Change
674ac67
674ac67cb927cd868f1c203dadcf2589dcd9bcb8 · commit on GitHub
aws-blog-feed: changed (658639 bytes, HTTP 200)
raw/aws-blog-feed/response.xml modified
- Source
- aws-blog-feed
- Lines added
- +5,616
- Lines removed
- -5,168
- Stored bytes at this commit
- 658,639
- Timestamp
- observed
- Raw artifact at this commit
- raw/aws-blog-feed/response.xml
Recorded headers
| observed_at | 2026-10-06T06:21:09.236Z |
|---|---|
| origin_date | null |
| status | 200 |
| final URL | https://aws.amazon.com/blogs/machine-learning/feed/ |
| etag | null |
| last-modified | Mon, 05 Oct 2026 23:25:28 GMT |
| date | Tue, 06 Oct 2026 06:21:09 GMT |
| age | null |
| cache-control | null |
| cf-cache-status | null |
| content-encoding | null |
| content-length | null |
@
@@ -5,7 +5,7 @@ <atom:link href="https://aws.amazon.com/blogs/machine-learning/feed/" rel="self" type="application/rss+xml"/> <link>https://aws.amazon.com/blogs/machine-learning/</link> <description>Official Machine Learning Blog of Amazon Web Services</description>-
<lastBuildDate>Fri, 02 Oct 2026 15:48:26 +0000</lastBuildDate>+
<lastBuildDate>Mon, 05 Oct 2026 23:25:17 +0000</lastBuildDate> <language>en-US</language> <sy:updatePeriod> hourly </sy:updatePeriod>@
@@ -13,314 +13,730 @@ 1 </sy:updateFrequency> <item>-
<title>Sweep thousands of leases for compliance using Amazon Quick and the Adjudicated Query pattern</title>-
<link>https://aws.amazon.com/blogs/machine-learning/sweep-thousands-of-leases-for-compliance-using-amazon-quick-and-the-adjudicated-query-pattern/</link>+
<title>Introducing GLM 5.3 on Amazon Bedrock</title>+
<link>https://aws.amazon.com/blogs/machine-learning/introducing-glm-5-3-on-amazon-bedrock/</link> -
<dc:creator><![CDATA[Anand Komandooru]]></dc:creator>-
<pubDate>Fri, 02 Oct 2026 15:48:26 +0000</pubDate>+
<dc:creator><![CDATA[Alex Thewsey]]></dc:creator>+
<pubDate>Mon, 05 Oct 2026 23:25:17 +0000</pubDate> <category><![CDATA[Advanced (300)]]></category>-
<category><![CDATA[Amazon Quick Suite]]></category>-
<category><![CDATA[Technical How-to]]></category>-
<guid isPermaLink="false">2f2cd30ac2942c76cf89e1fbda1bc39b085e37cc</guid>+
<category><![CDATA[Amazon Bedrock]]></category>+
<category><![CDATA[Announcements]]></category>+
<guid isPermaLink="false">6f3957c3db7756d44ae371ed56bdd96fe96046a0</guid>+
+
<description>GLM 5.3 from Z.ai is now available on Amazon Bedrock: a 753B-parameter mixture-of-experts model built for coding and long-horizon agentic tasks. Learn how to invoke it with the OpenAI-compatible APIs, cut cost and latency with prompt caching, and run an authorized security test wit…+
<content:encoded><p>Coding and agentic workloads are asking more of AI models than ever: refactor a repository spanning hundreds of files, sustain a multi-hour agentic workflow without losing context, and reason through complex systems problems with tool use at every step. Meeting th…+
<p><a href="https://z.ai/blog/glm-5.3" target="_blank" rel="noopener">GLM 5.3 from Z.ai</a> (Zhipu AI) is now available on <a href="https://aws.amazon.com/bedrock/" target="_blank" rel="noopener">Amazon Bedrock</a>. GLM 5.3, as published <a href="https://huggingface.…+
<p>In this post, we show you how to invoke GLM 5.3 on Amazon Bedrock using the OpenAI-compatible APIs and reduce cost and latency with prompt caching. We then put the model to work in a realistic agentic workflow: running an authorized security test of your own application with Strix, an open-…+
<h2 id="whats-new-compared-to-glm-5">What’s new compared to GLM 5</h2>+
<p>GLM 5 arrived on Amazon Bedrock earlier this year. GLM 5.3 builds on the same lineage, with a range of important gains:</p>+
<ul>+
<li><strong>Stronger coding:</strong> <a href="https://z.ai/blog/glm-5.3" target="_blank" rel="noopener">Z.ai claims</a> competitive performance on a range of coding benchmarks including DeepSWE, Terminal Bench 3.0, and FrontierSWE. They also report a 50% improvement o…+
<li><strong>Emergent cyber security capabilities:</strong> Reported benchmark performance on security tasks stands out, which makes the model a natural fit for defensive security workflows. For example, Z.ai <a href="https://z.ai/blog/glm-5.3" target="_blank" rel="noopener">…+
<li><strong>Broader Amazon Bedrock integration:</strong> Cross-Region inference profiles, implicit and explicit prompt caching, and improved feature parity of the OpenAI-compatible Responses and Chat Completions APIs alongside Invoke and Converse.</li>+
</ul>+
<h2 id="key-capabilities">Key capabilities</h2>+
<ul>+
<li><strong>Frontier coding and agentic performance.</strong> GLM 5.3 is designed for complex systems engineering and long-horizon agentic tasks. These include multi-step reasoning, tool-augmented workflows, and sustained context across large code bases.</li>+
<li><strong>Flexible API access.</strong> You can invoke GLM 5.3 through the OpenAI-compatible Responses and Chat Completions APIs, or the Amazon Bedrock Invoke and Converse APIs.</li>+
