AWS published security patterns for Bedrock AgentCore Runtime. The architectures use an internet-facing load balancer with AWS WAF and route traffic through a VPC interface endpoint.
As AI agents become internet-accessible services, runtime security is becoming a deployment requirement rather than an afterthought. WAF rules, private endpoints, and proxy layers can help reduce exposure for agent applications.
The guidance points to a maturing agent stack where governance and perimeter controls sit alongside model and tool orchestration.