AWS Bedrock updated its abuse detection and monitoring practices on June 2, 2026. The revised terms clarify that abuse detection mechanisms may now store service inputs and outputs for up to 30 days to detect policy violations, and specify that if child sexual abuse material is detected, AWS may review flagged content before reporting it to authorities. The prior language described automated detection without explicitly stating the 30-day retention period or the review step.
Consumers: Your data sent to Bedrock services may be stored for up to 30 days while AWS runs automated checks for policy violations and safety issues.
The updated terms establish that AWS Bedrock may retain service inputs and outputs for up to 30 days solely to detect policy violations and harmful content, including potential child sexual abuse material. The revised language also specifies that if such material is detected, AWS may review the flagged content to confirm it before reporting to the National Center for Missing and Exploited Children or other authorities. These terms apply to 23 AWS services that incorporate Bedrock generative AI features.
ConductAtlas has recorded 6 material changes to this document (since May 2026). An additional minor or cosmetic changes were excluded.
2 of AWS Bedrock's significant changes have been classified as negative for consumers.
Updated language explicitly authorizes 30-day retention of inputs and outputs for detection of policy violations.
Clarified that AWS may review flagged content before reporting apparent child sexual abuse material to authorities.
Minor wording change from 'automated' to unqualified 'abuse detection mechanisms' applying to 23 enumerated AWS services.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
AWS clarified its abuse detection and data retention practices on June 2, 2026. The updated Service Terms now explicitly authorize 30-day retention of inputs and outputs for abuse detection and establish a two-step process for …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002570.
AWS Bedrock removed language requiring explicit consent to transfer customer content and metadata to Anthropic for abuse detection, and removed …
AWS expanded the list of services classified as 'Indemnified Generative AI Services' in its AWS Service Terms, adding three additional …
AWS Bedrock updated its Service Terms to introduce a new AWS (new) program and restructured billing and project management terms. …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.