What is AI Governance?
AI Governance is a framework ensuring AI systems operate safely, fairly, and legally. Think of it like hospital prescription protocols — doctors don't prescribe randomly. They review records, consider side effects, follow regulations, and document decisions. AI needs the same rigor.
In AIF-C01, AI governance is a core topic in Domain 5 (Security, Compliance, Governance), accounting for about 14% of the exam.
---
The 3 Pillars of AI Governance
| Pillar | Meaning | Real-world Analogy | |--------|---------|--------------------| | Transparency | Openness about how AI works | Food nutrition labels | | Explainability | Ability to explain AI decisions | Doctor explaining a diagnosis | | Accountability | Clear ownership when things go wrong | Driver's legal responsibility in an accident |
---
Explainable AI (XAI)
Imagine applying for a bank loan and being rejected with only "AI denied your application." You'd want to know why — to appeal or improve your application next time. This is why Explainable AI matters.
Black-box vs. White-box Models
| Type | Explainability | Examples | Trade-off | |------|---------------|----------|-----------| | White-box | High | Linear regression, Decision trees | Easy to explain, limited performance | | Black-box | Low | Deep learning, LLMs | High performance, opaque logic |
For black-box models, techniques like SHAP and LIME provide post-hoc explanations — showing which features most influenced a prediction.
---
SageMaker Model Cards
Model Cards are standardized documentation for AI models — like a product manual written for people who didn't build the model.
What Model Cards Include
| Section | Content | |---------|---------| | Model Overview | Name, version, date, owner | | Intended Use | Appropriate use cases, prohibited uses | | Training Details | Datasets, methods, hyperparameters | | Evaluation Results | Accuracy, error rates across groups | | Fairness Analysis | Bias assessment, known limitations | | Ethical Considerations | Misuse risks, edge cases |
---
AWS Compliance Services
| Service | Role | Remember it as | |---------|------|---------------| | AWS Config | Tracks resource configuration changes | "What changed and when?" | | AWS CloudTrail | Logs all API calls | "Who did what and when?" | | AWS Audit Manager | Auto-generates compliance audit reports | "Automated audit prep" | | AWS Artifact | Provides AWS's own compliance certifications | "Proof AWS follows the rules" | | Amazon Macie | Auto-detects PII in S3 | "Does this bucket contain social security numbers?" |
Exam tip: Config = "what is configured," CloudTrail = "who did what." Don't confuse them.
---
Shared Responsibility Model for AI
| Responsible Party | Coverage | |------------------|----------| | AWS | Physical infrastructure, hypervisor, base service security | | Customer | Training data quality, bias detection, output review, IAM permissions |
AWS builds and manages the building. The customer decides what happens inside, locks the doors, and controls who enters.
---
Exam Quick Reference
| Concept | Exam Point | |---------|-----------| | Model Cards | Documents purpose, limitations, bias, training info — core transparency tool | | AWS Config | Tracks config changes (compliance violation detection) | | CloudTrail | API audit log (who did what) | | Audit Manager | Auto-generates compliance audit reports | | Amazon Macie | Auto-detects PII in S3 | | Shared Responsibility | AWS = infrastructure / Customer = data, model, access | | Explainable AI | White-box = inherently explainable; Black-box = use SHAP/LIME |