Publicado el — Deja un comentario

Amazon MWAA adds built-in monitoring with Amazon CloudWatch

Amazon Managed Workflows for Apache Airflow (MWAA) now includes a built-in monitoring experience on the environment detail page in the AWS Management Console. A new metrics dashboard displays key Amazon CloudWatch metrics for your environment in one place, and each graph includes an optional toggle to overlay suggested warning ranges, helping you quickly identify conditions that may affect your environment’s health and performance.

The environment detail page also now shows an alarms table that lists all Amazon CloudWatch alarms associated with your MWAA environment. You can use the one-click Create Recommended Alarms action to provision a curated set of alarms from an AWS-managed template, so you can start monitoring critical metrics without having to configure each alarm manually. This feature is available for Amazon MWAA Provisioned environments in all regions where Amazon MWAA is available. Standard Amazon CloudWatch pricing applies for metric queries and alarms.

To get started, open the AWS Management Console, review the Amazon MWAA supported regions, or visit the Amazon MWAA documentation to learn more.

 

 

​Amazon Managed Workflows for Apache Airflow (MWAA) now includes a built-in monitoring experience on the environment detail page in the AWS Management Console. A new metrics dashboard displays key Amazon CloudWatch metrics for your environment in one place, and each graph includes an optional toggle to overlay suggested warning ranges, helping you quickly identify conditions that may affect your environment’s health and performance.
The environment detail page also now shows an alarms table that lists all Amazon CloudWatch alarms associated with your MWAA environment. You can use the one-click Create Recommended Alarms action to provision a curated set of alarms from an AWS-managed template, so you can start monitoring critical metrics without having to configure each alarm manually. This feature is available for Amazon MWAA Provisioned environments in all regions where Amazon MWAA is available. Standard Amazon CloudWatch pricing applies for metric queries and alarms.
To get started, open the AWS Management Console, review the Amazon MWAA supported regions, or visit the Amazon MWAA documentation to learn more.
   

Publicado el — Deja un comentario

Amazon Linux 2027 is now available in public preview

Today, AWS announces the public preview of Amazon Linux 2027 (AL2027), the next version of the Amazon Linux operating system, purpose-built for cloud-native workloads on AWS with performance, scale, and security in mind. Built on AL2023’s baseline, AL2027 is designed for customers running web applications, databases, containerized microservices, AI/ML workloads, and large-scale infrastructure who need a secure, stable, and AWS-native operating system.

AL2027 runs on kernel 7.1+, enables SELinux in enforcing mode as default, accelerates cryptographic performance with AWS-LC, and keeps builders current with the latest toolchains and language runtimes. For AI and machine learning workloads, it delivers access to accelerator drivers, including AWS Neuron driver support. The public preview gives customers hands-on access before general availability (GA) to experiment with new features, validate their applications, and provide direct feedback to the Amazon Linux team.

AL2027 Preview AMIs are available through the AWS Management Console across all commercial AWS Regions, with both x86-64 and ARM variants. Container base images are available on Amazon ECR Public Gallery. Customers can submit feedback through the AL2027 GitHub repository. For a full list of changes relative to AL2023, see the AL2027 documentation. To learn more, visit the Amazon Linux product page.

 

​Today, AWS announces the public preview of Amazon Linux 2027 (AL2027), the next version of the Amazon Linux operating system, purpose-built for cloud-native workloads on AWS with performance, scale, and security in mind. Built on AL2023’s baseline, AL2027 is designed for customers running web applications, databases, containerized microservices, AI/ML workloads, and large-scale infrastructure who need a secure, stable, and AWS-native operating system.
AL2027 runs on kernel 7.1+, enables SELinux in enforcing mode as default, accelerates cryptographic performance with AWS-LC, and keeps builders current with the latest toolchains and language runtimes. For AI and machine learning workloads, it delivers access to accelerator drivers, including AWS Neuron driver support. The public preview gives customers hands-on access before general availability (GA) to experiment with new features, validate their applications, and provide direct feedback to the Amazon Linux team.
AL2027 Preview AMIs are available through the AWS Management Console across all commercial AWS Regions, with both x86-64 and ARM variants. Container base images are available on Amazon ECR Public Gallery. Customers can submit feedback through the AL2027 GitHub repository. For a full list of changes relative to AL2023, see the AL2027 documentation. To learn more, visit the Amazon Linux product page.  

