AWS updated its Service Terms on June 10, 2026 to add AWS FinOps Agent (Preview) to the list of AI Services and services that incorporate generative AI features. More substantially, AWS restructured and expanded its abuse detection provisions: it now requires explicit consent from users of certain Anthropic models for AWS to transfer user content and metadata to Anthropic for abuse detection processing, and it clarified that Bedrock stores inputs and outputs for up to 30 days solely for abuse detection purposes on identified models. This shifts abuse detection from an implicit AWS-only process to one that may involve third-party model providers with user consent.
The updated terms now require users of certain Anthropic models to provide explicit consent for AWS to transfer their content and associated metadata to Anthropic for abuse detection and processing. Previously, abuse detection was described as an AWS-only internal function. The revised terms clarify that Bedrock stores service inputs and outputs for up to 30 days on identified models solely for abuse detection purposes. Users of Anthropic models can provide this consent through the opt-in mechanism described in the applicable service documentation, as stated in section 50.12.2.2 of the updated terms.
The updated terms introduce a material change in data flow governance: abuse detection on Anthropic models now requires explicit user consent and involves third-party data transfer, rather than remaining an implicit AWS-internal function. This operationally requires organizations to implement consent collection, disclose Anthropic's involvement in user agreements, and review third-party processing addenda. For compliance teams, this expands third-party risk governance and may trigger DPA amendment requirements.
→ Review whether you are using Anthropic models on AWS Bedrock; if so, evaluate the consent mechanism in your service documentation.
→ If deploying to end users, implement opt-in consent collection for Anthropic abuse detection and communicate the Anthropic Data Processing Addendum.
→ Review Anthropic's DPA and compare it against your existing data processing agreements and privacy frameworks.
→ If you use Anthropic models without providing explicit consent, abuse detection for those models will not function as designed, and AWS will not transfer content to Anthropic for violation detection.
→ Organizations that do not communicate the Anthropic transfer to downstream customers may face transparency and consent compliance gaps under GDPR, CCPA, or other privacy regimes.
ConductAtlas has recorded 7 material changes to this document over 31 days of monitoring (since May 2026). An additional minor or cosmetic changes were excluded.
3 of AWS Bedrock's significant changes have been classified as negative for consumers.
Users must now explicitly consent for AWS to transfer content and metadata to Anthropic for abuse detection processing.
Inputs and outputs are retained for up to 30 days on identified models solely for abuse detection, separated from service improvement uses.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
If you use an Anthropic model on Bedrock, you must opt-in to allow AWS to send your content to Anthropic for abuse detection.
AWS will store your Bedrock inputs and outputs for up to 30 days on certain models specifically for detecting policy violations.
AWS restructured its abuse detection provisions on June 10, 2026 to require explicit user consent for certain Anthropic models to receive customer content and metadata. The change moves abuse detection from implicit AWS retention to an explicit third-party data transfer model. Organizations using Bedrock with Anthropic models will need to assess whether they can satisfy this consent requirement operationally, communicate it to their own end users if applicable, and potentially update vendor risk assessments and data processing documentation. The language references Anthropic's Data Processing Addendum, suggesting GDPR and standard processor frameworks may apply. No hard deadline is stated; the change appears to have taken effect on June 10, 2026.
ConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-002819.
AWS updated its Service Terms on July 18, 2026 with several operational clarifications and restrictions. For On-Demand Capacity Reservations, the …
AWS Bedrock updated its AWS Clean Rooms service terms on July 11, 2026, revising how content deletion and resource removal …
AWS Bedrock updated its AWS Service Terms on July 1, 2026, removing several AWS IQ marketplace provisions and adding new …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.