[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:sr":3,"public-menus:all":38,"post:what-is-an-ai-platform-architect-models-data-runtime-security-and-operations:sr":205,"related:post:what-is-an-ai-platform-architect-models-data-runtime-security-and-operations:sr:1":2441},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","sr","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":2440},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1202,"featuredImage":1203,"featuredImageAlt":1204,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1205,"publishedAt":1206,"createdAt":1207,"updatedAt":1208,"seoLocalePaths":1209,"categories":1218,"author":1231,"translations":1236},"484","Šta je arhitekta AI platforme? Modeli, podaci, izvršno okruženje, bezbednost i operacije","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","\u003Cp>\u003Cstrong>Arhitekta AI platforme\u003C\u002Fstrong> projektuje višekratno upotrebljivu AI osnovu preko koje više aplikacija, timova ili korisničkih konteksta pristupa modelima, podacima i pretraživanju, izvršnim okruženjima agenata i alata, identitetu i dozvolama, evaluaciji, nadzoru, kvotama, tajnama i mogućnostima za implementaciju. Uloga je šira od infrastrukture, ali uža od vlasništva nad svakim AI proizvodom: njena centralna odgovornost je da odluči \u003Cstrong>šta treba deliti, kako se deljene mogućnosti upravljaju i izoluju, i šta mora ostati specifično za rešenje\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--info my-6 rounded-xl border p-5 border-blue-300 bg-blue-50 dark:border-blue-900 dark:bg-blue-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Direktan odgovor\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>Arhitekta AI platforme projektuje zajednički tehnički i operativni sloj za AI sisteme.\u003C\u002Fstrong> Umesto projektovanja jednog asistenta ili jednog toka rada, uloga definiše višekratno upotrebljive ugovore i granice za pristup modelima\u002Fdobavljačima, kapije i rutiranje, usluge pretraživanja, izvršna okruženja agenata, pristup alatima, identitet i izolaciju korisnika, tajne, evaluaciju, telemetriju, implementaciju i upravljanje životnim ciklusom.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Napomena o terminologiji\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>Arhitekta AI platforme je praktična oznaka uloge, a ne univerzalno standardizovan naziv radnog mesta.\u003C\u002Fstrong> ISO\u002FIEC\u002FIEEE 42010:2022 definiše koncepte za opise arhitekture, a ne ovu ulogu. Različite organizacije mogu podeliti ove odgovornosti između arhitekata platforme, arhitekata rešenja, arhitekata preduzeća, bezbednosnih arhitekata, MLOps\u002FLLMOps specijalista i timova za inženjering platforme. Ovaj članak koristi termin za arhitektonsku odgovornost nad višekratno upotrebljivim slojem AI platforme.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Napomena o aktuelnim izvorima — 8. oktobar 2026.\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Stabilni arhitektonski principi ovde su neutralni u pogledu dobavljača. Aktuelne Microsoft, AWS i NIST smernice koriste se kao spoljni dokaz o implementaciji i upravljanju. NIST navodi da se AI RMF 1.0 revidira; funkcije platforme dobavljača, proizvodi kapija, izvršna okruženja agenata i mogućnosti modela razvijaju se brže od arhitektonskih principa, pa se izbori implementacije osetljivi na verziju moraju ponovo proveriti pre implementacije.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cnav class=\"editorjs-toc\" data-editorjs-toc=\"true\" aria-label=\"Sadržaj\">\u003Cstrong class=\"editorjs-toc__title\">Sadržaj\u003C\u002Fstrong>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-0\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-6\" class=\"editorjs-toc__link\">Šta Arhitekta AI platforme zapravo projektuje?\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-10\" class=\"editorjs-toc__link\">Najjednostavniji primer\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-15\" class=\"editorjs-toc__link\">Gde se jednostavan primer zaustavlja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-18\" class=\"editorjs-toc__link\">Najvažnija odluka platforme: deljeno naspram specifičnog za rešenje\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-21\" class=\"editorjs-toc__link\">Mapa odgovornosti arhitekture\u003C\u002Fa>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-1\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-22\" class=\"editorjs-toc__link\">1. Pristup modelu i provajderu\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-26\" class=\"editorjs-toc__link\">2. Gejtvej, rutiranje, kvote i kontrole troškova\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-30\" class=\"editorjs-toc__link\">3. Zajednički podaci, usluge pretrage i utemeljenja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-34\" class=\"editorjs-toc__link\">4. Vreme izvršavanja agenata i alata\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-38\" class=\"editorjs-toc__link\">5. Identitet, izolacija zakupaca i autorizacija\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-42\" class=\"editorjs-toc__link\">6. Tajne, akreditivi i granice poverenja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-45\" class=\"editorjs-toc__link\">7. Evaluacija, observabilnost i mogućnost revizije\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-49\" class=\"editorjs-toc__link\">8. Izvršno okruženje, raspoređivanje i lokalnost\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-52\" class=\"editorjs-toc__link\">9. Životni ciklus platforme, kompatibilnost i onboarding\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-55\" class=\"editorjs-toc__link\">Praktični model kontrolne ravni \u002F izvršne ravni \u002F ravni rešenja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-59\" class=\"editorjs-toc__link\">Šta bi arhitekta AI platforme trebalo da proizvede?\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-61\" class=\"editorjs-toc__link\">Posao je uglavnom kompromis, a ne maksimalna centralizacija\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-63\" class=\"editorjs-toc__link\">Kako se ovo razlikuje od srodnih uloga?\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-66\" class=\"editorjs-toc__link\">Dokaz implementacije: kako se ove granice platforme pojavljuju u mom radu\u003C\u002Fa>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-1\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-68\" class=\"editorjs-toc__link\">Aaasaasa AI Client: razdvajanje provajdera, izvršnog okruženja i dozvola\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-73\" class=\"editorjs-toc__link\">Aaasaasa AI CMS: autorizacija ograničena na tenanta kao granica platforme\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-77\" class=\"editorjs-toc__link\">Source of Truth Research Engine: deljeni mehanizmi pretrage bez deljene istine\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-82\" class=\"editorjs-toc__link\">Kako trenutne arhitektonske smernice podržavaju ovaj obim platforme\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-88\" class=\"editorjs-toc__link\">Uobičajene zablude\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-90\" class=\"editorjs-toc__link\">Načini otkaza koje AI Platform Architect treba da spreči\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-92\" class=\"editorjs-toc__link\">Praktičan sled odluka o arhitekturi platforme\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-94\" class=\"editorjs-toc__link\">Rubni slučajevi i ograničenja uloge\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-100\" class=\"editorjs-toc__link\">Šta bi promenilo ovaj odgovor?\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-103\" class=\"editorjs-toc__link\">Kontrolna lista AI Platform Arhitekte\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-105\" class=\"editorjs-toc__link\">Zaključak\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-109\" class=\"editorjs-toc__link\">Povezano kanonsko znanje\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-114\" class=\"editorjs-toc__link\">Često postavljana pitanja\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-116\" class=\"editorjs-toc__link\">Pojmovnik\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-118\" class=\"editorjs-toc__link\">Primarni izvori i aktuelne smernice arhitekture\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fnav>\n\u003Ch2 id=\"section-6\">Šta Arhitekta AI platforme zapravo projektuje?\u003C\u002Fh2>\n\u003Cp>Predmet rada je \u003Cstrong>platforma\u003C\u002Fstrong>: skup zajedničkih mogućnosti koje smanjuju ponovljeni rad na integraciji uz očuvanje eksplicitnih bezbednosnih, podatkovnih i operativnih granica. Platforma može izložiti pristup modelima, adaptere dobavljača, primitive pretraživanja, izvršavanje agenata, brokere alata, sprovođenje politika, evaluaciju, telemetriju i usluge implementacije mnogim potrošačkim rešenjima.\u003C\u002Fp>\n\u003Cp>Platforma nije vredna samo zato što su komponente centralizovane. Vredna je kada potrošači dobijaju stabilne mogućnosti sa jasnim ugovorima, vlasništvom, izolacijom, nadzorom i pravilima životnog ciklusa. Ključno arhitektonsko pitanje stoga nije „Koji model treba svi da koriste?“ već \u003Cstrong>„Koje se odgovornosti mogu bezbedno standardizovati i ponovo koristiti bez brisanja zahteva svakog rešenja?“\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Arhitektura rešenja i arhitektura platforme rešavaju različite probleme obima\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">Arhitekta AI rešenja\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">Arhitekta AI platforme\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Primarni obim\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">One concrete AI-enabled product, workflow or application.\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Reusable AI capabilities consumed by multiple solutions, teams or tenant contexts.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Glavno pitanje\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">How should this solution meet its business, data, security, quality and operational requirements?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Which shared capabilities and controls should solutions consume, and where must solution-specific ownership remain?\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Nadležnost nad podacima\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Defines which domain data is authoritative and how the solution may use it.\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Provides storage, retrieval, provenance or access primitives without automatically becoming the authority for every domain.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Evaluacija\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Defines task-specific quality and acceptance criteria.\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Provides reusable evaluation, telemetry and release mechanisms; it cannot define every domain&#39;s success threshold.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Životni ciklus\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Owns the lifecycle of the specific workload.\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Owns shared capability versions, compatibility, onboarding, quotas, policy and operational contracts.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-10\">Najjednostavniji primer\u003C\u002Fh2>\n\u003Cp>Zamislite da organizacija ima pet AI proizvoda: internog asistenta za dokumente, kopilota za korisničku podršku, agenta za softverski inženjering, tok rada za pregled ugovora i asistenta za pretragu proizvoda. Svaki proizvod može nezavisno integrisati API-je modela, čuvati akreditive, implementirati ponovne pokušaje, prikupljati metrike tokena, kreirati kod za pretraživanje i graditi sopstvene dozvole za alate.\u003C\u002Fp>\n\u003Cp>To dupliranje je skupo i opasno kada svaki tim izmišlja drugačiji bezbednosni i operativni model. Zajednička platforma umesto toga može ponuditi odobrene veze sa dobavljačima, otkrivanje modela, kvote, akreditive, pristup svesan korisnika, zajedničku telemetriju, višekratno upotrebljive usluge pretraživanja i ugovor o izvršnom okruženju agenata\u002Falata.\u003C\u002Fp>\n\u003Cp>Ali platforma mora stati na pravoj granici. Rešenje za pregled ugovora može zahtevati nadležnost nad pravnim dokumentima i pravila citiranja koja softverski agent ne zahteva. Asistent za pretragu proizvoda može zahtevati pravila svežine i autorizacije specifična za trgovinu. \u003Cstrong>Višekratno upotrebljiva infrastruktura ne čini svu domensku istinu višekratno upotrebljivom.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Zajednička putanja AI zahteva\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. Potrošač se identifikuje\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Aplikacija koja poziva, korisnik, servis, tim ili korisnički kontekst ulazi kroz autentifikovani identitet i eksplicitni obim.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. Primenjuje se politika platforme\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Slojevi kapije i politike određuju dozvoljene dobavljače, modele, kvote, putanje podataka, alate i režime izvršavanja.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. Izvršava se zajednička mogućnost\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Zahtev može koristiti inferenciju, pretraživanje, izvršno okruženje agenata, pristup alatima ili drugu višekratno upotrebljivu uslugu platforme.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. Kontekst specifičan za rešenje ostaje merodavan\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Potrošačko rešenje obezbeđuje domenska pravila, nameru korisnika, nadležnost nad podacima, ograničenja specifična za zadatak i logiku prihvatanja.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. Beleže se telemetrija i dokazi\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Platforma beleži identitet, rutu, model\u002Fdobavljača, latenciju, trošak, greške, aktivnost alata i druge dozvoljene signale nadzora.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. Rezultat se vraća pod ugovorom rešenja\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Rešenje ostaje odgovorno za to da li je izlaz prihvatljiv za njegovog korisnika i domen.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-15\">Gde se jednostavan primer zaustavlja\u003C\u002Fh2>\n\u003Cp>Centralizacija nije automatski arhitektura. Jedna krajnja tačka ispred nekoliko API-ja modela je korisna, ali sama po sebi ne stvara AI platformu. Produkciona platforma takođe zahteva granice identiteta, ugovore o mogućnostima, upravljanje zdravljem i životnim ciklusom dobavljača, kvote, vlasništvo nad tajnama, nadzor, pravila kompatibilnosti, bezbednosne kontrole, disciplinu izdanja i jasnu operativnu odgovornost.\u003C\u002Fp>\n\u003Cp>Suprotan neuspeh je takođe čest: stavljanje svakog upita, vektorskog indeksa, poslovnog pravila, agenta i toka rada aplikacije u jedan „AI backend“. To stvara monolit čiji je zajednički status slučajan, a ne arhitektonski. \u003Cstrong>Platforma treba da standardizuje sveobuhvatne mogućnosti, a ne da preuzima domensko vlasništvo samo zato što je AI uključen.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch2 id=\"section-18\">Najvažnija odluka platforme: deljeno naspram specifičnog za rešenje\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Oblast sposobnosti\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Dobar kandidat za vlasništvo zajedničke platforme\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Obično ostaje specifično za rešenje\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Pristup modelu\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Odobrene veze sa provajderima, adapteri, akreditivi, zdravlje, primitivi rutiranja, kvote\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Prihvatanje modela specifično za zadatak, ponašanje upita, prag kvaliteta\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Pretraga\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Primitivi za unos, ekstrakcija, indeksiranje, API-ji za pretragu, ugovori o poreklu, kuke za autorizaciju\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Autoritativni korpus, pravila svežine, metapodaci domena, dovoljnost dokaza\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Agenti i alati\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Životni ciklus izvršavanja, registar\u002Fbroker alata, sprovođenje dozvola, praćenje, otkazivanje\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Poslovni tok rada, dozvoljena semantika akcija, politika eskalacije, uspeh zadatka\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Bezbednost\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Integracija identiteta, skladištenje tajni, sprovođenje politike, ugovori o reviziji, mehanizmi izolacije zakupaca\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Klasifikacija podataka, poslovna pravila autorizacije, prihvatanje rizika specifično za domen\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Evaluacija\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Okvir, mehanika skupova podataka\u002Fverzija, telemetrija, tok rada eksperimenta\u002Fizdanja\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Osnovna istina, domen test skup, prag prihvatanja, ishod korisnika\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Operacije\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Obrazac implementacije, zdravlje, metrike, integracija incidenata, kontrole kapaciteta\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">SLO-ovi rešenja gde se razlikuju, uticaj na kontinuitet poslovanja, runbook-ovi specifični za radno opterećenje\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Princip platforme\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">\u003Cstrong>Delite mehaniku i kontrole tamo gde je ponovna upotreba stvarna; zadržite autoritet i prihvatanje tamo gde ih domen poseduje.\u003C\u002Fstrong> Ovo sprečava dve suprotne greške: dupliranu infrastrukturu svuda i centralnu platformu koja lažno postaje vlasnik podataka, politike i kvaliteta svake aplikacije.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-21\">Mapa odgovornosti arhitekture\u003C\u002Fh2>\n\u003Ch3 id=\"section-22\">1. Pristup modelu i provajderu\u003C\u002Fh3>\n\u003Cp>Arhitekta platforme definiše kako potrošači otkrivaju i pozivaju modele bez prisiljavanja svake aplikacije da hardkodira jednog provajdera. Ovo uključuje adaptere provajdera, identifikatore modela, metapodatke o sposobnostima, autentifikaciju, provere zdravlja, konfiguraciju krajnjih tačaka, normalizaciju zahteva i ponašanje kompatibilnosti.\u003C\u002Fp>\n\u003Cp>Apstrakcija provajdera mora ostati iskrena. Različiti provajderi izlažu različita ograničenja konteksta, semantiku alata, ponašanje strukturiranog izlaza, multimodalne sposobnosti, sigurnosne kontrole, keširanje, cene i načine otkaza. Dobra apstrakcija stvara stabilan ugovor platforme dok čuva pristup sposobnostima koje se ne mogu smisleno spljoštiti.\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Ne mešajte apstrakciju sa pretvaranjem da su provajderi identični\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">API najnižeg zajedničkog imenioca može olakšati migraciju, ali može i izbrisati sposobnosti koje su važne. Arhitektura treba da definiše koje su funkcije prenosive, koje su specifične za provajdera i kako potrošači otkrivaju tu razliku.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch3 id=\"section-26\">2. Gejtvej, rutiranje, kvote i kontrole troškova\u003C\u002Fh3>\n\u003Cp>Zajednički AI gejtvej može centralizovati autentifikaciju, rutiranje, ograničavanje, ponovne pokušaje, ograničenja tokena, atribuciju upotrebe i sprovođenje politike. Microsoft-ove trenutne smernice za AI Gateway eksplicitno tretiraju ograničenja tokena u minuti, kvote i višeprojektno zadržavanje kao pitanja platforme; AWS takođe izlaže kvote naloga i modela i centralizovane kontrole.\u003C\u002Fp>\n\u003Cp>Gejtvej je stoga više od obrnutog proksija kada nosi AI-specifičnu politiku i operativnu semantiku. Ali ne bi trebalo tiho da donosi poslovne odluke. Politika rutiranja može preferirati zdrav lokalni model, jeftinijeg provajdera ili regionalno usklađenu krajnju tačku; da li je ta ruta prihvatljiva za određeni zadatak i dalje je ugovor između platforme i rešenja.\u003C\u002Fp>\n\u003Cp>Rutiranje takođe zahteva semantiku otkaza. Ako preferirani model nije dostupan, platforma mora znati da li je fallback dozvoljen, da li cloud ruta zahteva eksplicitnu saglasnost, da li je model nižih sposobnosti validan i kako se odluka prikazuje u observability-ju.\u003C\u002Fp>\n\u003Ch3 id=\"section-30\">3. Zajednički podaci, usluge pretrage i utemeljenja\u003C\u002Fh3>\n\u003Cp>Usluge pretrage su jaki kandidati za platformu jer su parsiranje, deljenje na delove, indeksiranje, leksička pretraga, semantička pretraga, filtriranje metapodataka, poreklo i mehanika citiranja ponovo upotrebljivi. Međutim, platforma ne sme da pobrka zajednički motor za pretragu sa zajedničkim izvorom istine.\u003C\u002Fp>\n\u003Cp>Rešenje i dalje poseduje pitanja kao što su: Koji korpus je autoritativan? Koja verzija je validna? Može li ovaj korisnik da vidi ovaj dokument? Koliko sveži podaci moraju biti? Šta se smatra dovoljnim dokazom? Može li se odgovor generisati kada pretraga ne uspe? To su zahtevi domena i rešenja čak i kada platforma obezbeđuje mehanizam pretrage.\u003C\u002Fp>\n\u003Cp>Ova granica je posebno važna u multi-tenant sistemima. Tehnički zajednički indeks ili vektorska usluga ne opravdava vidljivost između zakupaca. Kontekst autorizacije mora se sačuvati kroz pretragu, a ne dodavati tek nakon što su rezultati pretrage već prešli granicu.\u003C\u002Fp>\n\u003Ch3 id=\"section-34\">4. Vreme izvršavanja agenata i alata\u003C\u002Fh3>\n\u003Cp>Agentni sistemi dodaju ponovo upotrebljive brige o vremenu izvršavanja: životni ciklus niti\u002Fsesije, petlje planiranja, registracija alata, pozivanje alata, otkazivanje, vremenski limiti, ljudska odobrenja, interfejsi memorije\u002Fstanja, protokoli udaljenih agenata i korelacija tragova. Platforma može da obezbedi ovu mehaniku kako svaki proizvod ne bi ponovo gradio.\u003C\u002Fp>\n\u003Cp>Platforma takođe mora da drži dozvolu za alat odvojeno od sposobnosti modela. To što je model sposoban da generiše shell komandu ne znači da bi vreme izvršavanja trebalo da dozvoli izvršavanje shell-a. Granica dozvole pripada arhitekturi aplikacije\u002Fvremena izvršavanja i mora biti sprovodiva nezavisno od modela.\u003C\u002Fp>\n\u003Cp>Trenutne AWS smernice za agentnu AI naglašavaju ograničene agente, eksplicitna ovlašćenja, praćenje od početka do kraja, verzionisane artefakte ponašanja i ljudski nadzor srazmeran posledicama. To su pitanja koja omogućavaju platformu, ali rešenje koje je koristi i dalje definiše koje su radnje legitimne za njegov domen.\u003C\u002Fp>\n\u003Ch3 id=\"section-38\">5. Identitet, izolacija zakupaca i autorizacija\u003C\u002Fh3>\n\u003Cp>AI platforme često stoje ispred modela visoke vrednosti, vlasničkih podataka i alata sposobnih za radnje. Autentifikacija je zato samo početak. Arhitektura mora da nosi kontekst korisnika, servisa, aplikacije i zakupca kroz svaku privilegovanu operaciju kojoj je to potrebno.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>RBAC i izolacija zakupaca rešavaju različite probleme.\u003C\u002Fstrong> RBAC odgovara šta identitet sme da radi; izolacija zakupaca odgovara na čije resurse tog zakupca taj identitet sme da deluje. Platforma koja proverava uloge ali izgubi kontekst zakupca i dalje može da izloži pogrešne podatke.\u003C\u002Fp>\n\u003Cp>Microsoft-ove trenutne smernice za AI radna opterećenja eksplicitno preporučuju segmentaciju identiteta i pristup sadržaju svestan autorizacije. AWS-ove smernice za višezakupničku generativnu AI platformu takođe tretiraju logičku izolaciju, centralizovane kontrole i mogućnost revizije kao pitanja platforme.\u003C\u002Fp>\n\u003Ch3 id=\"section-42\">6. Tajne, akreditivi i granice poverenja\u003C\u002Fh3>\n\u003Cp>Platforma treba da definiše ko poseduje ključeve provajdera, udaljene bearer tokene, materijal za potpisivanje i akreditive alata, gde se čuvaju, koji proces im može pristupiti, kako se rotiraju i mogu li ikada stići do pregledača ili nepouzdanog renderera.\u003C\u002Fp>\n\u003Cp>Ovo je arhitektonska granica, a ne detalj implementacije. Ako svaka aplikacija koja koristi platformu kopira akreditive provajdera u sopstvenu konfiguraciju, organizacija je duplirala i operativni teret i domet štete. Centralizacija može smanjiti taj rizik samo ako sama platforma ima uže, proverljive pristupne putanje.\u003C\u002Fp>\n\u003Ch3 id=\"section-45\">7. Evaluacija, observabilnost i mogućnost revizije\u003C\u002Fh3>\n\u003Cp>Platforma koja se može ponovo koristiti može da obezbedi okvire za evaluaciju, ID-ove tragova, metapodatke modela\u002Fprovajdera, metrike tokena i troškova, latenciju, stope grešaka, povezivanje verzija upita\u002Fmodela, tragove agenata\u002Falata i kontrolisano evidentiranje. I AWS i Microsoft tretiraju observabilnost i evaluaciju kao ključna produkciona pitanja za AI radna opterećenja.\u003C\u002Fp>\n\u003Cp>Evaluacija platforme i evaluacija rešenja moraju ostati odvojene. Platforma može da potvrdi da je endpoint zdrav, da verzija modela prolazi opšti regresioni paket i da su tragovi potpuni. Ne može da odluči da su pravni odgovor, medicinski tok rada ili preporuka proizvoda prihvatljivi bez ground truth-a i kriterijuma prihvatanja specifičnih za domen.\u003C\u002Fp>\n\u003Cp>Evidentiranje takođe stvara granicu privatnosti. Dnevnici upita i odgovora mogu sadržati osetljive ili vlasničke podatke. Arhitekta platforme zato mora da odluči šta se evidentira, rediguje, uzorkuje, zadržava i čini dostupnim, umesto da pretpostavlja da je više telemetrije uvek bezbednije.\u003C\u002Fp>\n\u003Ch3 id=\"section-49\">8. Izvršno okruženje, raspoređivanje i lokalnost\u003C\u002Fh3>\n\u003Cp>Arhitekta platforme odlučuje kako se deljene AI sposobnosti raspoređuju i dohvataju: upravljani cloud servisi, samostalno hostovani endpointi, lokalna inferencija, hibridno rutiranje, kontejnerizovani servisi, desktop izvršna okruženja, privatno umrežavanje ili vazdušno izolovana okruženja. Važna razlika je između \u003Cstrong>toga gde se izvršava proces kontrole\u002Fizvršnog okruženja\u003C\u002Fstrong> i \u003Cstrong>toga gde se inferencija i obrada podataka zaista odvijaju\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>Lokalni klijent i dalje može da poziva cloud model. Cloud kontrolna ravan može da rutira ka on-premises modelu. Udaljeni agent može da izvršava alate unutar mreže korisnika. Arhitektonski dijagrami zato moraju da prikazuju granice poverenja i tokova podataka, umesto da koriste „lokalno“ i „cloud“ kao nejasne oznake.\u003C\u002Fp>\n\u003Ch3 id=\"section-52\">9. Životni ciklus platforme, kompatibilnost i onboarding\u003C\u002Fh3>\n\u003Cp>Sposobnost koja se može ponovo koristiti postaje platforma tek kada korisnici mogu dugoročno da se oslone na nju. To zahteva verzionisane ugovore, pravila migracije, politiku kompatibilnosti, ukidanje, testiranje izdanja, vraćanje na prethodnu verziju, vlasništvo nad incidentima, planiranje kapaciteta, dokumentaciju i put za uvođenje novih timova ili aplikacija.\u003C\u002Fp>\n\u003Cp>AI ekosistemi koji se brzo menjaju čine ovo posebno važnim. Imena modela, SDK-ovi, verzije protokola, API-ji provajdera i bezbednosne sposobnosti menjaju se nezavisno. Platforma mora da apsorbuje deo te volatilnosti bez skrivanja promena koje materijalno utiču na ponašanje rešenja.\u003C\u002Fp>\n\u003Ch2 id=\"section-55\">Praktični model kontrolne ravni \u002F izvršne ravni \u002F ravni rešenja\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Predloženi arhitektonski model\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Model sa tri ravni ispod je praktičan način da se razmišlja o odgovornostima; to nije ISO, NIST, Microsoft ili AWS standard. Njegova svrha je da učini granice vlasništva eksplicitnim.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Ravan\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Tipične odgovornosti\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Ne bi trebalo tiho da poseduje\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kontrolna ravan platforme\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Registar provajdera, politika modela, kvote, konfiguracija zakupca, identiteti, tajne, pravila rutiranja, verzije mogućnosti, konfiguracija implementacije\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Poslovna logika aplikacije ili istina domena\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Izvršna ravan \u002F ravan podataka platforme\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Zahtevi za inferenciju, operacije pretrage, izvršavanje agenata\u002Falata, ekstrakcija, indeksiranje, emitovanje telemetrije, sprovođenje politike\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Pristup između zakupaca samo zato što je infrastruktura deljena\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ravan rešenja\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Korisnički tok rada, uputstva\u002Finstrukcije, izbor autoritativnog korpusa, autorizacija domena, poslovna pravila, evaluacija zadataka i prihvatanje\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Integracija provajdera niskog nivoa koju platforma eksplicitno poseduje\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>Ovo razdvajanje pomaže u dijagnostikovanju odstupanja platforme. Ako aplikacija mora da zna svaki akreditiv i endpoint specifičan za provajdera, ugovor platforme je previše tanak. Ako platforma odlučuje koji je korisnički zapis pravno autoritativan ili da li je odgovor domena prihvatljiv, platforma je prešla u vlasništvo rešenja.\u003C\u002Fp>\n\u003Ch2 id=\"section-59\">Šta bi arhitekta AI platforme trebalo da proizvede?\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Arhitektonski artefakt\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Svrha\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Mapa mogućnosti platforme\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše šta platforma pruža, ko je koristi i koje mogućnosti ostaju van opsega.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ugovor provajdera\u002Fmodela\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše provajdere, modele, mogućnosti, granice apstrakcije, metapodatke ruta i semantiku rezervnih opcija.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Model identiteta i zakupništva\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše identitet korisnika\u002Fservisa\u002Faplikacije, kontekst zakupca, RBAC\u002FABAC kuke i izolaciju resursa.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Politika gejveja i kvota\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše ograničenja brzine, budžete tokena\u002Ftroškova, kontrole rutiranja, ponovne pokušaje i ponašanje kapaciteta.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ugovor o pretrazi\u002Fpodacima\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše unos, poreklo, pretragu, metapodatke, propagaciju autorizacije i gde autoritet domena ostaje.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ugovor o agentima\u002Falata\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše životni ciklus izvršavanja, registraciju alata, dozvole, odobrenja, otkazivanje i ponašanje praćenja.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Model tajni i granica poverenja\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše vlasništvo nad akreditivima, skladištenje, granice procesa, rotaciju i putanje osetljivih podataka.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ugovor o evaluaciji i telemetriji\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše zajedničke metrike, tragove, veze skupova podataka\u002Fverzija, politiku evidentiranja i tačke proširenja rešenja.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Politika životnog ciklusa i kompatibilnosti\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Definiše verzije, migracije, ukidanje, izdanja, vraćanje, vlasništvo nad incidentima i uvođenje.