Publicado el — Deja un comentario

Introducing Amazon Quick Max: 5x the usage for power users who want the most out of Quick

Amazon Quick now offers Quick Max, a new plan for power users who want to get the absolute most out of Quick. With 5x the usage and 5x the storage of Plus, Max gives you the room to do more: more agents, more workflows, more of whatever makes Quick yours. 

With Max, you can run large, concurrent workloads without interruption—all month long. It delivers more value per dollar the more you use it and is available with both monthly and annual billing options.  

New to Amazon Quick? You can sign up for free in minutes. Already on Plus? Click your name at the bottom of the left navigation bar, then select «Upgrade plan» to switch to Max. To compare all available plans—Free, Plus, and Max—visit the Amazon Quick pricing page. 

 

​Amazon Quick now offers Quick Max, a new plan for power users who want to get the absolute most out of Quick. With 5x the usage and 5x the storage of Plus, Max gives you the room to do more: more agents, more workflows, more of whatever makes Quick yours. 
With Max, you can run large, concurrent workloads without interruption—all month long. It delivers more value per dollar the more you use it and is available with both monthly and annual billing options.  
New to Amazon Quick? You can sign up for free in minutes. Already on Plus? Click your name at the bottom of the left navigation bar, then select «Upgrade plan» to switch to Max. To compare all available plans—Free, Plus, and Max—visit the Amazon Quick pricing page.   

Publicado el — Deja un comentario

AWS Transform announces general availability of Amazon FSx for NetApp ONTAP support

AWS Transform for migrations adds Amazon FSx for NetApp ONTAP as a generally available storage target for block storage workloads, alongside Amazon EBS. With AWS Transform, you can now migrate block storage directly to FSx for ONTAP as part of the same migration wave that handles compute and networks, eliminating the need for intermediate storage platforms and separate migration tools.

Whether migrating from NetApp ONTAP, other block storage platforms, or VMware environments, your data access patterns and operational processes remain unchanged with FSx for ONTAP. Now your workloads run on a fully managed, production-ready shared storage service that combines ONTAP’s enterprise capabilities with the scalability and resiliency of AWS. What previously required stitching together multiple tools is now a single migration workflow.

This capability is available in all AWS Transform supported target Regions and where Amazon FSx for NetApp ONTAP is supported. To get started, visit AWS Transform for migrations. To learn more about Amazon FSx for NetApp ONTAP, see the product page.

 

​AWS Transform for migrations adds Amazon FSx for NetApp ONTAP as a generally available storage target for block storage workloads, alongside Amazon EBS. With AWS Transform, you can now migrate block storage directly to FSx for ONTAP as part of the same migration wave that handles compute and networks, eliminating the need for intermediate storage platforms and separate migration tools.
Whether migrating from NetApp ONTAP, other block storage platforms, or VMware environments, your data access patterns and operational processes remain unchanged with FSx for ONTAP. Now your workloads run on a fully managed, production-ready shared storage service that combines ONTAP’s enterprise capabilities with the scalability and resiliency of AWS. What previously required stitching together multiple tools is now a single migration workflow.
This capability is available in all AWS Transform supported target Regions and where Amazon FSx for NetApp ONTAP is supported. To get started, visit AWS Transform for migrations. To learn more about Amazon FSx for NetApp ONTAP, see the product page.  

Publicado el — Deja un comentario

Amazon Connect Customer expands automated performance evaluations to Malay

Amazon Connect Customer now automates evaluations of human and AI agents in Malay using generative AI. Managers define custom evaluation criteria in natural language and receive AI-generated evaluations with justifications in their preferred language. Performance evaluations also supports cross-language evaluation and can complete assessments in English, even when the conversation is in Malay. This enables multilingual contact centers to use a standardized evaluation framework across languages.

