AI Agents
AWS Agent Registry Catalogs Agents; It Does Not Certify Them
AWS made Agent Registry generally available on August 31 in five regions. The service catalogs agents, tools, skills, MCP servers, and custom resources with approvals, search, CloudTrail records, infrastructure-as-code support, cross-account sharing, and automatic detection; a registry entry does not by itself prove safety, ownership, freshness, or task reliability.
Citation-ready: AWS Agent Registry became generally available on August 31, 2026, in five regions as a private catalog for agents, tools, skills, MCP servers, and custom resources.

What happened and why it matters
No. The registry can make ownership, discovery and approval workflows visible, while runtime permissions, security review, evaluation results, version freshness, and incident controls still require separate receipts.
Official AWS availability record and documentation
Primary reference: AWS: Agent Registry generally available. Kaleido Field checked the event date and the article's attributed facts against this source.
| Source date | August 31, 2026 |
|---|---|
| Checked by Kaleido Field | September 1, 2026, 08:12 CST |
| Source function | current agent-governance analysis separating catalog discovery, approval state, infrastructure-as-code records, cross-account sharing, automatic detection, runtime authority, evaluation, and certification |
A useful record needs more than a name
A catalog entry can expose what exists and who owns it, reducing duplicate agent and tool work. Infrastructure-as-code support also makes registry configuration reviewable alongside deployment changes.
Teams should attach version, artifact hash, source, owner, data classes, permissions, endpoints, dependency lock, approval scope, expiry, eval set, known failures, and rollback path.
Automatic detection creates an inventory, not trust
AgentCore runtime and gateway resources can be detected across an organization and added to a central registry. Discovery closes an inventory gap but cannot infer whether the resource should retain access.
A release gate should compare detected runtime state with the reviewed record, then fail closed when code, model, tools, identity, policy, or data scope has drifted.
Evidence boundary
Official product facts: GA state, regional availability, supported resource types, search, approvals, audit logs, infrastructure as code, tagging, cross-account sharing, and AgentCore detection. Not established by a listing: verified publisher identity, harmless code, least privilege, prompt-injection resistance, current version, task accuracy, service level, or approval validity after a dependency changes.
FAQ
Where is it available?
AWS lists Oregon, Tokyo, Sydney, Ireland, and Northern Virginia.
Can it be managed as code?
AWS names CloudFormation, Terraform, and the AWS CDK.
Does it evaluate agent quality?
The GA notice describes discovery and governance features, not a universal task-quality certification.