Agent security & threat detection
Amazon Bedrock Guardrails
Configurable safeguard service inside Amazon Bedrock that evaluates user inputs and model responses against content filters, denied topics, sensitive information filters and word filters, including a prompt attack category. It can be applied at inference or via a standalone API, but does not authorize agent tool calls.
commercial · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Agent security & threat detection · Runtime authorization & controls · Data governance & privacy
Useful conversation with: Cloud security architect, ML platform owner, Compliance lead.
Ask for a demonstration
Show me a Bedrock guardrail blocking a prompt attack and masking PII for a Bedrock Agent, then show the same guardrail invoked through ApplyGuardrail for a non-Bedrock model.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
Guardrails evaluate both user inputs and model responses against configured policies including content filters with a Prompt Attack category, denied topics, sensitive information filters and word filters, returning blocked messaging or masked content on intervention.
Limit: Documentation does not describe detection of tool misuse, agent action authorization or multi-step agent behaviour analysis.
Source s1 · Source s2
Documented by provider
Guardrails can be applied during foundation model inference by specifying a guardrail ID and version, or invoked independently through the ApplyGuardrail API without calling a model, and are supported with Bedrock Agents and Knowledge Bases.
Limit: Cross-account and cross-region behaviour is documented separately and was not verified here.
Source s1 · Source s2
Limitations to discuss
- Content and data filtering only; no tool authorization
- Agent-specific threat detection not documented
Sources
- Detect and filter harmful content by using Amazon Bedrock Guardrails · Amazon Web Services · official docs
Access date reported by researcher: 2026-09-06 - How Amazon Bedrock Guardrails works · Amazon Web Services · official docs
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction