Back to board
100Cloud Risk And ResponsibilitySign in neededSignals connecting

Getting Started With Cloud / Cloud Risk And Responsibility

Shared Responsibility In Cloud And AI

Understand what the provider handles, what the company still owns, and why AI makes the boundary even more important.

9 min read 100 Foundation 1/1 in module
allbusiness-analystarchitectengineering-lead
Why readThe Core Idea

Understand what the provider handles, what the company still owns, and why AI makes the boundary even more important.

How to use itApply one decision rule

Use the brief to sharpen a real cloud upskill conversation: what is the decision, what evidence matters, and what should remain human-led?

What to retainHow To Talk About This With IT

Capture one design rule you would reuse when reviewing an AI workload, assistant, or operating model.

01

Executive note

The Core Idea

Shared responsibility means the cloud provider and the customer each own part of the security, reliability, and governance picture. The provider operates the cloud platform. The customer still owns how services are configured, who can access them, what data is stored, and how applications behave.

The more managed the service, the more the provider handles. The more custom the solution, the more responsibility stays with the customer.

02

Section 2 of 7

Plain-English Vocabulary

  • Provider responsibility: physical datacenters, core platform infrastructure, and managed service operation.
  • Customer responsibility: identity, data classification, access, configuration, application logic, and business process controls.
  • Configuration risk: a secure service used in an unsafe way.
  • AI responsibility: data grounding, prompt and instruction design, safety controls, evidence, review, and accountability.
03

Section 3 of 7

Realistic Scenario

A team stores confidential documents in cloud storage. The provider protects the physical datacenter and storage platform. The company still needs to configure access, encryption settings, logging, retention, data classification, and review processes.

If an AI assistant summarizes those documents, responsibility expands. The team must decide who may ask questions, which documents can be retrieved, how outputs are reviewed, and how unsupported claims are detected.

04

Section 4 of 7

Why It Matters

Cloud does not remove accountability. It changes where accountability sits. Business users, product owners, engineers, architects, security teams, and platform teams must understand the boundary.

In AI, shared responsibility becomes even more visible because outputs may sound confident. The provider may run the model, but the company owns use case suitability, data access, user permissions, validation, and business decisions made from the output.

05

Section 5 of 7

Common Misunderstandings

  • Managed services are not automatically approved for every data type.
  • Provider security does not replace internal access control.
  • AI output review is not optional just because the model is hosted by a major provider.
  • Compliance is not inherited in full; configuration and usage still matter.
07

Section 7 of 7

How To Talk About This With IT

Ask: "Which responsibilities move to the provider, which remain with us, and what evidence proves the controls are working?"

Versionv1.1Updated 09 Jun 2026
MCMarius CONSTANTINESCU