<li><strong>Prompt caching.</strong> GLM 5.3 supports implicit (automatic) prompt caching by default, and explicit cache controls (recommended) on the Responses and Chat Completions APIs. For agentic workloads that resend large system prompts or repository context every turn, cach…+
<li><strong>Cross-Region inference.</strong> GLM 5.3 is available through US cross-Region inference (<code>us.zai.glm-5.3</code>) and Global cross-Region inference (<code>global.zai.glm-5.3</code>) profiles. You send requests to the “source” AWS Region of y…+
<li><strong>Service tiers.</strong> Choose Flex to optimize cost for less-time-sensitive workloads, Priority to prioritize latency-critical requests in return for a higher price, or Standard for the default balance between price and speed.</li>+
</ul>+
<h2 id="prerequisites">Prerequisites</h2>+
<p>For the following usage examples, you need:</p>+
<ol type="1">+
<li>An AWS account with access to Amazon Bedrock.</li>+
<li>AWS Identity and Access Management (IAM) <a href="https://docs.aws.amazon.com/service-authorization/latest/reference/list_bedrock.html" target="_blank" rel="noopener">permissions</a> to call the base model and the target inference profile: <code>bedrock:InvokeModel</c…+
<li>(For the code-based demos) Python 3.10 or later.</li>+
<li>(For the optional security-testing demo only) install Docker and <a href="https://docs.strix.ai/llm-providers/bedrock" target="_blank" rel="noopener">Strix with the bedrock extra</a>.</li>+
</ol>+
<h2 id="try-glm-5.3-on-the-amazon-bedrock-console">Try GLM 5.3 on the Amazon Bedrock console</h2>+
<p>You can start sending prompts to GLM 5.3 on the AWS Management Console, with no need to write code or install developer tools. To get started, navigate to <a href="https://console.aws.amazon.com/bedrock/" target="_blank" rel="noopener">Amazon Bedrock</a> and then choose <stro…+
<p>From this playground interface you can select GLM 5.3 from the model list and send your first prompts through the chat UI, as shown in the following screenshot:</p>+
<div id="attachment_140841" style="width: 2090px" class="wp-caption alignnone">+
<img aria-describedby="caption-attachment-140841" class="wp-image-140841 size-full" src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/10/05/Screenshot-2026-10-05-at-6.11.23 PM.png" alt="[Amazon Bedrock Playground screenshot showing chat interface with GLM 5…+
<p id="caption-attachment-140841" class="wp-caption-text">Figure 1: Chatting with GLM 5.3 on the Amazon Bedrock console</p>+
</div>+
<h2 id="get-started-with-the-responses-api">Get started with the Responses API</h2>+
<p>Programmatically, you can call the model through the <code>bedrock-runtime</code> endpoint. This supports both the OpenAI-compatible <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/inference-responses-api.html" target="_blank" rel="noopener">Responses</a&g…+
<p>Amazon Bedrock does support <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/api-keys-generate.html" target="_blank" rel="noopener">generating API keys</a> for OpenAI-compatible integrations that require them. However, we strongly recommend preferring short-lived cr…+
<p>In the following example, we will call the Responses API from Python using the OpenAI Python SDK, and the <a href="https://pypi.org/project/aws-bedrock-token-generator/" target="_blank" rel="noopener">aws-bedrock-token-generator</a> library to generate short-term tokens from you…+
<ol type="1">+
<li>Install the required packages.+
<div class="hide-language">+
<pre><code class="language-bash">pip install -U openai aws-bedrock-token-generator</code></pre>+
</div></li>+
<li>Save the following code as <code>bedrock-request.py</code>.+
<div class="hide-language">+
<pre><code class="language-python">from aws_bedrock_token_generator import provide_token+
from openai import OpenAI-
<description>The Adjudicated Query pattern pairs the Amazon Quick chat agent with a bounded MCP server over a deterministic rules engine to deliver provably complete, defensible compliance answers. This post walks through the reference architecture and a deployable AWS CDK sample, using lease c…-
<content:encoded><p>Checking tens of thousands of apartment leases against constantly changing state landlord-tenant laws, and proving you actually checked all of them, has been beyond the reach of most compliance teams. But with generative AI in <a href="https://aws.amazon.com/qu…-
<h2 id="the-compliance-challenge-at-scale">The compliance challenge at scale</h2>-
<p>A portfolio operator holds 50,000 leases across multiple states. Each state publishes landlord-tenant statutes (late-fee caps, notice periods, security-deposit limits) that change on the legislature’s schedule, not the operator’s. When a regulation changes, the team responsible for complian…-
<p>At small volume a paralegal reads the leases. The answer is trustworthy because a human stands behind it. Past some threshold, that stops being possible. The work moves to software, and a new problem appears: the answer is now a number on a screen that nobody can independently verify.</p…-
