Skip to content
Handbook navigation

Section 2

Privacy, Security, and Compliance

AI systems create derived stores and model-mediated authority that ordinary service diagrams often omit. Prompt context may be copied into provider logs or evaluation fixtures. Retrieved text may influence a tool running with application credentials. An annual checklist may describe controls that no longer match the deployed model, provider, jurisdiction, or workflow. This section makes those paths explicit. It treats retrieval indexes, embeddings, caches, traces, review queues, fine-tuning datasets, and backups as governed data stores. It treats model output as untrusted input to deterministic identity, authorization, policy, schema, egress, spend, and side-effect boundaries.

Chapters

3

Lesson Reading

1 hr

Labs

3

Interview Sets

3

Begin SectionAcademy Pass

Chapter Path