<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>AWS Public Sector Blog</title>
	<atom:link href="https://aws.amazon.com/blogs/publicsector/feed/" rel="self" type="application/rss+xml"/>
	<link>https://aws.amazon.com/blogs/publicsector/</link>
	<description>Innovating in the Public Sector</description>
	<lastBuildDate>Wed, 16 Sep 2026 16:11:06 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>A community credit union’s path from VMware outages to cloud resilience</title>
		<link>https://aws.amazon.com/blogs/publicsector/a-community-credit-unions-path-from-vmware-outages-to-cloud-resilience/</link>
		
		<dc:creator><![CDATA[Jason Beard]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 16:11:06 +0000</pubDate>
				<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">40661fad7b662809c4ffa045e16c155b3299b7d1</guid>

					<description>For 70 years, Carter Credit Union has served communities across northwest Louisiana and beyond. What started in 1954 as a small financial cooperative for International Paper company employees in Springhill, Louisiana, has grown into a $770 million institution serving more than 45,000 members across 13 locations.</description>
										<content:encoded>&lt;p&gt;&lt;img class="size-full wp-image-32360 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/12/A-community-credit-unions-path-from-VMware-outages-to-cloud-resilience-1.png" alt="" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;For 70 years, &lt;a href="https://www.cartercu.org/" target="_blank" rel="noopener"&gt;Carter Credit Union&lt;/a&gt; has served communities across northwest Louisiana and beyond. What started in 1954 as a small financial cooperative for International Paper company employees in Springhill, Louisiana, has grown into a $770 million institution serving more than 45,000 members across 13 locations. For many of those members, particularly in rural and underserved areas, Carter represents their primary access point to mainstream financial services, financial education, and the economic stability that comes with belonging to a trusted institution.&lt;/p&gt; 
&lt;p&gt;But behind that growth was an aging technology infrastructure that put member services at risk. In 2022, Carter’s IT team began migrating the credit union’s on-premises VMware environment to &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt;, a move that would reduce costs, strengthen security, and facilitate uninterrupted access for the communities that depend on Carter. What makes the story remarkable is that a three-person team executed the entire migration while maintaining continuous service to members.&lt;/p&gt; 
&lt;h2&gt;The breaking point&lt;/h2&gt; 
&lt;p&gt;Carter’s legacy environment relied on a VMware virtualization stack hosted on physical servers in a single data center, all dependent on one fiber circuit for connectivity. Jason Berard, Carter’s chief information technology officer, saw how vulnerable this architecture was when a construction crew severed the primary fiber line. The backup circuit, which was routed through the same conduit, failed simultaneously. The organization remained completely offline for 24 hours. In a separate incident, a hardware failure caused a multiday outage, leaving critical systems unavailable for 3 consecutive days.&lt;/p&gt; 
&lt;p&gt;“We had a single point of failure in almost every layer of our infrastructure,” Berard said. The credit union had moved some VMware workloads to a colocation facility in Dallas, Texas, but the arrangement still required Carter’s small team to manage physical hardware, maintain VMware licensing, handle firmware updates, and budget for server replacement cycles every 3–5 years. The total cost of ownership continued to climb while the risk of member-facing outages remained unacceptably high.&lt;/p&gt; 
&lt;h2&gt;Choosing AWS&lt;/h2&gt; 
&lt;p&gt;Berard evaluated AWS, Google Cloud, and Microsoft Azure. The determining factor came not from a sales pitch but from a peer recommendation: The president of a credit union service organization (CUSO) shared their positive experience migrating to AWS, and colleagues across the credit union industry confirmed similar results. In a sector built on trust and cooperative values, those endorsements from fellow practitioners carried more weight than any vendor presentation. AWS also offered &lt;a href="https://aws.amazon.com/government-education/nonprofits/credit-union/" target="_blank" rel="noopener"&gt;purpose-built solutions for credit unions&lt;/a&gt;, including infrastructure designed to meet the compliance and security requirements that financial institutions navigate daily.&lt;/p&gt; 
&lt;h2&gt;A phased migration from VMware to AWS with a small team&lt;/h2&gt; 
&lt;p&gt;Carter’s entire migration from its VMware environment to AWS was executed by a team of three, with Berard providing strategic oversight and two infrastructure specialists handling the day-to-day technical work. Rather than attempting a full lift and shift over a single weekend, the team chose a phased strategy that meant they built confidence and validated performance at each step before moving to the next set of workloads.&lt;/p&gt; 
&lt;p&gt;Carter began with a set of servers already approaching required operating system (OS) upgrades. Rather than investing in OS updates on aging hardware and renewing VMware licensing, the team rebuilt those workloads in AWS. As the migration matured, they incorporated &lt;a href="https://aws.amazon.com/application-migration-service/" target="_blank" rel="noopener"&gt;AWS Transform MGN&lt;/a&gt; to streamline the transition of remaining systems.&lt;/p&gt; 
&lt;p&gt;One team member, Randy, had spent his career managing traditional on‑premises data centers. To support the shift in skill requirements, the team completed AWS training focused on cloud server management, auto scaling, and cost optimization. That investment proved effective: Carter successfully executed the migration without hiring external consultants and without disruption to member services throughout the transition.&lt;/p&gt; 
&lt;h2&gt;Expanding access through Interactive Teller Machines&lt;/h2&gt; 
&lt;p&gt;Carter has been rethinking how it delivers financial services to members who might not live near a traditional branch. The credit union has deployed an Interactive Teller Machine (ITM) service called CarterLIVE! as its primary service model across most locations, with only one traditional teller-line branch remaining.&lt;/p&gt; 
&lt;p&gt;These machines connect members to live tellers through two-way video while providing standard ATM functionality, effectively bringing face-to-face financial guidance to communities that might otherwise lack convenient access. As a next step, Carter is migrating its ITM infrastructure to a hybrid cloud model, splitting components between the credit union’s AWS environment and the ITM vendor’s cloud platform. With this collaborative approach, Carter aims to deliver the same redundancy and uptime the rest of its environment now enjoys while further strengthening its ability to serve members in rural and underserved areas.&lt;/p&gt; 
&lt;h2&gt;Measurable results for members and the bottom line&lt;/h2&gt; 
&lt;p&gt;Over a 3-year analysis period, Carter documented meaningful cost savings compared to the hardware replacement cycles, VMware licensing renewals, and maintenance contracts they would have faced on premises. Carter is projected to save more than $70,000 by migrating to AWS rather than refreshing its existing on‑premises server environment. These savings come from avoided hardware replacement costs, eliminated VMware licensing renewals, reduced data center overhead, and the efficiencies gained through the AWS consumption-based model.&lt;/p&gt; 
&lt;p&gt;The savings translate directly into resources Carter can reinvest in member services, financial education programs, and community development initiatives rather than spending them on hardware that depreciates the moment it arrives. In AWS, the credit union pays for the compute and storage it actually uses, scaling resources with member demand rather than overprovisioning for peak capacity.&lt;/p&gt; 
&lt;p&gt;The migration has also delivered a measurable improvement in security posture. Carter now benefits from AWS infrastructure designed to meet the security and compliance standards required by financial regulators, including encryption at rest and in transit, identity and access management controls, and continuous monitoring capabilities that would have been prohibitively expensive to implement on premises.&lt;/p&gt; 
&lt;p&gt;Most importantly for members, Carter hasn’t experienced the kind of extended outages that previously disrupted services. Members can access their accounts, process transactions, apply for loans, and connect with live tellers through CarterLIVE! video banking without interruption whether they bank in Shreveport, Springhill, or anywhere else in the country.&lt;/p&gt; 
&lt;h2&gt;What other credit unions can learn&lt;/h2&gt; 
&lt;p&gt;Carter Credit Union’s migration demonstrates that moving from an on-premises VMware environment to the cloud doesn’t require a large IT department or a massive budget. A small, focused team with the right training and a phased plan can modernize critical financial infrastructure while maintaining service for the members and communities who depend on them.&lt;/p&gt; 
&lt;p&gt;Here are some lessons to keep in mind if you’re considering a similar migration:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Start with what needs upgrading anyway.&lt;/strong&gt; Servers due for OS or hardware refreshes are natural first candidates for cloud migration.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Invest in training before you migrate.&lt;/strong&gt; Cloud fluency changed how Carter’s team approached every subsequent infrastructure decision.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Lean on peers in the credit union community.&lt;/strong&gt; Industry networks and CUSOs can provide honest firsthand feedback no vendor whitepaper can replicate.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Phase the work and protect member service above all else.&lt;/strong&gt; A gradual approach reduces risk and means members don’t bear the consequences of a transition they didn’t ask for.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;To learn more about how AWS supports credit unions, visit the &lt;a href="https://aws.amazon.com/government-education/nonprofits/credit-union/" target="_blank" rel="noopener"&gt;Digital Transformation for Credit Unions&lt;/a&gt; page or explore &lt;a href="https://aws.amazon.com/cloud-migration/" target="_blank" rel="noopener"&gt;cloud migration resources&lt;/a&gt; to plan your own journey.&lt;/p&gt; 
&lt;p&gt;Carter Credit Union is headquartered in Shreveport, Louisiana, and has served its communities since 1954. Learn more at &lt;a href="https://www.cartercu.org/" target="_blank" rel="noopener"&gt;cartercu.org&lt;/a&gt;.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>Develop an AI voice command center with Amazon Quick and Kiro</title>
		<link>https://aws.amazon.com/blogs/publicsector/develop-an-ai-voice-chief-of-staff-with-amazon-quick-and-kiro/</link>
		
		<dc:creator><![CDATA[Courtney Maatta]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 20:08:13 +0000</pubDate>
				<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">782293b1ea36aac085155a712587e34e4a78b2c4</guid>

					<description>This post covers the two prerequisites needed (a desktop assistant and an AI IDE), how they connect through a straightforward file bridge, why this pattern is a good fit for public sector constraints, and what to keep in mind when it comes to cost.</description>
										<content:encoded>&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32425 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/16/Develop-an-AI-voice-command-center-with-Amazon-Quick-and-Kiro.png" alt="Develop an AI voice command center with Amazon Quick and Kiro" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; public sector teams devote a significant portion of each day to administrative work such as compiling cost reports, monitoring security posture, triaging email and chat, and maintaining an accurate calendar. Individually, these tasks are minor. Collectively, they consume time and attention that could be better directed toward mission outcomes and the constituents these organizations serve.&lt;/p&gt; 
&lt;p&gt;With the solution example in this post, you can build a &lt;a href="https://github.com/coumit/chief-of-staff-voice-command-center" target="_blank" rel="noopener"&gt;voice-activated command center&lt;/a&gt; that runs on your local machine, listens when you talk to it, and answers back using a clean, high-tech dashboard. You can learn how to build a command center (you can give it a fun name such as Jarvis or Alfred) that briefs you on finances, security, your calendar, and your inbox. With an AI-powered integrated development environment (IDE) and a desktop productivity assistant, it doesn’t leave your laptop.&lt;/p&gt; 
&lt;p&gt;This post covers the two prerequisites needed (a desktop assistant and an AI IDE), how they connect through a straightforward file bridge, why this pattern is a good fit for public sector constraints, and what to keep in mind when it comes to cost.&lt;/p&gt; 
&lt;p&gt;This is a build-it-yourself, local solution for personal and team productivity. You’ll be using local desktop services including &lt;a href="https://aws.amazon.com/quick/desktop/" target="_blank" rel="noopener"&gt;Amazon Quick for desktop&lt;/a&gt; and &lt;a href="https://kiro.dev/" target="_blank" rel="noopener"&gt;Kiro&lt;/a&gt;.&lt;/p&gt; 
&lt;h2&gt;What you’ll build&lt;/h2&gt; 
&lt;p&gt;The result is a desktop application that gives you:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;A sci-fi-style animated dashboard&lt;/strong&gt; – A heads-up display with a live dial, transcript, and status readouts that react as you speak&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Voice in and out&lt;/strong&gt; – Talk to it and it speaks back to you in a short briefing&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;C-suite advisors you can call by name&lt;/strong&gt;, for example: 
  &lt;ul&gt; 
   &lt;li&gt;&lt;strong&gt;Chief financial officer (CFO)&lt;/strong&gt; – A spending or cost briefing&lt;/li&gt; 
   &lt;li&gt;&lt;strong&gt;Chief security officer (CSO)&lt;/strong&gt; – A security posture review&lt;/li&gt; 
   &lt;li&gt;&lt;strong&gt;UX designer&lt;/strong&gt; – Spins up a new design project using the open source &lt;a href="https://open-design.ai/" target="_blank" rel="noopener noreferrer"&gt;Open Design&lt;/a&gt; toolset&lt;/li&gt; 
   &lt;li&gt;&lt;strong&gt;Daily summary&lt;/strong&gt; – What happened across your work day, plus quick calendar and email checks&lt;/li&gt; 
   &lt;li&gt;&lt;strong&gt;AI developer&lt;/strong&gt; – Drives your local AI IDE to build and refine things for you&lt;/li&gt; 
  &lt;/ul&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Everything runs on your Mac or desktop operating system (OS). There’s no server to set up and data doesn’t leave your machine unless you explicitly wire an integration to do so. For example, you can say “Call my CFO” or “chief financial officer” as the key command to call the agent. The following image is an example of the end result, which is a local voice command center:&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/12/Figure-1-The-local-command-center-dashboard-running-on-your-desktop.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32367 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/12/Figure-1-The-local-command-center-dashboard-running-on-your-desktop.png" alt="A visual of the local voice command center dashboard featuring a sci-fi looking display, running on the desktop" width="1379" height="786"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 1: The local command center dashboard running on your desktop&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;Please note that names in this post are for fun demonstration purposes only. Any names shown, such as Jarvis or Alfred, are used solely as illustrative, user-chosen display names for a personal, local tool. Product names, logos, and brands are the property of their respective owners, and their use here is nominative and for demonstration purposes only. Choose your own name for your assistant and confirm you have the right to use any name or mark you adopt.&lt;/p&gt; 
&lt;h2&gt;How it works: The file bridge&lt;/h2&gt; 
&lt;p&gt;You build the bridge by prompting Amazon Quick for desktop. The command center itself is intentionally lightweight and offline. It doesn’t call a third-party API directly. Instead, it exchanges small JSON files with a desktop assistant through a shared folder called the bridge. Your AI desktop assistant does the work of connecting to email, chat, and reporting sources and writes the answers back for the command center to read aloud.&lt;/p&gt; 
&lt;p&gt;The following diagram shows the end-to-end flow, from your voice command to the spoken briefing:&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/12/Figure-2-AI-desktop-to-voice-command-center-workflow.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32366 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/12/Figure-2-AI-desktop-to-voice-command-center-workflow.png" alt="This image visually demonstrates the voice bridge workflow: 1. The voice bridge watcher agent first gathers your email, cost, and security reports and writes the results. 2. Shared bridge then is setup that the command center will read directly from." width="602" height="335"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 2: AI desktop to voice command center workflow. Major components are Amazon Quick and Kiro. Kiro CLI is depicted&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;The key idea: The desktop assistant creates and fills the &lt;code&gt;responses/&lt;/code&gt; and &lt;code&gt;outputs/&lt;/code&gt; folders; the command center only reads results for Amazon Quick. That clean separation is what keeps the local app lightweight and private.&lt;/p&gt; 
&lt;h2&gt;Prerequisite 1: A desktop assistant to feed the bridge&lt;/h2&gt; 
&lt;p&gt;&lt;a href="PLACEHOLDER_URL_1" target="_blank" rel="noopener noreferrer"&gt;Amazon Quick for desktop&lt;/a&gt; is a productivity assistant available for macOS and Windows that can connect to the services you already use and act on a schedule. This is the engine behind the bridge. The steps in the following section walk you through setup, agent creation, and wiring the bridge.&lt;/p&gt; 
&lt;h3&gt;Before you create agents: Three quick setup tasks&lt;/h3&gt; 
&lt;p&gt;When you install &lt;a href="PLACEHOLDER_URL_1" target="_blank" rel="noopener noreferrer"&gt;Amazon Quick for desktop&lt;/a&gt;, do these three things first so the assistant has good local data to work with and a place to write:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Enable your integrations&lt;/strong&gt; – Turn on the Google Calendar, email, Microsoft Teams, and Slack connections so Amazon Quick has accurate local data to supply the voice app.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Create the bridge folder&lt;/strong&gt; – Make a local folder named &lt;code&gt;CoS-Bridge&lt;/code&gt; in your Documents folder (&lt;code&gt;~/Documents/CoS-Bridge&lt;/code&gt;). This is where the assistant and the command center exchange files.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Grant Amazon Quick access to the folder&lt;/strong&gt; – In Amazon Quick, open the left sidebar, select My Computer inside Quick, and give Amazon Quick access to your &lt;code&gt;CoS-Bridge&lt;/code&gt; folder so it can read requests and write results there.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;h3&gt;Give Amazon Quick these agent prompts&lt;/h3&gt; 
&lt;p&gt;With integrations enabled and the folder in place, create scheduled agents in Amazon Quick using plain-language prompts such as these. (Adapt the specifics to your own sources.)&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;1. Daily Report agent&lt;/strong&gt;&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;Set up a Daily Report agent that runs at 3AM and sends me an email. It should provide me with key activities from my email over the last week, upcoming events, and calendar key activities for the week.&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;&lt;strong&gt;2. CFO Report agent&lt;/strong&gt;&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;Set up a CFO Report that pulls my Amazon Web Services (AWS) cost and billing report data from my email, my Salesforce dashboards, and any reports that are cost- and budget-related.&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;&lt;strong&gt;3. CSO Report agent&lt;/strong&gt;&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;Set up a CSO Report that pulls in &amp;lt;enter your security-related email or source&amp;gt;. (The AWS Security Agent is also a Kiro power that can scan a repository for you and summarize vulnerabilities, which is a useful complement to the CSO briefing.)&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;To wire these into the voice app, you also create a daily Bridge-watcher agent. You can explore the full &lt;a href="https://github.com/coumit/chief-of-staff-voice-command-center/blob/main/docs/quick-setup.md" target="_blank" rel="noopener"&gt;Amazon Quick bridge setup in GitHub&lt;/a&gt;, which includes instructions you can copy and paste as a prompt into the Amazon Quick desktop assistant, including the exact JSON shape it should write.&lt;/p&gt; 
&lt;h2&gt;Prerequisite 2: An AI IDE to build and shape the app&lt;/h2&gt; 
&lt;p&gt;Kiro is an AI-powered IDE, and the Kiro command-line interface (CLI) is its command-line counterpart. Together they mean you can clone the starter project, run it locally, and then refine it in natural language until it looks and behaves the way you want.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Download &lt;a href="https://kiro.dev/downloads" target="_blank" rel="noopener"&gt;Kiro&lt;/a&gt;.&lt;/strong&gt; (You can explore the &lt;a href="https://kiro.dev/docs" target="_blank" rel="noopener"&gt;Kiro Documentation&lt;/a&gt; too.)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Install the Kiro CLI.&lt;/strong&gt; The command center’s AI Developer feature drives it to build things for you, scoped to a project folder. Open Design is a third-party, optional solution that works with Kiro to design and prototype products and is open source. This repository is included for use if you choose to call the UX Designer.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Clone the starter repository and run it:&lt;/strong&gt;&lt;/li&gt; 
&lt;/ol&gt; 
&lt;pre&gt;&lt;code&gt;git clone --recurse-submodules &amp;lt;your-repo-url&amp;gt;
cd chief-of-staff-voice-command-center

