Amazon Web Services has opened the public preview of an artificial intelligence agent that audits customer cloud environments. The announcement arrived in a company blog post on Thursday, October 1, 2026, as reported by PYMNTS. Named the AWS Well-Architected Agent, the service analyzes a customer's infrastructure and recommends ways to improve cost, security, performance, and resilience. According to AWS, the recommendations are targeted, contextual, and ready to implement because they derive from the agent's analysis of each customer's infrastructure and business goals.

How the agent audits infrastructure

AWS describes the agent as evaluating environments the way an experienced cloud architect would. It automatically correlates utilization metrics, resource configurations, and application topology, then measures the results against Well-Architected best practices spanning more than 65 AWS services. Rather than handing customers generic checklists, the agent asks teams to declare their own business goals and prioritizes recommendations by impact and effort.

Findings arrive organized at three levels, as detailed in NeoTeo's breakdown of the launch. Resource-level findings cover individual resources. Application-level findings consolidate results across every resource in an application. Architecture-level findings address patterns and designs, including suggested changes to Infrastructure as Code. The agent reviews templates built with Terraform, AWS CloudFormation, and AWS CDK, identifying gaps and returning the code changes needed to align with best practices.

Each recommendation can ship with automation attached. Where applicable, the agent provides SSM runbooks, prescriptive CLI scripts, or guided console walkthroughs so teams can move from finding to fix quickly. As one illustration cited at launch, a team prioritizing reliability might receive a recommendation to add multi-AZ failover to a critical database. That recommendation would arrive with a runbook that automates the configuration change, alongside a cross-pillar analysis showing how the change affects cost and performance before the team commits to it.

Availability and access rules

The preview is hosted in three AWS commercial regions. Customers can onboard workloads from any AWS commercial region, so the hosting footprint does not limit coverage of the agent's analysis. The service is delivered by AWS Support, and HPCWire's AIwire notes that documentation puts the eligibility line at a Business+ tier plan or higher. AWS says initial resource and application recommendations generate within about a day of profile creation, though some launch documentation phrases the timeline differently, so teams should treat the exact cadence as provisional.

Setup begins in the AWS Well-Architected console, where customers create a profile, select accounts or regions, choose optimization pillars, and set goals. Customer-managed IAM roles grant the agent read access to the environment, and teams can add application context to sharpen the findings. AWS cautions that generative-AI recommendations may contain errors or incomplete information, and application-level recommendations carry a beta label during the preview. The caveat matters: this is an agent proposing changes to production infrastructure, so human review remains part of the workflow.

Agents are starting to audit agents

The launch reads as a next-generation evolution of AWS Trusted Advisor and the AWS Well-Architected Tool, services that have offered rule-based checks for years. This release swaps static rules for an agent that reasons across metrics, topology, and declared goals. The timing fits a broader industry pattern. In the same week, Mixpanel introduced Agent Intelligence to record and measure AI agent conversations, and Dataiku launched Agent Management to inventory agents across enterprise platforms. Enterprises are increasingly building agents whose job is to watch their other agents.

For the agent economy, the most consequential capability may be automated infrastructure-as-code review. Teams now deploying AI coding agents to generate cloud infrastructure have an agent on the other side checking that work against best practices. That closes a loop: agents writing systems, agents auditing them, and humans reviewing the prioritized output in between. It also raises the stakes on governance, since the reviewing agent's mistakes could bless bad infrastructure or flag good work as risky. The preview's explicit error warnings suggest AWS is aware of the tension.

Whether the Well-Architected Agent becomes a fixture of cloud operations will depend on how quickly the preview's rough edges smooth out and whether teams trust its recommendations enough to act on them at scale. For now, it marks a clear milestone: the agentic era has moved from helping users do tasks to inspecting the very infrastructure the agents run on. Related coverage continues on the AI News topic page, including earlier reporting on Cloudflare Clef's open-source decision models for AI agents.