AWS Brings Security Guardrails to Agentic AI
AWS Puts Security at the Center of Agentic AI
Alan Shimel speaks with Gee Rittenhouse of AWS during Techstrong TV’s Black Hat 2026 coverage. The discussion focuses on agentic security and why AI agents require a different approach from traditional applications. Rittenhouse explains that AWS has treated security as a core priority from the beginning. As AI workloads move into production, that same focus now has to extend to agents, models, identity and policy.
Rittenhouse says AI became another workload for AWS customers, but it behaves differently from earlier cloud workloads. Customers started with proofs of concept and experimentation. As those projects moved closer to production, security became a much larger concern. That shift helped drive AWS offerings such as Amazon Bedrock and AgentCore.
Agentic Workloads Need Guardrails
The conversation explores what organizations need when they build and run AI agents. Rittenhouse says teams want to create agentic workloads without managing every piece of security plumbing on their own. They need identity, policy, gateways, sandboxes and governance built into the workflow. That is where agentic security becomes a practical requirement rather than a future concept.
AWS is focused on helping customers build agents safely and monitor them once they are running. Rittenhouse points to the need to understand whether agents are behaving within expected limits. Teams also need to watch for takeover risks, hallucinations and actions that could disrupt applications. In his view, the goal is to make secure development easier without slowing builders down.
Identity and Least Privilege Still Matter
Alan and Rittenhouse also discuss the security fundamentals that still apply. Rittenhouse says organizations should continue to “eat your security vegetables.” That means minimum privilege, short-lived tokens and strong identity controls remain important. These ideas are not new, but they become more urgent when agentic systems can act quickly and independently.
The discussion connects agentic security to familiar cloud security principles. Teams should start with limited access and expand only where needed. They should also use policy to define what agents can do. That approach helps organizations move faster while keeping the blast radius under control.
Governance Will Shape AI Adoption
Rittenhouse also addresses concerns about trust, autonomy and AI safety. He notes that the industry has faced major technology transitions before, including the move to cloud. Each shift created uncertainty at first. Over time, better controls, better platforms and better operating models helped teams adopt the technology with more confidence.
For enterprise leaders, the takeaway is clear. Agentic AI can create new value, but it needs strong governance from the start. Agentic security gives teams a path to build, run and monitor AI workloads with greater confidence. AWS is positioning identity, policy, observability and platform controls as key parts of that path.