npm install

npm start&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;Because the whole thing is a local application, not a cloud deployment, and you own it. Open it in Kiro and ask for changes in plain English. You can rename the assistant, restyle the dashboard, add or remove an advisor, or change what a briefing says. The AI IDE is what turns a starter project into your command center. It runs on macOS and desktop operating systems (Windows and Linux), with a rich voice experience on macOS.&lt;/p&gt; 
&lt;h2&gt;Why a desktop assistant is the right pattern&lt;/h2&gt; 
&lt;p&gt;The reason this approach is valuable for public sector teams is that the desktop assistant can draw on many local connections you already have—for instance, Microsoft Teams, Slack, and email—and turn them into briefings the command center reads aloud. A few examples:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Cost reporting&lt;/strong&gt; – The assistant reads your finance or cost report emails and produces a CFO-style spending briefing.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Security reporting&lt;/strong&gt; – It summarizes security posture and findings into a CSO briefing.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Daily operations&lt;/strong&gt; – It scans your inbox, chat, and calendar and gives you a single morning summary.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Because that work happens through the assistant and lands in the bridge folder, the command center stays small, local, and straightforward to reason about while still benefiting from rich, connected data sources.&lt;/p&gt; 
&lt;h2&gt;Cost and token use disclaimer&lt;/h2&gt; 
&lt;p&gt;This solution is inexpensive to run, but it does have costs, and those costs depend on how you use it. Keep the following in mind:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;AI IDE (tokens)&lt;/strong&gt; – Explore the &lt;a href="https://kiro.dev/pricing/" target="_blank" rel="noopener"&gt;Kiro pricing page&lt;/a&gt;.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Desktop assistant (monthly)&lt;/strong&gt; – Explore the &lt;a href="https://aws.amazon.com/quick/pricing/?refid=77f1fbea-4ad5-4c1d-b16e-e5634ca5086e" target="_blank" rel="noopener"&gt;Amazon Quick pricing page&lt;/a&gt;.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Open Design&lt;/strong&gt; – This is a no-cost open source third-party solution.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;h2&gt;Get started&lt;/h2&gt; 
&lt;p&gt;To build your own AI chief of staff, you can take the following next steps:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;Download &lt;a href="https://aws.amazon.com/quick/desktop/" target="_blank" rel="noopener"&gt;Amazon Quick for desktop&lt;/a&gt; and complete first sign-in.&lt;/li&gt; 
 &lt;li&gt;Download &lt;a href="https://kiro.dev/downloads" target="_blank" rel="noopener"&gt;Kiro &lt;/a&gt;and install the Kiro CLI.&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://github.com/coumit/chief-of-staff-voice-command-center/" target="_blank" rel="noopener"&gt;Clone the starter repository&lt;/a&gt;, run &lt;code&gt;npm start&lt;/code&gt;, and open it in Kiro to make it your own.&lt;/li&gt; 
 &lt;li&gt;Create the voice-bridge-watcher agent in Amazon Quick using the setup instructions included with the project, and point it at the reporting sources you care about starting with a cost or finance report for the CFO.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Give it a name you enjoy saying, then ask it for your first briefing.&lt;/p&gt; 
&lt;h2&gt;Conclusion&lt;/h2&gt; 
&lt;p&gt;Administrative overhead doesn’t have to compete with mission delivery. With a local command center powered by Amazon Quick for desktop and Kiro, your team can turn routine tasks such as cost reporting, security monitoring, and inbox triage into voice-activated briefings that stay on your device.&lt;/p&gt; 
&lt;p&gt;No cloud deployment, no data leaving your machine, and no complex infrastructure to maintain. Clone the repository, set up the bridge, and give your AI chief of staff its first assignment.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>From Amazon RDS Custom for Oracle to what’s next: A technical guide to Oracle migration paths on AWS</title>
		<link>https://aws.amazon.com/blogs/publicsector/from-amazon-rds-custom-for-oracle-to-whats-next-a-technical-guide-to-oracle-migration-paths-on-aws/</link>
		
		<dc:creator><![CDATA[FNU Zubair]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 16:01:44 +0000</pubDate>
				<category><![CDATA[Amazon Elastic Block Store (Amazon EBS)]]></category>
		<category><![CDATA[Amazon EventBridge]]></category>
		<category><![CDATA[Amazon Simple Storage Service (S3)]]></category>
		<category><![CDATA[Amazon VPC]]></category>
		<category><![CDATA[AWS Backup]]></category>
		<category><![CDATA[AWS Identity and Access Management (IAM)]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[AWS Marketplace]]></category>
		<category><![CDATA[AWS Secrets Manager]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">3a32883aab75d8d1ffce811e48b1a51fc33e84d6</guid>

					<description>This post provides a decision framework and technical guidance to help database administrators and architects navigate the transition facing Amazon Web Services (AWS) customers who run workloads on Amazon Relational Database Service (Amazon RDS) Custom for Oracle.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32168 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/19/From-Amazon-RDS-Custom-for-Oracle-to-whats-next-A-technical-guide-to-Oracle-migration-paths-on-AWS.png" alt="From Amazon RDS Custom for Oracle to what’s next: A technical guide to Oracle migration paths on AWS" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;This post provides a decision framework and technical guidance to help database administrators and architects navigate the transition facing &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; customers who run workloads on &lt;a href="https://aws.amazon.com/rds/custom/" target="_blank" rel="noopener"&gt;Amazon Relational Database Service (Amazon RDS) Custom for Oracle&lt;/a&gt;. Following the AWS announcement that it will discontinue RDS Custom for Oracle on March 31, 2027, organizations need a clear, practical roadmap to evaluate and execute migration to the best-suited alternative—&lt;a href="https://aws.amazon.com/rds/oracle/" target="_blank" rel="noopener"&gt;Amazon RDS for Oracle&lt;/a&gt;, Oracle on &lt;a href="http://aws.amazon.com/ec2" target="_blank" rel="noopener"&gt;Amazon Elastic Compute Cloud (Amazon EC2)&lt;/a&gt; or &lt;a href="https://docs.aws.amazon.com/odb/latest/UserGuide/what-is-odb.html" target="_blank" rel="noopener"&gt;Oracle Database@AWS (ODB@AWS)&lt;/a&gt;—based on operational, technical, and business requirements.&lt;/p&gt; 
&lt;p&gt;To get the most out of this guide, readers should be familiar with the following:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Oracle Database administration fundamentals&lt;/li&gt; 
 &lt;li&gt;AWS core services, including Amazon RDS, Amazon EC2, &lt;a href="https://aws.amazon.com/vpc/" target="_blank" rel="noopener"&gt;Amazon Virtual Private Cloud (Amazon VPC)&lt;/a&gt;, &lt;a href="https://aws.amazon.com/iam/?trk=7ad0b48b-3532-4cda-87b0-c63aef99e9cc&amp;amp;sc_channel=ps&amp;amp;ef_id=CjwKCAjwyabTBhBFEiwAM3mNUA4LBlHx-R8Twbp0fzwabRDiFvRBq-Yk0CHgPKrbfPBObPXgVCjHDRoCccAQAvD_BwE&amp;amp;gads_camp=23527793912&amp;amp;gads_ag=187898877250&amp;amp;gads_ad=795794010907&amp;amp;gads_kw=amazon%20iam&amp;amp;gads_matchtype=e&amp;amp;gads_network=g&amp;amp;gads_device=c&amp;amp;gads_geo=9008163&amp;amp;gad_campaignid=23527793912&amp;amp;gbraid=0AAAAADjHtp8RRS-YDGFMWBM466B8hLMIV&amp;amp;gclid=CjwKCAjwyabTBhBFEiwAM3mNUA4LBlHx-R8Twbp0fzwabRDiFvRBq-Yk0CHgPKrbfPBObPXgVCjHDRoCccAQAvD_BwE" target="_blank" rel="noopener"&gt;AWS Identity and Access Management (IAM)&lt;/a&gt;, and &lt;a href="https://aws.amazon.com/systems-manager/" target="_blank" rel="noopener"&gt;AWS Systems Manager&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;Oracle database deployment models on AWS: RDS for Oracle, RDS Custom for Oracle, Amazon EC2 hosted Oracle, and multi-cloud option ODB@AWS&lt;/li&gt; 
 &lt;li&gt;Basic concepts of Oracle licensing, support timelines, and certified platform requirements&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Understanding the change&lt;/h2&gt; 
&lt;p&gt;AWS has announced that RDS Custom for Oracle will reach end of support on March 31, 2027. After this date, customers will no longer be able to access the RDS Custom for Oracle console or resources.&lt;/p&gt; 
&lt;p&gt;Organizations running workloads on RDS Custom for Oracle should assess their environment now. The key questions to answer are:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;What operating system (OS)-level customizations or dependencies exist on the RDS Custom host?&lt;/li&gt; 
 &lt;li&gt;What Oracle version, features, parameters, hidden parameters, or patch levels are in use that aren’t available in standard RDS for Oracle?&lt;/li&gt; 
 &lt;li&gt;What third-party agents or integrations interact with the Oracle OS or file system layer?&lt;/li&gt; 
 &lt;li&gt;What are the high availability and disaster recovery (HA/DR) requirements and current Oracle Data Guard configurations?&lt;/li&gt; 
 &lt;li&gt;What are the licensing arrangements: Bring Your Own License (BYOL), Oracle Unlimited License Agreement (ULA), or License Included (LI)?&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;These answers determine the right migration path. Complex, multi-workload environments should start a phased approach now.&lt;/p&gt; 
&lt;h2&gt;Amazon RDS for Oracle enhancements&lt;/h2&gt; 
&lt;p&gt;RDS for Oracle has gained capabilities that address why customers previously chose RDS Custom for Oracle. The biggest update: maximum storage increased from 64 TiB to 256 TiB, removing the main reason why many customers used RDS Custom for Oracle to hold large databases.&lt;/p&gt; 
&lt;h3&gt;Recent capability improvements&lt;/h3&gt; 
&lt;p&gt;The following improvements make RDS for Oracle a stronger option for workloads that previously required the RDS Custom variant:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Maximum database storage increased from 64 TiB to up to 256 TiB through additional storage volumes (up to three additional volumes per instance).&lt;/li&gt; 
 &lt;li&gt;Cross-Region read replicas with additional storage volumes for disaster recovery at scale.&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/organizations/" target="_blank" rel="noopener"&gt;AWS Organizations&lt;/a&gt; upgrade rollout policy for controlled, staggered automatic minor version upgrades across database fleets.&lt;/li&gt; 
 &lt;li&gt;Oracle Database version support expanded to 26ai. The databases that are currently supported are 19c, 21c, and 26ai Enterprise Edition.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h3&gt;Feature comparison: Amazon RDS for Oracle and Amazon RDS Custom for Oracle&lt;/h3&gt; 
&lt;p&gt;The following table highlights some key capability differences between RDS for Oracle and RDS Custom for Oracle to help teams identify functional gaps and options before migration.&lt;/p&gt; 
&lt;table border="2"&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Capability&lt;/th&gt; 
   &lt;th&gt;Amazon RDS for Oracle&lt;/th&gt; 
   &lt;th&gt;Amazon RDS Custom for Oracle&lt;/th&gt; 
   &lt;th&gt;Alternative for some Amazon RDS Custom functionalities in Amazon RDS for Oracle&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;OS-level access (SSH/RDP)&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓ (SSH + sudo)&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Scheduling cron jobs&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;Internal database jobs: DBMS_SCHEDULER&lt;br&gt; External schedule jobs: AWS Lambda and Amazon EventBridge&lt;br&gt; Complex workflows: AWS Step Functions&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Maximum database size&lt;/td&gt; 
   &lt;td&gt;256 TiB (multi-volume)&lt;/td&gt; 
   &lt;td&gt;64 TiB&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Automated quarterly patching&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;Shared responsibility&lt;/td&gt; 
   &lt;td&gt;AWS managed&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Automatic backups&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;Shared responsibility&lt;/td&gt; 
   &lt;td&gt;AWS managed&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Custom Oracle parameter groups&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Multi-AZ automated failover&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓ (shared responsibility)&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Custom Oracle home patching&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Third-party agent installation on host&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Monitor DB using Oracle Enterprise Manager (OEM)&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;No OEM agent on RDS for Oracle. Options with limited functionalities including Agentless OEM using Amazon EC2 Proxy, OEM DB Express, or Amazon CloudWatch&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;License Included (LI) option&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Bring Your Own License (BYOL)&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;Migration roadmap options&lt;/h2&gt; 
&lt;p&gt;Organizations migrating from RDS Custom for Oracle have three destination options. The best option depends on the workload, OS and business requirements, and target operational model.&lt;/p&gt; 
&lt;p&gt;The following table compares the three platforms against RDS Custom for Oracle as the current state.&lt;/p&gt; 
&lt;table border="2"&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Capability&lt;/th&gt; 
   &lt;th&gt;Amazon RDS for Oracle&lt;/th&gt; 
   &lt;th&gt;Oracle on Amazon EC2&lt;/th&gt; 
   &lt;th&gt;ODB@AWS&lt;/th&gt; 
   &lt;th&gt;Amazon RDS Custom for Oracle (Current)&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;OS-level access&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Max database size&lt;/td&gt; 
   &lt;td&gt;256 TiB&lt;/td&gt; 
   &lt;td&gt;Unlimited*&lt;/td&gt; 
   &lt;td&gt;Exadata scale&lt;/td&gt; 
   &lt;td&gt;64 TiB&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Management overhead&lt;/td&gt; 
   &lt;td&gt;Low (AWS managed)&lt;/td&gt; 
   &lt;td&gt;High (self-managed)&lt;/td&gt; 
   &lt;td&gt;Medium (Oracle managed)&lt;/td&gt; 
   &lt;td&gt;Medium&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Patching control&lt;/td&gt; 
   &lt;td&gt;AWS managed&lt;/td&gt; 
   &lt;td&gt;Customer controlled&lt;/td&gt; 
   &lt;td&gt;Oracle managed&lt;/td&gt; 
   &lt;td&gt;Customer controlled&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Licensing (BYOL)&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;License Included (LI)&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Multi-AZ failover (automated)&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;Manual&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓ (Shared)&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Oracle Real Application Clusters (RAC) support&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Exadata hardware&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Full SYSDBA access&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;AWS managed automated backups&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Cost model&lt;/td&gt; 
   &lt;td&gt;Per instance-hour&lt;/td&gt; 
   &lt;td&gt;Per instance-hour&lt;/td&gt; 
   &lt;td&gt;Subscription&lt;/td&gt; 
   &lt;td&gt;Per instance-hour&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;Path 1: Migrate to Amazon RDS for Oracle&lt;/h2&gt; 
&lt;p&gt;RDS for Oracle is the recommended path for managed workloads without OS-level or advanced Oracle infrastructure dependencies. If you chose RDS Custom for Oracle mainly for storage capacity (the old 64 TiB limit), that constraint is gone: RDS for Oracle now supports up to 256 TiB.&lt;/p&gt; 
&lt;p&gt;RDS for Oracle delivers a comprehensive set of AWS managed capabilities: automated Multi-AZ failover, &lt;a href="https://aws.amazon.com/backup/" target="_blank" rel="noopener"&gt;AWS Backup&lt;/a&gt; integration, &lt;a href="http://aws.amazon.com/cloudwatch" target="_blank" rel="noopener"&gt;Amazon CloudWatch&lt;/a&gt; metrics, IAM based authentication, automated patching, and version upgrades. This path trades operational flexibility for lower management overhead and higher reliability through AWS automation.&lt;/p&gt; 
&lt;h2&gt;Path 2: Migrate to Oracle on Amazon EC2&lt;/h2&gt; 
&lt;p&gt;Oracle on Amazon EC2 is a strong fit for workloads with OS-level dependencies that can’t be abstracted away: custom batch schedulers, third-party agents, direct file system access, SYSDBA/SYSASM operations beyond the Amazon RDS API surface, or Oracle patches not yet certified on Amazon RDS. Amazon EC2 gives the customer a fully self-managed Oracle environment with control over each layer of the stack.&lt;/p&gt; 
&lt;p&gt;The trade-off is operational complexity: OS patching, Oracle home maintenance, Oracle Recovery Manager (RMAN) backup management, Oracle Data Guard configuration, and instance lifecycle management become customer responsibilities. Teams on this path should invest in Systems Manager for automation, AWS Backup for Oracle RMAN integration, and CloudWatch custom metrics for observability.&lt;/p&gt; 
&lt;h2&gt;Path 3: Oracle Database@AWS&lt;/h2&gt; 
&lt;p&gt;ODB@AWS is jointly operated by Oracle and AWS, delivering Exadata hardware co-located in AWS data centers with direct, low-latency connectivity to AWS services. It targets organizations that need Exadata-class performance, Oracle RAC, full Oracle infrastructure feature access (Advanced Queuing, Oracle Streams, Oracle Text, Spatial), and continuity of existing Oracle Support agreements and ULAs.&lt;/p&gt; 
&lt;p&gt;This path suits large-scale Oracle E-Business Suite, PeopleSoft, and Oracle Applications customers who want to consolidate on AWS while keeping RAC and the full Oracle software stack and support model. It offers unified billing through&lt;a href="https://aws.amazon.com/marketplace" target="_blank" rel="noopener"&gt; AWS Marketplace&lt;/a&gt;, flexible and Oracle Subscription licensing, and network integration with AWS services through the ODB network.&lt;/p&gt; 
&lt;h2&gt;Use cases and migration approaches&lt;/h2&gt; 
&lt;p&gt;The following three use cases represent the most common RDS Custom for Oracle deployment patterns. Each maps to a recommended migration path based on the workload’s technical requirements.&lt;/p&gt; 
&lt;h3&gt;Use case 1: Oracle E-Business Suite to ODB@AWS&lt;/h3&gt; 
&lt;p&gt;In this scenario, a customer runs Oracle E-Business Suite (EBS) 12.2 with Advanced Queuing, Oracle Text, custom PL/SQL jobs, and Oracle Workflow on Exadata, using RAC, Smart Scan, Smart Flash Cache, and dedicated infrastructure to meet performance and security requirements. An active Oracle ULA covers the deployment. A second phase upgrades the database to Oracle 26ai, certified with EBS 12.2 on ODB@AWS.&lt;/p&gt; 
&lt;p&gt;ODB@AWS is a good fit for the following reasons:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Oracle EBS 12.2 is certified on ODB@AWS ExaDB-D with Oracle Database 19c—the application tier on Amazon EC2—with full support for Oracle-specific features, including DBMS_SCHEDULER, Advanced Queuing, Oracle Text, and Oracle Spatial.&lt;/li&gt; 
 &lt;li&gt;Exadata infrastructure co-located in AWS data centers delivers Smart Scan, Smart Flash Cache, and low-latency connectivity to AWS services. This meets transaction-heavy Oracle EBS financial module performance requirements without cross-data center latency.&lt;/li&gt; 
 &lt;li&gt;Preserves existing licensing and support agreements; SYSDBA access enables EBS patching on Oracle’s certification schedule, not the AWS managed patch timeline.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The migration approach consists of the following key phases:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Assessment&lt;/strong&gt; – Capture Automatic Workload Repository (AWR) baselines across Oracle EBS peak windows to right-size the ODB@AWS Exadata VM cluster. Run Oracle EBS Technology Codelevel Checker (ETCC) on the source to find and resolve mandatory patches before migration. Document custom database parameters, Oracle Home patches, and OS agents. Design ODB network CIDR ranges upfront. Initiate Oracle account and Oracle Cloud Infrastructure (OCI) tenancy setup.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Non-production migration&lt;/strong&gt; – Provision and peer ODB@AWS to the existing Amazon VPC. Run Oracle EBS pre-clone scripts on source DB and application tiers, then RMAN-duplicate to the ODB@AWS target. Execute post-clone steps, rerun AutoConfig on the Amazon EC2 application tier, start concurrent managers, and re-validate ETCC compliance. Benchmark top concurrent programs and complete full UAT testing before the production migration phase.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Production migration&lt;/strong&gt; – Use Oracle Data Guard to continuously synchronize the database from the source RDS Custom (primary) to ODB@AWS (standby). When the apply lag is stable, switch over from primary to standby on ODB@AWS. This yields near-zero downtime (minutes). Rerun AutoConfig on Amazon EC2 application tier nodes, restart Oracle EBS services, and confirm end-to-end validation.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For organizations needing parallel-run validation or phased cutover, Oracle GoldenGate provides bidirectional replication between source and target.&lt;/p&gt; 
&lt;h3&gt;Use case 2: PeopleSoft HCM/Financials to Oracle on Amazon EC2&lt;/h3&gt; 
&lt;p&gt;In this scenario, a customer runs PeopleSoft Human Capital Management and Financials on RDS Custom for Oracle. PeopleSoft HCM requires OS-level cron scheduling, third-party job schedulers, and specific Oracle patch sets for PeopleSoft’s certified platform matrix that RDS for Oracle does not yet support. For PeopleSoft environments that don’t need Oracle RAC or Exadata performance features, Oracle on Amazon EC2 is a good option—it’s flexible and lower cost than ODB@AWS. The database, application, and Process Scheduler tiers all run on Amazon EC2, preserving full OS access, RMAN control, and PeopleTools operational continuity.&lt;/p&gt; 
&lt;p&gt;Oracle on Amazon EC2 is a good fit for the following reasons:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;PeopleSoft’s Process Scheduler and SQR reporting engine require OS-level integration, file system access, and the ability to spawn processes.&lt;/li&gt; 
 &lt;li&gt;Batch processing uses shell scripts that must run on the OS alongside the Oracle database.&lt;/li&gt; 
 &lt;li&gt;Oracle on Amazon EC2 gives full control over Oracle Home, patch level, and database parameters. PeopleSoft’s certified platforms matrix requires specific Oracle Database patches. Third-party tools and agents install directly alongside the Oracle database on the EC2 instance.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The migration approach consists of the following key phases:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Assessment&lt;/strong&gt; – Capture AWR baselines to right-size the target EC2 instance and &lt;a href="http://aws.amazon.com/ebs" target="_blank" rel="noopener"&gt;Amazon Elastic Block Store (Amazon EBS)&lt;/a&gt; storage. Confirm Oracle PeopleSoft PeopleTools compatibility with Oracle Database 19c. Document custom database parameters, Oracle Home patches, OS agents, and Process Scheduler configuration files from the RDS Custom host. Validate Integration Broker node configuration, external system endpoints, and RMAN backup/recovery procedures to &lt;a href="http://aws.amazon.com/s3" target="_blank" rel="noopener"&gt;Amazon Simple Storage Service (Amazon S3)&lt;/a&gt; on the source environment.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Non-production validation&lt;/strong&gt; – Provision a target EC2 DB instance running Oracle 19c, matched to the source Oracle Home and patch level. Perform RMAN backup-based duplication from RDS Custom to Amazon EC2 using Amazon S3. Run post-clone steps on all application tier nodes to point to the new EC2 DB instance, reconfigure Process Scheduler domains, and re-register Integration Broker nodes. Complete end-to-end UAT testing and benchmark against the AWR baseline.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Production migration&lt;/strong&gt; – Establish Oracle Data Guard between RDS Custom (primary) and Amazon EC2 (standby) for continuous redo log synchronization ahead of cutover. When the primary and standby are synchronized, an Oracle Data Guard switchover promotes Amazon EC2 to primary in near-zero downtime (minutes). Update all PeopleSoft application tier nodes with new DB instance connection strings, restart services, and confirm end-to-end validation before the maintenance window closes.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h3&gt;Use case 3: Oracle DB with Oracle APEX to Amazon RDS for Oracle&lt;/h3&gt; 
&lt;p&gt;In this scenario, a customer running Oracle APEX on Oracle Database 19c on RDS Custom re-platforms to RDS for Oracle. For APEX workloads with no dependency on OS-level access, SYSDBA, RAC, or custom Oracle Home patches, RDS for Oracle is the ideal migration target—it supports APEX through managed Option Groups, removes operational overhead, and is an AWS managed Oracle service with an active support roadmap. This migration moves the customer to a fully managed service with few application changes.&lt;/p&gt; 
&lt;p&gt;RDS for Oracle is a good fit for the following reasons:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;AWS managed automated backups, patching, Multi-AZ HA, and &lt;a href="https://docs.google.com/document/d/1_8y6HHkB76zlstqzo8vOFfehEKEacesVr2iAj6VrKGY/edit?usp=sharing" target="_blank" rel="noopener"&gt;Amazon RDS Performance Insights&lt;/a&gt; avoid DBA intervention for routine lifecycle tasks.&lt;/li&gt; 
 &lt;li&gt;Oracle APEX is supported through AWS Option Groups (APEX and APEX-DEV). It is deployable as a runtime or full development environment with the listener hosted on a separate EC2 instance.&lt;/li&gt; 
 &lt;li&gt;Custom initialization parameters are managed through RDS parameter groups—the team reviews hidden parameters during assessment and any gaps flagged before migration.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The migration approach consists of the following key phases:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Assessment&lt;/strong&gt; – Document the source RDS Custom APEX environment: APEX version, workspace list, application export inventory, ORDS version and configuration, custom database parameters, OS-level backup scripts, and any custom APEX_version account configurations. Take APEX application exports for all workspaces and applications using the APEX Export utility as a pre-migration safety net. Design and validate AWS Backup.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Non-production migration&lt;/strong&gt; – Provision a new RDS for Oracle 19c instance with APEX and APEX-DEV Option Groups: AWS installs APEX automatically, removing the manual SYSDBA-driven process used on RDS Custom. Migrate APEX application schemas and workspace data using Oracle Data Pump export/import, reconfigure ORDS on the EC2 instance to point to the new RDS endpoint, and run &lt;code&gt;rdsadmin.rdsadmin_run_apex_rest_config&lt;/code&gt; to configure RESTful services. Validate all APEX applications end-to-end and confirm AWS Backup, &lt;a href="http://aws.amazon.com/lambda" target="_blank" rel="noopener"&gt;AWS Lambda&lt;/a&gt;, and &lt;a href="https://aws.amazon.com/eventbridge/" target="_blank" rel="noopener"&gt;Amazon EventBridge&lt;/a&gt; schedules with a successful backup and test restore.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Production migration&lt;/strong&gt; – During the maintenance window, set APEX applications to unavailable, take a final Oracle Data Pump export from RDS Custom, import it into the production RDS for Oracle instance, and reconfigure ORDS to the new endpoint. Enable Multi-AZ for automated HA, set APEX applications back to available, and confirm end-to-end validation across all workspaces before the window closes.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Migration approach and tools&lt;/h2&gt; 
&lt;p&gt;The primary decision in choosing your migration approach is between physical and logical migration. Each has distinct trade-offs in downtime, complexity, and suitability by target platform:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Oracle Data Guard&lt;/strong&gt; – Maintains a synchronized physical standby on the target Amazon EC2 or ODB@AWS platform during migration. When ready, a planned switchover completes in minutes with near-zero data loss and no extended downtime.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Oracle GoldenGate&lt;/strong&gt; – Continuously captures and applies redo log changes between source and target, letting both systems run at the same time for heterogeneous migrations, cross-version upgrades, or extended parallel validation.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Oracle Data Pump (expdp/impdp)&lt;/strong&gt; – Exports full or partial schemas to a dump file set—stored on Amazon S3 or transferred directly to the target. This option is suitable for smaller databases or non-production environments where a maintenance window is acceptable.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;AWS DMS&lt;/strong&gt; – &lt;a href="https://aws.amazon.com/dms/" target="_blank" rel="noopener"&gt;AWS Database Migration Service (AWS DMS)&lt;/a&gt; supports Oracle as both source and target. Its change data capture (CDC) engine replicates changes continuously with low latency. It’s suitable for migrations to RDS for Oracle that need schema transformation or an extended replication window.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The following table compares physical and logical migration options.&lt;/p&gt; 
&lt;table border="2"&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Dimension&lt;/th&gt; 
   &lt;th&gt;Physical migration&lt;/th&gt; 
   &lt;th&gt;Logical migration&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Methods&lt;/td&gt; 
   &lt;td&gt;RMAN, Oracle Data Guard&lt;/td&gt; 
   &lt;td&gt;Oracle Data Pump, AWS DMS, Oracle GoldenGate&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Data fidelity&lt;/td&gt; 
   &lt;td&gt;Block-level exact copy&lt;/td&gt; 
   &lt;td&gt;Object-level (schema + rows)&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Downtime&lt;/td&gt; 
   &lt;td&gt;RMAN: Depends on the DB size&lt;br&gt; Oracle Data Guard Switchover: Minutes&lt;/td&gt; 
   &lt;td&gt;Oracle Data Pump: Hours to days&lt;br&gt; AWS DMS: Varies&lt;br&gt; Oracle GoldenGate: Minutes (CDC)&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Schema changes allowed&lt;/td&gt; 
   &lt;td&gt;✗&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Cross-version migration&lt;/td&gt; 
   &lt;td&gt;Limited&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Cross-platform migration&lt;/td&gt; 
   &lt;td&gt;With XTTS&lt;/td&gt; 
   &lt;td&gt;✓&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Best for&lt;/td&gt; 
   &lt;td&gt;Same-version, Amazon EC2 and ODB@AWS targets&lt;/td&gt; 
   &lt;td&gt;RDS for Oracle target, schema evolution scenarios&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Validation complexity&lt;/td&gt; 
   &lt;td&gt;Lower (bit-exact)&lt;/td&gt; 
   &lt;td&gt;Higher (row counts, checksums, application testing)&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;Conclusion&lt;/h2&gt; 
&lt;p&gt;The March 31, 2027, end of support for RDS Custom for Oracle gives Oracle database teams on AWS a defined window to right-size their deployment model—reducing operational overhead, optimizing costs, and improving availability with modern AWS tooling.&lt;/p&gt; 
&lt;p&gt;The guiding principle is workload-driven platform selection: workloads without OS-level dependencies belong on RDS for Oracle, which now supports up to 256 TiB with extensive AWS automation integration; workloads with genuine OS requirements belong on Amazon EC2; and Oracle Applications or Exadata-dependent workloads belong on ODB@AWS.&lt;/p&gt; 
&lt;p&gt;To begin planning your migration, review the &lt;a href="PLACEHOLDER_URL" target="_blank" rel="noopener noreferrer"&gt;A&lt;/a&gt;&lt;a href="https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_Oracle.html" target="_blank" rel="noopener"&gt;mazon RDS for Oracle User Guide&lt;/a&gt;, explore the &lt;a href="https://docs.aws.amazon.com/odb/latest/UserGuide/" target="_blank" rel="noopener"&gt;Oracle Database@AWS User Guide&lt;/a&gt;, and connect with your AWS account team to discuss your specific requirements.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>How Common Crawl and AWS Open Data built the foundation for the AI revolution</title>
		<link>https://aws.amazon.com/blogs/publicsector/how-common-crawl-and-aws-open-data-built-the-foundation-for-the-ai-revolution/</link>
		
