Amazon Web Services rebuilds its cloud plumbing for AI agents
From faster runtimes to sandboxes and tighter permissions, AWS is reshaping core services so autonomous AI agents can run in production
Amazon Web Services is reworking parts of its cloud so it can host AI agents, not just the humans who build them.
The company is adding new building blocks: fast databases, compute sandboxes, and improved permissions. Agents need a different kind of house.
Over a few weeks in September and October 2026, AWS shipped a run of agent-focused updates. These include a reworked runtime, a managed agent service built with OpenAI, an automated architecture reviewer, and an open-source sandbox. The common thread is less about smarter models and more about where agents live, what they remember, and what they are allowed to touch.
What AWS actually shipped
The center of the effort is Amazon Bedrock AgentCore, which AWS has been rearchitecting with production deployment in mind. Its components include Runtime, Memory, Identity, and Policy Evaluations.
On or around September 18, 2026, AWS released a reworked AgentCore Runtime. The update adds memory reclamation and keeps cold-start latency consistent at approximately two seconds.
A cold start is the delay when a dormant service has to spin up before answering. A predictable two-second wake-up matters because agent workloads tend to be either long-running or bursty. Memory reclamation addresses the long-running side, keeping agents from hoarding resources over extended periods.
On September 29, 2026, AWS and OpenAI launched Bedrock Managed Agents in limited preview. The service lets OpenAI’s API-based agents run entirely within AWS. Customer data is meant to remain secure and inside the customer’s chosen jurisdiction, rather than traveling between providers.
AI, tech, and the markets they move—in one daily briefing.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
On October 1, 2026, AWS announced the public preview of the AWS Well-Architected Agent. This tool analyzes a customer’s infrastructure and returns prioritized recommendations on security and performance.
On October 7, 2026, AWS open-sourced Strands Box. It is a sandbox for agents with OS-level isolation and policy controls, including history-aware action controls. Instead of judging each action on its own, the system can weigh what the agent has already done before approving the next move.
Why agents need different infrastructure
Traditional cloud services were designed around a fairly simple model. A person or an application sends a request, the server responds, and everyone moves on. Agents break that pattern. They take sequences of actions, call tools, store context between steps, and operate with some degree of autonomy.
That creates three practical problems that AWS’s updates line up against directly. The first is compute: agents need environments where they can run code and take actions without endangering the rest of a company’s systems. Sandboxes like Strands Box target that need. The second is context: persistent memory lets agents carry state across long tasks. The third is permissions: Identity and Policy Evaluations address what software acting on a company’s behalf is actually allowed to do.
What this means for AWS and its customers
The most strategically interesting piece is the OpenAI partnership. By letting OpenAI’s agents run entirely inside AWS, Amazon positions its cloud as neutral ground where customers can use a leading outside model without moving their data elsewhere. The limited-preview status is worth keeping in mind, though. Access is restricted, and the terms of broader availability are not yet settled.
Several of these launches are previews, which means features, pricing, and performance can still change before general release. A consistent cold start of approximately two seconds is a useful benchmark, but real-world results will depend on how customers build and scale their agents.
The things to watch next are whether Bedrock Managed Agents moves beyond limited preview, how quickly developers pick up the open-source Strands Box, and whether the Well-Architected Agent becomes a standard part of how AWS customers review their setups.