5 ms·
Every time somebody questions why you might "trust" AWS (or Azure or GCP or whatever), or why you'd pay this premium, I realize they are not accustomed to worki
by kylemaxwell 4mo ago
Every time somebody questions why you might "trust" AWS (or Azure or GCP or whatever), or why you'd pay this premium, I realize they are not accustomed to working in enterprise environments.
In my case, I work at a large enterprise with strict data governance built into customer contracts, and (partly related, partly not) our own governance concerns. Using vendors where you not only have infosec permission, but they are also listed as data processors in our contracts with our customers is the way not to get fired and sued.
If I'm playing around at home, with my own code and data, I can do whatever I want. But with my employer and customer? Absolutely not. It's the same reason we don't use whatever is the flavor of the month frontier model is.
Side hustles and startups just have an entirely different set of constraints and considerations.
- sntran 4mo agoI have just moved from a free environment in which I was able to use any AI harnesses or models to a strict enterprise environment. I was shocked to realize how difficult it has been to have a GitHub CoPilot license on Azure. I mean, they're both Microsoft products. But no, the IT now has to figure out how to set up a GitHub enterprise, link to Azure subscription, and all that.
- philipwhiuk 4mo agoand set reasonable global and user token limits to avoid burning a year's IT spend cause Dave in Legal went ham on tokenmaxxing by uploading his entire legal case history. in a company of 12 you can do that by saying 'we're all generalists, just don't be an idiot'. In a company of 10,000, you hired Dave cause he's good at legal merger mumbo jumbo not because he's an IT generalist.
- foolfoolz 4mo agowhile true, everyone signed this same data privacy agreement with anthropic / openai a long tiem ago
- bunderbunder 4mo agoIt’s not just that. Oftentimes contracts stipulate that the client’s data can’t be transferred across certain boundaries. If you have signed such an agreement, even sending the data to a service on the same cloud provider but in a different region could be a huge compliance violation.
- kube-system 4mo agoThe agreements that Anthropic/OpenAI are pretty general and there’s a lot of use cases they don’t meet. The list of compliance standards that AWS meets is so big they have a separate product just to deliver the compliance documents. They basically do everything imaginable.
- rushcar 4mo agoThere are differences. Vertex / Bedrock have zero prompt logging for Opus 4.8. Anthropic logs prompts for 30 days. source: https://openrouter.ai/anthropic/claude-opus-4.8/providers https://openrouter.ai/anthropic/claude-opus-4.8/providers
- btown 4mo agoOn top of this, there's a vast difference between "what do you mean that team spent $1000 on AI in their expense report, what did we get for that?" vs. "oh, the company-wide AWS bill went up by a few percent, let's look into that when we have time." The latter makes projects far more viable.
- cubefox 4mo agoBut note that this difference is the result of bad accounting.
- dragonwriter 4mo agoWell, as framed its bad accounting. OTOH, the other form is that instead of generic AI spend going up it is total spending for a particular AWS account within the umbrella of the firms AWS organization, so that the spending is attributed to a specific project whose use case, other costs, and (presumably) benefit and/or revenue can be considered. Of course, if your AWS stuff is just one undifferentiated bucket, that’s a problem, but AFAICT AWS (like GCP) is much better set up for tracking use and costs by project than OpenAI (or Anthropic), because its an enterprise cloud provider where fitting into how large organizations track things at multiple levels is as much a core competency as any technical feature, whereas OpenAI and Anthropic are AI technology providers that are much less mature as enterprise vendors.
- raincole 4mo agoOr to put it simply, nobody ever got fired for buying IBM.
- jimbokun 4mo ago-> Microsoft -> AWS.
- petesergeant 4mo agoI would absolutely fire someone for using Azure without extenuating circumstances.
- hdgvhicv 4mo agoAre you the CTO of a $1b+ revenue company?
- petesergeant 4mo agoAre they the only people allowed to fire someone?
- IMTDb 4mo agoWhat GP meant is that the CTO of a $1b company wold absolutely not fire someone for going Azure because at those scale it's very likely they have a set of customers that exclusively want to work on Azure, so that choice makes sense. It's easy to do blanket statements like "never choose azure", "avoid GCP at all cost" or "never again on AWS". Until real world comes your way and you are forced to deal with it. That being said: I'd fire anyone choosing to deploy a workload on GCP.
- mitchitized 4mo agoAnother reality is that at that scale you need to diversify your vendor portfolio so you never get stuck in a single-vendor scenario (for contracts, liability or scale). Many companies half this size have infrastructure across all three - AWS, Azure and GCP. The primary reason is redundancy, but that also gives them potential leverage for contract negotiation.
- glzone1 4mo agoThe security posture at AWS is different. AI startups are going to get hacked and leak data etc. All the startup webapp builder tools, vscode plugin players etc. AWS could still be hacked, but they've taken some care to make it a bit less likely, a bit easier to track which customers affected etc. If you dig into AWS logging for example, there is a TON if you turn it on, you can really go back and see who did what to the permissions / environment etc. I imagine they've got pretty good logging of their staffs access to things as well. I had to jump through some hoops once to have their staff on my account.
- deleted 4mo ago[deleted]
- gobdovan 4mo agoHave you considered checking the actual AWS contract and the limited liability they explicitly stipulate in contracts and even linked docs from marketing materials? If you read the fine print, you'll notice something funny. You are largely responsible for data loss, SLA claims require you to present concrete evidence, and the remediation you accepted is usually credits for future spend on specifically the same product you lost your data on. And AWS fine print is actually quite reasonable compared with, say, GCP, where the SLA seems mostly useful so the enterprise acquisition team can say "they have SLA, I can't get fired for choosing them since I did my due diligence!", while GCP can say "you already accepted the proposed remedy when signing the contract, sue us and we'll just point you to it. Thanks for your trust.". [0] [0] https://docs.cloud.google.com/storage/docs/storage-classes https://docs.cloud.google.com/storage/docs/storage-classes ^ Standard multi-region or dual-region storage has a 99.95% availability SLA, regional Standard has 99.9%, and regional Nearline, Coldline, or Archive can be as low as 99.0%. The credits are 10%, 25%, or 50% of the monthly bill for the affected service tier, with 50% as the aggregate monthly cap, applied to future use. Google also says the customer must request the credit within 30 days or forfeit it.
- citrin_ru 4mo agoNobody ever got fired for buying I̵B̵M̵ AWS. Most corporations already use AWS, used to its legal terms and accepted the risk. Any new provider will be scrutinised by legal more than an existing one.
- saidnooneever 4mo agothis..it doesnt really matter whats on the contract they all sell same things. in enterprise things just should not get u sacked :p then it workks perfectly.
- regularfry 4mo agoModels on Bedrock can have different and additional terms and conditions, there's even variety within the same provider for some of them. The Anthropic ones certainly have their own EULA. It's a bit frustrating because ideally it should be a known legal status, but in fact it still needs legal review if you're doing anything interesting.
- comandillos 4mo agoIn my company is simpler, we deal with data under EU Export Control so we cannot use any US provider due to the CLOUD Act.
- notepad0x90 4mo agoYeah, cloud agents come with nice things like being able to filter content, implement guardrails like preventing PII or prompt injection from taking place. even if they sucked, at least liability wise you're set. I don't know how someone could even come close to this capability by doing it on their own. If anyone does, please share what tools, platforms and projects you're using.
- devld 4mo agoI think I would trust Amazon more than Antrophic, since they have no models of their own, they have no business collecting your data for training, while Antrophic most certainly does.