Introducing Amazon GuardDuty AI Protection for AWS AI Workloads
AWS, Tuesday, July 14th, 2026
GuardDuty extends threat detection to Amazon Bedrock and SageMaker, flagging anomalous model invocations, cost harvesting, and prompt injection.
Amazon GuardDuty launched AI Protection, expanding its managed threat detection to cover AWS AI services including Amazon Bedrock and Amazon SageMaker.
The feature analyzes CloudTrail management and data events to surface suspicious activity such as unusual invocation patterns and cost harvesting attacks, where attackers force AI resources to burn excessive GPU time and tokens.
It also detects prompt injection attempts through an integration with Amazon Bedrock Guardrails. GuardDuty monitors these workloads continuously without requiring manual configuration or custom tooling, addressing a visibility gap security teams face as AI adoption accelerates.