AWS Public Sector Blog

Deploy AI agents in AWS GovCloud (US) using Amazon Bedrock AgentCore

https://app.asana.com/1/8442528107068/project/1207199896111772/task/1214563334767899?focus=true

The Federal Government, the Industrial Base, and SaaS technology providers are taking the next step after experimenting with generative AI in their highly regulated cloud environments and asking the question: How do we put AI agents into production at scale, compliantly, securely, reliably, and without building everything from scratch?

AI agents enable mission owners to advance beyond simple prompt-response interactions. They can now reason, plan, use tools, and take actions across systems, automating complex workflows that previously required human intervention at every step. However, deploying agents in environments with elevated compliance requirements introduces challenges that commercial tooling alone can’t solve: runtime isolation for sensitive workloads, auditable tool access, identity delegation that aligns with existing authorization models, and real-time observability for compliance and oversight. AgentCore lets you deploy AI agents that act autonomously while maintaining the same compliance posture as your most controlled systems.

Amazon Bedrock AgentCore is currently available in AWS GovCloud (US) to address these needs and provides customers operating in regulated industries with a fully managed solution to build, deploy, and operate AI agents at production scale, without needing to manage the underlying infrastructure. This launch is part of Amazon’s broader commitment to invest up to $50 billion in U.S. Federal Supercomputing cloud and AI infrastructure, delivering cutting-edge AI capabilities to customers in our secure and compliant AWS GovCloud (US) environments.

What is Amazon Bedrock AgentCore?

Amazon Bedrock AgentCore provides the production infrastructure layer for agentic AI. Whereas Amazon Bedrock gives you access to foundation models and agent orchestration, AgentCore handles the operational challenges that can emerge when agents move from prototype to mission-critical deployment. These include runtime isolation, secure tool access, identity delegation, observability, and composable architecture.

With AgentCore, mission owners can accelerate agents from prototype to production using their choice of framework and model, while maintaining the security and compliance controls required for government and regulated workloads. AgentCore offers the following key capabilities:

  • AgentCore Runtime – With AgentCore Runtime, agent execution runs in a secure, isolated environment at the session level, preventing cross-tenant interference and sensitive data processed by one agent from being leaked to another.
  • Secure tool access using AgentCore GatewayAgentCore Gateway converts existing APIs and AWS Lambda functions into agent-ready tools through the Model Context Protocol (MCP), giving agents secure access to enterprise data and services.
  • Identity delegationAgentCore Identity enables agents to inherit and operate within the identity and permission boundaries of the user or system that invoked them. It natively supports external OAuth 2.0/OpenID Connect (OIDC) identity providers (IdPs). Existing AWS Identity and Access Management (IAM) policies, permission boundaries, and session controls extend naturally to agent actions without requiring user migration or exposing identity infrastructure to the public internet.
  • Real-time observabilityAgentCore Observability provides full visibility into agent reasoning, tool usage, and decision paths. The actions an agent takes are logged and traceable, which is critical for compliance audits, incident response, and building trust in automated decision-making.
  • Composable architectureAgentCore Evaluations enables teams to define test scenarios and measure agent performance against expected outcomes, supporting responsible AI practices and ongoing validation requirements.

Agencies don’t need to adopt everything at once. AgentCore services are composable: a team might start with runtime isolation for a sensitive CUI workload, add identity delegation when they’re ready to connect their existing workforce IdP, then layer in observability as they move to production. The flexibility extends to frameworks and models too, so teams can build with what they know today and evolve without rearchitecting.

Unlike bolt-on agent toolkits, AgentCore inherits compliance from the platform. There’s no separate authorization cycle, no additional infrastructure to harden, and no gap between your agent’s security posture and your environment’s.

Why this matters for government agencies

Customers operating in regulated environments face unique architectural considerations when deploying AI systems. Agentic AI, where models autonomously take actions, raises the stakes on these considerations. By addressing these challenges at the infrastructure level, AgentCore helps mission owners move faster from prototype to production, accelerating mission outcomes while maintaining the rigorous security and compliance posture that regulated operations demand. Customers can benefit from the following features:

  • Accountability requirements – When an agent takes an action on behalf of a customer, there must be a clear audit trail showing what the agent did, why it did it, and under whose authority. The observability and identity delegation features in AgentCore create this chain of accountability by construction.
  • Least-privilege enforcement – Agents should access only the tools and data their invoking user is authorized to reach. With identity delegation, developers can configure agents to operate within the invoking user’s permission boundaries, preventing privilege escalation.
  • Multi-tenant safety – In shared infrastructure environments, which are common in civilian organizations and shared services, session-level runtime isolation prevents one tenant’s agent workload from observing or affecting another’s.
  • Compliance and oversight – Reviewers, inspectors general, security incident responders, and compliance officers need to understand what AI systems are doing. Real-time observability and structured logging provide the evidence base for oversight without requiring manual agent supervision.
  • Operational readiness – Moving from a proof of concept to a production system that handles thousands of concurrent agent executions requires infrastructure that scales automatically, recovers from failures gracefully, and maintains performance under load. AgentCore provides this without custom engineering.

Example use cases

With AgentCore in AWS GovCloud (US), agencies can deploy production-grade agentic AI for the following scenarios:

  • Intelligent document processing – Agents that ingest, classify, extract, and route documents across customer workflows, with full audit trails and human-in-the-loop escalation paths.
  • Citizen service automation – Agents that handle multi-step citizen requests (verifying eligibility, pulling records, calculating benefits, and generating responses), reducing processing time from weeks to minutes.
  • Multi-step research and analysis – Agents that gather information from multiple sources, synthesize findings, and produce structured analysis products—all operating within the analyst’s access boundaries.
  • Automated compliance monitoring – Agents that continuously scan configurations, policies, and system states against regulatory requirements, flagging deviations and initiating remediation workflows.
  • IT operations and incident response – Agents that detect anomalies, diagnose root causes, execute runbook remediation steps, and escalate to human operators when confidence is low.

Getting started

AgentCore is available today in the AWS GovCloud (US-West) Region. You can get started with the following steps:

  1. Enable Amazon Bedrock in your AWS GovCloud (US) account if you haven’t already.
  2. Access AgentCore through the Amazon Bedrock console, the AgentCore CLI, or programmatically using the AWS SDK.
  3. Choose your agent framework — AgentCore supports Strands Agents, LangGraph, Google ADK, and OpenAI Agents SDK.
  4. Define your agent’s tools using the MCP-compatible tool interface—connect to databases, APIs, and enterprise systems your agent needs to access.
  5. Configure identity delegation so agents operate within the invoking user’s permission boundary.
  6. Deploy and monitor using AgentCore observability features to track agent behavior, tune performance, and demonstrate compliance.

For agencies already building agents with Amazon Bedrock Agents, AgentCore provides the production hardening layer—you can adopt it incrementally without rewriting existing agent logic.

Conclusion

The leap from agentic AI experimentation to mission-ready deployment has been one of the biggest barriers to wider AI adoption in regulated environments. AgentCore in AWS GovCloud (US) addresses this issue, providing the security, observability, and operational infrastructure that customers require, without the custom engineering that has historically slowed deployment timelines.

To learn more, refer to the Amazon Bedrock AgentCore Developer Guide. To get started, see Get started with Amazon Bedrock AgentCore, or contact your AWS account team to discuss how agentic AI can accelerate your mission. For more on multi-model access in AWS GovCloud (US), see AI Model Choice is a Mission Advantage.

David Schatzman

David Schatzman

David is a technical business development manager for Amazon Web Services (AWS), focused on serving public sector civilian and financial customers using the AWS GovCloud (US) Regions. In this role, David works closely with customers to ensure alignment of their mission goals and technology strategies with the capabilities of the AWS GovCloud (US) Regions. David is also interested in global economics, digital assets, cloud security, and cloud resiliency and is the lead for the AWS GovCloud (US) digital assets, supercomputing, perimeter protection, modernization, and resiliency product strategies. He is a doctoral candidate at the Liberty University School of Business and holds an MBA, MS, and BS, as well as several Project Management Institute credentials, such as the PfMP.

Heather Crawford

Heather Crawford

Heather is a Senior Marketing Manager at Amazon Web Services (AWS) supporting Government Regions (GovCloud, Secret Cloud, and Top Secret Cloud) customers. She is responsible for generating awareness of and interest in AWS services in sovereign and classified regions through strategic, multichannel marketing campaigns, content, and events. She has worked in marketing, editorial, product, and sales with public sector customers across government, nonprofit, multinational, education, and healthcare organizations throughout the technology and media sectors. She holds an MBA from NYU Stern School of Business, an MA from CUNY Graduate Center, and a BA from James Madison University and has been recognized for her charitable work in education and literacy through service on various nonprofit and industry boards and committees.