Amazon Bedrock AgentCore release notes — Consent Portal for AgentCore Identity (Sept 2026) and AWS Agent Registry GA (Aug 2026)
Tag: S-2026-09-aws-agentcore-consent-portal-agent-registry Type: article (vendor product documentation — AWS Developer Guide release notes, fetched in full) Author(s): Amazon Web Services (documentation team; no individual byline) Date of source: 2026-09 (month-level; the page dates entries “September 2026” and “August 2026” with no day) ⚠️ Date ingested: 2026-09-11 Authority weight: medium — official product documentation (reliable on what AWS says a feature does and its stated prerequisites); self-interested; no effectiveness evidence, no standard, no retention model; day-level dating unavailable Raw file: /_raw_sources/S-2026-09-aws-agentcore-consent-portal-agent-registry.md
What it claims
Two governance-relevant additions appear in the AgentCore release notes.
September 2026 — Consent Portal for AgentCore Identity. AgentCore Identity “now offers a Consent Portal, a hosted portal that lets your end users grant consent for an agent to access resources on their behalf”. The deploying developer directs the user to the portal URL, “where they review and approve the requested access before the agent proceeds”. Prerequisites: an AgentCore Gateway configured with JWT inbound authentication as the portal’s source, and an identity provider whose permitted scopes include openid; portals are managed through create/get/list/update/delete operations. The same month AgentCore Evaluations added support for TypeScript versions of Strands Agents, LangGraph, OpenAI Agents and the Vercel AI SDK.
August 2026 — AWS Agent Registry general availability. The registry “is now generally available” with auto-detection across AWS Organizations — AgentCore Runtimes and Gateways in all member accounts are discovered and catalogued “into a single registry, with no per-account setup”, and “the catalog stays in sync as resources are created, updated, or deleted and as accounts join or leave the organization” — and customer-managed KMS key encryption of registry data at rest. Separate August entries add AWS PrivateLink access to the registry and cross-account sharing via AWS RAM with four managed permission levels (ReadOnly, Consumer, Publisher, Admin). Other August entries add skill-level evaluators (skill selection accuracy; skill instruction following, one result per skill invocation anchored to the tool-call span), DeepEval/AutoEval third-party evaluators, JSON “behavioral events, activity logs, and system events” payloads in AgentCore Memory, and GovCloud availability for memory, policy and harness.
The page names no regulatory standard, no retention or immutability property for Consent Portal decisions or registry records, and no customer.
Notable quotes
- “a hosted portal that lets your end users grant consent for an agent to access resources on their behalf … where they review and approve the requested access before the agent proceeds.” (September 2026 — Consent Portal)
- “Automatically discover and catalog AgentCore Runtimes and Gateways across your organization’s member accounts into a single registry, with no per-account setup. The catalog stays in sync as resources are created, updated, or deleted and as accounts join or leave the organization.” (August 2026 — Agent Registry)
- “Encrypt registry data at rest with a customer managed key from AWS KMS that you own and control.” (August 2026 — Agent Registry)
What’s speculative vs. asserted
Asserted (documentation): availability of the Consent Portal and its JWT/OIDC prerequisites; GA of AWS Agent Registry with org-wide auto-detection, CMK encryption, PrivateLink and RAM sharing; the evaluation and memory additions.
Not stated (gaps): exact dates (month only) ⚠️; whether and where consent grants are logged, their retention and exportability; whether the registry covers anything other than AgentCore Runtimes and Gateways (as documented it does not); any regulatory standard; any customer.
Vault inference: that the Consent Portal makes delegated human authority for agent actions an explicit, infrastructure-recorded step relevant to GDPR Art. 22 / EU AI Act Art. 14 human oversight and to SS1/23 / SR 11-7 delegation-of-authority controls; that an org-wide, continuously synced Agent Registry is a hyperscaler answer to the AI-inventory-of-record problem (EU AI Act record-keeping, ISO/IEC 42001 asset inventory) whose documented scope leaves cross-platform completeness to the buyer. AWS makes none of these claims.
Topics this feeds
- AI Governance Platforms — cloud-native governance locus: delegated human consent joins identity, action-authorisation and spending as infrastructure-layer agent-control primitives; a fifth/sixth claimant to the agent inventory of record (hyperscaler-native, auto-synced).
- AWS — company page (created on this second source).
Open questions raised
- Is a Consent Portal approval a retained, exportable record (who consented, to what scope, when, for which agent), or a transient OAuth step — and does it satisfy the “meaningful human involvement” test under GDPR Art. 22 or EU AI Act Art. 14 for the action the agent then takes?
- Does the AWS Agent Registry reconcile with governance-platform inventories (IBM AI Asset Discovery, which already scans Bedrock), security inventories (Obsidian, Neo) and identity registries (Okta, Hush) — or is it a seventh partial inventory?
- Does auto-detection cover agents built on Bedrock outside AgentCore, or self-hosted agents calling Bedrock models? As documented, no.