Refacto Agents

Industry story

AWS Security Hub adds 31 automated controls for AI/agent workloads

ai-in-adtech engineering privacy

AWS just made "we didn't know the agent runtime was misconfigured" a harder excuse to use. Security Hub's new AI Security Best Practices standard ships 31 automated controls across Bedrock, Bedrock AgentCore, and SageMaker — checking network isolation, encryption, VPC placement, and authorization settings continuously, no manual audit required. For teams actually running agents in production, this closes a real gap: agent-specific infrastructure like memory stores, gateways, and custom browsers now gets the same posture scanning as the rest of the stack. The question is whether security teams adopt it before an incident makes it mandatory.

Full analysis

AWS Security Hub's cloud security posture management (CSPM) tool — which continuously scans cloud environments for misconfigurations — has launched an 'AI Security Best Practices' standard containing 31 automated controls specifically targeting deployed AI resources. The controls cover Amazon Bedrock, Bedrock AgentCore (AWS's managed agent runtime), and SageMaker workloads, checking for network isolation, encryption, VPC placement, KMS key usage, private container registries, and authorization settings without requiring manual assessments.

The standard spans agent-specific infrastructure including Bedrock AgentCore runtimes, gateways, memory stores, and custom browsers — components directly relevant to production agent deployments. When a resource deviates from recommended configuration, the system generates a finding for security teams to remediate. The standard is available globally including AWS GovCloud and China Regions, with a 30-day free trial.

Comments