Change record
CA-C-002819
AWS Service Terms | AWS Bedrock
Entity
Date detected
June 10, 2026
Effective date
June 10, 2026
Severity
Direction
Negative
Affected users
all users aws bedrock users anthropic model users
Taxonomy
Consent expansion
Changes
+1 sentence added · 7 sentences modified
Stay ahead of the changes
Track AWS Bedrock and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF

Event Summary

AWS updated its Service Terms on June 10, 2026 to add AWS FinOps Agent (Preview) to the list of AI Services and services that incorporate generative AI features. More substantially, AWS restructured and expanded its abuse detection provisions: it now requires explicit consent from users of certain Anthropic models for AWS to transfer user content and metadata to Anthropic for abuse detection processing, and it clarified that Bedrock stores inputs and outputs for up to 30 days solely for abuse detection purposes on identified models. This shifts abuse detection from an implicit AWS-only process to one that may involve third-party model providers with user consent.

MEDIUM

Consumer Impact

The updated terms now require users of certain Anthropic models to provide explicit consent for AWS to transfer their content and associated metadata to Anthropic for abuse detection and processing. Previously, abuse detection was described as an AWS-only internal function. The revised terms clarify that Bedrock stores service inputs and outputs for up to 30 days on identified models solely for abuse detection purposes. Users of Anthropic models can provide this consent through the opt-in mechanism described in the applicable service documentation, as stated in section 50.12.2.2 of the updated terms.

Governance Analysis

The updated terms introduce a material change in data flow governance: abuse detection on Anthropic models now requires explicit user consent and involves third-party data transfer, rather than remaining an implicit AWS-internal function. This operationally requires organizations to implement consent collection, disclose Anthropic's involvement in user agreements, and review third-party processing addenda. For compliance teams, this expands third-party risk governance and may trigger DPA amendment requirements.

Available Actions

Review whether you are using Anthropic models on AWS Bedrock; if so, evaluate the consent mechanism in your service documentation.

If deploying to end users, implement opt-in consent collection for Anthropic abuse detection and communicate the Anthropic Data Processing Addendum.

Review Anthropic's DPA and compare it against your existing data processing agreements and privacy frameworks.

If No Action Is Taken

If you use Anthropic models without providing explicit consent, abuse detection for those models will not function as designed, and AWS will not transfer content to Anthropic for violation detection.

Organizations that do not communicate the Anthropic transfer to downstream customers may face transparency and consent compliance gaps under GDPR, CCPA, or other privacy regimes.

Historical Context

ConductAtlas has recorded 7 material changes to this document over 31 days of monitoring (since May 2026). An additional minor or cosmetic changes were excluded.

3 of AWS Bedrock's significant changes have been classified as negative for consumers.

Key Clauses Affected

Anthropic model consent requirement (50.12.2.2)

Users must now explicitly consent for AWS to transfer content and metadata to Anthropic for abuse detection processing.

Abuse detection storage clarification (50.12.2)

Inputs and outputs are retained for up to 30 days on identified models solely for abuse detection, separated from service improvement uses.

Full clause-by-clause analysis available with Insight.

This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology

Evidence Verification

✓ Verified
Previous Version
fe2ad8e475c7223be304443c27fca9f43ce70ae337fb8c79c8f36229294fb926
June 2, 2026 01:09 UTC
✓ Verified
Current Version
9bceaf4786a44b4ea349566516e903525c04a9a287a26192860864f4923246ce
June 10, 2026 01:24 UTC
✓ Verified
Change Detected
June 10, 2026 01:24 UTC
Analysis Methodology
✓ Verified
Source Document
https://aws.amazon.com/service-terms/
Citation Record
Entity: AWS Bedrock
Document: AWS Service Terms
Record ID: CA-C-002819
Captured: 2026-06-10 01:24:50 UTC
URL: https://conductatlas.com/change/2026-06-10-aws-bedrock-aws-service-terms-2819/
Accessed: July 28, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.

Impact Summary

1
New obligations
1
Expanded
Users Added

If you use an Anthropic model on Bedrock, you must opt-in to allow AWS to send your content to Anthropic for abuse detection.

Developers Expanded

AWS will store your Bedrock inputs and outputs for up to 30 days on certain models specifically for detecting policy violations.

For legal and compliance teams

Institutional Analysis

Assessment

AWS restructured its abuse detection provisions on June 10, 2026 to require explicit user consent for certain Anthropic models to receive customer content and metadata. The change moves abuse detection from implicit AWS retention to an explicit third-party data transfer model. Organizations using Bedrock with Anthropic models will need to assess whether they can satisfy this consent requirement operationally, communicate it to their own end users if applicable, and potentially update vendor risk assessments and data processing documentation. The language references Anthropic's Data Processing Addendum, suggesting GDPR and standard processor frameworks may apply. No hard deadline is stated; the change appears to have taken effect on June 10, 2026.

ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002819.

Full Changes

View complete diff →

Document Context

Version history → Policy drift analysis → Document page →
Document
AWS Service Terms
Entity
AWS Bedrock
Captured
June 10, 2026
Source URL
https://aws.amazon.com/service-terms/
Other changes to AWS Service Terms
Previous change Jun 2, 2026
AWS Bedrock updated its abuse detection and monitoring practices on June 2, 2026. The revised terms clarify that abuse detection …
Medium Neutral
Next change Jun 16, 2026
AWS Bedrock updated its service terms on June 16, 2026 to add new provisions governing metadata sharing with Anthropic for …
Medium Negative
View full version history →
More from AWS Bedrock
Jul 18, 2026 Medium
AWS Service Terms

AWS updated its Service Terms on July 18, 2026 with several operational clarifications and restrictions. For On-Demand Capacity Reservations, the …

Jul 11, 2026 Low
AWS Service Terms

AWS Bedrock updated its AWS Clean Rooms service terms on July 11, 2026, revising how content deletion and resource removal …

Jul 1, 2026 Low
AWS Service Terms

AWS Bedrock updated its AWS Service Terms on July 1, 2026, removing several AWS IQ marketplace provisions and adding new …

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Stay ahead of the changes

Track AWS Bedrock policy changes

Get alerted when this policy changes again, including what changed and why it matters.

All AWS Bedrock changes →