usually malformed. Every agent runs on a generative model, so asking which to choose is like asking whether to use an engine or a car. Generative AI is the capability; agentic AI is one thing you can build with it.

The confusion matters commercially because it turns up in procurement, where a team ends up comparing a model provider against an agent platform as though they were substitutes.

  • Generative AI is the substrate. The model that composes the output. You buy or host it, and its capability sets an upper bound on what anything above it can do.
  • Agentic AI is an architecture on top of it. A generative model given tools, a loop, and the discretion to choose its own steps. See AI agent for what distinguishes that from automation with a model inside it.
  • They fail differently and the second inherits the first. A generative failure is a wrong output. An agentic failure is a wrong action taken on a wrong output. Every problem in the model is still present, with consequences attached.
  • The buying decision is not either-or. The model question is capability and cost per token. The platform question is whether you can see, bound and account for what gets built on it. Different vendors, different criteria, both needed.

What does having no source make harder?

Four things, and they are the four this glossary spends most of its pages on. When a system produces something that did not previously exist, there is nothing to check it against, nothing to attribute it to, no ground truth to score it on, and nothing to reconstruct it from later.

Tracing all four back to a single property is the useful thing this page can do, because it explains why they are hard rather than treating each as a separate surprise.

On the left, a retrieval system returning a document that exists, with four checks all satisfied: verify against the source, attribute to the source, score against ground truth, and reconstruct from the record. On the right, a generative system producing new output, with the same four checks marked as having nothing to check against, no source to attribute to, no ground truth available, and only the output recorded rather than its basis. Each of the four is labelled with the glossary term that addresses it.
Four consequences of generative output having no inherent source, and where each is addressed
What becomes hard Why, and where it is addressed
Verifying correctness The output is fluent whether or not it is true, and nothing distinguishes the two from the text itself. See AI hallucination
Attributing provenance There is no document the output came from. Grounding supplies one deliberately, which is why retrieval became standard practice. See agentic RAG
Scoring quality No single correct answer exists, so evaluation compares against criteria rather than a key, often using another model as judge. See agent evaluation
Explaining afterwards The model's stated reasoning is another generated output rather than a disclosure of cause. See agent explainability

Read that table as a design brief rather than a list of problems. Each row describes something you have to supply, because the model does not bring it. Grounding supplies a source. Evaluation supplies criteria. Tracing supplies a record. None of it comes with the model, and the organizations that struggle are the ones that assumed it did.

Why is the cost model different?

Because you pay per use rather than per deployment. Conventional software runs on a licence model. The cost stays fixed while the benefit grows as more people use it, so wider adoption improves the value for money. A generative system works differently. It charges for every request made, so cost rises alongside usage instead of staying flat. This reverses the usual relationship between scale and value, and it often catches finance teams off guard.

This is a foundational property rather than a pricing quirk, and it is the origin of the economics described at agentic AI ROI.

  • Cost tracks usage, not headcount. A successful rollout raises the bill in direct proportion, so the business case has to be built on cost per completed unit of work rather than on a licence line.
  • Output length is a cost lever. Verbosity is billable. A model asked to explain its reasoning at length costs more than one asked for an answer, which is a genuine trade against the explainability you might want.
  • The price gap between models is large. Wide enough that matching each task to the cheapest model meeting its quality bar is a material control rather than an optimisation. See model routing.
  • Falling unit prices do not settle it. Per-token prices have come down while consumption per task has risen, so usage growth can outrun price declines. Planning on future price cuts is planning on the wrong variable.

Where does generative AI sit now?

Underneath everything, which is why it has stopped being the interesting question. Frontier capability is broadly available to anyone with an account, so it no longer differentiates between organizations. What differentiates is what you build on it and whether you can govern it.

Two consequences worth acting on.

Capability is not the constraint anymore, and waiting for a better model is not a strategy. Capability and reliability have also started moving in different directions. Some newer models perform better on general capability tests while performing worse on factual accuracy about specific people, places or facts. If a deployment is struggling because of poor integration, messy data, unclear accountability or weak unit economics, a stronger model will not fix any of that.

The defining problem of the earlier generative AI era was factual reliability. The defining problem of the current era is accountability. When a person reviewed every output before it was used, an incorrect draft could be caught during that review. Once systems start acting on their own output without a person checking each step, the key question changes. The concern diverts towards what action was taken, who authorized it, and whether it can be stopped if something goes wrong. This shift is the central subject of this glossary, and it is explained in more detail under enterprise AI.

