Amazon Bedrock AgentCore

AWS

Vendor

AWS services to run, govern and observe agents from any framework: Runtime, Gateway, Identity, Policy, Observability and Agent Registry.

Curated by Tiberiu ArvaVerified

Proprietary

Strengths

  • Agent Registry auto-discovery across AWS Organizations
  • Policy controls on agent-tool access
  • Per-service consumption pricing

Practitioner note

Use it as the governance and runtime layer for agents on AWS; the registry and policy pieces are strongest when agents run on AgentCore Runtime/Gateway. Bedrock Agents (the managed agent builder) is tracked separately.

Warning

Amazon Bedrock AgentCore: GA since October 2025; Policy GA March 2026; AWS Agent Registry GA August 2026 (preview from April 2026).

Governance posture

Reviewed 2026-09-30
PartialData residency

Regional service (including AWS GovCloud US-West); Agent Registry supports customer-managed KMS keys. No multi-cloud or sovereign option.

Source
YesDeployment model

Fully managed AWS service; no self-hosted option. (saas)

Source
YesAudit logging

Control-plane API calls (e.g. Agent Registry, Gateway) are logged to AWS CloudTrail as management events.

Source
YesSOC 2

AgentCore is in scope for SOC 2 per AWS compliance validation.

Source
YesISO 27001

AgentCore is compliant with ISO 27001:2022 (plus 27017, 27018, 27701).

Source
UnknownISO 42001

ISO 42001 is not listed on the AgentCore compliance validation page.

N/AEU AI Act

Infrastructure for building and governing agents, not itself an AI system placed on the market; obligations rest with the deployer. (role: not-applicable)

YesLicense risk

Proprietary AWS service; framework-agnostic agents, but registry, policy and identity are AWS-bound. (medium)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from Amazon Bedrock AgentCore's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Change history

Source-backed and auto-detected events for this tool, newest first.

  1. FeatureHigh impact

    AWS released the new AgentCore Runtime (V2) with consumption-based memory billing and about 2-second P75 cold starts, in five regions.

    The new AgentCore Runtime is now available in Amazon Bedrock AgentCore · AWS What’s New

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.