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-61\">Posao je uglavnom kompromis, a ne maksimalna centralizacija\u003C\u002Fh2>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Uobičajeni kompromisi platforme\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">Pritisak A\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">Pritisak B\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Apstrakcija provajdera\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Stable portable platform API\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Access to provider-specific capabilities and fast innovation\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Ponovna upotreba\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Shared services reduce duplication\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Isolation and domain autonomy prevent unsafe coupling\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Upravljanje\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Central policy and auditability\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Team speed and local experimentation\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Opservabilnost\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Rich traces for debugging and evaluation\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Privacy, data minimization and logging cost\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Dostupnost\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Fallback and multi-provider resilience\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Predictable quality, compliance and data-location guarantees\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">Opseg platforme\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">More reusable capabilities\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">Smaller blast radius and less platform lock-in\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-63\">Kako se ovo razlikuje od srodnih uloga?\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Uloga\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Primarni arhitektonski opseg\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Arhitekta AI rešenja\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Konkretno AI rešenje i njegovi zahtevi od početka do kraja, granice, kompromisi i prihvatanje u produkciji.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Arhitekta AI platforme\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Mogućnosti AI koje se mogu ponovo koristiti i operativni\u002Fbezbednosni ugovori koji se koriste u više rešenja ili timova.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Arhitekta preduzeća\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Portfolio poslovanja\u002Ftehnologije na nivou organizacije, usklađivanje mogućnosti i upravljanja na širem nivou.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MLOps \u002F LLMOps arhitekta ili specijalista\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Životni ciklus modela i AI, implementacija, eksperimenti, opservabilnost, izdanja i operativne prakse; može se snažno preklapati, ali ne poseduje automatski celu deljenu aplikativnu platformu.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Inženjer platforme \u002F SRE\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Implementira i upravlja infrastrukturom platforme, pouzdanošću, automatizacijom i iskustvom programera; odgovornost za arhitekturu može se deliti sa arhitektom platforme.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI \u002F softverski inženjer\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Implementira modele, integracije, servise, agente, pretragu i funkcionalnost proizvoda unutar dogovorene arhitekture.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>Ove granice su organizacione, a ne univerzalne. U malom timu jedna osoba može imati nekoliko odgovornosti. U regulisanom preduzeću mogu biti podeljene između grupa za arhitekturu, bezbednost, platformu, podatke i operacije. Korisna razlika je \u003Cstrong>opseg arhitektonske odgovornosti\u003C\u002Fstrong>, a ne naziv radnog mesta na organizacionoj šemi.\u003C\u002Fp>\n\u003Ch2 id=\"section-66\">Dokaz implementacije: kako se ove granice platforme pojavljuju u mom radu\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Dokaz originalne implementacije\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Sledeći odeljci opisuju konkretne obrasce iz mojih projekata. Oni su dokaz da su ove arhitektonske granice implementirane ili eksplicitno dizajnirane u stvarnom kodu i projektnim sistemima. Oni \u003Cstrong>nisu\u003C\u002Fstrong> tvrdnje da projekti zajedno već predstavljaju komercijalno implementiranu enterprise AI platformu.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch3 id=\"section-68\">Aaasaasa AI Client: razdvajanje provajdera, izvršnog okruženja i dozvola\u003C\u002Fh3>\n\u003Cp>Aaasaasa AI Client je lokalno-prvenstveni desktop AI radni prostor izgrađen sa Nuxt 4, Electron i TypeScript. Njegov AI Hub namerno razdvaja \u003Cstrong>agenta\u002Fklijenta, provajdera, model, lokaciju veze\u002Fizvršnog okruženja, dozvole i web klijenta\u003C\u002Fstrong> umesto da ih tretira kao jednu konfiguracionu vrednost.\u003C\u002Fp>\n\u003Cp>Implementacija uključuje direktne adaptere provajdera, integraciju Codex agent izvršnog okruženja, lokalne Ollama\u002FLM Studio putanje, servise kompatibilne sa OpenAI, centralizovane dozvole radnog prostora, skladištenje akreditiva u glavnom procesu, DuckDB, Qdrant\u002Fvektorsku podršku, PDF\u002Freadability ekstrakciju i autentifikovani pristup direktorijumu zasnovan na MCP.\u003C\u002Fp>\n\u003Cp>Dve lekcije o platformi su posebno relevantne. Prvo, lokalno izvršno okruženje nije isto kao lokalna inferencija: lokalni Codex proces i dalje može koristiti cloud model. Drugo, automatsko rutiranje ne prelazi tiho sa lokalne na plaćenu cloud inferenciju. To čini politiku rutiranja i lokalnost izvršnog okruženja eksplicitnim, a ne izvedenim iz UI oznaka.\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Implementirana granica\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Značenje za arhitekturu platforme\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Agent vs provajder vs model\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Različite odgovornosti mogu se razvijati nezavisno umesto da budu skrivene iza jednog „AI“ selektora.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Dozvole odvojene od modela\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Autoritet nad fajl sistemom\u002Falatom pripada politici izvršnog okruženja, a ne mogućnostima modela.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Tajne u glavnom procesu\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Vlasništvo nad akreditivima prati granicu privilegovanog procesa, a ne renderer\u002FUI.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Zdravlje provajdera i otkrivanje modela\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Rutiranje i dostupnost su pitanja izvršnog okruženja\u002Fplatforme.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Nema tihog cloud fallback-a\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Troškovi, lokalnost i semantika prenosa podataka ostaju eksplicitne političke odluke.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch3 id=\"section-73\">Aaasaasa AI CMS: autorizacija ograničena na tenanta kao granica platforme\u003C\u002Fh3>\n\u003Cp>Kodna baza Aaasaasa AI CMS pruža poseban primer implementacije: RBAC ograničen na tenanta predstavljen je kroz uloge, dozvole i dodele korisničkih uloga vezane za identifikator tenanta. Sistemske dozvole su grupisane po sposobnostima, a pretraga i ažuriranje uloga ostaju ograničeni na tenanta.\u003C\u002Fp>\n\u003Cp>Ovo samo po sebi nije dokaz kompletne AI platforme, ali je direktno relevantno za jednu od najtežih granica deljene platforme: usluga koja se može ponovo koristiti mora da očuva \u003Cstrong>ko sme šta da radi\u003C\u002Fstrong> i \u003Cstrong>za kog tenanta\u003C\u002Fstrong>. Dodavanje AI inferencije ili pretrage na vrhu aplikativne platforme ne uklanja taj zahtev.\u003C\u002Fp>\n\u003Cp>Arhitektonska implikacija je da bi model gateway-i, servisi za pretragu i agenti trebalo da koriste uspostavljeni identitetski\u002Ftenant kontekst umesto da izmišljaju paralelni univerzum autorizacije samo za AI.\u003C\u002Fp>\n\u003Ch3 id=\"section-77\">Source of Truth Research Engine: deljeni mehanizmi pretrage bez deljene istine\u003C\u002Fh3>\n\u003Cp>Source of Truth Research Engine pruža treći primer implementacije. Različiti režimi istraživanja dele zajedničko jezgro dokaza: Sources, Artifacts, provenance, Claims, Relations, Contradictions, Reference Model i revizorski trag. Sistem takođe pruža lokalnu leksičku pretragu, opcionu semantičku pretragu, ekstrakciju, snimke i provenance zasnovan na SHA-256.\u003C\u002Fp>\n\u003Cp>Projekat eksplicitno tretira pretragu i semantičku sličnost kao signale za otkrivanje, a ne kao dokaze. Rezultat mora biti ušančen nazad do konkretnog izvora i lokatora pre nego što može da podrži tvrdnju. Upravo to je razlika koja je potrebna AI platformi: \u003Cstrong>mehanizmi pretrage koji se mogu ponovo koristiti mogu biti deljeni dok autoritet dokaza ostaje vođen metodologijom koja ih koristi i domenom.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Engine takođe pokazuje zašto jedna deljena platforma ne zahteva jedno deljeno tumačenje. Istorijski, naučno-tehnički, režimi tržišne inteligencije i monitoringa mogu ponovo koristiti osnovnu infrastrukturu dokaza dok zadržavaju metodologiju specifičnu za režim.\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">Šta ove implementacije zajedno pokazuju\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Kroz ove projekte, obrazac koji se može ponovo koristiti nije „jedan backend za sve“. To je \u003Cstrong>razdvajanje odgovornosti plus eksplicitni ugovori\u003C\u002Fstrong>: razdvajanje provajdera\u002Fmodela\u002Fruntime-a, autorizacija svesna tenanta, granice akreditiva, primitivi za podatke\u002Fpretragu koji se mogu ponovo koristiti, provenance i autoritet specifičan za domen. Buduća integrisana platforma bi zahtevala stabilne ugovore između tih sposobnosti umesto direktnog povezivanja između kodnih baza.\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-82\">Kako trenutne arhitektonske smernice podržavaju ovaj obim platforme\u003C\u002Fh2>\n\u003Cp>ISO\u002FIEC\u002FIEEE 42010:2022 pruža opštu disciplinu za opise arhitekture kroz softver, sisteme, preduzeća i povezane entitete. Ne definiše AI Platform Architect, ali pojačava potrebu da se izraze arhitektonske brige, odnosi i stanovišta umesto da se arhitektura svede na listu tehnologija.\u003C\u002Fp>\n\u003Cp>NIST AI RMF 1.0 i Generative AI Profile uokviruju upravljanje AI rizikom kroz životni ciklus, a ne samo u trenutku izbora modela. Upravljanje, mapiranje, merenje i upravljanje su stoga kompatibilni sa arhitekturom platforme koja nosi deljene kontrole i dokaze kroz mnoge radne opterećenja koja ih koriste.\u003C\u002Fp>\n\u003Cp>Microsoft-ove trenutne smernice za AI radna opterećenja tretiraju dizajn aplikacije, podatke, bezbednost, operacije, testiranje\u002Fevaluaciju i GenAIOps kao povezane arhitektonske oblasti. Njegove trenutne smernice za AI Gateway takođe pokazuju praktične brige platforme kao što su centralizovani pristup modelima, ograničenja tokena specifična za projekat, kvote i zadržavanje više timova.\u003C\u002Fp>\n\u003Cp>AWS-ov trenutni Generative AI Lens i scenario platforme sa više zakupaca na sličan način razdvajaju temeljne kontrole platforme od vlasništva aplikacije koja ih koristi. AWS eksplicitno napominje da centralna platforma može da sprovodi deljene zaštitne mere i revizibilnost dok kvalitet podataka i observabilnost specifična za radno opterećenje i dalje ostaju odgovornost aplikacija koje ih koriste ili proizvođača podataka.\u003C\u002Fp>\n\u003Cp>Proizvodi dobavljača se razlikuju, ali obrazac između izvora je stabilan: produkcijske AI platforme moraju da koordiniraju identitet, pristup podacima, modele, politiku, evaluaciju, observabilnost, kapacitet, troškove i životni ciklus. GPU klaster ili endpoint modela pokriva samo deo te odgovornosti.\u003C\u002Fp>\n\u003Ch2 id=\"section-88\">Uobičajene zablude\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Zabluda\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Zašto je pogrešna\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„AI platforma je GPU klaster.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Računanje je jedan supstrat. Platforma takođe zahteva ugovore za identitet, pristup modelima, podatke, politiku, evaluaciju, observabilnost i životni ciklus.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„AI gateway je samo reverse proxy.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Može takođe da nosi rutiranje modela, kvote tokena, atribuciju troškova, sprovođenje politike, identitet i telemetriju specifičnu za AI.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Deljeno znači globalno deljeno.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Usluga može biti fizički deljena dok je logički segmentirana po zakupcu, aplikaciji, regionu, klasifikaciji ili nivou rizika.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Jedna centralna vektorska baza podataka postaje istina kompanije.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Vektorsko skladište ili servis za pretragu je infrastruktura. Autoritet domena, svežina, provenance i pristup ostaju odvojene brige.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Evaluacija platforme zamenjuje evaluaciju rešenja.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Opšta regresija i telemetrija ne mogu da definišu da li je odgovor ili akcija specifična za domen prihvatljiva.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„Apstrakcija provajdera treba da sakrije svaku razliku.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Neke razlike su materijalne sposobnosti, bezbednosne semantike ili načini otkaza i moraju ostati vidljive.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„RBAC rešava multi-tenancy.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">RBAC kontroliše akcije; izolacija zakupaca kontroliše granice resursa. Oba mogu biti potrebna.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">„AI Platform Architect je samo drugo ime za MLOps.“\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">MLOps\u002FLLMOps je glavna disciplina koja se preklapa, ali deljena aplikacija\u002Fruntime, identitet, gateway, pretraga i granice alata mogu se protezati izvan operacija životnog ciklusa modela.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-90\">Načini otkaza koje AI Platform Architect treba da spreči\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Način neuspeha\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Arhitektonska posledica\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Svaki tim čuva sopstvene ključeve provajdera\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Duplirano rukovanje tajnama, nedosledna rotacija i veći radijus eksplozije.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Apstrakcija provajdera skriva potrebne mogućnosti\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Potrošači ne mogu da koriste funkcije koje su im potrebne ili tiho dobijaju ponašanje različito od pretpostavki.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Deljeni retrieval ignoriše kontekst tenanta\u002Fkorisnika\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Može doći do curenja podataka preko granica pre nego što aplikacija dobije priliku da filtrira rezultate.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Fallback tiho menja provajdera ili lokaciju\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Troškovi, usklađenost, lokacija podataka i kvalitet izlaza mogu se promeniti bez znanja pozivaoca.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Alati agenta se dodeljuju izborom modela\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Sposoban model postaje prekomerno privilegovan jer se autoritet u vreme izvršavanja ne sprovodi nezavisno.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Svi promptovi\u002Fodgovori se podrazumevano loguju\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Observability može stvoriti novi repozitorijum osetljivih podataka i problem usklađenosti.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Platforma poseduje jedan generički skor kvaliteta\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Domen-specifični neuspesi ostaju skriveni iza platformskih metrika zdravlja.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Nema ugovora o verzijama za platformske mogućnosti\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Promene modela\u002Fprovajdera\u002Fruntime-a nepredvidivo kvare potrošače.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Sve što je povezano sa AI je centralizovano\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Platforma postaje usko grlo i monolit umesto sloja za ponovnu upotrebu.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-92\">Praktičan sled odluka o arhitekturi platforme\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Od potrebe platforme do operativne deljene mogućnosti\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. Identifikujte stvarne potrošače\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Navedite rešenja, timove, tenante i radna opterećenja koji bi koristili platformu; izbegnite izgradnju platforme za hipotetičku ponovnu upotrebu.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. Definišite deljenu granicu\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Odvojite mehanizme koji seku kroz više oblasti od domen-specifičnog autoriteta, toka rada i prihvatanja rešenja.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. Prvo definišite identitet i izolaciju\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Uspostavite korisnike, servise, aplikacije, tenante, regione i klasifikacije podataka pre deljenja retrieval ili tool mogućnosti.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. Definišite ugovore o mogućnostima\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Specifikujte API-je za model\u002Fprovajdera, retrieval, agente\u002Falate, gateway i telemetriju sa eksplicitnim vlasništvom i verzionisanjem.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. Odlučite o strategiji provajdera i runtime-a\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Izaberite managed, self-hosted, lokalno ili hibridno izvršavanje i dokumentujte fallback, lokaciju i semantiku mogućnosti.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. Dizajnirajte granice podataka i retrieval-a\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Definišite poreklo, propagaciju autorizacije, vlasništvo nad korpusom, indeksiranje i odgovornosti za dokaze.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. Dodajte kvote, tajne i politiku\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Kontrolišite troškove, kapacitet, akreditive, dozvole za alate, bezbednosne kontrole i radijus eksplozije.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. Izgradite ugovore za evaluaciju i observability\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Obezbedite platformske metrike i tracing, dok domen-specifičnu osnovnu istinu i prihvatanje ostavljate rešenju.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">9\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">9. Definišite životni ciklus i operacije\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Verzionišite mogućnosti, testirajte nadogradnje, dokumentujte ukidanje, rollback, incidente, kapacitet i onboarding potrošača.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">10\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">10. Validirajte sa više od jednog potrošača\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">Tvrdnja o platformi postaje kredibilna kada deljena mogućnost zaista služi različitim radnim opterećenjima bez prisiljavanja na isti domen model.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-94\">Rubni slučajevi i ograničenja uloge\u003C\u002Fh2>\n\u003Cp>Mala organizacija sa jednom AI aplikacijom možda neće imati potrebu za posebnom AI platformom ili platform arhitektom. Prevremeno platformisanje može stvoriti više apstrakcije nego vrednosti. Ispravna arhitektura može biti jedno dobro dizajnirano rešenje sa nekoliko modula za ponovnu upotrebu.\u003C\u002Fp>\n\u003Cp>Air-gapped ili suvereno postavljanje značajno menja model provajdera, ažuriranja i observability. Hostovanje modela, distribucija artefakata, integracija identiteta i izvoz telemetrije mogu zahtevati lokalne ekvivalente.\u003C\u002Fp>\n\u003Cp>Visoko regulisana ili radna opterećenja sa velikim posledicama mogu zahtevati jaču fizičku ili organizacionu izolaciju umesto logički deljene platforme. Ponovna upotreba nikada nije dovoljan razlog da se oslabi zahtevana bezbednosna granica.\u003C\u002Fp>\n\u003Cp>Managed cloud AI servisi mogu ukloniti teret implementacije, ali ne uklanjaju arhitektonsku odgovornost. Organizacija i dalje odlučuje o identitetu, pristupu podacima, logovanju, zadržavanju, kvotama, podobnosti modela, fallback-u, evaluaciji i prihvatanju rešenja.\u003C\u002Fp>\n\u003Cp>Granica platforme može se razlikovati i po modalitetu. Tekstualna inferencija, multimodalna generacija, govor, korišćenje računara i autonomni agenti mogu imati različite zahteve za latenciju, podatke, dozvole i observability čak i kada dele infrastrukturu provajdera i identiteta.\u003C\u002Fp>\n\u003Ch2 id=\"section-100\">Šta bi promenilo ovaj odgovor?\u003C\u002Fh2>\n\u003Cp>Osnovna definicija bi se promenila ako se promeni organizacioni obim. Ako arhitekta poseduje jedno radno opterećenje, uloga postaje bliža AI Solution Architect. Ako se odgovornost proširi na strategiju sposobnosti na nivou organizacije, investicije, standarde i portfolije ciljnog stanja, pomera se ka Enterprise AI Architecture.\u003C\u002Fp>\n\u003Cp>Smernice za implementaciju se menjaju kad god se promene provajderi, gateway proizvodi, protokoli agenata, regulatorne obaveze, mogućnosti modela ili ograničenja postavljanja. Zato arhitektura platforme treba da izražava stabilne odgovornosti i ugovore odvojeno od trenutnih mehanizama dobavljača.\u003C\u002Fp>\n\u003Ch2 id=\"section-103\">Kontrolna lista AI Platform Arhitekte\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Pitanje\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">Očekivani odgovor\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ko su stvarni potrošači platforme?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Imenovana rešenja, timovi ili konteksti tenanta sa različitim ali preklapajućim potrebama.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šta je zaista deljeno?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Eksplicitna lista mogućnosti, a ne nejasan „AI backend“.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Šta mora ostati specifično za rešenje?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Autoritet domena, poslovni tok rada, prihvatanje zadataka i druge brige koje pripadaju radnom opterećenju.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako su modeli\u002Fprovajderi predstavljeni?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Verzionisani ugovori provajdera\u002Fmodela sa mogućnostima i eksplicitnom semantikom fallback-a.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se identitet propagira?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kontekst korisnika\u002Fservisa\u002Faplikacije\u002Ftenanta preživljava svaku privilegovanu putanju zahteva.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se sprovodi izolacija tenanta?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Ograničavanje resursa je odvojeno od provera dozvola uloga.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se rukuje tajnama?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Privilegovano skladištenje, rotacija, ograničeno izlaganje i revizorsko vlasništvo.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako retrieval čuva autoritet?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Deljeni mehanizmi sa autorizacijom, poreklom i pravilima dokaza u vlasništvu domena.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako su alati i agenti ograničeni?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Dozvole u vreme izvršavanja, ograničeni ugovori alata, odobrenja, otkazivanje i sledljivost.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se kontrolišu troškovi i kapacitet?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kvote, kontrole tokena\u002Fbrzine, atribucija upotrebe i ponašanje pri preopterećenju.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se meri kvalitet?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Platformska regresija\u002Fevaluacija plus osnovna istina i prihvatanje specifično za rešenje.\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Kako se uvode promene?\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Verzionisanje, kompatibilnost, migracija, ukidanje, rollback i vlasništvo nad incidentima.\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-105\">Zaključak\u003C\u002Fh2>\n\u003Cp>AI Platform Arhitekta je odgovoran za arhitekturu za ponovnu upotrebu \u003Cstrong>između AI mogućnosti i rešenja koja ih koriste\u003C\u002Fstrong>. Uloga definiše kako modeli, provajderi, retrieval, agenti, alati, identitet, tenanti, tajne, evaluacija, observability, kvote i runtime operacije postaju pouzdani platformski servisi umesto ponovljenih jednokratnih integracija.\u003C\u002Fp>\n\u003Cp>Težak deo nije maksimiziranje ponovne upotrebe. To je izbor ispravne granice. Jaka platforma standardizuje mehanizme, politiku i operacije tamo gde više potrošača zaista ima koristi, dok čuva autoritet nad podacima specifičan za rešenje, poslovnu logiku, bezbednosne zahteve i kriterijume prihvatanja.\u003C\u002Fp>\n\u003Cp>Ta razlika takođe objašnjava odnos sa AI Solution Architecture: \u003Cstrong>solution arhitekta čini da jedan AI-omogućen sistem odgovara svojoj svrsi; platform arhitekta čini da deljene AI mogućnosti budu bezbedne, ponovo upotrebljive, operativne i evolutivne kroz mnoge takve sisteme.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Ch2 id=\"section-109\">Povezano kanonsko znanje\u003C\u002Fh2>\n\u003Cp>Ovaj članak se nadovezuje na kanonske osnove o komponentama generativne AI, ADR naspram NFR i AI Solution Architecture. Ti koncepti su preduslovi jer platforma postoji da bi pružala višekratno upotrebljive sistemske mogućnosti i kodifikovala arhitekturne odluke u skladu sa eksplicitnim zahtevima kvaliteta i operativnim zahtevima.\u003C\u002Fp>\n\u003Cp>Retrieval-Augmented Generation je jedan primer mogućnosti koja se može ponuditi kroz platformu, ali platforma ne bi trebalo da sažme infrastrukturu za pretragu, domensko znanje i validnost odgovora u jedan koncept.\u003C\u002Fp>\n\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fsr\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Šta je RAG? Najjednostavnije objašnjenje kako funkcioniše\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Kanonski uvod u retrieval-augmented generation i granicu između generisanja modela i eksternog pronalaženja znanja.\u003C\u002Fp>\u003C\u002Fa>\n\u003Cp>Agent protokoli, izolacija zakupaca, AI upravljanje, rutiranje modela, Context Engineering i MLOps\u002FLLMOps su nizvodni ili susedni čvorovi znanja. Oni postaju lakši za razumevanje kada je granica platforme eksplicitna.\u003C\u002Fp>\n\u003Ch2 id=\"section-114\">Često postavljana pitanja\u003C\u002Fh2>\n\u003Csection class=\"editorjs-faq my-6 rounded-xl border border-gray-200 p-5 dark:border-gray-700\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">AI Platform Architect FAQ\u003C\u002Fh3>\u003Cdiv id=\"faq-1\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li je AI Platform Architect isto što i AI Solution Architect?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Ne. Solution arhitekta se fokusira na jedno konkretno AI rešenje. Platform arhitekta se fokusira na višekratno upotrebljive AI mogućnosti, kontrole i operativne ugovore koji mogu podržati više rešenja.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq-2\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li AI platforma treba da hostuje sopstvene modele?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Ne. Platforma može koristiti upravljane cloud modele, samostalno hostovane modele, lokalnu inferenciju ili hibridnu strategiju. Arhitektura mora učiniti eksplicitnim posledice po provajdera, lokaciju, identitet, rutiranje, podatke i operacije.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq-3\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li je AI gateway dovoljan da bude AI platforma?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Obično ne. Gateway može biti važna komponenta platforme, ali kompletna platforma takođe zahteva ugovore za identitet, tajne, podatke\u002Fpretragu, evaluaciju, observabilnost, životni ciklus i operativno vlasništvo.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq-4\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li pretragu treba centralizovati?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Mehanika pretrage se često može deliti, ali autoritet domena, autorizacija, svežina, dovoljnost dokaza i vlasništvo nad korpusom treba da ostanu eksplicitni. Deljena infrastruktura ne podrazumeva deljenu istinu.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq-5\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li evaluacija platforme zamenjuje evaluaciju aplikacije?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Ne. Evaluacija platforme može testirati deljene mogućnosti i regresije. Svako rešenje i dalje zahteva ground truth specifičan za zadatak, kriterijume prihvatanja i domenske pragove kvaliteta.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq-6\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">Da li je multi-tenancy samo RBAC?\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">Ne. RBAC određuje šta identitet može da radi. Izolacija zakupaca određuje na resurse kog zakupca identitet može da deluje. Platforma često zahteva oboje.\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-116\">Pojmovnik\u003C\u002Fh2>\n\u003Csection class=\"editorjs-glossary my-6 rounded-xl border border-gray-200 dark:border-gray-700 p-5\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">Ključni pojmovi arhitekture AI platforme\u003C\u002Fh3>\u003Cdl>\u003Cdiv id=\"ai-platform\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">AI platforma\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Višekratno upotrebljiv skup AI-related tehničkih i operativnih mogućnosti koje koristi više aplikacija, timova ili konteksta zakupaca.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"ai-gateway\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">AI gateway\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Gateway sloj za AI endpoint-e koji može dodati autentifikaciju, rutiranje, kvote, politiku, ponovne pokušaje, atribuciju troškova i AI-specifičnu telemetriju iznad osnovnog proxy-ja.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"provider-adapter\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Provider adapter\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Komponenta koja mapira ugovor platforme na API, mogućnosti, zdravlje i semantiku otkaza provajdera modela.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"tenant-isolation\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Izolacija zakupaca\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Granica koja sprečava jedan kontekst zakupca da pristupi resursima drugog zakupca, nezavisno od dozvola uloga.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"capability-contract\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Ugovor o mogućnosti\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Verzionisani interfejs i sporazum o ponašanju koji opisuje šta deljena usluga platforme pruža i šta potrošač mora da obezbedi ili poseduje.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"grounding-service\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Grounding \u002F retrieval servis\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Deljena mehanika za pronalaženje i snabdevanje AI radnog opterećenja eksternim informacijama; ne definiše automatski koje informacije su autoritativne za domen.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"evaluation-harness\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Evaluation harness\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Višekratno upotrebljiva infrastruktura za pokretanje testova, skupova podataka, verzija modela\u002Fprompt-ova i metrika; domensko prihvatanje ostaje specifično za rešenje.