AWS places responsibility on you as the customer to ensure that whatever the AI generates for you is used legally and in compliance with AWS's policies, not on AWS itself.
This analysis describes what AWS Bedrock's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The provision establishes a compliance framework in which customers retain primary responsibility for output review and lawfulness rather than AWS providing pre-validated or pre-screened outputs. This allocation of responsibility affects how disputes over output-related compliance violations would be structured.
The updated terms remove the explicit reference to a Data Processing Addendum governing Anthropic data transfers, though the requirement to obtain opt-in consent for Anthropic model use remains in place. For Kiro users, the revised language now explicitly states that abuse detection includes retention and potential human review of inputs and outputs when selecting certain models. Users of Anthropic models on Bedrock should verify opt-in consent mechanisms in service documentation to understand data handling practices.
View change record →The updated terms establish a new project-based service structure for AWS (new) users, effective August 17, 2026, with new rules governing team member access and content ownership. Users who enable spend limits agree that AWS may suspend their account or project access upon reaching their limit, and may permanently close the account or project if not reactivated within an unspecified timeframe. Contributed content by team members becomes the project owner's property and is subject to a nonexclusive irrevocable license granted to all project members. You can configure AI services opt-out policies through AWS Settings; project owners can manage team member permissions and access controls.
View change record →The updated terms now explicitly state that AWS IoT SiteWise Scenario Discovery is not designed for real-time vehicle control and cannot be used as the sole basis for determining vehicle safety or regulatory compliance. Organizations deploying this service must implement independent human monitoring and safety validation before using its outputs to support vehicle system decisions. The terms make clear that AWS assumes no responsibility for uses that violate these constraints.
View change record →Businesses and developers using Bedrock outputs in their products or services remain fully responsible for ensuring those outputs comply with applicable law, sector-specific regulations, and AWS's acceptable use policy, which requires active legal review of AI-assisted workflows rather than passive reliance on the platform.
How other platforms handle this
CALENDLY DOES NOT ASSUME ANY RESPONSIBILITY FOR RETENTION OF ANY OUTPUT.
AI outputs may be incomplete, inaccurate, outdated, inappropriate, or inconsistent and may change over time. They are not a substitute for professional advice...You are responsible for your use of Outputs...
the Output from the Generative AI Features may not be unique across users, and the Generative AI Features may generate or return the same or similar Output to Walmart or a third party
"You are responsible for making independent assessment of your use of the outputs of Amazon Bedrock models, including ensuring your use of such outputs complies with the AWS Acceptable Use Policy and all applicable laws.Excerpt from AWS Bedrock's AWS Service Terms
REGULATORY LANDSCAPE: This provision engages emerging AI liability frameworks including the EU AI Act, which places obligations on deployers of AI systems in high-risk categories.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
How Meta, TikTok, and Supabase restructured governance language across documents, jurisdictions, and consent frameworks through incremental document updates.
How 10 AI platforms describe the use of user data for model training, improvement, and development, based on archived governance provisions.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The provision establishes a compliance framework in which customers retain primary responsibility for output review and lawfulness rather than AWS providing pre-validated or pre-screened outputs. This allocation of responsibility affects how disputes over output-related compliance violations would be structured.
Businesses and developers using Bedrock outputs in their products or services remain fully responsible for ensuring those outputs comply with applicable law, sector-specific regulations, and AWS's acceptable use policy, which requires active legal review of AI-assisted workflows rather than passive reliance on the platform.
ConductAtlas has identified this type of provision across 216 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS Bedrock.