Live
OpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual riskDynamic Tier in Google Cloud Managed Lustre: Cost‑Effective, Low‑Latency Storage for AI and HPCArgo CD 4.0 Visioning and Scaling Lessons from ArgoCon NA 2026Always‑On OpenAI Dots: Free Baseline, Metered Delegation, and What It Means for Cost and GovernanceOpenAPPA delivers zero‑success prompt‑injection protection in benchmark tests – what AI engineers need to knowEU Cyber Resilience Act expands software supply‑chain responsibilities for digital product manufacturersTyped Probability Model Jev Shifts AI Output from Text to Structured DecisionsBasin Pipelines per‑stream ingest capacity jumps to 1 GB/s – what engineers need to knowAI‑driven vulnerability management: moving from CVE counts to contextual riskDynamic Tier in Google Cloud Managed Lustre: Cost‑Effective, Low‑Latency Storage for AI and HPCArgo CD 4.0 Visioning and Scaling Lessons from ArgoCon NA 2026Always‑On OpenAI Dots: Free Baseline, Metered Delegation, and What It Means for Cost and Governance
AWS

Runtime Filtering for AgentCore Web Search Adds Per-Call Governance

AI SummaryPowered by AI

Amazon Bedrock AgentConnector version 1.2.0 introduces server-side domain and publication-date filters that allow developers to restrict agent search scopes dynamically at the API call level rather than relying solely on static policies.

Organizations deploying AI agents with Web Search capabilities previously relied entirely on organization-wide admin-level policies to control data sources. This approach lacked granularity for specific tasks, such as ensuring a financial-services agent never consults unvetted blogs or preventing product-information agents from citing outdated inventory data.

New Capabilities in Connector 1.2.0

The latest release of the Web Search connector introduces two new fields within the filters object that shift control to runtime execution:
  • Runtime domain filtering: Developers can now pass an include (allowlist) or exclude (denylist) list on every tools/call invocation. This allows per-request definition of which sources are permissible.
  • Published-date filtering: Results can be restricted to content published within a specific ISO-8601 UTC date range using from and to bounds, ensuring temporal relevance for queries like "this week's earnings calls" or recent release notes.

The Layered Filtering Model

A critical architectural constraint in this implementation is that runtime filters can only narrow the scope of search; they cannot expand it. The system enforces a layered governance model where admin-level policies act as the baseline boundary. The merge logic operates strictly server-side:

  • Domain include lists (allowlists) are merged by intersection, meaning a domain must be present in both the admin policy and the runtime request to appear in results.
  • Domain exclude lists (denylists) are merged by union, so if an administrator blocks a domain or a specific call excludes it, that source is suppressed regardless of other settings.
This ensures enterprise compliance remains enforced even when individual API calls attempt dynamic adjustments. The entire lifecycle—from the tools/call invocation to verified results—is handled server-side without client-side filtering loops or additional roundtrips.

Regional Expansion and Architecture Implications

Beyond filtering, this release expands Web Search availability to eu-west-1 (Dublin) and ap-northeast-1 (Tokyo). AgentCore utilizes a zero-egress architecture where search queries remain within AWS. For regulated customers in these regions, the regional expansion provides an entry point for grounded agents without routing traffic across borders.

What This Means For Practitioners

This update fundamentally changes how platform teams architect agent governance. Instead of maintaining rigid global policies that break on edge cases like specific compliance requirements or time-sensitive data, engineers can now implement dynamic allow/deny logic directly within the API call parameters.

The ability to enforce content freshness guarantees and per-task source restrictions without creating separate targets for each tenant simplifies multi-tenant platform operations. However, practitioners must remember that runtime filters are additive constraints; they cannot override a stricter admin policy or unblock domains denied at the administrative level. For teams building agents on AWS infrastructure, this capability reduces latency by utilizing regional endpoints while tightening security posture through server-side enforcement of data proximity and source vetting requirements.

Originally published atAWS Machine Learning Blog