\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"control-plane\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">Control plane\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">Sloj konfiguracije i upravljanja koji upravlja mogućnostima platforme, identitetima, politikama, kvotama, verzijama i stanjem implementacije.\u003C\u002Fdd>\u003C\u002Fdiv>\u003C\u002Fdl>\u003C\u002Fsection>\n\u003Ch2 id=\"section-118\">Primarni izvori i aktuelne smernice arhitekture\u003C\u002Fh2>\n\u003Cp>Izvori ispod podržavaju opšte tvrdnje o arhitekturi i produkcijskoj platformi. Sekcije Aaasaasa AI Client, Aaasaasa AI CMS i Source of Truth Research Engine su eksplicitno originalni dokazi implementacije. Eksterni izvori o trenutnom stanju provereni su 8. oktobra 2026.\u003C\u002Fp>\n\u003Ca href=\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">ISO\u002FIEC\u002FIEEE 42010:2022 — Opis arhitekture\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelni objavljeni međunarodni standard za koncepte i odnose opisa arhitekture.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST AI Risk Management Framework\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">NIST AI RMF resursi i trenutni status; AI RMF 1.0 je u reviziji od oktobra 2026.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST AI 600-1 — Generative AI Profile\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Generative AI profil za primenu razmatranja upravljanja AI rizikom kroz životni ciklus AI.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft Azure Well-Architected — AI Workloads\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelne arhitekturne smernice koje pokrivaju AI aplikaciju, podatke, operacije, evaluaciju, odgovornu AI i pitanja životnog ciklusa.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fdesign-principles\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft — Design Principles for AI Workloads\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelne smernice o segmentaciji identiteta, bezbednosnim granicama, telemetriji, performansama, podacima i kompromisima platforme.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fai-foundry\u002Fconfiguration\u002Fenable-ai-api-management-gateway-portal?view=foundry\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Microsoft Foundry — AI Gateway Architecture\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelne smernice za AI Gateway za deljeni pristup projektu, ograničavanje tokena, kvote i upravljanje.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Farchitecture\u002Fai-ml\u002Fguide\u002Fazure-openai-gateway-guide\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Azure Architecture Center — Access Models Through a Gateway\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Arhitekturne smernice za centralizovan pristup modelima, rutiranje, ograničavanje, failover i odgovornosti klijenta\u002Fplatforme.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fgenerative-ai-lens\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">AWS Well-Architected — Objektiv za generativnu veštačku inteligenciju\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelne smernice za produkcionu arhitekturu za radna opterećenja generativne veštačke inteligencije u pogledu bezbednosti, pouzdanosti, operacija, performansi i troškova.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fgenerative-ai-lens\u002Fmulti-tenant-generative-ai-platform-scenario.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">AWS — Scenario višekorisničke platforme za generativnu veštačku inteligenciju\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelni primer koji razdvaja centralne kontrole platforme i mogućnost revizije od kvaliteta podataka aplikacija koje ih koriste i odgovornosti specifičnih za radno opterećenje.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fagentic-ai-lens\u002Fdesign-principles.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">AWS Well-Architected — Principi dizajna agentske veštačke inteligencije\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelne smernice o ograničenom ovlašćenju agenata, sledljivosti, verzionisanom ponašanju, eksplicitnim ugovorima i ljudskom nadzoru.\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdocs.aws.amazon.com\u002FAmazonCloudWatch\u002Flatest\u002Fmonitoring\u002FGenAI-observability.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">AWS CloudWatch — Nadzor generativne veštačke inteligencije\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">Aktuelne mogućnosti nadzora i produkcione metrike za modele, agente, baze znanja, alate i analizu troškova\u002Flatencije\u002Fgrešaka.\u003C\u002Fp>\u003C\u002Fa>",{"time":212,"blocks":213,"version":1201},1791477417804,[214,219,226,232,237,244,248,252,256,300,304,308,312,316,341,345,349,353,357,388,394,398,402,406,410,416,420,424,428,432,436,440,444,448,452,456,460,464,468,472,476,480,484,488,492,496,500,504,508,512,516,520,524,528,532,536,541,561,565,569,603,607,655,659,682,686,690,695,699,703,707,711,733,737,741,745,749,753,757,761,765,770,774,778,782,786,790,794,798,829,833,867,871,906,910,914,918,922,926,930,934,938,942,946,989,993,997,1001,1005,1009,1013,1017,1027,1031,1035,1064,1068,1105,1109,1113,1121,1129,1137,1145,1153,1161,1169,1177,1185,1193],{"id":215,"data":216,"type":218},"intro",{"text":217},"\u003Cstrong>Arhitekta AI platforme\u003C\u002Fstrong> projektuje višekratno upotrebljivu AI osnovu preko koje više aplikacija, timova ili korisničkih konteksta pristupa modelima, podacima i pretraživanju, izvršnim okruženjima agenata i alata, identitetu i dozvolama, evaluaciji, nadzoru, kvotama, tajnama i mogućnostima za implementaciju. Uloga je šira od infrastrukture, ali uža od vlasništva nad svakim AI proizvodom: njena centralna odgovornost je da odluči \u003Cstrong>šta treba deliti, kako se deljene mogućnosti upravljaju i izoluju, i šta mora ostati specifično za rešenje\u003C\u002Fstrong>.","paragraph",{"id":220,"data":221,"type":225},"direct",{"body":222,"title":223,"variant":224},"\u003Cstrong>Arhitekta AI platforme projektuje zajednički tehnički i operativni sloj za AI sisteme.\u003C\u002Fstrong> Umesto projektovanja jednog asistenta ili jednog toka rada, uloga definiše višekratno upotrebljive ugovore i granice za pristup modelima\u002Fdobavljačima, kapije i rutiranje, usluge pretraživanja, izvršna okruženja agenata, pristup alatima, identitet i izolaciju korisnika, tajne, evaluaciju, telemetriju, implementaciju i upravljanje životnim ciklusom.","Direktan odgovor","info","callout",{"id":227,"data":228,"type":225},"term-note",{"body":229,"title":230,"variant":231},"\u003Cstrong>Arhitekta AI platforme je praktična oznaka uloge, a ne univerzalno standardizovan naziv radnog mesta.\u003C\u002Fstrong> ISO\u002FIEC\u002FIEEE 42010:2022 definiše koncepte za opise arhitekture, a ne ovu ulogu. Različite organizacije mogu podeliti ove odgovornosti između arhitekata platforme, arhitekata rešenja, arhitekata preduzeća, bezbednosnih arhitekata, MLOps\u002FLLMOps specijalista i timova za inženjering platforme. Ovaj članak koristi termin za arhitektonsku odgovornost nad višekratno upotrebljivim slojem AI platforme.","Napomena o terminologiji","note",{"id":233,"data":234,"type":225},"version-note",{"body":235,"title":236,"variant":231},"Stabilni arhitektonski principi ovde su neutralni u pogledu dobavljača. Aktuelne Microsoft, AWS i NIST smernice koriste se kao spoljni dokaz o implementaciji i upravljanju. NIST navodi da se AI RMF 1.0 revidira; funkcije platforme dobavljača, proizvodi kapija, izvršna okruženja agenata i mogućnosti modela razvijaju se brže od arhitektonskih principa, pa se izbori implementacije osetljivi na verziju moraju ponovo proveriti pre implementacije.","Napomena o aktuelnim izvorima — 8. oktobar 2026.",{"id":238,"data":239,"type":243},"toc",{"title":240,"maxLevel":241,"minLevel":242},"Sadržaj",3,2,"tableOfContents",{"id":245,"data":246,"type":42},"h-meaning",{"text":247,"level":242},"Šta Arhitekta AI platforme zapravo projektuje?",{"id":249,"data":250,"type":218},"p-meaning-1",{"text":251},"Predmet rada je \u003Cstrong>platforma\u003C\u002Fstrong>: skup zajedničkih mogućnosti koje smanjuju ponovljeni rad na integraciji uz očuvanje eksplicitnih bezbednosnih, podatkovnih i operativnih granica. Platforma može izložiti pristup modelima, adaptere dobavljača, primitive pretraživanja, izvršavanje agenata, brokere alata, sprovođenje politika, evaluaciju, telemetriju i usluge implementacije mnogim potrošačkim rešenjima.",{"id":253,"data":254,"type":218},"p-meaning-2",{"text":255},"Platforma nije vredna samo zato što su komponente centralizovane. Vredna je kada potrošači dobijaju stabilne mogućnosti sa jasnim ugovorima, vlasništvom, izolacijom, nadzorom i pravilima životnog ciklusa. Ključno arhitektonsko pitanje stoga nije „Koji model treba svi da koriste?“ već \u003Cstrong>„Koje se odgovornosti mogu bezbedno standardizovati i ponovo koristiti bez brisanja zahteva svakog rešenja?“\u003C\u002Fstrong>.",{"id":257,"data":258,"type":299},"solution-vs-platform",{"rows":259,"title":290,"layout":291,"columns":292},[260,266,272,278,284],{"id":261,"label":262,"values":263},"c1","Primarni obim",{"platform":264,"solution":265},"Reusable AI capabilities consumed by multiple solutions, teams or tenant contexts.","One concrete AI-enabled product, workflow or application.",{"id":267,"label":268,"values":269},"c2","Glavno pitanje",{"platform":270,"solution":271},"Which shared capabilities and controls should solutions consume, and where must solution-specific ownership remain?","How should this solution meet its business, data, security, quality and operational requirements?",{"id":273,"label":274,"values":275},"c3","Nadležnost nad podacima",{"platform":276,"solution":277},"Provides storage, retrieval, provenance or access primitives without automatically becoming the authority for every domain.","Defines which domain data is authoritative and how the solution may use it.",{"id":279,"label":280,"values":281},"c4","Evaluacija",{"platform":282,"solution":283},"Provides reusable evaluation, telemetry and release mechanisms; it cannot define every domain's success threshold.","Defines task-specific quality and acceptance criteria.",{"id":285,"label":286,"values":287},"c5","Životni ciklus",{"platform":288,"solution":289},"Owns shared capability versions, compatibility, onboarding, quotas, policy and operational contracts.","Owns the lifecycle of the specific workload.","Arhitektura rešenja i arhitektura platforme rešavaju različite probleme obima","table",[293,296],{"id":294,"label":295},"solution","Arhitekta AI rešenja",{"id":297,"label":298},"platform","Arhitekta AI platforme","comparison",{"id":301,"data":302,"type":42},"h-simple",{"text":303,"level":242},"Najjednostavniji primer",{"id":305,"data":306,"type":218},"p-simple-1",{"text":307},"Zamislite da organizacija ima pet AI proizvoda: internog asistenta za dokumente, kopilota za korisničku podršku, agenta za softverski inženjering, tok rada za pregled ugovora i asistenta za pretragu proizvoda. Svaki proizvod može nezavisno integrisati API-je modela, čuvati akreditive, implementirati ponovne pokušaje, prikupljati metrike tokena, kreirati kod za pretraživanje i graditi sopstvene dozvole za alate.",{"id":309,"data":310,"type":218},"p-simple-2",{"text":311},"To dupliranje je skupo i opasno kada svaki tim izmišlja drugačiji bezbednosni i operativni model. Zajednička platforma umesto toga može ponuditi odobrene veze sa dobavljačima, otkrivanje modela, kvote, akreditive, pristup svesan korisnika, zajedničku telemetriju, višekratno upotrebljive usluge pretraživanja i ugovor o izvršnom okruženju agenata\u002Falata.",{"id":313,"data":314,"type":218},"p-simple-3",{"text":315},"Ali platforma mora stati na pravoj granici. Rešenje za pregled ugovora može zahtevati nadležnost nad pravnim dokumentima i pravila citiranja koja softverski agent ne zahteva. Asistent za pretragu proizvoda može zahtevati pravila svežine i autorizacije specifična za trgovinu. \u003Cstrong>Višekratno upotrebljiva infrastruktura ne čini svu domensku istinu višekratno upotrebljivom.\u003C\u002Fstrong>",{"id":317,"data":318,"type":340},"simple-flow",{"steps":319,"title":338,"orientation":339},[320,323,326,329,332,335],{"label":321,"description":322},"1. Potrošač se identifikuje","Aplikacija koja poziva, korisnik, servis, tim ili korisnički kontekst ulazi kroz autentifikovani identitet i eksplicitni obim.",{"label":324,"description":325},"2. Primenjuje se politika platforme","Slojevi kapije i politike određuju dozvoljene dobavljače, modele, kvote, putanje podataka, alate i režime izvršavanja.",{"label":327,"description":328},"3. Izvršava se zajednička mogućnost","Zahtev može koristiti inferenciju, pretraživanje, izvršno okruženje agenata, pristup alatima ili drugu višekratno upotrebljivu uslugu platforme.",{"label":330,"description":331},"4. Kontekst specifičan za rešenje ostaje merodavan","Potrošačko rešenje obezbeđuje domenska pravila, nameru korisnika, nadležnost nad podacima, ograničenja specifična za zadatak i logiku prihvatanja.",{"label":333,"description":334},"5. Beleže se telemetrija i dokazi","Platforma beleži identitet, rutu, model\u002Fdobavljača, latenciju, trošak, greške, aktivnost alata i druge dozvoljene signale nadzora.",{"label":336,"description":337},"6. Rezultat se vraća pod ugovorom rešenja","Rešenje ostaje odgovorno za to da li je izlaz prihvatljiv za njegovog korisnika i domen.","Zajednička putanja AI zahteva","auto","processFlow",{"id":342,"data":343,"type":42},"h-stops",{"text":344,"level":242},"Gde se jednostavan primer zaustavlja",{"id":346,"data":347,"type":218},"p-stops-1",{"text":348},"Centralizacija nije automatski arhitektura. Jedna krajnja tačka ispred nekoliko API-ja modela je korisna, ali sama po sebi ne stvara AI platformu. Produkciona platforma takođe zahteva granice identiteta, ugovore o mogućnostima, upravljanje zdravljem i životnim ciklusom dobavljača, kvote, vlasništvo nad tajnama, nadzor, pravila kompatibilnosti, bezbednosne kontrole, disciplinu izdanja i jasnu operativnu odgovornost.",{"id":350,"data":351,"type":218},"p-stops-2",{"text":352},"Suprotan neuspeh je takođe čest: stavljanje svakog upita, vektorskog indeksa, poslovnog pravila, agenta i toka rada aplikacije u jedan „AI backend“. To stvara monolit čiji je zajednički status slučajan, a ne arhitektonski. \u003Cstrong>Platforma treba da standardizuje sveobuhvatne mogućnosti, a ne da preuzima domensko vlasništvo samo zato što je AI uključen.\u003C\u002Fstrong>",{"id":354,"data":355,"type":42},"h-boundary",{"text":356,"level":242},"Najvažnija odluka platforme: deljeno naspram specifičnog za rešenje",{"id":358,"data":359,"type":291},"shared-boundary-table",{"content":360,"stretched":43,"withHeadings":14},[361,365,369,373,377,381,384],[362,363,364],"Oblast sposobnosti","Dobar kandidat za vlasništvo zajedničke platforme","Obično ostaje specifično za rešenje",[366,367,368],"Pristup modelu","Odobrene veze sa provajderima, adapteri, akreditivi, zdravlje, primitivi rutiranja, kvote","Prihvatanje modela specifično za zadatak, ponašanje upita, prag kvaliteta",[370,371,372],"Pretraga","Primitivi za unos, ekstrakcija, indeksiranje, API-ji za pretragu, ugovori o poreklu, kuke za autorizaciju","Autoritativni korpus, pravila svežine, metapodaci domena, dovoljnost dokaza",[374,375,376],"Agenti i alati","Životni ciklus izvršavanja, registar\u002Fbroker alata, sprovođenje dozvola, praćenje, otkazivanje","Poslovni tok rada, dozvoljena semantika akcija, politika eskalacije, uspeh zadatka",[378,379,380],"Bezbednost","Integracija identiteta, skladištenje tajni, sprovođenje politike, ugovori o reviziji, mehanizmi izolacije zakupaca","Klasifikacija podataka, poslovna pravila autorizacije, prihvatanje rizika specifično za domen",[280,382,383],"Okvir, mehanika skupova podataka\u002Fverzija, telemetrija, tok rada eksperimenta\u002Fizdanja","Osnovna istina, domen test skup, prag prihvatanja, ishod korisnika",[385,386,387],"Operacije","Obrazac implementacije, zdravlje, metrike, integracija incidenata, kontrole kapaciteta","SLO-ovi rešenja gde se razlikuju, uticaj na kontinuitet poslovanja, runbook-ovi specifični za radno opterećenje",{"id":389,"data":390,"type":225},"boundary-principle",{"body":391,"title":392,"variant":393},"\u003Cstrong>Delite mehaniku i kontrole tamo gde je ponovna upotreba stvarna; zadržite autoritet i prihvatanje tamo gde ih domen poseduje.\u003C\u002Fstrong> Ovo sprečava dve suprotne greške: dupliranu infrastrukturu svuda i centralnu platformu koja lažno postaje vlasnik podataka, politike i kvaliteta svake aplikacije.","Princip platforme","success",{"id":395,"data":396,"type":42},"h-responsibility-map",{"text":397,"level":242},"Mapa odgovornosti arhitekture",{"id":399,"data":400,"type":42},"h-provider",{"text":401,"level":241},"1. Pristup modelu i provajderu",{"id":403,"data":404,"type":218},"p-provider-1",{"text":405},"Arhitekta platforme definiše kako potrošači otkrivaju i pozivaju modele bez prisiljavanja svake aplikacije da hardkodira jednog provajdera. Ovo uključuje adaptere provajdera, identifikatore modela, metapodatke o sposobnostima, autentifikaciju, provere zdravlja, konfiguraciju krajnjih tačaka, normalizaciju zahteva i ponašanje kompatibilnosti.",{"id":407,"data":408,"type":218},"p-provider-2",{"text":409},"Apstrakcija provajdera mora ostati iskrena. Različiti provajderi izlažu različita ograničenja konteksta, semantiku alata, ponašanje strukturiranog izlaza, multimodalne sposobnosti, sigurnosne kontrole, keširanje, cene i načine otkaza. Dobra apstrakcija stvara stabilan ugovor platforme dok čuva pristup sposobnostima koje se ne mogu smisleno spljoštiti.",{"id":411,"data":412,"type":225},"provider-warning",{"body":413,"title":414,"variant":415},"API najnižeg zajedničkog imenioca može olakšati migraciju, ali može i izbrisati sposobnosti koje su važne. Arhitektura treba da definiše koje su funkcije prenosive, koje su specifične za provajdera i kako potrošači otkrivaju tu razliku.","Ne mešajte apstrakciju sa pretvaranjem da su provajderi identični","warning",{"id":417,"data":418,"type":42},"h-gateway",{"text":419,"level":241},"2. Gejtvej, rutiranje, kvote i kontrole troškova",{"id":421,"data":422,"type":218},"p-gateway-1",{"text":423},"Zajednički AI gejtvej može centralizovati autentifikaciju, rutiranje, ograničavanje, ponovne pokušaje, ograničenja tokena, atribuciju upotrebe i sprovođenje politike. Microsoft-ove trenutne smernice za AI Gateway eksplicitno tretiraju ograničenja tokena u minuti, kvote i višeprojektno zadržavanje kao pitanja platforme; AWS takođe izlaže kvote naloga i modela i centralizovane kontrole.",{"id":425,"data":426,"type":218},"p-gateway-2",{"text":427},"Gejtvej je stoga više od obrnutog proksija kada nosi AI-specifičnu politiku i operativnu semantiku. Ali ne bi trebalo tiho da donosi poslovne odluke. Politika rutiranja može preferirati zdrav lokalni model, jeftinijeg provajdera ili regionalno usklađenu krajnju tačku; da li je ta ruta prihvatljiva za određeni zadatak i dalje je ugovor između platforme i rešenja.",{"id":429,"data":430,"type":218},"p-gateway-3",{"text":431},"Rutiranje takođe zahteva semantiku otkaza. Ako preferirani model nije dostupan, platforma mora znati da li je fallback dozvoljen, da li cloud ruta zahteva eksplicitnu saglasnost, da li je model nižih sposobnosti validan i kako se odluka prikazuje u observability-ju.",{"id":433,"data":434,"type":42},"h-data",{"text":435,"level":241},"3. Zajednički podaci, usluge pretrage i utemeljenja",{"id":437,"data":438,"type":218},"p-data-1",{"text":439},"Usluge pretrage su jaki kandidati za platformu jer su parsiranje, deljenje na delove, indeksiranje, leksička pretraga, semantička pretraga, filtriranje metapodataka, poreklo i mehanika citiranja ponovo upotrebljivi. Međutim, platforma ne sme da pobrka zajednički motor za pretragu sa zajedničkim izvorom istine.",{"id":441,"data":442,"type":218},"p-data-2",{"text":443},"Rešenje i dalje poseduje pitanja kao što su: Koji korpus je autoritativan? Koja verzija je validna? Može li ovaj korisnik da vidi ovaj dokument? Koliko sveži podaci moraju biti? Šta se smatra dovoljnim dokazom? Može li se odgovor generisati kada pretraga ne uspe? To su zahtevi domena i rešenja čak i kada platforma obezbeđuje mehanizam pretrage.",{"id":445,"data":446,"type":218},"p-data-3",{"text":447},"Ova granica je posebno važna u multi-tenant sistemima. Tehnički zajednički indeks ili vektorska usluga ne opravdava vidljivost između zakupaca. Kontekst autorizacije mora se sačuvati kroz pretragu, a ne dodavati tek nakon što su rezultati pretrage već prešli granicu.",{"id":449,"data":450,"type":42},"h-agent-runtime",{"text":451,"level":241},"4. Vreme izvršavanja agenata i alata",{"id":453,"data":454,"type":218},"p-agent-1",{"text":455},"Agentni sistemi dodaju ponovo upotrebljive brige o vremenu izvršavanja: životni ciklus niti\u002Fsesije, petlje planiranja, registracija alata, pozivanje alata, otkazivanje, vremenski limiti, ljudska odobrenja, interfejsi memorije\u002Fstanja, protokoli udaljenih agenata i korelacija tragova. Platforma može da obezbedi ovu mehaniku kako svaki proizvod ne bi ponovo gradio.",{"id":457,"data":458,"type":218},"p-agent-2",{"text":459},"Platforma takođe mora da drži dozvolu za alat odvojeno od sposobnosti modela. To što je model sposoban da generiše shell komandu ne znači da bi vreme izvršavanja trebalo da dozvoli izvršavanje shell-a. Granica dozvole pripada arhitekturi aplikacije\u002Fvremena izvršavanja i mora biti sprovodiva nezavisno od modela.",{"id":461,"data":462,"type":218},"p-agent-3",{"text":463},"Trenutne AWS smernice za agentnu AI naglašavaju ograničene agente, eksplicitna ovlašćenja, praćenje od početka do kraja, verzionisane artefakte ponašanja i ljudski nadzor srazmeran posledicama. To su pitanja koja omogućavaju platformu, ali rešenje koje je koristi i dalje definiše koje su radnje legitimne za njegov domen.",{"id":465,"data":466,"type":42},"h-identity",{"text":467,"level":241},"5. Identitet, izolacija zakupaca i autorizacija",{"id":469,"data":470,"type":218},"p-identity-1",{"text":471},"AI platforme često stoje ispred modela visoke vrednosti, vlasničkih podataka i alata sposobnih za radnje. Autentifikacija je zato samo početak. Arhitektura mora da nosi kontekst korisnika, servisa, aplikacije i zakupca kroz svaku privilegovanu operaciju kojoj je to potrebno.",{"id":473,"data":474,"type":218},"p-identity-2",{"text":475},"\u003Cstrong>RBAC i izolacija zakupaca rešavaju različite probleme.\u003C\u002Fstrong> RBAC odgovara šta identitet sme da radi; izolacija zakupaca odgovara na čije resurse tog zakupca taj identitet sme da deluje. Platforma koja proverava uloge ali izgubi kontekst zakupca i dalje može da izloži pogrešne podatke.",{"id":477,"data":478,"type":218},"p-identity-3",{"text":479},"Microsoft-ove trenutne smernice za AI radna opterećenja eksplicitno preporučuju segmentaciju identiteta i pristup sadržaju svestan autorizacije. AWS-ove smernice za višezakupničku generativnu AI platformu takođe tretiraju logičku izolaciju, centralizovane kontrole i mogućnost revizije kao pitanja platforme.",{"id":481,"data":482,"type":42},"h-secrets",{"text":483,"level":241},"6. Tajne, akreditivi i granice poverenja",{"id":485,"data":486,"type":218},"p-secrets-1",{"text":487},"Platforma treba da definiše ko poseduje ključeve provajdera, udaljene bearer tokene, materijal za potpisivanje i akreditive alata, gde se čuvaju, koji proces im može pristupiti, kako se rotiraju i mogu li ikada stići do pregledača ili nepouzdanog renderera.",{"id":489,"data":490,"type":218},"p-secrets-2",{"text":491},"Ovo je arhitektonska granica, a ne detalj implementacije. Ako svaka aplikacija koja koristi platformu kopira akreditive provajdera u sopstvenu konfiguraciju, organizacija je duplirala i operativni teret i domet štete. Centralizacija može smanjiti taj rizik samo ako sama platforma ima uže, proverljive pristupne putanje.",{"id":493,"data":494,"type":42},"h-eval",{"text":495,"level":241},"7. Evaluacija, observabilnost i mogućnost revizije",{"id":497,"data":498,"type":218},"p-eval-1",{"text":499},"Platforma koja se može ponovo koristiti može da obezbedi okvire za evaluaciju, ID-ove tragova, metapodatke modela\u002Fprovajdera, metrike tokena i troškova, latenciju, stope grešaka, povezivanje verzija upita\u002Fmodela, tragove agenata\u002Falata i kontrolisano evidentiranje. I AWS i Microsoft tretiraju observabilnost i evaluaciju kao ključna produkciona pitanja za AI radna opterećenja.",{"id":501,"data":502,"type":218},"p-eval-2",{"text":503},"Evaluacija platforme i evaluacija rešenja moraju ostati odvojene. Platforma može da potvrdi da je endpoint zdrav, da verzija modela prolazi opšti regresioni paket i da su tragovi potpuni. Ne može da odluči da su pravni odgovor, medicinski tok rada ili preporuka proizvoda prihvatljivi bez ground truth-a i kriterijuma prihvatanja specifičnih za domen.",{"id":505,"data":506,"type":218},"p-eval-3",{"text":507},"Evidentiranje takođe stvara granicu privatnosti. Dnevnici upita i odgovora mogu sadržati osetljive ili vlasničke podatke. Arhitekta platforme zato mora da odluči šta se evidentira, rediguje, uzorkuje, zadržava i čini dostupnim, umesto da pretpostavlja da je više telemetrije uvek bezbednije.",{"id":509,"data":510,"type":42},"h-runtime",{"text":511,"level":241},"8. Izvršno okruženje, raspoređivanje i lokalnost",{"id":513,"data":514,"type":218},"p-runtime-1",{"text":515},"Arhitekta platforme odlučuje kako se deljene AI sposobnosti raspoređuju i dohvataju: upravljani cloud servisi, samostalno hostovani endpointi, lokalna inferencija, hibridno rutiranje, kontejnerizovani servisi, desktop izvršna okruženja, privatno umrežavanje ili vazdušno izolovana okruženja. Važna razlika je između \u003Cstrong>toga gde se izvršava proces kontrole\u002Fizvršnog okruženja\u003C\u002Fstrong> i \u003Cstrong>toga gde se inferencija i obrada podataka zaista odvijaju\u003C\u002Fstrong>.",{"id":517,"data":518,"type":218},"p-runtime-2",{"text":519},"Lokalni klijent i dalje može da poziva cloud model. Cloud kontrolna ravan može da rutira ka on-premises modelu. Udaljeni agent može da izvršava alate unutar mreže korisnika. Arhitektonski dijagrami zato moraju da prikazuju granice poverenja i tokova podataka, umesto da koriste „lokalno“ i „cloud“ kao nejasne oznake.",{"id":521,"data":522,"type":42},"h-lifecycle",{"text":523,"level":241},"9. Životni ciklus platforme, kompatibilnost i onboarding",{"id":525,"data":526,"type":218},"p-lifecycle-1",{"text":527},"Sposobnost koja se može ponovo koristiti postaje platforma tek kada korisnici mogu dugoročno da se oslone na nju. To zahteva verzionisane ugovore, pravila migracije, politiku kompatibilnosti, ukidanje, testiranje izdanja, vraćanje na prethodnu verziju, vlasništvo nad incidentima, planiranje kapaciteta, dokumentaciju i put za uvođenje novih timova ili aplikacija.",{"id":529,"data":530,"type":218},"p-lifecycle-2",{"text":531},"AI ekosistemi koji se brzo menjaju čine ovo posebno važnim. Imena modela, SDK-ovi, verzije protokola, API-ji provajdera i bezbednosne sposobnosti menjaju se nezavisno. Platforma mora da apsorbuje deo te volatilnosti bez skrivanja promena koje materijalno utiču na ponašanje rešenja.",{"id":533,"data":534,"type":42},"h-control-plane",{"text":535,"level":242},"Praktični model kontrolne ravni \u002F izvršne ravni \u002F ravni rešenja",{"id":537,"data":538,"type":225},"model-note",{"body":539,"title":540,"variant":231},"Model sa tri ravni ispod je praktičan način da se razmišlja o odgovornostima; to nije ISO, NIST, Microsoft ili AWS standard. Njegova svrha je da učini granice vlasništva eksplicitnim.","Predloženi arhitektonski model",{"id":542,"data":543,"type":291},"planes-table",{"content":544,"stretched":43,"withHeadings":14},[545,549,553,557],[546,547,548],"Ravan","Tipične odgovornosti","Ne bi trebalo tiho da poseduje",[550,551,552],"Kontrolna ravan platforme","Registar provajdera, politika modela, kvote, konfiguracija zakupca, identiteti, tajne, pravila rutiranja, verzije mogućnosti, konfiguracija implementacije","Poslovna logika aplikacije ili istina domena",[554,555,556],"Izvršna ravan \u002F ravan podataka platforme","Zahtevi za inferenciju, operacije pretrage, izvršavanje agenata\u002Falata, ekstrakcija, indeksiranje, emitovanje telemetrije, sprovođenje politike","Pristup između zakupaca samo zato što je infrastruktura deljena",[558,559,560],"Ravan rešenja","Korisnički tok rada, uputstva\u002Finstrukcije, izbor autoritativnog korpusa, autorizacija domena, poslovna pravila, evaluacija zadataka i prihvatanje","Integracija provajdera niskog nivoa koju platforma eksplicitno poseduje",{"id":562,"data":563,"type":218},"p-control-plane-1",{"text":564},"Ovo razdvajanje pomaže u dijagnostikovanju odstupanja platforme. Ako aplikacija mora da zna svaki akreditiv i endpoint specifičan za provajdera, ugovor platforme je previše tanak. Ako platforma odlučuje koji je korisnički zapis pravno autoritativan ili da li je odgovor domena prihvatljiv, platforma je prešla u vlasništvo rešenja.",{"id":566,"data":567,"type":42},"h-artifacts",{"text":568,"level":242},"Šta bi arhitekta AI platforme trebalo da proizvede?",{"id":570,"data":571,"type":291},"artifacts-table",{"content":572,"stretched":43,"withHeadings":14},[573,576,579,582,585,588,591,594,597,600],[574,575],"Arhitektonski artefakt","Svrha",[577,578],"Mapa mogućnosti platforme","Definiše šta platforma pruža, ko je koristi i koje mogućnosti ostaju van opsega.",[580,581],"Ugovor provajdera\u002Fmodela","Definiše provajdere, modele, mogućnosti, granice apstrakcije, metapodatke ruta i semantiku rezervnih opcija.",[583,584],"Model identiteta i zakupništva","Definiše identitet korisnika\u002Fservisa\u002Faplikacije, kontekst zakupca, RBAC\u002FABAC kuke i izolaciju resursa.",[586,587],"Politika gejveja i kvota","Definiše ograničenja brzine, budžete tokena\u002Ftroškova, kontrole rutiranja, ponovne pokušaje i ponašanje kapaciteta.",[589,590],"Ugovor o pretrazi\u002Fpodacima","Definiše unos, poreklo, pretragu, metapodatke, propagaciju autorizacije i gde autoritet domena ostaje.",[592,593],"Ugovor o agentima\u002Falata","Definiše životni ciklus izvršavanja, registraciju alata, dozvole, odobrenja, otkazivanje i ponašanje praćenja.",[595,596],"Model tajni i granica poverenja","Definiše vlasništvo nad akreditivima, skladištenje, granice procesa, rotaciju i putanje osetljivih podataka.",[598,599],"Ugovor o evaluaciji i telemetriji","Definiše zajedničke metrike, tragove, veze skupova podataka\u002Fverzija, politiku evidentiranja i tačke proširenja rešenja.",[601,602],"Politika životnog ciklusa i kompatibilnosti","Definiše verzije, migracije, ukidanje, izdanja, vraćanje, vlasništvo nad incidentima i uvođenje.",{"id":604,"data":605,"type":42},"h-tradeoffs",{"text":606,"level":242},"Posao je uglavnom kompromis, a ne maksimalna centralizacija",{"id":608,"data":609,"type":299},"tradeoff-comparison",{"rows":610,"title":647,"layout":291,"columns":648},[611,617,623,629,635,641],{"id":612,"label":613,"values":614},"t1","Apstrakcija provajdera",{"pressureA":615,"pressureB":616},"Stable portable platform API","Access to provider-specific capabilities and fast innovation",{"id":618,"label":619,"values":620},"t2","Ponovna upotreba",{"pressureA":621,"pressureB":622},"Shared services reduce duplication","Isolation and domain autonomy prevent unsafe coupling",{"id":624,"label":625,"values":626},"t3","Upravljanje",{"pressureA":627,"pressureB":628},"Central policy and auditability","Team speed and local experimentation",{"id":630,"label":631,"values":632},"t4","Opservabilnost",{"pressureA":633,"pressureB":634},"Rich traces for debugging and evaluation","Privacy, data minimization and logging cost",{"id":636,"label":637,"values":638},"t5","Dostupnost",{"pressureA":639,"pressureB":640},"Fallback and multi-provider resilience","Predictable quality, compliance and data-location guarantees",{"id":642,"label":643,"values":644},"t6","Opseg platforme",{"pressureA":645,"pressureB":646},"More reusable capabilities","Smaller blast radius and less platform lock-in","Uobičajeni kompromisi platforme",[649,652],{"id":650,"label":651},"pressureA","Pritisak A",{"id":653,"label":654},"pressureB","Pritisak B",{"id":656,"data":657,"type":42},"h-adjacent",{"text":658,"level":242},"Kako se ovo razlikuje od srodnih uloga?",{"id":660,"data":661,"type":291},"roles-table",{"content":662,"stretched":43,"withHeadings":14},[663,666,668,670,673,676,679],[664,665],"Uloga","Primarni arhitektonski opseg",[295,667],"Konkretno AI rešenje i njegovi zahtevi od početka do kraja, granice, kompromisi i prihvatanje