This feature is supported in 8 AWS regions including US East (N. Virginia), US West (Oregon), Europe (Frankfurt), Europe (London), Canada (Central), Asia Pacific (Sydney), Asia Pacific (Tokyo), and Asia Pacific (Singapore). For information about Amazon Connect pricing, please visit our pricing page. To learn more, please visit our documentation and our webpage.

 

​Amazon Connect Customer now automates evaluations of human and AI agents in Malay using generative AI. Managers define custom evaluation criteria in natural language and receive AI-generated evaluations with justifications in their preferred language. Performance evaluations also supports cross-language evaluation and can complete assessments in English, even when the conversation is in Malay. This enables multilingual contact centers to use a standardized evaluation framework across languages.
This feature is supported in 8 AWS regions including US East (N. Virginia), US West (Oregon), Europe (Frankfurt), Europe (London), Canada (Central), Asia Pacific (Sydney), Asia Pacific (Tokyo), and Asia Pacific (Singapore). For information about Amazon Connect pricing, please visit our pricing page. To learn more, please visit our documentation and our webpage.  

Publicado el — Deja un comentario

Web Search on Amazon Bedrock is now available in AWS GovCloud (US-West)

The Web Search built-in server-side tool on Amazon Bedrock is now available in AWS GovCloud (US-West), helping bring grounded web results to compliance-sensitive government and public-sector workloads. Web Search helps supported OpenAI GPT models ground responses with information from the web. Responses include citations to the sources the model used so users can trace each claim back to its web origin. This can be especially valuable whenever an answer depends on information that changes over time or is more recent than a model’s training data, such as current events, recent releases or live pricing. Because the tool runs inside Amazon Bedrock, you don’t host a search index, manage crawlers, or write the tool-call loop yourself.

Web Search is designed to support the governance and data-handling standards AWS GovCloud (US) customers require. By default, it keeps your request data within the AWS boundary, serving results from a web index and cache maintained by Amazon. As an AWS-native capability governed by AWS Identity and Access Management (IAM), administrators can allow or deny it at the account or organization level and restrict it by Region, giving teams centralized control while keeping request data within the AWS boundary by default. To get started, add a tool of type web_search to the tools array in your OpenAI Responses API request using your existing OpenAI client library with an Amazon Bedrock API key. The model uses the tool only when it determines a request needs current information. At launch, Web Search in AWS GovCloud (US-West) supports GPT-5.4 , GPT-5.6 Terra and Luna models.

Web Search is available in AWS GovCloud (US-West), in addition to US East (N. Virginia), US East (Ohio), and US West (Oregon). To get started, see the Web Search technical blog. For implementation guidance, see the Web Search documentation. For pricing, see the Amazon Bedrock pricing page.

 

​The Web Search built-in server-side tool on Amazon Bedrock is now available in AWS GovCloud (US-West), helping bring grounded web results to compliance-sensitive government and public-sector workloads. Web Search helps supported OpenAI GPT models ground responses with information from the web. Responses include citations to the sources the model used so users can trace each claim back to its web origin. This can be especially valuable whenever an answer depends on information that changes over time or is more recent than a model’s training data, such as current events, recent releases or live pricing. Because the tool runs inside Amazon Bedrock, you don’t host a search index, manage crawlers, or write the tool-call loop yourself.
Web Search is designed to support the governance and data-handling standards AWS GovCloud (US) customers require. By default, it keeps your request data within the AWS boundary, serving results from a web index and cache maintained by Amazon. As an AWS-native capability governed by AWS Identity and Access Management (IAM), administrators can allow or deny it at the account or organization level and restrict it by Region, giving teams centralized control while keeping request data within the AWS boundary by default. To get started, add a tool of type web_search to the tools array in your OpenAI Responses API request using your existing OpenAI client library with an Amazon Bedrock API key. The model uses the tool only when it determines a request needs current information. At launch, Web Search in AWS GovCloud (US-West) supports GPT-5.4 , GPT-5.6 Terra and Luna models.
Web Search is available in AWS GovCloud (US-West), in addition to US East (N. Virginia), US East (Ohio), and US West (Oregon). To get started, see the Web Search technical blog. For implementation guidance, see the Web Search documentation. For pricing, see the Amazon Bedrock pricing page.  

