Security, privacy, and AI governance

Production controls

Production needs clear safety and recovery rules

Security, scaling, reliability, observability, and human review are one connected control system.

Security, privacy, and AI governance

  • Identity and access: workload and user identity, least privilege, role separation, time-bound access, and tool-level authorization.
  • PHI protection: data minimization, encryption in transit and at rest, approved model endpoints, private network paths, secure logging, and retention controls.
  • Prompt and tool security: input validation, instruction hierarchy, prompt-injection defenses, tool allowlists, parameter validation, and output schemas.
  • Grounding: approved sources, version and effective date, citation, retrieval-quality evaluation, and blocking or review thresholds.
  • Model governance: approved models, documented intended use, evaluation evidence, change control, fallback, monitoring, and retirement.

Slide 35 of 48: Security, privacy, and AI governance