Control agent behaviors and cost beyond a single action: new capabilities in Amazon Bedrock AgentCore
AWS adds temporal policies to AgentCore to enforce limits across agent action sequences, not just individual calls
“security controls belong in the infrastructure layer, enforced consistently across every agent, rather than in application code where each team implements them differently.”
AWS announced temporal policies and rate limiting in Amazon Bedrock AgentCore, powered by Dogwood, a new open-source policy language designed specifically for AI agents. The key architectural advance is moving from stateless per-request authorization to sequence-aware enforcement that evaluates whether an agent's cumulative actions—across a session—remain within allowed bounds. This directly targets the class of agent failures where each individual action passes a guardrail but the aggregate pattern causes harm, a problem McKinsey estimates has affected roughly 80% of organizations deploying agents.