Skip to main content

Public Sector

New updates on AWS GovCloud (US) | Issue #7 (2026)

August 16-31, 2026 | New updates on AWS GovCloud (US): AI Without Compromise. Choice Without Complexity. The model portfolio on Amazon Bedrock in AWS GovCloud (US) now spans seven families: Amazon Nova, Anthropic Claude, Google Gemma, Meta Llama, NVIDIA Nemotron, OpenAI GPT, and xAI Grok. This issue covers what the expanding lineup means for government AI strategy and how AgentCore’s latest capabilities, Memory, Policy, and Managed Harness, give teams the tools to deploy agents at mission speed. More models. Same boundary. Built in.

Missing alt text value

Executive Insights

AI Model Choice Brings Mission Advantage

Missing alt text value

Your mission now picks the AI model. AWS GovCloud (US) now offers multiple AI model families through Amazon Bedrock, including Amazon Nova, Anthropic Claude, Google Gemma, Meta Llama, NVIDIA Nemotron, OpenAI GPT, and xAI Grok, all inside the compliance boundary. As AWS CEO Matt Garman has shared, customers should never be locked into a single model. For government missions, model choice is how agencies stay in control of their technology systems, promote innovation, and deliver outcomes at the pace the mission demands. Model choice directly supports America’s AI Action Plan, which calls on government to accelerate AI adoption and promote innovation across federal missions. AWS’s up to $50 billion infrastructure commitment underpins these models with the capacity to run them at the scale the mission demands. A mission system can use a lightweight model to classify sensor data, a reasoning model to generate threat assessments, and a code model to automate patching, all through a single access point with no additional procurement or vendor onboarding. Read more on the AWS Public Sector Blog.

Solutions Insights

Amazon Bedrock AgentCore – Memory, Policy, and Managed Harness in AWS GovCloud (US-West)

Here's what practitioners need to know about the new Amazon Bedrock AgentCore capabilities now available in AWS GovCloud (US).

Missing alt text value

Amazon Bedrock AgentCore, the fully managed platform for building, connecting, and optimizing AI agents, has expanded its feature set in AWS GovCloud (US-West) with three new capabilities: Memory, Policy, and Managed Harness. Building on AgentCore Runtime's existing FedRAMP Class D (formerly High) authorization, these three capabilities expand the platform for production agent deployment in regulated environments. Teams can now build context-aware, policy-governed agents and move from prototype to production faster with the organizational controls required for regulated workloads. All data is processed entirely within the isolated AWS GovCloud (US-West) Region.

Memory gives agents both short-term and long-term recall without requiring teams to manage complex memory infrastructure. Short-term memory captures immediate conversation context within a session, enabling coherent multi-turn interactions. Long-term memory automatically extracts persistent insights and user preferences across sessions, so agents become more intelligent and personalized over time. For government teams, this means an agent assisting with procurement workflows can remember a user's preferred contract vehicles, past vendor evaluations, and recurring compliance requirements across sessions, eliminating repetitive context-setting while maintaining data residency within the AWS GovCloud (US) boundary. Long-term memory is always encrypted at rest using AWS KMS. By default, encryption uses an AWS-owned key. For additional control, teams can optionally configure a customer-managed KMS key.

Policy provides centralized, fine-grained controls for agent-tool interactions through natural language policies. Teams author rules in plain English (e.g., "Allow the grants agent to query funding databases only for the user's assigned program office"). These natural language policies are automatically transpiled to Cedar, AWS's open-source authorization policy language, and formally verified before enforcement — ensuring policies behave exactly as intended before execution. Policies attach to an AgentCore Gateway that evaluates every tool-access request before allowing or denying it. Cedar enforces default-deny semantics: no policy means no access. This architecture separates authorization logic from agent code, giving security teams auditable, centralized control over what agents can and cannot do — a critical requirement for FedRAMP Class D environments. Policy evaluation metrics, including allow/deny decision counts and determining policy identifiers, are published to CloudWatch by default. For detailed per-request audit trails (authorization decisions, reasons, and tool-level allow/deny lists), enable CloudTrail data events for Gateway resources and activate Gateway traces.

