AWS states that it will not use the data or content you send to Bedrock models to train Amazon's own AI models unless you have given consent for that use.
This analysis describes what AWS Bedrock's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The terms explicitly state that customer prompts and content submitted through Bedrock inference are not used to train Amazon foundation models by default, which is a material data handling commitment relevant to customers submitting proprietary or sensitive data.
Interpretive note: The scope of what constitutes customer content versus aggregated service metadata is not exhaustively defined, creating some uncertainty about the full extent of the no-training commitment.
The updated terms now explicitly state that AWS IoT SiteWise Scenario Discovery is not designed for real-time vehicle control and cannot be used as the sole basis for determining vehicle safety or regulatory compliance. Organizations deploying this service must implement independent human monitoring and safety validation before using its outputs to support vehicle system decisions. The terms make clear that AWS assumes no responsibility for uses that violate these constraints.
View change record →The updated terms establish new restrictions on how AWS Capacity Reservations may be used. Specifically, customers purchasing On-Demand Capacity Reservations can no longer resell them to other parties, and AWS reserves the right to cancel the purchase or terminate running instances if the company suspects resale activity. For Capacity Blocks for ML, the grace period before instance termination increased from 30 minutes to 60 minutes for UltraServer instance types, allowing slightly more time to complete workloads. The Amazon Sidewalk qualification program was renamed and simplified, but the underlying security and operational requirements remain in effect.
View change record →The updated terms establish a formal framework for AWS Bedrock's free exploration services, clarifying the operational boundaries and responsibilities. AWS reserves the right to discontinue these services at any time without prior notice, meaning customers cannot rely on their continuation for production planning. Customers are solely responsible for testing, deploying, and maintaining any code, documents, or AI solutions AWS provides, including determining whether those solutions comply with applicable law. AWS retains the right to develop competing products based on content it creates during these engagements, though this does not override existing non-disclosure agreements. Customers are prohibited from requiring AWS personnel to sign additional terms as a condition of receiving free services, and any such documentation signed by AWS personnel is void.
View change record →Severity downgraded from high to medium, shifted from customer responsibility for lawful basis to AWS's explicit commitment not to use content for training without consent.
View full change record →Organizations submitting proprietary business data, personal data, or sensitive information as prompts through Bedrock can rely on the terms' statement that this content is not used to train Amazon's foundation models by default; however, customers should confirm that their specific Bedrock configuration and any fine-tuning features they use are covered by this commitment.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"AWS processes Customer Content you submit to Amazon Bedrock in accordance with the AWS Customer Agreement and applicable data protection terms. AWS does not use Customer Content processed by Amazon Bedrock to train Amazon's foundation models without your consent.Excerpt from AWS Bedrock's AWS Service Terms
(1) REGULATORY LANDSCAPE: This provision directly engages GDPR, CCPA, and HIPAA frameworks where customer content includes personal data or protected health information.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The terms explicitly state that customer prompts and content submitted through Bedrock inference are not used to train Amazon foundation models by default, which is a material data handling commitment relevant to customers submitting proprietary or sensitive data.
Organizations submitting proprietary business data, personal data, or sensitive information as prompts through Bedrock can rely on the terms' statement that this content is not used to train Amazon's foundation models by default; however, customers should confirm that their specific Bedrock configuration and any fine-tuning features they use are covered by this commitment.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS Bedrock.