
Amazon Bedrock AgentCore, AWS's infrastructure for building and running AI agents at scale, now includes two new security and cost controls. Temporal policies enforce rules on sequences of agent actions (not just individual calls), letting teams block risky patterns like budget overruns or uncontrolled retries; these policies run in the gateway layer outside the agent's own code, so the agent cannot reason around them.
Rate limiting on the gateway lets teams cap requests, tokens, or connection time per user across all tools and models.
AWS built these features because McKinsey found that roughly 80% of organizations have already seen risky agent behavior, and security concerns are the leading barrier to agent adoption in enterprises.
What happened
Amazon Bedrock AgentCore now includes temporal policies (powered by a new open-source policy language called Dogwood) and rate limiting on its gateway. Temporal policies let teams enforce rules on sequences of agent actions—not just individual ones—to block risky patterns like spending across multiple small purchases that exceed a budget, or retrying failed tools without cost limits. Rate limiting lets teams cap how many requests, tokens, or connection time any user can consume per second or per minute across all tools and models behind the gateway.
Why it matters
According to McKinsey, roughly 80% of organizations have already encountered risky behavior from AI agents, and security and risk concerns are the leading barrier to scaling agentic AI. Most guardrails were designed for predictable software; agents decide their own path, so individual calls look legitimate even when the pattern violates policy. By moving controls into the infrastructure layer (the gateway) rather than application code, AWS aims to let security teams approve agents at scale instead of negotiating one-by-one, and to give enterprises the trust to extend autonomy without hesitation.
What to watch
Temporal policies and rate limiting take effect once configured, with no changes to agent code—and work for agents already in production. Dogwood is available as an open-source specification and reference implementation under Apache 2.0, which AWS says gives customers visibility into how policies are evaluated and lets the ecosystem build supporting tooling. The capabilities can be adopted independently of each other.
Ask the AI about this article →
Trust has become the limiting factor for agent adoption in enterprises. According to McKinsey data cited in the article, roughly 80% of organizations have already encountered risky behavior from AI agents, and security and risk concerns rank as the leading barrier to scaling agentic AI. The challenge is that agents operate differently from traditional software: they decide their own path in real time, making each individual action appear legitimate even when the overall pattern violates policy. AWS identified a gap in how guardrails work today. Most were designed for predictable software that follows a predetermined path; they typically check one action at a time in isolation. But agents can exploit this by, for example, placing a series of small orders that each sit under an approval threshold, or retrying a failed tool repeatedly until token budgets are exhausted. The platform saw that the pattern emerges only when you look at the sequence, not the isolated calls.
AWS's philosophy for AgentCore has been to embed security controls in the infrastructure layer rather than in application code, so every agent is protected consistently without teams having to rebuild and review controls separately. The gateway—a fully managed, serverless entry point that routes requests to models, agents, and knowledge bases—is the natural enforcement point because every call passes through it. The two new capabilities extend this model: temporal policies allow rules to be enforced on sequences of actions, evaluated deterministically at the gateway and logged with full context; and rate limiting caps consumption per user across every tool and model, addressing the real failure modes teams hit (retry loops showing up as request volume, reasoning-heavy tasks as tokens, long sessions as held connections). By moving these controls outside the agent's own code, AWS aims to make approval of autonomous systems a matter of platform configuration rather than repeated negotiation.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Phonely Ltd. launched Alma, a large language AI model built for voice agents and trained on over 10 million re…
Aranya Inc., a startup founded last year, launched today with $11 million in funding
CBTS Technology Solutions LLC launched Forge Agents, a platform that turns a plain-language job description in…
Imec CEO Patrick Vandenameele said at SEMICON Taiwan 2026 that the Belgian research center is broadening its c…

Alphabet's AI Overviews now reach over 2.5 billion monthly users through Google Search, and its ad business ge…

Sarah O’Connor's book 'We Are Not Machines' explores how mechanization and AI have transformed the workforce…
