Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy prohibits users from using AWS services or the AWS website for illegal activity, rights violations, incitement of violence or terrorism, child sexual exploitation content, network or system security violations, and spam distribution, including indirect facilitation of these activities by others.
This analysis describes what Amazon's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision extends the prohibition beyond direct use to facilitation and allowance of third-party conduct, meaning AWS customers may be held accountable under these terms for prohibited activity conducted by their own users or clients through AWS infrastructure.
Under this clause, users are responsible not only for their own conduct but also for prohibited conduct that they facilitate or permit others to carry out using their AWS resources. The agreement requires users to ensure that third parties accessing services through their accounts do not engage in any of the listed prohibited categories.
Cross-platform context
See how other platforms handle Prohibited Use Categories and similar clauses.
Compare across platforms →Monitoring
Amazon has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"You may not use, or facilitate or allow others to use, the Services or the AWS Site: for any illegal or fraudulent activity; to violate the rights of others; to threaten, incite, promote, or actively encourage violence, terrorism, or other serious harm; for any content or activity that promotes child sexual exploitation or abuse; to violate the security, integrity, or availability of any user, network, computer or communications system, software application, or network or computing device; to distribute, publish, send, or facilitate the sending of unsolicited mass email or other messages, promotions, advertising, or solicitations (or "spam").Excerpt from Amazon's AWS Acceptable Use Policy
(1) REGULATORY LANDSCAPE: The prohibition on child sexual exploitation content engages reporting obligations under applicable U.S. law, including those administered through NCMEC, and FTC enforcement authority applies to the spam prohibition under the CAN-SPAM Act. Network and system integrity prohibitions interact with the Computer Fraud and Abuse Act (CFAA). For EU-based customers or AWS operations subject to the Digital Services Act, platform-level obligations around illegal content removal and transparency may extend beyond this policy's current articulation. (2) GOVERNANCE EXPOSURE: Medium. The facilitation and allowance language extends compliance obligations to enterprise customers who provision AWS services to their own end users, requiring those customers to maintain downstream conduct controls. The breadth of the facilitation standard may create ambiguity about the degree of oversight required of multi-tenant AWS customers. (3) JURISDICTION FLAGS: EU and EEA customers face additional obligations under the Digital Services Act regarding illegal content; California and other U.S. states may impose specific requirements around spam and data security that interact with the network integrity prohibition. The child exploitation prohibition aligns with mandatory reporting obligations in the U.S. and many other jurisdictions, which are not addressed in the policy itself. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers and B2B resellers of AWS services should review whether their own customer agreements and terms of service are aligned with these prohibited use categories, as downstream violations may trigger enforcement against the AWS account holder. Procurement teams should assess whether sub-processor or reseller agreements incorporate equivalent conduct standards. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether their platforms or products built on AWS have adequate content moderation, abuse detection, and reporting mechanisms in place, as the policy's enforcement clause references a user's existing processes as a factor in determining violation outcomes. Documentation of these processes may be operationally relevant if a violation inquiry is initiated.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision extends the prohibition beyond direct use to facilitation and allowance of third-party conduct, meaning AWS customers may be held accountable under these terms for prohibited activity conducted by their own users or clients through AWS infrastructure.
Under this clause, users are responsible not only for their own conduct but also for prohibited conduct that they facilitate or permit others to carry out using their AWS resources. The agreement requires users to ensure that third parties accessing services through their accounts do not engage in any of the listed prohibited categories.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Amazon.