u produkciji.",[298,669],"Mogućnosti AI koje se mogu ponovo koristiti i operativni\u002Fbezbednosni ugovori koji se koriste u više rešenja ili timova.",[671,672],"Arhitekta preduzeća","Portfolio poslovanja\u002Ftehnologije na nivou organizacije, usklađivanje mogućnosti i upravljanja na širem nivou.",[674,675],"MLOps \u002F LLMOps arhitekta ili specijalista","Životni ciklus modela i AI, implementacija, eksperimenti, opservabilnost, izdanja i operativne prakse; može se snažno preklapati, ali ne poseduje automatski celu deljenu aplikativnu platformu.",[677,678],"Inženjer platforme \u002F SRE","Implementira i upravlja infrastrukturom platforme, pouzdanošću, automatizacijom i iskustvom programera; odgovornost za arhitekturu može se deliti sa arhitektom platforme.",[680,681],"AI \u002F softverski inženjer","Implementira modele, integracije, servise, agente, pretragu i funkcionalnost proizvoda unutar dogovorene arhitekture.",{"id":683,"data":684,"type":218},"p-adjacent-1",{"text":685},"Ove granice su organizacione, a ne univerzalne. U malom timu jedna osoba može imati nekoliko odgovornosti. U regulisanom preduzeću mogu biti podeljene između grupa za arhitekturu, bezbednost, platformu, podatke i operacije. Korisna razlika je \u003Cstrong>opseg arhitektonske odgovornosti\u003C\u002Fstrong>, a ne naziv radnog mesta na organizacionoj šemi.",{"id":687,"data":688,"type":42},"h-evidence",{"text":689,"level":242},"Dokaz implementacije: kako se ove granice platforme pojavljuju u mom radu",{"id":691,"data":692,"type":225},"evidence-note",{"body":693,"title":694,"variant":231},"Sledeći odeljci opisuju konkretne obrasce iz mojih projekata. Oni su dokaz da su ove arhitektonske granice implementirane ili eksplicitno dizajnirane u stvarnom kodu i projektnim sistemima. Oni \u003Cstrong>nisu\u003C\u002Fstrong> tvrdnje da projekti zajedno već predstavljaju komercijalno implementiranu enterprise AI platformu.","Dokaz originalne implementacije",{"id":696,"data":697,"type":42},"h-ai-client",{"text":698,"level":241},"Aaasaasa AI Client: razdvajanje provajdera, izvršnog okruženja i dozvola",{"id":700,"data":701,"type":218},"p-ai-client-1",{"text":702},"Aaasaasa AI Client je lokalno-prvenstveni desktop AI radni prostor izgrađen sa Nuxt 4, Electron i TypeScript. Njegov AI Hub namerno razdvaja \u003Cstrong>agenta\u002Fklijenta, provajdera, model, lokaciju veze\u002Fizvršnog okruženja, dozvole i web klijenta\u003C\u002Fstrong> umesto da ih tretira kao jednu konfiguracionu vrednost.",{"id":704,"data":705,"type":218},"p-ai-client-2",{"text":706},"Implementacija uključuje direktne adaptere provajdera, integraciju Codex agent izvršnog okruženja, lokalne Ollama\u002FLM Studio putanje, servise kompatibilne sa OpenAI, centralizovane dozvole radnog prostora, skladištenje akreditiva u glavnom procesu, DuckDB, Qdrant\u002Fvektorsku podršku, PDF\u002Freadability ekstrakciju i autentifikovani pristup direktorijumu zasnovan na MCP.",{"id":708,"data":709,"type":218},"p-ai-client-3",{"text":710},"Dve lekcije o platformi su posebno relevantne. Prvo, lokalno izvršno okruženje nije isto kao lokalna inferencija: lokalni Codex proces i dalje može koristiti cloud model. Drugo, automatsko rutiranje ne prelazi tiho sa lokalne na plaćenu cloud inferenciju. To čini politiku rutiranja i lokalnost izvršnog okruženja eksplicitnim, a ne izvedenim iz UI oznaka.",{"id":712,"data":713,"type":291},"ai-client-evidence-table",{"content":714,"stretched":43,"withHeadings":14},[715,718,721,724,727,730],[716,717],"Implementirana granica","Značenje za arhitekturu platforme",[719,720],"Agent vs provajder vs model","Različite odgovornosti mogu se razvijati nezavisno umesto da budu skrivene iza jednog „AI“ selektora.",[722,723],"Dozvole odvojene od modela","Autoritet nad fajl sistemom\u002Falatom pripada politici izvršnog okruženja, a ne mogućnostima modela.",[725,726],"Tajne u glavnom procesu","Vlasništvo nad akreditivima prati granicu privilegovanog procesa, a ne renderer\u002FUI.",[728,729],"Zdravlje provajdera i otkrivanje modela","Rutiranje i dostupnost su pitanja izvršnog okruženja\u002Fplatforme.",[731,732],"Nema tihog cloud fallback-a","Troškovi, lokalnost i semantika prenosa podataka ostaju eksplicitne političke odluke.",{"id":734,"data":735,"type":42},"h-cms",{"text":736,"level":241},"Aaasaasa AI CMS: autorizacija ograničena na tenanta kao granica platforme",{"id":738,"data":739,"type":218},"p-cms-1",{"text":740},"Kodna baza Aaasaasa AI CMS pruža poseban primer implementacije: RBAC ograničen na tenanta predstavljen je kroz uloge, dozvole i dodele korisničkih uloga vezane za identifikator tenanta. Sistemske dozvole su grupisane po sposobnostima, a pretraga i ažuriranje uloga ostaju ograničeni na tenanta.",{"id":742,"data":743,"type":218},"p-cms-2",{"text":744},"Ovo samo po sebi nije dokaz kompletne AI platforme, ali je direktno relevantno za jednu od najtežih granica deljene platforme: usluga koja se može ponovo koristiti mora da očuva \u003Cstrong>ko sme šta da radi\u003C\u002Fstrong> i \u003Cstrong>za kog tenanta\u003C\u002Fstrong>. Dodavanje AI inferencije ili pretrage na vrhu aplikativne platforme ne uklanja taj zahtev.",{"id":746,"data":747,"type":218},"p-cms-3",{"text":748},"Arhitektonska implikacija je da bi model gateway-i, servisi za pretragu i agenti trebalo da koriste uspostavljeni identitetski\u002Ftenant kontekst umesto da izmišljaju paralelni univerzum autorizacije samo za AI.",{"id":750,"data":751,"type":42},"h-sot",{"text":752,"level":241},"Source of Truth Research Engine: deljeni mehanizmi pretrage bez deljene istine",{"id":754,"data":755,"type":218},"p-sot-1",{"text":756},"Source of Truth Research Engine pruža treći primer implementacije. Različiti režimi istraživanja dele zajedničko jezgro dokaza: Sources, Artifacts, provenance, Claims, Relations, Contradictions, Reference Model i revizorski trag. Sistem takođe pruža lokalnu leksičku pretragu, opcionu semantičku pretragu, ekstrakciju, snimke i provenance zasnovan na SHA-256.",{"id":758,"data":759,"type":218},"p-sot-2",{"text":760},"Projekat eksplicitno tretira pretragu i semantičku sličnost kao signale za otkrivanje, a ne kao dokaze. Rezultat mora biti ušančen nazad do konkretnog izvora i lokatora pre nego što može da podrži tvrdnju. Upravo to je razlika koja je potrebna AI platformi: \u003Cstrong>mehanizmi pretrage koji se mogu ponovo koristiti mogu biti deljeni dok autoritet dokaza ostaje vođen metodologijom koja ih koristi i domenom.\u003C\u002Fstrong>",{"id":762,"data":763,"type":218},"p-sot-3",{"text":764},"Engine takođe pokazuje zašto jedna deljena platforma ne zahteva jedno deljeno tumačenje. Istorijski, naučno-tehnički, režimi tržišne inteligencije i monitoringa mogu ponovo koristiti osnovnu infrastrukturu dokaza dok zadržavaju metodologiju specifičnu za režim.",{"id":766,"data":767,"type":225},"evidence-synthesis",{"body":768,"title":769,"variant":393},"Kroz ove projekte, obrazac koji se može ponovo koristiti nije „jedan backend za sve“. To je \u003Cstrong>razdvajanje odgovornosti plus eksplicitni ugovori\u003C\u002Fstrong>: razdvajanje provajdera\u002Fmodela\u002Fruntime-a, autorizacija svesna tenanta, granice akreditiva, primitivi za podatke\u002Fpretragu koji se mogu ponovo koristiti, provenance i autoritet specifičan za domen. Buduća integrisana platforma bi zahtevala stabilne ugovore između tih sposobnosti umesto direktnog povezivanja između kodnih baza.","Šta ove implementacije zajedno pokazuju",{"id":771,"data":772,"type":42},"h-frameworks",{"text":773,"level":242},"Kako trenutne arhitektonske smernice podržavaju ovaj obim platforme",{"id":775,"data":776,"type":218},"p-frameworks-1",{"text":777},"ISO\u002FIEC\u002FIEEE 42010:2022 pruža opštu disciplinu za opise arhitekture kroz softver, sisteme, preduzeća i povezane entitete. Ne definiše AI Platform Architect, ali pojačava potrebu da se izraze arhitektonske brige, odnosi i stanovišta umesto da se arhitektura svede na listu tehnologija.",{"id":779,"data":780,"type":218},"p-frameworks-2",{"text":781},"NIST AI RMF 1.0 i Generative AI Profile uokviruju upravljanje AI rizikom kroz životni ciklus, a ne samo u trenutku izbora modela. Upravljanje, mapiranje, merenje i upravljanje su stoga kompatibilni sa arhitekturom platforme koja nosi deljene kontrole i dokaze kroz mnoge radne opterećenja koja ih koriste.",{"id":783,"data":784,"type":218},"p-frameworks-3",{"text":785},"Microsoft-ove trenutne smernice za AI radna opterećenja tretiraju dizajn aplikacije, podatke, bezbednost, operacije, testiranje\u002Fevaluaciju i GenAIOps kao povezane arhitektonske oblasti. Njegove trenutne smernice za AI Gateway takođe pokazuju praktične brige platforme kao što su centralizovani pristup modelima, ograničenja tokena specifična za projekat, kvote i zadržavanje više timova.",{"id":787,"data":788,"type":218},"p-frameworks-4",{"text":789},"AWS-ov trenutni Generative AI Lens i scenario platforme sa više zakupaca na sličan način razdvajaju temeljne kontrole platforme od vlasništva aplikacije koja ih koristi. AWS eksplicitno napominje da centralna platforma može da sprovodi deljene zaštitne mere i revizibilnost dok kvalitet podataka i observabilnost specifična za radno opterećenje i dalje ostaju odgovornost aplikacija koje ih koriste ili proizvođača podataka.",{"id":791,"data":792,"type":218},"p-frameworks-5",{"text":793},"Proizvodi dobavljača se razlikuju, ali obrazac između izvora je stabilan: produkcijske AI platforme moraju da koordiniraju identitet, pristup podacima, modele, politiku, evaluaciju, observabilnost, kapacitet, troškove i životni ciklus. GPU klaster ili endpoint modela pokriva samo deo te odgovornosti.",{"id":795,"data":796,"type":42},"h-misconceptions",{"text":797,"level":242},"Uobičajene zablude",{"id":799,"data":800,"type":291},"misconceptions-table",{"content":801,"stretched":43,"withHeadings":14},[802,805,808,811,814,817,820,823,826],[803,804],"Zabluda","Zašto je pogrešna",[806,807],"„AI platforma je GPU klaster.“","Računanje je jedan supstrat. Platforma takođe zahteva ugovore za identitet, pristup modelima, podatke, politiku, evaluaciju, observabilnost i životni ciklus.",[809,810],"„AI gateway je samo reverse proxy.“","Može takođe da nosi rutiranje modela, kvote tokena, atribuciju troškova, sprovođenje politike, identitet i telemetriju specifičnu za AI.",[812,813],"„Deljeno znači globalno deljeno.“","Usluga može biti fizički deljena dok je logički segmentirana po zakupcu, aplikaciji, regionu, klasifikaciji ili nivou rizika.",[815,816],"„Jedna centralna vektorska baza podataka postaje istina kompanije.“","Vektorsko skladište ili servis za pretragu je infrastruktura. Autoritet domena, svežina, provenance i pristup ostaju odvojene brige.",[818,819],"„Evaluacija platforme zamenjuje evaluaciju rešenja.“","Opšta regresija i telemetrija ne mogu da definišu da li je odgovor ili akcija specifična za domen prihvatljiva.",[821,822],"„Apstrakcija provajdera treba da sakrije svaku razliku.“","Neke razlike su materijalne sposobnosti, bezbednosne semantike ili načini otkaza i moraju ostati vidljive.",[824,825],"„RBAC rešava multi-tenancy.“","RBAC kontroliše akcije; izolacija zakupaca kontroliše granice resursa. Oba mogu biti potrebna.",[827,828],"„AI Platform Architect je samo drugo ime za MLOps.“","MLOps\u002FLLMOps je glavna disciplina koja se preklapa, ali deljena aplikacija\u002Fruntime, identitet, gateway, pretraga i granice alata mogu se protezati izvan operacija životnog ciklusa modela.",{"id":830,"data":831,"type":42},"h-failure",{"text":832,"level":242},"Načini otkaza koje AI Platform Architect treba da spreči",{"id":834,"data":835,"type":291},"failures-table",{"content":836,"stretched":43,"withHeadings":14},[837,840,843,846,849,852,855,858,861,864],[838,839],"Način neuspeha","Arhitektonska posledica",[841,842],"Svaki tim čuva sopstvene ključeve provajdera","Duplirano rukovanje tajnama, nedosledna rotacija i veći radijus eksplozije.",[844,845],"Apstrakcija provajdera skriva potrebne mogućnosti","Potrošači ne mogu da koriste funkcije koje su im potrebne ili tiho dobijaju ponašanje različito od pretpostavki.",[847,848],"Deljeni retrieval ignoriše kontekst tenanta\u002Fkorisnika","Može doći do curenja podataka preko granica pre nego što aplikacija dobije priliku da filtrira rezultate.",[850,851],"Fallback tiho menja provajdera ili lokaciju","Troškovi, usklađenost, lokacija podataka i kvalitet izlaza mogu se promeniti bez znanja pozivaoca.",[853,854],"Alati agenta se dodeljuju izborom modela","Sposoban model postaje prekomerno privilegovan jer se autoritet u vreme izvršavanja ne sprovodi nezavisno.",[856,857],"Svi promptovi\u002Fodgovori se podrazumevano loguju","Observability može stvoriti novi repozitorijum osetljivih podataka i problem usklađenosti.",[859,860],"Platforma poseduje jedan generički skor kvaliteta","Domen-specifični neuspesi ostaju skriveni iza platformskih metrika zdravlja.",[862,863],"Nema ugovora o verzijama za platformske mogućnosti","Promene modela\u002Fprovajdera\u002Fruntime-a nepredvidivo kvare potrošače.",[865,866],"Sve što je povezano sa AI je centralizovano","Platforma postaje usko grlo i monolit umesto sloja za ponovnu upotrebu.",{"id":868,"data":869,"type":42},"h-decision",{"text":870,"level":242},"Praktičan sled odluka o arhitekturi platforme",{"id":872,"data":873,"type":340},"decision-flow",{"steps":874,"title":905,"orientation":339},[875,878,881,884,887,890,893,896,899,902],{"label":876,"description":877},"1. Identifikujte stvarne potrošače","Navedite rešenja, timove, tenante i radna opterećenja koji bi koristili platformu; izbegnite izgradnju platforme za hipotetičku ponovnu upotrebu.",{"label":879,"description":880},"2. Definišite deljenu granicu","Odvojite mehanizme koji seku kroz više oblasti od domen-specifičnog autoriteta, toka rada i prihvatanja rešenja.",{"label":882,"description":883},"3. Prvo definišite identitet i izolaciju","Uspostavite korisnike, servise, aplikacije, tenante, regione i klasifikacije podataka pre deljenja retrieval ili tool mogućnosti.",{"label":885,"description":886},"4. Definišite ugovore o mogućnostima","Specifikujte API-je za model\u002Fprovajdera, retrieval, agente\u002Falate, gateway i telemetriju sa eksplicitnim vlasništvom i verzionisanjem.",{"label":888,"description":889},"5. Odlučite o strategiji provajdera i runtime-a","Izaberite managed, self-hosted, lokalno ili hibridno izvršavanje i dokumentujte fallback, lokaciju i semantiku mogućnosti.",{"label":891,"description":892},"6. Dizajnirajte granice podataka i retrieval-a","Definišite poreklo, propagaciju autorizacije, vlasništvo nad korpusom, indeksiranje i odgovornosti za dokaze.",{"label":894,"description":895},"7. Dodajte kvote, tajne i politiku","Kontrolišite troškove, kapacitet, akreditive, dozvole za alate, bezbednosne kontrole i radijus eksplozije.",{"label":897,"description":898},"8. Izgradite ugovore za evaluaciju i observability","Obezbedite platformske metrike i tracing, dok domen-specifičnu osnovnu istinu i prihvatanje ostavljate rešenju.",{"label":900,"description":901},"9. Definišite životni ciklus i operacije","Verzionišite mogućnosti, testirajte nadogradnje, dokumentujte ukidanje, rollback, incidente, kapacitet i onboarding potrošača.",{"label":903,"description":904},"10. Validirajte sa više od jednog potrošača","Tvrdnja o platformi postaje kredibilna kada deljena mogućnost zaista služi različitim radnim opterećenjima bez prisiljavanja na isti domen model.","Od potrebe platforme do operativne deljene mogućnosti",{"id":907,"data":908,"type":42},"h-edge",{"text":909,"level":242},"Rubni slučajevi i ograničenja uloge",{"id":911,"data":912,"type":218},"p-edge-1",{"text":913},"Mala organizacija sa jednom AI aplikacijom možda neće imati potrebu za posebnom AI platformom ili platform arhitektom. Prevremeno platformisanje može stvoriti više apstrakcije nego vrednosti. Ispravna arhitektura može biti jedno dobro dizajnirano rešenje sa nekoliko modula za ponovnu upotrebu.",{"id":915,"data":916,"type":218},"p-edge-2",{"text":917},"Air-gapped ili suvereno postavljanje značajno menja model provajdera, ažuriranja i observability. Hostovanje modela, distribucija artefakata, integracija identiteta i izvoz telemetrije mogu zahtevati lokalne ekvivalente.",{"id":919,"data":920,"type":218},"p-edge-3",{"text":921},"Visoko regulisana ili radna opterećenja sa velikim posledicama mogu zahtevati jaču fizičku ili organizacionu izolaciju umesto logički deljene platforme. Ponovna upotreba nikada nije dovoljan razlog da se oslabi zahtevana bezbednosna granica.",{"id":923,"data":924,"type":218},"p-edge-4",{"text":925},"Managed cloud AI servisi mogu ukloniti teret implementacije, ali ne uklanjaju arhitektonsku odgovornost. Organizacija i dalje odlučuje o identitetu, pristupu podacima, logovanju, zadržavanju, kvotama, podobnosti modela, fallback-u, evaluaciji i prihvatanju rešenja.",{"id":927,"data":928,"type":218},"p-edge-5",{"text":929},"Granica platforme može se razlikovati i po modalitetu. Tekstualna inferencija, multimodalna generacija, govor, korišćenje računara i autonomni agenti mogu imati različite zahteve za latenciju, podatke, dozvole i observability čak i kada dele infrastrukturu provajdera i identiteta.",{"id":931,"data":932,"type":42},"h-change",{"text":933,"level":242},"Šta bi promenilo ovaj odgovor?",{"id":935,"data":936,"type":218},"p-change-1",{"text":937},"Osnovna definicija bi se promenila ako se promeni organizacioni obim. Ako arhitekta poseduje jedno radno opterećenje, uloga postaje bliža AI Solution Architect. Ako se odgovornost proširi na strategiju sposobnosti na nivou organizacije, investicije, standarde i portfolije ciljnog stanja, pomera se ka Enterprise AI Architecture.",{"id":939,"data":940,"type":218},"p-change-2",{"text":941},"Smernice za implementaciju se menjaju kad god se promene provajderi, gateway proizvodi, protokoli agenata, regulatorne obaveze, mogućnosti modela ili ograničenja postavljanja. Zato arhitektura platforme treba da izražava stabilne odgovornosti i ugovore odvojeno od trenutnih mehanizama dobavljača.",{"id":943,"data":944,"type":42},"h-checklist",{"text":945,"level":242},"Kontrolna lista AI Platform Arhitekte",{"id":947,"data":948,"type":291},"checklist-table",{"content":949,"stretched":43,"withHeadings":14},[950,953,956,959,962,965,968,971,974,977,980,983,986],[951,952],"Pitanje","Očekivani odgovor",[954,955],"Ko su stvarni potrošači platforme?","Imenovana rešenja, timovi ili konteksti tenanta sa različitim ali preklapajućim potrebama.",[957,958],"Šta je zaista deljeno?","Eksplicitna lista mogućnosti, a ne nejasan „AI backend“.",[960,961],"Šta mora ostati specifično za rešenje?","Autoritet domena, poslovni tok rada, prihvatanje zadataka i druge brige koje pripadaju radnom opterećenju.",[963,964],"Kako su modeli\u002Fprovajderi predstavljeni?","Verzionisani ugovori provajdera\u002Fmodela sa mogućnostima i eksplicitnom semantikom fallback-a.",[966,967],"Kako se identitet propagira?","Kontekst korisnika\u002Fservisa\u002Faplikacije\u002Ftenanta preživljava svaku privilegovanu putanju zahteva.",[969,970],"Kako se sprovodi izolacija tenanta?","Ograničavanje resursa je odvojeno od provera dozvola uloga.",[972,973],"Kako se rukuje tajnama?","Privilegovano skladištenje, rotacija, ograničeno izlaganje i revizorsko vlasništvo.",[975,976],"Kako retrieval čuva autoritet?","Deljeni mehanizmi sa autorizacijom, poreklom i pravilima dokaza u vlasništvu domena.",[978,979],"Kako su alati i agenti ograničeni?","Dozvole u vreme izvršavanja, ograničeni ugovori alata, odobrenja, otkazivanje i sledljivost.",[981,982],"Kako se kontrolišu troškovi i kapacitet?","Kvote, kontrole tokena\u002Fbrzine, atribucija upotrebe i ponašanje pri preopterećenju.",[984,985],"Kako se meri kvalitet?","Platformska regresija\u002Fevaluacija plus osnovna istina i prihvatanje specifično za rešenje.",[987,988],"Kako se uvode promene?","Verzionisanje, kompatibilnost, migracija, ukidanje, rollback i vlasništvo nad incidentima.",{"id":990,"data":991,"type":42},"h-conclusion",{"text":992,"level":242},"Zaključak",{"id":994,"data":995,"type":218},"p-conclusion-1",{"text":996},"AI Platform Arhitekta je odgovoran za arhitekturu za ponovnu upotrebu \u003Cstrong>između AI mogućnosti i rešenja koja ih koriste\u003C\u002Fstrong>. Uloga definiše kako modeli, provajderi, retrieval, agenti, alati, identitet, tenanti, tajne, evaluacija, observability, kvote i runtime operacije postaju pouzdani platformski servisi umesto ponovljenih jednokratnih integracija.",{"id":998,"data":999,"type":218},"p-conclusion-2",{"text":1000},"Težak deo nije maksimiziranje ponovne upotrebe. To je izbor ispravne granice. Jaka platforma standardizuje mehanizme, politiku i operacije tamo gde više potrošača zaista ima koristi, dok čuva autoritet nad podacima specifičan za rešenje, poslovnu logiku, bezbednosne zahteve i kriterijume prihvatanja.",{"id":1002,"data":1003,"type":218},"p-conclusion-3",{"text":1004},"Ta razlika takođe objašnjava odnos sa AI Solution Architecture: \u003Cstrong>solution arhitekta čini da jedan AI-omogućen sistem odgovara svojoj svrsi; platform arhitekta čini da deljene AI mogućnosti budu bezbedne, ponovo upotrebljive, operativne i evolutivne kroz mnoge takve sisteme.\u003C\u002Fstrong>",{"id":1006,"data":1007,"type":42},"h-related",{"text":1008,"level":242},"Povezano kanonsko znanje",{"id":1010,"data":1011,"type":218},"p-related-1",{"text":1012},"Ovaj članak se nadovezuje na kanonske osnove o komponentama generativne AI, ADR naspram NFR i AI Solution Architecture. Ti koncepti su preduslovi jer platforma postoji da bi pružala višekratno upotrebljive sistemske mogućnosti i kodifikovala arhitekturne odluke u skladu sa eksplicitnim zahtevima kvaliteta i operativnim zahtevima.",{"id":1014,"data":1015,"type":218},"p-related-2",{"text":1016},"Retrieval-Augmented Generation je jedan primer mogućnosti koja se može ponuditi kroz platformu, ali platforma ne bi trebalo da sažme infrastrukturu za pretragu, domensko znanje i validnost odgovora u jedan koncept.",{"id":1018,"data":1019,"type":1026},"related-rag",{"link":1020,"meta":1021},"https:\u002F\u002Fstajic.de\u002Fsr\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works",{"image":1022,"title":1024,"description":1025},{"url":1023},"","Šta je RAG? Najjednostavnije objašnjenje kako funkcioniše","Kanonski uvod u retrieval-augmented generation i granicu između generisanja modela i eksternog pronalaženja znanja.","linkTool",{"id":1028,"data":1029,"type":218},"p-related-3",{"text":1030},"Agent protokoli, izolacija zakupaca, AI upravljanje, rutiranje modela, Context Engineering i MLOps\u002FLLMOps su nizvodni ili susedni čvorovi znanja. Oni postaju lakši za razumevanje kada je granica platforme eksplicitna.",{"id":1032,"data":1033,"type":42},"h-faq",{"text":1034,"level":242},"Često postavljana pitanja",{"id":1036,"data":1037,"type":1036},"faq",{"items":1038,"title":1063},[1039,1043,1047,1051,1055,1059],{"id":1040,"answer":1041,"question":1042},"faq-1","Ne. Solution arhitekta se fokusira na jedno konkretno AI rešenje. Platform arhitekta se fokusira na višekratno upotrebljive AI mogućnosti, kontrole i operativne ugovore koji mogu podržati više rešenja.","Da li je AI Platform Architect isto što i AI Solution Architect?",{"id":1044,"answer":1045,"question":1046},"faq-2","Ne. Platforma može koristiti upravljane cloud modele, samostalno hostovane modele, lokalnu inferenciju ili hibridnu strategiju. Arhitektura mora učiniti eksplicitnim posledice po provajdera, lokaciju, identitet, rutiranje, podatke i operacije.","Da li AI platforma treba da hostuje sopstvene modele?",{"id":1048,"answer":1049,"question":1050},"faq-3","Obično ne. Gateway može biti važna komponenta platforme, ali kompletna platforma takođe zahteva ugovore za identitet, tajne, podatke\u002Fpretragu, evaluaciju, observabilnost, životni ciklus i operativno vlasništvo.","Da li je AI gateway dovoljan da bude AI platforma?",{"id":1052,"answer":1053,"question":1054},"faq-4","Mehanika pretrage se često može deliti, ali autoritet domena, autorizacija, svežina, dovoljnost dokaza i vlasništvo nad korpusom treba da ostanu eksplicitni. Deljena infrastruktura ne podrazumeva deljenu istinu.","Da li pretragu treba centralizovati?",{"id":1056,"answer":1057,"question":1058},"faq-5","Ne. Evaluacija platforme može testirati deljene mogućnosti i regresije. Svako rešenje i dalje zahteva ground truth specifičan za zadatak, kriterijume prihvatanja i domenske pragove kvaliteta.","Da li evaluacija platforme zamenjuje evaluaciju aplikacije?",{"id":1060,"answer":1061,"question":1062},"faq-6","Ne. RBAC određuje šta identitet može da radi. Izolacija zakupaca određuje na resurse kog zakupca identitet može da deluje. Platforma često zahteva oboje.","Da li je multi-tenancy samo RBAC?","AI Platform Architect FAQ",{"id":1065,"data":1066,"type":42},"h-glossary",{"text":1067,"level":242},"Pojmovnik",{"id":1069,"data":1070,"type":1069},"glossary",{"title":1071,"entries":1072},"Ključni pojmovi arhitekture AI platforme",[1073,1077,1081,1085,1089,1093,1097,1101],{"term":1074,"anchor":1075,"definition":1076},"AI platforma","ai-platform","Višekratno upotrebljiv skup AI-related tehničkih i operativnih mogućnosti koje koristi više aplikacija, timova ili konteksta zakupaca.",{"term":1078,"anchor":1079,"definition":1080},"AI gateway","ai-gateway","Gateway sloj za AI endpoint-e koji može dodati autentifikaciju, rutiranje, kvote, politiku, ponovne pokušaje, atribuciju troškova i AI-specifičnu telemetriju iznad osnovnog proxy-ja.",{"term":1082,"anchor":1083,"definition":1084},"Provider adapter","provider-adapter","Komponenta koja mapira ugovor platforme na API, mogućnosti, zdravlje i semantiku otkaza provajdera modela.",{"term":1086,"anchor":1087,"definition":1088},"Izolacija zakupaca","tenant-isolation","Granica koja sprečava jedan kontekst zakupca da pristupi resursima drugog zakupca, nezavisno od dozvola uloga.",{"term":1090,"anchor":1091,"definition":1092},"Ugovor o mogućnosti","capability-contract","Verzionisani interfejs i sporazum o ponašanju koji opisuje šta deljena usluga platforme pruža i šta potrošač mora da obezbedi ili poseduje.",{"term":1094,"anchor":1095,"definition":1096},"Grounding \u002F retrieval servis","grounding-service","Deljena mehanika za pronalaženje i snabdevanje AI radnog opterećenja eksternim informacijama; ne definiše automatski koje informacije su autoritativne za domen.",{"term":1098,"anchor":1099,"definition":1100},"Evaluation harness","evaluation-harness","Višekratno upotrebljiva infrastruktura za pokretanje testova, skupova podataka, verzija modela\u002Fprompt-ova i metrika; domensko prihvatanje ostaje specifično za rešenje.",{"term":1102,"anchor":1103,"definition":1104},"Control plane","control-plane","Sloj konfiguracije i upravljanja koji upravlja mogućnostima platforme, identitetima, politikama, kvotama, verzijama i stanjem implementacije.",{"id":1106,"data":1107,"type":42},"h-sources",{"text":1108,"level":242},"Primarni izvori i aktuelne smernice arhitekture",{"id":1110,"data":1111,"type":218},"p-sources-note",{"text":1112},"Izvori ispod podržavaju opšte tvrdnje o arhitekturi i produkcijskoj platformi. Sekcije Aaasaasa AI Client, Aaasaasa AI CMS i Source of Truth Research Engine su eksplicitno originalni dokazi implementacije. Eksterni izvori o trenutnom stanju provereni su 8. oktobra 2026.",{"id":1114,"data":1115,"type":1026},"src-iso-42010",{"link":1116,"meta":1117},"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html",{"image":1118,"title":1119,"description":1120},{"url":1023},"ISO\u002FIEC\u002FIEEE 42010:2022 — Opis arhitekture","Aktuelni objavljeni međunarodni standard za koncepte i odnose opisa arhitekture.",{"id":1122,"data":1123,"type":1026},"src-nist-rmf",{"link":1124,"meta":1125},"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework",{"image":1126,"title":1127,"description":1128},{"url":1023},"NIST AI Risk Management Framework","NIST AI RMF resursi i trenutni status; AI RMF 1.0 je u reviziji od oktobra 2026.",{"id":1130,"data":1131,"type":1026},"src-nist-gai",{"link":1132,"meta":1133},"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence",{"image":1134,"title":1135,"description":1136},{"url":1023},"NIST AI 600-1 — Generative AI Profile","Generative AI profil za primenu razmatranja upravljanja AI rizikom kroz životni ciklus AI.",{"id":1138,"data":1139,"type":1026},"src-ms-ai",{"link":1140,"meta":1141},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started",{"image":1142,"title":1143,"description":1144},{"url":1023},"Microsoft Azure Well-Architected — AI Workloads","Aktuelne arhitekturne smernice koje pokrivaju AI aplikaciju, podatke, operacije, evaluaciju, odgovornu AI i pitanja životnog ciklusa.",{"id":1146,"data":1147,"type":1026},"src-ms-principles",{"link":1148,"meta":1149},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fdesign-principles",{"image":1150,"title":1151,"description":1152},{"url":1023},"Microsoft — Design Principles for AI Workloads","Aktuelne smernice o segmentaciji identiteta, bezbednosnim granicama, telemetriji, performansama, podacima i kompromisima platforme.",{"id":1154,"data":1155,"type":1026},"src-ms-gateway",{"link":1156,"meta":1157},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fai-foundry\u002Fconfiguration\u002Fenable-ai-api-management-gateway-portal?view=foundry",{"image":1158,"title":1159,"description":1160},{"url":1023},"Microsoft Foundry — AI Gateway Architecture","Aktuelne smernice za AI Gateway za deljeni pristup projektu, ograničavanje tokena, kvote i upravljanje.",{"id":1162,"data":1163,"type":1026},"src-ms-gateway-guide",{"link":1164,"meta":1165},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Farchitecture\u002Fai-ml\u002Fguide\u002Fazure-openai-gateway-guide",{"image":1166,"title":1167,"description":1168},{"url":1023},"Azure Architecture Center — Access Models Through a Gateway","Arhitekturne smernice za centralizovan pristup modelima, rutiranje, ograničavanje, failover i odgovornosti klijenta\u002Fplatforme.",{"id":1170,"data":1171,"type":1026},"src-aws-genai",{"link":1172,"meta":1173},"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fgenerative-ai-lens\u002F",{"image":1174,"title":1175,"description":1176},{"url":1023},"AWS Well-Architected — Objektiv za generativnu veštačku inteligenciju","Aktuelne smernice za produkcionu arhitekturu za radna opterećenja generativne veštačke inteligencije u pogledu bezbednosti, pouzdanosti, operacija, performansi i troškova.",{"id":1178,"data":1179,"type":1026},"src-aws-multitenant",{"link":1180,"meta":1181},"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fgenerative-ai-lens\u002Fmulti-tenant-generative-ai-platform-scenario.html",{"image":1182,"title":1183,"description":1184},{"url":1023},"AWS — Scenario višekorisničke platforme za generativnu veštačku inteligenciju","Aktuelni primer koji razdvaja centralne kontrole platforme i mogućnost revizije od kvaliteta podataka aplikacija koje ih koriste i odgovornosti specifičnih za radno opterećenje.",{"id":1186,"data":1187,"type":1026},"src-aws-agentic",{"link":1188,"meta":1189},"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fagentic-ai-lens\u002Fdesign-principles.html",{"image":1190,"title":1191,"description":1192},{"url":1023},"AWS Well-Architected — Principi dizajna agentske veštačke inteligencije","Aktuelne smernice o ograničenom ovlašćenju agenata, sledljivosti, verzionisanom ponašanju, eksplicitnim ugovorima i ljudskom nadzoru.",{"id":1194,"data":1195,"type":1026},"src-aws-observability",{"link":1196,"meta":1197},"https:\u002F\u002Fdocs.aws.amazon.com\u002FAmazonCloudWatch\u002Flatest\u002Fmonitoring\u002FGenAI-observability.html",{"image":1198,"title":1199,"description":1200},{"url":1023},"AWS CloudWatch — Nadzor generativne veštačke inteligencije","Aktuelne mogućnosti nadzora i produkcione metrike za modele, agente, baze znanja, alate i analizu troškova\u002Flatencije\u002Fgrešaka.","2.31","Arhitekta AI platforme projektuje višekratno upotrebljive AI temelje kroz modele, provajdere, pretragu, agente, identitet, bezbednost, evaluaciju, opservabilnost i operacije.