		<dc:creator><![CDATA[Rich Skrenta]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 18:37:33 +0000</pubDate>
				<category><![CDATA[Amazon Athena]]></category>
		<category><![CDATA[Amazon CloudFront]]></category>
		<category><![CDATA[Amazon EMR]]></category>
		<category><![CDATA[Amazon SageMaker]]></category>
		<category><![CDATA[Amazon Simple Storage Service (S3)]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[open data]]></category>
		<guid isPermaLink="false">7da594333c4aa92fb7ec5f8fc69d70f8683c9e21</guid>

					<description>The Amazon Web Services (AWS) Open Data Sponsorship Program has hosted the Common Crawl open repository of web data at no cost since January 2012. It has become one of the most important sources of training data for the large language models (LLMs) reshaping industries. This is the story of a 14-year collaboration between a small nonprofit and AWS, and how open data infrastructure became the foundation of the AI era.</description>
										<content:encoded>&lt;p&gt;When Gil Elbaz founded Common Crawl in 2007, his goal was to make web-scale crawl data available to researchers and organizations that lacked the resources to operate their own crawling infrastructure. Nearly two decades later, that mission has had impacts far beyond what anyone anticipated.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; &lt;a href="https://aws.amazon.com/opendata/open-data-sponsorship-program/" target="_blank" rel="noopener"&gt;Open Data Sponsorship Program&lt;/a&gt; has hosted the Common Crawl open repository of web data at no cost since January 2012. It has become one of the most important sources of training data for the large language models (LLMs) reshaping industries.&lt;/p&gt; 
&lt;p&gt;A &lt;a href="https://www.mozillafoundation.org/en/research/library/generative-ai-training-data/common-crawl/" target="_blank" rel="noopener"&gt;2024 Mozilla Foundation study&lt;/a&gt; found that 64 percent of 47 major LLMs published between 2019–2023 used filtered versions of Common Crawl data for training. The dataset has been cited in over &lt;a href="https://commoncrawl.org/research-papers" target="_blank" rel="noopener"&gt;13,000&lt;/a&gt; research papers.&lt;/p&gt; 
&lt;p&gt;This is the story of a 14-year collaboration between a small nonprofit and AWS, and how open data infrastructure became the foundation of the AI era.&lt;/p&gt; 
&lt;h2&gt;From 5 billion to 300 billion pages at petabyte scale&lt;/h2&gt; 
&lt;p&gt;Common Crawl began collecting data in 2008 using a custom Hadoop-based crawler with a PageRank implementation. In January 2012, the organization joined the AWS Public Data Sets program—now the AWS Open Data Sponsorship Program—making its corpus of 5 billion web pages available at no cost on &lt;a href="https://aws.amazon.com/s3/" target="_blank" rel="noopener"&gt;Amazon Simple Storage Service (Amazon S3)&lt;/a&gt;. This meant Common Crawl could focus its limited nonprofit resources on crawling and data quality.&lt;/p&gt; 
&lt;p&gt;As Common Crawl noted at the time, “Demonstrating their commitment to an open web, AWS hosts public data sets at no charge for the community. Placing our data in the public data sets program not only benefits the larger community, but it also saves us money.”&lt;/p&gt; 
&lt;p&gt;In 2013, Common Crawl replaced its custom crawler with &lt;a href="https://commoncrawl.org/ccbot" target="_blank" rel="noopener"&gt;CCBot&lt;/a&gt;, a system based on the Apache Software Foundation’s Nutch web crawler, and adopted the Web ARChive (WARC) format (ISO 28500) as its standard distribution format. In March 2022, Common Crawl celebrated the 10-year anniversary of being a part of AWS Open Data Sponsorship Program and introduced &lt;a href="https://aws.amazon.com/cloudfront/" target="_blank" rel="noopener"&gt;Amazon CloudFront&lt;/a&gt; as a new distribution channel alongside Amazon S3, giving users faster access to the data.&lt;/p&gt; 
&lt;p&gt;Today, the Common Crawl archive contains more than 300 billion web pages, with monthly crawls capturing between 2.3–2.7 billion pages as of this writing.&lt;/p&gt; 
&lt;h2&gt;The LLM inflection point&lt;/h2&gt; 
&lt;p&gt;The release of the OpenAI GPT-3 model in 2020 drew global attention to the role Common Crawl plays in AI development. The GPT-3 paper reported that approximately 82 percent of its raw pre-training tokens were derived from filtered Common Crawl data, the beginning of an industry-wide pattern.&lt;/p&gt; 
&lt;p&gt;Common Crawl data has been used to train frontier models including GPT-3 (OpenAI, 2020), the BigScience Large Open-science Open-access Multilingual Language Model (BLOOM, 2022), the Meta Llama series, Google Gemini, and Falcon LLM (Technology Innovation Institute, 2023). More recently, Hugging Face FineWeb datasets, NVIDIA Nemotron-CC (6.3 trillion tokens), and Google MADLAD-400 (419 languages) have applied increasingly sophisticated filtering to Common Crawl snapshots.&lt;/p&gt; 
&lt;h2&gt;Scaling infrastructure to meet AI demand&lt;/h2&gt; 
&lt;p&gt;The explosion of AI training workloads placed extraordinary demands on the underlying infrastructure of Common Crawl. By late 2023, downloads had doubled every 6 months for several years, and aggressive downloaders began causing performance disruptions. AWS worked directly with Common Crawl to deploy rate limiting in November 2023, restoring reliable access for the broader community.&lt;/p&gt; 
&lt;p&gt;Today, the infrastructure spans Amazon S3 as the canonical distribution point, Amazon CloudFront for faster global access, &lt;a href="https://aws.amazon.com/athena/" target="_blank" rel="noopener"&gt;Amazon Athena&lt;/a&gt; for querying the index without downloading raw data, and &lt;a href="https://aws.amazon.com/emr/" target="_blank" rel="noopener"&gt;Amazon EMR&lt;/a&gt;, &lt;a href="https://aws.amazon.com/lambda/" target="_blank" rel="noopener"&gt;AWS Lambda&lt;/a&gt;, and &lt;a href="https://aws.amazon.com/sagemaker/" target="_blank" rel="noopener"&gt;Amazon SageMaker&lt;/a&gt; for large-scale processing and model fine-tuning. In April 2026, Common Crawl began experimentally distributing data through Hugging Face, although Amazon S3 remains the primary source.&lt;/p&gt; 
&lt;p&gt;This infrastructure means that a graduate student at a university in Nairobi, a two-person startup in São Paulo, and a research lab in Bangalore can access the same foundational data powering frontier AI systems at no cost.&lt;/p&gt; 
&lt;h2&gt;What this means for AWS customers&lt;/h2&gt; 
&lt;p&gt;The value Common Crawl delivers to the AWS environment extends well beyond the dataset itself.&lt;/p&gt; 
&lt;h3&gt;For builders&lt;/h3&gt; 
&lt;p&gt;If you’re training or fine-tuning language models, you can access pre-training data at scale without building crawling infrastructure, using the derived datasets such as Colossal Clean Crawled Corpus (C4), FineWeb, RefinedWeb, OSCAR, and Nemotron-CC. The &lt;a href="https://registry.opendata.aws/commoncrawl/" target="_blank" rel="noopener"&gt;Registry of Open Data on AWS lists Common Crawl&lt;/a&gt; with tutorials and usage examples that can help you query and process the data without downloading petabyte-scale archives.&lt;/p&gt; 
&lt;h3&gt;For researchers&lt;/h3&gt; 
&lt;p&gt;Over &lt;a href="https://huggingface.co/spaces/commoncrawl/cc-citations" target="_blank" rel="noopener"&gt;13,000&lt;/a&gt; published papers have used Common Crawl data across computational linguistics, information retrieval, machine translation, web science, digital preservation, cybersecurity, longitudinal web analytics, phishing detection, health misinformation retrieval, and studies of geolinguistic representation in text data and social science.&lt;/p&gt; 
&lt;p&gt;You can build on this foundation the same way Stanford’s 2014 Global Vectors for Word Representation (&lt;a href="https://nlp.stanford.edu/projects/glove/" target="_blank" rel="noopener"&gt;GloVe&lt;/a&gt;) word embedding model and Facebook AI Research’s &lt;a href="https://research.facebook.com/blog/2016/8/fasttext/" target="_blank" rel="noopener"&gt;fastText&lt;/a&gt; did: both trained word vectors on Common Crawl data covering up to 157 languages.&lt;/p&gt; 
&lt;h3&gt;For organizations&lt;/h3&gt; 
&lt;p&gt;If you’re building search, recommendation, translation, or knowledge extraction systems, you can prototype and validate approaches using Common Crawl before building your own data pipelines.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://commoncrawl.org/web-graphs" target="_blank" rel="noopener"&gt;Web Graphs&lt;/a&gt; give you structural web intelligence, 279.4 million host-level nodes and 13.4 billion edges, plus 122.3 million domain-level nodes and 6.1 billion edges as of the January 2026 release, which are unavailable from other open sources.&lt;/p&gt; 
&lt;h3&gt;For the multilingual AI community&lt;/h3&gt; 
&lt;p&gt;If you’re working to address the overrepresentation of English in AI training data, the Common Crawl &lt;a href="https://github.com/commoncrawl/web-languages/" target="_blank" rel="noopener"&gt;Web Languages Project&lt;/a&gt;, which was launched December 2024, and the &lt;a href="https://commonlid.org/" target="_blank" rel="noopener"&gt;CommonLID &lt;/a&gt;(Language Identification) benchmark, released early 2026 and covering 109 languages with &lt;a href="https://mlcommons.org/" target="_blank" rel="noopener"&gt;MLCommons&lt;/a&gt;, &lt;a href="https://www.eleuther.ai/" target="_blank" rel="noopener"&gt;EleutherAI&lt;/a&gt;, and &lt;a href="https://www.jhu.edu/" target="_blank" rel="noopener"&gt;Johns Hopkins University&lt;/a&gt;, provide critical resources.&lt;/p&gt; 
&lt;p&gt;The CommonLID benchmark was created through community annotation, with native speakers annotating over 350,000 lines of web text. Additionally, the High-Performance Language Technologies (HPLT) project uses Common Crawl data to build a 30-trillion-token multilingual dataset spanning 198 languages, further expanding multilingual AI capabilities beyond English.&lt;/p&gt; 
&lt;h2&gt;Looking ahead&lt;/h2&gt; 
&lt;p&gt;As AI models become more capable and more multilingual, demand for high-quality open training data continues to grow. The AWS Open Data Sponsorship Program helps this foundational resource remain available to everyone, from individual researchers to the world’s largest AI laboratories.&lt;/p&gt; 
&lt;p&gt;As Rich Skrenta, executive director of the Common Crawl Foundation, puts it: “Common Crawl would not exist without Amazon’s support for open data. We are grateful for our partnership and look forward to serving the AI ecosystem together.” Open data isn’t a side project. It’s infrastructure. And infrastructure, when done right, compounds.&lt;/p&gt; 
&lt;h2&gt;Accessing Common Crawl on AWS&lt;/h2&gt; 
&lt;p&gt;You can access Common Crawl data from the us-east-1 AWS Region at no cost in three formats: WARC (raw crawl data), WAT (metadata and link graphs), and WET (extracted plaintext). Monthly releases include index files in columnar format for querying with Amazon Athena.&lt;/p&gt; 
&lt;p&gt;For detailed format documentation and access instructions, visit the &lt;a href="https://registry.opendata.aws/commoncrawl" target="_blank" rel="noopener"&gt;Common Crawl page on the Registry of Open Data on AWS&lt;/a&gt;, or visit the &lt;a href="https://commoncrawl.org/get-started" target="_blank" rel="noopener"&gt;Common Crawl getting started page&lt;/a&gt; for different access methods.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>Building supply chain multi-agent workloads in AWS GovCloud (US)</title>
		<link>https://aws.amazon.com/blogs/publicsector/building-supply-chain-multi-agent-workloads-in-aws-govcloud-us/</link>
		
