419 Total
203 High severity
188 Medium severity
28 Low severity

Key Facts

Do AWS Bedrock personnel have access to customer Content on AWS Nitro System EC2 instances?
AWS Bedrock personnel do not have access to customer Content on AWS Nitro System EC2 instances.
What will AWS Bedrock defend customers and their employees, officers, and directors against?
AWS Bedrock will defend customers and their employees, officers, and directors against any third-party claim alleging that Generative AI Output generated by an Indemnified Generative AI Service infringes or misappropriates that third party's intellectual property rights.
What does AWS Bedrock defend customers against regarding Generative AI Output generated by an Indemnified Generative AI Service?
AWS Bedrock will defend customers and their employees, officers, and directors against any third-party claim alleging that Generative AI Output generated by an Indemnified Generative AI Service infringes or misappropriates that third party's intellectual property rights.
What may AWS Bedrock do with AI Content processed by listed AI Services?
AWS Bedrock may use and store AI Content processed by listed AI Services to develop and improve the applicable AI Service and its underlying technologies.
What may AWS Bedrock do if a customer does not remove or disable access to Prohibited Content within 2 business days of notice?
AWS Bedrock may remove or disable access to Prohibited Content, or suspend the Services, if a customer does not remove or disable access to the Prohibited Content within 2 business days of AWS's notice.
May AWS Bedrock remove or disable access to Prohibited Content or suspend the Services?
AWS Bedrock may remove or disable access to Prohibited Content, or suspend the Services, if a customer does not remove or disable access to the Prohibited Content within 2 business days of AWS's notice.
Will AWS Bedrock use Individualized Usage Data or customer Content to compete with a customer's products and services?
AWS Bedrock will not use Individualized Usage Data or customer Content to compete with a customer's products and services.
What are customers responsible for providing?
AWS Bedrock requires customers to be responsible for providing legally adequate privacy notices and obtaining all necessary consents for the processing of personal data.
Must customers obtain all necessary consents for the processing of personal data?
AWS Bedrock requires customers to be responsible for providing legally adequate privacy notices and obtaining all necessary consents for the processing of personal data.
Are AWS Bedrock's defense and payment obligations under Section 50.10 subject to any damages cap under the Agreement?
AWS Bedrock's defense and payment obligations under Section 50.10 are not subject to any damages cap under the Agreement.
Stay ahead of the changes
Track AWS Bedrock and get the diff the day its terms change.
Summary

These terms govern how you and AWS Bedrock can use AWS services and what each side is responsible for. AWS Bedrock will defend you if a third party claims that AI-generated output infringed their intellectual property, and that protection is not capped by the Agreement's damages limits. However, you are fully responsible for giving privacy notices and obtaining consents before personal data is processed, you cannot cancel certain reserved pricing commitments once made, and you must not use the services to mine cryptocurrency or allow your end users to do so.

Analysis

The AWS Service Terms establish the substantive obligations, rights, and limitations governing customer use of AWS Bedrock and related AWS services. On data handling, AWS Bedrock personnel are barred from accessing customer Content on AWS Nitro System EC2 instances, and AWS Bedrock commits not to use Individualized Usage Data or customer Content to compete with customers, while retaining the right to use and store AI Content processed by listed AI Services for service development and improvement. The document places responsibility for legally adequate privacy notices and all necessary consents entirely on the customer, and conditions the application of Standard Contractual Clauses on both GDPR applicability and a transfer of Customer Data outside the EEA. AWS Bedrock provides an IP indemnification defense for customers against third-party claims arising from Generative AI Output produced by Indemnified Generative AI Services, with that defense and payment obligation explicitly carved out from the Agreement's damages cap. Additional provisions establish a 2-business-day window for customers to remediate Prohibited Content before AWS Bedrock may act unilaterally, impose joint and several liability across Management and Member Accounts in an Organization, prohibit safety-critical use of AWS IoT Services and customer facilitation of cryptocurrency mining, and render Savings Plans and certain EC2 reserved instruments noncancellable and nonrefundable for their full term.

What this means for you

As a customer, your Content on AWS Nitro System EC2 instances is inaccessible to AWS Bedrock personnel, and AWS Bedrock will not use your Individualized Usage Data or Content to compete with your products or services. However, if you use any listed AI Services, your AI Content processed by those services may be used by AWS Bedrock to develop and improve those services and their underlying technologies. You bear full responsibility for providing legally adequate privacy notices and obtaining all necessary consents before personal data is processed through the services — if you use AWS services to process personal data on behalf of others, you should ensure those notices and consents are in place before processing begins.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

18 important changes detected

18 versions captured · Last updated: July 2026

July 30, 2026

medium
What changed AWS Bedrock's service terms were updated in an update detected on July 30, 2026, with several operational refinements. The terms expanded the definition of 'AI Services' to explicitly include AWS IoT SiteWise Scenario Discovery, clarified constraints on its use by adding language prohibiting reliance on its data for vehicle safety determinations, and refined IoT service liability language. These changes establish explicit guardrails around automated decision-making in safety-critical contexts like vehicle systems.
Why this matters The updated terms now explicitly state that AWS IoT SiteWise Scenario Discovery is not designed for real-time vehicle control and cannot be used as the sole basis for determining vehicle safety or regulatory compliance. Organizations deploying this service must implement independent human monitoring and safety validation before using its outputs to support vehicle system decisions. The terms make clear that AWS assumes no responsibility for uses that violate these constraints.
View full change record →

