AWS offers two complementary ways to build AI agents. Amazon Bedrock Agents is a managed, configuration-driven way to create agents quickly. Amazon Bedrock AgentCore is a set of services for deploying and operating agents built with the framework of your choice. Understanding the difference helps you pick the right starting point.
Bedrock Agents: managed and quick to start
With Bedrock Agents you define instructions, connect action groups (APIs described by schemas or backed by Lambda functions) and attach knowledge bases. Bedrock handles orchestration — planning steps, calling tools and maintaining the conversation. It suits well-defined business agents where speed to value matters.
AgentCore: run any agent at enterprise scale
AgentCore is aimed at teams building agents with open-source frameworks such as LangGraph, CrewAI or Strands Agents, using any model. It provides building blocks for production concerns, including:
- Runtime — secure, serverless hosting for agent code with session isolation.
- Memory — short- and long-term memory for context across interactions.
- Gateway — turns existing APIs and Lambda functions into tools agents can use, including via the Model Context Protocol (MCP).
- Identity — manages how agents authenticate to tools and act on behalf of users.
- Observability — tracing and metrics for every step an agent takes.
- Built-in tools — such as a secure browser and a code interpreter.
Which should you use?
| Bedrock Agents | AgentCore | |
|---|---|---|
| Build style | Configuration-driven, managed orchestration | Code-first, any framework |
| Models | Models available in Bedrock | Any model |
| Best for | Fast, well-scoped business agents | Complex or custom agents at scale |
| Control | Less, but simpler | More, with more engineering |
A reference architecture
- Users reach the agent through a web app, chat channel or internal tool, authenticated with your identity provider.
- The agent runs in AgentCore Runtime (or as a Bedrock Agent) with a model from Bedrock.
- Tools are exposed through a gateway with least-privilege permissions; sensitive actions require human approval via Step Functions or a review queue.
- Knowledge comes from Bedrock Knowledge Bases with metadata filtering.
- Guardrails filter inputs and outputs; every step is traced in CloudWatch.
Security essentials
- Give each agent its own IAM role with only the permissions it needs.
- Keep traffic private with VPC endpoints; encrypt with KMS.
- Defend against prompt injection, especially when agents read emails, web pages or documents.
- Log and review agent actions; cap steps, time and spend per task.
Our Amazon Bedrock and Agentic AI teams build production agents on AWS. AWS features evolve quickly — check current documentation for availability in your region.
Frequently asked questions
What is Amazon Bedrock AgentCore?
AgentCore is a set of AWS services for deploying and operating AI agents securely at scale, with components for runtime, memory, tool gateways, identity, observability and built-in tools. It works with popular open-source agent frameworks and any model.
Should I use Bedrock Agents or AgentCore?
Bedrock Agents is quicker for well-scoped agents with managed orchestration. AgentCore suits teams building custom agents with their preferred frameworks and models who need production-grade hosting and controls.
How do I keep AI agents on AWS secure?
Use per-agent IAM roles with least privilege, private networking, encryption, guardrails, prompt-injection defences, human approval for sensitive actions and full tracing.