		<dc:creator><![CDATA[Francisco Zabala]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 18:25:58 +0000</pubDate>
				<category><![CDATA[Amazon Athena]]></category>
		<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[Amazon Bedrock Guardrails]]></category>
		<category><![CDATA[Amazon Cognito]]></category>
		<category><![CDATA[Amazon DynamoDB]]></category>
		<category><![CDATA[Amazon SageMaker AI]]></category>
		<category><![CDATA[Amazon Simple Queue Service (SQS)]]></category>
		<category><![CDATA[Amazon Simple Storage Service (S3)]]></category>
		<category><![CDATA[AWS Batch]]></category>
		<category><![CDATA[AWS Certificate Manager]]></category>
		<category><![CDATA[AWS GovCloud (US)]]></category>
		<category><![CDATA[AWS Identity and Access Management (IAM)]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">c1f75d66c914c6fe8b9295185924b2c213bc6e1a</guid>

					<description>This post shows how to build that on Amazon Web Services (AWS) using Amazon Bedrock, deployed in AWS GovCloud (US). You’ll deploy a working multi-agent workload, see how a supervisor coordinates specialized agents through the Converse API in Amazon Bedrock, and learn which AWS GovCloud (US) details break patterns copied from commercial Regions.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32286 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/03/Building-supply-chain-multi-agent-workloads-in-AWS-GovCloud-US.png" alt="Building supply chain multi-agent workloads in AWS GovCloud (US)" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;If you support a public sector supply chain, a shortage is a mission problem before it’s a cost problem. Your inventory position sits in a system of record. The signals that predict a shortfall don’t: a supplier advisory here, a port closure there, lead time that keeps slipping. Analysts reconcile all of it by hand, one item at a time. They usually find out too late.&lt;/p&gt; 
&lt;p&gt;Agents can carry out that reconciliation and hand back a ranked short list with the reasoning attached, and they never place an order without your approval.&lt;/p&gt; 
&lt;p&gt;This post shows how to build that on &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; using &lt;a href="https://aws.amazon.com/bedrock/" target="_blank" rel="noopener"&gt;Amazon Bedrock&lt;/a&gt;, deployed in &lt;a href="https://aws.amazon.com/govcloud-us/" target="_blank" rel="noopener"&gt;AWS GovCloud (US)&lt;/a&gt;. You’ll deploy a working multi-agent workload, see how a supervisor coordinates specialized agents through the Converse API in Amazon Bedrock, and learn which AWS GovCloud (US) details break patterns copied from commercial Regions.&lt;/p&gt; 
&lt;h2&gt;What you build&lt;/h2&gt; 
&lt;p&gt;By following the steps in this post, you’ll build a read-only console that ranks items by readiness risk, backed by three agents on Amazon Bedrock.&lt;/p&gt; 
&lt;p&gt;This complements a system of record rather than replacing it. Enterprise resource planning (ERP) and inventory suites already compute reorder points well. What they don’t do is pull in outside signals and tell you which items deserve attention first. That is the gap the agents fill.&lt;/p&gt; 
&lt;p&gt;The workflow carries inventory and disruption data through ingestion, processing, and analysis, and stops for an analyst before anything is ordered. The following steps describe each stage in turn.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;Inventory data and external disruption signals land in an &lt;a href="https://aws.amazon.com/s3/" target="_blank" rel="noopener"&gt;Amazon Simple Storage Service (Amazon S3)&lt;/a&gt; raw zone.&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/sqs/" target="_blank" rel="noopener"&gt;Amazon Simple Queue Service (Amazon SQS)&lt;/a&gt; decouples sources from processing. Extract, transform, and load (ETL) jobs on &lt;a href="https://aws.amazon.com/lambda/" target="_blank" rel="noopener"&gt;AWS Lambda&lt;/a&gt; or &lt;a href="https://aws.amazon.com/batch/" target="_blank" rel="noopener"&gt;AWS Batch&lt;/a&gt; normalize records into a curated dataset.&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/athena/" target="_blank" rel="noopener"&gt;Amazon Athena&lt;/a&gt; exposes that dataset as the read-only query surface for the agents.&lt;/li&gt; 
 &lt;li&gt;A supervisor orchestrates the workflow. It calls Amazon Bedrock through an AWS GovCloud (US) inference profile, bounded by &lt;a href="https://aws.amazon.com/bedrock/guardrails/" target="_blank" rel="noopener"&gt;Amazon Bedrock Guardrails.&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;Three specialized agents run under it. The ETL agent fetches and validates the demand series. The analytics agent forecasts demand and scores risk. The visualization agent builds the ranked queue, drafts a brief, and proposes an action. &lt;a href="https://aws.amazon.com/dynamodb/" target="_blank" rel="noopener"&gt;Amazon DynamoDB&lt;/a&gt; holds agent state.&lt;/li&gt; 
 &lt;li&gt;An &lt;a href="https://aws.amazon.com/elasticloadbalancing/application-load-balancer/" target="_blank" rel="noopener"&gt;Application Load Balancer&lt;/a&gt; fronts the console on AWS Fargate. Amazon CloudFront is not available in AWS GovCloud (US), so the load balancer is the delivery layer.&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/cognito/" target="_blank" rel="noopener"&gt;Amazon Cognito&lt;/a&gt; authenticates the user before the console is reachable. Authentication is enforced at the application layer, so an unauthenticated request never reaches the console.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;When an action is warranted, the workflow pauses for an analyst to approve or reject it. No agent acts on its own.&lt;/p&gt; 
&lt;p&gt;This architecture is shown in the following diagram.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/07/Multi-agent-supply-chain-risk-workflow-in-AWS-GovCloud-US.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32304 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/07/Multi-agent-supply-chain-risk-workflow-in-AWS-GovCloud-US.png" alt="Architecture diagram, which is described in the text." width="1027" height="615"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 1: Multi-agent supply chain risk workflow in AWS GovCloud (US)&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;An analyst works from the ranked queue rather than from raw inventory records. The following screenshot shows that queue, with the highest-risk items at the top.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/07/The-console-ranks-items-by-readiness-risk.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32307 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/07/The-console-ranks-items-by-readiness-risk.png" alt="Risk console, which is described in the text." width="1588" height="1133"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 2: The console ranks items by readiness risk and links each row to its location&lt;/em&gt;&lt;/p&gt; 
&lt;h2&gt;Prerequisites&lt;/h2&gt; 
&lt;p&gt;To implement the solution, you need to have the following prerequisites:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;An AWS GovCloud (US) account with permissions for the services described in the architecture&lt;/li&gt; 
 &lt;li&gt;The &lt;a href="https://docs.aws.amazon.com/cdk/v2/guide/getting-started.html" target="_blank" rel="noopener"&gt;AWS Cloud Development Kit (AWS CDK)&lt;/a&gt; v2 and the &lt;a href="https://aws.amazon.com/cli/" target="_blank" rel="noopener"&gt;AWS Command Line Interface (AWS CLI)&lt;/a&gt;, both configured for &lt;code&gt;us-gov-west-1&lt;/code&gt;&lt;/li&gt; 
 &lt;li&gt;A container runtime (Docker or Finch), Python 3.11 or later, and Node.js 20 or later&lt;/li&gt; 
 &lt;li&gt;Access to an Amazon Bedrock foundation model (FM), with its inference profile available to your account&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Amazon Bedrock charges per token. The deployed console runs a load balancer, one AWS Fargate task, and Amazon Cognito. Remove the resources when you finish (see &lt;strong&gt;Cleanup&lt;/strong&gt;).&lt;/p&gt; 
&lt;h2&gt;Deploy it&lt;/h2&gt; 
&lt;p&gt;Run the analytics locally first. You don’t need an AWS account for this. The example backtests a moving-average forecast against a seasonal-naive baseline and derives a decision per item:&lt;/p&gt; 
&lt;pre&gt;&lt;code&gt;== SKU-1001 ==
  backtest MAPE:      model(MA3)= 8.94%  baseline(seasonal)=14.46%  -&amp;gt; winner: model
  readiness risk:     HIGH
  recommended action: Reorder 500 and qualify an alternate supplier
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;Then deploy the console and agents:&lt;/p&gt; 
&lt;pre&gt;&lt;code&gt;git clone https://github.com/aws-samples/multi-agent-supply-chain-risk-for-govcloud &amp;amp;&amp;amp; cd multi-agent-supply-chain-risk-for-govcloud
python -m venv .venv &amp;amp;&amp;amp; .venv/bin/pip install -e ".[dev,bedrock]"
.venv/bin/python examples/worked_forecast.py     # local run

cd infra/cdk &amp;amp;&amp;amp; npm ci
npx cdk deploy -c qualifier=&amp;lt;your-bootstrap-qualifier&amp;gt;
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;Create a user in the Amazon Cognito user pool the stack provisions, then sign in. The following screenshot shows the sign-in page.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/07/The-console-ranks-items-by-readiness-risk-and-links-each-row-to-its-location.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32305 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/07/The-console-ranks-items-by-readiness-risk-and-links-each-row-to-its-location.png" alt="Sign-in page, which is described in the text." width="1588" height="1166"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 3: Users authenticate through Amazon Cognito before reaching the console&lt;/em&gt;&lt;/p&gt; 
&lt;h2&gt;How the agents work&lt;/h2&gt; 
&lt;p&gt;Each agent owns a small tool set. Every tool carries an autonomy classification, so the approval boundary lives in code rather than in prompt text:&lt;/p&gt; 
&lt;pre&gt;&lt;code&gt;class ToolAccess(str, Enum):
    AUTONOMOUS = "autonomous"          # read/compute, no side effects
    HUMAN_APPROVAL = "human_approval"  # consequential; requires sign-off

VISUALIZATION_AGENT = Agent(
    name="visualization_agent",
    tools=(
        Tool("build_view", "Assemble map markers and queue rows.", ToolAccess.AUTONOMOUS),
        Tool("draft_brief", "Draft a grounded, plain-language brief.", ToolAccess.AUTONOMOUS),
        Tool("place_reorder", "Place an order. REQUIRES human approval.",
             ToolAccess.HUMAN_APPROVAL),
    ),
)
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;The supervisor hands each agent’s tools to a foundation model through the Converse API. The model chooses which tool to call and in what order, reacting to each result. Nothing here follows a fixed script.&lt;/p&gt; 
&lt;p&gt;One AWS GovCloud (US) difference will stop you immediately. Converse requires an inference profile ID. Amazon Bedrock rejects the on-demand model ID.&lt;/p&gt; 
&lt;pre&gt;&lt;code&gt;DEFAULT_REGION = "us-gov-west-1"
DEFAULT_MODEL_ID = "us-gov.anthropic.claude-sonnet-4-5-20250929-v1:0"

response = client.converse(
    modelId=DEFAULT_MODEL_ID,
    system=[{"text": SYSTEM_PROMPT}],
    messages=messages,
    toolConfig=build_tool_config(),
)
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;When the model proposes a consequential action, the loop stops and returns it for approval instead of executing it:&lt;/p&gt; 
&lt;pre&gt;&lt;code&gt;for tool_use in tool_uses:
    if requires_human_approval(tool_use["name"]):
        return AdapterResult(
            stopped_for_approval=True,
            pending_action={"tool": tool_use["name"], "input": tool_use.get("input", {})},
        )
    tool_results.append(execute_tool(tool_use))
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;The ranking itself is a weighted blend of three inputs: stockout pressure from the forecast and reorder point, the external disruption signal, and mission criticality, which the sample data carries as a flag on each item in the system of record. Every item shows its score, its primary driver, and a plain-language rationale, as shown in the following screenshot. A reviewer can tell why an item sits where it does.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/07/Selecting-a-location-shows-its-risk-score-inventory-position-and-primary-driver-1.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32306 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/07/Selecting-a-location-shows-its-risk-score-inventory-position-and-primary-driver-1.png" alt="Location detail, which is described in the text." width="1475" height="937"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 4: Selecting a location shows its risk score, inventory position, and primary driver&lt;/em&gt;&lt;/p&gt; 
&lt;h2&gt;Customize it for your needs&lt;/h2&gt; 
&lt;p&gt;Treat the deployed stack as a starting point. Five changes cover most adaptations, and each one is restricted to a single layer:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Point it at your data&lt;/strong&gt; – Swap the sample connectors for your inventory source and whichever disruption feeds you trust. The agents read a curated dataset through Amazon Athena, so all they need is a table rather than a schema rewrite.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Tune the risk model&lt;/strong&gt; – The weighting exists in a single function. Adjust it or replace the forecast with statsmodels, Prophet, or an &lt;a href="https://aws.amazon.com/sagemaker-ai/" target="_blank" rel="noopener"&gt;Amazon SageMaker AI&lt;/a&gt; endpoint. Whatever you choose should exceed a documented baseline for mean absolute percentage error (MAPE) before you rely on it.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Scope permissions tightly&lt;/strong&gt; – The repository ships one &lt;a href="https://aws.amazon.com/iam/" target="_blank" rel="noopener"&gt;AWS Identity and Access Management (IAM)&lt;/a&gt; role per layer, each validated with &lt;a href="https://aws.amazon.com/iam/features/analyze-access/" target="_blank" rel="noopener"&gt;IAM Access Analyzer&lt;/a&gt;. Two details require attention. The Converse API authorizes against &lt;code&gt;bedrock:InvokeModel&lt;/code&gt; because there is no &lt;code&gt;bedrock:Converse&lt;/code&gt; action. And an AWS GovCloud (US) system-defined inference profile can route to either &lt;code&gt;us-gov-west-1&lt;/code&gt; or &lt;code&gt;us-gov-east-1&lt;/code&gt;, so the policy has to list the model &lt;a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference-arns.html" target="_blank" rel="noopener"&gt;Amazon Resource Name (ARN)&lt;/a&gt; in both Regions. Omit one and the service denies the call. Agent data access stays read-only over the curated prefix.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Harden the transport&lt;/strong&gt; – The reference console serves over HTTP on an internal load balancer for demonstration. Before real users touch it, terminate TLS at the load balancer with a certificate from &lt;a href="https://aws.amazon.com/certificate-manager/" target="_blank" rel="noopener"&gt;AWS Certificate Manager&lt;/a&gt;, redirect port 80 to 443, mark session cookies &lt;code&gt;Secure&lt;/code&gt;, and add &lt;code&gt;Strict-Transport-Security&lt;/code&gt;.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Add an agent&lt;/strong&gt; – Define it with its tools and register it with the supervisor. A notification agent is a natural next step. Another option is a context-retrieval agent over &lt;a href="https://aws.amazon.com/bedrock/knowledge-bases/" target="_blank" rel="noopener"&gt;Amazon Bedrock Knowledge Bases&lt;/a&gt;. The supervisor enforces the approval boundary centrally, so anything you add inherits it.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The structure travels. Ranking grant applications, triaging compliance findings, prioritizing maintenance: the pattern fits many workflows where an agent gathers cross-source data and recommends an action for a person to authorize.&lt;/p&gt; 
&lt;h2&gt;Cleanup&lt;/h2&gt; 
&lt;p&gt;Destroy the stack to stop charges, then remove the image repository if you no longer need it:&lt;/p&gt; 
&lt;pre&gt;&lt;code&gt;cd infra/cdk &amp;amp;&amp;amp; npx cdk destroy -c qualifier=&amp;lt;your-bootstrap-qualifier&amp;gt;
aws ecr delete-repository --repository-name supply-chain-console \
  --force --region us-gov-west-1
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;Confirm in the &lt;a href="https://aws.amazon.com/console/" target="_blank" rel="noopener"&gt;AWS Management Console&lt;/a&gt; that the &lt;a href="https://aws.amazon.com/cloudformation/" target="_blank" rel="noopener"&gt;AWS CloudFormation&lt;/a&gt; stack and the &lt;a href="https://aws.amazon.com/ecr/" target="_blank" rel="noopener"&gt;Amazon Elastic Container Registry (Amazon ECR)&lt;/a&gt; repository are gone.&lt;/p&gt; 
&lt;h2&gt;Conclusion&lt;/h2&gt; 
&lt;p&gt;You can deploy agentic AI workloads in AWS GovCloud (US) today, provided you account for its specifics: invoke Amazon Bedrock through an inference profile, scope model and data permissions to what each agent needs, deliver the application behind a load balancer, and keep a person in the loop for consequential actions. Start with the local run, deploy the stack, then point it at your own data.&lt;/p&gt; 
&lt;h2&gt;Additional resources&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;Sample code for this post&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/using-services.html" target="_blank" rel="noopener"&gt;Services in AWS GovCloud (US) Regions&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html" target="_blank" rel="noopener"&gt;AWS GovCloud (US) User Guide&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://docs.aws.amazon.com/bedrock/latest/APIReference/API_runtime_Converse.html" target="_blank" rel="noopener"&gt;Converse API reference in Amazon Bedrock&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/bedrock/guardrails/" target="_blank" rel="noopener"&gt;Amazon Bedrock Guardrails&lt;/a&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;em&gt;Please note that this post is intended for informational purposes. The approach described might not be suitable for every organization or compliance program. Evaluate it against your organization’s compliance needs and any applicable regulatory obligations.&lt;/em&gt;&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>How Forseti and AWS connect domestic violence survivors to services in real time</title>
		<link>https://aws.amazon.com/blogs/publicsector/how-forseti-and-aws-connect-domestic-violence-survivors-to-services-in-real-time/</link>
		
