Running an OpenAI model in production has, for seven years, meant routing through Microsoft's cloud. Microsoft's investment in OpenAI made Azure the default enterprise on-ramp for the company's frontier models, and that arrangement shaped how most companies built their AI infrastructure. That changed on September 29, 2026, when OpenAI and Amazon used OpenAI's DevDay keynote to ship Bedrock Managed Agents in preview.
The new service runs OpenAI's own agent stack entirely inside AWS. According to coverage of the launch from Pondero AI, the offering combines OpenAI's models with the Codex agent harness and Amazon Bedrock AgentCore. It carries over the customization of the Agents API that OpenAI introduced earlier in the same keynote, while keeping both the agent runtime and model inference inside AWS rather than OpenAI's own infrastructure or Azure.
For enterprises already committed to Amazon's cloud, the appeal is straightforward. Teams that run identity, security, and compliance tooling on AWS can now deploy OpenAI-powered agents without standing up parallel Azure infrastructure alongside it, and without rebuilding agent orchestration from scratch.
What Bedrock Managed Agents actually ships
Three operational details matter most for anyone evaluating the preview. The first is identity. Every agent gets its own AWS identity, which means least-privilege IAM policies attach directly to the agent rather than to the human who launched it. If an agent is compromised, a security team can contain it the same way it would contain any other service principal. Independent analysis of the launch, including a detailed breakdown from jahanzaib.ai, argues this is a real difference from running OpenAI's Assistants API in self-hosted infrastructure, where identity bookkeeping stays the customer's problem.
The second is auditability. Every tool call, every model call, and every state mutation is logged, and those logs can flow into CloudTrail, S3, or any existing SIEM. For regulated teams, the practical payoff is passing audits without writing custom telemetry from scratch.
The third is the runtime itself. The service is built on what Amazon describes as OpenAI's agent harness, a runtime engineered for orchestrating long-running, multi-step tasks. Coverage of the launch notes that the harness is tuned to drive OpenAI's reasoning models specifically, including mid-task correction that generic agent runtimes tend to fumble.
Identity is becoming the agent era's permission system
The per-agent identity story is part of a broader 2026 pattern. Security teams have been racing to build agent identity infrastructure all year, from NVIDIA's open agent safety platform to AWS's own push for keeping access controls outside the agent itself. Bedrock Managed Agents arrives as the enterprise packaging of that idea: the agent's credentials are inherently limited to the permissions it was granted, and prompt manipulation alone should not widen them.
That framing is not just marketing copy. Earlier this year, AWS engineers demonstrated the same philosophy across DynamoDB, Bedrock Knowledge Bases, and Salesforce, showing how underlying services can be configured to reject unauthorized requests regardless of what the agent asks for. A report on that work from Help Net Security concluded that the approach keeps the blast radius small even when an agent is manipulated through prompt injection.
Salesforce signs on as an early named partner
Salesforce is the first named partner for the preview. According to AWS's product page, the company's Headless 360 product will pair OpenAI's models and AWS infrastructure with Salesforce's own data, workflows, and controls.
Salesforce President of Enterprise & AI Technology Joe Inzerillo said that in that configuration, data never leaves AWS. That characterization comes from Salesforce and AWS themselves rather than an independent audit, and neither company has yet published a customer using the integration in production.
The end of a seven-year exclusivity
OpenAI's infrastructure has run almost exclusively on Microsoft Azure since the 2019 investment, and Azure is expected to serve the bulk of OpenAI's API load for years to come. Both companies still describe Microsoft as OpenAI's primary cloud partner.
But the exclusivity that defined the relationship is gone. Bedrock Managed Agents gives AWS-committed enterprises a way to run the whole stack through Amazon. Analysts are already asking whether Google Cloud or another hyperscaler will ship a comparable first-party OpenAI-agent integration next, and what Microsoft will say publicly about the expansion.
The launch also continues a busy DevDay for enterprise channels. OpenAI introduced Dots always-on agents and a Decisions API at the same event, and the company has been courting business partners on several fronts at once, as seen in the Sierra marketplace partnership announced the same week.
What to watch next
The service is in preview, and AWS has not published general-availability pricing, a GA date, or supported regions. The questions that matter now are whether Microsoft comments publicly on the expansion, whether AWS names a production timeline, and whether enterprise security teams adopt per-agent identity as the default posture for agent deployment.
AgentCore, the compute layer underpinning the service, has been maturing all year: it entered preview in May, reached general availability in June, and now hosts OpenAI's own agent stack. AWS's direction is clear. It wants to be the neutral ground where agents from every lab run, and the race to build that ground is officially on.
Sources
Reporting on the launch from Pondero AI (OpenAI agents now run natively on AWS through new Bedrock Managed Agents), technical analysis from jahanzaib.ai, the AWS News Blog introduction to Bedrock AgentCore, and Help Net Security's coverage of AWS agent access controls.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.