tag: Ai-Security · 2 items
- Platform/SRE — Learn: Useful framing for understanding how unsanctioned AI tools introduce new attack surfaces into the platform layer, but no specific infrastructure action or deadline is present.
- CI/CD — Learn: Directly relevant to pipeline security thinking — AI extensions and agents in the build path are an emerging supply-chain risk worth evaluating, but no concrete deprecation, compromise, or deadline anchors an Act or Plan verdict.
- Leader — Plan: Shadow AI in delivery pipelines is a policy and governance gap that warrants adding AI tool usage to supply-chain standards and acceptable-use policy; schedule a review of which AI integrations teams are using in pipelines before the next security audit cycle.
- Platform/SRE — Plan: New GA capability that auto-discovers AI workloads (Bedrock, SageMaker, EC2, ECR) via Config, Inspector SBOM, and GuardDuty DNS telemetry — worth enabling this quarter for teams running AI workloads to close the visibility gap before it becomes a compliance issue.
- CI/CD — Skip
- Leader — Learn: Signals that AWS is building central AI governance tooling; relevant for leaders setting security standards around AI deployments, but no forced decision or pricing change — shapes thinking on AI risk posture policy rather than requiring action now.