AWS introduces temporal policies and rate limiting for Amazon Bedrock AgentCore to control AI agent behavior and costs
Feature update ● Confirmed 95% confidence first seen
AWS announced new security and cost control features for Amazon Bedrock AgentCore, including temporal policies that evaluate sequences of agent actions using a new open-source policy language called Dogwood, and rate limiting capabilities to cap resource consumption per user. These features shift security enforcement from application code to infrastructure, allowing organizations to enforce stateful rules like budget limits, transaction matching, and cumulative exposure controls across multi-step agent interactions.
Decision brief
- What changed
- AWS announced new Bedrock AgentCore capabilities: temporal policies that evaluate sequences of agent actions (up to 24 hours of session history) using the new Dogwood policy language built on Cedar, plus rate limiting features that cap per-user consumption across tools and models using metrics like RPM, TPM, and CPS.
- Why it matters
- These features move security and cost enforcement from custom application code into managed infrastructure, addressing a known gap where per-action authorization checks miss cumulative risks like budget overruns, unauthorized aggregate exposure, or hallucinated data propagating across tool calls in agentic workflows. For enterprises deploying AI agents at scale, this reduces custom engineering burden for governance and cost control, but also signals that AWS is positioning itself as the governance layer for agentic AI, which has implications for vendor lock-in and architecture decisions.
- Evidence
- All three articles are AWS's own Machine Learning blog posts, so coverage is from a single source (the vendor) with no independent third-party verification; the three posts are consistent in describing the same feature set with complementary technical detail (overview, rate-limiting configuration, temporal policy mechanics).
- What remains uncertain
- It is unclear how these features perform in production at scale, what the pricing model for rate-limited or temporal-policy-evaluated requests will be, and how Dogwood as a new open-source policy language will be adopted or audited by third parties. There is no independent customer or analyst commentary yet confirming real-world effectiveness or limitations.
- Monitor next
- Watch for early customer case studies, third-party security audits of Dogwood/Cedar-based policies, or analyst commentary assessing whether these controls meaningfully reduce agentic AI incidents or costs in production deployments.
Analytical support, not advice — assumptions and open questions stated above.