AWS · AWS Customer Agreement · View original document ↗

Customer Responsibility for All Account Activity

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time AWS changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Monitor governance changes for AWS Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

Customers bear responsibility for all activities occurring under their AWS account, including unauthorized activities by third parties, contractors, agents, and end users, except where the activity results from AWS's own breach. AWS and its affiliates disclaim responsibility for unauthorized account access.

This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision assigns customer responsibility for all account activity regardless of authorization, meaning that compromised credentials or unauthorized third-party access resulting in service charges or policy violations remains the customer's contractual obligation rather than AWS's. This interacts with the indemnification obligations in Section 7.1.

Consumer impact (what this means for users)

Under Section 2.1, customers are contractually responsible for all charges, policy violations, and consequences arising from any activity under their account, including activity conducted without their authorization by third parties, contractors, or end users, except where AWS's breach caused the activity.

Cross-platform context

See how other platforms handle Customer Responsibility for All Account Activity and similar clauses.

Compare across platforms →

Monitoring

AWS has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Except to the extent caused by our breach of this Agreement, (a) you are responsible for all activities that occur under your account, regardless of whether the activities are authorized by you or undertaken by you, your employees or a third party (including your contractors, agents or End Users), and (b) we and our affiliates are not responsible for unauthorized access to your account.

Excerpt from AWS's Customer Agreement

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision interacts with data protection obligations under GDPR and CCPA where unauthorized third-party access to customer accounts results in data breaches, as customers may face dual exposure as both contractually responsible parties under this agreement and as data controllers subject to regulatory breach notification obligations. FTC Act Section 5 is relevant to the reasonableness of security practices required to avoid unauthorized access. 2. GOVERNANCE EXPOSURE: High. The assignment of responsibility for unauthorized account activity, including unauthorized access by external threat actors, creates contractual liability for charges incurred and policy violations triggered by account compromise events. This provision interacts with cybersecurity incident response obligations and may affect how account takeover incidents are managed and disclosed. 3. JURISDICTION FLAGS: Payment card industry regulations, banking regulations, and sector-specific security frameworks may establish separate allocation of responsibility for unauthorized transactions that interact with this contractual provision. In consumer-facing contexts in some jurisdictions, liability for unauthorized access may be subject to consumer protection limitations not applicable to B2B commercial agreements. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations should assess whether their cybersecurity incident response plans adequately address the contractual responsibility for unauthorized account activity under AWS terms, including potential for immediate account charges from compromised credentials. Multi-factor authentication and access management configurations are customer-side obligations under Section 2.3. 5. COMPLIANCE CONSIDERATIONS: Security and compliance teams should implement multi-factor authentication, credential rotation, and access logging as part of the customer-side security obligation in Section 2.3, which is directly relevant to this responsibility allocation. Cyber liability insurance policies should be evaluated for coverage of unauthorized charges and policy violations arising from account compromise.

Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Applicable agencies

  • FTC
    The FTC has jurisdiction over data security practices and consumer protection in commercial service agreements, relevant to the allocation of responsibility for unauthorized account access.
    File a complaint →

Provision details

Document information
Document
AWS Customer Agreement
Entity
AWS
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-014474
Document ID
CA-D-00674
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
9df8e129bfd7d38f49d5f527b5c87cb344da507e62f98112482fffa7af8bd0f0
Analysis generated
July 9, 2026 05:40 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: AWS
Document: AWS Customer Agreement
Record ID: CA-P-014474
Captured: 2026-07-09 05:40:32 UTC
SHA-256: 9df8e129bfd7d38f…
URL: https://conductatlas.com/platform/aws/aws-customer-agreement/provision/CA-P-014474/customer-responsibility-for-all-account-activity/
Accessed: July 24, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Start Insight · $19.99/mo Start with Monitor · $4.99/mo

Frequently Asked Questions

What does AWS's Customer Responsibility for All Account Activity clause do?

This provision assigns customer responsibility for all account activity regardless of authorization, meaning that compromised credentials or unauthorized third-party access resulting in service charges or policy violations remains the customer's contractual obligation rather than AWS's. This interacts with the indemnification obligations in Section 7.1.

How does this clause affect you?

Under Section 2.1, customers are contractually responsible for all charges, policy violations, and consequences arising from any activity under their account, including activity conducted without their authorization by third parties, contractors, or end users, except where AWS's breach caused the activity.

Is ConductAtlas affiliated with AWS?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.