AWS Bedrock removed language requiring explicit consent to transfer customer content and metadata to Anthropic for abuse detection, and removed the sentence describing that transfer. The updated terms now state that abuse detection for certain Anthropic models requires consent via an opt-in mechanism in service documentation, but the removed language no longer mentions the Data Processing Addendum or explicit instruction to transfer data. Additionally, the terms now explicitly disclose that Bedrock abuse detection on Kiro includes retention and potential human review of inputs and outputs when selecting certain models.
Consumers: The contract no longer explicitly mentions a Data Processing Addendum, but you still must opt-in to allow your content to be sent to Anthropic for abuse detection.
Consumers: Kiro terms now explicitly tell you that your content may be kept and reviewed by humans as part of abuse detection.
The updated terms remove the explicit reference to a Data Processing Addendum governing Anthropic data transfers, though the requirement to obtain opt-in consent for Anthropic model use remains in place. For Kiro users, the revised language now explicitly states that abuse detection includes retention and potential human review of inputs and outputs when selecting certain models. Users of Anthropic models on Bedrock should verify opt-in consent mechanisms in service documentation to understand data handling practices.
→ Review the opt-in consent mechanism for Anthropic models in your Bedrock service documentation to confirm you understand what content and metadata will be transferred.
→ For Kiro users: review the updated abuse detection disclosure in the terms to understand that your inputs and outputs may be retained and subject to human review.
ConductAtlas has recorded 13 material changes to this document over 115 days of monitoring (since May 2026). An additional minor or cosmetic changes were excluded.
6 of AWS Bedrock's significant changes have been classified as negative for consumers.
Removed explicit Data Processing Addendum reference but retained opt-in consent requirement; transfer authorization now flows through service documentation rather than explicit contractual instruction.
Expanded to explicitly state that abuse detection includes retention and potential human review of inputs and outputs.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
AWS removed contractual language explicitly referencing a Data Processing Addendum for Anthropic abuse detection transfers while retaining the opt-in consent requirement. This change may affect how organizations document third-party data processing relationships in their vendor …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004805.
AWS expanded the list of services classified as 'Indemnified Generative AI Services' in its AWS Service Terms, adding three additional …
AWS Bedrock updated its Service Terms to introduce a new AWS (new) program and restructured billing and project management terms. …
AWS Bedrock updated its Professional Services Terms to incorporate a new data processing addendum (DPA) when customers expressly direct AWS …
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.