# AWS AI Infrastructure — 4+1 Layer AI Infrastructure Assessment

> Mapped to the 4+1 Layer AI Infrastructure Model  
> Version: v1.4 - Single-Vendor API Re-Lens & Label Reconciliation · Date: July 12, 2026  
> Source: re:Invent 2025, GTC 2026, Bedrock AgentCore GA, AgentCore Policy GA (Mar 2026), SageMaker Unified Studio, AWS/NVIDIA collaboration, OpenAI/AWS partnership, analyst coverage. v1.2 (instrument reconciliation): 1A S3 and 2A EKS Retained→Delegated — a managed service behind a multi-vendor standard interface is Delegated; Retained is reserved for an open substrate the enterprise operates. Corrects the prior over-application of Retained. Also aligned the VAST Layer 2C cross-reference to VAST's current gap status (PolicyEngine GA end 2026). v1.3 (lab-validated against the TFD corpus RAG build): added Amazon S3 Vectors (GA Dec 2025) to Layer 1B as a Ceded component (single-vendor vector API, no open exit), and added the self-orchestrate-versus-Bedrock-KB Retain/Delegate fork to the 1B and 1C narration, mirroring 2A/2B. v1.4 (July 12, 2026, /reconcile): the hyperscaler lens drift resolved — AWS's single-vendor managed services re-lensed under the litmus's own rule (single-vendor API = Ceded; Delegated requires a multi-vendor standard or open substrate), aligning the row with the Azure/GCP/OCI treatment of architecturally identical services. Chips moved D→C: Glue Catalog + Lake Formation, SageMaker Catalog (1A); Bedrock Knowledge Bases (1B); Bedrock, AgentCore Runtime (2B); Guardrails, AgentCore Policy, Evaluations + Memory (2C); Amazon Q, Kiro, Bedrock Agents (L3). Invalid dual-enum chips split into per-mode components (SageMaker managed Ceded / self-hosted Retained; Bedrock Agents Ceded / Strands apps Retained; Glue ETL Delegated / Unified Studio Ceded; MWAA Delegated / Step Functions Ceded). Agent Registry (Preview) descored to the watch-list per the GA-gate. statusLabels moved to capability vocabulary. No capability grades changed.  
> Published by: The CTO Advisor LLC · thectoadvisor.com  
> Author: Keith Townsend

[Full interactive assessment](https://layer2c.com/assessment/aws) · [Methodology](https://layer2c.com/methodology) · [What Is Layer 2C?](https://layer2c.com/what-is-layer-2c)

## Executive Summary

AWS is the first vendor in this assessment series that makes a credible claim across every layer of the 4+1 model — including Layer 2C. The structural difference between AWS and every on-prem vendor (Dell, HPE, VAST) is the direction of authority. On-prem vendors build upward from hardware, attempting to extend authority into orchestration and runtime layers. AWS builds downward from managed services, extending authority into custom silicon (Trainium, Inferentia, Graviton), custom networking (EFA/SRD, Nitro), and now on-prem infrastructure (AWS AI Factories).

The DAPM classification for AWS is structurally inverted compared to on-prem vendors. The enterprise architect using AWS retains less direct authority at every layer — but gains operational leverage that on-prem vendors cannot match. The question is not whether AWS has the capabilities. The question is whether the enterprise architect has made the authority delegation explicit, and whether they understand what borrowed judgment they inherit when they adopt AWS’s Reasoning Plane as their own.

AWS already has the control plane everyone else is trying to build. The problem is that customers do not always see where AWS’s control plane ends and their own authority begins. When Bedrock routes inference, SageMaker auto-scales, or Karpenter provisions nodes — those are Layer 2C functions operating invisibly inside managed services. This is the ‘DGX Realization’ that birthed the 4+1 model: the cloud operates an invisible Reasoning Plane that becomes visible only when you try to replicate it on bare metal.

The OpenAI partnership (2GW of Trainium capacity, Stateful Runtime on Bedrock) and NVIDIA deepened collaboration (1M+ GPUs including Blackwell and Rubin) demonstrate AWS positioning as the substrate on which multiple AI ecosystems converge — creating one of the broadest Layer 3 ecosystems and one of the most complex borrowed judgment landscapes.

## Layer Status

| Layer | Status | Classification |
|---|---|---|
| Layer 0 · Compute | ● Custom Silicon Full Stack | Compute & Network Fabric |
| Layer 1A · Storage | ● Managed Data Foundation | Data Storage & Governance |
| Layer 1B · Retrieval | ● Managed Retrieval Portfolio | Context Management & Retrieval |
| Layer 1C · Pipelines | ● Managed Pipelines (Spark/Airflow Substrates) | Data Movement & Pipelines |
| Layer 2A · Orchestration | ● EKS + Capacity Management | Infrastructure Orchestration |
| Layer 2B · Runtime | ● Bedrock + Open Paths | Application Runtime & Execution |
| Layer 2C · Reasoning | ◑ Intelligence-2C Toolkit; Placement Implicit | Agentic Infrastructure — The Reasoning Plane |
| Layer 3 (+1) · Applications | ● Broadest Ecosystem | AI Application Layer — The Value Plane |

## DAPM Profile

| Classification | Count | Meaning |
|---|---|---|
| Retained | 3 | Enterprise owns and controls this capability |
| Delegated | 7 | Provided by substitutable partner; enterprise retains swap authority |
| Ceded | 20 | Vendor controls this; enterprise has no governance authority |
| Absent | 0 | No capability at this layer |

## Strongest Layers

- **Layer 0** (Compute & Network Fabric) — Custom Silicon Full Stack
- **Layer 1A** (Data Storage & Governance) — Managed Data Foundation
- **Layer 1B** (Context Management & Retrieval) — Managed Retrieval Portfolio
- **Layer 1C** (Data Movement & Pipelines) — Managed Pipelines (Spark/Airflow Substrates)
- **Layer 2A** (Infrastructure Orchestration) — EKS + Capacity Management
- **Layer 2B** (Application Runtime & Execution) — Bedrock + Open Paths
- **Layer 3 (+1)** (AI Application Layer — The Value Plane) — Broadest Ecosystem

## Layer-by-Layer Detail

### ● Layer 0 · Compute: Compute & Network Fabric

*Raw compute, networking, and acceleration fabric*  
**Status:** Custom Silicon Full Stack

**AWS Custom Silicon (Annapurna Labs)** [DAPM: Ceded]  
Trainium3 GA: EC2 Trn3 UltraServers, 144 chips/UltraServer, 4.4x compute vs Trn2, 4x energy efficiency, 4x memory bandwidth. Sub-10µs chip-to-chip latency. Designed for agentic AI, MoE models, large-scale RL. Trainium4 expected 2027. Inferentia2 for inference. Graviton for ARM CPU. AWS-owned silicon IP.

**NVIDIA GPUs on AWS** [DAPM: Ceded]  
Broadest NVIDIA GPU collection of any cloud. P5 (H100), P5e (H200), P6 (B200), P6e (GB200). 1M+ GPUs added 2026 including Blackwell and Rubin.

**Nitro System + EFA + SRD** [DAPM: Ceded]  
Custom hardware/firmware for I/O offload. Hardware-enforced security isolation. EFA: OS-bypass with 3,200 Gbps bandwidth. SRD: AWS custom multi-path, fault-tolerant transport. EC2 UltraClusters: petabit-scale, 20,000 GPUs, 16% latency reduction (v2.0).

**AWS AI Factories (On-Prem)** [DAPM: Ceded]  
Dedicated on-prem environments as private AWS Region. Customer provides space/power; AWS deploys and manages Trainium, NVIDIA GPUs, networking, storage, and full managed services (Bedrock, SageMaker). Inverted vs Dell/HPE: AWS operates infrastructure the customer houses.

**Gap Analysis:** The enterprise has no authority over Layer 0 hardware beyond choosing instance types. The multi-accelerator marketplace (Trainium, NVIDIA, AMD, Intel) creates a workload-to-silicon matching problem that is itself a Layer 2C function. This problem doesn’t exist in on-prem (accelerator choice made once at procurement) but recurs with every cloud workload placement decision.

AWS is the only vendor that owns accelerator silicon IP (Annapurna Labs). Dell and HPE brand third-party silicon. VAST has no Layer 0 silicon. AWS AI Factories invert the on-prem model: Ceded infrastructure even when physically in the customer’s facility.

**Borrowed Judgment:** Inverted. The enterprise Cedes Layer 0 entirely — AWS makes all silicon, networking, and infrastructure decisions. The enterprise selects from AWS’s menu but does not influence underlying hardware design, networking topology, or physical infrastructure. The trade-off: loss of direct hardware authority in exchange for operational leverage (no procurement lead time, per-workload silicon selection, managed scaling).

### ● Layer 1A · Storage: Data Storage & Governance

*Durable, governed data foundation — the Governance Catalog that Layer 2C queries*  
**Status:** Managed Data Foundation

**Amazon S3 + S3 Tables** [DAPM: Delegated]  
De facto object storage standard. S3 Tables (re:Invent 2025): Iceberg-native table storage. S3 Express One Zone: single-digit ms latency. S3 is a vendor-managed service behind the multi-vendor S3 standard — object opinions lift to any S3-compatible platform, so Delegated (operation delegated to AWS; the standard interface keeps the opinions portable). Reserve Retained for an open substrate the enterprise operates (e.g. self-run Ceph/MinIO).

**AWS Glue Data Catalog + Lake Formation** [DAPM: Ceded]  
Centralized metadata with catalog federation to remote Iceberg catalogs. Fine-grained access control, cross-account sharing, column/row-level security. SageMaker and Bedrock inherit IAM/Lake Formation context. The primitives for 1A→2C exist; the composition is customer-built. Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**SageMaker Catalog** [DAPM: Ceded]  
Discovery, subscription, governed sharing of data assets within SageMaker Unified Studio. Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**Gap Analysis:** Most mature governance catalog in this assessment. Glue + Lake Formation metadata is API-accessible to higher layers. The 1A→2C connection (Reasoning Plane querying governance metadata for placement decisions) is not a product today — the primitives exist, composition is customer-built. Catalog federation to remote Iceberg catalogs is unmatched within this series. Hybrid gap: federated catalog covers S3 and Iceberg-compatible catalogs but not proprietary on-prem storage metadata.

**Borrowed Judgment:** Delegated with customer-retained policy. Lake Formation policies are customer-defined; enforcement is AWS-managed. Cleaner DAPM than Dell (MetadataIQ indexes Dell-only) or VAST (governance catalog is proprietary).

### ● Layer 1B · Retrieval: Context Management & Retrieval

*Low-latency retrieval for RAG — vector/hybrid search, context windows*  
**Status:** Managed Retrieval Portfolio

**Amazon Bedrock Knowledge Bases** [DAPM: Ceded]  
Managed RAG: ingest → chunk → embed → index → retrieve. Supports OpenSearch, Aurora/pgvector, Pinecone, Redis. Vertically integrates 1B+1C within managed boundary. Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**Amazon OpenSearch Serverless** [DAPM: Delegated]  
Vector search with HNSW/FAISS. Default Bedrock Knowledge Bases backend. Serverless scaling.

**Amazon Neptune** [DAPM: Delegated]  
Graph database for relationship-aware retrieval. Multi-hop reasoning for agentic workloads. Delegated survives on the consumed interface: Gremlin and openCypher are multi-vendor query standards — the weakest survivor of the July 2026 re-lens, flagged as such.

**Amazon S3 Vectors** [DAPM: Ceded]  
Native vector storage in S3 buckets. GA Dec 2025. Up to 2 billion vectors per index, sub-100ms on frequent queries, roughly 90 percent cheaper than specialized vector databases. A metadata filter on query-vectors gives hybrid semantic-plus-structured retrieval in one call. Usable standalone or as a Bedrock Knowledge Bases storage engine. The put/query interface is single-vendor AWS with no open implementation elsewhere, so the store is captive even though the vectors re-embed cheaply: Ceded. The cheapest 1B option is also the most captive interface.

**Gap Analysis:** Bedrock Knowledge Bases erases the 1B/1C boundary within its managed surface — borrowed judgment, not a gap. AWS makes chunking, embedding, retrieval strategy decisions on the customer’s behalf. The enterprise should ask whether defaults suit their domain. The governance fork mirrors 2A and 2B: consume Bedrock Knowledge Bases and the chunk, embed, and retrieve decisions are AWS's (Delegated), or self-orchestrate the pipeline on primitives (InvokeModel embeddings into S3 Vectors or OpenSearch) and Retain the retrieval-strategy opinions. Self-orchestration Retains the pipeline logic, not the store: OpenSearch stays portable, S3 Vectors is captive to a single-vendor API.

Interoperability gap: no unified retrieval abstraction across Bedrock Knowledge Bases + self-hosted Weaviate + Neptune. Routing logic between backends is a Layer 2C function living in application code.

**Borrowed Judgment:** Moderate, with a Retain path. Self-orchestrating the embed-and-index pipeline on primitives (InvokeModel embeddings into S3 Vectors or OpenSearch) Retains the retrieval-strategy opinions, though the chosen store keeps its own authority. Consume Bedrock Knowledge Bases and AWS makes retrieval quality decisions the enterprise inherits without explicit governance. Compare to VAST (InsightEngine — tighter but VAST-controlled) or Dell (Elastic — separate ISV).

