Get the weekly digest
Every policy change across 844 tracked documents, once a week. No account needed.
AWS Bedrock updated its abuse detection and monitoring practices on June 2, 2026. The revised terms clarify that abuse detection mechanisms may now store service inputs and outputs for up to 30 days to detect policy violations, and specify that if child sexual abuse material is detected, AWS may review flagged content before reporting it to authorities. The prior language described automated detection without explicitly stating the 30-day retention period or the review step.
The updated terms establish that AWS Bedrock may retain service inputs and outputs for up to 30 days solely to detect policy violations and harmful content, including potential child sexual abuse material. The revised language also specifies that if such material is detected, AWS may review the flagged content to confirm it before reporting to the National Center for Missing and Exploited Children or other authorities. These terms apply to 23 AWS services that incorporate Bedrock generative AI features.
The updated terms establish explicit operational practices for how AWS Bedrock processes and retains service data for safety purposes. The 30-day retention window is now formally documented, which clarifies data handling practices for organizations that must disclose retention periods in their own customer agreements or privacy policies. The two-step CSAM reporting process (review before reporting) reflects a procedural refinement that may affect how organizations communicate about safety practices to their own customers.
→ Service inputs and outputs will be retained for up to 30 days as stated in the updated terms when using Bedrock-powered AWS services.
→ If child sexual abuse material is detected in your content, AWS will review it before reporting to authorities, as specified in the revised terms.
ConductAtlas has recorded 6 material changes to this document (since May 2026). An additional minor or cosmetic changes were excluded.
2 of AWS Bedrock's significant changes have been classified as negative for consumers.
Updated language explicitly authorizes 30-day retention of inputs and outputs for detection of policy violations.
Clarified that AWS may review flagged content before reporting apparent child sexual abuse material to authorities.
Minor wording change from 'automated' to unqualified 'abuse detection mechanisms' applying to 23 enumerated AWS services.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
Your data sent to Bedrock services may be stored for up to 30 days while AWS runs automated checks for policy violations and safety issues.
AWS clarified its abuse detection and data retention practices on June 2, 2026. The updated Service Terms now explicitly authorize 30-day retention of inputs and outputs for abuse detection and establish a two-step process for child safety reporting: review followed by disclosure to authorities. Organizations using Bedrock-powered services should review whether this retention window and detection scope align with their data governance policies, particularly if they operate in jurisdictions with strict data retention or processing requirements. The change does not impose new reporting obligations on customers, but clarifies AWS's own operational practices.
Full institutional analysis
Regulatory exposure, obligation analysis, escalation trigger, board language, and recommended action.
Analyst $49/moConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002570.
AWS updated its Service Terms on July 18, 2026 with several operational clarifications and restrictions. For On-Demand Capacity Reservations, the …
AWS Bedrock updated its AWS Clean Rooms service terms on July 11, 2026, revising how content deletion and resource removal …
AWS Bedrock updated its AWS Service Terms on July 1, 2026, removing several AWS IQ marketplace provisions and adding new …
Buried in Robinhood's customer agreement is broad authority to close your positions, suspend your account, and force arbitration. Here is w…
Stripe's terms authorize fund reserves, payout withholding, and account termination. Here is what the agreement states and what business ow…
Get alerted when this policy changes again — including what changed and why it matters.