April 2, 2026via AWS Machine Learning Blog
Control which domains your AI agents can access
Why it matters
AWS is addressing a critical enterprise security gap by enabling IT teams to control which internet domains their AI agents can access, making AI deployment safer for regulated industries.
Key signals
- AWS Network Firewall integration with AgentCore
- SNI inspection for domain filtering
- Defense-in-depth security approach for AI agents
The hook
Not a pilot. AWS just shipped domain-level security controls for AI agents in production.
In this post, we show you how to configure AWS Network Firewall to restrict AgentCore resources to an allowlist of approved internet domains. This post focuses on domain-level filtering using SNI inspection — the first layer of a defense-in-depth approach.
Relevance score:75/100