<p>Two properties follow from that reality:</p>+
region = "us-west-2" # Your source AWS Region+
+
client = OpenAI(+
api_key=provide_token(region=region),+
base_url=f"https://bedrock-runtime.{region}.amazonaws.com/openai/v1",+
)+
+
resp = client.responses.create(+
input="Refactor this Python function to be iterative instead of recursive: ...",+
model="global.zai.glm-5.3",+
)+
+
print(resp.output_text)</code></pre>+
</div></li>+
<li>Run the script, which will display the model’s output.+
<div class="hide-language">+
<pre><code class="language-bash">python bedrock-request.py</code></pre>+
</div></li>+
</ol>+
<h3 id="optimize-inference-with-explicit-prompt-caching">Optimize inference with explicit prompt caching</h3>+
<p>Long-running coding and knowledge workflows often resend stable context across multiple conversation turns, such as system prompts, tool definitions, or repository files.</p>+
<p>GLM 5.3 on Amazon Bedrock supports implicit prompt caching by default, which helps reduce response latency and input token costs for repeated calls sharing the same initial prompt prefix.</p>+
<p>With <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-caching.html" target="_blank" rel="noopener">explicit prompt caching</a> mode you specifically identify the reusable prompt prefixes, which can further improve cache hit rate (and therefore latency and cos…+
<p>To use explicit prompt caching with GLM 5.3, as shown in the following example:</p>+
<ol type="1">+
<li>Select the explicit caching mode through <code>prompt_cache_options</code> on your request.</li>+
<li>Add one or more <code>prompt_cache_breakpoint</code> markers on input content blocks to indicate the end (inclusive) of reusable prompt prefixes. Each breakpoint must contain at least 1,024 tokens to be eligible for caching.</li>+
</ol>+
<div class="hide-language">+
<pre><code class="language-python">resp = client.responses.create(+
model="global.zai.glm-5.3",+
# Enable explicit caching mode:+
extra_body={"prompt_cache_options": {"mode": "explicit"}},+
input=[+
{+
"type": "message",+
"role": "system",+
"content": [+
{+
"type": "input_text",+
"text": SYSTEM_PROMPT,+
# A long, static system prompt is a great target for caching:+
"prompt_cache_breakpoint": {"mode": "explicit"},+
},+
]+
},+
{+
"type": "message",+
"role": "user",+
"content": [+
{+
"type": "input_text",+
"text": USER_INPUT,+
# Multiple breakpoints can also be defined, for layered cache:+
"prompt_cache_breakpoint": {"mode": "explicit"},+
},+
],+
},+
],+
)+
+
if resp.usage.input_tokens_details.cached_tokens:+
print("Hit cache!")</code></pre>+
</div>+
<p>For more information, refer to the <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/prompt-caching.html#prompt-caching-openai" target="_blank" rel="noopener">prompt caching section</a> of the Amazon Bedrock User Guide.</p>+
<h2 id="example-agentic-workload-authorized-security-testing-with-strix">Example agentic workload: Authorized security testing with Strix</h2>+
<p>One workload that benefits directly from GLM 5.3’s strengths is automated security testing of your own applications. <a href="https://github.com/usestrix/strix" target="_blank" rel="noopener">Strix</a> is an open-source AI penetration testing agent that runs your code dynamicall…+
<p><strong>Only test applications you own or have explicit written permission to test.</strong> Unauthorized security testing of systems you don’t own is illegal in most jurisdictions and violates the AWS Acceptable Use Policy. In this walkthrough, the target is <a href="https:/…+
<p>If you want fully managed, continuous security testing beyond running open-source agents yourself, <a href="https://aws.amazon.com/security-agent/" target="_blank" rel="noopener">AWS Continuum</a> provides on-demand penetration testing and other security analyses as a managed se…+
<h3 id="to-run-an-authorized-security-test">To run an authorized security test</h3>+
<ol type="1">+
<li>Start the example Juice Shop target application locally.+
<div class="hide-language">+
<pre><code class="language-bash">docker run --rm -p 3000:3000 bkimminich/juice-shop</code></pre>+
</div></li>+
<li>Configure Strix to use GLM 5.3 on Amazon Bedrock. Strix uses <a href="https://docs.litellm.ai/docs/providers/bedrock" target="_blank" rel="noopener">LiteLLM</a> under the hood so (as described in <a href="https://docs.strix.ai/llm-providers/bedrock" target="_blank" rel="noo…+
<div class="hide-language">+
<pre><code class="language-bash"># Fill in the REGION and ACCOUNT_ID placeholders below before running!+
export STRIX_LLM="bedrock/converse/arn:aws:bedrock:{AWS_REGION}:{AWS_ACCOUNT_ID}:inference-profile/global.zai.glm-5.3"</code></pre>+
</div></li>+
<li>Run Strix against the local target.+
<div class="hide-language">+
<pre><code class="language-bash">strix --target http://localhost:3000</code></pre>+
</div></li>+
<li>Wait for the root Strix agent to complete, then review the findings.</li>+
</ol>+
