← Back to all announcements
★★☆☆☆ 30/06/2026

AWS Security Hub CSPM launches AI Security Best Practices standard with 31 automated controls

31 automated controls now continuously enforce security best practices across Bedrock, AgentCore, and SageMaker—no custom rules needed.

View original announcement →

Visual Summary

graph TD A{{AI Security Best Practices Standard}}:::announced B(AWS Security Hub CSPM):::compute C(Amazon Bedrock AgentCore):::compute D(Amazon SageMaker):::compute E([31 Automated Controls]):::feature F([Security Findings]):::feature G(Amazon EventBridge):::compute H((Security Teams)):::external A ==>|"enables"| B A -->|"evaluates"| C A -->|"evaluates"| D A -->|"executes"| E E -->|"generates"| F F -->|"routes to"| G F -->|"alerts"| H G -.->|"automated remediation"| D classDef announced fill:#ff9900,stroke:#ec7211,color:#fff,font-weight:bold classDef compute fill:#e3f2fd,stroke:#1565c0,color:#1565c0 classDef storage fill:#e8f5e9,stroke:#2e7d32,color:#2e7d32 classDef feature fill:#fff3e0,stroke:#e65100,color:#e65100 classDef external fill:#f5f5f5,stroke:#616161,color:#616161

What's New

AWS Security Hub CSPM has launched the AI Security Best Practices standard, introducing 31 automated security controls specifically designed to detect misconfigurations in deployed AI workloads. The standard continuously evaluates Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker resources against AWS-recommended security configurations across domains such as network isolation, encryption, VPC placement, and authorization controls. This eliminates the need for manual security assessments or custom rule authoring to maintain a strong security posture for AI infrastructure.

How It Works

  • The standard is identified as standards/ai-security-best-practices/v/1.0.0 and is enabled within AWS Security Hub CSPM, which aggregates security findings across AWS accounts and services into a single pane of glass.
  • 31 automated controls continuously scan deployed AI resources and generate findings whenever a resource deviates from a defined security best practice, without requiring any manual trigger or custom rule.
  • Controls cover Amazon Bedrock AgentCore components (runtimes, gateways, memory stores, custom browsers) and Amazon SageMaker resources (notebook instances, endpoints, models, monitoring jobs, feature groups).
  • Each control is mapped to a specific security category (e.g., network isolation, encryption at rest/in transit, KMS key usage, VPC placement, private container registry requirements, authorization controls), making it easy to prioritize remediation by domain.
  • When a control check fails, Security Hub CSPM generates a structured finding that security teams can act on directly, or route through automation rules and Amazon EventBridge for automated remediation workflows.
  • The standard integrates natively with existing Security Hub CSPM features such as cross-Region aggregation, multi-account management, and dashboard visibility.

Why It's Important

  • AI workloads introduce unique attack surfaces—model endpoints, agent runtimes, memory stores, and feature pipelines—that traditional security standards were not designed to cover, leaving a significant governance gap.
  • Manual security reviews of AI infrastructure are slow, inconsistent, and difficult to scale as organizations rapidly expand their use of Bedrock and SageMaker; continuous automated controls address this at scale.
  • Misconfigurations in AI infrastructure (e.g., publicly accessible notebook instances, unencrypted model artifacts, or endpoints outside a VPC) can expose sensitive training data, proprietary models, or inference outputs to unauthorized access.
  • The standard provides a codified, AWS-expert-authored baseline that organizations can reference for internal compliance, audit evidence, and regulatory alignment without building it from scratch.
  • Security teams gain immediate, actionable findings rather than periodic point-in-time assessments, enabling faster mean time to remediation (MTTR) for AI-specific risks.
  • Coverage of GovCloud (US) and China Regions signals that regulated industries and public sector organizations can apply the same AI security posture management framework across their entire AWS footprint.

How It's Different

  • Unlike general-purpose standards (AWS FSBP, CIS, PCI DSS, NIST) already available in Security Hub CSPM, this standard is purpose-built exclusively for AI/ML service resources, covering constructs that no prior standard addressed.
  • It extends posture management to Amazon Bedrock AgentCore—a relatively new agentic AI platform—including its runtimes, gateways, memory stores, and custom browsers, which have no equivalent coverage in existing standards.
  • The 31 controls are authored and maintained by AWS security experts with deep knowledge of Bedrock and SageMaker internals, rather than being derived from a third-party compliance framework that may lag behind AWS service evolution.
  • Findings are generated automatically and continuously, contrasting with traditional approaches that rely on periodic manual reviews, custom AWS Config rules, or bespoke Lambda-based checks that teams must build and maintain themselves.
  • Because it is a native Security Hub CSPM standard, it inherits the full platform ecosystem: multi-account aggregation, automation rules, EventBridge integration, and cross-Region rollup—capabilities that custom solutions typically require significant engineering effort to replicate.

When to Prefer It

  • Use this standard when your organization is deploying or operating Amazon Bedrock, Bedrock AgentCore, or SageMaker workloads and needs a structured, continuously enforced security baseline without writing custom detection logic.
  • Prefer it when preparing for internal security audits or external compliance reviews that require documented evidence of AI infrastructure security controls and automated, repeatable assessment results.
  • It is the right choice for security engineering teams that want to extend their existing Security Hub CSPM posture management program to cover AI workloads using the same tooling, workflows, and dashboards already in place.
  • Organizations in regulated industries (financial services, healthcare, public sector) operating in GovCloud or China Regions should enable this standard to ensure AI workloads meet the same security bar as the rest of their AWS environment.
  • Use it when onboarding new AI projects to establish a security-by-default posture from day one, catching misconfigurations before they reach production rather than discovering them after deployment.
  • Teams adopting agentic AI architectures with Bedrock AgentCore should prioritize this standard, as it provides the only currently available automated coverage for AgentCore-specific security configurations.

Availability

  • Status: Generally Available (GA) as of June 30, 2026.
  • Regions: Available in all AWS Regions where Security Hub CSPM is currently supported, including AWS GovCloud (US-East and US-West) and the AWS China Regions (Beijing and Ningxia).
  • Standard Identifier: standards/ai-security-best-practices/v/1.0.0
  • Pricing: Follows standard Security Hub CSPM pricing, which is based on the number of security checks performed per account per month; a 30-day free trial is available via the AWS Free Tier for new Security Hub CSPM users.
  • Prerequisites: AWS Security Hub CSPM must be enabled in the target account(s); the standard must be explicitly enabled within Security Hub after activation.
  • Scope: Covers 31 controls across Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker; resources from other AI/ML services are not included in this initial version (v1.0.0).

Tags

Servicesother-aws
Typenew-featuresecurity
Conceptsagentic-aigenaimlops
Use Casesenterpriseobservability
GeographyGlobal

Related Resources

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.