Securing AI agents with temporal policies in Amazon Bedrock AgentCore
AWS Bedrock AgentCore adds stateful temporal policies to enforce agent trajectory-aware authorization
“One tool call might be deemed safe when considered in isolation, but harmful in the context of the preceding call, such as after reading from an untrusted data source.”
Amazon Bedrock AgentCore now supports temporal policies that evaluate agent authorization based on full session history rather than individual tool calls in isolation. This addresses a fundamental gap in AI agent security where stateless controls miss multi-step harms like hallucinated values propagating across tool calls or runaway cumulative actions. The policies run at the gateway perimeter outside agent code, making them impossible for the agent itself to bypass.