AWS announces temporal policies and rate limiting features for Amazon Bedrock AgentCore
Feature update ● Confirmed 95% confidence first seen
Amazon announced new security and cost control capabilities for Bedrock AgentCore, including temporal policies that evaluate sequences of agent actions using the Dogwood policy language to enforce stateful authorization rules, and rate limiting features that cap consumption per user across tools and models with granular metrics including requests per minute, tokens per minute, and connections per second.
Decision brief
- What changed
- AWS announced new Bedrock AgentCore capabilities: temporal policies that evaluate sequences of agent actions (up to 24 hours of session history) using the new Dogwood policy language built on Cedar, plus rate limiting features that cap per-user consumption across tools and models using metrics like RPM, TPM, and CPS.
- Why it matters
- These features move security and cost enforcement from custom application code into managed infrastructure, addressing a known gap where per-action authorization checks miss cumulative risks like budget overruns, unauthorized aggregate exposure, or hallucinated data propagating across tool calls in agentic workflows. For enterprises deploying AI agents at scale, this reduces custom engineering burden for governance and cost control, but also signals that AWS is positioning itself as the governance layer for agentic AI, which has implications for vendor lock-in and architecture decisions.
- Evidence
- All three articles are AWS's own Machine Learning blog posts, so coverage is from a single source (the vendor) with no independent third-party verification; the three posts are consistent in describing the same feature set with complementary technical detail (overview, rate-limiting configuration, temporal policy mechanics).
- What remains uncertain
- It is unclear how these features perform in production at scale, what the pricing model for rate-limited or temporal-policy-evaluated requests will be, and how Dogwood as a new open-source policy language will be adopted or audited by third parties. There is no independent customer or analyst commentary yet confirming real-world effectiveness or limitations.
- Monitor next
- Watch for early customer case studies, third-party security audits of Dogwood/Cedar-based policies, or analyst commentary assessing whether these controls meaningfully reduce agentic AI incidents or costs in production deployments.
Analytical support, not advice — assumptions and open questions stated above.