AWS states that it will not use the data or content you send to Bedrock models to train Amazon's own AI models unless you have given consent for that use.
This analysis describes what AWS Bedrock's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The terms explicitly state that customer prompts and content submitted through Bedrock inference are not used to train Amazon foundation models by default, which is a material data handling commitment relevant to customers submitting proprietary or sensitive data.
Interpretive note: The scope of what constitutes customer content versus aggregated service metadata is not exhaustively defined, creating some uncertainty about the full extent of the no-training commitment.
The updated terms remove the explicit reference to a Data Processing Addendum governing Anthropic data transfers, though the requirement to obtain opt-in consent for Anthropic model use remains in place. For Kiro users, the revised language now explicitly states that abuse detection includes retention and potential human review of inputs and outputs when selecting certain models. Users of Anthropic models on Bedrock should verify opt-in consent mechanisms in service documentation to understand data handling practices.
View change record →The updated terms establish a new project-based service structure for AWS (new) users, effective August 17, 2026, with new rules governing team member access and content ownership. Users who enable spend limits agree that AWS may suspend their account or project access upon reaching their limit, and may permanently close the account or project if not reactivated within an unspecified timeframe. Contributed content by team members becomes the project owner's property and is subject to a nonexclusive irrevocable license granted to all project members. You can configure AI services opt-out policies through AWS Settings; project owners can manage team member permissions and access controls.
View change record →The updated terms now explicitly state that AWS IoT SiteWise Scenario Discovery is not designed for real-time vehicle control and cannot be used as the sole basis for determining vehicle safety or regulatory compliance. Organizations deploying this service must implement independent human monitoring and safety validation before using its outputs to support vehicle system decisions. The terms make clear that AWS assumes no responsibility for uses that violate these constraints.
View change record →Organizations submitting proprietary business data, personal data, or sensitive information as prompts through Bedrock can rely on the terms' statement that this content is not used to train Amazon's foundation models by default; however, customers should confirm that their specific Bedrock configuration and any fine-tuning features they use are covered by this commitment.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"AWS processes Customer Content you submit to Amazon Bedrock in accordance with the AWS Customer Agreement and applicable data protection terms. AWS does not use Customer Content processed by Amazon Bedrock to train Amazon's foundation models without your consent.Excerpt from AWS Bedrock's AWS Service Terms
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR, CCPA, and HIPAA frameworks where customer content includes personal data or protected health information.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The terms explicitly state that customer prompts and content submitted through Bedrock inference are not used to train Amazon foundation models by default, which is a material data handling commitment relevant to customers submitting proprietary or sensitive data.
Organizations submitting proprietary business data, personal data, or sensitive information as prompts through Bedrock can rely on the terms' statement that this content is not used to train Amazon's foundation models by default; however, customers should confirm that their specific Bedrock configuration and any fine-tuning features they use are covered by this commitment.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS Bedrock.