View a markdown version of this page

Scoping generative AI use cases - Navigating the security landscape of generative AI

Scoping generative AI use cases

The first step in developing a robust security strategy for generative AI is to properly scope its use within your organization. See the AWS Generative AI Security Scoping Matrix (shown in the following figure) to categorize your use cases.

Generative AI Security Scoping Matrix, a mental model to classify use cases.

Figure 1: Generative AI Security Scoping Matrix, a mental model to classify use cases.

The scoping matrix includes five scopes. For Scope 1 or Scope 2 applications, which typically involve off-the-shelf AI solutions, adopt a buyer's perspective. Focus on risk management through data governance and carefully review enterprise agreements. It's crucial to clearly understand which data is authorized for sharing and under what circumstances. While Scope 2 applications would typically be built to support enterprise data security and compliance needs, Scope 1 applications most often are not.

For Scope 3, 4, or 5 applications, which involve more customized or internally developed AI solutions, adopt a builder's perspective. Determine what data is in scope for the application and conduct thorough threat modeling (detailed in Threat modeling for generative AI applications). In these three scopes, while you generally have more control over your data, you also have more responsibility in protecting it. Be aware that the complexities for managing both the model and data components progressively increase as you move from Scope 3 through Scope 5, requiring increasingly rigorous security considerations at each level.

For all scopes, the way you approach governance and compliance, legal and privacy, risk management, controls, and resilience requirements will vary. However, by understanding the scopes that align to your use cases, you can quickly narrow down how you will address the requirements that align to these different security dimensions.