### ● Layer 1C · Pipelines: Data Movement & Pipelines

*Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering*  
**Status:** Managed Pipelines (Spark/Airflow Substrates)

**AWS Glue ETL (Spark Substrate)** [DAPM: Delegated]  
Glue: serverless ETL with Spark 3.5.6, Iceberg 1.10. SageMaker Unified Studio: horizontal integration across 1A/1C/2B with one-click onboarding. Single governed environment collapsing organizational boundaries across data engineering, data science, ML engineering. Chip scoped to the ETL engine: Glue jobs are Spark code — an open substrate; job logic ports to any Spark. The catalog surface is scored Ceded at 1A; the Studio console is split below.

**SageMaker Unified Studio** [DAPM: Ceded]  
Single-vendor development and pipeline console — workspace and pipeline-definition opinions accumulate against an AWS-only surface. Ceded, split from the Spark-substrate ETL chip.

**Amazon MWAA (Managed Airflow)** [DAPM: Delegated]  
Managed Airflow for complex DAGs. Step Functions for serverless multi-step workflows in ML pipeline reference architectures. Chip scoped to MWAA: managed open-source Airflow — DAGs port to any Airflow. Step Functions split below.

**AWS Step Functions** [DAPM: Ceded]  
Single-vendor state-machine language — workflow definitions have nowhere to run but AWS. Ceded, split from the Airflow chip.

**Gap Analysis:** AWS horizontal integration vs VAST vertical integration: same functional coverage, different authority models. VAST = one authority boundary, fewer choices, fewer seams. AWS = many services sharing governance via Lake Formation/IAM, more policy control, more operational complexity. SageMaker Unified Studio addresses fragmentation but underlying services remain distinct.

**Borrowed Judgment:** Delegated with customer-retained configuration. AWS provides pipeline services; customer defines transformations and flows. The same fork as 1B applies to the embed-and-index pipeline: consume Bedrock Knowledge Bases and the chunk, embed, and index movement is collapsed and managed (Delegated), or self-orchestrate it on primitives (InvokeModel embeddings feeding S3 Vectors or OpenSearch) and Retain the pipeline opinions, with the chosen store carrying its own authority. Operational complexity of maintaining consistent governance across many AWS accounts is the trade-off for flexibility.

### ● Layer 2A · Orchestration: Infrastructure Orchestration

*GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization*  
**Status:** EKS + Capacity Management

**Amazon EKS Auto Mode + Karpenter** [DAPM: Delegated]  
Managed K8s with GPU-aware scheduling. EKS Auto Mode automates cluster/compute management. Karpenter: open-source autoscaler provisioning exact instance types. Mixed compute (NVIDIA, Trainium, Inferentia, Graviton). Note: no DRA support, Capacity Blocks negate scale-to-zero. EKS is a managed service behind the standard Kubernetes API — manifests lift to another conformant cluster, so Delegated (operation delegated to AWS; the standard interface keeps the opinions portable).

**Capacity Management** [DAPM: Ceded]  
Capacity Block Reservations, Flex Start, Savings Plans, Spot. All AWS-controlled allocation. These are capacity acquisition mechanisms, not workload placement reasoning.

**Gap Analysis:** For Dell/HPE, Layer 2A is where authority slips to NVIDIA. For AWS, Layer 2A is where AWS retains authority through managed services while integrating NVIDIA optionally. GPU scheduling primitives are AWS-controlled.

Governance choice: Retain 2A by running self-managed EKS, or Cede 2A by consuming Bedrock (no EKS, no Karpenter — AWS handles 2A invisibly). Both legitimate; the choice is a governance decision with DAPM implications.

**Borrowed Judgment:** Low to moderate depending on path. EKS (Kubernetes interface): Delegated — managed K8s, manifests lift to another conformant cluster. Bedrock consumption: Ceded. NVIDIA dependency is optional, structurally different from Dell/HPE where Run:ai is the primary GPU scheduler.

