Home icon

The AWS AI Security Framework: Securing AI with the right controls, at the right layers, at the right phases

Security Blog



This article introduces the AWS AI Security Framework, a structured approach to securing AI workloads across three dimensions: use cases, infrastructure layers, and deployment phases.

  • Three AI use cases require cumulative security: AI that answers questions, AI that connects to enterprise data (RAG), and AI that acts autonomously (agents).
  • Three security layers provide defense-in-depth: infrastructure (compute isolation, network), identity and data (authentication, encryption, access control), and AI application (content filtering, guardrails, behavioral monitoring).
  • Three deployment phases build security progressively: foundational (prototype with day-1 controls), enhanced (production hardening), and advanced (continuous improvement at scale).
  • AI workloads are probabilistic and autonomous, requiring output validation, prompt injection detection, continuous monitoring, and least-privilege agent permissions.
  • AWS provides secure-by-default infrastructure (Nitro System), consistent security services (IAM, KMS, CloudTrail), and AI-specific controls (Bedrock Guardrails, AgentCore).
  • Defense-in-depth example: prompt injection mitigated across 10 layers from authentication through egress monitoring and incident detection.
  • Organizations should audit AI workloads, establish identity controls day-1, classify data, threat model before production, and update incident response plans.

The framework enables security teams to enable AI adoption by applying the right controls systematically, rather than retrofitting security after incidents.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 17
2025
Securing AI: AWS Marketplace and Partner Solutions from Adoption to Protection
May 13
2026
Securing AI agents: How AWS and Cisco AI Defense scale MCP and A2A deployments
May 13
2026
Introducing the updated AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption
Apr 14
2026
Secure AI agent access patterns to AWS resources using Model Context Protocol

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.