- Introduces a “deny by default” governance setting for custom permissions, automatically blocking new AI capabilities at launch
- Administrators must explicitly allow capabilities per profile, user, role, or account, enhancing control over AI feature rollout
- Configurable via Manage account UI or AWS CLI and available in all Amazon Quick regions