Customers bear responsibility for all activities occurring under their AWS account, including unauthorized activities by third parties, contractors, agents, and end users, except where the activity results from AWS's own breach. AWS and its affiliates disclaim responsibility for unauthorized account access.
This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision assigns customer responsibility for all account activity regardless of authorization, meaning that compromised credentials or unauthorized third-party access resulting in service charges or policy violations remains the customer's contractual obligation rather than AWS's. This interacts with the indemnification obligations in Section 7.1.
Under Section 2.1, customers are contractually responsible for all charges, policy violations, and consequences arising from any activity under their account, including activity conducted without their authorization by third parties, contractors, or end users, except where AWS's breach caused the activity.
Cross-platform context
See how other platforms handle Customer Responsibility for All Account Activity and similar clauses.
Compare across platforms →"Except to the extent caused by our breach of this Agreement, (a) you are responsible for all activities that occur under your account, regardless of whether the activities are authorized by you or undertaken by you, your employees or a third party (including your contractors, agents or End Users), and (b) we and our affiliates are not responsible for unauthorized access to your account.Excerpt from AWS's Customer Agreement
1.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision assigns customer responsibility for all account activity regardless of authorization, meaning that compromised credentials or unauthorized third-party access resulting in service charges or policy violations remains the customer's contractual obligation rather than AWS's. This interacts with the indemnification obligations in Section 7.1.
Under Section 2.1, customers are contractually responsible for all charges, policy violations, and consequences arising from any activity under their account, including activity conducted without their authorization by third parties, contractors, or end users, except where AWS's breach caused the activity.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.