Managed Harness eliminates the need to write orchestration code. Developers declare an agent's model, tools, and instructions through configuration and deploy it with minimal API calls. AgentCore handles environment, compute, memory, identity, and observability management. The harness is model-agnostic, meaning teams can switch foundation model providers without losing session context or rewriting infrastructure. From a single configuration definition, a production-grade agent runs in its own isolated environment with filesystem, shell access, memory persistence, and web browsing. When custom orchestration is needed, a single CLI command exports to Strands-based code for full flexibility.

Together, these three capabilities address the core challenge regulated teams face when operationalizing AI agents: maintaining security and compliance controls while moving at the speed mission demands. Memory delivers personalization without data leakage, Policy enforces least-privilege tool access with full auditability, and Harness removes infrastructure overhead so teams focus on mission logic rather than plumbing.

To learn more, visit the Amazon Bedrock AgentCore documentation and the AWS Public Sector blog: Deploy AI agents in AWS GovCloud (US) using Amazon Bedrock AgentCore.

Service and Feature Releases

Source: What's New Posts, 08/16/26 - 08/31/26.

 

Service Area 

Service 

Region 

Announcement 

Analytics 

Amazon Kinesis Data Streams 

Both 

Amazon Kinesis Data Streams announces streaming tables, delivering data to Apache Iceberg tables on Amazon S3 Tables 

Analytics 

Amazon Kinesis Data Streams 

Both 

Amazon Kinesis Data Streams announces data delivery to general purpose Amazon S3 buckets 

Analytics 

Amazon MSK 

Both 

Amazon MSK now supports configuring custom domain names for MSK Provisioned clusters 

Analytics 

Amazon MSK 

Both 

Amazon MSK Connect now supports restarting connectors 

Analytics 

Amazon OpenSearch 

Both 

Amazon OpenSearch Ingestion is now available in GovCloud Regions 

Analytics 

Amazon Redshift 

Both 

Amazon Redshift now supports concurrency scaling of streaming ingestion workloads from Amazon Kinesis data streams 

Analytics 

Amazon Redshift 

Both 

Amazon Redshift streaming can now ingest 10MiB records from Amazon Kinesis Data Streams 

Analytics 

Amazon Redshift 

Both 

Amazon Redshift integrates with Agent Toolkit for AWS for AI-assisted data warehouse management 

Analytics 

Amazon Redshift 

Both 

Amazon Redshift now supports AWS IAM Identity Center authentication with enhanced VPC routing 

Analytics 

Amazon Redshift 

Both 

Amazon Redshift now supports Apache Iceberg v3 tables 

Analytics 

AWS Glue 

Both 

AWS Glue 6.0 delivers 30% price reduction and Iceberg v3 support 

Analytics 

AWS Glue 

Both 

AWS Glue now supports catalog federation for remote Apache Iceberg catalogs in AWS GovCloud (US) regions 

AWS Security Hub 

Automated Security Responces on AWS 

Both 

Automated Security Response on AWS adds AI Toolkit for custom remediations 

Compute 

Amazon EC2 

Both 

Amazon EC2 Auto Scaling now supports batch instance termination 

Compute 

Amazon EC2 

Both 

Amazon EC2 enables AMI creation with local snapshots from instances on Outposts 

Compute 

AWS Batch 

Both 

AWS Batch now supports Amazon ECS Managed Instances 

Compute 

AWS Elastic Beanstalk 

Both 

AWS Elastic Beanstalk now supports Active Directory domain join for Windows Server environments 

Compute 

AWS Lambda 

Both 

AWS Lambda introduces managed runtimes in public preview for Node.js 26 and Python 3.15 

Compute 

AWS ParallelCLuster 

Both 

AWS ParallelCluster 3.16 adds an on-node diagnostics tool 

Container 

Amazon ECR 

Both 

Amazon ECR now supports 25 replication rules per registry 

Container 

Amazon ECS 

Both 

Amazon ECS now automatically detects and repairs container instances with impaired agent connectivity 

Container 

Amazon EKS 

Both 

Amazon EKS now supports multiple external OIDC identity providers per cluster 

Customer Engagement 

Amazon Connect 

West 

Amazon Connect Customer dashboards now support reporting on routing steps and agent proficiencies 

