Which Generative AI Solution Scope Gives the Most Security Ownership?

A company is using the Generative AI Security Scoping Matrix to assess security responsibilities for its solutions. The company has identified four different solution scopes based on the matrix. Which solution scope gives the company the MOST ownership of security responsibilities?

  1. Using a third-party enterprise application that has embedded generative AI features.
  2. Building an application by using an existing third-party generative AI foundation model (FM).
  3. Refining an existing third-party generative AI foundation model (FM) by fine-tuning the model by using data specific to the business.
  4. Building and training a generative AI model from scratch by using specific data that a customer owns. Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the core principle of the shared responsibility model applied to generative AI: the more layers you build and control yourself, the more security responsibility you assume.

The Generative AI Security Scoping Matrix defines how security responsibility shifts between the customer and the provider depending on the level of control and customization. Building and training a foundation model from scratch with customer-owned data gives the customer the MOST ownership of security responsibilities.

Candidates sometimes choose option B (building an app on a third-party FM) or C (fine-tuning), confusing application-level control with full model ownership, forgetting that fine-tuning still relies on a provider-managed base model and infrastructure.

Community Discussion (6 comments)

Rcosmos 👍 1 Selected: D
Explicação: De acordo com a Generative AI Security Scoping Matrix, quanto maior o controle e customização de uma solução, maior é a responsabilidade da empresa pela segurança. Opção D representa o maior nível de propriedade: ao construir e treinar um modelo do zero, a empresa assume controle total sobre o modelo, os dados, o treinamento, a implantação e a segurança em cada etapa. As demais opções têm menos responsabilidade direta porque envolvem componentes terceirizados:
Jessiii 👍 1 Selected: D
Building and training a generative AI model from scratch by using specific data that a customer owns: When a company builds and trains a model from scratch using its own or customer-specific data, the company has full control over the entire development process, including data collection, model training, infrastructure management, and deployment. As a result, the company assumes the most responsibility for security in all areas, from data protection to model security and the underlying infrastructure.
Moon 👍 1 Selected: D
D: Building and training a generative AI model from scratch by using specific data that a customer owns. Explanation: When a company builds and trains a generative AI model from scratch, it assumes the most ownership of security responsibilities, including: Data security and compliance during training. Model development and training processes. Infrastructure and deployment security. Protecting the model from adversarial attacks. Ensuring ethical use of the model and safeguarding against bias and misuse. This approach provides complete control over the entire lifecycle of the AI solution but also places the greatest burden of responsibility on the company.
kyo 👍 1 Selected: D
https://aws.amazon.com/ai/generative-ai/security/scoping-matrix/
eesa 👍 1 Selected: D
D. Building and training a generative AI model from scratch by using specific data that a customer owns. In this scenario, the company has the most control over the entire development and deployment process. This includes: Data security: The company is responsible for securing the training data, which might contain sensitive information. Model security: The company needs to implement measures to protect the model itself, including securing the training process, model parameters, and deployment infrastructure. Operational security: The company is responsible for securing the deployment environment and monitoring the model for potential vulnerabilities. While the other options involve some level of security responsibility, they rely on third-party providers to a greater extent. This reduces the company's direct control over the security aspects of the solution.
jove 👍 3 Selected: D
D. Building and training a generative AI model from scratch by using specific data that a customer owns gives the company the most ownership of security responsibilities, as they are responsible for all aspects of the model's development and deployment.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Generative AI Security Scoping Matrix

AWS defines a Generative AI Security Scoping Matrix that maps four typical solution scopes to the division of security responsibilities between the customer and the AWS/managed-service provider. The matrix follows the same logic as the classic shared responsibility model: the more you build and control, the more you are responsible for securing.

Evaluating Each Option

  • Option A – Third-party enterprise app with embedded GenAI: The vendor owns the application, the model, the infrastructure, and the data pipeline. The customer only manages identity, access, and the data they feed into the app. Least customer ownership.
  • Option B – Building an app on a third-party foundation model (FM): The customer writes application logic and prompts, but the FM, its training, hosting, and underlying infrastructure remain the provider's responsibility. Security ownership is higher than A but still limited.
  • Option C – Fine-tuning a third-party FM: The customer introduces proprietary data and adjusts model weights, so they own data security and prompt/fine-tune pipeline security. However, the base model architecture, pre-training, and much of the infrastructure are still provider-managed.
  • Option D – Building and training a GenAI model from scratch with customer-owned data: The customer controls every layer — data collection and labeling, model architecture, training infrastructure, hyperparameters, evaluation, deployment, and ongoing operations. Consequently, the customer assumes the MOST ownership of security responsibilities, including data security, model security, infrastructure security, and compliance.

Community Consensus

The community voted 100% for D, and comments consistently highlight that full control over data, training, infrastructure, and deployment translates directly into full security ownership. AWS's own scoping matrix page confirms this interpretation.

Official Reference

Exam Strategy

When a question references a 'scoping matrix' or 'shared responsibility model,' rank options by the number of layers the customer controls. The option where the customer builds the most from scratch almost always carries the greatest security responsibility.

Related Analysis

Practice All AIF-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AIF-C01 Practice Test →

← Back to AIF-C01 Study Guide