Publicado el — Deja un comentario

Second-generation AWS Outposts racks now in the AWS GovCloud (US) Regions

Second-generation AWS Outposts racks are now supported in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. Outposts racks extend AWS infrastructure, AWS services, APIs, and tools to virtually any on-premises data center or colocation space for a truly consistent hybrid experience.

Organizations from startups to enterprises and the public sector can now order their Outposts racks connected to the new supported regions, optimizing for their latency and data residency needs. Outposts allows customers to run workloads that need low latency access to on-premises systems locally while connecting back to their home Region for application management. Customers can also use Outposts and AWS services to manage and process data that needs to remain on-premises to meet data residency requirements. This regional expansion provides additional flexibility in the AWS Regions that customers’ Outposts can connect to.

To learn more about second-generation Outposts racks, read this blog post and user guide. For the most updated list of countries and territories and the AWS Regions where second-generation Outposts racks are supported, check out the Outposts rack FAQs page.

 

​Second-generation AWS Outposts racks are now supported in the AWS GovCloud (US-East) and AWS GovCloud (US-West) Regions. Outposts racks extend AWS infrastructure, AWS services, APIs, and tools to virtually any on-premises data center or colocation space for a truly consistent hybrid experience. Organizations from startups to enterprises and the public sector can now order their Outposts racks connected to the new supported regions, optimizing for their latency and data residency needs. Outposts allows customers to run workloads that need low latency access to on-premises systems locally while connecting back to their home Region for application management. Customers can also use Outposts and AWS services to manage and process data that needs to remain on-premises to meet data residency requirements. This regional expansion provides additional flexibility in the AWS Regions that customers’ Outposts can connect to. To learn more about second-generation Outposts racks, read this blog post and user guide. For the most updated list of countries and territories and the AWS Regions where second-generation Outposts racks are supported, check out the Outposts rack FAQs page.  

Publicado el — Deja un comentario

Amazon Quick adds new tool settings and Model Context Protocol (MCP) sync support for connectors

Amazon Quick connectors let users leverage tools and services such as Outlook, Slack, Salesforce, Jira, and homegrown MCP servers directly into their workflows across chat, agents, apps, flows, and deep research. Today, Amazon Quick introduces new tool settings and MCP sync support that give admins and connector owners more control over how connectors are deployed and kept up to date.

Connector owners and admins can now selectively enable or disable individual tools within a connector to ensure only approved tools are available to end users. Additionally, new tool permission settings let connector owners decide which tools require consent before proceeding or give end users the flexibility to decide for themselves. Lastly, MCP sync keeps connectors current as external MCP servers add new tools, update descriptions, and evolve their capabilities, ensuring users always have the latest information to get their work done.

These features are available in all AWS Regions where Amazon Quick is available. To learn more, visit the Amazon Quick User Guide.

 

​Amazon Quick connectors let users leverage tools and services such as Outlook, Slack, Salesforce, Jira, and homegrown MCP servers directly into their workflows across chat, agents, apps, flows, and deep research. Today, Amazon Quick introduces new tool settings and MCP sync support that give admins and connector owners more control over how connectors are deployed and kept up to date.
Connector owners and admins can now selectively enable or disable individual tools within a connector to ensure only approved tools are available to end users. Additionally, new tool permission settings let connector owners decide which tools require consent before proceeding or give end users the flexibility to decide for themselves. Lastly, MCP sync keeps connectors current as external MCP servers add new tools, update descriptions, and evolve their capabilities, ensuring users always have the latest information to get their work done.
These features are available in all AWS Regions where Amazon Quick is available. To learn more, visit the Amazon Quick User Guide.  

Publicado el — Deja un comentario

AWS Config now supports 60 new resource types

AWS Config now supports 60 additional AWS resource types across key services including Amazon Bedrock,  Amazon EC2, Amazon SageMaker, and AWS Organizations. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources.

With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators.