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc","PUBLISHED","2026-10-08T12:32:00.000Z","2026-10-08T16:32:14.856Z","2026-10-08T16:47:57.364Z",{"en":1210,"de":1211,"sr":1212,"es":1213,"fr":1214,"it":1215,"ru":1216,"zh":1217},"\u002Fblog\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations","\u002Fde\u002Fblog\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations","\u002Fsr\u002Fblog\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations","\u002Fes\u002Fblog\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations","\u002Ffr\u002Fblog\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations","\u002Fit\u002Fblog\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations","\u002Fru\u002Fblog\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations","\u002Fzh\u002Fblog\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations",[1219,1223,1227],{"id":1220,"name":1221,"slug":1222},84,"Politike i granice podataka","policy-and-data",{"id":1224,"name":1225,"slug":1226},57,"Granice podataka","data-boundaries",{"id":1228,"name":1229,"slug":1230},80,"Pristup i identitet","access-and-identity",{"id":1232,"login":1233,"email":1234,"displayName":1235},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1237,2015],{"lang":1238,"title":1239,"content":1240,"contentJson":1241,"excerpt":2014},"en","What Is an AI Platform Architect? Models, Data, Runtime, Security and Operations","{\"time\":1791476955677,\"blocks\":[{\"id\":\"intro\",\"data\":{\"text\":\"An \u003Cstrong>AI Platform Architect\u003C\u002Fstrong> designs the reusable AI foundation through which multiple applications, teams, or tenant contexts access models, data and retrieval, agent and tool runtimes, identity and permissions, evaluation, observability, quotas, secrets, and deployment capabilities. The role is broader than infrastructure but narrower than owning every AI-enabled product: its central responsibility is deciding \u003Cstrong>what should be shared, how shared capabilities are governed and isolated, and what must remain solution-specific\u003C\u002Fstrong>.\"},\"type\":\"paragraph\"},{\"id\":\"direct\",\"data\":{\"body\":\"\u003Cstrong>An AI Platform Architect designs the shared technical and operational substrate for AI systems.\u003C\u002Fstrong> Instead of architecting one assistant or one workflow, the role defines reusable contracts and boundaries for model\u002Fprovider access, gateways and routing, retrieval services, agent runtimes, tool access, identity and tenant isolation, secrets, evaluation, telemetry, deployment and lifecycle management.\",\"title\":\"Direct answer\",\"variant\":\"info\"},\"type\":\"callout\"},{\"id\":\"term-note\",\"data\":{\"body\":\"\u003Cstrong>AI Platform Architect is a practical role label, not a universally standardized job title.\u003C\u002Fstrong> ISO\u002FIEC\u002FIEEE 42010:2022 defines concepts for architecture descriptions, not this role. Different organizations may split these responsibilities among platform architects, solution architects, enterprise architects, security architects, MLOps\u002FLLMOps specialists and platform engineering teams. This article uses the term for the architecture responsibility over a reusable AI platform layer.\",\"title\":\"Terminology note\",\"variant\":\"note\"},\"type\":\"callout\"},{\"id\":\"version-note\",\"data\":{\"body\":\"The stable architectural principles here are vendor-neutral. Current Microsoft, AWS and NIST guidance is used as external implementation and governance evidence. NIST states that AI RMF 1.0 is being revised; vendor platform features, gateway products, agent runtimes and model capabilities evolve faster than the architectural principles, so version-sensitive implementation choices must be rechecked before deployment.\",\"title\":\"Current-source note — 8 October 2026\",\"variant\":\"note\"},\"type\":\"callout\"},{\"id\":\"toc\",\"data\":{\"title\":\"Contents\",\"maxLevel\":3,\"minLevel\":2},\"type\":\"tableOfContents\"},{\"id\":\"h-meaning\",\"data\":{\"text\":\"What does an AI Platform Architect actually architect?\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-meaning-1\",\"data\":{\"text\":\"The object of the work is the \u003Cstrong>platform\u003C\u002Fstrong>: a set of shared capabilities that reduces repeated integration work while preserving explicit security, data and operational boundaries. A platform can expose model access, provider adapters, retrieval primitives, agent execution, tool brokers, policy enforcement, evaluation, telemetry and deployment services to many consuming solutions.\"},\"type\":\"paragraph\"},{\"id\":\"p-meaning-2\",\"data\":{\"text\":\"The platform is not valuable merely because components are centralized. It is valuable when consumers receive stable capabilities with clear contracts, ownership, isolation, observability and lifecycle rules. The key architectural question is therefore not “Which model should everyone use?” but \u003Cstrong>“Which responsibilities can be safely standardized and reused without erasing the requirements of each solution?”\u003C\u002Fstrong>.\"},\"type\":\"paragraph\"},{\"id\":\"solution-vs-platform\",\"data\":{\"rows\":[{\"id\":\"c1\",\"label\":\"Primary scope\",\"values\":{\"platform\":\"Reusable AI capabilities consumed by multiple solutions, teams or tenant contexts.\",\"solution\":\"One concrete AI-enabled product, workflow or application.\"}},{\"id\":\"c2\",\"label\":\"Main question\",\"values\":{\"platform\":\"Which shared capabilities and controls should solutions consume, and where must solution-specific ownership remain?\",\"solution\":\"How should this solution meet its business, data, security, quality and operational requirements?\"}},{\"id\":\"c3\",\"label\":\"Data authority\",\"values\":{\"platform\":\"Provides storage, retrieval, provenance or access primitives without automatically becoming the authority for every domain.\",\"solution\":\"Defines which domain data is authoritative and how the solution may use it.\"}},{\"id\":\"c4\",\"label\":\"Evaluation\",\"values\":{\"platform\":\"Provides reusable evaluation, telemetry and release mechanisms; it cannot define every domain's success threshold.\",\"solution\":\"Defines task-specific quality and acceptance criteria.\"}},{\"id\":\"c5\",\"label\":\"Lifecycle\",\"values\":{\"platform\":\"Owns shared capability versions, compatibility, onboarding, quotas, policy and operational contracts.\",\"solution\":\"Owns the lifecycle of the specific workload.\"}}],\"title\":\"Solution architecture and platform architecture solve different scope problems\",\"layout\":\"table\",\"columns\":[{\"id\":\"solution\",\"label\":\"AI Solution Architect\"},{\"id\":\"platform\",\"label\":\"AI Platform Architect\"}]},\"type\":\"comparison\"},{\"id\":\"h-simple\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-simple-1\",\"data\":{\"text\":\"Imagine an organization has five AI-enabled products: an internal document assistant, a customer-support copilot, a software-engineering agent, a contract review workflow and a product-search assistant. Each product could independently integrate model APIs, keep credentials, implement retries, collect token metrics, create retrieval code and build its own tool permissions.\"},\"type\":\"paragraph\"},{\"id\":\"p-simple-2\",\"data\":{\"text\":\"That duplication is expensive and dangerous when every team invents a different security and operational model. A shared platform can instead offer approved provider connections, model discovery, quotas, credentials, tenant-aware access, common telemetry, reusable retrieval services and an agent\u002Ftool runtime contract.\"},\"type\":\"paragraph\"},{\"id\":\"p-simple-3\",\"data\":{\"text\":\"But the platform must stop at the correct boundary. The contract-review solution may require legal-document authority and citation rules that the software agent does not. The product-search assistant may need commerce-specific freshness and authorization rules. \u003Cstrong>Reusable infrastructure does not make all domain truth reusable.\u003C\u002Fstrong>\"},\"type\":\"paragraph\"},{\"id\":\"simple-flow\",\"data\":{\"steps\":[{\"label\":\"1. Consumer identifies itself\",\"description\":\"The calling application, user, service, team or tenant enters through an authenticated identity and explicit scope.\"},{\"label\":\"2. Platform policy applies\",\"description\":\"Gateway and policy layers determine allowed providers, models, quotas, data paths, tools and execution modes.\"},{\"label\":\"3. Shared capability executes\",\"description\":\"The request may use inference, retrieval, agent runtime, tool access or another reusable platform service.\"},{\"label\":\"4. Solution-specific context remains authoritative\",\"description\":\"The consuming solution supplies domain rules, user intent, data authority, task-specific constraints and acceptance logic.\"},{\"label\":\"5. Telemetry and evidence are captured\",\"description\":\"The platform records identity, route, model\u002Fprovider, latency, cost, errors, tool activity and other permitted observability signals.\"},{\"label\":\"6. Result returns under the solution contract\",\"description\":\"The solution remains responsible for whether the output is acceptable for its user and domain.\"}],\"title\":\"A shared AI request path\",\"orientation\":\"auto\"},\"type\":\"processFlow\"},{\"id\":\"h-stops\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-stops-1\",\"data\":{\"text\":\"Centralization is not automatically architecture. A single endpoint in front of several model APIs is useful, but it does not by itself create an AI platform. A production platform also needs identity boundaries, capability contracts, provider health and lifecycle handling, quotas, secret ownership, observability, compatibility rules, security controls, release discipline and clear operational responsibility.\"},\"type\":\"paragraph\"},{\"id\":\"p-stops-2\",\"data\":{\"text\":\"The opposite failure is also common: putting every prompt, vector index, business rule, agent and application workflow into one “AI backend.” That creates a monolith whose shared status is accidental rather than architectural. \u003Cstrong>A platform should standardize cross-cutting capabilities, not absorb domain ownership merely because AI is involved.\u003C\u002Fstrong>\"},\"type\":\"paragraph\"},{\"id\":\"h-boundary\",\"data\":{\"text\":\"The most important platform decision: shared versus solution-specific\",\"level\":2},\"type\":\"header\"},{\"id\":\"shared-boundary-table\",\"data\":{\"content\":[[\"Capability area\",\"Good candidate for shared platform ownership\",\"Usually remains solution-specific\"],[\"Model access\",\"Approved provider connections, adapters, credentials, health, routing primitives, quotas\",\"Task-specific model acceptance, prompt behavior, quality threshold\"],[\"Retrieval\",\"Ingestion primitives, extraction, indexing, search APIs, provenance contracts, authorization hooks\",\"Authoritative corpus, freshness rules, domain metadata, evidence sufficiency\"],[\"Agents and tools\",\"Runtime lifecycle, tool registry\u002Fbroker, permission enforcement, tracing, cancellation\",\"Business workflow, allowed action semantics, escalation policy, task success\"],[\"Security\",\"Identity integration, secret storage, policy enforcement, audit contracts, tenant isolation mechanisms\",\"Data classification, business authorization rules, domain-specific risk acceptance\"],[\"Evaluation\",\"Harness, dataset\u002Fversion mechanics, telemetry, experiment\u002Frelease workflow\",\"Ground truth, domain test set, acceptance threshold, user outcome\"],[\"Operations\",\"Deployment pattern, health, metrics, incident integration, capacity controls\",\"Solution SLOs where they differ, business continuity impact, workload-specific runbooks\"]],\"stretched\":false,\"withHeadings\":true},\"type\":\"table\"},{\"id\":\"boundary-principle\",\"data\":{\"body\":\"\u003Cstrong>Share mechanics and controls where reuse is real; keep authority and acceptance where the domain owns them.\u003C\u002Fstrong> This prevents two opposite errors: duplicated infrastructure everywhere, and a central platform that falsely becomes the owner of every application's data, policy and quality.\",\"title\":\"Platform principle\",\"variant\":\"success\"},\"type\":\"callout\"},{\"id\":\"h-responsibility-map\",\"data\":{\"text\":\"Architecture responsibility map\",\"level\":2},\"type\":\"header\"},{\"id\":\"h-provider\",\"data\":{\"text\":\"1. Model and provider access\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-provider-1\",\"data\":{\"text\":\"A platform architect defines how consumers discover and invoke models without forcing every application to hard-code one provider. This includes provider adapters, model identifiers, capability metadata, authentication, health checks, endpoint configuration, request normalization and compatibility behavior.\"},\"type\":\"paragraph\"},{\"id\":\"p-provider-2\",\"data\":{\"text\":\"Provider abstraction must remain honest. Different providers expose different context limits, tool semantics, structured-output behavior, multimodal capabilities, safety controls, caching, pricing and failure modes. A good abstraction creates a stable platform contract while preserving access to capabilities that cannot be meaningfully flattened.\"},\"type\":\"paragraph\"},{\"id\":\"provider-warning\",\"data\":{\"body\":\"A lowest-common-denominator API can make migration easier but can also erase capabilities that matter. The architecture should define which features are portable, which are provider-specific and how consumers discover that difference.\",\"title\":\"Do not confuse abstraction with pretending providers are identical\",\"variant\":\"warning\"},\"type\":\"callout\"},{\"id\":\"h-gateway\",\"data\":{\"text\":\"2. Gateway, routing, quotas and cost controls\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-gateway-1\",\"data\":{\"text\":\"A shared AI gateway can centralize authentication, routing, throttling, retries, token limits, usage attribution and policy enforcement. Microsoft’s current AI Gateway guidance explicitly treats token-per-minute limits, quotas and multi-project containment as platform concerns; AWS likewise exposes account and model quotas and centralized controls.\"},\"type\":\"paragraph\"},{\"id\":\"p-gateway-2\",\"data\":{\"text\":\"The gateway is therefore more than a reverse proxy when it carries AI-specific policy and operational semantics. But it should not silently make business decisions. A routing policy may prefer a healthy local model, a lower-cost provider or a regionally compliant endpoint; whether that route is acceptable for a particular task is still a contract between platform and solution.\"},\"type\":\"paragraph\"},{\"id\":\"p-gateway-3\",\"data\":{\"text\":\"Routing also needs failure semantics. If the preferred model is unavailable, the platform must know whether fallback is permitted, whether a cloud route requires explicit consent, whether a lower-capability model is valid and how the decision is surfaced to observability.\"},\"type\":\"paragraph\"},{\"id\":\"h-data\",\"data\":{\"text\":\"3. Shared data, retrieval and grounding services\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-data-1\",\"data\":{\"text\":\"Retrieval services are strong platform candidates because parsing, chunking, indexing, lexical search, semantic search, metadata filtering, provenance and citation mechanics are reusable. However, the platform must not confuse a shared retrieval engine with a shared source of truth.\"},\"type\":\"paragraph\"},{\"id\":\"p-data-2\",\"data\":{\"text\":\"A solution still owns questions such as: Which corpus is authoritative? Which version is valid? Can this user see this document? How fresh must the data be? What counts as sufficient evidence? Can an answer be generated when retrieval fails? Those are domain and solution requirements even when the platform supplies the retrieval machinery.\"},\"type\":\"paragraph\"},{\"id\":\"p-data-3\",\"data\":{\"text\":\"This boundary is especially important in multi-tenant systems. A technically shared index or vector service does not justify cross-tenant visibility. Authorization context must be preserved through retrieval, not added only after search results have already crossed the boundary.\"},\"type\":\"paragraph\"},{\"id\":\"h-agent-runtime\",\"data\":{\"text\":\"4. Agent and tool runtime\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-agent-1\",\"data\":{\"text\":\"Agentic systems add reusable runtime concerns: thread\u002Fsession lifecycle, planning loops, tool registration, tool invocation, cancellation, timeouts, human approvals, memory\u002Fstate interfaces, remote-agent protocols and trace correlation. A platform can provide these mechanics so each product does not rebuild them.\"},\"type\":\"paragraph\"},{\"id\":\"p-agent-2\",\"data\":{\"text\":\"The platform must also keep tool permission separate from model capability. A model being capable of generating a shell command does not mean the runtime should allow shell execution. The permission boundary belongs to the application\u002Fruntime architecture and must be enforceable independently of the model.\"},\"type\":\"paragraph\"},{\"id\":\"p-agent-3\",\"data\":{\"text\":\"Current AWS Agentic AI guidance emphasizes bounded agents, explicit authority, end-to-end tracing, versioned behavioral artifacts and human oversight proportionate to consequence. Those are platform-enabling concerns, but the consuming solution still defines what actions are legitimate for its domain.\"},\"type\":\"paragraph\"},{\"id\":\"h-identity\",\"data\":{\"text\":\"5. Identity, tenant isolation and authorization\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-identity-1\",\"data\":{\"text\":\"AI platforms often sit in front of high-value models, proprietary data and action-capable tools. Authentication is therefore only the beginning. The architecture must carry user, service, application and tenant context through every privileged operation that needs it.\"},\"type\":\"paragraph\"},{\"id\":\"p-identity-2\",\"data\":{\"text\":\"\u003Cstrong>RBAC and tenant isolation solve different problems.\u003C\u002Fstrong> RBAC answers what an identity may do; tenant isolation answers which tenant’s resources that identity may act on. A platform that checks roles but loses tenant context can still expose the wrong data.\"},\"type\":\"paragraph\"},{\"id\":\"p-identity-3\",\"data\":{\"text\":\"Microsoft’s current AI workload guidance explicitly recommends identity segmentation and authorization-aware access to content. AWS’s multi-tenant generative AI platform guidance similarly treats logical isolation, centralized controls and auditability as platform concerns.\"},\"type\":\"paragraph\"},{\"id\":\"h-secrets\",\"data\":{\"text\":\"6. Secrets, credentials and trust boundaries\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-secrets-1\",\"data\":{\"text\":\"A platform should define who owns provider keys, remote bearer tokens, signing material and tool credentials, where they are stored, which process can access them, how they are rotated and whether they can ever reach a browser or untrusted renderer.\"},\"type\":\"paragraph\"},{\"id\":\"p-secrets-2\",\"data\":{\"text\":\"This is an architectural boundary, not an implementation detail. If every consuming application copies provider credentials into its own configuration, the organization has duplicated both operational burden and blast radius. Centralization can reduce that risk only if the platform itself has narrower, auditable access paths.\"},\"type\":\"paragraph\"},{\"id\":\"h-eval\",\"data\":{\"text\":\"7. Evaluation, observability and auditability\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-eval-1\",\"data\":{\"text\":\"A reusable platform can provide evaluation harnesses, trace IDs, model\u002Fprovider metadata, token and cost metrics, latency, error rates, prompt\u002Fmodel version linkage, agent\u002Ftool traces and controlled logging. AWS and Microsoft both treat observability and evaluation as core production concerns for AI workloads.\"},\"type\":\"paragraph\"},{\"id\":\"p-eval-2\",\"data\":{\"text\":\"Platform evaluation and solution evaluation must remain separate. A platform can verify that an endpoint is healthy, a model version passes a general regression suite and traces are complete. It cannot decide that a legal answer, medical workflow or product recommendation is acceptable without domain-specific ground truth and acceptance criteria.\"},\"type\":\"paragraph\"},{\"id\":\"p-eval-3\",\"data\":{\"text\":\"Logging also creates a privacy boundary. Prompt and response logs may contain sensitive or proprietary data. The platform architect must therefore decide what is logged, redacted, sampled, retained and accessible rather than assuming that more telemetry is always safer.\"},\"type\":\"paragraph\"},{\"id\":\"h-runtime\",\"data\":{\"text\":\"8. Runtime, deployment and locality\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-runtime-1\",\"data\":{\"text\":\"A platform architect decides how shared AI capabilities are deployed and reached: managed cloud services, self-hosted endpoints, local inference, hybrid routing, containerized services, desktop runtimes, private networking or air-gapped environments. The important distinction is between \u003Cstrong>where the control\u002Fruntime process runs\u003C\u002Fstrong> and \u003Cstrong>where inference and data processing actually occur\u003C\u002Fstrong>.\"},\"type\":\"paragraph\"},{\"id\":\"p-runtime-2\",\"data\":{\"text\":\"A local client may still call a cloud model. A cloud control plane may route to an on-premises model. A remote agent may execute tools inside a customer network. Architectural diagrams must therefore show trust and data-flow boundaries rather than using “local” and “cloud” as vague labels.\"},\"type\":\"paragraph\"},{\"id\":\"h-lifecycle\",\"data\":{\"text\":\"9. Platform lifecycle, compatibility and onboarding\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-lifecycle-1\",\"data\":{\"text\":\"Reusable capability becomes a platform only when consumers can depend on it over time. That requires versioned contracts, migration rules, compatibility policy, deprecation, release testing, rollback, incident ownership, capacity planning, documentation and a path for onboarding new teams or applications.\"},\"type\":\"paragraph\"},{\"id\":\"p-lifecycle-2\",\"data\":{\"text\":\"Fast-moving AI ecosystems make this particularly important. Model names, SDKs, protocol versions, provider APIs and safety capabilities change independently. A platform must absorb some of that volatility without hiding changes that materially affect a solution’s behavior.\"},\"type\":\"paragraph\"},{\"id\":\"h-control-plane\",\"data\":{\"text\":\"A practical control-plane \u002F execution-plane \u002F solution-plane model\",\"level\":2},\"type\":\"header\"},{\"id\":\"model-note\",\"data\":{\"body\":\"The three-plane model below is a practical way to reason about responsibilities; it is not an ISO, NIST, Microsoft or AWS standard. Its purpose is to make ownership boundaries explicit.\",\"title\":\"Proposed architecture model\",\"variant\":\"note\"},\"type\":\"callout\"},{\"id\":\"planes-table\",\"data\":{\"content\":[[\"Plane\",\"Typical responsibilities\",\"Should not silently own\"],[\"Platform control plane\",\"Provider registry, model policy, quotas, tenant configuration, identities, secrets, routing rules, capability versions, deployment configuration\",\"Application business logic or domain truth\"],[\"Platform execution\u002Fdata plane\",\"Inference requests, retrieval operations, agent\u002Ftool execution, extraction, indexing, telemetry emission, policy enforcement\",\"Cross-tenant access merely because infrastructure is shared\"],[\"Solution plane\",\"User workflow, prompts\u002Finstructions, authoritative corpus selection, domain authorization, business rules, task evaluation and acceptance\",\"Low-level provider integration that the platform explicitly owns\"]],\"stretched\":false,\"withHeadings\":true},\"type\":\"table\"},{\"id\":\"p-control-plane-1\",\"data\":{\"text\":\"This separation helps diagnose platform drift. If an application must know every provider-specific credential and endpoint, the platform contract is too thin. If the platform decides which customer record is legally authoritative or whether a domain answer is acceptable, the platform has crossed into solution ownership.\"},\"type\":\"paragraph\"},{\"id\":\"h-artifacts\",\"data\":{\"text\":\"What should an AI Platform Architect produce?\",\"level\":2},\"type\":\"header\"},{\"id\":\"artifacts-table\",\"data\":{\"content\":[[\"Architecture artifact\",\"Purpose\"],[\"Platform capability map\",\"Defines what the platform provides, who consumes it and which capabilities remain outside scope.\"],[\"Provider\u002Fmodel contract\",\"Defines providers, models, capabilities, abstraction boundaries, route metadata and fallback semantics.\"],[\"Identity and tenancy model\",\"Defines user\u002Fservice\u002Fapplication identity, tenant context, RBAC\u002FABAC hooks and resource isolation.\"],[\"Gateway and quota policy\",\"Defines rate limits, token\u002Fcost budgets, routing controls, retries and capacity behavior.\"],[\"Retrieval\u002Fdata contract\",\"Defines ingestion, provenance, search, metadata, authorization propagation and where domain authority remains.\"],[\"Agent\u002Ftool contract\",\"Defines runtime lifecycle, tool registration, permissions, approvals, cancellation and trace behavior.\"],[\"Secret and trust-boundary model\",\"Defines credential ownership, storage, process boundaries, rotation and sensitive data paths.\"],[\"Evaluation and telemetry contract\",\"Defines common metrics, traces, datasets\u002Fversion links, logging policy and solution extension points.\"],[\"Lifecycle and compatibility policy\",\"Defines versions, migrations, deprecation, releases, rollback, incident ownership and onboarding.\"]],\"stretched\":false,\"withHeadings\":true},\"type\":\"table\"},{\"id\":\"h-tradeoffs\",\"data\":{\"text\":\"The work is mostly trade-offs, not maximum centralization\",\"level\":2},\"type\":\"header\"},{\"id\":\"tradeoff-comparison\",\"data\":{\"rows\":[{\"id\":\"t1\",\"label\":\"Provider abstraction\",\"values\":{\"pressureA\":\"Stable portable platform API\",\"pressureB\":\"Access to provider-specific capabilities and fast innovation\"}},{\"id\":\"t2\",\"label\":\"Reuse\",\"values\":{\"pressureA\":\"Shared services reduce duplication\",\"pressureB\":\"Isolation and domain autonomy prevent unsafe coupling\"}},{\"id\":\"t3\",\"label\":\"Governance\",\"values\":{\"pressureA\":\"Central policy and auditability\",\"pressureB\":\"Team speed and local experimentation\"}},{\"id\":\"t4\",\"label\":\"Observability\",\"values\":{\"pressureA\":\"Rich traces for debugging and evaluation\",\"pressureB\":\"Privacy, data minimization and logging cost\"}},{\"id\":\"t5\",\"label\":\"Availability\",\"values\":{\"pressureA\":\"Fallback and multi-provider resilience\",\"pressureB\":\"Predictable quality, compliance and data-location guarantees\"}},{\"id\":\"t6\",\"label\":\"Platform scope\",\"values\":{\"pressureA\":\"More reusable capabilities\",\"pressureB\":\"Smaller blast radius and less platform lock-in\"}}],\"title\":\"Common platform trade-offs\",\"layout\":\"table\",\"columns\":[{\"id\":\"pressureA\",\"label\":\"Pressure A\"},{\"id\":\"pressureB\",\"label\":\"Pressure B\"}]},\"type\":\"comparison\"},{\"id\":\"h-adjacent\",\"data\":{\"text\":\"How is this different from adjacent roles?\",\"level\":2},\"type\":\"header\"},{\"id\":\"roles-table\",\"data\":{\"content\":[[\"Role\",\"Primary architectural scope\"],[\"AI Solution Architect\",\"A concrete AI-enabled solution and its end-to-end requirements, boundaries, trade-offs and production acceptance.\"],[\"AI Platform Architect\",\"Reusable AI capabilities and operational\u002Fsecurity contracts consumed across multiple solutions or teams.\"],[\"Enterprise Architect\",\"Organization-wide business\u002Ftechnology portfolio, capability and governance alignment at a broader level.\"],[\"MLOps \u002F LLMOps Architect or specialist\",\"Model and AI lifecycle, deployment, experiments, observability, release and operational practices; may overlap strongly but does not automatically own the whole shared application platform.\"],[\"Platform Engineer \u002F SRE\",\"Implements and operates platform infrastructure, reliability, automation and developer experience; architecture responsibility may be shared with the platform architect.\"],[\"AI \u002F Software Engineer\",\"Implements models, integrations, services, agents, retrieval and product functionality inside the agreed architecture.\"]],\"stretched\":false,\"withHeadings\":true},\"type\":\"table\"},{\"id\":\"p-adjacent-1\",\"data\":{\"text\":\"These boundaries are organizational, not universal. In a small team one person may hold several responsibilities. In a regulated enterprise they may be split across architecture, security, platform, data and operations groups. The useful distinction is the \u003Cstrong>scope of architectural responsibility\u003C\u002Fstrong>, not the job title printed on an org chart.\"},\"type\":\"paragraph\"},{\"id\":\"h-evidence\",\"data\":{\"text\":\"Implementation evidence: how these platform boundaries appear in my own work\",\"level\":2},\"type\":\"header\"},{\"id\":\"evidence-note\",\"data\":{\"body\":\"The following sections describe concrete patterns from my own projects. They are evidence that these architectural boundaries have been implemented or explicitly designed in real code and project systems. They are \u003Cstrong>not\u003C\u002Fstrong> claims that the projects together already constitute a commercially deployed enterprise AI platform.\",\"title\":\"Original implementation evidence\",\"variant\":\"note\"},\"type\":\"callout\"},{\"id\":\"h-ai-client\",\"data\":{\"text\":\"Aaasaasa AI Client: provider, runtime and permission separation\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-ai-client-1\",\"data\":{\"text\":\"Aaasaasa AI Client is a local-first desktop AI workspace built with Nuxt 4, Electron and TypeScript. Its AI Hub deliberately separates \u003Cstrong>agent\u002Fclient, provider, model, connection\u002Fruntime location, permissions and web client\u003C\u002Fstrong> instead of treating them as one configuration value.\"},\"type\":\"paragraph\"},{\"id\":\"p-ai-client-2\",\"data\":{\"text\":\"The implementation includes direct provider adapters, Codex agent runtime integration, local Ollama\u002FLM Studio paths, OpenAI-compatible services, centralized workspace permissions, main-process credential storage, DuckDB, Qdrant\u002Fvector support, PDF\u002Freadability extraction and authenticated MCP-based directory access.\"},\"type\":\"paragraph\"},{\"id\":\"p-ai-client-3\",\"data\":{\"text\":\"Two platform lessons are especially relevant. First, a local runtime is not the same as local inference: a local Codex process can still use a cloud model. Second, automatic routing does not silently fall back from local to paid cloud inference. That makes routing policy and runtime locality explicit rather than inferred from UI labels.\"},\"type\":\"paragraph\"},{\"id\":\"ai-client-evidence-table\",\"data\":{\"content\":[[\"Implemented boundary\",\"Platform-architecture meaning\"],[\"Agent vs provider vs model\",\"Different responsibilities can evolve independently instead of being hidden behind one “AI” selector.\"],[\"Permissions separate from model\",\"Filesystem\u002Ftool authority belongs to the runtime policy, not model capability.\"],[\"Main-process secrets\",\"Credential ownership follows the privileged process boundary rather than the renderer\u002FUI.\"],[\"Provider health and model discovery\",\"Routing and availability are runtime\u002Fplatform concerns.\"],[\"No silent cloud fallback\",\"Cost, locality and data-transfer semantics remain explicit policy decisions.\"]],\"stretched\":false,\"withHeadings\":true},\"type\":\"table\"},{\"id\":\"h-cms\",\"data\":{\"text\":\"Aaasaasa AI CMS: tenant-scoped authorization as a platform boundary\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-cms-1\",\"data\":{\"text\":\"The Aaasaasa AI CMS codebase provides a separate implementation example: tenant-scoped RBAC is represented through roles, permissions and user-role assignments bound to a tenant identifier. System permissions are grouped by capability, and role lookup and updates remain tenant-scoped.\"},\"type\":\"paragraph\"},{\"id\":\"p-cms-2\",\"data\":{\"text\":\"This is not itself proof of a complete AI platform, but it is directly relevant to one of the hardest shared-platform boundaries: a reusable service must preserve \u003Cstrong>who may do what\u003C\u002Fstrong> and \u003Cstrong>for which tenant\u003C\u002Fstrong>. Adding AI inference or retrieval on top of an application platform does not remove that requirement.\"},\"type\":\"paragraph\"},{\"id\":\"p-cms-3\",\"data\":{\"text\":\"The architectural implication is that model gateways, retrieval services and agents should consume established identity\u002Ftenant context rather than inventing a parallel AI-only authorization universe.