Blog 4: Essential Guide to Cloud Governance at AWS re:Invent 2025
Overview: Governance as a Launchpad for Innovation
At AWS re:Invent 2025, the theme of Cloud Governance is no longer viewed as a compliance burden but has become a strategic factor to drive innovation. This year’s Cloud Governance track focuses on bridging the gap between operational excellence and business innovation.
This post summarizes guidance for attending the most important sessions, divided into 4 main themes reflecting today’s most pressing challenges.
Key Themes
This year’s program is organized around 4 main pillars:
- Generative AI & Intelligent Governance: Using AI to analyze logs, automate controls, and shift from reactive to proactive governance.
- Operational Efficiency & Cost Optimization: Balancing strict controls with operational efficiency, optimizing monitoring costs.
- Secure Operations & Automation: Shifting from “checkbox” compliance to automated, continuous protection through Policy-as-Code.
- Multicloud & Sovereign Cloud: Consistent governance across multiple cloud environments and meeting data sovereignty requirements.
Featured Sessions Details
Below is a list of “must-attend” sessions categorized by theme to help you easily plan your learning schedule.
1. Generative AI & Intelligent Governance
Revolutionizing governance processes with AI to reduce manual operations.
- COP350 | Building and validating cloud controls with generative AI: (Breakout) Technical guidance on using GenAI to customize AWS Control Tower, write rules for AWS Config, and analyze CloudTrail logs.
- COP411 | Intelligent automation for managing cloud governance: (Builders session) Hands-on building intelligent workflows that analyze data from Config and Security Hub to provide context-based insights.
2. Operational Efficiency & Cost Optimization
Building a governance framework that helps enterprises stay agile while saving costs.
- COP355 | A practical guide to implement cost-effective governance controls: (Chalk talk) Strategies to reduce monitoring costs while maintaining security, using Config and CloudTrail.
- COP351 | Innovation Sandbox on AWS: (Lightning Talk) Automating the creation and destruction of temporary sandbox environments to control costs and security.
- COP324 | Moving AWS Accounts seamlessly at scale: (Chalk talk) Guidance on safely migrating AWS accounts in merger and acquisition (M&A) scenarios.
3. Secure Operations & Automation
Applying Policy-as-Code and continuous compliance checking.
- COP347 | Actionable controls for improving governance and compliance: (Breakout) Transforming compliance frameworks into practical AWS controls using Control Tower and Audit Manager.
- COP352 | From Reactive to Proactive: Infrastructure governance by design: (Code talk) Using CloudFormation Guard and Hooks to block non-compliant deployments from the start.
- COP406 | Build and automate policy as code: (Builders session) Hands-on building Policy-as-Code pipelines with automated security testing steps (shift-left security).
4. Multicloud & Sovereign Cloud
Addressing complex requirements for data sovereignty and multi-cloud.
- COP409 | Building Sovereign Cloud Environments: (Code talk) How Control Tower supports data sovereignty requirements and controls cross-border data movement.
- COP349 | Balancing agility and compliance feat. The Japan Digital Agency: (Breakout) Case study on Japan’s government managing centralized governance for 30 ministries and 5,000 AWS accounts.
- COP346 | Governance that Enables Innovation at Scale feat. Eli Lilly: (Breakout) Case study on pharmaceutical company Eli Lilly modernizing governance with Control Tower without causing operational disruption (zero downtime).
Conclusion
This year’s sessions emphasize fundamental shifts in cloud operations:
- Integrating Generative AI into governance processes.
- Emphasis on Policy-as-Code.
- Shifting from reactive controls to proactive approaches.
Attending these sessions will equip you with knowledge to lead your organization’s digital transformation safely and efficiently.
Author

David Sokolik
David Sokolik is an Enterprise Support Technical Account Manager at Amazon Web Services based out of Tel Aviv, Israel. With over a decade of IT and cloud experience, David is a dedicated team member and advocate for his customers for building scalable, resilient and cost-effective solutions. David enjoys spending time with his family and friends traveling the world and exploring local cuisines.