<p>Strix spins up a team of sub-agents to map the threat surface, explore a range of potential vulnerability categories, and attempt to validate each finding with a working proof of concept. This helps minimize time spent triaging false positives. A successful run will generate a report includ…+
<p>The following video shows the end-to-end journey of setting up and running Strix against the example application, and exploring the results:</p>+
<div style="width: 640px;" class="wp-video">+
<video class="wp-video-shortcode" id="video-140838-1" width="640" height="360" preload="metadata" controls="controls"><source type="video/mp4" src="https://d2908q01vomqb2.cloudfront.net/artifacts/DBSBlogs/ML-22047/Strix+Demo+Video+Censored.mp4?_=1"></video>+
</div>+
<p>Figure 2: Running an example security test with GLM 5.3 and Strix</p>+
<blockquote>+
<p style="text-align: left"></p>+
</blockquote>+
<h2 id="clean-up">Clean up</h2>+
<p>Stop the Juice Shop container with <strong>Ctrl+C</strong> in the terminal where it’s running, or run <code>docker ps</code> to find the container ID and stop it with <code>docker stop &lt;container-id&gt;</code>. Amazon Bedrock inference is pay-p…+
<h2 id="availability">Availability</h2>+
<p>Give GLM 5.3 a try on the <a href="https://console.aws.amazon.com/bedrock" target="_blank" rel="noopener">Amazon Bedrock console</a>, use it through coding assistants like OpenCode as shown in our <a href="https://aws.amazon.com/blogs/machine-learning/use-open-weight-models-a…+
<p><em>Interested in how Amazon Bedrock can support your team?</em> <a href="https://pages.awscloud.com/Amazon-Bedrock-Contact-Us.html" target="_blank" rel="noopener"><em>Connect with us</em></a> <em>to start the conversation.</em></p>+
<hr style="width: 100%">+
<h2>About the authors</h2>+
<footer>+
<div class="blog-author-box" style="padding-top: 2.0em">+
<div class="blog-author-image" style="margin-right: 1.0em">+
<p><img loading="lazy" class="alignnone size-full" src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/09/17/ML-21636-3.jpg" alt="Alex Thewsey" width="100" height="133"></p>+
</div>+
<h3 class="lb-h4">Alex Thewsey</h3>+
<p>Alex is an AI Specialist Solutions Architect at AWS, based in Singapore. He focuses on how open source technologies and open weight models can help customers around the world to build innovative AI solutions and tackle AI governance challenges.</p>+
</div>+
</footer></content:encoded>+
+
+
<enclosure length="353017803" type="video/mp4" url="https://d2908q01vomqb2.cloudfront.net/artifacts/DBSBlogs/ML-22047/Strix+Demo+Video+Censored.mp4"/>+
+
</item>+
<item>+
<title>Supercharge regulated workloads with Claude Code and Amazon Bedrock</title>+
<link>https://aws.amazon.com/blogs/machine-learning/supercharge-regulated-workloads-with-claude-code-and-amazon-bedrock/</link>+
+
<dc:creator><![CDATA[Bradley Wyman]]></dc:creator>+
<pubDate>Mon, 05 Oct 2026 17:25:20 +0000</pubDate>+
<category><![CDATA[Amazon Bedrock]]></category>+
<category><![CDATA[Intermediate (200)]]></category>+
<category><![CDATA[Technical How-to]]></category>+
<guid isPermaLink="false">0cbe16ca98bef589de7fcf6ba5ec623095bdb76d</guid>+
+
<description>Anthropic Claude Opus 5.5 and Claude Sonnet 5.5 are available on Amazon Bedrock in the AWS GovCloud (US) Regions. Learn how to use them with Claude Code, Anthropic's agentic coding tool, for compliance-aligned, AI-assisted development on regulated and ITAR workloads.</description>+
<content:encoded><p><em>Please note that the following post is intended for informational purposes only. The approach detailed below may not be suitable for all organizations or compliance programs. It is important to evaluate this potential solution against the compliance requ…+
<p>The availability of Anthropic Claude Opus 5.5 and Claude Sonnet 5.5 in the AWS GovCloud (US) Regions introduces an on-ramp for AI-assisted development for workloads with regulatory or compliance requirements, including International Traffic in Arms Regulations (ITAR). Claude Sonnet 5 holds …+
<p>In this post, we explore how to use these models on <a href="https://aws.amazon.com/bedrock" target="_blank" rel="noopener">Amazon Bedrock</a> in AWS GovCloud (US) with <a href="https://code.claude.com" target="_blank" rel="noopener">Claude Code</a>, Anthropic’s agen…+
<h2 id="amazon-bedrock-in-aws-govcloud-us">Amazon Bedrock in AWS GovCloud (US)</h2>+
<p><a href="https://aws.amazon.com/govcloud-us/" target="_blank" rel="noopener">AWS GovCloud (US) Regions</a> are designed specifically for US customers with elevated <a href="https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-compliance.html" target="_blank" rel=…+
<p><a href="https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html" target="_blank" rel="noopener">Built-in data protection</a> where customer content isn’t stored, logged, or used to train AWS models or shared with third parties.</p>+
<p>FedRAMP Class D (formerly High) certification and DoD Cloud Service Provider (CSP) SRG IL4/IL5 authorization pathways, supporting government agencies’ compliance requirements. See the <a href="https://aws.amazon.com/compliance/services-in-scope/FedRAMP/amazon-bedrock-models/" target="_bl…+
