← All posts

AWS just shipped the guardrails for production AI agents. Here's who you'll need to run them.

In a single week, AWS open-sourced a governance language for agents, added history-aware policies to AgentCore, backed a vendor-neutral plugin standard, and put vector search inside DynamoDB. The message: agents are going to production — governed, audited, and operated like real infrastructure.

If you only skimmed the AWS news feed this month, you might have missed how much of it pointed in one direction. In its August 10 weekly roundup, AWS announced Dogwood, an open-source governance language for AI agents that builds on Cedar policies and adds temporal conditions; temporal policies for Amazon Bedrock AgentCore, where an authorization decision can depend on the full history of what an agent has done in a session rather than just the current request; support for Agent Plugins, an open, vendor-neutral packaging spec so an agent extension built once can run in Kiro, VS Code, Cursor, or anything else that implements it; and dedicated runtime instances on AgentCore for teams that need predictable performance and cost from their agent workloads.

Add vector search landing natively in DynamoDB — embeddings stored and queried right next to your operational data, no separate vector database to run — and Web Search for OpenAI models on Bedrock, and a pattern emerges that every cloud leader should read carefully.

The demo era is over

You don't build governance languages for toys. Cedar-style policy enforcement, session-history-aware authorization, dedicated runtimes, packaging standards — this is the tooling a platform grows when its customers start running the thing in production and their security, compliance, and finance teams show up with questions.

That's precisely where enterprise agentic AI is right now. The 2024–2025 phase was pilots: a support copilot here, a document-processing agent there, most of them running with permissions nobody had fully thought through. The 2026 phase is the hard part — putting autonomous software in front of real customer data and real internal systems, and being able to answer an auditor when they ask what is this agent allowed to do, what did it actually do, and who approved that?

The new hiring spec

Here's the uncomfortable part for hiring managers: the engineer this era demands barely existed as a job description eighteen months ago. The profile that keeps showing up in our client intakes is a senior AWS platform engineer — strong IAM, networking, serverless or EKS — layered with real GenAI production experience on Bedrock, plus the security instincts to treat an autonomous agent as an untrusted distributed system. People who can write the Cedar policy and explain to a CISO why it's sufficient.

Every company will have AI agents in production within a few years. The ones that avoid the ugly headlines will be the ones that hired governance-minded platform engineers before the incident, not after it.

Demand for that profile is compounding faster than the labor market can mint it. Kubernetes took roughly five years to go from "niche skill" to "table stakes"; the agent-platform stack is compressing the same curve into quarters, because AWS is shipping the primitives faster than most teams can absorb them.

Staffing the production-agent era

This is the market we live in every day. Fastwater Cloud Staffing is the number one staffing firm for AWS and cloud projects because we screen for exactly this intersection: senior AWS engineers with Bedrock and AgentCore exposure, IAM and policy-as-code depth, RAG and vector-data architecture, and the platform discipline to run agents like production infrastructure. Through our sister consultancy Fastwater Cloud.AI, our own team ships agentic solutions on AWS for real clients — so when we say a candidate has production agent experience, we know what that actually looks like.

For AWS consulting partners, we work white-label — your SOW, your brand, our engineers — which is why partners taking agentic-AI engagements to their clients treat us as the staffing source they trust most for AWS talent. Contract, contract-to-hire, or direct placement, with first qualified submittals typically in days, not weeks.

The guardrails have shipped. The question is whether your team knows how to install them.

Putting agents into production?

Tell us the stack and the timeline. We'll come back within one business day with an honest read on the talent market and our bench.

Get Engineers