Customer Engagement 

Amazon Connect 

West 

Amazon Connect Customer now lets managers chat with their data 

Customer Engagement 

Amazon Connect 

West 

Amazon Connect Customer now supports unplanned shrinkage in agent schedules 

Customer Engagement 

Amazon Connect 

West 

Amazon Connect Customer now supports points-based scoring in performance evaluations 

Customer Engagement 

Amazon SES 

Both 

Amazon SES now supports open and click tracking override parameters 

Database 

Amazon Aurora 

Both 

Amazon Aurora now supports PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 

Database 

Amazon Aurora 

Both 

Amazon Aurora MySQL 3.13 (compatible with MySQL 8.0.45) is generally available 

Database 

Amazon DocumentDB 

Both 

Amazon DocumentDB now supports direct major version upgrades to version 8.0 

Database 

Amazon DynamoDB 

Both 

Amazon DynamoDB Streams now supports attribute-based access control 

Database 

Amazon RDS 

Both 

Amazon RDS for MySQL now supports new minor version 8.4.11 

Database 

Amazon RDS 

Both 

Amazon RDS for Oracle now supports July 2026 Release Update 

Database 

Amazon RDS 

Both 

Amazon RDS now supports the latest CU for Microsoft SQL Server 

Database 

Amazon RDS 

Both 

Amazon RDS for PostgreSQL supports minor versions 18.6, 17.11, 16.15, 15.19, and 14.24 

Developer Tools 

AWS Cloudshell 

Both 

AWS CloudShell now includes a built-in visual file editor 

End User Computing 

Amazon WorkSpaces 

Both 

Amazon WorkSpaces Applications now offers in-console monitoring capabilities 

Internet of Things 

Amazon Location Service 

West 

Amazon Location Service now supports POI category and density filtering in map styles 

Internet of Things 

AWS IoT Core 

Both 

AWS IoT Core now supports native InfluxDB routing for time-series data 

Machine Learning 

Amazon Bedrock 

Both 

OpenAI GPT-5.6 Terra and Luna now available on Amazon Bedrock in AWS GovCloud (US) 

Machine Learning 

Amazon Bedrock 

Both 

SpaceXAI Grok 4.6 now available on Amazon Bedrock in AWS GovCloud (US) 

Machine Learning 

Amazon Quick 

West 

Amazon Quick adds deny by default for custom permissions 

Management & Governance 

Amazon CloudWatch 

Both 

Amazon CloudWatch agent adds support for journald logs 

Management & Governance 

AWS Elastic Disaster Recovery 

Both 

AWS Elastic Disaster Recovery introduces Recovery Plans for orchestrated application recovery 

Networking & Content Delivery 

Amazon Application Recovery Controller 

Both 

ARC Region switch adds Amazon RDS Switchover Read Replica execution block  

Networking & Content Delivery 

AWS Direct Connect 

Both 

AWS Direct Connect introduces inbound prefix controls and higher prefix scale 

Security, Identity, & Compliance 

Amazon Cognito 

Both 

Amazon Cognito now supports machine-to-machine authorization without a user pool domain 

Security, Identity, & Compliance 

AWS IAM 

Both 

IAM Policy Autopilot now supports Terraform plan files 

Security, Identity, & Compliance 

AWS IAM 

Both 

AWS IAM now supports 20 managed policies per role by default 

Security, Identity, & Compliance 

AWS IAM 

Both 

IAM Roles Anywhere now provides a Java plugin for the AWS SDK 

Security, Identity, & Compliance 

AWS Secrets Manager 

Both 

AWS Secrets Manager adds managed external secrets support for Cisco Security Platform and Netskope 

Storage 

Amazon FSx 

Both 

Amazon FSx for NetApp ONTAP now supports copying backups across AWS Regions and accounts 

Storage 

Amazon S3 

Both 

Amazon S3 Metadata and annotations are now available in AWS GovCloud (US) Regions 

Storage 

AWS Backup 

Both 

AWS Backup adds cross-Region and cross-account backup support for Amazon FSx for NetApp ONTAP 

Storage 

AWS Storage Gateway 

Both 

AWS Storage Gateway now supports FIPS-compliant private connectivity for Tape and Volume Gateway 

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages