← Back to all announcements
★★★☆☆ 21/05/2026

Quick Research now supports customer managed keys

Bring your own KMS keys to Quick Research for full encryption control, rapid key revocation, and audit-ready compliance in regulated environments.

View original announcement →

Visual Summary

graph TD A{{Quick Research CMK Support}}:::announced B(AWS KMS):::compute C(AWS CloudTrail):::compute D(Amazon Quick Research):::compute E([Encryption Control]):::feature F([Key Revocation]):::feature G([Audit Logging]):::feature H((Enterprise Users)):::external I(Quick Research Data):::storage H ==>|"manages keys"| A A ==>|"encrypts via"| B B -->|"protects"| I I -->|"serves"| D A -->|"enables"| E A -->|"enables"| F A -.->|"logs to"| C C -->|"provides"| G classDef announced fill:#ff9900,stroke:#ec7211,color:#fff,font-weight:bold classDef compute fill:#e3f2fd,stroke:#1565c0,color:#1565c0 classDef storage fill:#e8f5e9,stroke:#2e7d32,color:#2e7d32 classDef feature fill:#fff3e0,stroke:#e65100,color:#e65100 classDef external fill:#f5f5f5,stroke:#616161,color:#616161

What's New

Amazon Quick Research now supports customer-managed keys (CMK) via AWS Key Management Service (KMS), giving organizations direct control over the encryption keys protecting their business intelligence and research data. This feature enables enterprises with strict security and compliance requirements to bring their own symmetric KMS keys rather than relying solely on AWS-managed encryption. The capability is generally available across all AWS Regions where Amazon Quick Research is offered.

How It Works

  • CMK Integration via AWS KMS: Customers create symmetric KMS keys in the same AWS account and region as their Quick Research resources, then designate one as the default key per account per region.
  • Multiple CMK Support: The feature allows multiple CMKs to be associated with a single account, enabling granular encryption control across different datasets or organizational units.
  • Symmetric Keys Only: Only symmetric AWS KMS keys are supported; asymmetric keys are not compatible with this feature.
  • CloudTrail Audit Integration: All key usage and data access events are logged through AWS CloudTrail, providing a comprehensive, tamper-evident audit trail for security and compliance reviews.
  • Key Revocation: In the event of a security incident, access to a compromised key can be revoked within 15 minutes, limiting the blast radius of potential data exposure.
  • Same-Region Requirement: CMKs must reside in the same AWS account and region as the Quick Research resources they protect, ensuring data sovereignty and low-latency key operations.

Why It's Important

  • Regulatory Compliance: Organizations subject to frameworks such as HIPAA, FedRAMP, GDPR, or PCI-DSS often mandate customer-controlled encryption keys; this feature removes a previous blocker to adopting Quick Research in regulated environments.
  • Enhanced Security Posture: Owning the key lifecycle—creation, rotation, and deletion—means organizations are not dependent on AWS's key management schedule, reducing shared-responsibility ambiguity.
  • Rapid Incident Response: The ability to revoke key access within 15 minutes provides a meaningful operational control during active security incidents, limiting potential data exposure windows.
  • Auditability: Deep CloudTrail integration satisfies auditor demands for evidence of who accessed what data and when, which is critical for internal governance and external audits.
  • Enterprise Readiness: CMK support signals that Quick Research is maturing toward enterprise-grade security requirements, making it viable for use cases involving sensitive IP, financial data, or proprietary research.

How It's Different

  • Customer vs. AWS-Managed Keys: Previously, Quick Research relied on AWS-managed encryption keys, where AWS controlled the key material. CMK support shifts that control entirely to the customer.
  • Granular Multi-Key Management: Unlike a single default encryption model, this feature supports multiple CMKs per account, allowing different encryption policies for different datasets or business units—a level of granularity not available with AWS-managed keys.
  • Active Revocation Capability: AWS-managed keys cannot be revoked by the customer on demand; CMKs allow near-immediate revocation (within 15 minutes), a critical differentiator for incident response.
  • Full Audit Trail Ownership: With CMKs, CloudTrail logs for key usage are owned and accessible by the customer, whereas AWS-managed key usage logs are less directly surfaced to end users.
  • Compliance Posture: CMK support enables Quick Research to meet compliance requirements that explicitly prohibit the use of provider-managed keys, expanding its eligible deployment scenarios.

When to Prefer It

  • Regulated Industries: Use CMKs when operating in healthcare, financial services, government, or other sectors where regulations require demonstrable control over encryption key material.
  • Zero-Trust Security Architectures: Prefer CMKs when your security model mandates that no third party—including AWS—can access data without explicit customer-controlled key authorization.
  • Multi-Tenant or Multi-Business-Unit Environments: Use multiple CMKs to enforce encryption boundaries between different teams, projects, or data sensitivity levels within the same AWS account.
  • Active Incident Response Programs: Organizations with mature security operations centers (SOCs) that need the ability to rapidly revoke data access during a breach should leverage CMK revocation capabilities.
  • Audit-Intensive Workloads: When external auditors or internal compliance teams require detailed, customer-owned logs of every data access event, CMK + CloudTrail integration is the appropriate choice.
  • Data Sovereignty Requirements: Use CMKs when contractual or legal obligations require that encryption keys never leave a specific AWS account or region boundary.

Availability

  • GA Status: Generally available as of May 21, 2026; this is not a preview or beta feature.
  • Regional Availability: Available in all AWS Regions where Amazon Quick Research is supported, including US East (N. Virginia), US West (Oregon), and multiple Asia Pacific, Europe, and other regions.
  • Key Constraints: Only symmetric AWS KMS keys are supported; asymmetric keys are not compatible.
  • Account/Region Boundary: CMKs must be created in the same AWS account and region as the Quick Research resources they encrypt; cross-account or cross-region keys are not supported.
  • Default Key Limit: One default CMK per AWS account per region is enforced, though multiple CMKs can be configured for use across different datasets.
  • Pricing: AWS KMS charges apply for CMK creation, storage, and API calls; Quick Research feature enablement itself does not carry an additional announced surcharge, but customers should review KMS pricing for key usage costs.

Tags

Servicesquick
Typenew-featuresecurity
Conceptsdata-analytics
Use Casesenterprise
GeographyGlobal

Related Resources

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.