You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the resources are available:

Resource Types:

AWS::AppSync::ChannelNamespace AWS::EC2::RouteServer AWS::Organizations::Policy
AWS::AppSync::SourceApiAssociation AWS::EC2::RouteServerEndpoint AWS::Organizations::ResourcePolicy
AWS::Bedrock::EnforcedGuardrailConfiguration AWS::EC2::RouteServerPeer AWS::QuickSight::RefreshSchedule
AWS::Bedrock::Flow AWS::EKS::PodIdentityAssociation AWS::RDS::DBProxy
AWS::Bedrock::FlowVersion AWS::ElasticLoadBalancingV2::ListenerRule AWS::S3Vectors::Index
AWS::Bedrock::PromptVersion AWS::GameLiftStreams::Application AWS::SageMaker::Action
AWS::BedrockAgentCore::OAuth2CredentialProvider AWS::GameLiftStreams::StreamGroup AWS::SageMaker::Algorithm
AWS::BedrockAgentCore::PaymentManager AWS::IdentityStore::Group AWS::SageMaker::App
AWS::BedrockAgentCore::Policy AWS::IoT::TopicRuleDestination AWS::SageMaker::Context
AWS::BedrockAgentCore::PolicyEngine AWS::Lightsail::Container AWS::SageMaker::Hub
AWS::BedrockAgentCore::TokenVault AWS::Lightsail::Database AWS::SageMaker::MlflowApp
AWS::Chime::AppInstance AWS::Lightsail::Distribution AWS::SageMaker::ModelCard
AWS::CloudTrail::ResourcePolicy AWS::Lightsail::Domain AWS::SageMaker::ModelPackage
AWS::CodePipeline::Webhook AWS::Lightsail::Instance AWS::SES::MailManagerArchive
AWS::Config::OrganizationConformancePack AWS::Lightsail::LoadBalancer AWS::Transfer::WebApp
AWS::Connect::AgentStatus AWS::Logs::ResourcePolicy AWS::WorkSpacesWeb::TrustStore
AWS::Connect::EvaluationForm AWS::MediaConnect::Bridge AWS::WorkSpacesWeb::UserAccessLoggingSettings
AWS::Connect::View AWS::NetworkManager::CoreNetwork AWS::XRay::Group
AWS::Connect::ViewVersion AWS::Organizations::Account AWS::XRay::ResourcePolicy
AWS::EC2::NetworkPerformanceMetricSubscription AWS::Organizations::Organization AWS::XRay::SamplingRule

 

​AWS Config now supports 60 additional AWS resource types across key services including Amazon Bedrock,  Amazon EC2, Amazon SageMaker, and AWS Organizations. This expansion provides greater coverage over your AWS environment, enabling you to more effectively discover, assess, audit, and remediate an even broader range of resources.
With this launch, if you have enabled recording for all resource types, then AWS Config will automatically track these new additions. The newly supported resource types are also available in Config rules and Config aggregators.
You can now use AWS Config to monitor the following newly supported resource types in all AWS Regions where the resources are available:
Resource Types:

AWS::AppSync::ChannelNamespace
AWS::EC2::RouteServer
AWS::Organizations::Policy

AWS::AppSync::SourceApiAssociation
AWS::EC2::RouteServerEndpoint
AWS::Organizations::ResourcePolicy

AWS::Bedrock::EnforcedGuardrailConfiguration
AWS::EC2::RouteServerPeer
AWS::QuickSight::RefreshSchedule

AWS::Bedrock::Flow
AWS::EKS::PodIdentityAssociation
AWS::RDS::DBProxy

AWS::Bedrock::FlowVersion
AWS::ElasticLoadBalancingV2::ListenerRule
AWS::S3Vectors::Index

AWS::Bedrock::PromptVersion
AWS::GameLiftStreams::Application
AWS::SageMaker::Action

AWS::BedrockAgentCore::OAuth2CredentialProvider
AWS::GameLiftStreams::StreamGroup
AWS::SageMaker::Algorithm

AWS::BedrockAgentCore::PaymentManager
AWS::IdentityStore::Group
AWS::SageMaker::App

AWS::BedrockAgentCore::Policy
AWS::IoT::TopicRuleDestination
AWS::SageMaker::Context

