AgentCore course → Lesson 6
What's new, and the frontier
AgentCore's newest surface area is where customers will test whether you are current. It is also where the temptation to over-promise is strongest, because most of the interesting things here are still preview — and because three more shipped in the five days after this lesson was first written.
Start from what you have
You've sat on the other side of this: a vendor demos something exciting, you ask "is that GA?", and the answer arrives three sentences later than it should. Your credibility with a technical founder rests more on how fast you volunteer that answer than on the feature itself.
harness, properly
Lesson 1 introduced harness as the managed-loop alternative to Runtime. It reached GA on 17 June 2026 and deserves a closer look, because it is the most significant change to AgentCore's shape since launch.
AWS's framing is worth learning verbatim: an agent is more than a model. If the model is the brain, the harness is the body. It runs the orchestration loop, executes tools, manages the context window, persists state across turns, recovers from failures, and isolates each session. AWS goes further and claims the harness shapes how well an agent performs as much as the model does, and that building a durable one is where most teams spend their time today.All harness detail in this section from AgentCore harness is now generally available, 17 June 2026, and AgentCore adds new features to help developers build agents faster, April 2026. Retrieved 2026-08-05.
What you actually get from a single configuration: a production-grade agent running in minutes in its own isolated environment with a filesystem and shell, memory across sessions, skills including an AWS-curated catalog, and web browsing. Four properties are worth carrying into a customer conversation:
Model-decoupled, mid-session
Switch model providers mid-session without losing context: plan with one model, write code with another.
The most concrete anti-lock-in fact in AgentCore.
Override per invocation
Any create-time configuration can be overridden on a single invocation, so a team experiments without redeploying.
Changes the iteration loop from minutes to seconds.
Not a starter tool
AWS's explicit claim: the configuration you start with is what you operate at scale, or as AWS puts it, "the agent declared on day one is the agent that runs at the thousandth."
Pre-empts "we'll outgrow this."
Exports to code
One CLI command exports the harness orchestration to Strands-based code, on the same compute and the same primitives. Claude Agent SDK is a stated future target.
This is the door back out.
The one idea
Because harness exports to code on the same primitives, choosing it is reversible. That single fact is what makes "start with harness and see" a responsible recommendation to a startup rather than a bet on a managed abstraction.
Two supporting facts worth having ready. harness, the AgentCore CLI, and skills carry no additional charge, so you pay only for the underlying capabilities consumed. And the CLI deploys with infrastructure-as-code governance, with AWS CDK supported today and Terraform announced as coming. There is also a preview filesystem persistence capability that externalises session state so an agent can suspend mid-task and resume exactly where it left off.
Three things that shipped in five days
A worked example of why this lesson exists. These lessons were written on 5 August 2026 and re-verified on the 10th. In those five days AgentCore shipped three times, and one claim in the first draft turned out to be wrong. If you take one habit from this course, make it re-checking the region matrix and the What's New feed before a meeting rather than after it.
Everything in this section, plus every earlier release and both corrections, is on the release log card. It also carries the five-minute procedure for bringing the course up to date, which is more useful to your team than this lesson is.
Runtime Instances, GA 6 August 2026
The most consequential of the three, because it changes an answer you would otherwise give confidently and wrongly. Agents can now run on AWS-managed EC2 instances in the customer's own account: you declare a capacity provider with the EC2 families you need, including GPU-accelerated, memory-optimised and compute-optimised, and attach agents to it. AgentCore still handles provisioning, patching, scaling and lifecycle, and how you deploy and invoke does not change.AgentCore runtime instances are now generally available, 6 August 2026. Retrieved 2026-08-10.
Two numbers to hold: Instances support sessions up to 14 days against the microVM runtime's 8 hours, and they bill EC2 On-Demand cost plus an AgentCore management fee charged per instance-hour from boot. That last part matters commercially: the microVM runtime bills active consumption and makes I/O wait free, whereas an Instance bills whether the agent is working or waiting. For a bursty agent the microVM is cheaper by construction.
