← AWS Certified AI Practitioner: decisions and applications
05 / 5 · 40 MIN

AI security and governance

Control identity, data, tools, and evidence throughout the usage lifecycle.

Concept and mechanism

A managed application retains customer responsibilities for content, configuration, and access. Distinguish authentication, which establishes identity, from authorization to perform actions on resources. IAM roles and policies should restrict access to application needs; a prompt instruction does not replace that boundary. Encryption in transit and at rest, private connectivity, and key management address different concerns. Macie helps discover sensitive data in S3; it does not automatically secure every model request. Plan classification, provenance, retention, deletion, and access for prompts, responses, and memory. Avoid confidential data in tags or name fields that may appear in operational records. Checking region, processing, and applicable policies is part of assessment without assuming a universal rule for every bank.

Guided application

In a fictional scenario, a retrieved document instructs the application to send a file to an external destination. Treat that content as untrusted data. Alongside filtering, restrict tools, destinations, and actions and require approval where impact justifies it. Validate arguments and outputs outside the model. Record relevant identity, version, decision, and tool-call evidence while protecting log contents. CloudTrail helps audit API activity; do not assume it contains every conversation or the application’s reasoning. Workflow observability provides complementary evidence. Define who handles failures, how to suspend a tool, and how to recover partial work. AWS Artifact provides supplier reports; the team still needs to demonstrate its own configuration and process. Governance follows model, data, prompt, and permission changes with review proportionate to risk.

IN PRACTICE

An instruction inside a document must not expand agent permissions.

Common pitfalls

Prompts treated as access controls; logs containing secrets; supplier reports treated as application proof; memory without defined retention.

Related topics: AI and ML: problem, data, and metrics · Generative AI, context, and agents · Foundation models: RAG, prompts, and evaluation

Take this idea with you

Enforce boundaries outside the model and retain sufficient evidence with controlled access.

Create account

Reference: AIF-C01 domain5: Security, Compliance, and Governance for AI Solutions · AIF-C01