### ● Layer 2B · Runtime: Application Runtime & Execution

*Model serving, agent execution, inference APIs, distributed inference*  
**Status:** Bedrock + Open Paths

**Amazon Bedrock** [DAPM: Ceded]  
Foundation model access: Anthropic Claude, Amazon Nova, Meta Llama, OpenAI (Stateful Runtime), Mistral, Cohere, NVIDIA Nemotron. Unified API. Fine-tuning including RFT. Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**Bedrock AgentCore Runtime** [DAPM: Ceded]  
Serverless agent runtime. Framework-agnostic (Strands, LangChain, CrewAI). Protocol-agnostic (MCP, A2A). Model-agnostic. MicroVM session isolation. 2M+ SDK downloads in 5 months. Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**SageMaker AI (Managed)** [DAPM: Ceded]  
Training, fine-tuning, inference endpoints. LMI containers with vLLM. Multi-LoRA. Supports Trainium + NVIDIA. vLLM on EKS and Ray on EKS for fully self-hosted (Retained). Chip scoped to the managed platform: SageMaker training/serving APIs are single-vendor — Ceded, matching Vertex on the GCP row. The self-hosted path is split below.

**Self-Hosted OSS Runtimes on EC2/EKS** [DAPM: Retained]  
vLLM, Ray, KServe-class serving the customer operates on rented compute — open substrates; the opinions lift to any infrastructure. The Retained escape valve of the AWS runtime story.

**Strands Agents SDK** [DAPM: Retained]  
AWS open-source agentic framework. Model-first, native AgentCore/Guardrails/OpenTelemetry integration. Multi-agent patterns with A2A.

**Gap Analysis:** AWS owns multiple 2B surfaces (Bedrock, SageMaker, AgentCore, EKS). NVIDIA dependency is optional in a way it’s not for Dell/HPE. Agent frameworks blur 2B/2C/3 boundaries — AgentCore bundles Runtime (2B) + Policy (2C) + agent logic (3). Product boundary ≠ architectural boundary.

Borrowed judgment: using Bedrock to access Anthropic Claude or Meta Llama means the model provider’s alignment decisions become part of the enterprise’s AI system. Guardrails constrain output but reasoning in model weights is not customer-configurable.

**Borrowed Judgment:** Varies by path. Bedrock: Delegated + model provider borrowed judgment. SageMaker self-hosted: Retained. AgentCore: Delegated. Self-hosted EKS: fully Retained. Runtime proliferation is itself a 2C decision AWS doesn’t automate.

### ◑ Layer 2C · Reasoning: Agentic Infrastructure — The Reasoning Plane

*Policy-driven placement and resource coordination — the Autonomy Layer*  
**Status:** Intelligence-2C Toolkit; Placement Implicit

**Bedrock Guardrails** [DAPM: Ceded]  
Content filtering, PII protection, topic blocking. ApplyGuardrail API works with any model. Cross-account organizational safeguards (GA Apr 2026). Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**AgentCore Policy (GA Mar 2026)** [DAPM: Ceded]  
Centralized governance outside agent code. Natural language → Cedar policy. Intercepts every tool call before execution. 13 AWS regions. Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**AgentCore Evaluations + Memory** [DAPM: Ceded]  
Built-in evaluators for correctness, safety, adherence, consistency. Episodic Memory for stateful reasoning across sessions. Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**Gap Analysis:** Intelligence Layer 2C (partially present): AgentCore Policy + Guardrails + Evaluations govern agent behavior. Real and productized. Natural-language-to-Cedar conversion is the most accessible policy authoring in this assessment.

Infrastructure Layer 2C (not built): No service answers ‘given data residency, cost, latency, and compliance, should this run on Trainium in us-east-1 or NVIDIA in eu-west-1?’ Capacity primitives are building blocks, not a policy-driven placement engine querying 1A governance metadata.

The structural insight: AWS already has the control plane everyone else is trying to build — but it’s implicit. Dell’s 2C gap is product absence. AWS’s 2C gap is visibility and authority — the capability exists but is implicit, managed, and Ceded.

Five-vendor Layer 2C comparison:
• Dell: Absent.
• HPE: Retained (IT ops) + Delegated (Kamiwaza).
• VAST: Gap, emerging (Polaris ships as placement abstraction — routing, not reasoning; PolicyEngine GA end 2026).
• AWS: Intelligence 2C Delegated (productized). Infrastructure 2C implicit (inside managed services).

The question is not ‘Does AWS have Layer 2C?’ but ‘How much can the enterprise configure, audit, and control — and how much has been Ceded without explicit classification?’

**Borrowed Judgment:** Intelligence 2C: Low — AgentCore Policy, Guardrails, Evaluations are AWS IP. Customer defines policies; AWS enforces.

