Latest
AWS Adds Access Controls for AI Agents Calling External Tools
AWS released Bedrock AgentCore Gateway, a managed layer that authenticates and authorizes AI agents before they can call external tools, APIs or databases, and logs every call. It closes a common gap where agents built for automation get broad, unaudited access to backend systems.
What changes for operators — If your company has connected an AI agent to your CRM, ticketing system, or internal APIs to automate sales outreach or support triage, that agent likely has more access than it needs and no audit trail of what it actually did. AgentCore Gateway lets you set per-tool permissions (e.g., an agent can read customer records but not modify billing) and get a log of every call, which matters the moment a customer asks what data an AI touched or a security review asks the same question. For a 10-200 person company without a dedicated security team, this shifts agent governance from a custom-built afterthought to a configuration you turn on, provided you're already on AWS or willing to route agent traffic through Bedrock.