What this breaks, and the Canada catch
Until 6 August, a GPU requirement meant leaving AgentCore for ECS or EKS. That is now the wrong answer, and it is still what most write-ups say. Lesson 2's decision tree gained a gate because of it.
Except in Canada. Runtime Instances are not in ca-central-1
— nine regions at launch, and Canada is not among them. So for your customers the old
answer still holds, and you should say why rather than leaving it looking like an
oversight.
Temporal policies and rate limiting, 6 August 2026
Covered in Lesson 3, and worth revisiting here because they change what you can promise a security reviewer. Temporal policies make authorization stateful, so a rule can require human approval before a privileged action, or require that a tool argument exactly match the output of a prior call. Rate limiting caps requests, inference tokens and concurrent connections per user or group. Regional availability is not stated in the announcement, so treat both as announced rather than available.
GovCloud, and a contradiction worth knowing about
On 7 August AWS announced Memory, policy and harness in GovCloud (US-West). The region matrix retrieved on the 10th still shows all three unavailable there.The two sources: GovCloud What's New, 7 August 2026, against the region matrix. Both retrieved 2026-08-10. Both are primary AWS sources and they disagree. The professional move is to say so: promise what the matrix shows, mention that an announcement suggests more is coming, and offer to confirm. Customers trust that answer more than a confident one that turns out to be wrong.
AWS Agent Registry, and a live deadline
Registry is a single place to discover, share, and reuse agents, MCP servers, tools,
and agent skills across an organisation, with governed publish-review-approve workflows
and combined semantic and keyword search. Record types are
AGENT, MCP, SKILL, and
CUSTOM. It is still in preview, which is worth being
precise about: the developer guide still carries the preview label and the pricing page
still says there is no charge during preview, so the 6 August date was a namespace
migration and not a GA announcement.Registry scope and record types,
AWS
Agent Registry; migration detail from the
migration
guide. Retrieved 2026-08-05.
The problem it solves is one your enterprise-adjacent customers will recognise immediately: once several teams build agents independently, nobody knows what exists, two teams wrap the same API differently, and no one can answer "which agents can reach production data?" Registry is the answer to agent sprawl.
Time-critical: check this before you quote anything
Registry's namespace migration opened on 6 August 2026, one day after these lessons were
written, and moved from the bedrock-agentcore namespace into its
own agent-registry namespace with breaking API schema changes.
- Migration window 6 Aug – 17 Sep 2026. The old namespace shuts down and any data left there is lost.
- Endpoints, IAM action prefix, service principal, ARNs, SDK client classes, CLI namespace, CloudTrail source, EventBridge source, and CloudWatch namespace all change.
BedrockAgentCoreFullAccesswill not be updated, so customers need the newAgentRegistryFullAccesspolicy.- Workload identity and OAuth credential provider resources deliberately stay on the old namespace. Do not blanket-replace.
- Registry is not available in
ca-central-1. N. Virginia, Oregon, Ireland, Sydney, and Tokyo only. - There is no charge while it is in preview. Published per-record and per-search rates are presumably the post-GA ones, so do not quote them as current.
If you have a customer on the Registry preview, this is the single most valuable thing you can tell them this month. Full detail on the service map card.
Payments and x402: genuinely new territory
Payments GA lets agents autonomously access and pay for APIs, MCP servers, web content, and other agents. Built with Coinbase and Stripe, it handles the full lifecycle from wallet authentication through transaction execution to spending governance and observability. AgentCore payments is now generally available, 18 August 2026. Retrieved 2026-08-24.
It reached GA on 18 August 2026, which happened three days after this course last claimed it was preview. GA added Quick Create for Coinbase credential provisioning in the console, a curated Coinbase Bazar MCP server of pay-per-use x402 endpoints through Gateway, support for the Machine Payment Protocol, and the x402 "upto" scheme for pay-per-inference and dynamic pricing. That last one is the interesting one for AI workloads: it lets an agent commit to a ceiling rather than a fixed price before it knows how much inference a task will need.
