Module 6
AI-Native Software Security
An AI application is not just a prompt. It is a software system with users, APIs, data, permissions, logs, cost, and failure modes.
New risks in AI-native systems
Prompt injection
Data leakage
Untrusted document retrieval
Hallucinated responses
Over-permissioned agents
Excessive token cost
No traceability of model outputs
Sensitive data in prompts
Trustworthy AI app checklist
| Area | Question |
|---|---|
| Data | What data is sent to the model? |
| Access | What can the AI agent access? |
| Retrieval | Are sources trusted? |
| Logging | Are prompts and outputs traceable where appropriate? |
| Privacy | Is sensitive data protected? |
| Guardrails | Are unsafe actions restricted? |
| Human review | Are critical decisions reviewed? |
| Cost | Are token usage and model calls monitored? |
AWS building blocks
Amazon Bedrock
Bedrock Guardrails
IAM controls
CloudWatch logs
S3 data permissions
Knowledge Bases for grounded responses
For students
The next generation of engineers will not only build cloud apps. They will build AI-native systems that need stronger trust, safety, and governance.