Scoping generative AI use cases
The first step in developing a robust security
strategy for generative AI is to properly scope its use within your
organization. See the
AWS Generative AI Security Scoping Matrix
Figure 1: Generative AI Security Scoping Matrix, a mental model to classify use cases.
The scoping matrix includes five scopes. For Scope 1 or Scope 2 applications, which typically involve off-the-shelf AI solutions, adopt a buyer's perspective. Focus on risk management through data governance and carefully review enterprise agreements. It's crucial to clearly understand which data is authorized for sharing and under what circumstances. While Scope 2 applications would typically be built to support enterprise data security and compliance needs, Scope 1 applications most often are not.
For Scope 3, 4, or 5 applications, which involve more customized or
internally developed AI solutions, adopt a builder's perspective.
Determine what data is in scope for the application and conduct
thorough threat modeling (detailed in
Threat
modeling for generative AI applications
For all scopes, the way you approach governance and compliance, legal and privacy, risk management, controls, and resilience requirements will vary. However, by understanding the scopes that align to your use cases, you can quickly narrow down how you will address the requirements that align to these different security dimensions.