The mechanism is elegant enough to be worth explaining precisely, because it is the part that makes engineers lean in. An agent encounters a paid resource and receives an HTTP 402. AgentCore then handles the x402 protocol negotiation, wallet authentication, stablecoin payment, and proof delivery back to the endpoint, without interrupting the agent's reasoning loop. Spending limits are enforced deterministically at the infrastructure layer, not in the prompt, and every transaction is observable through the same traces.
Two concrete details worth carrying: wallets are Coinbase CDP or Stripe Privy, and the Coinbase x402 Bazaar MCP server is available through Gateway, exposing over 10,000 x402 endpoints an agent can search, discover, and pay for autonomously.
Note the pattern repeating from Lesson 3: spending limits enforced deterministically at the infrastructure layer is the same architectural argument as Policy at the Gateway perimeter. AgentCore's consistent position is that constraints on autonomous systems belong outside the model's reasoning, not inside its instructions. If you internalise one design philosophy from this course, make it that one.
Canada consequence
Payments is still not in ca-central-1. Its footprint grew from four
regions to twelve at GA — all of the US and Europe, plus Singapore and Sydney — and
Canada is not among them. For a Canadian agent-native startup interested in
agent-to-agent commerce, that means an out-of-region deployment for the payments
layer. It being GA rather than preview makes that harder to wave away: you can no
longer say "it is early anyway".
How to talk about preview without over-promising
This is a skill, not a disclaimer. Four rules that keep you credible:
- Volunteer the status before you are asked. Say "this is preview" in the same breath as the feature name. Waiting to be asked reads as concealment even when it isn't.
- Separate "can pilot" from "can plan." Preview capabilities are usually fine to experiment with and wrong to put on a funded roadmap. Optimization being free in preview makes it genuinely cheap to try, which is a better pitch than implying it is finished.
- Name what could change. AWS's own docs warn that preview features and APIs may change before GA. Registry is the live proof: it changed namespace, endpoints, IAM prefix, and API schema at GA. Customers who built on the preview have real migration work.
- Never guess a GA date. Optimization and Registry still have no announced GA timing. "I don't know, and I'll find out" costs you nothing; a wrong date costs you the relationship. Payments is the counter-example worth remembering: it went GA eight days after this course called it preview.
Say this to a customer"Two of the things I just showed you are preview: Optimization and Registry. That means pilot them, don't plan around them. If you're on the Registry preview you've a migration with a 17 September deadline. Payments went GA last week. Everything else I've described is generally available — though check the region list, because several of these aren't in Canada."
One aside relevant to you specifically: AgentCore ships skills for coding assistants that provide accurate, up-to-date AgentCore guidance, distributed through Kiro Power with Claude Code, Codex, and Cursor support announced. If your SA team uses any of these, that is a faster route to current AgentCore knowledge than documentation.
Read this next: 5 minutes, and the best-argued of the set
AgentCore harness is now generally available
Unusually well written for a What's New post. Contains the brain-and-body metaphor, the mid-session model switching claim, and the export-to-Strands escape hatch. Those are the three facts that do the most work in a lock-in conversation. Retrieved 2026-08-05.
Retrieval practice
Four questions on maturity and the newest surface area.
-
Which pair of capabilities is still in preview?
Answer: C (Optimization and Registry).
-
A founder worries that starting with harness traps them in a managed abstraction. What is the accurate reassurance?
Answer: B. It exports to Strands code on the same primitives.
-
What triggers the x402 flow in AgentCore Payments?
Answer: A (an HTTP 402 response).
-
What design philosophy do Policy and Payments spending limits share?
Answer: C. Enforced at the infrastructure layer, outside the reasoning.
Where to go next
You are now current on AgentCore's full surface area and can give a straight answer on maturity for every capability. Lesson 7 is the drill: three Canadian startup scenarios where you pick primitives, justify them, cost them, and handle a planted objection.
This lesson produces the objection-handling card, covering five objections you will actually hear, with honest answers and the real remaining gap in each.
Questions to take forward
- Role-play a sceptical CTO on lock-in and pressure-test the harness-export answer.
- What does a Registry migration actually involve for a customer already on the preview?
- Which of these preview capabilities should I not mention in a first meeting?