AWS
Type: company (hyperscaler; on Paul’s cloud-native AI governance watchlist — Bedrock Guardrails, SageMaker Model Governance / Clarify, and now the AgentCore agent-control lines) Sector: cloud infrastructure and AI platforms First seen: 2026-08-28 (S-2026-08-18-aws-agentcore-payments-ga) Last updated: 2026-09-17
Updated 2026-09-17 based on S-2026-09-15-salesforce-aws-dreamforce-informatica-headless (daily DG/DM vendor-intelligence scan; Salesforce-authored partner story) — Bedrock AgentCore and Amazon Quick are now stated consumers of Informatica’s headless MCP context (catalog, DQ scores, MDM), and Salesforce relays an AWS “ISO 42001 compliance and full audit trails” assertion for Bedrock model choice that carries no certificate or scope. Tracked changes and Sources only; per-vendor facts on Informatica; nothing prior superseded. Updated 2026-09-16 based on S-2026-09-15-archer-evolv-ai-compliance (daily AI-governance vendor-intelligence scan) — a third-party source, not an AWS release: Archer’s Evolv AI Compliance compiles regulatory and policy obligations into native Amazon Bedrock Guardrails deployed in the customer’s AWS account, making Bedrock Guardrails the enforcement substrate for a GRC vendor’s obligation-traced controls (and the Bedrock Apply Guardrail API the route for non-Bedrock models). Added to Positions, Relationships, Tracked changes and Sources; nothing prior superseded.
Created 2026-09-11 from S-2026-09-aws-agentcore-consent-portal-agent-registry (daily AI-governance vendor-intelligence scan; AWS AgentCore release notes fetched in full; entries dated by month only ⚠️). Second dedicated source after S-2026-08-18-aws-agentcore-payments-ga — schema 2+-source trigger met. Scope note: this page tracks AWS’s AI-governance-relevant moves only (Bedrock/AgentCore control primitives, registry, evaluations, guardrails), not the company generally. Earlier AWS items referenced in the vault only via scan notes — Bedrock AgentCore Policy GA (Mar 2026), cross-account safeguards (Apr 2026), Guardrails-in-Policy (Jun/Jul 2026) — were outside the ingestion window when checked and have no Source pages; they are not summarised here.
Snapshot
AWS is the hyperscaler whose agent platform, Amazon Bedrock AgentCore, has been shipping governance-relevant control primitives below the AI-governance-platform layer: delegated spending authority with deterministic infrastructure-layer caps (payments GA, 18 Aug 2026) [S-2026-08-18-aws-agentcore-payments-ga]; an org-wide, auto-synced AWS Agent Registry (GA, Aug 2026) with customer-managed-key encryption, PrivateLink and cross-account sharing; and a hosted Consent Portal (Sep 2026) through which end users review and approve the resource access an agent requests on their behalf before it proceeds [S-2026-09-aws-agentcore-consent-portal-agent-registry]. It matters to this wiki because these are default-infrastructure answers to questions — delegated authority, inventory of record, human consent for agent action — that the AI-governance pure-plays sell as category products, and because none of the AWS documentation names a regulatory standard, a retention model or a regulated customer [S-2026-08-18-aws-agentcore-payments-ga][S-2026-09-aws-agentcore-consent-portal-agent-registry].
Positions / Claims they advance
- Agent payments should run inside payment sessions with spend and expiry caps “checked deterministically at the infrastructure layer”, because “agents are inherently non-deterministic” and can misread a response as authorisation to spend; credentials are isolated so “the agent does not see the raw credentials”; audit trails flow to AgentCore Observability / CloudWatch [S-2026-08-18-aws-agentcore-payments-ga].
- An agent estate can be inventoried automatically: AWS Agent Registry auto-detects AgentCore Runtimes and Gateways across all AWS Organizations member accounts into one registry that “stays in sync as resources are created, updated, or deleted”, encrypted at rest under a customer-managed KMS key [S-2026-09-aws-agentcore-consent-portal-agent-registry].
- Human consent for delegated agent access can be an infrastructure step: the Consent Portal is where end users “review and approve the requested access before the agent proceeds”, built on JWT-authenticated Gateways and OIDC identity providers [S-2026-09-aws-agentcore-consent-portal-agent-registry].
- Agent evaluation is a platform service: AgentCore Evaluations spans Python and TypeScript frameworks, adds skill-level evaluators anchored to tool-call spans, and offers DeepEval/AutoEval third-party evaluators [S-2026-09-aws-agentcore-consent-portal-agent-registry].
- All of the above are AWS product claims; no regulatory standard is named in either ingested source, and the FS/model-risk read-across on this page is the vault’s [inference].
- (Third-party use, per Archer, not AWS:) Bedrock Guardrails can host obligation-traced “policy as code” authored and version-controlled outside AWS — Archer deploys approved guardrails into the customer’s account, reads guardrail configuration and violation events through a scoped IAM role, and relies on the guardrails continuing to enforce “as last deployed” if its own connectivity drops; sold via AWS Marketplace [S-2026-09-15-archer-evolv-ai-compliance].
Relationships
- relates-to → AI Governance Platforms — cloud-native governance locus: spending authority, inventory of record and delegated consent as infrastructure-layer agent-control primitives [S-2026-08-18-aws-agentcore-payments-ga][S-2026-09-aws-agentcore-consent-portal-agent-registry].