\"},\"type\":\"paragraph\"},{\"id\":\"h-sot\",\"data\":{\"text\":\"Source of Truth Research Engine: shared retrieval mechanics without shared truth\",\"level\":3},\"type\":\"header\"},{\"id\":\"p-sot-1\",\"data\":{\"text\":\"The Source of Truth Research Engine provides a third implementation example. Different research modes share a common evidence core: Sources, Artifacts, provenance, Claims, Relations, Contradictions, a Reference Model and audit trail. The system also provides local lexical retrieval, optional semantic retrieval, extraction, snapshots and SHA-256-based provenance.\"},\"type\":\"paragraph\"},{\"id\":\"p-sot-2\",\"data\":{\"text\":\"The project explicitly treats search and semantic similarity as discovery signals rather than evidence. A result must be traced back to a concrete source and locator before it can support a claim. This is precisely the distinction an AI platform needs: \u003Cstrong>reusable retrieval machinery can be shared while evidence authority remains governed by the consuming methodology and domain.\u003C\u002Fstrong>\"},\"type\":\"paragraph\"},{\"id\":\"p-sot-3\",\"data\":{\"text\":\"The engine also demonstrates why one shared platform does not require one shared interpretation. Historical, scientific\u002Ftechnical, market-intelligence and monitoring modes can reuse core evidence infrastructure while retaining mode-specific methodology.\"},\"type\":\"paragraph\"},{\"id\":\"evidence-synthesis\",\"data\":{\"body\":\"Across these projects, the reusable pattern is not “one backend for everything.” It is \u003Cstrong>separation of concerns plus explicit contracts\u003C\u002Fstrong>: provider\u002Fmodel\u002Fruntime separation, tenant-aware authorization, credential boundaries, reusable data\u002Fretrieval primitives, provenance, and domain-specific authority. A future integrated platform would need stable contracts between those capabilities rather than direct coupling between codebases.\",\"title\":\"What these implementations demonstrate together\",\"variant\":\"success\"},\"type\":\"callout\"},{\"id\":\"h-frameworks\",\"data\":{\"text\":\"How current architecture guidance supports this platform scope\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-frameworks-1\",\"data\":{\"text\":\"ISO\u002FIEC\u002FIEEE 42010:2022 provides a general discipline for architecture descriptions across software, systems, enterprises and related entities. It does not define an AI Platform Architect, but it reinforces the need to express architectural concerns, relationships and viewpoints rather than reducing architecture to a technology list.\"},\"type\":\"paragraph\"},{\"id\":\"p-frameworks-2\",\"data\":{\"text\":\"NIST AI RMF 1.0 and the Generative AI Profile frame AI risk management across the lifecycle rather than only at model selection time. Governance, mapping, measurement and management are therefore compatible with a platform architecture that carries shared controls and evidence across many consuming workloads.\"},\"type\":\"paragraph\"},{\"id\":\"p-frameworks-3\",\"data\":{\"text\":\"Microsoft’s current AI workload guidance treats application design, data, security, operations, testing\u002Fevaluation and GenAIOps as connected architectural areas. Its current AI Gateway guidance also shows practical platform concerns such as centralized model access, project-specific token limits, quotas and multi-team containment.\"},\"type\":\"paragraph\"},{\"id\":\"p-frameworks-4\",\"data\":{\"text\":\"AWS’s current Generative AI Lens and multi-tenant platform scenario similarly separate foundational platform controls from consuming-application ownership. AWS explicitly notes that a central platform can enforce shared guardrails and auditability while data quality and workload-specific observability still remain responsibilities of consuming applications or data producers.\"},\"type\":\"paragraph\"},{\"id\":\"p-frameworks-5\",\"data\":{\"text\":\"The vendor products differ, but the cross-source pattern is stable: production AI platforms must coordinate identity, data access, models, policy, evaluation, observability, capacity, cost and lifecycle. A GPU cluster or model endpoint covers only part of that responsibility.\"},\"type\":\"paragraph\"},{\"id\":\"h-misconceptions\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"type\":\"header\"},{\"id\":\"misconceptions-table\",\"data\":{\"content\":[[\"Misconception\",\"Why it is wrong\"],[\"“An AI platform is the GPU cluster.”\",\"Compute is one substrate. A platform also needs contracts for identity, model access, data, policy, evaluation, observability and lifecycle.\"],[\"“An AI gateway is just a reverse proxy.”\",\"It may also carry model routing, token quotas, cost attribution, policy enforcement, identity and AI-specific telemetry.\"],[\"“Shared means globally shared.”\",\"A service may be physically shared while logically segmented by tenant, application, region, classification or risk level.\"],[\"“One central vector database becomes the company truth.”\",\"A vector store or retrieval service is infrastructure. Domain authority, freshness, provenance and access remain separate concerns.\"],[\"“Platform evaluation replaces solution evaluation.”\",\"General regression and telemetry cannot define whether a domain-specific answer or action is acceptable.\"],[\"“Provider abstraction should hide every difference.”\",\"Some differences are material capabilities, security semantics or failure modes and must remain visible.\"],[\"“RBAC solves multi-tenancy.”\",\"RBAC controls actions; tenant isolation controls resource boundaries. Both can be required.\"],[\"“AI Platform Architect is just another name for MLOps.”\",\"MLOps\u002FLLMOps is a major overlapping discipline, but shared application\u002Fruntime, identity, gateway, retrieval and tool boundaries can extend beyond model lifecycle operations.\"]],\"stretched\":false,\"withHeadings\":true},\"type\":\"table\"},{\"id\":\"h-failure\",\"data\":{\"text\":\"Failure modes an AI Platform Architect should prevent\",\"level\":2},\"type\":\"header\"},{\"id\":\"failures-table\",\"data\":{\"content\":[[\"Failure mode\",\"Architectural consequence\"],[\"Every team stores its own provider keys\",\"Duplicated secret handling, inconsistent rotation and larger blast radius.\"],[\"Provider abstraction hides required capabilities\",\"Consumers cannot use features they need or silently receive behavior different from assumptions.\"],[\"Shared retrieval ignores tenant\u002Fuser context\",\"Cross-boundary data leakage can occur before the application gets a chance to filter results.\"],[\"Fallback silently changes provider or locality\",\"Cost, compliance, data location and output quality can change without the caller knowing.\"],[\"Agent tools are granted by model choice\",\"A capable model becomes over-privileged because runtime authority is not independently enforced.\"],[\"All prompts\u002Fresponses are logged by default\",\"Observability can create a new sensitive-data repository and compliance problem.\"],[\"Platform owns one generic quality score\",\"Domain failures remain hidden behind platform health metrics.\"],[\"No version contract for platform capabilities\",\"Model\u002Fprovider\u002Fruntime changes break consumers unpredictably.\"],[\"Everything AI-related is centralized\",\"The platform becomes a bottleneck and monolith instead of a reusable capability layer.\"]],\"stretched\":false,\"withHeadings\":true},\"type\":\"table\"},{\"id\":\"h-decision\",\"data\":{\"text\":\"A practical platform-architecture decision sequence\",\"level\":2},\"type\":\"header\"},{\"id\":\"decision-flow\",\"data\":{\"steps\":[{\"label\":\"1. Identify real consumers\",\"description\":\"List solutions, teams, tenants and workloads that would consume the platform; avoid building a platform for hypothetical reuse.\"},{\"label\":\"2. Define the shared boundary\",\"description\":\"Separate cross-cutting mechanics from solution-specific domain authority, workflow and acceptance.\"},{\"label\":\"3. Define identity and isolation first\",\"description\":\"Establish users, services, applications, tenants, regions and data classifications before sharing retrieval or tool capabilities.\"},{\"label\":\"4. Define capability contracts\",\"description\":\"Specify model\u002Fprovider, retrieval, agent\u002Ftool, gateway and telemetry APIs with explicit ownership and versioning.\"},{\"label\":\"5. Decide provider and runtime strategy\",\"description\":\"Choose managed, self-hosted, local or hybrid execution and document fallback, locality and capability semantics.\"},{\"label\":\"6. Design data and retrieval boundaries\",\"description\":\"Define provenance, authorization propagation, corpus ownership, indexing and evidence responsibilities.\"},{\"label\":\"7. Add quotas, secrets and policy\",\"description\":\"Control cost, capacity, credentials, tool permissions, safety controls and blast radius.\"},{\"label\":\"8. Build evaluation and observability contracts\",\"description\":\"Provide platform metrics and tracing while leaving domain ground truth and acceptance to the solution.\"},{\"label\":\"9. Define lifecycle and operations\",\"description\":\"Version capabilities, test upgrades, document deprecation, rollback, incidents, capacity and consumer onboarding.\"},{\"label\":\"10. Validate with more than one consumer\",\"description\":\"A platform claim becomes credible when the shared capability actually serves distinct workloads without forcing them into the same domain model.\"}],\"title\":\"From platform need to operable shared capability\",\"orientation\":\"auto\"},\"type\":\"processFlow\"},{\"id\":\"h-edge\",\"data\":{\"text\":\"Edge cases and limits of the role\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-edge-1\",\"data\":{\"text\":\"A small organization with one AI application may not need a distinct AI platform or platform architect. Premature platforming can create more abstraction than value. The correct architecture may be one well-designed solution with a few reusable modules.\"},\"type\":\"paragraph\"},{\"id\":\"p-edge-2\",\"data\":{\"text\":\"An air-gapped or sovereign deployment changes the provider, update and observability model substantially. Model hosting, artifact distribution, identity integration and telemetry export may all need local equivalents.\"},\"type\":\"paragraph\"},{\"id\":\"p-edge-3\",\"data\":{\"text\":\"Highly regulated or high-consequence workloads may require stronger physical or organizational isolation instead of a logically shared platform. Reuse is never a sufficient reason to weaken a required security boundary.\"},\"type\":\"paragraph\"},{\"id\":\"p-edge-4\",\"data\":{\"text\":\"Managed cloud AI services can remove implementation burden but do not remove architectural accountability. The organization still decides identity, data access, logging, retention, quotas, model eligibility, fallback, evaluation and solution acceptance.\"},\"type\":\"paragraph\"},{\"id\":\"p-edge-5\",\"data\":{\"text\":\"The platform boundary may also differ by modality. Text inference, multimodal generation, speech, computer use and autonomous agents can have different latency, data, permission and observability requirements even when they share provider and identity infrastructure.\"},\"type\":\"paragraph\"},{\"id\":\"h-change\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-change-1\",\"data\":{\"text\":\"The core definition would change if the organizational scope changes. If the architect owns one workload, the role becomes closer to AI Solution Architect. If the responsibility expands to organization-wide capability strategy, investment, standards and target-state portfolios, it moves toward Enterprise AI Architecture.\"},\"type\":\"paragraph\"},{\"id\":\"p-change-2\",\"data\":{\"text\":\"Implementation guidance changes whenever providers, gateway products, agent protocols, regulatory obligations, model capabilities or deployment constraints change. That is why platform architecture should express stable responsibilities and contracts separately from current vendor mechanisms.\"},\"type\":\"paragraph\"},{\"id\":\"h-checklist\",\"data\":{\"text\":\"AI Platform Architect checklist\",\"level\":2},\"type\":\"header\"},{\"id\":\"checklist-table\",\"data\":{\"content\":[[\"Question\",\"Expected answer\"],[\"Who are the actual platform consumers?\",\"Named solutions, teams or tenant contexts with distinct but overlapping needs.\"],[\"What is genuinely shared?\",\"Explicit capability list, not a vague “AI backend.”\"],[\"What must remain solution-specific?\",\"Domain authority, business workflow, task acceptance and other workload-owned concerns.\"],[\"How are models\u002Fproviders represented?\",\"Versioned provider\u002Fmodel contracts with capabilities and explicit fallback semantics.\"],[\"How is identity propagated?\",\"User\u002Fservice\u002Fapplication\u002Ftenant context survives every privileged request path.\"],[\"How is tenant isolation enforced?\",\"Resource scoping is separate from role permission checks.\"],[\"How are secrets handled?\",\"Privileged storage, rotation, limited exposure and auditable ownership.\"],[\"How does retrieval preserve authority?\",\"Shared mechanics with authorization, provenance and domain-owned evidence rules.\"],[\"How are tools and agents constrained?\",\"Runtime permissions, bounded tool contracts, approvals, cancellation and traceability.\"],[\"How are cost and capacity controlled?\",\"Quotas, token\u002Frate controls, usage attribution and overload behavior.\"],[\"How is quality measured?\",\"Platform regression\u002Fevaluation plus solution-specific ground truth and acceptance.\"],[\"How are changes rolled out?\",\"Versioning, compatibility, migration, deprecation, rollback and incident ownership.\"]],\"stretched\":false,\"withHeadings\":true},\"type\":\"table\"},{\"id\":\"h-conclusion\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-conclusion-1\",\"data\":{\"text\":\"An AI Platform Architect is responsible for the reusable architecture \u003Cstrong>between AI capabilities and the solutions that consume them\u003C\u002Fstrong>. The role defines how models, providers, retrieval, agents, tools, identity, tenants, secrets, evaluation, observability, quotas and runtime operations become dependable platform services rather than repeated one-off integrations.\"},\"type\":\"paragraph\"},{\"id\":\"p-conclusion-2\",\"data\":{\"text\":\"The difficult part is not maximizing reuse. It is choosing the correct boundary. A strong platform standardizes mechanics, policy and operations where multiple consumers genuinely benefit, while preserving solution-specific data authority, business logic, security requirements and acceptance criteria.\"},\"type\":\"paragraph\"},{\"id\":\"p-conclusion-3\",\"data\":{\"text\":\"That distinction also explains the relationship with AI Solution Architecture: \u003Cstrong>the solution architect makes one AI-enabled system fit its purpose; the platform architect makes shared AI capabilities safe, reusable, operable and evolvable across many such systems.\u003C\u002Fstrong>\"},\"type\":\"paragraph\"},{\"id\":\"h-related\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-related-1\",\"data\":{\"text\":\"This article sits after the canonical foundations on generative AI components, ADR versus NFR, and AI Solution Architecture. Those concepts are prerequisites because a platform exists to provide reusable system capabilities and to encode architectural decisions against explicit quality and operational requirements.\"},\"type\":\"paragraph\"},{\"id\":\"p-related-2\",\"data\":{\"text\":\"Retrieval-Augmented Generation is one example of a capability that may be offered through a platform, but the platform should not collapse retrieval infrastructure, domain knowledge and answer validity into one concept.\"},\"type\":\"paragraph\"},{\"id\":\"related-rag\",\"data\":{\"link\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"What Is RAG? The Simplest Explanation of How It Works\",\"description\":\"Canonical introduction to retrieval-augmented generation and the boundary between model generation and external knowledge retrieval.\"}},\"type\":\"linkTool\"},{\"id\":\"p-related-3\",\"data\":{\"text\":\"Agent protocols, tenant isolation, AI governance, model routing, Context Engineering and MLOps\u002FLLMOps are downstream or adjacent knowledge nodes. They become easier to reason about once the platform boundary is explicit.\"},\"type\":\"paragraph\"},{\"id\":\"h-faq\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"type\":\"header\"},{\"id\":\"faq\",\"data\":{\"items\":[{\"id\":\"faq-1\",\"answer\":\"No. The solution architect focuses on one concrete AI-enabled solution. The platform architect focuses on reusable AI capabilities, controls and operational contracts that can support multiple solutions.\",\"question\":\"Is an AI Platform Architect the same as an AI Solution Architect?\"},{\"id\":\"faq-2\",\"answer\":\"No. A platform can use managed cloud models, self-hosted models, local inference or a hybrid strategy. The architecture must make provider, locality, identity, routing, data and operational consequences explicit.\",\"question\":\"Does an AI platform need to host its own models?\"},{\"id\":\"faq-3\",\"answer\":\"Usually not. A gateway can be an important platform component, but a complete platform also needs contracts for identity, secrets, data\u002Fretrieval, evaluation, observability, lifecycle and operational ownership.\",\"question\":\"Is an AI gateway enough to be an AI platform?\"},{\"id\":\"faq-4\",\"answer\":\"Retrieval mechanics can often be shared, but domain authority, authorization, freshness, evidence sufficiency and corpus ownership should remain explicit. Shared infrastructure does not imply shared truth.\",\"question\":\"Should retrieval be centralized?\"},{\"id\":\"faq-5\",\"answer\":\"No. Platform evaluation can test shared capabilities and regressions. Each solution still needs task-specific ground truth, acceptance criteria and domain quality thresholds.\",\"question\":\"Does platform evaluation replace application evaluation?\"},{\"id\":\"faq-6\",\"answer\":\"No. RBAC determines what an identity may do. Tenant isolation determines which tenant's resources the identity may act on. A platform often needs both.\",\"question\":\"Is multi-tenancy just RBAC?\"}],\"title\":\"AI Platform Architect FAQ\"},\"type\":\"faq\"},{\"id\":\"h-glossary\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"type\":\"header\"},{\"id\":\"glossary\",\"data\":{\"title\":\"Key AI platform architecture terms\",\"entries\":[{\"term\":\"AI platform\",\"anchor\":\"ai-platform\",\"definition\":\"A reusable set of AI-related technical and operational capabilities consumed by multiple applications, teams or tenant contexts.\"},{\"term\":\"AI gateway\",\"anchor\":\"ai-gateway\",\"definition\":\"A gateway layer for AI endpoints that may add authentication, routing, quotas, policy, retries, cost attribution and AI-specific telemetry beyond basic proxying.\"},{\"term\":\"Provider adapter\",\"anchor\":\"provider-adapter\",\"definition\":\"A component that maps a platform contract to a model provider's API, capabilities, health and failure semantics.\"},{\"term\":\"Tenant isolation\",\"anchor\":\"tenant-isolation\",\"definition\":\"The boundary that prevents one tenant context from accessing another tenant's resources, independent of role permissions.\"},{\"term\":\"Capability contract\",\"anchor\":\"capability-contract\",\"definition\":\"A versioned interface and behavioral agreement describing what a shared platform service provides and what the consumer must supply or own.\"},{\"term\":\"Grounding \u002F retrieval service\",\"anchor\":\"grounding-service\",\"definition\":\"Shared mechanics for finding and supplying external information to an AI workload; it does not automatically define which information is authoritative for a domain.\"},{\"term\":\"Evaluation harness\",\"anchor\":\"evaluation-harness\",\"definition\":\"Reusable infrastructure for running tests, datasets, model\u002Fprompt versions and metrics; domain acceptance remains solution-specific.\"},{\"term\":\"Control plane\",\"anchor\":\"control-plane\",\"definition\":\"The configuration and governance layer that manages platform capabilities, identities, policies, quotas, versions and deployment state.\"}]},\"type\":\"glossary\"},{\"id\":\"h-sources\",\"data\":{\"text\":\"Primary sources and current architecture guidance\",\"level\":2},\"type\":\"header\"},{\"id\":\"p-sources-note\",\"data\":{\"text\":\"The sources below support the general architecture and production-platform claims. The Aaasaasa AI Client, Aaasaasa AI CMS and Source of Truth Research Engine sections are explicitly original implementation evidence. Current-state external references were checked on 8 October 2026.\"},\"type\":\"paragraph\"},{\"id\":\"src-iso-42010\",\"data\":{\"link\":\"https:\u002F\u002Fwww.iso.org\u002Fstandard\u002F74393.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"ISO\u002FIEC\u002FIEEE 42010:2022 — Architecture Description\",\"description\":\"Current published international standard for architecture-description concepts and relationships.\"}},\"type\":\"linkTool\"},{\"id\":\"src-nist-rmf\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fai-risk-management-framework\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST AI Risk Management Framework\",\"description\":\"NIST's AI RMF resources and current status; AI RMF 1.0 is under revision as of October 2026.\"}},\"type\":\"linkTool\"},{\"id\":\"src-nist-gai\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fartificial-intelligence-risk-management-framework-generative-artificial-intelligence\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST AI 600-1 — Generative AI Profile\",\"description\":\"Generative AI profile for applying AI risk-management considerations across the AI lifecycle.\"}},\"type\":\"linkTool\"},{\"id\":\"src-ms-ai\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fget-started\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft Azure Well-Architected — AI Workloads\",\"description\":\"Current architectural guidance covering AI application, data, operations, evaluation, responsible AI and lifecycle concerns.\"}},\"type\":\"linkTool\"},{\"id\":\"src-ms-principles\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fwell-architected\u002Fai\u002Fdesign-principles\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft — Design Principles for AI Workloads\",\"description\":\"Current guidance on identity segmentation, security boundaries, telemetry, performance, data and platform trade-offs.\"}},\"type\":\"linkTool\"},{\"id\":\"src-ms-gateway\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Fai-foundry\u002Fconfiguration\u002Fenable-ai-api-management-gateway-portal?view=foundry\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Microsoft Foundry — AI Gateway Architecture\",\"description\":\"Current AI Gateway guidance for shared project access, token containment, quotas and governance.\"}},\"type\":\"linkTool\"},{\"id\":\"src-ms-gateway-guide\",\"data\":{\"link\":\"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fazure\u002Farchitecture\u002Fai-ml\u002Fguide\u002Fazure-openai-gateway-guide\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Azure Architecture Center — Access Models Through a Gateway\",\"description\":\"Architecture guidance for centralized model access, routing, throttling, failover and client\u002Fplatform responsibilities.\"}},\"type\":\"linkTool\"},{\"id\":\"src-aws-genai\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fgenerative-ai-lens\u002F\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"AWS Well-Architected — Generative AI Lens\",\"description\":\"Current production architecture guidance for generative AI workloads across security, reliability, operations, performance and cost.\"}},\"type\":\"linkTool\"},{\"id\":\"src-aws-multitenant\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fgenerative-ai-lens\u002Fmulti-tenant-generative-ai-platform-scenario.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"AWS — Multi-tenant Generative AI Platform Scenario\",\"description\":\"Current example separating central platform controls and auditability from consuming-application data quality and workload-specific responsibilities.\"}},\"type\":\"linkTool\"},{\"id\":\"src-aws-agentic\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.aws.amazon.com\u002Fwellarchitected\u002Flatest\u002Fagentic-ai-lens\u002Fdesign-principles.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"AWS Well-Architected — Agentic AI Design Principles\",\"description\":\"Current guidance on bounded agent authority, traceability, versioned behavior, explicit contracts and human oversight.\"}},\"type\":\"linkTool\"},{\"id\":\"src-aws-observability\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.aws.amazon.com\u002FAmazonCloudWatch\u002Flatest\u002Fmonitoring\u002FGenAI-observability.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"AWS CloudWatch — Generative AI Observability\",\"description\":\"Current observability capabilities and production metrics for models, agents, knowledge bases, tools and cost\u002Flatency\u002Ferror analysis.\"}},\"type\":\"linkTool\"}],\"version\":\"2.31.0\"}",{"time":1242,"blocks":1243,"version":2013},1791476955677,[1244,1247,1251,1255,1259,1262,1265,1268,1271,1295,1298,1301,1304,1307,1329,1332,1335,1338,1341,1371,1375,1378,1381,1384,1387,1391,1394,1397,1400,1403,1406,1409,1412,1415,1418,1421,1424,1427,1430,1433,1436,1439,1442,1445,1448,1451,1454,1457,1460,1463,1466,1469,1472,1475,1478,1481,1485,1504,1507,1510,1543,1546,1573,1576,1598,1601,1604,1608,1611,1614,1617,1620,1641,1644,1647,1650,1653,1656,1659,1662,1665,1669,1672,1675,1678,1681,1684,1687,1690,1720,1723,1756,1759,1793,1796,1799,1802,1805,1808,1811,1814,1817,1820,1823,1865,1868,1871,1874,1877,1880,1883,1886,1893,1896,1899,1920,1923,1947,1950,1953,1959,1964,1969,1974,1979,1984,1989,1995,2001,2007],{"id":215,"data":1245,"type":218},{"text":1246},"An \u003Cstrong>AI Platform Architect\u003C\u002Fstrong> designs the reusable AI foundation through which multiple applications, teams, or tenant contexts access models, data and retrieval, agent and tool runtimes, identity and permissions, evaluation, observability, quotas, secrets, and deployment capabilities. The role is broader than infrastructure but narrower than owning every AI-enabled product: its central responsibility is deciding \u003Cstrong>what should be shared, how shared capabilities are governed and isolated, and what must remain solution-specific\u003C\u002Fstrong>.",{"id":220,"data":1248,"type":225},{"body":1249,"title":1250,"variant":224},"\u003Cstrong>An AI Platform Architect designs the shared technical and operational substrate for AI systems.\u003C\u002Fstrong> Instead of architecting one assistant or one workflow, the role defines reusable contracts and boundaries for model\u002Fprovider access, gateways and routing, retrieval services, agent runtimes, tool access, identity and tenant isolation, secrets, evaluation, telemetry, deployment and lifecycle management.","Direct answer",{"id":227,"data":1252,"type":225},{"body":1253,"title":1254,"variant":231},"\u003Cstrong>AI Platform Architect is a practical role label, not a universally standardized job title.\u003C\u002Fstrong> ISO\u002FIEC\u002FIEEE 42010:2022 defines concepts for architecture descriptions, not this role. Different organizations may split these responsibilities among platform architects, solution architects, enterprise architects, security architects, MLOps\u002FLLMOps specialists and platform engineering teams. This article uses the term for the architecture responsibility over a reusable AI platform layer.","Terminology note",{"id":233,"data":1256,"type":225},{"body":1257,"title":1258,"variant":231},"The stable architectural principles here are vendor-neutral. Current Microsoft, AWS and NIST guidance is used as external implementation and governance evidence. NIST states that AI RMF 1.0 is being revised; vendor platform features, gateway products, agent runtimes and model capabilities evolve faster than the architectural principles, so version-sensitive implementation choices must be rechecked before deployment.","Current-source note — 8 October 2026",{"id":238,"data":1260,"type":243},{"title":1261,"maxLevel":241,"minLevel":242},"Contents",{"id":245,"data":1263,"type":42},{"text":1264,"level":242},"What does an AI Platform Architect actually architect?",{"id":249,"data":1266,"type":218},{"text":1267},"The object of the work is the \u003Cstrong>platform\u003C\u002Fstrong>: a set of shared capabilities that reduces repeated integration work while preserving explicit security, data and operational boundaries. A platform can expose model access, provider adapters, retrieval primitives, agent execution, tool brokers, policy enforcement, evaluation, telemetry and deployment services to many consuming solutions.",{"id":253,"data":1269,"type":218},{"text":1270},"The platform is not valuable merely because components are centralized. It is valuable when consumers receive stable capabilities with clear contracts, ownership, isolation, observability and lifecycle rules. The key architectural question is therefore not “Which model should everyone use?” but \u003Cstrong>“Which responsibilities can be safely standardized and reused without erasing the requirements of each solution?”\u003C\u002Fstrong>.",{"id":257,"data":1272,"type":299},{"rows":1273,"title":1289,"layout":291,"columns":1290},[1274,1277,1280,1283,1286],{"id":261,"label":1275,"values":1276},"Primary scope",{"platform":264,"solution":265},{"id":267,"label":1278,"values":1279},"Main question",{"platform":270,"solution":271},{"id":273,"label":1281,"values":1282},"Data authority",{"platform":276,"solution":277},{"id":279,"label":1284,"values":1285},"Evaluation",{"platform":282,"solution":283},{"id":285,"label":1287,"values":1288},"Lifecycle",{"platform":288,"solution":289},"Solution architecture and platform architecture solve different scope problems",[1291,1293],{"id":294,"label":1292},"AI Solution Architect",{"id":297,"label":1294},"AI Platform Architect",{"id":301,"data":1296,"type":42},{"text":1297,"level":242},"The simplest example",{"id":305,"data":1299,"type":218},{"text":1300},"Imagine an organization has five AI-enabled products: an internal document assistant, a customer-support copilot, a software-engineering agent, a contract review workflow and a product-search assistant. Each product could independently integrate model APIs, keep credentials, implement retries, collect token metrics, create retrieval code and build its own tool permissions.",{"id":309,"data":1302,"type":218},{"text":1303},"That duplication is expensive and dangerous when every team invents a different security and operational model. A shared platform can instead offer approved provider connections, model discovery, quotas, credentials, tenant-aware access, common telemetry, reusable retrieval services and an agent\u002Ftool runtime contract.",{"id":313,"data":1305,"type":218},{"text":1306},"But the platform must stop at the correct boundary. The contract-review solution may require legal-document authority and citation rules that the software agent does not. The product-search assistant may need commerce-specific freshness and authorization rules. \u003Cstrong>Reusable infrastructure does not make all domain truth reusable.\u003C\u002Fstrong>",{"id":317,"data":1308,"type":340},{"steps":1309,"title":1328,"orientation":339},[1310,1313,1316,1319,1322,1325],{"label":1311,"description":1312},"1. Consumer identifies itself","The calling application, user, service, team or tenant enters through an authenticated identity and explicit scope.",{"label":1314,"description":1315},"2. Platform policy applies","Gateway and policy layers determine allowed providers, models, quotas, data paths, tools and execution modes.",{"label":1317,"description":1318},"3. Shared capability executes","The request may use inference, retrieval, agent runtime, tool access or another reusable platform service.",{"label":1320,"description":1321},"4. Solution-specific context remains authoritative","The consuming solution supplies domain rules, user intent, data authority, task-specific constraints and acceptance logic.",{"label":1323,"description":1324},"5. Telemetry and evidence are captured","The platform records identity, route, model\u002Fprovider, latency, cost, errors, tool activity and other permitted observability signals.",{"label":1326,"description":1327},"6. Result returns under the solution contract","The solution remains responsible for whether the output is acceptable for its user and domain.","A shared AI request path",{"id":342,"data":1330,"type":42},{"text":1331,"level":242},"Where the simple example stops",{"id":346,"data":1333,"type":218},{"text":1334},"Centralization is not automatically architecture. A single endpoint in front of several model APIs is useful, but it does not by itself create an AI platform. A production platform also needs identity boundaries, capability contracts, provider health and lifecycle handling, quotas, secret ownership, observability, compatibility rules, security controls, release discipline and clear operational responsibility.",{"id":350,"data":1336,"type":218},{"text":1337},"The opposite failure is also common: putting every prompt, vector index, business rule, agent and application workflow into one “AI backend.” That creates a monolith whose shared status is accidental rather than architectural. \u003Cstrong>A platform should standardize cross-cutting capabilities, not absorb domain ownership merely because AI is involved.