When you use AI models from companies other than Amazon in Bedrock, you are also agreeing to that external company's own terms of service, not just AWS's terms.
This analysis describes what AWS Bedrock's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Customers using third-party foundation models through Bedrock are bound by an additional, separate layer of terms from the model provider, which may impose different restrictions on output use, data handling, or permitted applications that are not visible within the primary AWS Service Terms.
The updated terms now explicitly state that AWS IoT SiteWise Scenario Discovery is not designed for real-time vehicle control and cannot be used as the sole basis for determining vehicle safety or regulatory compliance. Organizations deploying this service must implement independent human monitoring and safety validation before using its outputs to support vehicle system decisions. The terms make clear that AWS assumes no responsibility for uses that violate these constraints.
View change record →The updated terms establish new restrictions on how AWS Capacity Reservations may be used. Specifically, customers purchasing On-Demand Capacity Reservations can no longer resell them to other parties, and AWS reserves the right to cancel the purchase or terminate running instances if the company suspects resale activity. For Capacity Blocks for ML, the grace period before instance termination increased from 30 minutes to 60 minutes for UltraServer instance types, allowing slightly more time to complete workloads. The Amazon Sidewalk qualification program was renamed and simplified, but the underlying security and operational requirements remain in effect.
View change record →The updated terms establish a formal framework for AWS Bedrock's free exploration services, clarifying the operational boundaries and responsibilities. AWS reserves the right to discontinue these services at any time without prior notice, meaning customers cannot rely on their continuation for production planning. Customers are solely responsible for testing, deploying, and maintaining any code, documents, or AI solutions AWS provides, including determining whether those solutions comply with applicable law. AWS retains the right to develop competing products based on content it creates during these engagements, though this does not override existing non-disclosure agreements. Customers are prohibited from requiring AWS personnel to sign additional terms as a condition of receiving free services, and any such documentation signed by AWS personnel is void.
View change record →This standalone provision was replaced with the more comprehensive 'Layered Model Provider Acceptable Use Policy' that incorporates terms by reference rather than merely requiring agreement.
View full change record →Severity downgraded from high to medium, and language shifted from mandatory compliance to agreement-based acknowledgment without explicit incorporation by reference.
View full change record →Accessing third-party models such as Anthropic Claude, Meta Llama, or Cohere models through Bedrock automatically binds the customer to that model provider's terms, which may include restrictions on use cases, output sharing, or data submission that differ from AWS's own terms.
How other platforms handle this
We may receive Personal Data in the form of Technical Data and Usage Data about you from various third parties, such as analytics providers or advertising networks.
Some of our ad partners may also enable us to collect similar data directly from their website or app by integrating our or our affiliates' advertising technology.
you may refer a friend to Instacart or send an Instacart gift delivery or gift card to someone. In these cases, we collect the recipient's name, email, and delivery address, as applicable.
"Third-party models available through Amazon Bedrock are provided pursuant to the relevant third-party model provider's terms. By using those models, you agree to the applicable model provider terms.Excerpt from AWS Bedrock's AWS Service Terms
(1) REGULATORY LANDSCAPE: The incorporation by reference of third-party model provider terms creates a layered contractual structure that compliance teams must track separately for each model provider used.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Customers using third-party foundation models through Bedrock are bound by an additional, separate layer of terms from the model provider, which may impose different restrictions on output use, data handling, or permitted applications that are not visible within the primary AWS Service Terms.
Accessing third-party models such as Anthropic Claude, Meta Llama, or Cohere models through Bedrock automatically binds the customer to that model provider's terms, which may include restrictions on use cases, output sharing, or data submission that differ from AWS's own terms.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS Bedrock.