		<dc:creator><![CDATA[Dr. Dawn Heisey-Grove]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 16:04:34 +0000</pubDate>
				<category><![CDATA[AWS GovCloud (US)]]></category>
		<category><![CDATA[Industries]]></category>
		<category><![CDATA[Public Safety]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">573c39a05bfad55eebd1dbb1197a58a1e7df202a</guid>

					<description>Learn how Forseti, a public safety technology company, built the Honest Assessment Response Tool (HART) to meet survivors in that moment. Running on Amazon Web Services (AWS), HART digitizes on-scene domestic violence risk screening, connects survivors to services in real time, and gives state agencies population-level visibility into intimate partner violence patterns.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32311 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/08/How-Forseti-and-AWS-connect-domestic-violence-survivors-to-services-in-real-time.png" alt="How Forseti and AWS connect domestic violence survivors to services in real time" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;In the time it takes to read this sentence, a domestic violence survivor might have decided to seek help, and the window for connecting them to safety is already closing. Research shows &lt;a href="https://pubmed.ncbi.nlm.nih.gov/9274065/" target="_blank" rel="noopener"&gt;88% of help-seeking&lt;/a&gt; occurs in the moments between the acute crisis and the return to an abusive cycle. Services exist, but getting survivors connected to them is challenging. But now, technology exists that can make that connection fast enough to matter.&lt;/p&gt; 
&lt;p&gt;Across the United States, &lt;a href="https://www.cdc.gov/intimate-partner-violence/about/index.html" target="_blank" rel="noopener"&gt;more than 64 million adults&lt;/a&gt; have experienced intimate partner violence in their lifetimes, but &lt;a href="https://nij.ojp.gov/library/publications/barriers-domestic-violence-help-seeking-implications-intervention" target="_blank" rel="noopener"&gt;82% of abused women&lt;/a&gt; never contact an agency or counselor and 74% never seek medical care for their abuse. Of those who do come forward, the majority never connect with the services that could change their trajectory. When a law enforcement officer responds to a domestic violence call, the first few minutes represent a singular opportunity: the survivor is present, the danger clear, and the system paying attention. What happens next depends entirely on whether the response infrastructure can match that moment.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://nij.ojp.gov/library/publications/barriers-domestic-violence-help-seeking-implications-intervention" target="_blank" rel="noopener"&gt;Forseti&lt;/a&gt;, a public safety technology company, built the &lt;a href="https://forseti.io/hart-dv" target="_blank" rel="noopener"&gt;Honest Assessment Response Tool (HART)&lt;/a&gt; to meet survivors in that moment. Running on &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt;, HART digitizes on-scene domestic violence risk screening, connects survivors to services in real time, and gives state agencies population-level visibility into intimate partner violence patterns.&lt;/p&gt; 
&lt;h2&gt;Why timing matters: The research case for real-time connection&lt;/h2&gt; 
&lt;p&gt;The evidence on timing is unambiguous. Foundational research on the violence cycle identifies a narrow &lt;strong&gt;“Open Window Phase”&lt;/strong&gt; between the acute battering incident and the subsequent calm period. During this window, a survivor realizes they can’t stop the violence, is most likely to reach out for help, and is most receptive to intervention.&lt;/p&gt; 
&lt;p&gt;When that window closes, the drop-off is severe because survivors frequently experience post-traumatic stress that inhibits long-term planning, combined with manipulation and coercion from the abuser that compromises their ability to follow up independently. Even among highly motivated survivors who call the National Domestic Violence Hotline and express clear intention to act, &lt;a href="https://acf.gov/opre/report/short-term-outcomes-following-contact-national-domestic-violence-hotline-and" target="_blank" rel="noopener"&gt;only 24.6%&lt;/a&gt; who intended to go to a shelter actually did within 2 weeks. Only 31.9% contacted law enforcement as planned.&lt;/p&gt; 
&lt;p&gt;An immediate, active connection improves action fivefold: &lt;a href="https://pubmed.ncbi.nlm.nih.gov/28987297/" target="_blank" rel="noopener"&gt;72.7% of survivor&lt;/a&gt;s who received an immediate referral connected with behavioral health resources, compared to only 15.7% for those who received a passive referral. This is the gap Forseti closes. Rather than handing a survivor a phone number and hoping they call, HART creates a real-time digital connection between the officer on scene, the completed risk assessment, and the local service provider, while the survivor is still present and receptive.&lt;/p&gt; 
&lt;h2&gt;The challenge: Paper processes in a time-critical system&lt;/h2&gt; 
&lt;p&gt;A &lt;a href="https://dallascityhall.com/departments/auditor/Documents/Audit%20of%20DPD%20Domestic%20Violence%20Program-Final%20Report%2003-13-2025.pdf" target="_blank" rel="noopener"&gt;2025 audit&lt;/a&gt; examined a sample of domestic violence incident reports from the Dallas Police Department and found that among intimate partner cases, 28% were missing a completed Lethality Assessment Program (LAP) form. Paper forms moved slowly through interdepartmental mail. Even when officers completed the LAP at the scene, 35% of sampled forms never reached the database caseworkers use to track high-risk victims. The share of high-risk victims who spoke with a shelter or counselor at the scene had fallen from over 40% when the program launched in 2012 to approximately 20% during the audit period.&lt;/p&gt; 
&lt;p&gt;Dallas is not an outlier. Research shows that standard care for domestic violence includes identification, but rarely includes providing support, facilitating access to support, or following up. When it does, it typically consists of printed educational material or a phone number to a community-based advocacy agency, materials that previous research suggests survivors feel a need to hide from the abuser.&lt;/p&gt; 
&lt;h2&gt;The solution: Digital connection changes outcomes&lt;/h2&gt; 
&lt;p&gt;HART replaces the paper workflow entirely. Officers complete the same Domestic Violence Supplemental Form and Lethality Assessment on a device at the scene. The record is structured, validated, and shareable the moment it’s submitted. Behind HART sits &lt;strong&gt;County Connect&lt;/strong&gt;, Forseti’s referral infrastructure that routes each completed assessment in real time to the district attorney, local domestic violence service providers, and other agencies with a need to know.&lt;/p&gt; 
&lt;p&gt;No paper to scan. No courier to wait for. No caseworker retyping data from a handwritten form. When officers identify a survivor as being in high danger, the local domestic violence service provider receives a referral while the officer is still on scene.&lt;/p&gt; 
&lt;p&gt;This approach mirrors the evidence-based model validated by the&lt;a href="https://www.mnadv.org/lethalityassessmentprogram/" target="_blank" rel="noopener"&gt; Lethality Assessment Program-Maryland Model&lt;/a&gt;, which combines standardized screening with immediate service connection. And these digital connections work, as observed with a digital warm handoff tool, the &lt;strong&gt;Domestic Violence Report and Referral (DVRR) system&lt;/strong&gt;. &lt;em&gt;(A warm handoff is when care is transferred between caregivers with the patient present.)&lt;/em&gt; Among &lt;a href="https://escholarship.org/uc/item/0c60q65h" target="_blank" rel="noopener"&gt;1,366 DV-related emergency departmen&lt;/a&gt;t visits between 2014 and 2018, DVRR-associated visits increased patients’ odds of reaching advocacy services for the populations most underserved by legacy systems:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;2.6 times&lt;/strong&gt; for Latinx female survivors&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;4.66 times&lt;/strong&gt; for Black survivors&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;12.8 times&lt;/strong&gt; for male survivors&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;HART builds on this model by adding digital infrastructure that eliminates the manual steps where connections are lost.&lt;/p&gt; 
&lt;h2&gt;Addressing the geographic lottery: Rural communities need real-time infrastructure most&lt;/h2&gt; 
&lt;p&gt;Women in small rural areas experience domestic violence at rates of &lt;a href="https://pubmed.ncbi.nlm.nih.gov/21919777/" target="_blank" rel="noopener"&gt;22.5% compared to 15.5%&lt;/a&gt; for urban women. Women in small rural areas also report more severe events: more than 60% report four or more events of physical violence compared to 40% of urban women. Yet services in rural areas have long been limited due to geographic isolation, lack of transportation, and limited access to legal services, housing, and health services.&lt;/p&gt; 
&lt;p&gt;HART’s multistate architecture addresses this directly. Forseti’s single cloud platform provides standardized data collection across &lt;strong&gt;14 states&lt;/strong&gt;, providing an officer in a rural North Carolina county with the same assessment tools, the same real-time referral pathways, and the same data quality as a detective in a metropolitan police department. The platform eliminates the geographic lottery of response quality that currently defines domestic violence intervention in America.&lt;/p&gt; 
&lt;h2&gt;Built on AWS for security and scale&lt;/h2&gt; 
&lt;p&gt;HART and County Connect run on &lt;a href="https://aws.amazon.com/govcloud-us/" target="_blank" rel="noopener"&gt;AWS GovCloud (US)&lt;/a&gt;. The platform is fully compliant with the FBI’s Criminal Justice Information Services (CJIS) Security Policy, with a formal assessment and authorization on record, and holds SOC 2 Type II compliance. This is the security posture that law enforcement, state agencies, and domestic violence service providers require before survivor and case data touches a cloud platform.&lt;/p&gt; 
&lt;p&gt;The platform is powered by &lt;a href="https://aws.amazon.com/opensearch-service/" target="_blank" rel="noopener"&gt;Amazon OpenSearch Service&lt;/a&gt; and &lt;a href="https://aws.amazon.com/cloudwatch/" target="_blank" rel="noopener"&gt;Amazon CloudWatch&lt;/a&gt;. OpenSearch Service powers search and analytics across incident records so prosecutors and state researchers can query structured domestic violence data instead of paging through PDFs. CloudWatch provides around-the-clock monitoring for a system that must be available the moment an officer is standing in a survivor’s home.&lt;/p&gt; 
&lt;p&gt;As Forseti has grown from a single-agency pilot to a multistate platform, AWS infrastructure has enabled a small team to support more than 160 agencies without rebuilding architecture for each new state deployment.&lt;/p&gt; 
&lt;h2&gt;Impact by the numbers&lt;/h2&gt; 
&lt;p&gt;HART is now in use across more than 160 law enforcement and domestic violence service provider agencies in 14 states, with more than 10,000 survivors assessed to date. Forseti is also collaborating with leading domestic violence researchers and institutions across the country to analyze assessment data and improve how agencies nationwide respond to domestic violence calls for service.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;“All agencies need to be on the same team to assist survivors, and that’s exactly what we are doing here at Forseti,”&lt;/em&gt; says Warren Lautz, chief operating officer, Forseti. &lt;em&gt;“It is unacceptable to let archaic processes hinder communities’ ability to save lives.”&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;h2&gt;Looking ahead&lt;/h2&gt; 
&lt;p&gt;For criminal justice and social service agencies working to close the gap between a 911 call and a connected support system, Forseti and HART demonstrate what becomes possible when on-scene data collection and statewide infrastructure run on the same secure cloud platform. The research is clear: real-time connection during the critical window of opportunity&lt;a href="https://escholarship.org/uc/item/0c60q65h" target="_blank" rel="noopener"&gt; increases the share of survivors who reach advocacy services&lt;/a&gt;, and agencies implementing the Lethality Assessment Program have seen a &lt;a href="https://www.sciencedirect.com/science/article/abs/pii/S0167268123004018" target="_blank" rel="noopener"&gt;significant reduction in intimate partner homicide&lt;/a&gt;. As new states and metropolitan agencies come online, the model offers a path from fragmented paper processes to coordinated, real-time response at scale.&lt;/p&gt; 
&lt;p&gt;Learn more about &lt;a href="https://aws.amazon.com/about-aws/our-impact/" target="_blank" rel="noopener"&gt;AWS social impact&lt;/a&gt;.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>AI-powered customs classification, duty calculation, and pre-departure collection now available to postal operators across 192 nations</title>
		<link>https://aws.amazon.com/blogs/publicsector/ai-powered-customs-classification-duty-calculation-and-pre-departure-collection-now-available-to-postal-operators-across-192-nations/</link>
		
		<dc:creator><![CDATA[Mike Lentine]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 15:18:35 +0000</pubDate>
				<category><![CDATA[Industries]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">9feb200c80001aa37d2a6d34db0defaebbe0954a</guid>

					<description>Learn how Amazon PreDepart has successfully met the technical requirements of the Universal Postal Union (UPU) TechCert Programme for information technology integration and interoperability with UPU technology.</description>
										<content:encoded>&lt;p&gt;For international e-commerce customers whose packages are shipped through one of 192 postal networks, the cost of a purchase often isn’t final at checkout. Duties and taxes are calculated after departure, assessed at the border, and charged upon delivery. This creates unexpected costs, refused deliveries, and eroded trust. Postal operators want to solve this, but offering full landed cost transparency requires customs classification expertise across thousands of tariff codes and dozens of destination countries – expertise that most Posts aren’t equipped to build in-house. Today, that changes for all 192 UPU member nations.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://predepart.amazon/" target="_blank" rel="noopener"&gt;Amazon PreDepart&lt;/a&gt; has successfully met the technical requirements of the &lt;a href="https://www.upu.int/en/Postal-Solutions/Technical-Solutions/Products/UPU-TechCert" target="_blank" rel="noopener"&gt;Universal Postal Union (UPU) TechCert Programme&lt;/a&gt; for information technology integration and interoperability with UPU technology. This certification makes Amazon PreDepart available as a solution for providing Delivered Duty Paid (DDP) customer pricing to postal operators across the UPU’s 192-member nation network, accessible through the platforms they already use. This milestone builds on over six years of developing AI-powered customs classification and duty collection capabilities and follows &lt;a href="https://aws.amazon.com/blogs/publicsector/ai-powered-customs-duties-classification-assessment-and-collection-for-international-mail-shipments-to-the-united-states/" target="_blank" rel="noopener"&gt;US Customs and Border Protection’s selection of Amazon PreDepart under the Commercial Solutions Opening Pilot&lt;/a&gt; earlier this year.&lt;/p&gt; 
&lt;h2&gt;What is the UPU Delivered Duty Paid Solution?&lt;/h2&gt; 
&lt;p&gt;The UPU DDP solution enables postal operators to collect duties and taxes at origin &lt;strong&gt;(before shipment departure)&lt;/strong&gt; improving customs clearance efficiency and providing full landed cost transparency to customers. For consumers purchasing goods online, DDP means that all relevant costs (shipping, duties, and taxes) are known at the time of purchase, reducing risk of unexpected charges at delivery and reducing risk of delays at the border by transmitting the product and shipment details pre-departure through Amazon PreDepart Service.&lt;/p&gt; 
&lt;p&gt;The solution is available through the UPU’s Customs Declaration System (CDS) and APIs, and supports integration with certified third-party providers. Amazon PreDepart is now one of seven certified providers, validated by the UPU TechCert Program to operate seamlessly within the UPU’s global postal technology ecosystem.&lt;/p&gt; 
&lt;h2&gt;What this means for operators&lt;/h2&gt; 
&lt;p&gt;Amazon PreDepart’s UPU TechCert certification gives postal operators and express shippers a turnkey path to offering DDP services without building the underlying complexity themselves.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;For postal operators and express shippers,&lt;/strong&gt; the certification means immediate access to AI-powered customs classification and duty collection capabilities through the UPU infrastructure they already use. CDS users can activate Amazon PreDepart as their DDP service enabler through a configuration parameter. Non-CDS Posts connect via the UPU PTC API Gateway. Express shipper platforms integrate directly through PreDepart APIs. All paths deliver automated HTS/HS classification, duty calculation, and pre-departure customs filing drafting at scale, no new systems or customs expertise required.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;For customers,&lt;/strong&gt; it means full cost transparency at the point of sale so long as complete product information is provided. Amazon PreDepart calculates and collects duties and taxes before shipment, so customers know their total landed cost for such products upfront. No surprises at delivery, no refused packages, no uncertainty about what they owe on those products.&lt;/p&gt; 
&lt;h2&gt;How it works: the technology behind PreDepart&lt;/h2&gt; 
&lt;p&gt;Amazon PreDepart combines Amazon Customs and Trade’s (ACT) deep trade and customs expertise with AWS generative AI and global cloud infrastructure. The solution delivers AI-powered capabilities across four key dimensions:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Automated HTS/HS classification.&lt;/strong&gt; Generative AI analyzes product descriptions, materials, and specifications to recommend the correct tariff classification code from thousands of possible classifications within seconds, removing the guesswork and inconsistency of manual classification.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Complete duty breakdown.&lt;/strong&gt; The solution compiles all relevant tariff classification codes and import duties into a single, unified view. Postal operators and their customers can quickly identify applicable tariff classification codes and understand import costs, enabling faster decision-making and greater confidence in customs compliance.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;PreDepart Elements.&lt;/strong&gt; Ready-to-use web tools integrate directly into a postal operator’s website or shipping platform. The PreDepart Application Line Item Element embeds into the item identification step for interactive customs data collection, while the PreDepart Application Element offers a simpler single-component solution for managing multiple items. Both can appear as drawers, modals, or within existing workflows to match a platform’s design.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Integrated duty calculation and collection.&lt;/strong&gt; Once classification is complete, the system automatically calculates and collects duties within the carrier’s existing shipping flow — no separate systems, no manual handoffs. Amazon PreDepart then drafts customs filings before goods depart, supporting rapid clearance upon arrival.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Navigating UPU certification&lt;/h2&gt; 
&lt;p&gt;Achieving UPU TechCert certification required Amazon to demonstrate interoperability across the UPU’s global postal technology ecosystem. The certification scope covers three key areas of integration:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;DDP functionalities: CDS software integration.&lt;/strong&gt; Amazon PreDepart integrates fully with the UPU CDS, enabling postal operators to activate DDP services through a simple configuration parameter — no custom development required.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;POST*Net integration.&lt;/strong&gt; The system transmits shipment data securely through the UPU’s global postal network, sending only the information required for customs filing: item identification, declared value, country of origin, and transport information.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Customs broker services for US-bound shipments.&lt;/strong&gt; ACT is a licensed US customs broker able to file customs declarations with US Customs and Border Protection and handle the financial settlement of applicable duties and taxes on US imports.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The certification supports multi-provider configurations (from CDS 2025 SP1 onwards), so operators can add Amazon PreDepart to their existing setup or run it as their sole provider, selecting the best fit for their routes and volumes.&lt;/p&gt; 
&lt;h2&gt;What our leaders are saying&lt;/h2&gt; 
&lt;p&gt;“Amazon PreDepart’s UPU TechCert certification represents our commitment to making international trade simpler and more transparent for postal operators and their customers worldwide,” said David Cardadeiro, vice president of Amazon Customs and Trade. “By integrating directly with the UPU’s global postal infrastructure, we can now bring our AI-powered customs solution to Posts across 192 nations through the platforms they already use.”&lt;/p&gt; 
&lt;h2&gt;Get involved&lt;/h2&gt; 
&lt;p&gt;In this post, we announced Amazon PreDepart’s UPU TechCert certification and how it enables postal operators across 192 nations to offer Delivered Duty Paid services through the platforms they already use, no customs expertise or custom integrations required.&lt;/p&gt; 
&lt;p&gt;Any operator in the UPU’s 192-member nation network can activate Amazon PreDepart as their certified DDP service enabler today. There’s no customs integration to build and no in-house expertise to develop. Activate, configure, and start collecting duties before departure.&lt;/p&gt; 
&lt;p&gt;Are you a postal operator or express shipper interested in activating Amazon PreDepart as your certified DDP service enabler? We’d like to hear from you! Connect with our team directly at &lt;a href="mailto:predepart-interest@amazon.com" target="_blank" rel="noopener"&gt;predepart-interest@amazon.com&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;Amazon Customs and Trade (ACT) is Amazon’s trade technology and customs brokerage organization, delivering AI-powered solutions that simplify cross-border commerce for shippers, carriers, and government agencies worldwide.&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;Amazon Web Services (AWS) provides the most comprehensive and broadly adopted cloud platform, offering over 200 fully featured services from data centers globally. Millions of customers — including government agencies, the fastest-growing startups, largest enterprises, and leading nonprofits — use AWS to lower costs, become more agile, and innovate faster.&lt;/em&gt;&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>How MTC’s 511 program uses Amazon Connect to serve 1.6 million callers</title>
		<link>https://aws.amazon.com/blogs/publicsector/511-keeping-the-bay-area-moving-one-call-at-a-time/</link>
		
		<dc:creator><![CDATA[Ofelia Walsh]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 17:47:44 +0000</pubDate>
				<category><![CDATA[Amazon Connect]]></category>
		<category><![CDATA[Amazon Lex]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">a96264229836fa38ca437278caecbf51094af37e</guid>

					<description>Whether it’s checking when the next bus, train, or ferry departs, finding out about a freeway closure, or getting a broken-down car towed off the Bay Bridge, the region’s 511 traveler information service is a critical public resource. Its phone service runs on Amazon Web Services (AWS) using services Amazon Connect Customer and Amazon Lex.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32212 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/25/How-MTCs-511-program-uses-Amazon-Connect-to-serve-1.6-million-callers.png" alt="How MTC’s 511 program uses Amazon Connect to serve 1.6 million callers" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;For the 7 million residents of the San Francisco Bay Area, getting to work, school, or home safely and on time depends on reliable, real-time travel information. Whether it’s checking when the next bus, train, or ferry departs; finding out about a freeway closure; or getting a broken-down car towed off the Bay Bridge, the region’s 511 traveler information service is a critical public resource. Its phone service runs on &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; using &lt;a href="https://aws.amazon.com/products/connect/customer/" target="_blank" rel="noopener"&gt;Amazon Connect Customer&lt;/a&gt; and &lt;a href="https://aws.amazon.com/lex/" target="_blank" rel="noopener"&gt;Amazon Lex&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;The Metropolitan Transportation Commission (MTC), the transportation planning, financing, and coordinating agency for the nine-county Bay Area, operates the 511 phone service as a fully automated interactive voice response (IVR) system that handles approximately 1.6 million calls per year with zero wait times and no live agents.&lt;/p&gt; 
&lt;h2&gt;A 20-year-old service needed a new platform&lt;/h2&gt; 
&lt;p&gt;MTC has operated the 511 traveler information line for more than 20 years, providing callers with real-time transit departures, traffic conditions, driving directions, emergency alerts, and transfers to regional transit agencies and paratransit operators. The system has always been fully automated with no live agents and no hold queues while serving an unlimited number of concurrent callers around the clock.&lt;/p&gt; 
&lt;p&gt;MTC selected Amazon Connect Customer for its breadth of features and its ability to integrate with the agency’s existing data infrastructure, which is hosted on AWS. MTC completed the migration and launched the new Amazon Connect Customer 511 phone service on September 28, 2023.&lt;/p&gt; 
&lt;h2&gt;Conversational AI replaces traditional IVR menus&lt;/h2&gt; 
&lt;p&gt;Unlike traditional IVR systems that force callers through rigid touchtone menus, MTC’s 511 service uses Amazon Lex—the same conversational AI technology that powers &lt;a href="https://alexa.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Alexa&lt;/a&gt;—to understand natural speech and guide callers to the information they need.&lt;/p&gt; 
&lt;p&gt;When a caller dials 511, Amazon Lex processes their spoken request, identifies their intent, and routes them through the appropriate call flow within Amazon Connect. A caller can say “transit departure times,” name a transit agency such as BART or VTA, and provide a stop name. Amazon Lex handles the exchange, collecting each piece of information and returning a real-time answer. MTC’s 511 service supports both English and Spanish. Callers who prefer touchtone input can use that as well.&lt;/p&gt; 
&lt;p&gt;Because Amazon Lex handles all caller interactions, MTC operates the 511 phone service without a single live agent. Each call is answered instantly. The system handles an unlimited number of concurrent callers, which is a critical capability for a service covering nine counties and over 7 million residents.&lt;/p&gt; 
&lt;h2&gt;Real-time data powers every call&lt;/h2&gt; 
&lt;p&gt;Behind each 511 call is a data pipeline built on AWS. MTC’s data and development team collects transit and traffic information from dozens of regional operators and stores it in databases hosted within AWS. A custom API layer exposes this data to both the 511 IVR system and the 511.org website, providing a consistent experience across channels.&lt;/p&gt; 
&lt;p&gt;The data falls into two categories:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Static data&lt;/strong&gt; – Transit schedules that update whenever agencies publish changes, typically monthly or quarterly.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Real-time data&lt;/strong&gt; – Live predictions refreshed as frequently as every 10 seconds, depending on the transit operator.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;When Amazon Lex captures a caller’s request, the Amazon Connect Customer contact flow invokes the API, retrieves the real-time prediction, and delivers the answer back to the caller through text-to-speech. This exchange takes seconds.&lt;/p&gt; 
&lt;h2&gt;Serving travelers across nine counties&lt;/h2&gt; 
&lt;p&gt;Callers interact with Amazon Lex call flows that provide information across several categories:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Transit departure times&lt;/strong&gt; – Callers name a transit agency, provide a stop, and receive the next scheduled departure. Amazon Lex manages the multi-turn conversation, prompting for any missing details. This is the most requested feature, accounting for 75% of all calls.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Traffic conditions and driving times&lt;/strong&gt; – Callers provide a city, landmark, or start and end city and receive real-time route guidance, estimated travel times, and traffic conditions.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Transit agency transfers&lt;/strong&gt; – Callers can request a live transfer to BART, AC Transit, Caltrain, SamTrans, SFMTA, or VTA for issues such as lost items, to speak with a live operator, or specific inquiries, making up 10% of call volume.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Freeway Assist&lt;/strong&gt; – Motorists whose vehicles break down on Bay Area freeways can call 511 to receive a no-cost tow, helping clear congestion quickly.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Paratransit&lt;/strong&gt; – Dedicated menu options for riders who need accessible transit services, including transfers to live operators.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Partner programs&lt;/strong&gt; – Information on FasTrak, Clipper, All-Nighter, Vanpool, and other regional transportation initiatives.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Amazon Connect Customer orchestrates the flow, there’s no dependency on human staffing. The system scales automatically to meet demand.&lt;/p&gt; 
&lt;h2&gt;Improved visibility and reliable operations&lt;/h2&gt; 
&lt;p&gt;Since migrating to Amazon Connect Customer, MTC’s team has gained operational capabilities unavailable in the previous system.&lt;/p&gt; 
&lt;p&gt;The ability to look up individual contact IDs in Amazon Connect Customer has been particularly valuable. “I can look up a contact ID and see exactly what the issue is with that call,” said a member of MTC’s 511 team. “It’s helpful and allows us to address user concerns and feedback quickly.”&lt;/p&gt; 
&lt;p&gt;To maintain continuous service availability, MTC’s consultant performs daily monitoring across both the Amazon Connect Customer production and staging environments. Whenever a subsystem experiences downtime, the team receives immediate Slack alerts, meaning a rapid response is mounted before callers are affected. This proactive monitoring, combined with separate environments, follows AWS operational best practices by catching issues early and keeping changes validated before they reach production.&lt;/p&gt; 
&lt;p&gt;Since going live on Amazon Connect Customer, the agency hasn’t experienced an unplanned outage. The team provides monthly call volume statistics and request breakdowns to leadership, giving decision-makers visibility into how the traveling public uses the service.&lt;/p&gt; 
&lt;h2&gt;Navigating real-world challenges&lt;/h2&gt; 
&lt;p&gt;The primary technical challenge MTC has encountered is background noise during calls. Because the majority of 511 callers are requesting transit departure times, many are calling from bus stops, train platforms, and other noisy environments. This can affect the accuracy of the Amazon Lex speech recognition function.&lt;/p&gt; 
&lt;p&gt;Beyond that, the transition has been seamless. “No other challenges,” said MTC’s 511 team lead. “Everything’s been pretty great and smooth.”&lt;/p&gt; 
&lt;h2&gt;A model for agentless public sector automation&lt;/h2&gt; 
&lt;p&gt;MTC’s 511 phone service demonstrates how public agencies can combine Amazon Connect Customer and Amazon Lex to deliver critical information services at scale without staffing a traditional call center or employing a single live agent.&lt;/p&gt; 
&lt;p&gt;By pairing conversational AI with real-time data APIs hosted on AWS, MTC serves 1.6 million callers per year across nine counties, covering modes of transportation from buses, trains, and ferries to freeway towing.&lt;/p&gt; 
&lt;p&gt;The result is a service that keeps the Bay Area moving, one 511 call at a time.&lt;/p&gt; 
&lt;p&gt;For additional public sector stories, you can explore the &lt;a href="https://aws.amazon.com/blogs/publicsector/" target="_blank" rel="noopener"&gt;AWS Public Sector Blog&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;The Metropolitan Transportation Commission (MTC) is the transportation planning, financing, and coordinating agency for the nine-county San Francisco Bay Area, serving over 7 million residents across San Francisco, Alameda, Contra Costa, Marin, Napa, San Mateo, Santa Clara, Solano, and Sonoma counties.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>AWS expands its Defending Digital Campaigns offering for the 2026 election cycle</title>
		<link>https://aws.amazon.com/blogs/publicsector/aws-expands-its-defending-digital-campaigns-offering-for-the-2026-election-cycle/</link>
		
		<dc:creator><![CDATA[Leo Zhadanovsky]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 21:53:19 +0000</pubDate>
				<category><![CDATA[Amazon CloudWatch]]></category>
		<category><![CDATA[Amazon Cognito]]></category>
		<category><![CDATA[Amazon Detective]]></category>
		<category><![CDATA[Amazon GuardDuty]]></category>
		<category><![CDATA[Amazon Inspector]]></category>
		<category><![CDATA[Amazon Macie]]></category>
		<category><![CDATA[Announcements]]></category>
		<category><![CDATA[AWS Audit Manager]]></category>
		<category><![CDATA[AWS CloudTrail]]></category>
		<category><![CDATA[AWS Config]]></category>
		<category><![CDATA[AWS Control Tower]]></category>
		<category><![CDATA[AWS Firewall Manager]]></category>
		<category><![CDATA[AWS Identity and Access Management (IAM)]]></category>
		<category><![CDATA[AWS Key Management Service]]></category>
		<category><![CDATA[AWS Secrets Manager]]></category>
		<category><![CDATA[AWS Security Hub]]></category>
		<category><![CDATA[AWS Shield]]></category>
		<category><![CDATA[AWS WAF]]></category>
		<category><![CDATA[AWS Wickr]]></category>
		<category><![CDATA[Federal]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Resource Access Manager (RAM)]]></category>
		<category><![CDATA[Security, Identity, & Compliance]]></category>
		<guid isPermaLink="false">d781460463698695cf81be50c1b200eb63d22ca9</guid>

					<description>This post describes the program for the 2026 cycle, the services it covers, and how eligible campaigns and committees can enroll. Since AWS first joined DDC in 2020 and expanded the offering in 2022 and again in 2024, eligible campaigns and committees of any size and on either side of the aisle have used these services to protect the data, identities, and applications they rely on through Election Day.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32096 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/16/AWS-expands-its-Defending-Digital-Campaigns-offering-for-the-2026-election-cycle-1.png" alt="AWS expands its Defending Digital Campaigns offering for the 2026 election cycle" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;For the 2026 U.S. midterm election cycle, &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; is continuing to work with &lt;a href="https://defendcampaigns.org/" target="_blank" rel="noopener"&gt;Defending Digital Campaigns&lt;/a&gt; (DDC) to provide more than 20 cybersecurity-related services at low or no cost to active and registered national party committees and federal candidate campaigns for the U.S. House and Senate.&lt;/p&gt; 
&lt;p&gt;This post describes the program for the 2026 cycle, the services it covers, and how eligible campaigns and committees can enroll. Since AWS first joined DDC in 2020 and &lt;a href="https://aws.amazon.com/blogs/publicsector/aws-announces-low-no-cost-security-services-federal-political-campaigns-committees/" target="_blank" rel="noopener"&gt;expanded the offering in 2022&lt;/a&gt; and &lt;a href="https://aws.amazon.com/blogs/publicsector/aws-expands-program-offering-low-to-no-cost-security-services-for-federal-political-campaigns-and-committees/" target="_blank" rel="noopener"&gt;again in 2024&lt;/a&gt;, eligible campaigns and committees of any size and on either side of the aisle have used these services to protect the data, identities, and applications they rely on through Election Day.&lt;/p&gt; 
&lt;p&gt;DDC is a nonprofit, nonpartisan, non-aligned organization that helps eligible federal political campaigns and committees access cybersecurity products, services, and information regardless of party affiliation. The Federal Election Commission has granted DDC special permission to operate this model so that all eligible campaigns and committees can receive consistent support within the bounds of campaign finance law.&lt;/p&gt; 
&lt;h2&gt;Updates and highlights&lt;/h2&gt; 
&lt;p&gt;The 2026 program refreshes the AWS service catalog available to eligible campaigns and committees through DDC. Here are three services to highlight this cycle:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;AWS Security Agent – New for 2026&lt;/strong&gt; – Announced at &lt;a href="https://aws.amazon.com/reinvent/" target="_blank" rel="noopener"&gt;AWS re:Invent 2025&lt;/a&gt;, &lt;a href="https://aws.amazon.com/security-agent/" target="_blank" rel="noopener"&gt;AWS Security Agent&lt;/a&gt; is an &lt;a href="https://aws.amazon.com/ai/agentic-ai/" target="_blank" rel="noopener"&gt;agentic AI&lt;/a&gt; assistant that helps customers proactively secure their applications throughout the development lifecycle. It supports workflows that map directly to common campaign needs: on-demand penetration testing that produces validated vulnerabilities and reproducible exploit paths, design security reviews that analyze architecture and technical designs for security risks, and automated code security reviews on pull requests with inline remediation guidance. Eligible campaigns and committees enrolled in DDC can now use AWS Security Agent at no cost during the program window.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;AWS Shield Advanced&lt;/strong&gt; – Provides managed distributed denial-of-service (DDoS) protection for campaign websites, donor portals, and any other internet-facing application during the high-traffic windows that surround a national election. The DDC offering provides up to a 60-day program window with no long-term commitment.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;AWS Wickr&lt;/strong&gt; – Provides end-to-end encrypted messaging, voice and video calling, file sharing, and screen sharing for campaign teams. AWS Wickr holds a &lt;a href="https://aws.amazon.com/compliance/services-in-scope/DoD_CC_SRG/" target="_blank" rel="noopener"&gt;Defense Information Systems Agency (DISA) Provisional Authorization at Impact Level 5 in AWS GovCloud&lt;/a&gt; under the U.S. Department of Defense (DoD) Cloud Computing Security Requirements Guide (SRG), and &lt;a href="https://aws.amazon.com/compliance/fedramp/" target="_blank" rel="noopener"&gt;Federal Risk and Authorization Management Program (FedRAMP) &lt;/a&gt;High authorization in &lt;a href="https://aws.amazon.com/govcloud-us/" target="_blank" rel="noopener"&gt;AWS GovCloud (US)&lt;/a&gt;. It’s in active use across the DoD, including a U.S. Air Force deployment of Wickr RAM through Air Force Cloud One and Air Force Special Operations Command (AFSOC), and a &lt;a href="https://www.army.mil/article/290211/" target="_blank" rel="noopener"&gt;U.S. Army rollout&lt;/a&gt; that, as of January 2026, was approaching 100,000 registered users. Eligible organizations should work with their AWS account team to enroll in AWS Wickr.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;In addition to these three, the program covers a broader set of identity, network, data, and operational security services. The full complement of services is listed later in this post.&lt;/p&gt; 
&lt;h2&gt;Why this matters for the 2026 cycle&lt;/h2&gt; 
&lt;p&gt;Election campaigns and committees continue to be high-value targets for nation-state actors, financially motivated criminal groups, and opportunistic intruders. The Federal Bureau of Investigation (FBI) Internet Crime Complaint Center (IC3) &lt;a href="https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf" target="_blank" rel="noopener"&gt;2024 Internet Crime Report&lt;/a&gt; recorded 859,532 complaints with $16.6 billion in reported losses, a 33% increase from 2023.&lt;/p&gt; 
&lt;p&gt;Phishing and spoofing was the most-reported crime type by volume, with 193,407 complaints, and government impersonation accounted for $405 million in losses. Adding to that picture, the FBI &lt;a href="https://www.fbi.gov/investigate/cyber/alerts/2025/senior-us-officials-impersonated-in-malicious-messaging-campaign" target="_blank" rel="noopener"&gt;warned in May 2025&lt;/a&gt; that malicious actors are using AI-generated voice messages and text messages to impersonate senior U.S. officials and target their contacts—a tactic that translates directly to the campaign-staff threat model.&lt;/p&gt; 
&lt;p&gt;Campaigns operate on compressed timelines with lean staff, and they often lack the security headcount or budget that an enterprise has on hand year-round. Through this collaboration with DDC, campaigns of any size can access the same kinds of foundational security services larger organizations already rely on.&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Campaigns operate with small staffs and tight timelines. Access to enterprise-grade security tools is something they need, not something they can usually afford. The continued collaboration between AWS and DDC puts essential security in the hands of every eligible campaign—at no cost.&lt;/em&gt; — Michael Kaiser, President and CEO, Defending Digital Campaigns&lt;/p&gt; 
&lt;h2&gt;Services included in the 2026 offering&lt;/h2&gt; 
&lt;p&gt;Eligible campaigns and committees can use these services through the program window. Each link goes to the service’s product page on aws.amazon.com.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/cloudwatch/" target="_blank" rel="noopener noreferrer"&gt;Amazon CloudWatch&lt;/a&gt; – Centralize logs from systems, applications, and AWS services&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/cognito/" target="_blank" rel="noopener noreferrer"&gt;Amazon Cognito&lt;/a&gt; – User sign-up, sign-in, and access control&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/detective/" target="_blank" rel="noopener noreferrer"&gt;Amazon Detective&lt;/a&gt; – Security data analysis and visualization for root cause analysis&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/guardduty/" target="_blank" rel="noopener noreferrer"&gt;Amazon GuardDuty&lt;/a&gt; – Intelligent threat detection&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/inspector/" target="_blank" rel="noopener noreferrer"&gt;Amazon Inspector&lt;/a&gt; – Automated vulnerability management&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/macie/" target="_blank" rel="noopener noreferrer"&gt;Amazon Macie&lt;/a&gt; – Discovery and protection of sensitive data&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/audit-manager/" target="_blank" rel="noopener noreferrer"&gt;AWS Audit Manager&lt;/a&gt; – Continuous auditing for risk and compliance&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/certificate-manager/" target="_blank" rel="noopener noreferrer"&gt;AWS Certificate Manager&lt;/a&gt; – Public and private SSL/TLS certificate management&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/cloudtrail/" target="_blank" rel="noopener noreferrer"&gt;AWS CloudTrail&lt;/a&gt; – User and API activity tracking&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/config/" target="_blank" rel="noopener noreferrer"&gt;AWS Config&lt;/a&gt; – Assess, audit, and evaluate AWS resources&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/controltower/" target="_blank" rel="noopener noreferrer"&gt;AWS Control Tower&lt;/a&gt; – Set up and govern a secure, multi-account AWS environment&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/firewall-manager/" target="_blank" rel="noopener noreferrer"&gt;AWS Firewall Manager&lt;/a&gt; – Centrally configure and manage firewall rules&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/iam/identity-center/" target="_blank" rel="noopener noreferrer"&gt;AWS IAM Identity Center&lt;/a&gt; – Central management of access to multiple AWS accounts and applications&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/kms/" target="_blank" rel="noopener noreferrer"&gt;AWS Key Management Service (AWS KMS)&lt;/a&gt; – Create and manage cryptographic keys&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/network-firewall/" target="_blank" rel="noopener noreferrer"&gt;AWS Network Firewall&lt;/a&gt; – Network security for your Amazon Virtual Private Cloud (Amazon VPC)&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/ram/" target="_blank" rel="noopener noreferrer"&gt;AWS Resource Access Manager&lt;/a&gt; – Securely share AWS resources&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/secrets-manager/" target="_blank" rel="noopener noreferrer"&gt;AWS Secrets Manager&lt;/a&gt; – Manage, retrieve, and rotate database credentials, API keys, and other secrets&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/security-agent/" target="_blank" rel="noopener"&gt;AWS Security Agent&lt;/a&gt;&lt;strong&gt; – New for 2026&lt;/strong&gt; – Agentic AI assistant for on-demand penetration testing, design security reviews, and code security reviews&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/security-hub/" target="_blank" rel="noopener noreferrer"&gt;AWS Security Hub&lt;/a&gt; – Automated security checks and centralized security alerts&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/shield/" target="_blank" rel="noopener noreferrer"&gt;AWS Shield Advanced&lt;/a&gt; – Managed DDoS protection&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/waf/" target="_blank" rel="noopener noreferrer"&gt;AWS WAF&lt;/a&gt; – Protection for web applications from common web exploits&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/wickr/" target="_blank" rel="noopener noreferrer"&gt;AWS Wickr&lt;/a&gt; – End-to-end encrypted messaging, voice and video calls, file sharing, and screen sharing&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Who is eligible and how to enroll&lt;/h2&gt; 
&lt;p&gt;Eligibility is determined by DDC, in line with &lt;a href="https://www.fec.gov/" target="_blank" rel="noopener"&gt;Federal Election Commission&lt;/a&gt; guidance and DDC’s own program rules. The program is available to active and registered:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;National party committees of major political parties&lt;/li&gt; 
 &lt;li&gt;Federal candidate campaigns for the U.S. House and Senate&lt;/li&gt; 
 &lt;li&gt;Other federal-level committees that meet DDC’s program criteria&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Eligible campaigns and committees can visit &lt;a href="https://pages.awscloud.com/aws-federal-political-campaigns.html" target="_blank" rel="noopener"&gt;AWS Security Services for Federal Political Campaigns&lt;/a&gt; to enroll. To learn more about DDC, &lt;a href="https://defendcampaigns.org/" rel="noopener noreferrer"&gt;contact DDC directly&lt;/a&gt; to confirm eligibility and request access. Existing AWS customers can also reach out to their account team or the &lt;a href="https://aws.amazon.com/government-education/contact/" target="_blank" rel="noopener"&gt;AWS Public Sector team&lt;/a&gt; to discuss next steps after DDC has confirmed eligibility.&lt;/p&gt; 
&lt;h2&gt;Conclusion&lt;/h2&gt; 
&lt;p&gt;Election campaigns of every size deserve access to current, well-maintained security services. The 2026 refresh of the AWS offering through DDC—including AWS Security Agent—is intended to help campaigns and committees focus on running their operations and reaching voters with one fewer thing to worry about.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;Democracy works when candidates and campaigns can focus on engaging voters, not worrying about protecting themselves from cyber threats. Our continued collaboration with DDC reflects the civic responsibility of AWS, making essential security accessible to every eligible campaign, regardless of party affiliation and budget.&lt;/em&gt; — Kim Majerus, Vice President of Global Education and Local Government, AWS&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;To learn more about DDC, visit &lt;a href="https://defendcampaigns.org/" target="_blank" rel="noopener"&gt;defendcampaigns.org&lt;/a&gt;. To learn more about how AWS supports election cybersecurity, refer to prior posts on the &lt;a href="https://aws.amazon.com/blogs/publicsector/" target="_blank" rel="noopener"&gt;AWS Public Sector Blog&lt;/a&gt; covering the &lt;a href="https://aws.amazon.com/blogs/publicsector/aws-announces-low-no-cost-security-services-federal-political-campaigns-committees/" target="_blank" rel="noopener"&gt;2022&lt;/a&gt; and &lt;a href="https://aws.amazon.com/blogs/publicsector/aws-expands-program-offering-low-to-no-cost-security-services-for-federal-political-campaigns-and-committees/" target="_blank" rel="noopener"&gt;2024&lt;/a&gt; updates.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>Human-in-the-loop claims processing with Amazon Bedrock AgentCore</title>
		<link>https://aws.amazon.com/blogs/publicsector/human-in-the-loop-claims-processing-with-amazon-bedrock-agentcore/</link>
		
		<dc:creator><![CDATA[Brigette Bucke]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 19:25:05 +0000</pubDate>
				<category><![CDATA[Amazon Bedrock AgentCore]]></category>
		<category><![CDATA[Amazon Bedrock Knowledge Bases]]></category>
		<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[AWS Step Functions]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[State or Local Government]]></category>
		<guid isPermaLink="false">b67b270c500fcaa36beff3bf64b40f0ccddd843b</guid>

					<description>In this post, we explore a human-in-the-loop (HITL) framework in the form of architectural patterns teams can use to introduce agentic AI incrementally into eligibility workflows that are adapted to their programs, policies, and risk tolerances.</description>
										<content:encoded>&lt;p&gt;Each state eligibility office we talk to asks the same question: How do we move faster without increasing errors? The agentic AI pitch sounds compelling. The agent handles everything, humans step back, costs drop. But for environments where a bad decision means a family loses benefits or a state faces federal penalties, that pitch skips a few chapters.&lt;/p&gt; 
&lt;p&gt;States face financial sanctions when Supplemental Nutrition Assistance Program (SNAP) determination error rates exceed &lt;a href="https://www.ecfr.gov/current/title-7/subtitle-B/chapter-II/subchapter-C/part-275/subpart-G/section-275.23" target="_blank" rel="noopener"&gt;6%&lt;/a&gt;. A single misclassified household can trigger corrective action cascading across a program. These stakes are budgetary and concrete, not abstract.&lt;/p&gt; 
&lt;p&gt;Here’s the argument the autonomous agent pitch avoids: Most production deployments don’t start fully autonomous, and many won’t. We recommend that the architecture supports the reality by design. &lt;a href="https://aws.amazon.com/bedrock/agentcore/" target="_blank" rel="noopener"&gt;Amazon Bedrock AgentCore&lt;/a&gt; developed by &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; does.&lt;/p&gt; 
&lt;p&gt;In this post, we explore a human-in-the-loop (HITL) framework in the form of architectural patterns teams can use to introduce agentic AI incrementally into eligibility workflows that are adapted to their programs, policies, and risk tolerances.&lt;/p&gt; 
&lt;h2&gt;The autonomy progression model&lt;/h2&gt; 
&lt;p&gt;Teams deploying agentic AI for claims processing tend to fall on a spectrum. At one end, the agent drafts and a human approves everything. At the other, the agent decides autonomously on scoped case types with proven accuracy. The middle ground is supervised autonomy, and that’s where most production systems live for a long time. Trust is earned through measured accuracy, not declared by architecture.&lt;/p&gt; 
&lt;p&gt;In this middle framework, &lt;strong&gt;Assist mode&lt;/strong&gt; is where the agent drafts determinations and surfaces evidence. A caseworker reviews and approves each one. This is where you build trust, measure accuracy, and establish your baseline error rate.&lt;/p&gt; 
&lt;p&gt;In &lt;strong&gt;Supervised autonomy&lt;/strong&gt;, the agent handles routine cases independently. Edge cases, denials, and anything below a given confidence threshold still route to humans.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://cedarpolicy.com/en" target="_blank" rel="noopener"&gt;Cedar policies&lt;/a&gt; define the boundary between Assist and Supervised autonomy modes declaratively. Cedar is an open source policy language developed by AWS where you can write human-readable rules specifying what an agent is permitted or forbidden to do. Instead of burying authorization logic in application code, you express it as policy: If conditions A, B, and C are true, permit this action. If condition D is true, forbid it. The rules are auditable, able to be versioned, and separate from the agent itself.&lt;/p&gt; 
&lt;p&gt;In &lt;strong&gt;Full autonomy (selective)&lt;/strong&gt;, only case types where the agent has demonstrated sustained accuracy at or below the acceptable error rate qualify. You can expand the scope based on evidence, not ambition.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;table border="2"&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;Assist&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;Supervised&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;Autonomous&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Agent role&lt;/td&gt; 
   &lt;td&gt;Drafts determinations, surfaces evidence&lt;/td&gt; 
   &lt;td&gt;Approves routine cases autonomously&lt;/td&gt; 
   &lt;td&gt;Full decision authority on scoped types&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Human role&lt;/td&gt; 
   &lt;td&gt;Reviews and approves each decision&lt;/td&gt; 
   &lt;td&gt;Reviews edge cases and denials&lt;/td&gt; 
   &lt;td&gt;Monitors metrics, handles escalations&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Use when&lt;/td&gt; 
   &lt;td&gt;Building trust, establishing baseline&lt;/td&gt; 
   &lt;td&gt;Accuracy proven on routine cases&lt;/td&gt; 
   &lt;td&gt;Sustained accuracy below error threshold&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;How Amazon Bedrock AgentCore supports the spectrum&lt;/h2&gt; 
&lt;p&gt;A claims processing agent needs multiple capabilities working together. Here’s what matters, grouped by the question each capability answers:&lt;/p&gt; 
&lt;h3&gt;Know: What policy applies?&lt;/h3&gt; 
&lt;p&gt;&lt;a href="https://aws.amazon.com/bedrock/knowledge-bases/" target="_blank" rel="noopener"&gt;Amazon Bedrock Knowledge Bases&lt;/a&gt; ingests federal regulations, state manuals, and county procedures. The agent retrieves actual policy language rather than approximating it. &lt;a href="https://aws.amazon.com/blogs/machine-learning/amazon-bedrock-agentcore-memory-building-context-aware-agents/" target="_blank" rel="noopener"&gt;Amazon Bedrock AgentCore Memory&lt;/a&gt; persists context across sessions so the agent doesn’t start from zero on a reopened case. The case history, redetermination timelines, and pending verifications are all carried forward.&lt;/p&gt; 
&lt;h3&gt;Decide: What action is authorized?&lt;/h3&gt; 
&lt;p&gt;Authorization boundaries must be explicit, not implied. Cedar policies make them declarative. &lt;a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agents-tools-runtime.html" target="_blank" rel="noopener"&gt;Amazon Bedrock AgentCore Runtime&lt;/a&gt; reasons about the determination in an isolated environment. Cedar policies define what the agent can and can’t do. For example: Calculate eligibility, yes. Override a human denial, no. Modify policy rules, no. Access cases outside its caseload, no. Cedar also scopes authority per program. This can apply to decisions such as authorizing the agent for making SNAP determinations, but making it recommend-only for Medicaid.&lt;/p&gt; 
&lt;h3&gt;Connect: How does it reach external systems?&lt;/h3&gt; 
&lt;p&gt;&lt;a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway.html" target="_blank" rel="noopener"&gt;Amazon Bedrock AgentCore Gateway&lt;/a&gt; routes tool calls through a single managed entry point, such as case management systems, document services, state wage databases, and federal verification hubs. &lt;a href="https://aws.amazon.com/bedrock/guardrails/" target="_blank" rel="noopener"&gt;Amazon Bedrock Guardrails&lt;/a&gt; helps prevent personally identifiable information (PII) leakage, block prompt injection, and enforce topic boundaries.&lt;/p&gt; 
&lt;h3&gt;Trust: How do humans stay in control?&lt;/h3&gt; 
&lt;p&gt;Oversight is the mechanism that makes autonomy possible. &lt;a href="https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability.html" target="_blank" rel="noopener"&gt;Amazon Bedrock AgentCore Observability&lt;/a&gt; tracks each determination through the full reasoning chain. Evaluation scores decisions against ground truth and can detect drift within days. &lt;a href="https://aws.amazon.com/step-functions/" target="_blank" rel="noopener"&gt;AWS Step Functions&lt;/a&gt; embeds agentic reasoning inside workflows with human approval gates. &lt;a href="https://aws.amazon.com/lambda/" target="_blank" rel="noopener"&gt;AWS Lambda&lt;/a&gt; interceptors evaluate each action in real time and escalate dynamically.&lt;/p&gt; 
&lt;table border="2"&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Group&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;Question&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;Components&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Know&lt;/td&gt; 
   &lt;td&gt;What policy applies?&lt;/td&gt; 
   &lt;td&gt;Amazon Bedrock Knowledge Bases, Amazon Bedrock AgentCore Memory&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Decide&lt;/td&gt; 
   &lt;td&gt;What action is authorized?&lt;/td&gt; 
   &lt;td&gt;Amazon Bedrock AgentCore Runtime, Cedar policies&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Connect&lt;/td&gt; 
   &lt;td&gt;How does it reach external systems?&lt;/td&gt; 
   &lt;td&gt;Amazon Bedrock AgentCore Gateway, Amazon Bedrock Guardrails&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Trust&lt;/td&gt; 
   &lt;td&gt;How do humans stay in control?&lt;/td&gt; 
   &lt;td&gt;Amazon Bedrock AgentCore Observability, evaluation, AWS Step Functions, AWS Lambda&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;Three human-in-the-loop mechanisms&lt;/h2&gt; 
&lt;p&gt;This framework provides three patterns for keeping humans in the loop at the right points in a claims workflow.&lt;/p&gt; 
&lt;h3&gt;1. Cedar policies as approval gates&lt;/h3&gt; 
&lt;p&gt;The same policy that grants autonomous authority on routine cases can require human sign-off on exceptions. The agent does the cognitive work by gathering evidence, calculating eligibility, and drafting a determination, but the final action waits for confirmation when the policy demands it. Cedar’s forbid-beats-permit semantics make this a direct expression of policy rather than a workaround.&lt;/p&gt; 
&lt;p&gt;The following Cedar policy example shows how you could scope autonomous approval for routine SNAP renewals while requiring human review when income changes are detected:&lt;/p&gt; 
&lt;pre&gt;&lt;code&gt;// Permit autonomous processing for routine SNAP renewals
// where no income change is detected and confidence is high
permit (
  principal == EligibilityAgent::"snap-claims-agent",
  action == Action::"approve_determination",
  resource is Case
)
when {
  resource.program == "SNAP" &amp;amp;&amp;amp;
  resource.case_type == "renewal" &amp;amp;&amp;amp;
  resource.income_change_detected == false &amp;amp;&amp;amp;
  context.confidence_score &amp;gt;= 0.92
};
 
// Forbid autonomous approval when income has changed.
// This forces the case to a human reviewer.
forbid (
  principal == EligibilityAgent::"snap-claims-agent",
  action == Action::"approve_determination",
  resource is Case
)
when {
  resource.income_change_detected == true
};&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;In this example, the permit policy allows the agent to approve routine SNAP renewals only when no income change is detected and the model confidence score meets the 92% threshold. The forbid policy overrides any permit when income has changed, routing the case to a human caseworker. Because Cedar uses forbid-beats-permit semantics, a single forbid policy is sufficient to block autonomous action regardless of other permits in the policy set.&lt;/p&gt; 
&lt;h3&gt;2. AWS Step Functions for workflow-level control&lt;/h3&gt; 
&lt;p&gt;In this pattern, the agent handles high-volume cognitive tasks such as evidence gathering, eligibility calculation, and document assembly. The workflow pauses at a defined checkpoint. A human reviews the determination. Execution continues only after approval. You get AI throughput on low-risk work and human judgment where it matters.&lt;/p&gt; 
&lt;h3&gt;3. AWS Lambda interceptors for dynamic escalation (design pattern)&lt;/h3&gt; 
&lt;p&gt;Unlike Cedar policies and AWS Step Functions, which are product features you configure, AWS Lambda interceptors are an architectural design pattern you implement yourself. You write AWS Lambda functions that sit in the agent’s action path and evaluate each action in real time.&lt;/p&gt; 
&lt;p&gt;This provides fine-grained, dynamic escalation logic without hard-coding each edge case. For example, if the agent is about to deny benefits to a household with children under 5, escalate to a supervisor. These rules incorporate context the agent itself surfaces, giving teams dynamic escalation logic that adapts as policy evolves.&lt;/p&gt; 
&lt;h2&gt;Why this matters now&lt;/h2&gt; 
&lt;p&gt;Caseloads outpace hiring year over year. Caseworker turnover exceeds 30% in some states according to &lt;a href="https://www.casey.org/turnover-costs-and-retention-strategies/" target="_blank" rel="noopener"&gt;workforce surveys&lt;/a&gt; and &lt;a href="https://acf.gov/opre/report/national-survey-child-and-adolescent-well-being-iii-workforce-study-reasons-child" target="_blank" rel="noopener"&gt;federal research&lt;/a&gt;. Policy complexity increases each legislative session. Missed redetermination deadlines mean families lose coverage, agencies face audit findings, and program integrity erodes.&lt;/p&gt; 
&lt;p&gt;The framework discussed in this post gives caseworkers an agent that handles the research, retrieval, calculation, and documentation so human judgment goes toward the cases that actually need it.&lt;/p&gt; 
&lt;p&gt;An agent designed to process the majority of routine redeterminations autonomously while routing exceptions, denials, and low-confidence cases to caseworkers is a force multiplier. It helps keep error rates within federal tolerance while clearing the backlog that causes missed deadlines. Families can get answers faster, caseworkers can spend time on cases that need human judgment, and agencies can maintain the public trust that makes these programs work.&lt;/p&gt; 
&lt;h2&gt;Get started&lt;/h2&gt; 
&lt;p&gt;Ready to explore how HITL patterns can apply to your agency’s eligibility workflows? Start with these three components:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Amazon Bedrock AgentCore&lt;/strong&gt; – Build, deploy, and manage AI agents with runtime isolation and observability.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Cedar policy language&lt;/strong&gt; – Declarative authorization for fine-grained agent permissions. Use Cedar to define what your agent can and can’t do per program and case type.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;AWS Step Functions&lt;/strong&gt; – Embed agentic reasoning inside HITL workflows. Design checkpoints where human review is required before the agent proceeds.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;You can contact your AWS account team to discuss a pilot, or visit the &lt;strong&gt;Amazon Bedrock AgentCore Documentation&lt;/strong&gt; to start building.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>AWS and OST Eastern Switzerland University of Applied Sciences: An Innovation Factory for Swiss Industry</title>
		<link>https://aws.amazon.com/blogs/publicsector/aws-and-ost-eastern-switzerland-university-of-applied-sciences-an-innovation-factory-for-swiss-industry/</link>
		
