Back to AI Tools
Amazon Bedrock
Risk Overview
Minimal Risk
2.7
/10
Model API
·
Model Hosting
·
Top Risks
CLOUD Act exposure despite EU Sovereign Cloud option. Bedrock Agents can access external APIs, databases, and execute code actions. Third-party models on Bedrock (Anthropic, Meta, etc.) have their own terms via separate EULA addendum.
Mitigations
Use AWS European Sovereign Cloud for EU data. Review Bedrock third-party model EULA for each foundation model used. Restrict Bedrock Agent action groups to minimum required. Enable CloudTrail logging for audit trail. Sign AWS GDPR DPA.
Get started
Is your team using
Amazon Bedrock
safely?
Highest Risk Categories
The highest-scoring risk categories identified in this assessment.
Legal Terms
AWS Customer Agreement includes mandatory arbitration. EEA/Switzerland/UK disputes go to Dublin under UNCITRAL rules; US disputes go to JAMS in San Francisco. Class action waivers present. Standard enterprise cloud terms; AWS arbitration broadly applies.
5
/10
Data Sovereignty
US company subject to CLOUD Act, but AWS European Sovereign Cloud launched January 2026 as separate German legal entity with EU-citizen board, offering stronger sovereignty. GDPR DPA, ISO compliance available. EU Sovereign Cloud reduces but doesn't eliminate CLOUD Act risk.
4
/10
3rd-Party Sharing
Standard AWS sub-processor model. Model providers do not have access to Bedrock logs, customer prompts, or completions. Data shared only within AWS infrastructure for service delivery. No ad/marketing data sales.
3
/10
Unlock the complete assessment
Run a free assessment to access the full AI tool risk analysis.
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue
Reference Documentation
Official documentation and policies referenced as part of this assessment.
Terms of Service
https://aws.amazon.com/service-terms/
Privacy Policy
https://aws.amazon.com/privacy/
End User License Agreement (EULA)
https://aws.amazon.com/legal/bedrock/third-party-models/