Fetching from the wire…
Public story · 2026-09-18 · high
AI agents holding live AWS credentials finally get a stop switch, since Budgets only alerts once spend crosses a threshold.
Why now: AWS's Accounts reference lists account-level spend limits as of September 18, the first native alternative to Budgets' after-the-fact alerts.
AWS added a way for account owners to cap spending outright, per its account-level spend limits page in the Accounts reference. The only existing control, AWS Budgets, notifies after spend crosses a threshold; it doesn't stop the bill. For an agent running with standing AWS credentials, that gap has been a blank check.
Before this, an agent calling paid services on its own could keep running past a Budgets alert, since nothing stopped the meter. A hard limit closes that gap without needing a human to read a notification in time.
What the docs don't spell out is behavior at the edges. It's unclear whether a limit blocks new API calls only, or also affects resources already running when the cap hits.
Anyone wiring this into an agent's AWS setup should test that behavior before trusting it as a kill switch. Set the limit ahead of the agent's first live run, before a surprise invoice forces the question.
Each link below shares sources, entities, or timing with this story.
Per AWS's own documentation, the agent product Amazon launched in November 2023 entered maintenance mode: no new customers, model catalog frozen as of that date, so every model released after July 30 is AgentCore-only. Existing allowlisted accounts keep access with no EOL anno...
Bedrock invocation logs to S3 carrying model ID, token counts and IAM Identity Center user identity; an Athena view computing per-user daily spend; a Lambda on a 15-minute EventBridge schedule rewriting Customer Managed Policies via iam:CreatePolicyVersion (AWS). Denials take...
If you wrote an MCP server before July, it's on a protocol shape the maintainers have already removed. Not deprecated-with-a-migration-window. Removed from the spec. MCP lead maintainers David Soria Parra and Den Delimarsky published an updated roadmap on August 22, and the re...
It's a cross-cloud control plane to discover, govern, and secure agents across Microsoft, AWS, and Google Cloud, with Defender context mapping that ties each agent to its device, MCP servers, identities, and reachable cloud resources. Local discovery now spans 18 agent types i...
AWS's September 11 walkthrough pairs its DevOps Agent with AgentCore Evaluations, aimed at a specific gap: "an agent can successfully invoke Amazon Bedrock, call every tool without errors, and return a response while completely misunderstanding what the user needs." Thirteen L...
Announced September 8, running on the Bedrock inference engine. AWS An availability item, and it matters if you need Astra-class reasoning inside an AWS account boundary with existing IAM and VPC controls. ---
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.