Shared responsibility for an AI workload
The split is the same one that governs every other AWS service, applied to models. AWS owns and secures the managed infrastructure the model runs on. The customer owns data classification, access control, and the configuration of what they build - for a generative workload, who may invoke which model, what data reaches it, and where the outputs land. Bedrock keeps customer content private and does not use it to improve base models, but that is a property of the service, not a substitute for your own controls.