Which is the honest summary for a foundational term: generative AI is what makes all of this possible, and almost none of the difficulty now lives at this layer.

Frequently asked questions about generative AI

If your question is not here, our team will answer it directly.


Talk to a Specialist →
What is generative AI?

Systems that produce artifacts rather than find or rate them. A search engine returns documents that exist; a classifier picks a label from a fixed set; a generative model composes something that did not exist a moment earlier. The mechanism is prediction applied recursively, producing the next most probable element and repeating, which explains both the fluency and the characteristic failures. The operational point is that generation leaves no source trail by default.

How is generative AI different from predictive AI?

By the size of the output space, and everything follows from that. A predictive model returns a label or a score from a closed set, so a test set can establish its behaviour across the whole space and it can be signed off before deployment. A generative model can return any sequence it can compose, so no test set covers the space. Assurance therefore had to move from certification to runtime.

Why can generative AI not be certified before deployment?

Because the space of possible outputs has no edges. Evaluating a generative model tells you how it behaved on the cases you thought of and nothing about the rest, which is a genuinely different epistemic position from measuring a classifier's error rate. Model validation therefore stopped being the control and became one input to it: an organization that has evaluated a model thoroughly and built nothing at runtime has assured the component rather than the system.

Is generative AI the same as agentic AI?

No. Putting them side by side as options is a mistake about what kind of thing each one is. Agents are constructed out of generative models, so the choice does not exist: what you are picking between is a component and something assembled from it. Add tools, a loop and the freedom to sequence its own work, and a model becomes an agent. Where this bites is procurement, when a shortlist ends up holding a model vendor and a platform vendor in the same column.

What is the difference between generative AI and an LLM?

Generative AI is the category; a large language model is one kind of system within it. The category also covers image, audio, video and code generation, some of which use different architectures. In enterprise conversation the two words get used interchangeably because language models are what most organizations are actually deploying, which is harmless in practice as long as nobody concludes that generative AI means only text.

Why does generative AI hallucinate?

Because it composes the most probable continuation rather than retrieving a fact, and probability is not truth. When the training data supported a correct answer the probable continuation is true; when it did not, the probable continuation is still an answer-shaped output rather than an admission of ignorance. Same mechanism, different luck. It is a property of generating plausible text without a model of truth rather than a defect to be patched.

What makes generative output hard to govern?

The absence of a source. When a system produces something that did not previously exist, there is nothing to verify the output against, nothing to attribute it to, no ground truth to score it on, and nothing to reconstruct its basis from afterwards. All four are things you have to supply deliberately: grounding supplies a source, evaluation supplies criteria, tracing supplies a record. None of it arrives with the model.

Why is generative AI priced differently from software?

Because you pay per use rather than per deployment. Conventional software has a fixed licence cost and a benefit that grows with adoption, so scale improves the ratio. A generative system charges for every request, which inverts that: a successful rollout raises the bill in proportion. Output length is billable too, so a model asked to explain itself at length costs more than one asked for an answer.

Will falling model prices solve the cost problem?

Not on their own, and planning on it is planning on the wrong variable. Per-token prices have fallen while consumption per task has risen, so usage growth can outrun price declines. The controllable lever is matching each task to the cheapest model that meets its quality bar, since the price gap between models is wide enough to make that a material control rather than a refinement.

Do you need a better model to make generative AI work?

Rarely. Frontier capability is broadly available, so it no longer differentiates between organizations, and capability and calibration have moved on separate tracks: some newer models score better on capability while scoring worse on factual reliability about specific entities. If a deployment is failing on integration, ambiguous data, accountability or unit economics, a stronger model changes none of those four.

What replaced factual reliability as the main concern?

Accountability. When a person reviewed every output, an incorrect draft was caught at review, so the defining problem of the generative era was whether you could trust the text. Once systems act on their own output the question changes to what happened, on whose authority, and whether you can stop it. That is why the current generation of tooling is about tracing, permissions and audit rather than about output quality alone.

Is generative AI still the interesting question?

Not really, and that is a sign of maturity rather than decline. It sits underneath everything, which is precisely why the difficulty has moved up the stack. What differentiates organizations now is what they build on it and whether they can see, bound and account for it. Generative AI is what makes all of this possible, and almost none of the hard problems now live at this layer.

Assurance moved to runtime
You cannot sign off a model whose output space has no edges

SERAA Cortex supplies what the model does not: runtime guardrails on each action, a recorded trace of every model and tool call with cost and actor attribution, promotion gates before production, and per-agent permission scoping, inside your own perimeter.