FR
live

AWS Well-Architected Agent audits your cloud like an architect and ships IaC fixes

AWS launches a preview AI agent that analyzes an environment against 65+ services and produces dollar-quantified recommendations, with Terraform or CloudFormation fixes ready to apply. Read it like a junior architect, not an oracle.

An architect’s loupe resting on a scale model of a building on a work table, one single amber window lit in the model.

October 1, 2026. AWS announces the public preview of AWS Well-Architected Agent, a generative-AI service that analyzes a cloud environment and produces targeted recommendations for cost, security, performance, and resilience. October 1, 2026. The agent evaluates infrastructure against Well-Architected best practices across more than 65 AWS services. October 1, 2026. The first recommendations are generated within 24 hours of creating an agent profile. Why it matters: the Well-Architected framework shifts from a manual checklist to an agent that correlates metrics, configurations, and topology — and ships Infrastructure as Code fixes ready to apply.

An audit that correlates instead of a checklist that ticks

The promise is in the method. Where the classic Well-Architected Tool asks an architect to answer a questionnaire by hand, the agent analyzes the real infrastructure. It automatically correlates utilization metrics, resource configurations, and application topology, then compares the result against Well-Architected best practices across more than 65 AWS services.

The official positioning is explicit: the agent evaluates the environment “as an experienced cloud architect would.” It generates recommendations aligned to declared business goals, delivers an implementation package with every finding, and surfaces cross-pillar trade-offs — for example, when a cost optimization risks degrading resilience.

Three features structure the service. Goal-aligned intelligence replaces flat, undifferentiated findings with recommendations prioritized by impact and effort once business objectives are declared. Three-level recommendations span individual resource findings — with dollar impact and step-by-step remediation — to consolidated findings across multiple resources of a single application, up to broad architectural patterns shipped with the IaC code changes needed. Optionality in remediation lets you choose the path: guided console walk-throughs, IaC changes for architectural recommendations, or AWS CLI commands.

How you wire it up, and what it sees

Setup is built around an agent profile. You define which AWS accounts and regions the agent can observe, which optimization pillars to prioritize — cost, performance, resilience, security — and the associated permissions. Access runs through customer-managed IAM roles the agent uses to read resource configurations, utilization metrics, and application topology.

The read scope is therefore the real risk lever. An IAM role that is too broad would give the agent visibility the team may not want to expose, even read-only. Scoping it to the strict minimum — the accounts and regions actually under review — is the first security decision to make, before even looking at the first recommendation.

The agent can also evaluate code before it deploys. The architecture review feature accepts an IaC project — Terraform, AWS CloudFormation, or CDK — uploaded as an archive, and analyzes it through the chosen Well-Architected lens. That is a notable shift: the audit no longer applies only to what already runs, but to what is about to run.

What it changes inside the team

The real shift is organizational. Until now, a Well-Architected Review was a point-in-time exercise, often run by an external architect or partner, with report-style deliverables. The agent turns it into a continuous process: recommendations are delivered through the console and the API, updated periodically, and therefore trackable over time like a remediation backlog.

The IaC link is the most concrete part. An architectural recommendation is no longer a paragraph a human has to translate into code: it arrives with the code changes to apply, which pulls the audit closer to the workflow of a platform or SRE team. An individual resource finding, in turn, arrives with a dollar impact — enough to prioritize by the money actually at stake, not an abstract score.

The limits still need reading. AWS says it explicitly: the generative-AI capabilities “may contain errors or incomplete information,” and the responsibility to evaluate the recommendation in your specific context remains with the team. It is an assistant that accelerates, not an authority that decides.

A concrete scenario: FinOps and security meet

A cost recommendation is no longer just “this instance is underutilized.” It quantifies the expected saving and proposes the remediation — a resizing, a move to Savings Plans, or the removal of an orphaned resource — as IaC changes or CLI commands. That is exactly the work FinOps teams do by hand today, through Cost Explorer exports and spreadsheets.

The same mechanism applies to security. A consolidated finding can point at a group of S3 buckets with overly permissive policies, correlate access metrics to separate real needs from historical leftovers, and propose the corrected IAM policy. The difference from a classic posture scanner is the trade-off layer: the agent weighs the security gain against the risk of breaking an application, and documents the compromise.

That is also where the risk concentrates. A security recommendation applied blindly can lock down a production application. AWS’s instruction — evaluate every recommendation in your context — is not a disclaimer clause, it is the real operating manual: the agent accelerates the analysis, the human keeps the decision. It is the posture to adopt toward a competent but not infallible junior architect.

Availability and positioning

The preview is bounded. Access to the agent and its recommendations is available in US East (N. Virginia), US East (Ohio), and US West (Oregon), with the ability to onboard workloads from any commercial AWS region. The service is delivered by AWS Support and reserved for customers on an AWS Support plan — making it, for now, an enterprise-tier benefit rather than a universal tool.

The strategic positioning is clear. AWS puts generative AI at the center of its own best-practices framework, where its competitors sell optimization as a separate observability or FinOps product. By making Well-Architected an agent rather than a questionnaire, AWS turns its long-standing reference framework into the entry point for continuous optimization — and, in passing, deepens its relationship with customers already invested in the framework. The support-plan gate is telling: this is a retention feature aimed at customers who already pay AWS to help them, not a standalone tool meant to compete on the open market.

Verdict

If you have an AWS Support plan and workloads in production, try the agent as a permanent second opinion on cost and security, starting with a narrow scope — one or two accounts, one pillar — and a minimal read-only IAM role. If you are already evaluating FinOps or observability tools, compare the agent on its ability to produce actionable IaC fixes rather than findings, because that is where it stands apart. If you lack a support plan or sit outside the three preview regions, there is nothing to do yet: it is a preview, and the agent is not yet a universal standard.

Références

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss