Category Archives: AI & Machine Learning
AI model inventory reconciliation is the process of comparing the organization’s official AI inventory with what actually exists in engineering, cloud platforms, vendor products, procurement records, code repositories, and production traffic. NIST AI RMF Govern 1.6 calls for mechanisms to inventory AI systems because governance cannot manage systems it does not know about. Within AI […]
AI policy exceptions are temporary, documented approvals to operate outside a defined governance requirement under controlled conditions. They are necessary because delivery realities do not always align perfectly with policy timing, but unmanaged exceptions can quickly become permanent bypasses that undermine the whole control framework. Within AI Governance, the exception process should make deviation visible, […]
AI red teaming is an adversarial evaluation practice designed to uncover harmful behaviors, security weaknesses, misuse pathways, failure modes, and gaps that ordinary testing may miss. Governance determines which systems are red-teamed, who performs the testing, how realistic attacks can be, what data or users may be involved, how findings are handled, and which results […]
AI risk acceptance is the deliberate decision by an authorized owner to proceed with a defined residual risk after controls, evidence, and alternatives have been considered. It is not the absence of remediation, a missed deadline, or a statement that “all AI has risk.” NIST AI RMF treats risk tolerance as contextual and does not […]
An AI risk taxonomy is a common classification system for describing the sources, scenarios, impacts, affected parties, and control domains associated with AI risk. Its purpose is to let product, engineering, security, privacy, legal, audit, and leadership teams discuss the same risk portfolio without using the same word to mean different things. Within AI Governance, […]
AI governance is the operating system around how an organization decides where AI can be used, who is accountable for it, what evidence must exist before deployment, how risk is measured, how exceptions are approved, and when a system should be changed or retired. It is broader than a policy document and narrower than “ethics” […]
Custom extraction is useful when an application needs documents to become structured business data rather than only searchable text. Azure AI Document Intelligence can train custom models from labeled examples and return fields as typed values that downstream systems can validate and process. The engineering challenge is not simply getting a model to recognize a […]
The Layout model in Azure AI Document Intelligence is designed for a different problem from fixed field extraction. It identifies the structure of a document: pages, words, lines, paragraphs, tables, selection marks, figures, sections, and other layout elements. That structure is valuable when the next system needs to preserve reading order and document semantics for […]
Amazon Bedrock AgentCore Gateway is a managed entry point for tools, services, and other capabilities that agents need to invoke. It standardizes discovery and invocation through Model Context Protocol, handles inbound and outbound authentication, can synchronize tool schemas from targets, and integrates with AgentCore Policy and Observability. The gateway is most useful when an organization […]
Amazon Bedrock AgentCore Identity gives AI agents a durable identity and a managed way to obtain credentials for AWS resources and external services. It is designed for workloads that may need to act as themselves, act on behalf of a user, or obtain machine-to-machine credentials for a tool without embedding secrets directly in agent code. […]
Amazon Bedrock AgentCore Memory separates conversational history from durable, extracted knowledge about users and interactions. Short-term memory stores raw events organized by actor and session. Long-term memory is optional and requires a memory strategy that processes those events into structured memory records stored under namespaces. That distinction gives agent teams more control than simply replaying […]
Amazon Bedrock AgentCore Observability gives teams a CloudWatch-backed view of agent behavior across sessions, traces, spans, service metrics, logs, and custom telemetry. It is designed for the problem that makes production agents difficult to operate: one user request can involve model calls, memory reads, gateway operations, policy evaluation, tools, external APIs, and multiple reasoning steps […]
Amazon Q Developer introduced agentic coding workflows that could inspect project context, edit files, run commands, use tools, and carry multi-step development tasks through a conversational interface. By 2026, the product is in transition: AWS has announced that Amazon Q Developer IDE plugins will reach end of support on April 30, 2027, and the former […]
Amazon Aurora PostgreSQL with pgvector gives teams a vector-search path inside a relational database they may already operate. In 2026, AWS guidance for production pgvector workloads emphasizes HNSW for most online retrieval, IVFFlat for selected memory-sensitive or build-cost scenarios, and no approximate index at all for small datasets or cases where exact recall is more […]
Amazon Bedrock Agents turn model reasoning into action through action groups. An action group describes functions or an OpenAPI-defined API surface that the agent may choose during orchestration. Bedrock can pass the requested action to a Lambda function for fulfillment, or it can return control to the application so the application decides how to execute […]