← Back to all announcements
★☆☆☆☆ 14/05/2026

AWS Transform now supports customer-owned artifact stores

Enterprises can now store Transform migration artifacts in their own S3 buckets with custom KMS encryption, unlocking compliance for regulated industries.

View original announcement →

What's New

AWS Transform now allows customers to designate their own Amazon S3 buckets as the storage destination for transformation artifacts generated during assessment, migration, and modernization workflows. Customers can optionally encrypt these artifacts using their own AWS KMS keys and manage bucket access policies entirely within their own AWS accounts. This update is specifically designed to help enterprises in regulated industries satisfy data sovereignty, residency, and compliance requirements while continuing to leverage the full AWS Transform AI-powered experience.

How It Works

  • Customer-owned S3 bucket configuration: Customers designate a specific S3 bucket in their own AWS account as the artifact store for AWS Transform, replacing the default service-managed storage.
  • Customer-managed KMS encryption: Artifacts can optionally be encrypted using a customer-managed AWS KMS key (CMK), giving customers full control over encryption key lifecycle, rotation, and access policies.
  • Self-managed access policies: Bucket access policies, IAM permissions, and resource-based policies are defined and enforced entirely within the customer's AWS account, not delegated to the service.
  • Direct file uploads by practitioners: Migration practitioners can upload files (e.g., discovery data, configuration files, assessment inputs) directly to the configured bucket, where transformation agents can immediately consume them.
  • Cross-account artifact centralization: Organizations can configure a single S3 bucket to centralize artifacts from multiple AWS accounts, enabling consolidated governance and auditability across large enterprise environments.
  • No workflow disruption: The underlying AWS Transform experience — including its AI-driven agents and guided transformation steps — remains unchanged; only the storage backend is redirected.

Why It's Important

  • Regulated industry compliance: Industries such as financial services, healthcare, and government often have strict data residency and sovereignty mandates that prohibit sensitive data from residing in service-managed storage outside the customer's control boundary.
  • Audit and governance readiness: Storing artifacts in a customer-owned bucket means all access logs, versioning, and lifecycle policies are under the customer's direct control, simplifying audit trails for compliance frameworks like HIPAA, PCI-DSS, and FedRAMP.
  • Encryption key sovereignty: With customer-managed KMS keys, organizations can revoke access to transformation artifacts at any time by disabling or deleting the key, a critical control for zero-trust and data protection strategies.
  • Enterprise-scale centralization: Large organizations running transformations across dozens of AWS accounts can now funnel all artifacts into a single governed bucket, reducing operational fragmentation and improving visibility.
  • Reduced trust boundary concerns: Customers who were previously hesitant to use AWS Transform due to uncertainty about where sensitive migration data was stored now have a clear, controllable answer.

How It's Different

  • Previously, artifact storage was service-managed: Before this launch, AWS Transform stored artifacts in AWS-managed infrastructure, giving customers limited visibility and control over where their data resided.
  • Full encryption key ownership vs. AWS-managed encryption: Unlike the default model where AWS manages encryption, customers can now use their own CMKs, enabling key revocation, custom rotation schedules, and integration with existing enterprise key management processes.
  • Customer IAM policies vs. service-defined access: Access control is now expressed through the customer's own IAM and S3 bucket policies rather than being implicitly governed by the service, aligning with least-privilege and zero-trust architectures.
  • Cross-account aggregation capability: The ability to centralize artifacts from multiple accounts into one bucket is a new operational pattern not available with the default service-managed storage model.
  • No feature trade-off: Unlike some "bring your own" integrations that limit service functionality, this update preserves the full AWS Transform feature set, making it a pure capability addition.

When to Prefer It

  • Regulated industries with data residency requirements: Use customer-owned artifact stores when operating under regulations (e.g., GDPR, HIPAA, FedRAMP) that require sensitive data to remain within a specific account, region, or organizational boundary.
  • Organizations with existing CSPM or DLP tooling: When your security team already monitors specific S3 buckets using Cloud Security Posture Management or Data Loss Prevention tools, routing Transform artifacts to those buckets ensures consistent coverage.
  • Multi-account enterprise environments: When running large-scale migrations across many AWS accounts, centralizing artifacts in a single governed bucket simplifies reporting, auditing, and lifecycle management.
  • Zero-trust security postures: When your organization requires the ability to immediately revoke access to sensitive data (e.g., during an incident), customer-managed KMS keys provide that kill-switch capability.
  • Enterprises with strict change management processes: When internal policies require all data stores to be inventoried, tagged, and approved before use, owning the bucket ensures Transform artifacts go through standard provisioning workflows.
  • Scenarios requiring long-term artifact retention policies: When compliance mandates specific retention or deletion schedules for migration artifacts, customer-owned buckets allow direct application of S3 Lifecycle policies aligned to those requirements.

Availability

  • General Availability (GA): This feature is generally available as of May 14, 2026; it is not in preview.
  • Regional availability: Available in all AWS Regions where AWS Transform is currently offered; no additional regional enablement is required.
  • Pricing model: No additional charge is announced for this capability itself; standard Amazon S3 storage, request, and data transfer costs apply to the customer-owned bucket, and AWS KMS key usage is billed at standard KMS rates if a CMK is configured.
  • Prerequisite: Customers must have an existing or newly created S3 bucket in their AWS account and appropriate IAM permissions to configure it as the artifact store within AWS Transform.
  • Limitation — no retroactive migration: Artifacts previously stored in the service-managed default store are not automatically migrated to the customer-owned bucket; this applies to new artifacts generated after configuration.
  • Documentation: Full setup instructions are available in the AWS Transform User Guide.

Tags

Servicesaws-transform
Typenew-featuresecurity
Conceptsagentic-ai
Use Casesenterprisemigration
GeographyGlobal

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.