- Adds a “deny by default” governance setting for custom permissions that automatically blocks new AI capabilities at launch.
- Administrators must explicitly allow each capability per profile, role, user, or account before it becomes usable.
- Configurable via the Manage account UI or AWS CLI and applies only to the selected custom permissions profile.