<p>Integration with existing security controls and compliance frameworks available in AWS GovCloud (US), maintaining the same high security standards as other AWS Regions while providing additional authorization pathways.</p>+
<p>Amazon Bedrock in AWS GovCloud (US) supports two endpoint surfaces, bedrock-runtime and bedrock-mantle, both powered by the same underlying Mantle inference engine with Zero Operator Access (ZOA) architecture. The <strong>bedrock-runtime</strong> endpoint uses the AWS SDK (Invok…+
<h2 id="claude-code">Claude Code</h2>+
<p><a href="https://code.claude.com" target="_blank" rel="noopener">Claude Code</a> is Anthropic’s agentic coding tool that reads your codebase, edits files, runs commands, and integrates with your development tools. Powered by models such as Claude Opus 5.5 and Claude Sonnet 5.5 o…<ul>-
<li><strong>Provable completeness:</strong> A claim like “we checked all 22,910 Texas leases” must be true and demonstrable. A record never assessed must be reported as unevaluated rather than silently omitted.</li>-
<li><strong>Defensibility:</strong> A finding may be challenged months later in litigation, an audit, or a regulatory examination. Defending it means knowing which version of which rule was applied, to which clause text, by what method, on what date, and by whom.</li>+
<li>Write code and fix bugs spanning multiple files across your codebase.</li>+
<li>Answer questions about your code’s architecture and logic.</li>+
<li>Execute and fix tests, linting, and other commands.</li>+
<li>Search through Git history, resolve merge conflicts, and create commits and pull requests.</li>+
<li>Connect to external tools and data sources with the <a href="https://docs.anthropic.com/en/docs/claude-code/mcp" target="_blank" rel="noopener">Model Context Protocol (MCP)</a>, including the <a href="https://aws.amazon.com/cli" target="_blank" rel="noopener">AWS Command…+
<li>Spawn <a href="https://docs.anthropic.com/en/docs/claude-code/sub-agents" target="_blank" rel="noopener">sub-agents</a> that work on different parts of a task simultaneously.</li>+
<li>Customize behavior with <a href="https://docs.anthropic.com/en/docs/claude-code/memory" target="_blank" rel="noopener">CLAUDE.md</a> memory files, <a href="https://docs.anthropic.com/en/docs/claude-code/skills" target="_blank" rel="noopener">skills</a> for repeatab…+
<li>Automate recurring tasks and integrate with continuous integration and continuous delivery (CI/CD) through <a href="https://docs.anthropic.com/en/docs/claude-code/github-actions" target="_blank" rel="noopener">GitHub Actions</a> or <a href="https://docs.anthropic.com/en/doc…</ul>-
<p>These two properties are what distinguish this problem from enterprise search. Retrieval Augmented Generation (RAG) addresses the accessibility gap but cannot satisfy either property. Similarity search has no threshold that means <em>all of them</em>. A ranked sample never knows…-
<p>Text-to-SQL narrows this gap, but carries a category-level risk: a hallucinated predicate can silently reduce the population, and the resulting number looks exact even when the scope is wrong.</p>-
<h2 id="how-the-adjudicated-query-pattern-solves-it">How the Adjudicated Query pattern solves it</h2>-
<p>The Adjudicated Query pattern is a bounded conversational layer over a deterministic rules engine. The model does exactly two things: translate a natural-language question into a call on a fixed set of typed operations, and narrate the result that comes back. It never writes a query, never …-
<p>Behind the boundary sits a rules engine. Rules are versioned data, not code. The engine knows generic comparison operators (<code>gte</code>, <code>lte</code>, <code>equals</code>, <code>exists</code>) and contains no branch naming a jurisdict…-
<p>Every compliance sweep produces a completeness receipt: an asserted invariant where compliant + in-breach + ambiguous + unreadable must equal scanned. This is computed from counts and asserted before anything persists. A run that can’t account for its population never finishes. There’s no p…-
<p>The conversational surface carries counts, the receipt, and a labeled sample. The full result set (potentially tens of thousands of rows) lives on a dashboard surface reading the same data store, drillable per record. This separation means the model never summarizes away the guarantee.</…-
<h3 id="why-not-rag-or-text-to-sql">Why not RAG or text-to-SQL?</h3>+
<p>To learn more, see Anthropic’s articles: <a href="https://docs.anthropic.com/en/docs/claude-code/tutorials" target="_blank" rel="noopener">Claude Code tutorials</a> and <a href="https://www.anthropic.com/engineering/claude-code-best-practices" target="_blank" rel="noopener"&g…+
<h2 id="solution-overview-try-claude-code-with-amazon-bedrock-in-aws-govcloud-us">Solution overview: Try Claude Code with Amazon Bedrock in AWS GovCloud (US)</h2>+
