AWS has added a dedicated security baseline for artificial-intelligence workloads to Security Hub CSPM, giving cloud teams 31 automated controls to check against recommended configurations. In its June 30, 2026 announcement, AWS said the new AI Security Best Practices standard is designed to identify when deployed AI resources drift from those settings.
This is a posture-management release, not a new AI model or a promise that a workload is secure by default. The controls sit inside AWS Security Hub CSPM and are intended to run continuously, without requiring teams to build their own assessments or custom rules. That distinction matters: a finding can expose a configuration gap, but it does not by itself prove that a model, agent or application will resist every attack.
What the 31 controls cover
AWS says the standard checks several foundational areas: network isolation, encryption at rest and in transit, VPC placement, KMS key use, private-container-registry requirements and authorization controls. Its scope reaches across the AI stack rather than stopping at a single service. The announcement names Amazon Bedrock, Amazon Bedrock AgentCore and Amazon SageMaker, including AgentCore runtimes, gateways, memory stores and custom browsers, as well as SageMaker notebooks, endpoints, models, monitoring jobs and feature groups.
Each control belongs to a security category and produces a finding when a resource does not match the recommended configuration. That gives security teams a common language for issues that are often scattered across platform, data and application owners. Instead of treating an AI deployment as an exception to the cloud baseline, teams can start with a defined set of checks and decide which findings require immediate remediation, compensating controls or an accepted risk.
Why this matters as AI estates spread
AI environments are rarely a single endpoint. A production system may combine a model service, an agent runtime, a gateway, a memory store, a notebook used during development and a private container image. Every component introduces configuration decisions around identity, network reachability, encryption and access. The value of a posture standard is therefore less about the number 31 than about making those decisions visible and repeatable across supported resources.
AWS Security Hub already describes itself as a place to centralize security visibility, correlate findings and support response workflows. The AI standard extends that operating model into a part of the estate that can otherwise be reviewed through separate service consoles. For a security operations team, that should make it easier to route an AI misconfiguration into the same triage process used for other cloud findings, while keeping ownership with the team that can actually change the resource.
The release is also a reminder that AI security begins below the model layer. Prompt policies and application testing remain important, but they cannot compensate for an exposed endpoint, an over-broad role or an unprotected container image. The controls AWS lists are conventional cloud safeguards applied to AI infrastructure, which is precisely why they are useful: they address concrete failure modes without requiring a team to predict every future model behavior.
Availability and limits
AWS says the standard is available in every Region where Security Hub CSPM is available, including AWS GovCloud (US) and the China Regions. It identifies the release as standards/ai-security-best-practices/v/1.0.0. AWS also says customers can try Security Hub CSPM at no cost for 30 days; that is a trial statement, not evidence that the full service is permanently free.
Teams evaluating the announcement should first confirm that their Region and resource types are covered, then map the listed controls to their own architecture. The Security Hub CSPM User Guide is the right place to verify enablement and finding details. AWS's Security Hub product page provides the wider context for its centralized findings and response workflows.
There is no performance benchmark in the announcement, and AWS does not claim that the 31 controls detect every prompt-injection attempt, malicious instruction or unsafe agent action. Organizations will still need identity review, logging, data-protection controls, application testing and an incident-response plan. The honest reading is narrower and more useful: AWS is turning a defined set of AI infrastructure recommendations into machine-generated posture findings.
That makes the update relevant for teams moving from AI experiments to governed production workloads. It will not replace security engineering, but it can reduce the number of configuration assumptions that remain invisible. The practical question is whether those findings fit an organization's existing ownership and remediation process—and whether the gaps they expose are closed before an AI workload becomes business-critical.
