InfoQ has published a practical guide for governing AI systems in cloud environments. The article lays out controls for discovering shadow AI, classifying data at creation, enforcing access through IAM, and embedding policy-as-code into delivery pipelines.

The focus is on making governance operational rather than manual. That is increasingly important as teams deploy copilots, agents, and model workflows across existing cloud infrastructure.

For architects, the useful takeaway is that AI governance is becoming a delivery-system problem: controls need to live in pipelines, identity systems, and runtime operations, not only in review documents.