<p>This section provides step-by-step instructions for setting up and configuring Claude Code to work with Amazon Bedrock in AWS GovCloud (US), including prerequisites, installation commands, environment configuration, and verification steps.</p>+
<h3 id="prerequisites">Prerequisites</h3>+
<p>Before you get started, make sure that you have the following in place:</p>+
<ul>+
<li>An <a href="https://signin.amazonaws-us-gov.com/" target="_blank" rel="noopener">AWS GovCloud (US) account</a> with access to Amazon Bedrock.</li>+
<li>Appropriate <a href="https://aws.amazon.com/iam/" target="_blank" rel="noopener">AWS Identity and Access Management (IAM)</a> roles and permissions for Amazon Bedrock. At minimum, your IAM policy should include:+
<ul>+
<li>For bedrock-runtime: <code>bedrock:InvokeModel</code>, <code>bedrock:InvokeModelWithResponseStream</code>, <code>bedrock:ListInferenceProfiles</code>, and <code>bedrock:GetInferenceProfile</code>.</li>+
<li>For bedrock-mantle (if using the Mantle endpoint): <code>bedrock-mantle:CreateInference</code>, <code>bedrock-mantle:GetProject</code>, <code>bedrock-mantle:ListProjects</code>, and <code>bedrock-mantle:ListModels</code>.</li>+
<li>Alternatively, attach the <code>AmazonBedrockMantleInferenceAccess</code> managed policy.</li>+
</ul></li>+
<li><a href="https://docs.aws.amazon.com/bedrock/latest/userguide/model-access-modify.html" target="_blank" rel="noopener">Amazon Bedrock model access</a> to Claude Opus 5.5, Claude Sonnet 5.5, and Claude Sonnet 5 enabled in your AWS GovCloud (US) account.</li>+
<li><a href="https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html" target="_blank" rel="noopener">AWS CLI</a> configured with valid AWS session credentials using short-term API keys or AWS SSO login.</li>+
</ul>+
<h3 id="set-up-claude-code-with-amazon-bedrock-in-aws-govcloud-us">Set up Claude Code with Amazon Bedrock in AWS GovCloud (US)</h3>+
<p>After configuring AWS CLI with your credentials, install Claude Code using one of the following methods:</p>+
<p><strong>macOS, Linux, WSL:</strong></p>+
<div class="hide-language">+
<pre><code class="language-bash">curl -fsSL https://claude.ai/install.sh | bash</code></pre>+
</div>+
<p><strong>Windows PowerShell:</strong></p>+
<div class="hide-language">+
<pre><code class="language-powershell">irm https://claude.ai/install.ps1 | iex</code></pre>+
</div>+
<p><strong>Windows CMD:</strong></p>+
<div class="hide-language">+
<pre><code class="language-dosbat">curl -fsSL https://claude.ai/install.cmd -o install.cmd &amp;&amp; install.cmd &amp;&amp; del install.cmd</code></pre>+
</div>+
<p><strong>Homebrew (macOS/Linux):</strong></p>+
<div class="hide-language">+
<pre><code class="language-bash">brew install --cask claude-code</code></pre>+
</div>+
<p>For additional installation methods, see <a href="https://code.claude.com/docs/en/quickstart" target="_blank" rel="noopener">Claude Code installation docs</a>.</p>+
<h4 id="option-a-interactive-setup-wizard-recommended">Option A: Interactive setup wizard (recommended)</h4>+
<ol type="1">+
<li>Navigate to your project:+
<div class="hide-language">+
<pre><code class="language-bash">cd your-code-project</code></pre>+
</div></li>+
<li>Launch Claude Code:+
<div class="hide-language">+
<pre><code class="language-bash">claude</code></pre>+
</div></li>+
<li>Run through the login wizard:+
<div class="hide-language">+
<pre><code class="language-plaintext">/login</code></pre>+
</div></li>+
</ol>+
<p>At the login prompt, select <strong>3rd-party platform</strong>, then <strong>Amazon Bedrock</strong>. Follow the wizard prompts to choose your authentication method, region (us-gov-west-1), and pin your models. The wizard saves configuration to your settings file au…+
<p>If you have previously configured Claude Code, run <code>/setup-bedrock</code> to reopen the wizard and update your credentials, region, or model pins.</p>+
<h4 id="option-b-manual-environment-variable-configuration">Option B: Manual environment variable configuration</h4>+
<p>For scripted or enterprise deployments, set the following environment variables:</p>+
<div class="hide-language">+
<pre><code class="language-bash">export CLAUDE_CODE_USE_BEDROCK=1+
export AWS_REGION='us-gov-west-1'+
export ANTHROPIC_MODEL='us-gov.anthropic.claude-sonnet-5-5'</code></pre>+
</div>+
<p>To use Claude Opus 5.5 as the primary model instead:</p>+
<div class="hide-language">+
<pre><code class="language-bash">export ANTHROPIC_MODEL='us-gov.anthropic.claude-opus-5-5'</code></pre>+
</div>+
<p>To pin specific model versions for consistent team deployments:</p>+
<div class="hide-language">+
<pre><code class="language-bash">export ANTHROPIC_DEFAULT_OPUS_MODEL='us-gov.anthropic.claude-opus-5-5'+
export ANTHROPIC_DEFAULT_SONNET_MODEL='us-gov.anthropic.claude-sonnet-5-5'</code></pre>+
</div>+
<p>Then navigate to your project and launch Claude Code:</p>+
<div class="hide-language">+
<pre><code class="language-bash">cd your-code-project+
claude</code></pre>+
</div>+
