Instiq
Chapter 4 · Responsible AI, Security, and Governance·v2.1.0·Updated 6/14/2026·~7 min

What's changed: In-scope coverage: added security (Macie/Inspector/Secrets Manager) to Ch4 §2 and governance/compliance/cost (CloudWatch/Config/Artifact/Audit Manager/Trusted Advisor/Well-Architected Tool/Cost Explorer/Budgets) to Ch4 §3

4.3Governance and Compliance for AI

Key points

Understand governance for AI use—defining policies, monitoring and logging usage, accountability, and compliance.

To use AI safely across an organization, governance—policies, monitoring, and accountability—is essential.

4.3.1Elements of governance

Diagram of AI governance: define policies (acceptable use & ownership) → monitor & log (usage, cost, outputs) → accountability (humans own outcomes).
How AI governance works
  • Define policies: set acceptable use, ownership, and approval for AI (who may use what, and how).
  • Monitor & log: monitor usage/cost/outputs and record with AWS CloudTrail (API activity), etc.
  • Accountability: people/organizations are ultimately responsible for AI outcomes. Data governance: manage the source, quality, and rights of training/usage data.

Governance is "how an organization controls AI." If the previous section’s security is technical defense, governance is the operational framework of rules, monitoring, and accountability. First define usage policies (acceptable uses, prohibitions, approval flow); then record/monitor "who used which model, when and how" with CloudTrail, etc.; finally, people/orgs own the outcomes (accountability). It also includes data governance (managing the source, quality, and rights of training/usage data) and compliance with industry regulations. These operationalize the responsible AI of section 1 at the organizational level.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.