Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Customers bear responsibility for all activities occurring under their AWS account, including unauthorized activities by third parties, contractors, agents, and end users, except where the activity results from AWS's own breach. AWS and its affiliates disclaim responsibility for unauthorized account access.
This analysis describes what AWS's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision assigns customer responsibility for all account activity regardless of authorization, meaning that compromised credentials or unauthorized third-party access resulting in service charges or policy violations remains the customer's contractual obligation rather than AWS's. This interacts with the indemnification obligations in Section 7.1.
Under Section 2.1, customers are contractually responsible for all charges, policy violations, and consequences arising from any activity under their account, including activity conducted without their authorization by third parties, contractors, or end users, except where AWS's breach caused the activity.
Cross-platform context
See how other platforms handle Customer Responsibility for All Account Activity and similar clauses.
Compare across platforms →Monitoring
AWS has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Except to the extent caused by our breach of this Agreement, (a) you are responsible for all activities that occur under your account, regardless of whether the activities are authorized by you or undertaken by you, your employees or a third party (including your contractors, agents or End Users), and (b) we and our affiliates are not responsible for unauthorized access to your account.Excerpt from AWS's Customer Agreement
1. REGULATORY LANDSCAPE: This provision interacts with data protection obligations under GDPR and CCPA where unauthorized third-party access to customer accounts results in data breaches, as customers may face dual exposure as both contractually responsible parties under this agreement and as data controllers subject to regulatory breach notification obligations. FTC Act Section 5 is relevant to the reasonableness of security practices required to avoid unauthorized access. 2. GOVERNANCE EXPOSURE: High. The assignment of responsibility for unauthorized account activity, including unauthorized access by external threat actors, creates contractual liability for charges incurred and policy violations triggered by account compromise events. This provision interacts with cybersecurity incident response obligations and may affect how account takeover incidents are managed and disclosed. 3. JURISDICTION FLAGS: Payment card industry regulations, banking regulations, and sector-specific security frameworks may establish separate allocation of responsibility for unauthorized transactions that interact with this contractual provision. In consumer-facing contexts in some jurisdictions, liability for unauthorized access may be subject to consumer protection limitations not applicable to B2B commercial agreements. 4. CONTRACT AND VENDOR IMPLICATIONS: Organizations should assess whether their cybersecurity incident response plans adequately address the contractual responsibility for unauthorized account activity under AWS terms, including potential for immediate account charges from compromised credentials. Multi-factor authentication and access management configurations are customer-side obligations under Section 2.3. 5. COMPLIANCE CONSIDERATIONS: Security and compliance teams should implement multi-factor authentication, credential rotation, and access logging as part of the customer-side security obligation in Section 2.3, which is directly relevant to this responsibility allocation. Cyber liability insurance policies should be evaluated for coverage of unauthorized charges and policy violations arising from account compromise.
This provision assigns customer responsibility for all account activity regardless of authorization, meaning that compromised credentials or unauthorized third-party access resulting in service charges or policy violations remains the customer's contractual obligation rather than AWS's. This interacts with the indemnification obligations in Section 7.1.
Under Section 2.1, customers are contractually responsible for all charges, policy violations, and consequences arising from any activity under their account, including activity conducted without their authorization by third parties, contractors, or end users, except where AWS's breach caused the activity.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by AWS.