<h4 id="option-c-using-the-bedrock-mantle-endpoint">Option C: Using the Bedrock Mantle endpoint</h4>+
<p>Bedrock Mantle supports the Anthropic Messages API natively and is available in AWS GovCloud (US-West). To route Claude Code through Mantle:</p>+
<div class="hide-language">+
<pre><code class="language-bash">export CLAUDE_CODE_USE_MANTLE=1+
export AWS_REGION='us-gov-west-1'</code></pre>+
</div>+
<p>When both bedrock-runtime and bedrock-mantle are needed in the same session:</p>+
<div class="hide-language">+
<pre><code class="language-bash">export CLAUDE_CODE_USE_BEDROCK=1+
export CLAUDE_CODE_USE_MANTLE=1</code></pre>+
</div>+
<p>Note: Guardrails and invocation logging are available exclusively through the bedrock-runtime endpoint. For deployments requiring these compliance features, use the bedrock-runtime endpoint (Option A or B).</p>+
<h4 id="verify-your-configuration">Verify your configuration</h4>+
<p>Verify that Claude Code is running by checking for the <strong>Welcome to Claude Code!</strong> message in your terminal. Run the <code>/status</code> command to confirm your model and provider. The provider line should show Amazon Bedrock or Amazon Bedrock (Mantle) …+
<p>To learn more about configuring Claude Code for Amazon Bedrock, see <a href="https://code.claude.com/docs/en/amazon-bedrock" target="_blank" rel="noopener">Claude Code on Amazon Bedrock</a>.</p>+
<h2 id="considerations-when-deploying-claude-code-to-your-organization">Considerations when deploying Claude Code to your organization</h2>+
<p>With Claude Code now generally available, the next step is deciding how to deploy it across your organization. Consider your foundational architecture for security, governance, and compliance:</p>+
<p><strong>Use</strong> <a href="https://aws.amazon.com/iam/identity-center/" target="_blank" rel="noopener">AWS IAM Identity Center</a> to centrally govern identity and access to Claude Code. This verifies that only authorized developers have access. Additionally, usin…+
<p><strong>Consider automated configuration of default environment variables.</strong> This includes the environment variables outlined in this post, such as <code>AWS_REGION</code>, <code>CLAUDE_CODE_USE_BEDROCK</code>, <code>ANTHROPIC_MODEL</code&…+
<p><strong>Consider implementing</strong> <a href="https://aws.amazon.com/solutions/guidance/claude-code-with-amazon-bedrock/" target="_blank" rel="noopener">Guidance for Claude Code with Amazon Bedrock</a> <strong>for large enterprise deployments.</strong> …+
<p><strong>Review</strong> <a href="https://docs.aws.amazon.com/bedrock/latest/userguide/quotas.html" target="_blank" rel="noopener">service quotas</a> <strong>and set appropriate tokens per minute (TPM) and requests per minute (RPM) based on the number of active …+
<p><strong>Pin model versions for consistent team deployments.</strong> Without pinning, model aliases such as <code>sonnet</code> and <code>opus</code> resolve to Claude Code’s built-in defaults, which may change between releases. Claude Code defaults to Cl…+
<p><strong>Implement cost monitoring and per-user token guardrails.</strong> Claude Code sessions can be token-intensive, particularly with Claude Opus 5.5, which carries a higher per-token cost than Claude Sonnet 5.5. According to Anthropic, Claude Opus 5.5 completes tasks using f…+
<ul>+
<li>Implement <a href="https://aws.amazon.com/blogs/publicsector/implementing-per-user-token-guardrails-for-amazon-bedrock-in-government-agencies/" target="_blank" rel="noopener">per-user token guardrails</a> to enforce daily token limits per developer, with alerting at 80% and 10…+
<li>Use prompt caching to reduce costs and improve response times. Both 5-minute and <a href="https://aws.amazon.com/about-aws/whats-new/2026/01/amazon-bedrock-one-hour-duration-prompt-caching/" target="_blank" rel="noopener">1-hour TTL</a> options are available for supported mode…+
<li>Consider defaulting teams to Claude Sonnet 5.5 (lower cost than Claude Opus 5.5) and reserving Claude Opus 5.5 for tasks requiring deeper reasoning or longer autonomous runs. For workloads that require IL4/IL5 authorization, default to Claude Sonnet 5.</li>+
</ul>+
<p>See the <a href="https://github.com/aws-solutions-library-samples/guidance-for-claude-code-with-amazon-bedrock/blob/main/assets/docs/MONITORING.md" target="_blank" rel="noopener">Claude Code Monitoring Implementation guide</a> for additional observability patterns.</p>+
<p><strong>Consider permissions, memory, and MCP servers for your organization.</strong> Security teams can configure managed <a href="https://docs.anthropic.com/en/docs/claude-code/security" target="_blank" rel="noopener">permissions</a> for what Claude Code is and is …+
<p><strong>Choose the appropriate endpoint for your compliance requirements.</strong> The bedrock-runtime endpoint supports Guardrails, invocation logging, and cross-region inference within both AWS GovCloud (US) Regions (US-West and US-East). The bedrock-mantle endpoint supports t…+
