What happened
On Sept 21, 2026 the AWS Security Blog published a pattern for streaming Amazon Bedrock Guardrails intervention events (prompt-injection blocks, sensitive-data redaction) into AWS security telemetry as Open Cybersecurity Schema Framework (OCSF) records via CloudWatch, enabling correlation with existing security data.
Why it matters
Turns guardrail intervention data into first-class, standards-shaped security evidence so AI-related incident investigations can correlate model-layer blocks with SIEM/EDR telemetry.
Applicability
Security teams on AWS Bedrock Guardrails should implement the OCSF enrichment pipeline to bring AI-security events into their SIEM/XDR correlation.