- relates-to → Model Risk Management and Agentic AI — delegation-of-authority and human-oversight controls for agent actions are SS1/23 / SR 11-7 questions the AWS primitives touch without naming [inference].
- relates-to → Google Cloud — peer hyperscaler shipping analogous cloud-native guardrail/control features (Model Armor, Gemini Enterprise control plane) [S-2026-09-02-google-model-armor-release-notes].
- relates-to → IBM — IBM’s AI Asset Discovery scans AWS Bedrock as a source platform, so the AWS Agent Registry and IBM’s governance-side inventory overlap on the same estate with reconciliation unaddressed by either [S-2026-07-09-ibm-asset-discovery][inference].
- relates-to → Okta — identity-layer agent registry (Universal Directory) is a competing home for the agent inventory of record [S-2026-08-24-okta-agent-sso-ga][inference].
- partners-with → Archer — Archer Evolv AI Compliance is built on Bedrock Guardrails and distributed on AWS Marketplace; the hyperscaler primitive becomes a shared dependency of a GRC vendor’s governance layer [S-2026-09-15-archer-evolv-ai-compliance].
Tracked changes
- 2026-08-18 — Amazon Bedrock AgentCore payments GA: delegated stablecoin-wallet payments under session-level deterministic spend caps and expiry; Machine Payment Protocol and x402 “upto” scheme; launch customers non-FS [S-2026-08-18-aws-agentcore-payments-ga].
- 2026-08 (day unstated) — AWS Agent Registry GA with AWS Organizations auto-detection and customer-managed-key encryption; PrivateLink support; cross-account sharing via AWS RAM (ReadOnly/Consumer/Publisher/Admin); skill evaluators and DeepEval/AutoEval third-party evaluators in AgentCore Evaluations; JSON activity-log payloads in AgentCore Memory; memory/policy/harness in GovCloud (US-West) [S-2026-09-aws-agentcore-consent-portal-agent-registry].
- 2026-09 (day unstated) — Consent Portal for AgentCore Identity (end-user review/approval of agent resource access before the agent proceeds); TypeScript agent-framework support in AgentCore Evaluations [S-2026-09-aws-agentcore-consent-portal-agent-registry].
- 2026-09-15 — (third-party) Archer launches Evolv AI Compliance on native Bedrock Guardrails, available on AWS Marketplace [S-2026-09-15-archer-evolv-ai-compliance].
- 2026-09-15 (logged 2026-09-17; Salesforce-authored partner story, not an AWS release) — Dreamforce 2026: Informatica headless MCP servers (platform administration, catalog discovery/enrichment, data-quality scores, master-data retrieval) stated as GA from Amazon Bedrock AgentCore and Amazon Quick; Salesforce Data 360 zero copy extended to Glue/S3 Iceberg, Aurora, RDS and SageMaker Lakehouse; Salesforce relays a claim that Bedrock model choice brings “HIPAA, PCI, SOC 2, and ISO 42001 compliance and full audit trails built in” for regulated industries — no certificate or scope cited ⚠️. Per-vendor detail on Informatica [S-2026-09-15-salesforce-aws-dreamforce-informatica-headless].
Open Questions
- Is a Consent Portal approval a retained, exportable record (who, what scope, when, which agent), and does it meet the “meaningful human involvement” tests of GDPR Art. 22 / EU AI Act Art. 14 for the action the agent then takes — or is it a transient OAuth step? Not stated [S-2026-09-aws-agentcore-consent-portal-agent-registry].
- Does AWS Agent Registry cover anything beyond AgentCore Runtimes and Gateways (as documented, no), and how does an EU/UK FS deployer reconcile it with governance-platform, security and identity inventories of the same agents? [S-2026-09-aws-agentcore-consent-portal-agent-registry][inference]
- Who sets and reviews payment-session caps in an enterprise deployment (developer vs risk function), and are session logs tamper-evident with a stated retention? Unaddressed [S-2026-08-18-aws-agentcore-payments-ga].
- EU-region availability and data residency for Consent Portal and Registry are unstated on the release-notes page (GovCloud US-West is the only region named for the August memory/policy/harness entry) [S-2026-09-aws-agentcore-consent-portal-agent-registry].
Sources
- S-2026-08-18-aws-agentcore-payments-ga — AWS launch blog, AgentCore payments GA (18 Aug 2026), fetched in full (medium authority; primary, self-interested).
- S-2026-09-aws-agentcore-consent-portal-agent-registry — AWS AgentCore Developer Guide release notes, September and August 2026 sections, fetched in full (medium authority; official documentation; month-level dates only).
- S-2026-09-15-archer-evolv-ai-compliance — Archer Evolv AI Compliance launch release (15 Sep 2026), fetched in full (medium authority; third-party vendor primary describing its use of Bedrock Guardrails; AWS-side claims not confirmed by AWS).
- S-2026-09-15-salesforce-aws-dreamforce-informatica-headless — Salesforce–AWS Dreamforce 2026 partner story (15 Sep 2026), fetched in full (medium authority; Salesforce-authored; AgentCore/Quick as consumers of Informatica MCP context; ISO 42001 assertion uncertificated).