<p><strong>Conduct a thorough security assessment before deployment.</strong> Evaluate Claude Code’s capabilities against your organization’s security policies. Amazon Bedrock secures the inference layer, but Claude Code runs on local developer machines and requires separate evalua…+
<h2 id="conclusion">Conclusion</h2>+
<p>The availability of Claude Opus 5.5 and Claude Sonnet 5.5 on Amazon Bedrock in AWS GovCloud (US) provides organizations with a compliance-aligned path to AI-assisted development for regulated workloads. Claude Sonnet 5, with FedRAMP Class D (formerly High) certification and DoD IL4/IL5 auth…+
<p>Combined with Claude Code, teams can adopt agentic coding workflows directly in their terminal, IDE, or CI/CD pipelines while data remains within AWS GovCloud (US) infrastructure. Whether you choose the bedrock-runtime endpoint for full Guardrails and logging support, or the bedrock-mantle …+
<h3 id="for-more-information">For more information</h3>+
<ul>+
<li><a href="https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-bedrock.html" target="_blank" rel="noopener">Amazon Bedrock in AWS GovCloud (US)</a></li>+
<li><a href="https://code.claude.com/docs/en/amazon-bedrock" target="_blank" rel="noopener">Claude Code on Amazon Bedrock</a></li>+
<li><a href="https://aws.amazon.com/solutions/guidance/claude-code-with-amazon-bedrock/" target="_blank" rel="noopener">Guidance for Claude Code with Amazon Bedrock</a></li>+
<li><a href="https://aws.amazon.com/compliance/services-in-scope/FedRAMP/amazon-bedrock-models/" target="_blank" rel="noopener">Amazon Bedrock model FedRAMP certification and DoD authorization status</a></li>+
<li><a href="https://aws.amazon.com/blogs/publicsector/implementing-per-user-token-guardrails-for-amazon-bedrock-in-government-agencies/" target="_blank" rel="noopener">Per-user token guardrails for Amazon Bedrock in government agencies</a></li>+
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/09/claude-sonnet-5-5-aws-govcloud-us/" target="_blank" rel="noopener">Claude Sonnet 5.5 in AWS GovCloud (US)</a></li>+
<li><a href="https://aws.amazon.com/about-aws/whats-new/2026/09/claude-opus-5-5-aws-govcloud/" target="_blank" rel="noopener">Claude Opus 5.5 in AWS GovCloud (US)</a></li>+
</ul>+
<hr style="width: 100%">+
<h2>About the authors</h2>+
<footer>+
<div class="blog-author-box" style="padding-top: 2.0em">+
<div class="blog-author-image" style="margin-right: 1.0em">+
<p><img loading="lazy" class="alignnone size-full" src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/09/23/ML-19466-1.jpg" alt="Bradley Wyman" width="100" height="133"></p>+
</div>+
<h3 class="lb-h4">Bradley Wyman</h3>+
<p>Bradley is a Solutions Architect on the AWS Aerospace &amp; Satellite team, where he helps Aerospace &amp; Satellite customers leverage cutting-edge technologies to solve complex business challenges. With a deep passion for Generative AI, Agentic Development, and workload moderniz…+
</div>+
<div class="blog-author-box" style="padding-top: 2.0em">+
<div class="blog-author-image" style="margin-right: 1.0em">+
<p><img loading="lazy" class="alignnone size-full" src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/09/23/ML-19466-2.jpg" alt="Doug Hairfield" width="100" height="133"></p>+
</div>+
<h3 class="lb-h4">Doug Hairfield</h3>+
<p>Doug is a senior solutions architect who helps organizations harness the power of AI to solve real-world problems. He brings a depth of experience helping public sector customers design their workloads in high compliance environments. When he’s not architecting cloud solutions, you’ll fin…+
</div>+
<div class="blog-author-box" style="padding-top: 2.0em">+
<div class="blog-author-image" style="margin-right: 1.0em">+
<p><img loading="lazy" class="alignnone size-full" src="https://d2908q01vomqb2.cloudfront.net/f1f836cb4ea6efb2a0b1b99f41ad8b103eff4b59/2026/09/23/ML-19466-3.jpg" alt="Jonathan Evans" width="100" height="133"></p>+
</div>+
<h3 class="lb-h4">Keith Martin</h3>+
<p>Keith began his career as a software engineer at NASA Mission Control, where system reliability in human spaceflight operations is non-negotiable. He has since applied that discipline to architecting trading systems in the energy sector, guiding AWS Aerospace &amp; Satellite customers…+
</div>+
</footer></content:encoded>+
+
+
+
</item>+
<item>+
<title>New agent skill: Amazon SageMaker optimized generative AI inference for your coding agent</title>+
<link>https://aws.amazon.com/blogs/machine-learning/new-agent-skill-amazon-sagemaker-optimized-generative-ai-inference-for-your-coding-agent/</link>+
+
<dc:creator><![CDATA[Mona Mona]]></dc:creator>+
<pubDate>Mon, 05 Oct 2026 17:23:19 +0000</pubDate>+
<category><![CDATA[Advanced (300)]]></category>+
<category><![CDATA[Amazon SageMaker AI]]></category>+
<category><![CDATA[Announcements]]></category>+
<guid isPermaLink="false">cf6f95ea7bf1aafa4505939aad0e550912dc69a2</guid>Diff display stops at 400 lines. The line counts above are from the whole diff. 60 lines shown here cut at 300 characters. The raw artifact at this commit is linked above.