AWS has added an AI inventory to Security Hub, giving central security teams a continuously updated view of AI assets and their security posture across an organization. The announcement addresses a basic problem emerging as companies deploy more models, agents and AI-enabled services: security teams cannot protect systems they cannot see.

The new capability is designed to identify AI workloads across managed AWS services, self-hosted infrastructure and external model dependencies. AWS says the inventory is included with Security Hub Essentials, requires no new enablement and is available in all commercial AWS Regions where Security Hub is offered.

Three discovery paths for AI workloads

For managed AI services, Security Hub uses AWS Config resources to inventory deployments involving Amazon Bedrock, Bedrock AgentCore and Amazon SageMaker. AWS says this path requires no additional configuration, which should make it useful for organizations that already use those services and want a consolidated view of their AI footprint.

The second path covers self-hosted AI workloads. AWS has enhanced Amazon Inspector's software bill of materials analysis to identify inference endpoints, models and AI agents installed on Amazon EC2 instances and Amazon Elastic Container Registry images. The announcement names Ollama, vLLM and Hugging Face Text Generation Inference among the frameworks that can be identified.

The third path looks beyond AWS-managed model services. Security Hub can use Amazon GuardDuty DNS telemetry to discover external AI API endpoints accessed from EC2 instances. That may reveal dependencies on third-party model providers that were not previously recorded in an organization's inventory.

From asset discovery to risk prioritization

Discovery is only the first step. AWS says each AI asset is mapped to its underlying infrastructure and correlated with findings from across the AWS security stack, including GuardDuty threat findings. Security teams can filter, group and query the inventory by account, resource type, discovery method and specific model identity.

That structure changes the question from “Where are we using AI?” to “Which AI assets are exposed, misconfigured or already associated with suspicious activity?” A model endpoint with no active finding may require governance review, while an AI workload linked to a threat signal can be prioritized for investigation. The distinction is important as organizations accumulate AI services through formal projects, developer experimentation and connections to external APIs.

AWS describes the inventory as an organization-wide view, but the announcement does not present it as a replacement for broader asset-management or software-supply-chain processes. Teams will still need to decide how the Security Hub view relates to their existing records and ownership models. They will also need to establish who is responsible for reviewing newly discovered assets and how findings are escalated.

What security teams should examine first

The release offers a practical starting point for reviewing AI exposure. Organizations adopting the feature should focus on four questions:

  • Does the inventory match the AI workloads already known to security and platform teams?
  • Which self-hosted endpoints, models or agents appear through software bill of materials analysis?
  • Are external model APIs being called from infrastructure that has not been documented or approved?
  • Which AI assets are connected to active findings and therefore need a faster remediation decision?

These checks are more useful than treating inventory as a one-time report. AI systems change quickly: new endpoints are deployed, models are replaced and applications gain access to additional tools or providers. A continuously updated view can support recurring reviews, but only if teams assign ownership and define what action follows a newly discovered asset.

Why the timing matters

AI security discussions often focus on prompt injection, model abuse or the behavior of autonomous agents. Those risks are real, but they are difficult to manage when the organization does not know which models, endpoints and integrations exist. Security Hub's update puts visibility at the center of the control problem and connects that visibility with AWS's existing security findings.

The result is not an automatic security guarantee. It is an inventory and correlation layer that can help teams build a clearer baseline, locate overlooked dependencies and prioritize investigations. Its value will depend on the completeness of the signals available in each environment and on whether organizations turn the resulting findings into accountable remediation work.

For AWS customers already using Security Hub, the announcement is significant because it extends an existing security view into the AI estate without requiring a separate inventory system. For teams operating across multiple clouds or with substantial unmanaged infrastructure, it should be treated as one source of evidence within a wider asset-governance process.

The announcement is documented in AWS's official release.

Sources and methodology

  1. Official source 1 Opens an external source