Amazon Bedrock now offers a public preview of Managed Agents that run OpenAI‑based agents entirely within AWS. The preview adds a choice of execution environments – either a self‑hosted compute target you provide or the managed Bedrock AgentCore Runtime – and introduces four new frontier models to the Bedrock catalog.
What Changed
Bedrock Managed Agents are built on a customized version of OpenAI’s Agents API, but they are packaged as an AWS‑native service. Agents inherit the AWS identity, permission, and governance framework you already use, and they can store state in your account. In parallel, Bedrock added the following models:
- OpenAI GPT‑6.1 Sol – positioned as a cost‑effective upgrade to GPT‑6 Sol, with strong performance on coding, computer‑use, and professional workloads at roughly one‑fifth the cost of GPT‑6 Astra.
- OpenAI GPT‑6 Astra UltraFast – a premium speed tier delivering up to six times faster inference and up to 300 tokens per second.
- Anthropic Claude Sonnet 5.5 – a more efficient Sonnet variant that improves coding assistance and task‑oriented interactions.
- SpaceXAI Grok 4.7 – an iteration that enhances mixed‑document handling, repo‑scale coding with planning and error recovery, and browser‑driven agents for form filling and portal navigation.
Why It Matters to Practitioners
Running agents inside your AWS account eliminates the need to manage external API keys or network egress for model calls, simplifying compliance and reducing latency. The dual execution model lets you prototype on local or containerized resources before switching to the fully managed runtime for production workloads. The new models give you more granular cost‑performance options, especially when building agentic pipelines that require high‑throughput or specialized coding assistance.
Architectural and Operational Implications
Adopting Managed Agents introduces several considerations:
- Identity and permission alignment – Agents operate under AWS identities, so you must ensure the associated IAM policies grant only the resources the agent needs. This aligns with existing least‑privilege practices.
- State storage – When using the AgentCore Runtime, state is stored in your account. Plan for appropriate S3 bucket policies and lifecycle rules to manage retention and cost.
- Execution environment choice – Self‑hosted compute gives you full control over the runtime environment, useful for debugging or custom dependencies. The managed runtime abstracts the infrastructure but ties you to the Bedrock service limits and pricing.
- Model selection – GPT‑6.1 Sol offers a lower‑cost path for heavy coding workloads, while UltraFast mode is suited for latency‑sensitive inference. Claude Sonnet 5.5 and Grok 4.7 provide alternatives for tasks where specialized reasoning or browser interaction is required.
- Operational monitoring – Bedrock emits standard CloudWatch metrics for agent invocations, latency, and errors. Integrate these with existing SRE dashboards to track performance and detect anomalies.
Related Service Updates to Watch
Other announcements in the same week may affect your architecture:
- AWS Well‑Architected Agent (preview) – an AI service that scans your AWS environment and surfaces cost, security, performance, and resilience recommendations.
- Amazon Aurora PostgreSQL now supports direct queries against Apache Iceberg and Parquet data, removing the need for ETL pipelines when combining operational and lake data.
- Amazon S3 Tables now support the full set of Apache Iceberg V3 data types, including geometry, geography, unknown, and nanosecond timestamps, expanding schema flexibility for lake‑house workloads.
Related CloudNinjas coverage: AWS.
What This Means For Practitioners
Start by evaluating a low‑risk prototype using the self‑hosted option to validate your agent logic against the new models. Align IAM policies with the principle of least privilege before moving to the managed runtime. Monitor CloudWatch metrics from day one to establish baseline performance, especially if you plan to use UltraFast mode. Finally, consider how the Well‑Architected Agent and the expanded Aurora and S3 Table capabilities can be combined with Managed Agents to build tighter, cost‑effective data pipelines that stay within a single AWS security perimeter.



