Industry story
AWS WAF now protects Bedrock AgentCore Gateway in GA
brand-safety engineering privacy
Agentic AI is moving fast enough that the security layer is playing catch-up in real time. AWS just closed one gap: WAF protection is now GA for Bedrock AgentCore Gateway, meaning IP controls, rate-limiting, and managed rules against bots and known exploits attach once at the Gateway and cover every tool and agent behind it automatically. For enterprises pushing agentic workloads from prototype to production, that single control point matters — per-agent hardening doesn't scale and creates the kind of inconsistency that gets exploited.
Full analysis
AWS has reached general availability for AWS Web Application Firewall (WAF) integration with Amazon Bedrock AgentCore Gateway, the traffic-routing layer for agentic AI workloads. Enterprises can now attach a WAF protection pack at the Gateway level to enforce IP-based access controls, rate-limiting rules to throttle abusive traffic, and AWS Managed Rule Groups covering common exploits, known bad inputs, and bot traffic — with a single configuration automatically covering all downstream tools, agents, and integrations behind the Gateway. The announcement targets the security gap that emerges as companies move agentic applications from prototype to production, giving platform and security teams a consistent, centralized control point rather than requiring per-agent hardening. The feature is available in all AWS regions where both services are offered.
Comments