Introducing Amazon GuardDuty AI Protection for AWS AI workloads
GuardDuty now detects prompt injection, cost harvesting, and anomalous Bedrock/SageMaker activity—no custom tooling required.
View original announcement →Visual Summary
What's New
Amazon GuardDuty has launched AI Protection, a new capability that extends its threat detection coverage to AWS AI services including Amazon Bedrock and Amazon SageMaker. The feature continuously monitors AI workloads for threats such as anomalous model invocations, cost harvesting attacks, and prompt injection attempts—without requiring manual configuration or custom tooling. Findings are surfaced directly into AWS Security Hub, providing security teams with a unified view of AI-specific threats alongside their broader AWS security posture.
How It Works
- GuardDuty AI Protection ingests and analyzes both CloudTrail management events and CloudTrail data events generated by AWS AI services (Bedrock, SageMaker) to build a behavioral baseline and detect deviations.
- Unusual invocation patterns are detected by applying machine learning models to model API call telemetry, flagging activity that deviates from established usage norms for a given account or workload.
- Cost harvesting attack detection identifies threat actors who have gained unauthorized access and are deliberately forcing AI resources to consume excessive GPU compute time and tokens, driving up costs.
- Prompt injection detection is achieved through native integration with Amazon Bedrock Guardrails, which evaluates inference inputs and outputs; suspicious attempts are surfaced as GuardDuty findings.
- All findings are automatically forwarded to AWS Security Hub, enabling centralized, prioritized response alongside findings from other GuardDuty protection plans and third-party security tools.
- Enablement is console-driven (GuardDuty or Security Hub console) with no manual log routing or custom infrastructure required; AWS Organizations support allows a single delegated administrator to enable the feature across all member accounts simultaneously.
Why It's Important
- AI workloads represent a rapidly growing and largely unmonitored attack surface; without dedicated detection, security teams are blind to threats that exploit AI-specific APIs and behaviors.
- Cost harvesting attacks against AI services can generate enormous, unexpected bills in minutes—early detection directly limits financial exposure in addition to security risk.
- Prompt injection is an emerging, AI-native attack vector with no equivalent in traditional workloads; purpose-built detection fills a gap that generic SIEM rules and network-based controls cannot address.
- Centralizing AI threat findings in Security Hub reduces analyst toil by eliminating the need to correlate signals across disparate logs, dashboards, or custom detection pipelines.
- Zero-configuration deployment lowers the barrier for organizations that lack dedicated AI security expertise, democratizing protection for teams of all sizes.
- Organization-wide enablement via AWS Organizations ensures consistent coverage across multi-account environments, preventing security gaps in development, staging, or less-monitored accounts.
How It's Different
- Unlike generic SIEM or CloudTrail alerting rules, GuardDuty AI Protection uses ML-based behavioral analysis tuned specifically to AI service usage patterns, reducing false positives from legitimate but bursty workloads.
- Native integration with Amazon Bedrock Guardrails provides prompt injection detection at the inference layer—a capability that external security tools cannot achieve without deep AWS service integration.
- Cost harvesting detection is an AI-specific threat category not addressed by existing GuardDuty protection plans (EC2, S3, EKS, RDS), which focus on compute, storage, and database threats respectively.
- The feature requires no log enablement, agent deployment, or custom infrastructure, contrasting with DIY approaches that require customers to route CloudTrail data events to a SIEM and write detection logic manually.
- Findings are natively correlated with other GuardDuty findings in Security Hub, enabling multi-stage attack detection that spans AI workloads and foundational AWS infrastructure in a single pane of glass.
- As a managed protection plan within GuardDuty, it inherits the service's existing IAM, multi-account, and compliance integrations, avoiding the need to onboard a separate security product.
When to Prefer It
- Use GuardDuty AI Protection when your organization has deployed Amazon Bedrock or SageMaker in production and needs continuous, automated monitoring without building custom detection pipelines.
- Prefer it when you are concerned about unauthorized access to AI model APIs—for example, leaked IAM credentials being used to invoke expensive foundation models at scale.
- It is the right choice when your security team lacks AI-specific threat expertise and needs managed, pre-built detections rather than authoring custom rules for AI service logs.
- Enable it in multi-account AWS Organizations environments where ensuring consistent AI security coverage across all accounts (including developer sandboxes) is a compliance or governance requirement.
- It is particularly valuable for cost-sensitive workloads using large foundation models, where a cost harvesting attack could generate significant financial damage before a human analyst notices anomalous spend.
- Choose it when you are already using AWS Security Hub as your central SOAR/SIEM aggregation point and want AI threat findings to flow into existing response workflows without additional integration work.
Availability
- GA Status: Generally available as of July 14, 2026, as a new GuardDuty protection plan.
- Free Trial: A 30-day free trial is available for GuardDuty customers who have not previously enabled AI Protection; trial days remaining and estimated daily costs are displayed in the GuardDuty console.
- Pricing Model: Pay-as-you-go based on the volume of CloudTrail management and data events analyzed from AWS AI services; consult the GuardDuty pricing page for tier-specific rates.
- Supported Regions: Available in select AWS Regions at launch; the full and current list is maintained on the AWS Regional Services List page (specific regions not enumerated in the announcement).
- Prerequisites: Requires an active GuardDuty subscription; prompt injection detection additionally requires Amazon Bedrock Guardrails to be configured on the relevant Bedrock resources.
- Multi-account Support: Can be centrally enabled for all accounts in an AWS Organization via the delegated GuardDuty administrator account, with no per-account manual steps required.
- Limitations: The default GuardDuty foundational threat detection cannot be disabled; AI Protection is an opt-in protection plan that can be toggled on or off independently of other plans.