1 of 17

Cloud Infrastructure as a Regulatory Layer for AI?

Presentation to ITREV Forum

04 April, 2025

Ilan Strauss with Tim O’Reilly

����

2 of 17

AI Disclosures Project

Risks / Vulnerabilities in an AI product

  • Are the risks just at the model level (the 15%)?
  • What about the system ( ~ 85%)?

Observability (Health): Is with the deployed application not the model

  • Observability is with the infrastructure
  • Observability & moderation is mostly algorithmic (LLM!)

3 of 17

Our deepening cloud dependence…

…Now: AI’s “elastic” brain

If you believe companies will build applications from scratch on top of the infrastructure services if the right selection [of services] existed, and we believed they would if the right selection existed, then the operating system becomes the internet” – Andy Jassy

4 of 17

Who holds the power in AI markets?

Power: External observability (data) + rules (standard setting)

Gatekeeper Power: Infrastructure & platform

  • Who caught DeepSeek’s exfiltration of OpenAI’s model?
  • Who decides age limits for Character.ai?
  • Who enforces AI-content labeling?
  • Who sets today’s global web security protocols?

5 of 17

Mastercard & Visa: de facto regulators

Who knows the answer to this question:

What are the conditions of acceptable vampire sex [for online pornographic videos]?

Financial Times (2022)

6 of 17

Hypothesis

To interrogate, debate, and ultimately reject if need be:��

The “Cloud”, as an essential internet infrastructure, can provide a foundational regulatory layer for the AI stack, enforcing agreed upon standards and operational controls.

7 of 17

Can standards exist on the cloud? (Tentative)

Monitoring & Standards already exist

  • Laws (CSAM)
  • ToS / AuP (Responsible AI Policy)

Enforce and extend

  • Enforce ToS through enhanced automated moderation
  • Know your customer (KYC)
  • Minimum guardrails on models deployed via AWS Bedrock
  • Applying automated scoring to new customer code

8 of 17

We would love to hear from you – feedback

If you work with cloud & LLM system integration, LLM applications and orchestration, IT controls, and more, we would love to hear from you.

Pulling on a string

9 of 17

End

10 of 17

LEFTOVERS

11 of 17

Gatekeepers and AI controls

  • Policy, practice, and standards often rely on key gatekeepers (deployment and dissemination).

  • Amidst competing standards and policies, the binding rules are those who own the operating system you run on.

  • Control is greater at the cloud level: greater usage, more controls, higher standards generally.

12 of 17

Shared Responsibility for Controls

“Shared responsibility” for security & compliance:

  • “of” (Amazon) vs “in” (customer)

13 of 17

How to regulate software run on internet networks?

To interrogate, debate, and ultimately invalidate if need be��

When infrastructure is code (DevOps)

Which code layers must become the law? (Lessig)

14 of 17

Regulating essential AI infrastructure?

Some facts

  • 22% of recently announced cloud implementations had an AI element (ML & LLM)
  • Amazon, Google, and Microsoft’s clouds > 60% combined market share
  • “Elastic brain” is key to AI

Structural power” (Berjon)

  • Control data and set standards
  • Private algorithmic management

��

15 of 17

But risks in “weaponizing” infrastructure

Example: Visa & Mastercard with Russian sanctions

  • Push people towards alternatives

Privacy is core to cloud adoption: can we monitor usage?

  • Privacy preserving: Algorithmic management (filters)

What standards? Which standards? Whose standards?

16 of 17

System / “stack”

17 of 17

This violates Robots.txt (protocol)���Who enforces the internet’s ‘rules’?