July 18, 2026

medium
What changed AWS updated its Service Terms on July 18, 2026 with several operational clarifications and restrictions. For On-Demand Capacity Reservations, the terms now explicitly prohibit resale and reserve the right to cancel or terminate instances if resale is suspected. For Capacity Blocks for ML, the termination window was extended from 30 minutes to 60 minutes for UltraServer instance types. Additionally, AWS renamed its Amazon Sidewalk qualification program from 'Works with Amazon Sidewalk' to 'On Amazon Sidewalk' and simplified related trademark and badge usage requirements.
Why this matters The updated terms establish new restrictions on how AWS Capacity Reservations may be used. Specifically, customers purchasing On-Demand Capacity Reservations can no longer resell them to other parties, and AWS reserves the right to cancel the purchase or terminate running instances if the company suspects resale activity. For Capacity Blocks for ML, the grace period before instance termination increased from 30 minutes to 60 minutes for UltraServer instance types, allowing slightly more time to complete workloads. The Amazon Sidewalk qualification program was renamed and simplified, but the underlying security and operational requirements remain in effect.
View full change record →

July 11, 2026 low

AWS Bedrock updated its AWS Clean Rooms service terms on July 11, 2026, revising how content deletion and resource removal work. The previous language stated that deletion requests would result …

View change record →
July 1, 2026 low

AWS Bedrock updated its AWS Service Terms on July 1, 2026, removing several AWS IQ marketplace provisions and adding new language around AWS Config third-party recorders. The change eliminates the …

View change record →
June 30, 2026 medium

AWS Bedrock added a new section (110) to its Service Terms governing free exploration services, which are technical consulting and advisory services AWS may provide at no charge. The updated …

View change record →
June 23, 2026 low

AWS Bedrock updated its Service Terms on June 23, 2026 to add Amazon GuardDuty to the list of Services that may incorporate generative AI features powered by Amazon Bedrock. The …

View change record →
June 18, 2026 low

AWS updated its Service Terms on June 18, 2026 to rename a service and clarify which AI-powered services incorporate Amazon Bedrock functionality. The company renamed AWS Security Agent to AWS …

View change record →
June 17, 2026 low

AWS updated its Professional Services licensing language on June 17, 2026. The prior version stated that Developed Content deliverables 'may include' AWS Content or Third Party Content provided under separate …

View change record →
June 16, 2026 medium

AWS Bedrock updated its service terms on June 16, 2026 to add new provisions governing metadata sharing with Anthropic for certain AI products and to introduce a new AWS WAF …

View change record →
June 10, 2026 medium

AWS updated its Service Terms on June 10, 2026 to add AWS FinOps Agent (Preview) to the list of AI Services and services that incorporate generative AI features. More substantially, …

View change record →
June 2, 2026 medium

AWS Bedrock updated its abuse detection and monitoring practices on June 2, 2026. The revised terms clarify that abuse detection mechanisms may now store service inputs and outputs for up …

View change record →
May 30, 2026 medium

AWS Bedrock updated its Amazon RDS service terms on May 30, 2026, adding new provisions governing Trusted Language Extensions, engine end-of-life management, and RDS Custom. The updated terms establish that …

View change record →
May 29, 2026 medium

AWS Bedrock's Service Terms were updated on May 29, 2026 to add detailed governance provisions for Amazon Connect Talent, a generative AI service for employment-related tasks. The updated terms establish …

View change record →
May 23, 2026 medium

AWS Bedrock updated its AWS Service Terms on May 23, 2026, adding explicit language stating that Reserved Cache Nodes and Amazon DynamoDB Reserved Capacity purchases are noncancellable and remain owed …

View change record →
May 19, 2026 low

AWS Bedrock updated its AWS Service Terms on May 19, 2026, modifying two contact information entries in its contracting party table. The mailing address for the Japan contracting party (Amazon …

View change record →
May 11, 2026 medium

AWS added a new section (50.16) establishing terms for Claude Platform on AWS, a service that integrates Anthropic's Claude AI into AWS. Under these new terms, content and metadata provided …

View change record →
May 9, 2026 medium

AWS Bedrock added a new service section for Amazon Bedrock AgentCore Payments, which enables developers to build payment solutions that route transactions between AI agents, third-party wallet providers, and sellers. …

View change record →
May 5, 2026 low

AWS Bedrock removed nine sentences describing its AgentCore Payments preview feature, which helped developers build payment solutions using AI agents and third-party wallet providers. The removed language clarified that AWS …

View change record →
Featured, High severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

419 provisions
12 featured
23 clause types
203 high severity
Acceptable Use Restrictions 71 51 high
Show all 71 acceptable use restrictions provisions
General Contract Terms 92 32 high
Show all 92 general contract terms provisions
Liability Limitation 29 23 high
Show all 29 liability limitation provisions
Payment & Fees 30 17 high
Show all 30 payment & fees provisions
Data Sharing 22 6 high
Show all 22 data sharing provisions
Data Usage 24 5 high
Show all 24 data usage provisions
Stay ahead of the changes

Monitoring

AWS Bedrock has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle ACM certificate must be immediately ceased on key compromise and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
CFAA
United States Federal
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured July 30, 2026 01:10 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000648
Version ID CA-V-005371
SHA-256 b0199b6f47c615ec15c6e3e055dc79254ae409fbbcd47621f87324289fa93300
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans