← Back to all announcements
★★☆☆☆ 14/07/2026

Introducing Amazon GuardDuty AI Protection for AWS AI workloads

GuardDuty now detects prompt injection, cost harvesting, and anomalous Bedrock/SageMaker activity—no custom tooling required.

View original announcement →

Visual Summary

graph TD A{{GuardDuty AI Protection}}:::announced B(Amazon Bedrock):::compute C(Amazon SageMaker):::compute D([Bedrock Guardrails]):::feature E(AWS CloudTrail):::storage F(AWS Security Hub):::compute G([Threat Findings]):::feature H((Security Teams)):::external I(AWS Organizations):::compute B -->|"data events"| E C -->|"data events"| E E ==>|"ingests logs"| A A -->|"prompt injection"| D A -->|"generates"| G G -->|"forwards to"| F F -->|"alerts"| H I -.->|"org-wide enablement"| A classDef announced fill:#ff9900,stroke:#ec7211,color:#fff,font-weight:bold classDef compute fill:#e3f2fd,stroke:#1565c0,color:#1565c0 classDef storage fill:#e8f5e9,stroke:#2e7d32,color:#2e7d32 classDef feature fill:#fff3e0,stroke:#e65100,color:#e65100 classDef external fill:#f5f5f5,stroke:#616161,color:#616161

What's New

Amazon GuardDuty has launched AI Protection, a new capability that extends its threat detection coverage to AWS AI services including Amazon Bedrock and Amazon SageMaker. The feature continuously monitors AI workloads for threats such as anomalous model invocations, cost harvesting attacks, and prompt injection attempts—without requiring manual configuration or custom tooling. Findings are surfaced directly into AWS Security Hub, providing security teams with a unified view of AI-specific threats alongside their broader AWS security posture.

How It Works

  • GuardDuty AI Protection ingests and analyzes both CloudTrail management events and CloudTrail data events generated by AWS AI services (Bedrock, SageMaker) to build a behavioral baseline and detect deviations.
  • Unusual invocation patterns are detected by applying machine learning models to model API call telemetry, flagging activity that deviates from established usage norms for a given account or workload.
  • Cost harvesting attack detection identifies threat actors who have gained unauthorized access and are deliberately forcing AI resources to consume excessive GPU compute time and tokens, driving up costs.
  • Prompt injection detection is achieved through native integration with Amazon Bedrock Guardrails, which evaluates inference inputs and outputs; suspicious attempts are surfaced as GuardDuty findings.
  • All findings are automatically forwarded to AWS Security Hub, enabling centralized, prioritized response alongside findings from other GuardDuty protection plans and third-party security tools.
  • Enablement is console-driven (GuardDuty or Security Hub console) with no manual log routing or custom infrastructure required; AWS Organizations support allows a single delegated administrator to enable the feature across all member accounts simultaneously.

Why It's Important

  • AI workloads represent a rapidly growing and largely unmonitored attack surface; without dedicated detection, security teams are blind to threats that exploit AI-specific APIs and behaviors.
  • Cost harvesting attacks against AI services can generate enormous, unexpected bills in minutes—early detection directly limits financial exposure in addition to security risk.
  • Prompt injection is an emerging, AI-native attack vector with no equivalent in traditional workloads; purpose-built detection fills a gap that generic SIEM rules and network-based controls cannot address.
  • Centralizing AI threat findings in Security Hub reduces analyst toil by eliminating the need to correlate signals across disparate logs, dashboards, or custom detection pipelines.
  • Zero-configuration deployment lowers the barrier for organizations that lack dedicated AI security expertise, democratizing protection for teams of all sizes.
  • Organization-wide enablement via AWS Organizations ensures consistent coverage across multi-account environments, preventing security gaps in development, staging, or less-monitored accounts.

How It's Different

  • Unlike generic SIEM or CloudTrail alerting rules, GuardDuty AI Protection uses ML-based behavioral analysis tuned specifically to AI service usage patterns, reducing false positives from legitimate but bursty workloads.
  • Native integration with Amazon Bedrock Guardrails provides prompt injection detection at the inference layer—a capability that external security tools cannot achieve without deep AWS service integration.
  • Cost harvesting detection is an AI-specific threat category not addressed by existing GuardDuty protection plans (EC2, S3, EKS, RDS), which focus on compute, storage, and database threats respectively.
  • The feature requires no log enablement, agent deployment, or custom infrastructure, contrasting with DIY approaches that require customers to route CloudTrail data events to a SIEM and write detection logic manually.
  • Findings are natively correlated with other GuardDuty findings in Security Hub, enabling multi-stage attack detection that spans AI workloads and foundational AWS infrastructure in a single pane of glass.
  • As a managed protection plan within GuardDuty, it inherits the service's existing IAM, multi-account, and compliance integrations, avoiding the need to onboard a separate security product.

When to Prefer It

  • Use GuardDuty AI Protection when your organization has deployed Amazon Bedrock or SageMaker in production and needs continuous, automated monitoring without building custom detection pipelines.
  • Prefer it when you are concerned about unauthorized access to AI model APIs—for example, leaked IAM credentials being used to invoke expensive foundation models at scale.
  • It is the right choice when your security team lacks AI-specific threat expertise and needs managed, pre-built detections rather than authoring custom rules for AI service logs.
  • Enable it in multi-account AWS Organizations environments where ensuring consistent AI security coverage across all accounts (including developer sandboxes) is a compliance or governance requirement.
  • It is particularly valuable for cost-sensitive workloads using large foundation models, where a cost harvesting attack could generate significant financial damage before a human analyst notices anomalous spend.
  • Choose it when you are already using AWS Security Hub as your central SOAR/SIEM aggregation point and want AI threat findings to flow into existing response workflows without additional integration work.

Availability

  • GA Status: Generally available as of July 14, 2026, as a new GuardDuty protection plan.
  • Free Trial: A 30-day free trial is available for GuardDuty customers who have not previously enabled AI Protection; trial days remaining and estimated daily costs are displayed in the GuardDuty console.
  • Pricing Model: Pay-as-you-go based on the volume of CloudTrail management and data events analyzed from AWS AI services; consult the GuardDuty pricing page for tier-specific rates.
  • Supported Regions: Available in select AWS Regions at launch; the full and current list is maintained on the AWS Regional Services List page (specific regions not enumerated in the announcement).
  • Prerequisites: Requires an active GuardDuty subscription; prompt injection detection additionally requires Amazon Bedrock Guardrails to be configured on the relevant Bedrock resources.
  • Multi-account Support: Can be centrally enabled for all accounts in an AWS Organization via the delegated GuardDuty administrator account, with no per-account manual steps required.
  • Limitations: The default GuardDuty foundational threat detection cannot be disabled; AI Protection is an opt-in protection plan that can be toggled on or off independently of other plans.

Tags

Servicesother-aws
Typenew-featuresecurity
Conceptsgenaillm
Use Casesenterpriseobservability
GeographyGlobal

Related Resources

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.