AWS::BedrockAgentCore::PolicyEngine
AWS::Lightsail::Container
AWS::SageMaker::Hub

AWS::BedrockAgentCore::TokenVault
AWS::Lightsail::Database
AWS::SageMaker::MlflowApp

AWS::Chime::AppInstance
AWS::Lightsail::Distribution
AWS::SageMaker::ModelCard

AWS::CloudTrail::ResourcePolicy
AWS::Lightsail::Domain
AWS::SageMaker::ModelPackage

AWS::CodePipeline::Webhook
AWS::Lightsail::Instance
AWS::SES::MailManagerArchive

AWS::Config::OrganizationConformancePack
AWS::Lightsail::LoadBalancer
AWS::Transfer::WebApp

AWS::Connect::AgentStatus
AWS::Logs::ResourcePolicy
AWS::WorkSpacesWeb::TrustStore

AWS::Connect::EvaluationForm
AWS::MediaConnect::Bridge
AWS::WorkSpacesWeb::UserAccessLoggingSettings

AWS::Connect::View
AWS::NetworkManager::CoreNetwork
AWS::XRay::Group

AWS::Connect::ViewVersion
AWS::Organizations::Account
AWS::XRay::ResourcePolicy

AWS::EC2::NetworkPerformanceMetricSubscription
AWS::Organizations::Organization
AWS::XRay::SamplingRule  

Publicado el — Deja un comentario

Tres decisiones de arquitectura detrás de la plataforma legal de IA de PONS en Microsoft Azure

Tres decisiones de arquitectura detrás de la plataforma legal de IA de PONS en Microsoft Azure

Resumen: PONS comparte tres decisiones de diseño detrás de su plataforma legal de IA en Microsoft Azure, desde separar el conocimiento jurídico público y los datos de los clientes hasta el uso de servicios gestionados e implementación de controles de seguridad y cumplimiento. El artículo destaca consideraciones prácticas para startups que desarrollan IA para clientes empresariales regulados.

Banner con las palabras: "Diseño de IA para industrias reguladas"

Publicado en Microsoft for Startups.

Construir IA legal para industrias reguladas requiere mucho más que conectar un modelo a los documentos. Para las startups que sirven a industrias reguladas, el reto no es solo la capacidad del modelo, sino cómo el sistema gestiona fuentes confiables, datos privados, prioridades de infraestructura y requisitos de cumplimiento.

PONS construyó su plataforma de IA legal en torno a esas limitaciones. Al correr en Microsoft Azure, soporta investigación, redacción, revisión de contratos, diligencia debida y gestión de asuntos para despachos de abogados, equipos legales internos y otras organizaciones reguladas.

Este texto examina tres decisiones de diseño detrás de la plataforma y qué pueden aprender de ellas las startups que desarrollan IA para clientes regulados.

A través de Microsoft for Startups, PONS pudo acceder a créditos de startup, orientación técnica y presentaciones oportunas mientras desarrollaba su arquitectura Azure alojada en la UE. Según PONS, este soporte ayudó a su pequeño equipo a probar decisiones arquitectónicas frente a cargas reales y a abordar los requisitos técnicos para clientes regulados.

¿Construir IA para clientes empresariales regulados? Las startups elegibles pueden solicitar a Microsoft for Startups acceso a créditos de startup que se desbloquean a medida que crean, herramientas para desarrolladores, orientación técnica y oportunidades para llegar a clientes.

Apliquen a Microsoft for startups

Dentro de la arquitectura legal de IA PONS en Azure

Tobias Zimmergren, CTO y cofundador técnico de PONS

La plataforma PONS consta de dos componentes principales: la PONS Data Factory y el PONS AI Engine.

PONS Data Factory es una cadena continua que valida, recopila, limpia e indexa fuentes jurídicas públicas, incluidas legislación, jurisprudencia y precedentes. Añade metadatos semánticos, estructura jerárquica, incrustaciones vectoriales y referencias enlazadas a fuentes para crear un corpus legal curado disponible en múltiples jurisdicciones.

