AgentCore service map

Every capability, its maturity, and whether it runs in ca-central-1 — one printed side. Context in Lesson 2. Re-verified 2026-08-241. This surface changes monthly; treat anything older than six weeks as suspect.

The capability surface, and where Canada stands
Group Capability One-line job Status In Canada
Compute Runtime microVMs Serverless host for an agent loop you wrote. Sessions to 8h GA Oct 2025 Yes
Compute Runtime Instances Same path on managed EC2. GPUs, sessions to 14 days GA 6 Aug 2026 No
Compute harness Managed agent loop declared in configuration GA Jun 2026 Yes
Tools & access Gateway Turns APIs, Lambda, and MCP servers into governed tools GA Oct 2025 Yes
Tools & access Identity Inbound and outbound auth against your existing IdP GA Oct 2025 Yes
Tools & access Policy Deterministic authorization on every tool call GA ~Dec 2025 Yes (caveat below)
Tools & access Browser Managed cloud browser for web interaction GA Oct 2025 Yes
Tools & access Code Interpreter Isolated sandbox for agent-written code GA Oct 2025 Yes
Tools & access Web Search Grounds answers in live web data. Domain and date filters GA No
State Memory Short-term and long-term agent state GA Oct 2025 Yes
Quality loop Observability OpenTelemetry step-level tracing GA Oct 2025 Yes
Quality loop Evaluations Automated quality scoring on sessions and traces GA Mar 2026 Yes
Quality loop Optimization Trace-driven prompt and tool-description improvement Preview May 2026 Yes
Ecosystem AWS Agent Registry Org-wide catalog of agents, MCP servers, tools, skills Preview migration 6 Aug No
Ecosystem Payments Agent micropayments over x402 GA 18 Aug 2026 No

Also: the AgentCore CLI (GA), Guardrails within Policy, and temporal policies plus rate limiting (announced 6 Aug 2026, regions unconfirmed). No charge for the harness, CLI, skills, or Registry while in preview.

The Canada gaps and the Policy caveat

Not in ca-central-1: Web Search (us-east-1, eu-west-1, ap-northeast-1), Runtime Instances (9 regions), Payments (12 regions, all US and Europe plus Singapore and Sydney), Registry (us-east-1, us-west-2, eu-west-1, ap-southeast-2, ap-northeast-1), Guardrails in Policy (us-east-1, eu-west-2, eu-north-1, ap-southeast-2, ap-northeast-1).1

Policy itself is in ca-central-1. Two things are not: the Guardrails screening inside it, and any guarantee about where its inference runs — authorization prompts from Canada route to any commercial region globally, with no opt-out and no CloudTrail record of where.2 Canada is one of only two such source regions. Detail on the Canada card.

Registry's namespace migration, deadline 17 Sep 2026, is on the release log.