Skip to content
TECH CEO Daily
AILaunch

AWS opens Bedrock Managed Agents powered by OpenAI in preview, keeping agents inside AWS

The jointly built service runs OpenAI-model agents under customers' own AWS identities and audit logs, with no extra charge during the preview beyond AWS resources used.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1AWS opened a preview of Bedrock Managed Agents, powered by OpenAI, on September 29 in three US regions.
  • 2Each agent gets its own IAM role, optional human approval before consequential actions, and CloudTrail activity records.
  • 3The preview carries no extra charge beyond AWS resources used; AWS says pricing may change at general availability.

The news

On September 29, 2026, Amazon Web Services (AWS), part of Amazon (AMZN), opened a preview of Bedrock Managed Agents, powered by OpenAI. AWS said the service runs agents built on OpenAI models entirely inside AWS, under the identities, permissions and governance controls customers already use.

AWS said the two companies developed the service jointly. It is built on a customized version of OpenAI's Agents API, adapted to work natively with AWS resources, and the product page says it pairs OpenAI models with OpenAI's Codex harness, the software layer that runs an agent's loop of reasoning and tool calls. The service tracks conversation state, picks and uses tools, executes code and coordinates multi-step work. Durable sessions keep messages and intermediate results so a task can resume later.

According to the announcement, each agent operates with its own AWS Identity and Access Management (IAM) role, supports human approval before consequential actions and records supported API activity in AWS CloudTrail, the cloud's audit log. Tools and commands run on compute the customer supplies: an existing machine or container, or Amazon Bedrock AgentCore Runtime, AWS's managed agent hosting service. AWS documentation says its preview examples do not require an OpenAI API key.

The preview is available in three US regions: US East (N. Virginia), US East (Ohio) and US West (Oregon). AWS said there is no additional charge for the service during the preview beyond the underlying AWS resources agents consume, and that pricing is subject to change at general availability. AWS did not give a general availability date.

AWS lists Salesforce (CRM) as a customer. Joe Inzerillo, Salesforce's president of enterprise and AI technology, is quoted on the AWS product page saying: "Data never leaves AWS." The Next Web reported that the launch came during OpenAI's DevDay 2026 event in San Francisco. Amazon first introduced the service on April 28 as part of an expanded OpenAI partnership, and in an October 5 roundup AWS listed GPT-6.1 Sol and a faster UltraFast tier of GPT-6 Astra among new OpenAI models on Bedrock.

The numbers

Preview opened
September 29, 2026
US regions in preview
3
Extra charge during preview
None beyond AWS resources used
Microsoft's non-exclusive OpenAI license runs through
2032

Why CEOs should care

For buyers at AWS-standardized companies, the main change is procurement. OpenAI agents can now be built and governed through the AWS accounts, IAM policies and audit trails a company already runs, rather than through a separate vendor relationship. Ask your AWS account team which OpenAI models the service supports in your regions, what general availability pricing will look like, and how usage will show up against existing AWS spending commitments.

CISOs should read the preview limits before approving pilots. AWS's documentation says the preview does not let customers set their own encryption key for service-managed session data, does not support subagents or cross-region inference, and accepts text input only. It also warns that commands and tools run with whatever access the execution environment has, and tells customers to treat instructions from documents, websites and tool responses as untrusted. Give each agent a dedicated workspace and the narrowest IAM role it needs, and confirm which actions require a human sign-off.

CFOs should note that "no additional charge" does not mean free. Model inference and AWS resources are billed during the preview, and AWS's documentation warns that its AgentCore example creates storage and networking resources, including a NAT gateway, that can keep incurring charges when no agent task is running. Set budget alerts and cleanup rules before teams start experimenting.

The bigger picture

The launch puts into practice a change in OpenAI's relationship with Microsoft (MSFT). In April, the two companies amended their agreement, according to Anadolu Agency: Azure remains OpenAI's primary cloud and OpenAI products launch first on Azure unless Microsoft cannot support the required capabilities, but OpenAI can now offer its products through any cloud provider, and Microsoft's license to OpenAI's models and products through 2032 became non-exclusive.

That leaves Microsoft with first-launch timing and its own product integrations rather than sole access. The Next Web reported that OpenAI is working with Microsoft to bring specialized OpenAI agents to Microsoft's Agent 365. For enterprise buyers, the practical result is more choice over where OpenAI agents run and more leverage when negotiating with either cloud.

What’s next

Watch for a general availability date and final pricing, expansion beyond the three US regions, and whether AWS adds the features missing from the preview, such as subagents and customer-managed encryption keys. Also watch whether Microsoft changes how it packages or prices OpenAI agents on Azure as AWS customers gain a native option.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

Earlier coverage of AWS

All AWS coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.