Category Archives: AI & Machine Learning
The NIST Artificial Intelligence Risk Management Framework (AI RMF) is a voluntary framework for incorporating trustworthiness considerations into the design, development, deployment, use, and evaluation of AI systems. AI RMF 1.0 organizes the Core into four functions—Govern, Map, Measure, and Manage—and NIST’s AI RMF Playbook provides suggested actions aligned to the framework’s categories and subcategories. […]
AI system change control is the discipline for deciding which changes require review, testing, approval, release evidence, and rollback before an AI-enabled service changes production behavior. The change may be code, but it can also be a model version, prompt, guardrail, training dataset, retrieval index, tool schema, policy threshold, vendor API, feature store, or agent […]
AI training data rights are the legal, contractual, privacy, and governance permissions that determine whether an organization may collect, copy, transform, license, disclose, retain, and use a dataset for model training, fine-tuning, evaluation, or retrieval. “We have access to the data” is not the same as “we have the right to train on it,” and […]
AI vendor contract clauses convert governance requirements into enforceable obligations around data, intellectual property, model changes, testing, security, privacy, incidents, performance, continuity, and exit. Standard SaaS boilerplate often leaves crucial AI questions unresolved: can the vendor train on your data, can the model change without notice, can you independently evaluate it, what evidence must the […]
AI vendor due diligence evaluates whether a provider’s model, data practices, security, governance, operations, finances, and contract can support the risk of the intended use. A vendor that is acceptable for internal brainstorming may be unacceptable for automated eligibility decisions or access to confidential customer records. Due diligence should therefore start from the use case […]
An algorithmic impact assessment (AIA) is a structured process for identifying who can be affected by an automated or AI-supported decision, how severe the consequences could be, what data and model risks exist, and which governance controls are required before and during production use. An AIA is broader than a model accuracy report because it […]
ISO/IEC 42001:2023 is the international management-system standard for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS). It is designed for organizations that develop, provide, or use AI systems and applies the familiar management-system logic of policies, objectives, risk management, documented processes, monitoring, review, and continual improvement. The standard is copyrighted, so […]
Vertex AI Agent Builder is Google Cloud’s suite for building, deploying, and governing AI agents. Current Google documentation uses the name for a family of agent capabilities rather than the older standalone search/chat product that originally carried the name. The suite includes Agent Development Kit (ADK), Agent Engine, Agent Garden, agent search/grounding, tools and MCP […]
Vertex AI Agent Engine is Google Cloud’s managed runtime and service layer for deploying, scaling, and operating AI agents. It began as LangChain on Vertex AI/Reasoning Engine and is now part of the broader Vertex AI Agent Builder / Gemini Enterprise Agent Platform stack. Agent Engine handles runtime infrastructure while exposing services such as Sessions, […]
Amazon Bedrock Knowledge Bases can retrieve from structured data by translating a user’s natural-language question into SQL and executing it through an Amazon Redshift query engine. Current AWS documentation supports structured knowledge bases with Redshift Serverless or Redshift Provisioned as the query engine, querying data stored in Redshift and supported data reachable through the default […]
Bedrock tool-use streaming lets an application receive model output and tool-call input incrementally instead of waiting for the entire assistant message to finish. With the ConverseStream API, Bedrock streams message/content-block events, including partial text and partial tool-use input JSON. For supported Anthropic Claude models, AWS also exposes fine-grained tool streaming that can begin returning large […]
CI/CD for generative AI applications has to release more than source code. Prompts, model versions, guardrails, tool schemas, retrieval configuration, evaluation datasets, infrastructure, and application code can all change user-visible behavior independently. A reliable pipeline therefore treats each of those artifacts as versioned production configuration and requires evidence that the combined release still meets quality, […]
Amazon Bedrock cross-Region inference lets an application invoke a system-defined inference profile from one source Region while Bedrock routes the request to one of several supported destination Regions for the selected model. The feature increases the compute pool available to on-demand inference and can improve resilience and throughput during regional demand spikes. Within Generative AI […]
Amazon Bedrock model import lets teams bring supported customized models into Bedrock and serve them through Bedrock runtime features rather than operating their own inference stack. Current AWS documentation supports custom model import jobs for compatible open-source foundation models and a separate path for customized Amazon Nova models fine-tuned in SageMaker AI. Within Generative AI […]
Bedrock prompt routers are named resources used by Amazon Bedrock intelligent prompt routing to choose among supported models. A router encapsulates candidate models, a fallback model, and routing criteria; applications invoke the router rather than implementing their own request classifier. Current AWS APIs include CreatePromptRouter, GetPromptRouter, ListPromptRouters, and DeletePromptRouter alongside AWS-provided default routers. Within Generative […]