AWS previews Well-Architected Agent, limited to Business+ Support plans and above
AWS announced a preview of AWS Well-Architected Agent on October 1, 2026. The service scans your AWS accounts on a schedule and returns recommendations for cost, security, resilience, and performance, ranked against business goals that you write yourself. Remediation scripts come attached, and the agent also reviews infrastructure-as-code templates on demand. Access requires an AWS Support plan at the Business+ tier or higher, and agent profiles are hosted in three US Regions.
Source
AWS Well-Architected Agent is now available in previewAWS What's New — Machine Learning · Original published October 1, 2026
AWS describes the agent as the next-generation evolution of AWS Trusted Advisor and the AWS Well-Architected Tool. You create an agent profile that names the accounts and Regions to scan, the optimization pillars to analyze, and at least one business goal written in plain text. The agent then ranks its recommendations against those goals. The user guide marks the service as a preview release that is subject to change.
What the agent produces
Recommendations come at three levels: resource, application, and architecture. Resource and application recommendations are generated on a schedule. According to the user guide, the first set arrives within 48 hours after a profile is configured, and the set is refreshed weekly after that. You cannot trigger those two types on demand.
Each recommendation shows its effect on the other pillars and describes the trade-offs of applying it. Where applicable, the fix is delivered as a Systems Manager (SSM) runbook, a CLI script, a guided console walkthrough, or updated infrastructure-as-code (IaC). AWS labels application-level recommendations as a new format in beta. The company asks you to review each recommendation thoroughly before acting on it, as with any AI-generated content.
The agent builds on findings from existing services. The user guide lists AWS Trusted Advisor, AWS Compute Optimizer, AWS Security Hub CSPM, AWS Resilience Hub, and AWS Cost Optimization Hub as inputs. Cost figures come from AWS Cost Explorer when it is enabled. Without it, the agent estimates costs from public AWS pricing.
What access the agent gets
The agent uses two kinds of IAM roles. An execution role lives in the account that holds the profile, and its only permission is to assume access roles. An access role is created in each account you want analyzed. AWS recommends the managed policy WellArchitectedAgentResourceScanning for it, which grants read-only access to resource metadata and configuration. The user guide states that neither role lets the agent modify your resources. Applying a fix is a separate step that you take yourself, and runbooks can be scheduled in AWS Systems Manager.
Architecture reviews of IaC templates
Architecture recommendations are not generated automatically. You start an architecture review by pointing the agent at IaC files in Amazon S3, and it returns updated templates with its fixes applied. The announcement names Terraform, CDK, and CloudFormation templates. The user guide's page on architecture reviews lists AWS CDK and Terraform projects as supported input.
- A zip archive can be up to 25 MB.
- An Amazon S3 folder can total up to 100 MB, and no single file in it can exceed 1 MB.
- The S3 bucket is expected to be in the same Region as the agent profile.
- Each profile is limited to 5 architecture reviews per day.
Who can use it and what the limits are
The agent is available to customers with an AWS Support plan at the Business+ tier or higher: Business+, Enterprise On-Ramp, Enterprise Support, or Unified Operations. Customers on the Developer and Business tiers have no access. Agent profiles are hosted in US East (N. Virginia), US East (Ohio), or US West (Oregon), and from there the agent can scan resources in all commercial AWS Regions.
Neither the announcement nor the user guide states a separate price for the preview or a date for general availability. The AWS Well-Architected Tool remains available, and AWS says the tool and the agent can be used at the same time.
- Business+ allows 2 profiles and 7 applications per profile.
- Enterprise On-Ramp, Enterprise Support, and Unified Operations allow 10 profiles and 30 applications per profile.
- One profile can analyze up to 100 AWS accounts and hold up to 10 active business goals.
- One generation run produces at most 30 recommendations.
„Neither role grants AWS WA Agent permission to modify your resources.“
Sources
Related

Claude Code mods are not sandboxed, and version 2.1.289 fixes a deny rule they could override
Anthropic introduced mods for Claude Code on October 1, 2026. They are TypeScript functions, shipped inside plugins, that can rewrite prompts, change tool calls, and redraw parts of the interface. The documentation says mods are not sandboxed and run with your permissions, which covers your files, environment variables, and API keys. On Team and Enterprise plans a built-in mod named sec-default loads first and restricts the mods that users install. Versions 2.1.288 and 2.1.289 fix several cases where permission rules did not hold.
Anthropicverified
GitHub Copilot retires four models and makes Balanced its default code review effort
GitHub deprecated four models across all Copilot experiences on October 2, 2026: Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, and Claude Opus 4.7. On the same day it made Copilot code review available through the REST and GraphQL APIs. Balanced is now the default review effort level, a change that took effect on September 28, 2026. According to GitHub's documentation, a Balanced review consumes more AI credits than a Lite one.
GitHub Changelogverified

Apple will add controls to Full Disk Access on macOS, citing risks from AI agents
Apple said on October 2, 2026, that it will add controls to Full Disk Access, the macOS permission that lets an app read nearly everything on a Mac. The company says some developers use the permission in ways that expose files, mail, messages, and browsing history without users fully understanding it. Apple expects the risk to grow as AI agents become more capable and autonomous. The post gives no date, no macOS version, and no description of the new controls.
Appleverified