El motor de IA PONS soporta razonamiento citado, redacción, revisión de contratos y extracción estructurada. Funciona tanto contra el corpus de Data Factory como contra documentos de clientes almacenados por separado (que no entran en Data Factory), con resultados evaluados para precisión legal, cobertura contextual, lenguaje y estructura, y que se reejecutan en automático en caso de fallo. El backend no llama directo al motor: el trabajo se publica en una cola que el AI Engine consulta, por lo que escala de manera independiente de la ruta de solicitud. Está impulsado por Azure OpenAI y alojado en Azure Sweden Central.

Los clientes también configuran asuntos, manuales, plantillas y una base de conocimiento conectada, lo que crea el contexto necesario para los flujos de trabajo específicos de la firma y el análisis legal.

Diagrama de la arquitectura PONS en Microsoft Azure. Data Factory organiza y prepara fuentes legales públicas para el motor de IA, mientras que los datos privados de los clientes omiten Data Factory y se procesan por una ruta independiente.

Decisión de diseño uno: Separar el conocimiento confiable del contexto privado

PONS separa de manera intencionada su corpus legal público de los datos de los clientes. La Data Factory está diseñada para recopilar y actualizar de manera continua, fuentes legales públicas en diferentes jurisdicciones. Según PONS, los documentos de los clientes permanecen separados, y el flujo de datos unidireccional significa que no entran en la Data Factory y se procesan de manera independiente a través del AI Engine. Los datos de cada empresa permanecen en almacenamiento aislado y contenedores de bases de datos dentro de su entorno Azure de la región de la UE, cifrados en tránsito y en reposo, con el acceso asignado por defecto a los usuarios individuales.

Este límite permite a PONS actualizar y validar su corpus legal sin incorporar material privado de clientes en esa canalización. También proporciona a la plataforma un control arquitectónico claro para demostrar dónde residen los datos del cliente y evitar que se conviertan en parte de la capa de conocimiento legal público.

Las startups deberían tener en cuenta este patrón cuando su producto combina un cuerpo de información fiable actualizado de manera continua, con datos específicos o sensibles para el cliente, en especial cuando ambos requieren controles de acceso, residencia o gobernanza diferentes. Establecer el límite desde el principio puede reducir el riesgo de que los datos privados se entrelacen con las canaletas compartidas de ingestión e indexación a medida que el producto crece.

Segunda decisión: Utilizar servicios gestionados de Azure para centrar el esfuerzo de ingeniería en la diferenciación

Para ONS, elegir servicios gestionados fue una decisión de priorización de ingeniería: comprar la infraestructura indiferenciada y concentrar al equipo en la calidad de datos legales, razonamiento, evaluación y flujo de trabajo del cliente.

Este principio moldeó la arquitectura de Azure. Azure App Service gestiona la aplicación, por lo que no operan servidores ni gestionan despliegues de manera manual. Azure SQL Database y Microsoft Azure Storage almacenan datos estructurados y archivos de clientes con la residencia europea fijada en Sweden Central, lo que convierte la localización de datos en una decisión de configuración y no en un proyecto de ingeniería. Azure Key Vault mantiene secretos y certificados fuera del código de la aplicación.

Azure App Configuration mantiene configuraciones compartidas no sensibles, y las conexiones de servicio a servicio funcionan con identidad gestionada, por lo que no hay credenciales que rotar de manera manual. El trabajo de análisis se transfiere a través de un Azure Queue Storage en lugar de una llamada directa, lo que permite que el AI Engine escale de manera independiente de la ruta de la solicitud, y Azure Web PubSub envía resultados y notificaciones de vuelta a la aplicación web en tiempo real.

Para la capa de IA, Azure OpenAI proporciona los modelos base, mientras que Microsoft Foundry aloja los modelos ajustados y de soporte detrás de Data Factory y AI Engine. Esto proporciona a PONS capacidades de frontera sin necesidad de crear su propia pila de servicio de modelos.

El beneficio práctico es que hay menos infraestructura para que un equipo pequeño opere. PONS puede basarse en las capacidades de Azure para escalado, despliegues, identidad, registro y configuración regional, mientras dirige más esfuerzo de ingeniería hacia las partes del producto que evalúan los clientes. PONS aceptó menos control de bajo nivel a cambio de servicios Azure gestionados que apoyen sus requisitos de despliegue regional, identidad, registro y evidencia de cumplimiento.

