Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The terms require that any autonomous or semi-autonomous software agent accessing Amazon Services must identify itself as an agent in HTTP/HTTPS request headers, must not mimic human behavior or circumvent CAPTCHA systems, and must respond truthfully to human-or-computer verification prompts. Amazon reserves the right to limit or block agent access by technical or other means.
This analysis describes what Amazon's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes specific technical and behavioral requirements for automated software, including AI agents and RPA tools, accessing Amazon Services, creating compliance obligations for developers and enterprises deploying such systems against Amazon's platform.
This clause applies to developers and enterprises deploying autonomous or semi-autonomous software to interact with Amazon Services, requiring technical self-identification in all HTTP/HTTPS requests and prohibiting human-mimicry or CAPTCHA circumvention. Amazon reserves the right to limit agent access at its sole discretion.
Cross-platform context
See how other platforms handle Agent Transparency and Access Requirements and similar clauses.
Compare across platforms →Monitoring
Amazon has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"No Agent may access, use, or interact with Amazon Services unless, at all times, it identifies itself and operates in strict accordance with the requirements in section 3 of these Agent Terms. In addition, no Agent may access, use, or interact with Amazon Services if we have requested that the Agent refrain from accessing, using, or interacting with any Amazon Service. Agents must: In all HTTP/HTTPS requests, identify that the request is from an Agent and disclose the name of the Agent by including the following in the request's user agent string: "Agent/[agent name]" (e.g., Agent/AmazonAgent). Not conceal or obfuscate that any access, use, or interactions are from an Agent, such as by (a) mimicking the speed or pattern of human keystrokes, page navigation, or other interactions or (b) completing or circumventing CAPTCHAs or other measures intended to distinguish computers from humans. Respond truthfully to any question or prompt seeking to determine if interactions are coming from a human or a computer. Not circumvent or otherwise avoid any measure intended to block, limit, modify, or control whether and how Agents access, use, or interact with an Amazon Service.Excerpt from Amazon's Conditions of Use
1) REGULATORY LANDSCAPE: The Agent Terms do not directly cite a specific regulatory framework, but they engage FTC guidance on automated systems transparency and may interact with the Computer Fraud and Abuse Act (CFAA) in the context of unauthorized automated access to online services. For EU-based deployments, the EU AI Act's provisions on transparency for AI systems that interact with humans may be relevant. Bot and automated access regulations at the state level, including California's Bolstering Online Transparency (BOT) Disclosure Act, may also interact with this provision. 2) GOVERNANCE EXPOSURE: Medium. Enterprises using robotic process automation (RPA), AI agents, or automated workflows to access Amazon Services, such as for procurement, inventory management, or price monitoring, must evaluate whether their systems comply with the self-identification and anti-obfuscation requirements. Non-compliance may result in technical blocking or account enforcement actions at Amazon's sole discretion. 3) JURISDICTION FLAGS: California's BOT Disclosure Act applies to automated accounts on online platforms and may create overlapping obligations for California-based operators. EU AI Act transparency requirements may apply to EU-based developers of agent systems. The provision applies globally as written. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams and developers building integrations with Amazon Services via automated systems should review technical architectures to confirm that user-agent string requirements are implemented. Third-party RPA vendors or software providers whose tools access Amazon Services on behalf of users may also need to be evaluated for compliance with these requirements. 5) COMPLIANCE CONSIDERATIONS: Organizations deploying automated agents against Amazon Services should conduct a technical audit to verify HTTP/HTTPS header compliance, confirm that CAPTCHA circumvention tools are not in use, and update vendor agreements with automation providers to incorporate these requirements. Internal AI governance and software procurement policies should be updated to reference the Agent Terms.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes specific technical and behavioral requirements for automated software, including AI agents and RPA tools, accessing Amazon Services, creating compliance obligations for developers and enterprises deploying such systems against Amazon's platform.
This clause applies to developers and enterprises deploying autonomous or semi-autonomous software to interact with Amazon Services, requiring technical self-identification in all HTTP/HTTPS requests and prohibiting human-mimicry or CAPTCHA circumvention. Amazon reserves the right to limit agent access at its sole discretion.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Amazon.