AWS Security Hub now provides AI inventory for organization-wide visibility of AI assets
Security Hub now auto-discovers managed, self-hosted, and third-party AI assets org-wide and links them to live threats—at no extra cost.
View original announcement →Visual Summary
What's New
AWS Security Hub now includes an AI inventory feature that automatically discovers, catalogs, and continuously monitors AI assets across an entire AWS organization. The inventory correlates discovered AI workloads—including managed services, self-hosted models, and third-party API dependencies—with active security findings to give central security teams a unified view of AI risk posture. This capability is included at no additional cost with Security Hub Essentials and requires no new configuration to enable.
How It Works
- Managed AI service discovery: Security Hub automatically inventories AWS Config resources from Amazon Bedrock, Bedrock AgentCore, and Amazon SageMaker with zero additional configuration, covering first-party managed AI services out of the box.
- Self-hosted AI workload discovery: Amazon Inspector's SBOM analysis has been enhanced to detect inference endpoints, models, and AI agents running on EC2 instances and ECR container images, covering popular open-source frameworks including Ollama, vLLM, and Hugging Face TGI.
- Third-party AI API discovery: Amazon GuardDuty DNS telemetry is used to identify outbound calls from EC2 instances to external AI API endpoints (e.g., third-party model providers), surfacing shadow AI dependencies that may be unknown to security teams.
- Infrastructure mapping and correlation: Each discovered AI asset is mapped to its underlying infrastructure and correlated with security findings from GuardDuty, Inspector, and other AWS security services using the Open Cybersecurity Schema Framework (OCSF).
- Queryable inventory: Teams can filter, group, and query the inventory by AWS account, resource type, discovery method, and specific model identity to prioritize remediation based on active threat exposure and organizational risk.
Why It's Important
- Shadow AI visibility: Organizations rapidly deploying AI agents and models often lack a complete inventory of what exists; this feature closes that gap by automatically discovering assets across all three deployment patterns (managed, self-hosted, third-party).
- Risk-prioritized remediation: By correlating AI assets directly with active threat findings from GuardDuty and vulnerability data from Inspector, security teams can focus effort on AI workloads that are actively under attack rather than treating all assets equally.
- Third-party dependency exposure: DNS telemetry-based discovery of external AI API calls reveals undocumented or unauthorized use of third-party model providers, a critical blind spot as employees and developers increasingly use external LLM APIs.
- No operational overhead: Zero additional configuration and no extra cost means organizations can immediately gain AI asset visibility without budget justification or complex deployment projects.
- Governance and compliance enablement: A continuously updated, centralized AI asset catalog supports emerging AI governance frameworks and regulatory requirements that demand organizations know and document their AI systems.
How It's Different
- Three-method discovery vs. single-source approaches: Unlike tools that only inventory managed cloud services, Security Hub combines Config-based discovery, SBOM analysis, and DNS telemetry to cover managed, self-hosted, and third-party AI assets in a single pane of glass.
- Threat correlation built in: Rather than providing a static asset list, Security Hub directly links each AI asset to live security findings, enabling risk-ranked prioritization that standalone CMDB or asset discovery tools do not provide.
- Framework-level self-hosted detection: The enhanced Inspector SBOM analysis identifies specific AI inference frameworks (Ollama, vLLM, Hugging Face TGI) running inside EC2 and containers, going beyond generic software inventory to AI-specific workload identification.
- Organization-wide scope by default: The inventory operates at the AWS Organizations level, giving central security teams cross-account visibility without requiring per-account enablement or aggregation configuration.
- Included in existing plan: Unlike many security add-ons, AI inventory is bundled into Security Hub Essentials at no additional cost, removing a common barrier to adoption.
When to Prefer It
- Large enterprises with decentralized AI adoption: When multiple teams across many AWS accounts are independently deploying AI workloads, this feature provides the central security team with consolidated visibility they could not otherwise achieve manually.
- Organizations concerned about unauthorized AI API usage: When security or compliance teams need to detect whether developers or applications are calling unapproved external LLM providers (e.g., OpenAI, Anthropic) from production infrastructure.
- Security teams implementing AI-specific threat response: When you need to quickly determine whether a GuardDuty threat finding is associated with an AI workload, enabling faster triage and context-aware incident response.
- Compliance and AI governance programs: When preparing for AI audits, regulatory reviews, or internal governance frameworks that require a documented inventory of all AI systems in use across the organization.
- Teams running self-hosted open-source models: When deploying models via Ollama, vLLM, or similar frameworks on EC2 or containers and needing those workloads included in enterprise security monitoring alongside managed services.
Availability
- General Availability: The AI inventory feature is generally available as of July 14, 2026.
- Regions: Available in all AWS commercial Regions where AWS Security Hub is currently offered; no region-specific limitations noted.
- Pricing: Included at no additional cost with the Security Hub Essentials plan; no separate SKU or add-on purchase required.
- Enablement: No new configuration or explicit opt-in is required; existing Security Hub customers automatically gain access to the AI inventory.
- Dependencies: Full discovery coverage requires Amazon Inspector (for SBOM-based self-hosted detection) and Amazon GuardDuty (for DNS telemetry-based third-party API discovery) to be enabled in the relevant accounts.