AWS Security Hub CSPM launches AI Security Best Practices standard with 31 automated controls
31 automated controls now continuously enforce security best practices across Bedrock, AgentCore, and SageMaker—no custom rules needed.
View original announcement →Visual Summary
What's New
AWS Security Hub CSPM has launched the AI Security Best Practices standard, introducing 31 automated security controls specifically designed to detect misconfigurations in deployed AI workloads. The standard continuously evaluates Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker resources against AWS-recommended security configurations across domains such as network isolation, encryption, VPC placement, and authorization controls. This eliminates the need for manual security assessments or custom rule authoring to maintain a strong security posture for AI infrastructure.
How It Works
- The standard is identified as
standards/ai-security-best-practices/v/1.0.0and is enabled within AWS Security Hub CSPM, which aggregates security findings across AWS accounts and services into a single pane of glass. - 31 automated controls continuously scan deployed AI resources and generate findings whenever a resource deviates from a defined security best practice, without requiring any manual trigger or custom rule.
- Controls cover Amazon Bedrock AgentCore components (runtimes, gateways, memory stores, custom browsers) and Amazon SageMaker resources (notebook instances, endpoints, models, monitoring jobs, feature groups).
- Each control is mapped to a specific security category (e.g., network isolation, encryption at rest/in transit, KMS key usage, VPC placement, private container registry requirements, authorization controls), making it easy to prioritize remediation by domain.
- When a control check fails, Security Hub CSPM generates a structured finding that security teams can act on directly, or route through automation rules and Amazon EventBridge for automated remediation workflows.
- The standard integrates natively with existing Security Hub CSPM features such as cross-Region aggregation, multi-account management, and dashboard visibility.
Why It's Important
- AI workloads introduce unique attack surfaces—model endpoints, agent runtimes, memory stores, and feature pipelines—that traditional security standards were not designed to cover, leaving a significant governance gap.
- Manual security reviews of AI infrastructure are slow, inconsistent, and difficult to scale as organizations rapidly expand their use of Bedrock and SageMaker; continuous automated controls address this at scale.
- Misconfigurations in AI infrastructure (e.g., publicly accessible notebook instances, unencrypted model artifacts, or endpoints outside a VPC) can expose sensitive training data, proprietary models, or inference outputs to unauthorized access.
- The standard provides a codified, AWS-expert-authored baseline that organizations can reference for internal compliance, audit evidence, and regulatory alignment without building it from scratch.
- Security teams gain immediate, actionable findings rather than periodic point-in-time assessments, enabling faster mean time to remediation (MTTR) for AI-specific risks.
- Coverage of GovCloud (US) and China Regions signals that regulated industries and public sector organizations can apply the same AI security posture management framework across their entire AWS footprint.
How It's Different
- Unlike general-purpose standards (AWS FSBP, CIS, PCI DSS, NIST) already available in Security Hub CSPM, this standard is purpose-built exclusively for AI/ML service resources, covering constructs that no prior standard addressed.
- It extends posture management to Amazon Bedrock AgentCore—a relatively new agentic AI platform—including its runtimes, gateways, memory stores, and custom browsers, which have no equivalent coverage in existing standards.
- The 31 controls are authored and maintained by AWS security experts with deep knowledge of Bedrock and SageMaker internals, rather than being derived from a third-party compliance framework that may lag behind AWS service evolution.
- Findings are generated automatically and continuously, contrasting with traditional approaches that rely on periodic manual reviews, custom AWS Config rules, or bespoke Lambda-based checks that teams must build and maintain themselves.
- Because it is a native Security Hub CSPM standard, it inherits the full platform ecosystem: multi-account aggregation, automation rules, EventBridge integration, and cross-Region rollup—capabilities that custom solutions typically require significant engineering effort to replicate.
When to Prefer It
- Use this standard when your organization is deploying or operating Amazon Bedrock, Bedrock AgentCore, or SageMaker workloads and needs a structured, continuously enforced security baseline without writing custom detection logic.
- Prefer it when preparing for internal security audits or external compliance reviews that require documented evidence of AI infrastructure security controls and automated, repeatable assessment results.
- It is the right choice for security engineering teams that want to extend their existing Security Hub CSPM posture management program to cover AI workloads using the same tooling, workflows, and dashboards already in place.
- Organizations in regulated industries (financial services, healthcare, public sector) operating in GovCloud or China Regions should enable this standard to ensure AI workloads meet the same security bar as the rest of their AWS environment.
- Use it when onboarding new AI projects to establish a security-by-default posture from day one, catching misconfigurations before they reach production rather than discovering them after deployment.
- Teams adopting agentic AI architectures with Bedrock AgentCore should prioritize this standard, as it provides the only currently available automated coverage for AgentCore-specific security configurations.
Availability
- Status: Generally Available (GA) as of June 30, 2026.
- Regions: Available in all AWS Regions where Security Hub CSPM is currently supported, including AWS GovCloud (US-East and US-West) and the AWS China Regions (Beijing and Ningxia).
- Standard Identifier:
standards/ai-security-best-practices/v/1.0.0 - Pricing: Follows standard Security Hub CSPM pricing, which is based on the number of security checks performed per account per month; a 30-day free trial is available via the AWS Free Tier for new Security Hub CSPM users.
- Prerequisites: AWS Security Hub CSPM must be enabled in the target account(s); the standard must be explicitly enabled within Security Hub after activation.
- Scope: Covers 31 controls across Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker; resources from other AI/ML services are not included in this initial version (v1.0.0).