Compliance Standards for AI Systems
Why governance matters
The story: A restaurant with health certificates on the wall earns customers' trust, can open more branches because each one follows the same standards, and avoids lawsuits and bad press. The landlord has already passed a long list of building and safety inspections, which helps.
In AI/AWS terms: Governance builds trust, lets AI scale, and protects the organization from legal and reputational risk such as bias, privacy violations, and unintended consequences. AWS supports 143 security standards and compliance certifications.
For the exam: AWS supports 143 security standards and compliance certifications.
Standards to recognize
The story: Different certificates for different kinds of kitchens: one for government canteens in the US, one issued by a European agency, an international standard for kitchen practices, an outside inspector's report, one for hospital food, one for how European diners' personal details are handled, and one from the card companies for taking card payments.
In AI/AWS terms:
| Kitchen certificate | Standard | What it covers |
|---|---|---|
| US government canteens | NIST SP 800-53 | Security controls for US federal information systems: confidentiality, integrity, availability |
| European agency | ENISA | The EU cybersecurity agency. Drafts EU cybersecurity certification schemes |
| International practices | ISO (ISO/IEC 27002) | Recommended security management practices and controls |
| Outside inspector's report | SOC reports | Independent third-party assessments of AWS controls |
| Hospital food | HIPAA | Protected health information in the US |
| European diners' details | GDPR | Privacy of EU citizens' personal data |
| Card companies' rules | PCI DSS | Payment card data, run by a council of card companies |
For the exam: Health data = HIPAA. EU personal data = GDPR. Card payments = PCI DSS. US federal systems = NIST SP 800-53. Third-party assessment = SOC.
Why AI compliance is different
The story: Inspecting a regular kitchen is straightforward: follow the recipe, check the temperature. Now imagine a kitchen where the chef invents new dishes every day, can't explain how, keeps changing after the inspection, sometimes discovers a skill nobody taught them, and might serve some customers worse than others. New laws start requiring the restaurant to explain decisions and keep a human in charge.
In AI/AWS terms:
- Complexity and opacity: hard to audit how an LLM reaches its output.
- Dynamism and adaptability: models change after deployment, so static standards fit poorly.
- Emergent capabilities: unexpected abilities that no one designed.
- Unique risks: algorithmic bias (from biased training data or human bias), privacy, misinformation, job displacement.
- Algorithm accountability: laws requiring transparency, risk assessment, and human oversight, such as the EU AI Act and New York City's Automated Decision Systems law.
For the exam: AI compliance is harder because models are opaque, change over time, and can show emergent capabilities.
Regulated workloads
The story: Some kitchens are under stricter rules than others: a hospital kitchen, an airline kitchen, a kitchen whose menu decisions affect people's health. Before building one, you ask: will inspectors check this? Do we have to keep our records for years? Does each meal ticket count as an official record? Are we storing customers' home addresses?
In AI/AWS terms: A workload is regulated when it must meet a framework like HIPAA, GDPR, or PCI DSS, or has regulated processes, outcomes (mortgage and credit decisions), usage (safety-critical systems), or liabilities. Common industries: financial services, healthcare, aerospace. Examples: HR, safety, and inspection workloads.
Questions to ask:
- Do you need to audit this workload?
- Do you need to archive the data for a period of time?
- Will the model's predictions count as a record?
- Does the source data include classifications restricted by internal governance, such as customer addresses?
For the exam: For a regulated workload, ask about auditing, archiving, predictions as records, and restricted data.