Amazon Bedrock AgentCore is now available in AWS GovCloud (US-West)
Government agencies and regulated enterprises can now build and deploy production-ready AI agents in a compliant, fully managed environment.
View original announcement →Visual Summary
What's New
Amazon Bedrock AgentCore is now generally available in the AWS GovCloud (US-West) region, extending enterprise-grade agentic AI capabilities to government and regulated workloads with elevated compliance requirements. AgentCore is a fully managed platform that enables organizations to build, deploy, and operate AI agents at scale without managing underlying infrastructure. This expansion allows federal agencies, defense contractors, and other regulated entities to leverage production-ready agentic AI while adhering to the strict security and compliance controls mandated by their operating environments.
How It Works
- AgentCore is composed of several modular, composable services that can be used together or independently. AgentCore Runtime provides the execution environment for AI agents, enforcing complete session isolation and supporting long-running, stateful workloads. AgentCore Gateway acts as a protocol translation layer, converting existing REST APIs and AWS Lambda functions into agent-consumable tools via the Model Context Protocol (MCP), enabling agents to securely interact with enterprise data sources and services. AgentCore Identity integrates with existing identity providers (e.g., IAM, SAML, OIDC-compliant systems) to handle automated authentication and fine-grained permission delegation for agents acting on behalf of users or systems. AgentCore Observability and Evaluations rounds out the platform with real-time telemetry, logging, and continuous quality assessment pipelines that monitor agent behavior and output quality in production.
- The platform is framework-agnostic and model-agnostic, supporting any orchestration framework (e.g., LangChain, LlamaIndex, custom) and any foundation model accessible within the region.
Why It's Important
- The availability of AgentCore in AWS GovCloud (US-West) is significant because it removes a critical barrier for government agencies and highly regulated industries—such as defense, intelligence, healthcare, and financial services—that are prohibited from running sensitive workloads outside of FedRAMP-authorized, ITAR-compliant, or similarly controlled environments.
- Previously, these organizations faced a difficult trade-off between adopting cutting-edge agentic AI capabilities and maintaining regulatory compliance.
- With this launch, they can now accelerate the path from AI prototype to production deployment without compromising on security posture, data residency requirements, or audit controls.
- The managed, infrastructure-free nature of the platform also reduces operational burden on teams that may lack deep MLOps expertise.
How It's Different
- Prior to this announcement, AgentCore was available only in standard AWS commercial regions, effectively excluding GovCloud-bound workloads from its capabilities.
- Organizations in regulated environments were forced to either build custom agentic infrastructure from scratch—handling session management, tool integration, identity delegation, and observability independently—or use less capable, piecemeal solutions.
- AgentCore differentiates itself from DIY approaches and earlier Bedrock Agents by offering a unified, production-hardened platform with native MCP support for tool integration, built-in session isolation at the runtime level, and integrated evaluation pipelines, all within a single managed service.
- Compared to self-managed agent frameworks deployed on EC2 or ECS in GovCloud, AgentCore eliminates infrastructure management overhead while providing compliance-ready controls out of the box.
When to Prefer It
- Choose AgentCore in GovCloud (US-West) when your workload involves sensitive government data, classified or controlled unclassified information (CUI), ITAR-regulated material, or any data subject to FedRAMP High, DoD IL2/IL4/IL5, or similar compliance frameworks that require data residency within GovCloud boundaries.
- It is the preferred option when you need to rapidly operationalize AI agents—particularly multi-step, long-running agents that call enterprise APIs or internal tools—without building and maintaining custom orchestration infrastructure.
- It is also the right choice when your organization requires auditable agent behavior, fine-grained identity and permission controls tied to existing enterprise identity providers, and continuous quality monitoring in production.
- Teams that want framework and model flexibility without sacrificing compliance controls will find AgentCore particularly well-suited to their needs.
Availability
- Amazon Bedrock AgentCore is now generally available (GA) in the AWS GovCloud (US-West) region as of May 5, 2026.
- It is also available in standard AWS commercial regions where it was previously launched.
- As with all GovCloud services, access requires an AWS GovCloud account, which is restricted to U.S. persons and entities meeting eligibility requirements.
- Specific model availability within GovCloud may be more limited than in commercial regions, depending on which foundation models have been authorized for use in that environment.
- Users should consult the official GovCloud documentation for the current list of supported models, service quotas, and any feature parity gaps relative to the commercial region offering.