Este enfoque es más útil cuando la diferenciación de una startup reside en datos específicos de dominio, flujos de trabajo o comportamiento del producto más que en operaciones de infraestructura. Evalúa un servicio gestionado por el trabajo recurrente que elimina, los controles que soporta y cómo su nivel de flexibilidad se alinea con los requisitos del producto.

Tobias Zimmergren, CTO y cofundador técnico de PONS

Decisión tres: Convertir los requisitos de cumplimiento y seguridad en controles exigibles

El asesor jurídico general y los equipos de compras evalúan más que las capacidades de la IA. Para PONS, su arquitectura debe responder preguntas clave, como:

  1. ¿Dónde residen los datos?
  2. ¿Quién puede acceder a ella?
  3. ¿Se puede auditar el sistema?
  4. ¿Acabarán los documentos de los clientes entrenando el modelo de alguien?
  5. ¿Esto se mantiene en todas las jurisdicciones en las que operamos?

PONS afirma que aborda la localización y acceso de datos mediante aislamiento regional y permisos con alcance. Los registros de procedencia vinculada a citas y auditoría soportan la trazabilidad, mientras que las puertas de evaluación reejecutan en automático salidas fallidas y aplican rechazo por diseño cuando el sistema no puede conectar a tierra una respuesta. Los documentos del cliente no entran en Data Factory ni se utilizan para el entrenamiento de modelos. El corpus legal de Data Factory abarca múltiples jurisdicciones y sigue expandiéndose, mientras que los controles de aislamiento, acceso, registro y evaluación de la plataforma proporcionan una línea técnica común de referencia.

PONS también cita sus controles SOC 2 Tipo II, ISO 27001, el Reglamento General de Protección de Datos (GDPR, por sus siglas en inglés) y las pruebas de penetración como criterios de entrada importantes para la adquisición empresarial, pero los requisitos subyacentes continúan con el moldeado de la arquitectura y los controles de la plataforma.

Para startups que construyen para empresas en mercados regulados, estas preguntas son más útiles cuando se plantean desde el principio, mientras que los límites sobre datos, acceso y comportamiento del modelo pueden seguir diseñándose en el sistema en lugar de documentarse después. Para una orientación más amplia sobre cómo preparar soluciones Azure para clientes empresariales, consulten LA preparación empresarial para startups en Azure.

Exploren la plataforma de IA legal PONS

PONS funciona en producción con clientes en múltiples jurisdicciones de la UE, donde sirve de manera primordial a despachos de abogados y equipos legales internos, con pilotos activos en marcha en otros sectores. Si ustedes exploran cómo construir IA basada en citas con los requisitos de seguridad, privacidad y gobernanza en mente, pueden leer más sobre lo que hace PONS, la plataforma y la arquitectura que hay detrás en pons.io.

Construir para clientes empresariales regulados con Microsoft para startups

A medida que la plataforma se desarrollaba, los créditos de startups a través de Microsoft for Startups dieron a PONS la flexibilidad para probar decisiones arquitectónicas en cargas reales mientras gestionaba los costes de la nube durante el crecimiento inicial. Los especialistas de Microsoft proporcionaron orientación sobre decisiones técnicas complejas, mientras que las presentaciones oportunas ayudaron al equipo a abordar los requisitos de producción y mantener el impulso a medida que la plataforma escalaba.

Si se encuentran en el proceso de desarrollo de soluciones de IA para clientes empresariales en sectores regulados, Microsoft for Startups puede ayudarlos a construir rápido, escalar de manera inteligente y vender más. Empiecen hoy mismo con Microsoft for Startups.

The post Tres decisiones de arquitectura detrás de la plataforma legal de IA de PONS en Microsoft Azure appeared first on Source LATAM.

 

​The post Tres decisiones de arquitectura detrás de la plataforma legal de IA de PONS en Microsoft Azure appeared first on Source LATAM.