Kiro

AWS

Vendor

AWS agentic development environment (IDE, CLI, web) built around spec-driven development; successor to Amazon Q Developer.

Curated by Tiberiu ArvaVerified

Proprietary

Strengths

  • Specs, steering files and hooks
  • Admin model and MCP allow-lists
  • Prompt logs and CloudTrail

Practitioner note

Default migration target for Amazon Q Developer estates: plan the move before the 2027-04-30 end of support, and use IAM Identity Center with model and MCP allow-lists before enabling Cloud Sessions, which are off by default.

Warning

Kiro: AWS announced on 2026-04-30 that Amazon Q Developer IDE plugins and paid subscriptions reach end of support on 2027-04-30 and positioned Kiro as the transition path. Kiro Mobile is in preview.

Governance posture

Reviewed 2026-09-30
PartialData residency

Enterprise content stored in the region where the profile is configured; cross-region Bedrock inference within a geography; free/individual content stored in US East (N. Virginia).

Source
YesDeployment model

Desktop IDE and CLI clients with AWS-hosted inference; no self-hosted option. (saas)

Source
YesAudit logging

CloudTrail API events, prompt logs of IDE/CLI chat prompts, and per-user activity reports.

Source
UnknownSOC 2

Kiro compliance page lists HIPAA eligibility and ISO 27001 only; not found in AWS SOC services-in-scope list at review time.

YesISO 27001

Kiro is in scope of AWS ISO/IEC 27001:2022 certification (EY CertifyPoint).

Source
UnknownISO 42001

Not listed on the Kiro compliance validation page at review time.

UnknownEU AI Act

Assessed limited-risk by product category (general-purpose assistant); no published AWS EU AI Act conformity statement for this product. (role: limited-risk)

YesLicense risk

Proprietary AWS service; AWS identity and billing lock-in. (medium)

Source

EU AI Act obligations

Risk tier: Limited risk · as of 2026-08-23

Source-backed information mapped from Kiro's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

Article 4AI literacy

Providers and deployers must take measures to ensure a sufficient level of AI literacy in staff and other persons operating AI systems on their behalf.

Applies from

Official text
Article 50Transparency for certain AI systems

People must be informed when they interact with an AI system; synthetic audio, image, video, and text content must be marked as artificially generated, and deepfakes disclosed.

Applies from

Official text

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.