\u003C\u002Fstrong>",{"id":354,"data":1339,"type":42},{"text":1340,"level":242},"The most important platform decision: shared versus solution-specific",{"id":358,"data":1342,"type":291},{"content":1343,"stretched":43,"withHeadings":14},[1344,1348,1352,1356,1360,1364,1367],[1345,1346,1347],"Capability area","Good candidate for shared platform ownership","Usually remains solution-specific",[1349,1350,1351],"Model access","Approved provider connections, adapters, credentials, health, routing primitives, quotas","Task-specific model acceptance, prompt behavior, quality threshold",[1353,1354,1355],"Retrieval","Ingestion primitives, extraction, indexing, search APIs, provenance contracts, authorization hooks","Authoritative corpus, freshness rules, domain metadata, evidence sufficiency",[1357,1358,1359],"Agents and tools","Runtime lifecycle, tool registry\u002Fbroker, permission enforcement, tracing, cancellation","Business workflow, allowed action semantics, escalation policy, task success",[1361,1362,1363],"Security","Identity integration, secret storage, policy enforcement, audit contracts, tenant isolation mechanisms","Data classification, business authorization rules, domain-specific risk acceptance",[1284,1365,1366],"Harness, dataset\u002Fversion mechanics, telemetry, experiment\u002Frelease workflow","Ground truth, domain test set, acceptance threshold, user outcome",[1368,1369,1370],"Operations","Deployment pattern, health, metrics, incident integration, capacity controls","Solution SLOs where they differ, business continuity impact, workload-specific runbooks",{"id":389,"data":1372,"type":225},{"body":1373,"title":1374,"variant":393},"\u003Cstrong>Share mechanics and controls where reuse is real; keep authority and acceptance where the domain owns them.\u003C\u002Fstrong> This prevents two opposite errors: duplicated infrastructure everywhere, and a central platform that falsely becomes the owner of every application's data, policy and quality.","Platform principle",{"id":395,"data":1376,"type":42},{"text":1377,"level":242},"Architecture responsibility map",{"id":399,"data":1379,"type":42},{"text":1380,"level":241},"1. Model and provider access",{"id":403,"data":1382,"type":218},{"text":1383},"A platform architect defines how consumers discover and invoke models without forcing every application to hard-code one provider. This includes provider adapters, model identifiers, capability metadata, authentication, health checks, endpoint configuration, request normalization and compatibility behavior.",{"id":407,"data":1385,"type":218},{"text":1386},"Provider abstraction must remain honest. Different providers expose different context limits, tool semantics, structured-output behavior, multimodal capabilities, safety controls, caching, pricing and failure modes. A good abstraction creates a stable platform contract while preserving access to capabilities that cannot be meaningfully flattened.",{"id":411,"data":1388,"type":225},{"body":1389,"title":1390,"variant":415},"A lowest-common-denominator API can make migration easier but can also erase capabilities that matter. The architecture should define which features are portable, which are provider-specific and how consumers discover that difference.","Do not confuse abstraction with pretending providers are identical",{"id":417,"data":1392,"type":42},{"text":1393,"level":241},"2. Gateway, routing, quotas and cost controls",{"id":421,"data":1395,"type":218},{"text":1396},"A shared AI gateway can centralize authentication, routing, throttling, retries, token limits, usage attribution and policy enforcement. Microsoft’s current AI Gateway guidance explicitly treats token-per-minute limits, quotas and multi-project containment as platform concerns; AWS likewise exposes account and model quotas and centralized controls.",{"id":425,"data":1398,"type":218},{"text":1399},"The gateway is therefore more than a reverse proxy when it carries AI-specific policy and operational semantics. But it should not silently make business decisions. A routing policy may prefer a healthy local model, a lower-cost provider or a regionally compliant endpoint; whether that route is acceptable for a particular task is still a contract between platform and solution.",{"id":429,"data":1401,"type":218},{"text":1402},"Routing also needs failure semantics. If the preferred model is unavailable, the platform must know whether fallback is permitted, whether a cloud route requires explicit consent, whether a lower-capability model is valid and how the decision is surfaced to observability.",{"id":433,"data":1404,"type":42},{"text":1405,"level":241},"3. Shared data, retrieval and grounding services",{"id":437,"data":1407,"type":218},{"text":1408},"Retrieval services are strong platform candidates because parsing, chunking, indexing, lexical search, semantic search, metadata filtering, provenance and citation mechanics are reusable. However, the platform must not confuse a shared retrieval engine with a shared source of truth.",{"id":441,"data":1410,"type":218},{"text":1411},"A solution still owns questions such as: Which corpus is authoritative? Which version is valid? Can this user see this document? How fresh must the data be? What counts as sufficient evidence? Can an answer be generated when retrieval fails? Those are domain and solution requirements even when the platform supplies the retrieval machinery.",{"id":445,"data":1413,"type":218},{"text":1414},"This boundary is especially important in multi-tenant systems. A technically shared index or vector service does not justify cross-tenant visibility. Authorization context must be preserved through retrieval, not added only after search results have already crossed the boundary.",{"id":449,"data":1416,"type":42},{"text":1417,"level":241},"4. Agent and tool runtime",{"id":453,"data":1419,"type":218},{"text":1420},"Agentic systems add reusable runtime concerns: thread\u002Fsession lifecycle, planning loops, tool registration, tool invocation, cancellation, timeouts, human approvals, memory\u002Fstate interfaces, remote-agent protocols and trace correlation. A platform can provide these mechanics so each product does not rebuild them.",{"id":457,"data":1422,"type":218},{"text":1423},"The platform must also keep tool permission separate from model capability. A model being capable of generating a shell command does not mean the runtime should allow shell execution. The permission boundary belongs to the application\u002Fruntime architecture and must be enforceable independently of the model.",{"id":461,"data":1425,"type":218},{"text":1426},"Current AWS Agentic AI guidance emphasizes bounded agents, explicit authority, end-to-end tracing, versioned behavioral artifacts and human oversight proportionate to consequence. Those are platform-enabling concerns, but the consuming solution still defines what actions are legitimate for its domain.",{"id":465,"data":1428,"type":42},{"text":1429,"level":241},"5. Identity, tenant isolation and authorization",{"id":469,"data":1431,"type":218},{"text":1432},"AI platforms often sit in front of high-value models, proprietary data and action-capable tools. Authentication is therefore only the beginning. The architecture must carry user, service, application and tenant context through every privileged operation that needs it.",{"id":473,"data":1434,"type":218},{"text":1435},"\u003Cstrong>RBAC and tenant isolation solve different problems.\u003C\u002Fstrong> RBAC answers what an identity may do; tenant isolation answers which tenant’s resources that identity may act on. A platform that checks roles but loses tenant context can still expose the wrong data.",{"id":477,"data":1437,"type":218},{"text":1438},"Microsoft’s current AI workload guidance explicitly recommends identity segmentation and authorization-aware access to content. AWS’s multi-tenant generative AI platform guidance similarly treats logical isolation, centralized controls and auditability as platform concerns.",{"id":481,"data":1440,"type":42},{"text":1441,"level":241},"6. Secrets, credentials and trust boundaries",{"id":485,"data":1443,"type":218},{"text":1444},"A platform should define who owns provider keys, remote bearer tokens, signing material and tool credentials, where they are stored, which process can access them, how they are rotated and whether they can ever reach a browser or untrusted renderer.",{"id":489,"data":1446,"type":218},{"text":1447},"This is an architectural boundary, not an implementation detail. If every consuming application copies provider credentials into its own configuration, the organization has duplicated both operational burden and blast radius. Centralization can reduce that risk only if the platform itself has narrower, auditable access paths.",{"id":493,"data":1449,"type":42},{"text":1450,"level":241},"7. Evaluation, observability and auditability",{"id":497,"data":1452,"type":218},{"text":1453},"A reusable platform can provide evaluation harnesses, trace IDs, model\u002Fprovider metadata, token and cost metrics, latency, error rates, prompt\u002Fmodel version linkage, agent\u002Ftool traces and controlled logging. AWS and Microsoft both treat observability and evaluation as core production concerns for AI workloads.",{"id":501,"data":1455,"type":218},{"text":1456},"Platform evaluation and solution evaluation must remain separate. A platform can verify that an endpoint is healthy, a model version passes a general regression suite and traces are complete. It cannot decide that a legal answer, medical workflow or product recommendation is acceptable without domain-specific ground truth and acceptance criteria.",{"id":505,"data":1458,"type":218},{"text":1459},"Logging also creates a privacy boundary. Prompt and response logs may contain sensitive or proprietary data. The platform architect must therefore decide what is logged, redacted, sampled, retained and accessible rather than assuming that more telemetry is always safer.",{"id":509,"data":1461,"type":42},{"text":1462,"level":241},"8. Runtime, deployment and locality",{"id":513,"data":1464,"type":218},{"text":1465},"A platform architect decides how shared AI capabilities are deployed and reached: managed cloud services, self-hosted endpoints, local inference, hybrid routing, containerized services, desktop runtimes, private networking or air-gapped environments. The important distinction is between \u003Cstrong>where the control\u002Fruntime process runs\u003C\u002Fstrong> and \u003Cstrong>where inference and data processing actually occur\u003C\u002Fstrong>.",{"id":517,"data":1467,"type":218},{"text":1468},"A local client may still call a cloud model. A cloud control plane may route to an on-premises model. A remote agent may execute tools inside a customer network. Architectural diagrams must therefore show trust and data-flow boundaries rather than using “local” and “cloud” as vague labels.",{"id":521,"data":1470,"type":42},{"text":1471,"level":241},"9. Platform lifecycle, compatibility and onboarding",{"id":525,"data":1473,"type":218},{"text":1474},"Reusable capability becomes a platform only when consumers can depend on it over time. That requires versioned contracts, migration rules, compatibility policy, deprecation, release testing, rollback, incident ownership, capacity planning, documentation and a path for onboarding new teams or applications.",{"id":529,"data":1476,"type":218},{"text":1477},"Fast-moving AI ecosystems make this particularly important. Model names, SDKs, protocol versions, provider APIs and safety capabilities change independently. A platform must absorb some of that volatility without hiding changes that materially affect a solution’s behavior.",{"id":533,"data":1479,"type":42},{"text":1480,"level":242},"A practical control-plane \u002F execution-plane \u002F solution-plane model",{"id":537,"data":1482,"type":225},{"body":1483,"title":1484,"variant":231},"The three-plane model below is a practical way to reason about responsibilities; it is not an ISO, NIST, Microsoft or AWS standard. Its purpose is to make ownership boundaries explicit.","Proposed architecture model",{"id":542,"data":1486,"type":291},{"content":1487,"stretched":43,"withHeadings":14},[1488,1492,1496,1500],[1489,1490,1491],"Plane","Typical responsibilities","Should not silently own",[1493,1494,1495],"Platform control plane","Provider registry, model policy, quotas, tenant configuration, identities, secrets, routing rules, capability versions, deployment configuration","Application business logic or domain truth",[1497,1498,1499],"Platform execution\u002Fdata plane","Inference requests, retrieval operations, agent\u002Ftool execution, extraction, indexing, telemetry emission, policy enforcement","Cross-tenant access merely because infrastructure is shared",[1501,1502,1503],"Solution plane","User workflow, prompts\u002Finstructions, authoritative corpus selection, domain authorization, business rules, task evaluation and acceptance","Low-level provider integration that the platform explicitly owns",{"id":562,"data":1505,"type":218},{"text":1506},"This separation helps diagnose platform drift. If an application must know every provider-specific credential and endpoint, the platform contract is too thin. If the platform decides which customer record is legally authoritative or whether a domain answer is acceptable, the platform has crossed into solution ownership.",{"id":566,"data":1508,"type":42},{"text":1509,"level":242},"What should an AI Platform Architect produce?",{"id":570,"data":1511,"type":291},{"content":1512,"stretched":43,"withHeadings":14},[1513,1516,1519,1522,1525,1528,1531,1534,1537,1540],[1514,1515],"Architecture artifact","Purpose",[1517,1518],"Platform capability map","Defines what the platform provides, who consumes it and which capabilities remain outside scope.",[1520,1521],"Provider\u002Fmodel contract","Defines providers, models, capabilities, abstraction boundaries, route metadata and fallback semantics.",[1523,1524],"Identity and tenancy model","Defines user\u002Fservice\u002Fapplication identity, tenant context, RBAC\u002FABAC hooks and resource isolation.",[1526,1527],"Gateway and quota policy","Defines rate limits, token\u002Fcost budgets, routing controls, retries and capacity behavior.",[1529,1530],"Retrieval\u002Fdata contract","Defines ingestion, provenance, search, metadata, authorization propagation and where domain authority remains.",[1532,1533],"Agent\u002Ftool contract","Defines runtime lifecycle, tool registration, permissions, approvals, cancellation and trace behavior.",[1535,1536],"Secret and trust-boundary model","Defines credential ownership, storage, process boundaries, rotation and sensitive data paths.",[1538,1539],"Evaluation and telemetry contract","Defines common metrics, traces, datasets\u002Fversion links, logging policy and solution extension points.",[1541,1542],"Lifecycle and compatibility policy","Defines versions, migrations, deprecation, releases, rollback, incident ownership and onboarding.",{"id":604,"data":1544,"type":42},{"text":1545,"level":242},"The work is mostly trade-offs, not maximum centralization",{"id":608,"data":1547,"type":299},{"rows":1548,"title":1567,"layout":291,"columns":1568},[1549,1552,1555,1558,1561,1564],{"id":612,"label":1550,"values":1551},"Provider abstraction",{"pressureA":615,"pressureB":616},{"id":618,"label":1553,"values":1554},"Reuse",{"pressureA":621,"pressureB":622},{"id":624,"label":1556,"values":1557},"Governance",{"pressureA":627,"pressureB":628},{"id":630,"label":1559,"values":1560},"Observability",{"pressureA":633,"pressureB":634},{"id":636,"label":1562,"values":1563},"Availability",{"pressureA":639,"pressureB":640},{"id":642,"label":1565,"values":1566},"Platform scope",{"pressureA":645,"pressureB":646},"Common platform trade-offs",[1569,1571],{"id":650,"label":1570},"Pressure A",{"id":653,"label":1572},"Pressure B",{"id":656,"data":1574,"type":42},{"text":1575,"level":242},"How is this different from adjacent roles?",{"id":660,"data":1577,"type":291},{"content":1578,"stretched":43,"withHeadings":14},[1579,1582,1584,1586,1589,1592,1595],[1580,1581],"Role","Primary architectural scope",[1292,1583],"A concrete AI-enabled solution and its end-to-end requirements, boundaries, trade-offs and production acceptance.",[1294,1585],"Reusable AI capabilities and operational\u002Fsecurity contracts consumed across multiple solutions or teams.",[1587,1588],"Enterprise Architect","Organization-wide business\u002Ftechnology portfolio, capability and governance alignment at a broader level.",[1590,1591],"MLOps \u002F LLMOps Architect or specialist","Model and AI lifecycle, deployment, experiments, observability, release and operational practices; may overlap strongly but does not automatically own the whole shared application platform.",[1593,1594],"Platform Engineer \u002F SRE","Implements and operates platform infrastructure, reliability, automation and developer experience; architecture responsibility may be shared with the platform architect.",[1596,1597],"AI \u002F Software Engineer","Implements models, integrations, services, agents, retrieval and product functionality inside the agreed architecture.",{"id":683,"data":1599,"type":218},{"text":1600},"These boundaries are organizational, not universal. In a small team one person may hold several responsibilities. In a regulated enterprise they may be split across architecture, security, platform, data and operations groups. The useful distinction is the \u003Cstrong>scope of architectural responsibility\u003C\u002Fstrong>, not the job title printed on an org chart.",{"id":687,"data":1602,"type":42},{"text":1603,"level":242},"Implementation evidence: how these platform boundaries appear in my own work",{"id":691,"data":1605,"type":225},{"body":1606,"title":1607,"variant":231},"The following sections describe concrete patterns from my own projects. They are evidence that these architectural boundaries have been implemented or explicitly designed in real code and project systems. They are \u003Cstrong>not\u003C\u002Fstrong> claims that the projects together already constitute a commercially deployed enterprise AI platform.","Original implementation evidence",{"id":696,"data":1609,"type":42},{"text":1610,"level":241},"Aaasaasa AI Client: provider, runtime and permission separation",{"id":700,"data":1612,"type":218},{"text":1613},"Aaasaasa AI Client is a local-first desktop AI workspace built with Nuxt 4, Electron and TypeScript. Its AI Hub deliberately separates \u003Cstrong>agent\u002Fclient, provider, model, connection\u002Fruntime location, permissions and web client\u003C\u002Fstrong> instead of treating them as one configuration value.",{"id":704,"data":1615,"type":218},{"text":1616},"The implementation includes direct provider adapters, Codex agent runtime integration, local Ollama\u002FLM Studio paths, OpenAI-compatible services, centralized workspace permissions, main-process credential storage, DuckDB, Qdrant\u002Fvector support, PDF\u002Freadability extraction and authenticated MCP-based directory access.",{"id":708,"data":1618,"type":218},{"text":1619},"Two platform lessons are especially relevant. First, a local runtime is not the same as local inference: a local Codex process can still use a cloud model. Second, automatic routing does not silently fall back from local to paid cloud inference. That makes routing policy and runtime locality explicit rather than inferred from UI labels.",{"id":712,"data":1621,"type":291},{"content":1622,"stretched":43,"withHeadings":14},[1623,1626,1629,1632,1635,1638],[1624,1625],"Implemented boundary","Platform-architecture meaning",[1627,1628],"Agent vs provider vs model","Different responsibilities can evolve independently instead of being hidden behind one “AI” selector.",[1630,1631],"Permissions separate from model","Filesystem\u002Ftool authority belongs to the runtime policy, not model capability.",[1633,1634],"Main-process secrets","Credential ownership follows the privileged process boundary rather than the renderer\u002FUI.",[1636,1637],"Provider health and model discovery","Routing and availability are runtime\u002Fplatform concerns.",[1639,1640],"No silent cloud fallback","Cost, locality and data-transfer semantics remain explicit policy decisions.",{"id":734,"data":1642,"type":42},{"text":1643,"level":241},"Aaasaasa AI CMS: tenant-scoped authorization as a platform boundary",{"id":738,"data":1645,"type":218},{"text":1646},"The Aaasaasa AI CMS codebase provides a separate implementation example: tenant-scoped RBAC is represented through roles, permissions and user-role assignments bound to a tenant identifier. System permissions are grouped by capability, and role lookup and updates remain tenant-scoped.",{"id":742,"data":1648,"type":218},{"text":1649},"This is not itself proof of a complete AI platform, but it is directly relevant to one of the hardest shared-platform boundaries: a reusable service must preserve \u003Cstrong>who may do what\u003C\u002Fstrong> and \u003Cstrong>for which tenant\u003C\u002Fstrong>. Adding AI inference or retrieval on top of an application platform does not remove that requirement.",{"id":746,"data":1651,"type":218},{"text":1652},"The architectural implication is that model gateways, retrieval services and agents should consume established identity\u002Ftenant context rather than inventing a parallel AI-only authorization universe.",{"id":750,"data":1654,"type":42},{"text":1655,"level":241},"Source of Truth Research Engine: shared retrieval mechanics without shared truth",{"id":754,"data":1657,"type":218},{"text":1658},"The Source of Truth Research Engine provides a third implementation example. Different research modes share a common evidence core: Sources, Artifacts, provenance, Claims, Relations, Contradictions, a Reference Model and audit trail. The system also provides local lexical retrieval, optional semantic retrieval, extraction, snapshots and SHA-256-based provenance.",{"id":758,"data":1660,"type":218},{"text":1661},"The project explicitly treats search and semantic similarity as discovery signals rather than evidence. A result must be traced back to a concrete source and locator before it can support a claim. This is precisely the distinction an AI platform needs: \u003Cstrong>reusable retrieval machinery can be shared while evidence authority remains governed by the consuming methodology and domain.\u003C\u002Fstrong>",{"id":762,"data":1663,"type":218},{"text":1664},"The engine also demonstrates why one shared platform does not require one shared interpretation. Historical, scientific\u002Ftechnical, market-intelligence and monitoring modes can reuse core evidence infrastructure while retaining mode-specific methodology.",{"id":766,"data":1666,"type":225},{"body":1667,"title":1668,"variant":393},"Across these projects, the reusable pattern is not “one backend for everything.” It is \u003Cstrong>separation of concerns plus explicit contracts\u003C\u002Fstrong>: provider\u002Fmodel\u002Fruntime separation, tenant-aware authorization, credential boundaries, reusable data\u002Fretrieval primitives, provenance, and domain-specific authority. A future integrated platform would need stable contracts between those capabilities rather than direct coupling between codebases.","What these implementations demonstrate together",{"id":771,"data":1670,"type":42},{"text":1671,"level":242},"How current architecture guidance supports this platform scope",{"id":775,"data":1673,"type":218},{"text":1674},"ISO\u002FIEC\u002FIEEE 42010:2022 provides a general discipline for architecture descriptions across software, systems, enterprises and related entities. It does not define an AI Platform Architect, but it reinforces the need to express architectural concerns, relationships and viewpoints rather than reducing architecture to a technology list.",{"id":779,"data":1676,"type":218},{"text":1677},"NIST AI RMF 1.0 and the Generative AI Profile frame AI risk management across the lifecycle rather than only at model selection time. Governance, mapping, measurement and management are therefore compatible with a platform architecture that carries shared controls and evidence across many consuming workloads.",{"id":783,"data":1679,"type":218},{"text":1680},"Microsoft’s current AI workload guidance treats application design, data, security, operations, testing\u002Fevaluation and GenAIOps as connected architectural areas. Its current AI Gateway guidance also shows practical platform concerns such as centralized model access, project-specific token limits, quotas and multi-team containment.",{"id":787,"data":1682,"type":218},{"text":1683},"AWS’s current Generative AI Lens and multi-tenant platform scenario similarly separate foundational platform controls from consuming-application ownership. AWS explicitly notes that a central platform can enforce shared guardrails and auditability while data quality and workload-specific observability still remain responsibilities of consuming applications or data producers.",{"id":791,"data":1685,"type":218},{"text":1686},"The vendor products differ, but the cross-source pattern is stable: production AI platforms must coordinate identity, data access, models, policy, evaluation, observability, capacity, cost and lifecycle. A GPU cluster or model endpoint covers only part of that responsibility.",{"id":795,"data":1688,"type":42},{"text":1689,"level":242},"Common misconceptions",{"id":799,"data":1691,"type":291},{"content":1692,"stretched":43,"withHeadings":14},[1693,1696,1699,1702,1705,1708,1711,1714,1717],[1694,1695],"Misconception","Why it is wrong",[1697,1698],"“An AI platform is the GPU cluster.”","Compute is one substrate. A platform also needs contracts for identity, model access, data, policy, evaluation, observability and lifecycle.",[1700,1701],"“An AI gateway is just a reverse proxy.”","It may also carry model routing, token quotas, cost attribution, policy enforcement, identity and AI-specific telemetry.",[1703,1704],"“Shared means globally shared.”","A service may be physically shared while logically segmented by tenant, application, region, classification or risk level.",[1706,1707],"“One central vector database becomes the company truth.”","A vector store or retrieval service is infrastructure. Domain authority, freshness, provenance and access remain separate concerns.",[1709,1710],"“Platform evaluation replaces solution evaluation.”","General regression and telemetry cannot define whether a domain-specific answer or action is acceptable.",[1712,1713],"“Provider abstraction should hide every difference.”","Some differences are material capabilities, security semantics or failure modes and must remain visible.",[1715,1716],"“RBAC solves multi-tenancy.”","RBAC controls actions; tenant isolation controls resource boundaries. Both can be required.",[1718,1719],"“AI Platform Architect is just another name for MLOps.”","MLOps\u002FLLMOps is a major overlapping discipline, but shared application\u002Fruntime, identity, gateway, retrieval and tool boundaries can extend beyond model lifecycle operations.",{"id":830,"data":1721,"type":42},{"text":1722,"level":242},"Failure modes an AI Platform Architect should prevent",{"id":834,"data":1724,"type":291},{"content":1725,"stretched":43,"withHeadings":14},[1726,1729,1732,1735,1738,1741,1744,1747,1750,1753],[1727,1728],"Failure mode","Architectural consequence",[1730,1731],"Every team stores its own provider keys","Duplicated secret handling, inconsistent rotation and larger blast radius.",[1733,1734],"Provider abstraction hides required capabilities","Consumers cannot use features they need or silently receive behavior different from assumptions.",[1736,1737],"Shared retrieval ignores tenant\u002Fuser context","Cross-boundary data leakage can occur before the application gets a chance to filter results.",[1739,1740],"Fallback silently changes provider or locality","Cost, compliance, data location and output quality can change without the caller knowing.",[1742,1743],"Agent tools are granted by model choice","A capable model becomes over-privileged because runtime authority is not independently enforced.",[1745,1746],"All prompts\u002Fresponses are logged by default","Observability can create a new sensitive-data repository and compliance problem.",[1748,1749],"Platform owns one generic quality score","Domain failures remain hidden behind platform health metrics.",[1751,1752],"No version contract for platform capabilities","Model\u002Fprovider\u002Fruntime changes break consumers unpredictably.",[1754,1755],"Everything AI-related is centralized","The platform becomes a bottleneck and monolith instead of a reusable capability layer.",{"id":868,"data":1757,"type":42},{"text":1758,"level":242},"A practical platform-architecture decision sequence",{"id":872,"data":1760,"type":340},{"steps":1761,"title":1792,"orientation":339},[1762,1765,1768,1771,1774,1777,1780,1783,1786,1789],{"label":1763,"description":1764},"1. Identify real consumers","List solutions, teams, tenants and workloads that would consume the platform; avoid building a platform for hypothetical reuse.",{"label":1766,"description":1767},"2. Define the shared boundary","Separate cross-cutting mechanics from solution-specific domain authority, workflow and acceptance.",{"label":1769,"description":1770},"3. Define identity and isolation first","Establish users, services, applications, tenants, regions and data classifications before sharing retrieval or tool capabilities.",{"label":1772,"description":1773},"4. Define capability contracts","Specify model\u002Fprovider, retrieval, agent\u002Ftool, gateway and telemetry APIs with explicit ownership and versioning.",{"label":1775,"description":1776},"5. Decide provider and runtime strategy","Choose managed, self-hosted, local or hybrid execution and document fallback, locality and capability semantics.",{"label":1778,"description":1779},"6. Design data and retrieval boundaries","Define provenance, authorization propagation, corpus ownership, indexing and evidence responsibilities.",{"label":1781,"description":1782},"7. Add quotas, secrets and policy","Control cost, capacity, credentials, tool permissions, safety controls and blast radius.",{"label":1784,"description":1785},"8. Build evaluation and observability contracts","Provide platform metrics and tracing while leaving domain ground truth and acceptance to the solution.",{"label":1787,"description":1788},"9. Define lifecycle and operations","Version capabilities, test upgrades, document deprecation, rollback, incidents, capacity and consumer onboarding.",{"label":1790,"description":1791},"10. Validate with more than one consumer","A platform claim becomes credible when the shared capability actually serves distinct workloads without forcing them into the same domain model.","From platform need to operable shared capability",{"id":907,"data":1794,"type":42},{"text":1795,"level":242},"Edge cases and limits of the role",{"id":911,"data":1797,"type":218},{"text":1798},"A small organization with one AI application may not need a distinct AI platform or platform architect. Premature platforming can create more abstraction than value. The correct architecture may be one well-designed solution with a few reusable modules.",{"id":915,"data":1800,"type":218},{"text":1801},"An air-gapped or sovereign deployment changes the provider, update and observability model substantially. Model hosting, artifact distribution, identity integration and telemetry export may all need local equivalents.",{"id":919,"data":1803,"type":218},{"text":1804},"Highly regulated or high-consequence workloads may require stronger physical or organizational isolation instead of a logically shared platform. Reuse is never a sufficient reason to weaken a required security boundary.",{"id":923,"data":1806,"type":218},{"text":1807},"Managed cloud AI services can remove implementation burden but do not remove architectural accountability. The organization still decides identity, data access, logging, retention, quotas, model eligibility, fallback, evaluation and solution acceptance.",{"id":927,"data":1809,"type":218},{"text":1810},"The platform boundary may also differ by modality. Text inference, multimodal generation, speech, computer use and autonomous agents can have different latency, data, permission and observability requirements even when they share provider and identity infrastructure.",{"id":931,"data":1812,"type":42},{"text":1813,"level":242},"What would change this answer?",{"id":935,"data":1815,"type":218},{"text":1816},"The core definition would change if the organizational scope changes. If the architect owns one workload, the role becomes closer to AI Solution Architect. If the responsibility expands to organization-wide capability strategy, investment, standards and target-state portfolios, it moves toward Enterprise AI Architecture.",{"id":939,"data":1818,"type":218},{"text":1819},"Implementation guidance changes whenever providers, gateway products, agent protocols, regulatory obligations, model capabilities or deployment constraints change. That is why platform architecture should express stable responsibilities and contracts separately from current vendor mechanisms.",{"id":943,"data":1821,"type":42},{"text":1822,"level":242},"AI Platform Architect checklist",{"id":947,"data":1824,"type":291},{"content":1825,"stretched":43,"withHeadings":14},[1826,1829,1832,1835,1838,1841,1844,1847,1850,1853,1856,1859,1862],[1827,1828],"Question","Expected answer",[1830,1831],"Who are the actual platform consumers?","Named solutions, teams or tenant contexts with distinct but overlapping needs.",[1833,1834],"What is genuinely shared?","Explicit capability list, not a vague “AI backend.”",[1836,1837],"What must remain solution-specific?","Domain authority, business workflow, task acceptance and other workload-owned concerns.",[1839,1840],"How are models\u002Fproviders represented?","Versioned provider\u002Fmodel contracts with capabilities and explicit fallback semantics.",[1842,1843],"How is identity propagated?","User\u002Fservice\u002Fapplication\u002Ftenant context survives every privileged request path.",[1845,1846],"How is tenant isolation enforced?","Resource scoping is separate from role permission checks.",[1848,1849],"How are secrets handled?","Privileged storage, rotation, limited exposure and auditable ownership.",[1851,1852],"How does retrieval preserve authority?","Shared mechanics with authorization, provenance and domain-owned evidence rules.",[1854,1855],"How are tools and agents constrained?","Runtime permissions, bounded tool contracts, approvals, cancellation and traceability.",[1857,1858],"How are cost and capacity controlled?","Quotas, token\u002Frate controls, usage attribution and overload behavior.",[1860,1861],"How is quality measured?","Platform regression\u002Fevaluation plus solution-specific ground truth and acceptance.",[1863,1864],"How are changes rolled out?","Versioning, compatibility, migration, deprecation, rollback and incident ownership.",{"id":990,"data":1866,"type":42},{"text":1867,"level":242},"Conclusion",{"id":994,"data":1869,"type":218},{"text":1870},"An AI Platform Architect is responsible for the reusable architecture \u003Cstrong>between AI capabilities and the solutions that consume them\u003C\u002Fstrong>. The role defines how models, providers, retrieval, agents, tools, identity, tenants, secrets, evaluation, observability, quotas and runtime operations become dependable platform services rather than repeated one-off integrations.",{"id":998,"data":1872,"type":218},{"text":1873},"The difficult part is not maximizing reuse. It is choosing the correct boundary. A strong platform standardizes mechanics, policy and operations where multiple consumers genuinely benefit, while preserving solution-specific data authority, business logic, security requirements and acceptance criteria.",{"id":1002,"data":1875,"type":218},{"text":1876},"That distinction also explains the relationship with AI Solution Architecture: \u003Cstrong>the solution architect makes one AI-enabled system fit its purpose; the platform architect makes shared AI capabilities safe, reusable, operable and evolvable across many such systems.