Skip to main content
AWS Security Hub dashboard displaying AI inventory across three data layers, enhancing cloud security.

Editorial illustration for AWS Security Hub Adds Free AI Inventory Using Three Data Layers

AWS Security Hub Adds Free AI Code Inventory Tool

4 min read

Amazon is putting its security tools inside the coding environments run by OpenAI and Anthropic, two companies it also competes with on foundation models. AWS announced at Black Hat USA 2026 that Continuum, its platform for catching code vulnerabilities, will now plug directly into Anthropic's Claude Code and OpenAI's Codex, in addition to AWS's own Kiro IDE. That puts AWS's scanning and remediation tools at the exact moment developers write code, no matter which model produced it.

The company paired that move with an expansion of Security Hub Extended, the curated security marketplace it launched in February that bundles vendor tools under a single AWS bill. A new tenth category targets supply chain protection, with Chainguard and Socket signed on as partners. Taken together, the two announcements mark AWS's biggest push yet to become the default layer enterprises rely on for securing software built with AI, a bet with real stakes given a global cloud infrastructure market Synergy Research Group pegs above $143 billion per quarter.

That urgency didn't come from nowhere. It traces back to a specific moment this year when a new frontier model exposed just how fast AI-generated code was outpacing anyone's ability to secure it.

Amazon Web Services is threading its AI-powered security infrastructure directly into the coding environments built by two of its fiercest rivals — and in doing so, it is making a bold bet that controlling the security layer matters more than controlling the model.

Why this matters

AWS betting on the security layer instead of the model layer is a real strategic tell, and it's worth watching closely. By wiring Continuum into Claude Code and Codex, AWS is positioning itself as the plumbing underneath its own rivals' products, which only works if enough teams standardize on AWS for inventory and vulnerability tracking regardless of which model or IDE they prefer. For developers and founders, the free AI inventory in Security Hub is the more immediately useful piece: knowing which SageMaker, Bedrock, and Agent Core instances exist across an org is a basic governance problem that most teams still handle with spreadsheets.

Fuller's line that "the industry is working on it" is honest but thin. Nobody has solved AI code security end to end, and AWS's three-layer approach is a starting inventory, not a finished defense. We'd treat this as a useful visibility tool to adopt now, not proof that AWS has cracked agentic coding security.

Watch whether Anthropic and OpenAI push their own competing security tooling into these same IDEs, because that's where the actual power struggle plays out.

Common Questions Answered

What coding environments does AWS Continuum now integrate with according to the Black Hat USA 2026 announcement?

AWS Continuum now integrates directly with Anthropic's Claude Code, OpenAI's Codex, and AWS's own Kiro IDE. This integration allows AWS's scanning and remediation tools to work across multiple coding environments regardless of which AI model produced the code, giving developers unified security coverage.

How does AWS's strategy of focusing on the security layer differ from competing on foundation models?

AWS is positioning itself as the security infrastructure layer underneath its rivals' products rather than trying to compete directly with OpenAI and Anthropic on foundation models. By wiring Continuum into competitors' coding environments, AWS is betting that controlling the security layer matters more than controlling the model itself, allowing it to maintain relevance across multiple AI platforms.

What is the primary benefit of AWS Security Hub's free AI inventory feature for developers?

The free AI inventory in Security Hub provides developers with immediate vulnerability tracking and code scanning capabilities integrated directly into their coding environment at the moment they write code. This real-time security scanning works regardless of which AI model or IDE developers choose to use, making security checks seamless and automatic.

Why is AWS integrating its security tools into competitors' platforms like Claude Code and Codex?

AWS is making a strategic bet that if enough development teams standardize on AWS for inventory and vulnerability tracking, they will become dependent on AWS's security infrastructure regardless of which AI model or coding environment they prefer. This approach positions AWS as essential plumbing in the development workflow, creating a competitive advantage through security rather than through model superiority.

LIVE23:35Claude Agent Found Vulnerability in Gym Appointment Software, Chat Logs Show