Infrastructure 2C: Ceded (implicit) — placement decisions inside managed services without explicit customer policy input. When SageMaker auto-scales or Bedrock routes, those are 2C functions the enterprise has Ceded without classification.

DAPM discipline demands: for every managed service placement decision, classify as Delegated (customer sets policy) or Ceded (AWS decides).

### ● Layer 3 (+1) · Applications: AI Application Layer — The Value Plane

*AI-powered business capabilities — business logic, workflow automation*  
**Status:** Broadest Ecosystem

**Bedrock Agents (Managed)** [DAPM: Ceded]  
No-code (Bedrock Agents) and full-code (Strands) agent construction. Bedrock Agents: Delegated behavior. Strands: Retained authority. Both span 2B/2C/3. Chip scoped to the managed agent service: single-vendor agent definitions and tool bindings — Ceded. Strands-built applications split below.

**Strands SDK Applications** [DAPM: Retained]  
Agents built on the open-source Strands SDK — model-agnostic, self-hostable; application opinions lift out. Retained.

**Amazon Q** [DAPM: Ceded]  
AWS AI assistant for business and development. Enterprise Delegates application behavior to AWS. Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**Model + ISV Ecosystem** [DAPM: Delegated]  
Anthropic Claude, Amazon Nova, Meta Llama, OpenAI, Mistral, Cohere, NVIDIA Nemotron. Thousands of ISV applications. 11,000+ government agencies.

**AWS Kiro (Agentic IDE Platform)** [DAPM: Ceded]  
Spec-driven agentic development platform replacing Amazon Q Developer (new signups ended May 2026). Three surfaces: VS Code-compatible IDE, CLI, and autonomous cloud agent. Spec-driven development generates requirements.md, design.md, and tasks.md before code — specs are source-of-truth, code is build artifact. Hooks system: 17 automated quality gates (security, linting, testing, validation) firing on file save and PR events. Multi-model routing: Claude Sonnet for reasoning-heavy specs, Amazon Nova for high-throughput code generation, Bedrock as unified model plane. 50+ Powers (MCP integrations: Figma, Terraform, Stripe, Datadog). Autonomous agent executes backlog tasks and opens PRs without developer in the loop. Deep AWS context: native Powers for AWS pricing, docs, Well-Architected, cost analysis. The most opinionated developer AI surface from any cloud vendor — enforces structured development discipline rather than freeform 'vibe coding.' Single-vendor API — the litmus names this class Ceded: the opinions accumulate against a surface only AWS implements, with nowhere to take them. Re-lensed July 2026 to match the Azure/GCP/OCI treatment of the architecturally identical service.

**Gap Analysis:** Broadest Layer 3 in this assessment — different category than Dell ISV partnerships, HPE Unleash AI, or VAST Cosmos. Each Layer 3 application brings its own governance domain. AgentCore Policy and Guardrails provide cross-agent governance primitives; whether they compose into enterprise-wide agent governance remains an implementation question.

The Retained/Delegated boundary is not uniform. Custom Strands on self-hosted EKS: fully Retained. Bedrock Agents / Q / partner apps: substantially Delegated. Same enterprise may have both patterns simultaneously.

Kiro represents AWS's strongest Layer 3 opinion: spec-driven development enforces structured requirements before code generation. This is an opinionated development methodology embedded in tooling — the enterprise Delegates development workflow decisions to AWS's architectural opinions about how AI-assisted software should be built. The autonomous agent (cloud agent executing tasks and opening PRs without human in the loop) creates a new DAPM question: when Kiro's agent writes and ships code autonomously, who owns the judgment embedded in that code? The developer who assigned the task, or Kiro's multi-model routing logic that chose which model to apply?

Compare to Google Antigravity 2.0 (agent orchestration platform, multi-agent parallel execution, Gemini-native) and GitHub Copilot (IDE-embedded coding agent with cloud agent for autonomous PR creation). All three clouds now have agentic developer surfaces that span Layer 2B (execution) and Layer 3 (application). The competitive dynamics are shifting from 'which cloud has the best models' to 'which cloud has the most productive developer surface.'

**Borrowed Judgment:** Distributed and complex. Model providers bring training data, alignment, safety decisions as inherited borrowed judgment. AWS platform defaults shape application behavior. DAPM Action 3 applies with force: when you move off AWS, what judgment doesn’t move with you? Answer: almost everything above Layer 0.

---
*Layer2C · AI Infrastructure Decision Intelligence · The CTO Advisor LLC · thectoadvisor.com*