\u003C\u002Fstrong>",{"id":1006,"data":1878,"type":42},{"text":1879,"level":242},"Related canonical knowledge",{"id":1010,"data":1881,"type":218},{"text":1882},"This article sits after the canonical foundations on generative AI components, ADR versus NFR, and AI Solution Architecture. Those concepts are prerequisites because a platform exists to provide reusable system capabilities and to encode architectural decisions against explicit quality and operational requirements.",{"id":1014,"data":1884,"type":218},{"text":1885},"Retrieval-Augmented Generation is one example of a capability that may be offered through a platform, but the platform should not collapse retrieval infrastructure, domain knowledge and answer validity into one concept.",{"id":1018,"data":1887,"type":1026},{"link":1888,"meta":1889},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works",{"image":1890,"title":1891,"description":1892},{"url":1023},"What Is RAG? The Simplest Explanation of How It Works","Canonical introduction to retrieval-augmented generation and the boundary between model generation and external knowledge retrieval.",{"id":1028,"data":1894,"type":218},{"text":1895},"Agent protocols, tenant isolation, AI governance, model routing, Context Engineering and MLOps\u002FLLMOps are downstream or adjacent knowledge nodes. They become easier to reason about once the platform boundary is explicit.",{"id":1032,"data":1897,"type":42},{"text":1898,"level":242},"Frequently asked questions",{"id":1036,"data":1900,"type":1036},{"items":1901,"title":1063},[1902,1905,1908,1911,1914,1917],{"id":1040,"answer":1903,"question":1904},"No. The solution architect focuses on one concrete AI-enabled solution. The platform architect focuses on reusable AI capabilities, controls and operational contracts that can support multiple solutions.","Is an AI Platform Architect the same as an AI Solution Architect?",{"id":1044,"answer":1906,"question":1907},"No. A platform can use managed cloud models, self-hosted models, local inference or a hybrid strategy. The architecture must make provider, locality, identity, routing, data and operational consequences explicit.","Does an AI platform need to host its own models?",{"id":1048,"answer":1909,"question":1910},"Usually not. A gateway can be an important platform component, but a complete platform also needs contracts for identity, secrets, data\u002Fretrieval, evaluation, observability, lifecycle and operational ownership.","Is an AI gateway enough to be an AI platform?",{"id":1052,"answer":1912,"question":1913},"Retrieval mechanics can often be shared, but domain authority, authorization, freshness, evidence sufficiency and corpus ownership should remain explicit. Shared infrastructure does not imply shared truth.","Should retrieval be centralized?",{"id":1056,"answer":1915,"question":1916},"No. Platform evaluation can test shared capabilities and regressions. Each solution still needs task-specific ground truth, acceptance criteria and domain quality thresholds.","Does platform evaluation replace application evaluation?",{"id":1060,"answer":1918,"question":1919},"No. RBAC determines what an identity may do. Tenant isolation determines which tenant's resources the identity may act on. A platform often needs both.","Is multi-tenancy just RBAC?",{"id":1065,"data":1921,"type":42},{"text":1922,"level":242},"Glossary",{"id":1069,"data":1924,"type":1069},{"title":1925,"entries":1926},"Key AI platform architecture terms",[1927,1930,1932,1934,1937,1940,1943,1945],{"term":1928,"anchor":1075,"definition":1929},"AI platform","A reusable set of AI-related technical and operational capabilities consumed by multiple applications, teams or tenant contexts.",{"term":1078,"anchor":1079,"definition":1931},"A gateway layer for AI endpoints that may add authentication, routing, quotas, policy, retries, cost attribution and AI-specific telemetry beyond basic proxying.",{"term":1082,"anchor":1083,"definition":1933},"A component that maps a platform contract to a model provider's API, capabilities, health and failure semantics.",{"term":1935,"anchor":1087,"definition":1936},"Tenant isolation","The boundary that prevents one tenant context from accessing another tenant's resources, independent of role permissions.",{"term":1938,"anchor":1091,"definition":1939},"Capability contract","A versioned interface and behavioral agreement describing what a shared platform service provides and what the consumer must supply or own.",{"term":1941,"anchor":1095,"definition":1942},"Grounding \u002F retrieval service","Shared mechanics for finding and supplying external information to an AI workload; it does not automatically define which information is authoritative for a domain.",{"term":1098,"anchor":1099,"definition":1944},"Reusable infrastructure for running tests, datasets, model\u002Fprompt versions and metrics; domain acceptance remains solution-specific.",{"term":1102,"anchor":1103,"definition":1946},"The configuration and governance layer that manages platform capabilities, identities, policies, quotas, versions and deployment state.",{"id":1106,"data":1948,"type":42},{"text":1949,"level":242},"Primary sources and current architecture guidance",{"id":1110,"data":1951,"type":218},{"text":1952},"The sources below support the general architecture and production-platform claims. The Aaasaasa AI Client, Aaasaasa AI CMS and Source of Truth Research Engine sections are explicitly original implementation evidence. Current-state external references were checked on 8 October 2026.",{"id":1114,"data":1954,"type":1026},{"link":1116,"meta":1955},{"image":1956,"title":1957,"description":1958},{"url":1023},"ISO\u002FIEC\u002FIEEE 42010:2022 — Architecture Description","Current published international standard for architecture-description concepts and relationships.",{"id":1122,"data":1960,"type":1026},{"link":1124,"meta":1961},{"image":1962,"title":1127,"description":1963},{"url":1023},"NIST's AI RMF resources and current status; AI RMF 1.0 is under revision as of October 2026.",{"id":1130,"data":1965,"type":1026},{"link":1132,"meta":1966},{"image":1967,"title":1135,"description":1968},{"url":1023},"Generative AI profile for applying AI risk-management considerations across the AI lifecycle.",{"id":1138,"data":1970,"type":1026},{"link":1140,"meta":1971},{"image":1972,"title":1143,"description":1973},{"url":1023},"Current architectural guidance covering AI application, data, operations, evaluation, responsible AI and lifecycle concerns.",{"id":1146,"data":1975,"type":1026},{"link":1148,"meta":1976},{"image":1977,"title":1151,"description":1978},{"url":1023},"Current guidance on identity segmentation, security boundaries, telemetry, performance, data and platform trade-offs.",{"id":1154,"data":1980,"type":1026},{"link":1156,"meta":1981},{"image":1982,"title":1159,"description":1983},{"url":1023},"Current AI Gateway guidance for shared project access, token containment, quotas and governance.",{"id":1162,"data":1985,"type":1026},{"link":1164,"meta":1986},{"image":1987,"title":1167,"description":1988},{"url":1023},"Architecture guidance for centralized model access, routing, throttling, failover and client\u002Fplatform responsibilities.",{"id":1170,"data":1990,"type":1026},{"link":1172,"meta":1991},{"image":1992,"title":1993,"description":1994},{"url":1023},"AWS Well-Architected — Generative AI Lens","Current production architecture guidance for generative AI workloads across security, reliability, operations, performance and cost.",{"id":1178,"data":1996,"type":1026},{"link":1180,"meta":1997},{"image":1998,"title":1999,"description":2000},{"url":1023},"AWS — Multi-tenant Generative AI Platform Scenario","Current example separating central platform controls and auditability from consuming-application data quality and workload-specific responsibilities.",{"id":1186,"data":2002,"type":1026},{"link":1188,"meta":2003},{"image":2004,"title":2005,"description":2006},{"url":1023},"AWS Well-Architected — Agentic AI Design Principles","Current guidance on bounded agent authority, traceability, versioned behavior, explicit contracts and human oversight.",{"id":1194,"data":2008,"type":1026},{"link":1196,"meta":2009},{"image":2010,"title":2011,"description":2012},{"url":1023},"AWS CloudWatch — Generative AI Observability","Current observability capabilities and production metrics for models, agents, knowledge bases, tools and cost\u002Flatency\u002Ferror analysis.","2.31.0","An AI Platform Architect designs reusable AI foundations across models, providers, retrieval, agents, identity, security, evaluation, observability and operations.",{"lang":7,"title":208,"content":210,"contentJson":2016,"excerpt":1202},{"time":212,"blocks":2017,"version":1201},[2018,2020,2022,2024,2026,2028,2030,2032,2034,2050,2052,2054,2056,2058,2067,2069,2071,2073,2075,2085,2087,2089,2091,2093,2095,2097,2099,2101,2103,2105,2107,2109,2111,2113,2115,2117,2119,2121,2123,2125,2127,2129,2131,2133,2135,2137,2139,2141,2143,2145,2147,2149,2151,2153,2155,2157,2159,2166,2168,2170,2183,2185,2203,2205,2215,2217,2219,2221,2223,2225,2227,2229,2238,2240,2242,2244,2246,2248,2250,2252,2254,2256,2258,2260,2262,2264,2266,2268,2270,2282,2284,2297,2299,2312,2314,2316,2318,2320,2322,2324,2326,2328,2330,2332,2348,2350,2352,2354,2356,2358,2360,2362,2366,2368,2370,2379,2381,2392,2394,2396,2400,2404,2408,2412,2416,2420,2424,2428,2432,2436],{"id":215,"data":2019,"type":218},{"text":217},{"id":220,"data":2021,"type":225},{"body":222,"title":223,"variant":224},{"id":227,"data":2023,"type":225},{"body":229,"title":230,"variant":231},{"id":233,"data":2025,"type":225},{"body":235,"title":236,"variant":231},{"id":238,"data":2027,"type":243},{"title":240,"maxLevel":241,"minLevel":242},{"id":245,"data":2029,"type":42},{"text":247,"level":242},{"id":249,"data":2031,"type":218},{"text":251},{"id":253,"data":2033,"type":218},{"text":255},{"id":257,"data":2035,"type":299},{"rows":2036,"title":290,"layout":291,"columns":2047},[2037,2039,2041,2043,2045],{"id":261,"label":262,"values":2038},{"platform":264,"solution":265},{"id":267,"label":268,"values":2040},{"platform":270,"solution":271},{"id":273,"label":274,"values":2042},{"platform":276,"solution":277},{"id":279,"label":280,"values":2044},{"platform":282,"solution":283},{"id":285,"label":286,"values":2046},{"platform":288,"solution":289},[2048,2049],{"id":294,"label":295},{"id":297,"label":298},{"id":301,"data":2051,"type":42},{"text":303,"level":242},{"id":305,"data":2053,"type":218},{"text":307},{"id":309,"data":2055,"type":218},{"text":311},{"id":313,"data":2057,"type":218},{"text":315},{"id":317,"data":2059,"type":340},{"steps":2060,"title":338,"orientation":339},[2061,2062,2063,2064,2065,2066],{"label":321,"description":322},{"label":324,"description":325},{"label":327,"description":328},{"label":330,"description":331},{"label":333,"description":334},{"label":336,"description":337},{"id":342,"data":2068,"type":42},{"text":344,"level":242},{"id":346,"data":2070,"type":218},{"text":348},{"id":350,"data":2072,"type":218},{"text":352},{"id":354,"data":2074,"type":42},{"text":356,"level":242},{"id":358,"data":2076,"type":291},{"content":2077,"stretched":43,"withHeadings":14},[2078,2079,2080,2081,2082,2083,2084],[362,363,364],[366,367,368],[370,371,372],[374,375,376],[378,379,380],[280,382,383],[385,386,387],{"id":389,"data":2086,"type":225},{"body":391,"title":392,"variant":393},{"id":395,"data":2088,"type":42},{"text":397,"level":242},{"id":399,"data":2090,"type":42},{"text":401,"level":241},{"id":403,"data":2092,"type":218},{"text":405},{"id":407,"data":2094,"type":218},{"text":409},{"id":411,"data":2096,"type":225},{"body":413,"title":414,"variant":415},{"id":417,"data":2098,"type":42},{"text":419,"level":241},{"id":421,"data":2100,"type":218},{"text":423},{"id":425,"data":2102,"type":218},{"text":427},{"id":429,"data":2104,"type":218},{"text":431},{"id":433,"data":2106,"type":42},{"text":435,"level":241},{"id":437,"data":2108,"type":218},{"text":439},{"id":441,"data":2110,"type":218},{"text":443},{"id":445,"data":2112,"type":218},{"text":447},{"id":449,"data":2114,"type":42},{"text":451,"level":241},{"id":453,"data":2116,"type":218},{"text":455},{"id":457,"data":2118,"type":218},{"text":459},{"id":461,"data":2120,"type":218},{"text":463},{"id":465,"data":2122,"type":42},{"text":467,"level":241},{"id":469,"data":2124,"type":218},{"text":471},{"id":473,"data":2126,"type":218},{"text":475},{"id":477,"data":2128,"type":218},{"text":479},{"id":481,"data":2130,"type":42},{"text":483,"level":241},{"id":485,"data":2132,"type":218},{"text":487},{"id":489,"data":2134,"type":218},{"text":491},{"id":493,"data":2136,"type":42},{"text":495,"level":241},{"id":497,"data":2138,"type":218},{"text":499},{"id":501,"data":2140,"type":218},{"text":503},{"id":505,"data":2142,"type":218},{"text":507},{"id":509,"data":2144,"type":42},{"text":511,"level":241},{"id":513,"data":2146,"type":218},{"text":515},{"id":517,"data":2148,"type":218},{"text":519},{"id":521,"data":2150,"type":42},{"text":523,"level":241},{"id":525,"data":2152,"type":218},{"text":527},{"id":529,"data":2154,"type":218},{"text":531},{"id":533,"data":2156,"type":42},{"text":535,"level":242},{"id":537,"data":2158,"type":225},{"body":539,"title":540,"variant":231},{"id":542,"data":2160,"type":291},{"content":2161,"stretched":43,"withHeadings":14},[2162,2163,2164,2165],[546,547,548],[550,551,552],[554,555,556],[558,559,560],{"id":562,"data":2167,"type":218},{"text":564},{"id":566,"data":2169,"type":42},{"text":568,"level":242},{"id":570,"data":2171,"type":291},{"content":2172,"stretched":43,"withHeadings":14},[2173,2174,2175,2176,2177,2178,2179,2180,2181,2182],[574,575],[577,578],[580,581],[583,584],[586,587],[589,590],[592,593],[595,596],[598,599],[601,602],{"id":604,"data":2184,"type":42},{"text":606,"level":242},{"id":608,"data":2186,"type":299},{"rows":2187,"title":647,"layout":291,"columns":2200},[2188,2190,2192,2194,2196,2198],{"id":612,"label":613,"values":2189},{"pressureA":615,"pressureB":616},{"id":618,"label":619,"values":2191},{"pressureA":621,"pressureB":622},{"id":624,"label":625,"values":2193},{"pressureA":627,"pressureB":628},{"id":630,"label":631,"values":2195},{"pressureA":633,"pressureB":634},{"id":636,"label":637,"values":2197},{"pressureA":639,"pressureB":640},{"id":642,"label":643,"values":2199},{"pressureA":645,"pressureB":646},[2201,2202],{"id":650,"label":651},{"id":653,"label":654},{"id":656,"data":2204,"type":42},{"text":658,"level":242},{"id":660,"data":2206,"type":291},{"content":2207,"stretched":43,"withHeadings":14},[2208,2209,2210,2211,2212,2213,2214],[664,665],[295,667],[298,669],[671,672],[674,675],[677,678],[680,681],{"id":683,"data":2216,"type":218},{"text":685},{"id":687,"data":2218,"type":42},{"text":689,"level":242},{"id":691,"data":2220,"type":225},{"body":693,"title":694,"variant":231},{"id":696,"data":2222,"type":42},{"text":698,"level":241},{"id":700,"data":2224,"type":218},{"text":702},{"id":704,"data":2226,"type":218},{"text":706},{"id":708,"data":2228,"type":218},{"text":710},{"id":712,"data":2230,"type":291},{"content":2231,"stretched":43,"withHeadings":14},[2232,2233,2234,2235,2236,2237],[716,717],[719,720],[722,723],[725,726],[728,729],[731,732],{"id":734,"data":2239,"type":42},{"text":736,"level":241},{"id":738,"data":2241,"type":218},{"text":740},{"id":742,"data":2243,"type":218},{"text":744},{"id":746,"data":2245,"type":218},{"text":748},{"id":750,"data":2247,"type":42},{"text":752,"level":241},{"id":754,"data":2249,"type":218},{"text":756},{"id":758,"data":2251,"type":218},{"text":760},{"id":762,"data":2253,"type":218},{"text":764},{"id":766,"data":2255,"type":225},{"body":768,"title":769,"variant":393},{"id":771,"data":2257,"type":42},{"text":773,"level":242},{"id":775,"data":2259,"type":218},{"text":777},{"id":779,"data":2261,"type":218},{"text":781},{"id":783,"data":2263,"type":218},{"text":785},{"id":787,"data":2265,"type":218},{"text":789},{"id":791,"data":2267,"type":218},{"text":793},{"id":795,"data":2269,"type":42},{"text":797,"level":242},{"id":799,"data":2271,"type":291},{"content":2272,"stretched":43,"withHeadings":14},[2273,2274,2275,2276,2277,2278,2279,2280,2281],[803,804],[806,807],[809,810],[812,813],[815,816],[818,819],[821,822],[824,825],[827,828],{"id":830,"data":2283,"type":42},{"text":832,"level":242},{"id":834,"data":2285,"type":291},{"content":2286,"stretched":43,"withHeadings":14},[2287,2288,2289,2290,2291,2292,2293,2294,2295,2296],[838,839],[841,842],[844,845],[847,848],[850,851],[853,854],[856,857],[859,860],[862,863],[865,866],{"id":868,"data":2298,"type":42},{"text":870,"level":242},{"id":872,"data":2300,"type":340},{"steps":2301,"title":905,"orientation":339},[2302,2303,2304,2305,2306,2307,2308,2309,2310,2311],{"label":876,"description":877},{"label":879,"description":880},{"label":882,"description":883},{"label":885,"description":886},{"label":888,"description":889},{"label":891,"description":892},{"label":894,"description":895},{"label":897,"description":898},{"label":900,"description":901},{"label":903,"description":904},{"id":907,"data":2313,"type":42},{"text":909,"level":242},{"id":911,"data":2315,"type":218},{"text":913},{"id":915,"data":2317,"type":218},{"text":917},{"id":919,"data":2319,"type":218},{"text":921},{"id":923,"data":2321,"type":218},{"text":925},{"id":927,"data":2323,"type":218},{"text":929},{"id":931,"data":2325,"type":42},{"text":933,"level":242},{"id":935,"data":2327,"type":218},{"text":937},{"id":939,"data":2329,"type":218},{"text":941},{"id":943,"data":2331,"type":42},{"text":945,"level":242},{"id":947,"data":2333,"type":291},{"content":2334,"stretched":43,"withHeadings":14},[2335,2336,2337,2338,2339,2340,2341,2342,2343,2344,2345,2346,2347],[951,952],[954,955],[957,958],[960,961],[963,964],[966,967],[969,970],[972,973],[975,976],[978,979],[981,982],[984,985],[987,988],{"id":990,"data":2349,"type":42},{"text":992,"level":242},{"id":994,"data":2351,"type":218},{"text":996},{"id":998,"data":2353,"type":218},{"text":1000},{"id":1002,"data":2355,"type":218},{"text":1004},{"id":1006,"data":2357,"type":42},{"text":1008,"level":242},{"id":1010,"data":2359,"type":218},{"text":1012},{"id":1014,"data":2361,"type":218},{"text":1016},{"id":1018,"data":2363,"type":1026},{"link":1020,"meta":2364},{"image":2365,"title":1024,"description":1025},{"url":1023},{"id":1028,"data":2367,"type":218},{"text":1030},{"id":1032,"data":2369,"type":42},{"text":1034,"level":242},{"id":1036,"data":2371,"type":1036},{"items":2372,"title":1063},[2373,2374,2375,2376,2377,2378],{"id":1040,"answer":1041,"question":1042},{"id":1044,"answer":1045,"question":1046},{"id":1048,"answer":1049,"question":1050},{"id":1052,"answer":1053,"question":1054},{"id":1056,"answer":1057,"question":1058},{"id":1060,"answer":1061,"question":1062},{"id":1065,"data":2380,"type":42},{"text":1067,"level":242},{"id":1069,"data":2382,"type":1069},{"title":1071,"entries":2383},[2384,2385,2386,2387,2388,2389,2390,2391],{"term":1074,"anchor":1075,"definition":1076},{"term":1078,"anchor":1079,"definition":1080},{"term":1082,"anchor":1083,"definition":1084},{"term":1086,"anchor":1087,"definition":1088},{"term":1090,"anchor":1091,"definition":1092},{"term":1094,"anchor":1095,"definition":1096},{"term":1098,"anchor":1099,"definition":1100},{"term":1102,"anchor":1103,"definition":1104},{"id":1106,"data":2393,"type":42},{"text":1108,"level":242},{"id":1110,"data":2395,"type":218},{"text":1112},{"id":1114,"data":2397,"type":1026},{"link":1116,"meta":2398},{"image":2399,"title":1119,"description":1120},{"url":1023},{"id":1122,"data":2401,"type":1026},{"link":1124,"meta":2402},{"image":2403,"title":1127,"description":1128},{"url":1023},{"id":1130,"data":2405,"type":1026},{"link":1132,"meta":2406},{"image":2407,"title":1135,"description":1136},{"url":1023},{"id":1138,"data":2409,"type":1026},{"link":1140,"meta":2410},{"image":2411,"title":1143,"description":1144},{"url":1023},{"id":1146,"data":2413,"type":1026},{"link":1148,"meta":2414},{"image":2415,"title":1151,"description":1152},{"url":1023},{"id":1154,"data":2417,"type":1026},{"link":1156,"meta":2418},{"image":2419,"title":1159,"description":1160},{"url":1023},{"id":1162,"data":2421,"type":1026},{"link":1164,"meta":2422},{"image":2423,"title":1167,"description":1168},{"url":1023},{"id":1170,"data":2425,"type":1026},{"link":1172,"meta":2426},{"image":2427,"title":1175,"description":1176},{"url":1023},{"id":1178,"data":2429,"type":1026},{"link":1180,"meta":2430},{"image":2431,"title":1183,"description":1184},{"url":1023},{"id":1186,"data":2433,"type":1026},{"link":1188,"meta":2434},{"image":2435,"title":1191,"description":1192},{"url":1023},{"id":1194,"data":2437,"type":1026},{"link":1196,"meta":2438},{"image":2439,"title":1199,"description":1200},{"url":1023},"Post erfolgreich abgerufen",{"items":2442,"source":2527,"manualIds":2528,"manualMatchedIds":2529},[2443,2450,2457,2464,2471,2478,2485,2492,2499,2506,2513,2520],{"id":2444,"slug":2445,"title":2446,"excerpt":2447,"featuredImage":2448,"publishedAt":2449},"490","rbac-vs-tenant-isolation-two-different-security-boundaries","RBAC naspram izolacije zakupaca: dve različite bezbednosne granice","RBAC kontroliše šta korisnik sme da radi; izolacija zakupaca kontroliše kojim resursima tog zakupca ta radnja može da pristupi. Saznajte zašto bezbednost višekorisničkog SaaS-a zahteva obe granice.","\u002Fuploads\u002F2026\u002F10\u002Frbac-vs-tenant-isolation-two-different-security-boundaries-1791485111528-qqtzby.webp","2026-10-08T14:43:00.000Z",{"id":2451,"slug":2452,"title":2453,"excerpt":2454,"featuredImage":2455,"publishedAt":2456},"483","what-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs","Šta je AI rešenje arhitekta? Granice sistema, odgovornosti i kompromisi","AI Solution Architect pretvara poslovne zahteve u AI sistem spreman za produkciju, obuhvatajući podatke, modele, alate, bezbednost, izvršno okruženje, evaluaciju i operacije.","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs-1791476643267-1st5xz.webp","2026-10-08T12:23:00.000Z",{"id":2458,"slug":2459,"title":2460,"excerpt":2461,"featuredImage":2462,"publishedAt":2463},"492","mcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits","MCP objašnjen: Šta povezuje, šta ne radi i gde se uklapa","Model Context Protocol povezuje AI aplikacije sa eksternim alatima, resursima i promptovima kroz standardnu granicu klijent-server. Saznajte šta MCP radi, šta ne radi i gde se uklapa u arhitekturu agenata.","\u002Fuploads\u002F2026\u002F10\u002Fmcp-explained-what-it-connects-what-it-does-not-do-and-where-it-fits-1791486640275-7ub1cq.webp","2026-10-08T15:09:00.000Z",{"id":2465,"slug":2466,"title":2467,"excerpt":2468,"featuredImage":2469,"publishedAt":2470},"485","enterprise-ai-architecture-what-changes-when-ai-enters-a-company","Enterprise AI arhitektura: Šta se menja kada AI uđe u kompaniju","Enterprise AI arhitektura objašnjava kako AI menja korporativne sisteme kroz autoritet podataka, identitet, dozvole, provajdere, rizik, upravljanje, evaluaciju, usklađenost i operacije.","\u002Fuploads\u002F2026\u002F10\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company-1791478161363-czrwaq.webp","2026-10-08T10:48:00.000Z",{"id":2472,"slug":2473,"title":2474,"excerpt":2475,"featuredImage":2476,"publishedAt":2477},"486","source-of-truth-in-ai-systems-where-reliable-knowledge-actually-comes-from","Izvor istine u AI sistemima: Odakle pouzdano znanje zaista dolazi","Izvor istine definiše koji je izvor merodavan za određenu činjenicu ili stanje. Saznajte kako se razlikuje od RAG-a, porekla, memorije, konteksta, vektorskih baza podataka i sistema evidencije.","\u002Fuploads\u002F2026\u002F10\u002Fsource-of-truth-in-ai-systems-where-reliable-knowledge-actually-comes-from-1791479103235-6bq9em.webp","2026-10-08T13:02:00.000Z",{"id":2479,"slug":2480,"title":2481,"excerpt":2482,"featuredImage":2483,"publishedAt":2484},"489","agentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","Agentna AI objašnjena: Kada AI sistem može da planira, koristi alate i deluje","Agentna AI koristi modele unutar višekoračnih izvršnih petlji gde mogu da biraju alate, posmatraju rezultate, ažuriraju stanje i prilagode svoju sledeću akciju unutar eksplicitnih granica izvršavanja i dozvola.","\u002Fuploads\u002F2026\u002F10\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act-1791481499084-wnji2a.webp","2026-10-08T11:43:00.000Z",{"id":2486,"slug":2487,"title":2488,"excerpt":2489,"featuredImage":2490,"publishedAt":2491},"466","the-gpu-is-not-the-product-future-proof-private-ai-architecture","GPU nije proizvod: Privatna AI arhitektura spremna za budućnost","Privatna AI infrastruktura ne bi trebalo da bude projektovana oko jednog GPU-a ili jednog modela. Otporniji pristup kombinuje brze GPU-ove za inferenciju, memorijski bogate AI sisteme, čvorove za fizički AI i opcione vodeće modele u oblaku iza sloja za rutiranje koji prepoznaje mogućnosti.","\u002Fuploads\u002F2026\u002F09\u002Fthe-gpu-is-not-the-product-future-proof-private-ai-architecture-1790140878812-8hsl39.webp","2026-09-23T01:19:00.000Z",{"id":2493,"slug":2494,"title":2495,"excerpt":2496,"featuredImage":2497,"publishedAt":2498},"476","mcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained","MCP vs A2A vs UCP vs AP2 vs A2UI: Objašnjen stek agentskih protokola","MCP, A2A, UCP, AP2 i A2UI se često predstavljaju kao konkurentski standardi za agente. Oni uglavnom rešavaju različite probleme interoperabilnosti. Ovaj vodič mapira svaki protokol na granicu koju zapravo standardizuje—i pokazuje kako oni mogu da rade zajedno u jednom produkcionom sistemu.","\u002Fuploads\u002F2026\u002F09\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained-1790352625869-2ezle0.webp","2026-09-25T12:09:00.000Z",{"id":2500,"slug":2501,"title":2502,"excerpt":2503,"featuredImage":2504,"publishedAt":2505},"468","ai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","Memorija AI agenta nije RAG: Kako razdvojiti memoriju, pronalaženje, stanje i kontekst","Memorija agenta, RAG, stanje i kontekst često se koriste kao da su međusobno zamenjivi. Oni to nisu. Ovaj praktični arhitektonski model razdvaja ova četiri sloja, pokazuje gde svaki pripada i objašnjava šta se kvari kada ih sistemi stope u jedno.","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context-1790350560308-np0xy6.webp","2026-09-25T11:34:00.000Z",{"id":2507,"slug":2508,"title":2509,"excerpt":2510,"featuredImage":2511,"publishedAt":2512},"479","where-does-an-llm-get-its-data-rag-data-sources-in-python","Odakle LLM dobija svoje podatke? RAG izvori podataka u Python-u","LLM ne zna magično vaše fajlove, baze podataka ili API-je. Ovaj praktični nastavak RAG serije pokazuje, uz jednostavan Python, kako eksterni podaci postaju dokazi koji se mogu pronaći: od tekstualnih fajlova i SQL-a do pretrage punog teksta, embeddinga, sastavljanja konteksta i konačnog LLM poziva.","\u002Fuploads\u002F2026\u002F09\u002Fwhere-does-an-llm-get-its-data-rag-data-sources-in-python-1790517200521-nfsi5i.webp","2026-09-27T05:51:00.000Z",{"id":2514,"slug":2515,"title":2516,"excerpt":2517,"featuredImage":2518,"publishedAt":2519},"495","sovereign-ai-control-of-models-data-infrastructure-and-dependencies","Suverena AI: Kontrola modela, podataka, infrastrukture i zavisnosti","Suverena AI se odnosi na efektivnu kontrolu nad modelima, podacima, infrastrukturom, softverom, operacijama i strateškim zavisnostima — a ne samo na to gde je AI model hostovan.","\u002Fuploads\u002F2026\u002F10\u002Fsovereign-ai-control-of-models-data-infrastructure-and-dependencies-1791488833132-niy85x.webp","2026-10-08T15:45:00.000Z",{"id":2521,"slug":2522,"title":2523,"excerpt":2524,"featuredImage":2525,"publishedAt":2526},"470","what-should-an-ai-agent-remember-forget-recompute-or-retrieve-again","Šta bi AI agent trebalo da zapamti, zaboravi, ponovo izračuna ili ponovo preuzme?","Dugotrajni agenti ne bi trebalo da pamte sve. Ovaj članak pruža praktičan model životnog ciklusa za odlučivanje o tome šta pripada trajnoj memoriji, šta bi trebalo ponovo preuzeti, šta je bezbednije ponovo izračunati i šta bi trebalo da istekne ili bude zamenjeno.","\u002Fuploads\u002F2026\u002F09\u002Fwhat-should-an-ai-agent-remember-forget-recompute-or-retrieve-again-1790351131087-iehz28.webp","2026-09-25T09:43:00.000Z","fallback",[],[]]