Amazon Bedrock AgentCore security, new compliance & cost pillars, and better email deliverability.
- NewAmazon Bedrock AgentCore security coverage — six new read-only checks over AgentCore’s control plane: memory, gateway, and runtime encryption without a customer-managed key; over-privileged gateway and runtime execution roles; a runtime reachable over the public network; and an unencrypted token vault. The AI Workload lens now covers both Bedrock Agents and AgentCore, so you’re ready before Bedrock Agents Classic closes to new customers on July 30, 2026 (existing agents keep running).
- NewA much bigger library of guidance: a dedicated AWS cost-optimization page, framework pages for HIPAA, PCI DSS, ISO 27001, NIST 800-53, AWS Well-Architected, and GDPR (joining SOC 2 and CIS), an AWS CSPM overview, and a new Guides hub with step-by-step how-tos — auditing public S3 access, rotating stale IAM keys, setting up Bedrock guardrails and logging, and cutting AWS cost waste. Every figure is pulled from the product, never hardcoded.
- ImprovedEmail deliverability — every account email (invites, setup links, alerts) now sends a plain-text alternative alongside the HTML, which helps inbox placement with providers like Microsoft 365 and Gmail. The docs FAQ now explains how to allowlist our sender if a message is quarantined.
- ImprovedThe AI Workload lens now catalogs twenty checks (up from fourteen with AgentCore), and its findings map into your compliance frameworks so an AI-workload gap reads as a specific control gap.