		<dc:creator><![CDATA[Christoph Schnidrig]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 16:42:17 +0000</pubDate>
				<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[Amazon Managed Grafana]]></category>
		<category><![CDATA[AWS IoT Greengrass]]></category>
		<category><![CDATA[AWS IoT SiteWise]]></category>
		<category><![CDATA[Industries]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">264d4c6bdb2e1eb796754deacd11d3aa2c0e2b9a</guid>

					<description>Learn what Amazon Web Services (AWS) and Eastern Switzerland University of Applied Sciences (OST) are now tackling together as part of a new collaboration under the AWS Cloud Innovation Lab program.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32246 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/30/AWS-and-OST-Eastern-Switzerland-University-of-Applied-Sciences-An-Innovation-Factory-for-Swiss-Industry.png" alt="AWS and OST Eastern Switzerland University of Applied Sciences: An Innovation Factory for Swiss Industry" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;How cloud technology and artificial intelligence reach the production line directly – and why a university of applied sciences is the ideal place for it.&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;In most factories, production machines, measurement stations, and robots from various vendors stand side by side. Often, however they don’t communicate with each other. Anyone looking to leverage artificial intelligence to create value from this data – whether to reduce scrap rates or predict downtime – first needs a unified data foundation. This is exactly the problem that Amazon Web Services (AWS) and Eastern Switzerland University of Applied Sciences (OST) are now tackling together as part of a new collaboration under the &lt;a href="https://aws.amazon.com/government-education/cloud-innovation-centers/" target="_blank" rel="noopener"&gt;AWS Cloud Innovation Lab &lt;/a&gt;program.&lt;/p&gt; 
&lt;h2&gt;A data platform for the smart factory&lt;/h2&gt; 
&lt;p&gt;The &lt;a href="https://www.ost.ch/de/forschung-und-dienstleistungen/technik/maschinentechnik/iwk-institut-fuer-werkstofftechnik-und-kunststoffverarbeitung" target="_blank" rel="noopener"&gt;IWK – Institute for Materials Science and Plastics Processing&lt;/a&gt; at OST has been developing innovative solutions for over 20 years in collaboration with a network of Swiss industrial companies and international research partners, with complementary core competencies in advanced materials, production technologies, and component design. Around 60 staff members work with a state-of-the-art machine park that is available to companies looking to test new materials, processes, technologies before investing in their own production capabilities.&lt;/p&gt; 
&lt;p&gt;At its Rapperswil-Jona campus, OST is expanding this collaboration with industry into an Innovation Factory. Unlike a traditional research lab, this interdisciplinary center directly connects real-world manufacturing technologies – injection molding, additive manufacturing, metal machining, 3D printing – with robotics, AI, and data analytics. Companies can bring their own challenges and develop solutions jointly with the research team. Few facilities in Switzerland offer this breadth.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/30/IWK-Techpark-in-Rapperswil-Jona.jpg" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32252 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/30/IWK-Techpark-in-Rapperswil-Jona.jpg" alt="Photo of factory" width="1430" height="609"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;IWK Techpark in Rapperswil-Jona: State-of-the-art manufacturing technology for research and industry.&lt;/em&gt;&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;“Before our data converged on local laptops and servers – difficult to share, and no foundation to rapidly leverage new technologies like AI. On top of that, it’s nearly impossible to take a good prototype into production at an industry partner’s site,” says Prof. Dr. Frank Ehrig, Director of IWK&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;As manufacturing specialists, the IWK team and their partners don’t want to spend their time building IT infrastructure from scratch. With AWS as the cloud provider, this infrastructure is production-ready and scalable from day one – serving as the foundation for the Innovation Factory and for every industry project that emerges from it.&lt;/p&gt; 
&lt;h2&gt;The first showcase project&lt;/h2&gt; 
&lt;p&gt;What this looks like in practice is demonstrated by the first showcase project in the Innovation Factory – representative of many other manufacturing processes to come. As the initial use case, we’re connecting a complete injection molding production cell to the cloud: the injection molding machine itself (KraussMaffei), mold temperature control and in-mold sensing (Kistler), laser marking for individual part identification (Matriq), a precision scale (Kern), and a camera for visual quality inspection (Keyence). Six data sources, multiple different protocols and data formats – and ultimately one unified data platform.&lt;/p&gt; 
&lt;p&gt;Based on &lt;a href="https://aws.amazon.com/greengrass/" target="_blank" rel="noopener"&gt;AWS IoT Greengrass&lt;/a&gt; – software that runs on an edge device directly at the plant and seamlessly connects it with the AWS Cloud – and &lt;a href="https://aws.amazon.com/iot-sitewise/" target="_blank" rel="noopener"&gt;AWS IoT SiteWise&lt;/a&gt; for structuring and visualizing industrial data, three concrete applications are built on top:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Real-time quality dashboards&lt;/strong&gt; with &lt;a href="https://aws.amazon.com/grafana/" target="_blank" rel="noopener"&gt;Amazon Managed Grafana&lt;/a&gt; give machine operators and production managers continuous visibility into current production status.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;AI-powered quality inspection directly at the machine&lt;/strong&gt; detects deviations immediately and derives recommendations for ongoing production – without a round-trip to the cloud. Less time critical, more complex analyses are handled by &lt;a href="https://aws.amazon.com/bedrock/" target="_blank" rel="noopener"&gt;Amazon Bedrock&lt;/a&gt; in the cloud, which automatically delivers root cause analysis.&lt;/li&gt; 
 &lt;li&gt;A&lt;strong&gt; digital product passport&lt;/strong&gt; gives each manufactured part its complete production history via QR code: process data, quality inspection results, and material traceability.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/30/The-production-cell-mold-temperature-control.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32251 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/30/The-production-cell-mold-temperature-control.png" alt="Architecture of AWS Cloud and production cell, factory floor" width="1215" height="612"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;The production cell (mold temperature control, in-mold sensors, laser marking, injection molding machine, scale, camera) transmits its data to AWS via various protocols. The cloud stores and synchronized the data, AI/ML models analyze it, and the results are displayed as dashboards in the browsers of machine operators and production managers.&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;Especially valuable for IWK: AWS cloud experts and the IWK team develop the infrastructure and application code jointly- using AI-assisted software development with &lt;a href="PLACEHOLDER_URL" target="_blank" rel="noopener noreferrer"&gt;Kiro&lt;/a&gt;, which drastically shortens development cycles. In the process, the IWK team itself undergoes a steep learning curve and can apply this knowledge to any number of additional production processes in the future – well beyond this first project.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;“Kiro connected straight to the running hardware and debugged it systematically. What would otherwise have been weeks of manual troubleshooting was done in a single session.”, says Ramon Iten, OT Engineer, IWK&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;h2&gt;Why this collaboration advances Swiss industry&lt;/h2&gt; 
&lt;p&gt;This collaboration is more than a single project. It’s part of our commitment to making cloud and AI technology directly available where Swiss industrial companies research, test, and train. Rather than offering technology only from a distance, we’re investing in an institution that has been bridging research and practice for years.&lt;/p&gt; 
&lt;p&gt;Not only companies benefit, but also the next generation of engineers: OST students work directly on this project, and in future bachelor’s and master’s theses they’ll use the same cloud and AI technologies deployed in industry – hands-on education that starts on the shop floor.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;“Swiss industry is renowned for its innovation – and for its exacting standards of quality and precision. In IWK, we’ve found a partner that has been living exactly this interplay between research and industrial practice for over 20 years. Together, we’re bringing AWS technology directly into applied research, right to the machine, where companies can experience it firsthand. What emerges is not a pilot project destined for the shelf, but a model that Swiss companies can adopt themselves,” says Felix Schoenherr, Country Manager, AWS Switzerland.&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;h2&gt;Get involved&lt;/h2&gt; 
&lt;p&gt;OST’s Innovation Factory is open to companies – regardless of how far along you are in your own digitalization journey:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Services&lt;/strong&gt; – short-term support, available at any time: consulting, material and failure analysis, or access to IWK’s state-of-the-art machine and equipment park.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Industry R&amp;amp;D Projects&lt;/strong&gt; – bring your own challenge, whether it involves new materials, products, or technologies. Initial trials can be conducted directly at IWK, with confidentiality guaranteed.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Publicly Funded R&amp;amp;D Projects&lt;/strong&gt; – for initiatives with greater innovation potential and risk: from &lt;a href="PLACEHOLDER_URL" target="_blank" rel="noopener noreferrer"&gt;Innosuisse&lt;/a&gt; innovation vouchers (feasibility analysis, CHF 15,000, 2–3 months) to multi-year Innosuisse or EU projects.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For more information or to discuss a specific project, visit the &lt;a href="https://www.ost.ch/Innovationsfabrik" target="_blank" rel="noopener"&gt;OST Innovation Factory website&lt;/a&gt;. If you’d like to learn more about the AWS technologies behind this project or discuss your own initiative with us, &lt;a href="https://aws.amazon.com/contact-us/" target="_blank" rel="noopener"&gt;contact your AWS team&lt;/a&gt;.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>How to secure communications beyond encryption with AWS Wickr</title>
		<link>https://aws.amazon.com/blogs/publicsector/how-to-secure-communications-beyond-encryption-with-aws-wickr/</link>
		
		<dc:creator><![CDATA[Chris O’Rourke]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 14:57:07 +0000</pubDate>
				<category><![CDATA[Amazon EC2]]></category>
		<category><![CDATA[AWS Fargate]]></category>
		<category><![CDATA[AWS Wickr]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Security, Identity, & Compliance]]></category>
		<category><![CDATA[AWS Public Sector]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Wickr]]></category>
		<guid isPermaLink="false">83b718e6c63d824a8354890fb66a32f7855f5f1f</guid>

					<description>Read this post to learn about AWS Wickr, a messaging and collaboration service that protects messaging, calling, file sharing, screen sharing, and location sharing with 256-bit end-to-end encryption (E2EE). Wickr combines advanced security for sensitive communications, administrative controls for user and policy management, and data retention for auditing and regulatory needs.</description>
										<content:encoded>&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2025/10/29/Secure-comms-image-for-blog.png"&gt;&lt;img loading="lazy" class="aligncenter size-full wp-image-28787" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2025/10/29/Secure-comms-image-for-blog.png" alt="A person is holding a cell phone and typing on a laptop. The laptop screen shows a green lock symbol. Concept of security and protection" width="2912" height="1632"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;In response to a rise in cyber espionage activity conducted by nation-state affiliated threat actors, the Cybersecurity and Infrastructure Security Agency (CISA) has recommended using encrypted messaging applications to protect sensitive communications.&lt;/p&gt; 
&lt;p&gt;CISA’s &lt;a href="https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf" target="_blank" rel="noopener"&gt;Mobile Communications Best Practice Guidance&lt;/a&gt; advises government, military, and political personnel to “adopt a free messaging application for secure communications that guarantees end-to-end encryption.”&lt;/p&gt; 
&lt;h2&gt;Encryption alone is not enough&lt;/h2&gt; 
&lt;p&gt;As adoption of these applications increases, it’s important&amp;nbsp;not to lose sight of recordkeeping and compliance obligations. Public-key cryptography pioneer Whitfield Diffie alluded to the recent US government group chat leak during the &lt;a href="https://www.youtube.com/watch?v=8GkJ6vX-7KY" target="_blank" rel="noopener"&gt;Cryptographer’s Panel&lt;/a&gt; at RSA Conference 2025. The use of an encrypted consumer messaging application to communicate classified information, he noted, broke archiving laws. Because many of these tools use 256-bit Advanced Encryption Standard (AES) encryption, which is “good enough” to protect sensitive information, he predicted an increase in the use of consumer applications in unapproved ways.&lt;/p&gt; 
&lt;p&gt;Consumer messaging applications are convenient, but they aren’t designed for national security or regulated environments. They don’t go beyond encryption to deliver the data retention and policy enforcement controls that are needed to secure mission-critical communications while meeting compliance requirements.&lt;/p&gt; 
&lt;h2&gt;How AWS can help&lt;/h2&gt; 
&lt;p&gt;&lt;a href="https://aws.amazon.com/wickr/"&gt;AWS Wickr&lt;/a&gt; is a messaging and collaboration service that protects messaging, calling, file sharing, screen sharing, and location sharing with 256-bit end-to-end encryption (E2EE). Wickr combines advanced security for sensitive communications, administrative controls for user and policy management, and data retention for auditing and regulatory needs.&lt;/p&gt; 
&lt;p&gt;With Wickr, communications are encrypted locally on devices and remain undecipherable in transit. Every call, message, and file is encrypted with a unique secret key, and no one but intended recipients can decrypt them. It’s straightforward for personnel and teams to use and to access and download on iOS, Android, macOS, Windows, and Linux devices.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;“For many federal agencies and organizations, having the ability to securely communicate and share information—whether in an office or out in the field, with the ability to translate languages in real-time—is key to mission success. AWS Wickr helps our customers collaborate securely with end-to-end encryption across multiple use cases, while also driving AI innovation and providing the administrative controls needed to support sensitive and regulated workloads.”&lt;/em&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;em&gt;–Dave Levy, vice president, worldwide public sector at AWS&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;Wickr is Department of Defense (DoD) &lt;a href="https://aws.amazon.com/blogs/messaging-and-targeting/aws-wickr-achieves-dod-impact-level-4-and-5-authorization/"&gt;Cloud Computing Security Requirements Guide Impact Level 5 (CC SRG IL5)&lt;/a&gt; and Federal Risk and Authorization Management Program (FedRAMP) &lt;a href="https://aws.amazon.com/blogs/security/aws-wickr-achieves-fedramp-high-authorization/"&gt;High authorized&lt;/a&gt; in the AWS GovCloud (US-West) Region. It also meets compliance programs and standards such as Health Insurance Portability and Accountability Act (HIPAA) eligibility, International Organization for Standardization (ISO) 27001, and System and Organization Controls (SOC) 1, 2, and 3.&lt;/p&gt; 
&lt;h2&gt;Meeting CISA recommendations&lt;/h2&gt; 
&lt;p&gt;A &lt;a href="https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance" target="_blank" rel="noopener"&gt;November 2025 update&lt;/a&gt; to CISA’s recommendations includes additional guidance aimed at combating the use of commercial spyware to target users of messaging applications. Wickr features and capabilities align with the following&amp;nbsp;CISA mobile communications best practices, and can help you enhance the protection of sensitive data against threats:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;E2EE on by default for all communications and metadata&lt;/li&gt; 
 &lt;li&gt;Text interoperability across operating systems&lt;/li&gt; 
 &lt;li&gt;No reliance on SMS-based authentication&lt;/li&gt; 
 &lt;li&gt;Integration with single sign-on for phishing-resistant authentication&lt;/li&gt; 
 &lt;li&gt;Burn-on-read and expiration timers for added security and privacy&lt;/li&gt; 
 &lt;li&gt;Continuous security updates and vulnerability management&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Centralized management&lt;/h2&gt; 
&lt;p&gt;Wickr offers a centralized management console you can use to monitor network security in real time, enforce role-based access controls and security policies, manage message retention periods in accordance with your requirements, and generate detailed compliance and audit reports.&lt;/p&gt; 
&lt;p&gt;Fine-grained administrative controls allow administrators to add and remove users, and you can organize them into security groups with restricted access to features and content at their level. You can apply policies to each group that are custom-tailored to meet desired outcomes. Files can be uploaded and organized in folders, and a view-only mode can be configured for specific security groups to prevent downloading.&lt;/p&gt; 
&lt;h2&gt;External collaboration&lt;/h2&gt; 
&lt;p&gt;Unlike consumer messaging apps that allow the registration of anyone with a phone number or username—and don’t enforce limits on who can be invited to a conversation—Wickr federation and guest access features promote secure collaboration with outside parties. Wickr network administrators can enable or disable guest access and restrict communication with external networks by using allow lists that limit communication to approved network IDs. Groups of users can be assigned to specific federation rules, and there is a differentiated UX treatment for conversations that include out-of-network users.&lt;/p&gt; 
&lt;h2&gt;Data retention&lt;/h2&gt; 
&lt;p&gt;Administrators can configure and apply data retention to both internal and external communications in a Wickr network. This includes conversations with guest users, external teams, and other partner networks, so you can retain messages and files sent to and from the organization. Data retention is implemented as an always-on recipient that is added to conversations, similar to the blind carbon copy (BCC) feature in email. AWS Wickr offers two data retention deployment options: Serverless and Bot-based. Serverless data retention is managed by AWS and uses your AWS Key Management Service (KMS) key to store the data in Amazon S3. Bot-based data retention requires a Docker host, which can be on-premises, on an &lt;a href="https://aws.amazon.com/ec2/" target="_blank" rel="noopener"&gt;Amazon EC2&lt;/a&gt;&amp;nbsp;instance, or at a location of your choice. See&amp;nbsp;&lt;a href="https://docs.aws.amazon.com/wickr/latest/adminguide/data-retention.html" target="_blank" rel="noopener"&gt;AWS Wickr Documentation&lt;/a&gt;&amp;nbsp;to choose the&amp;nbsp;method&amp;nbsp;that&amp;nbsp;best fits your organization’s infrastructure and compliance requirements. AWS&amp;nbsp;can’t decrypt conversations, giving you complete control over your data.&lt;/p&gt; 
&lt;h2&gt;Digital sovereignty&lt;/h2&gt; 
&lt;p&gt;When you use Wickr in an &lt;a href="https://aws.amazon.com/about-aws/global-infrastructure/regions_az/"&gt;AWS Region&lt;/a&gt; of your choice, all the infrastructure required to operate it and all the conversations in your network are hosted within that Region. Wickr is among the &lt;a href="https://aws.amazon.com/blogs/security/announcing-initial-services-available-in-the-aws-european-sovereign-cloud-backed-by-the-full-power-of-aws/"&gt;services&lt;/a&gt; that will be featured in the &lt;a href="https://aws.eu/"&gt;AWS European Sovereign Cloud&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;Wickr is currently available in the following AWS Regions:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;US East (N. Virginia)&lt;/li&gt; 
 &lt;li&gt;Asia Pacific (Malaysia, Singapore, Sydney, and Tokyo)&lt;/li&gt; 
 &lt;li&gt;Canada (Central)&lt;/li&gt; 
 &lt;li&gt;Europe (Frankfurt, London, and Zurich)&lt;/li&gt; 
 &lt;li&gt;AWS GovCloud (US-West)&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Wickr and generative AI&lt;/h2&gt; 
&lt;p&gt;&lt;a href="https://docs.aws.amazon.com/pdfs/wickr/latest/wickrio/wickrio.pdf"&gt;Wickr agents&lt;/a&gt; can help you extend the E2EE capabilities of Wickr to other applications and automate workflows. They function as standard users and facilitate integrations with external services, communication tools such as Slack, Discord, or Matrix-compatible endpoints, and specialized solutions such as the Android Team Awareness Kit (ATAK) through a dedicated plugin.&lt;/p&gt; 
&lt;p&gt;Using Wickr bots, your technical teams can build and deploy agent integrations within your Wickr network to bring AWS &lt;a href="https://aws.amazon.com/ai/generative-ai/"&gt;generative AI services&lt;/a&gt; to edge devices in a straightforward chat interface, opening up a variety of use cases:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Get answers with a Wickr LLM agent&lt;/strong&gt; – Build a Wickr LLM agent integration with &lt;a href="https://aws.amazon.com/bedrock/"&gt;Amazon Bedrock&lt;/a&gt; using sample code. The bot can be configured not to store your questions or the answers it provides.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Recognize images&lt;/strong&gt; – Build an agent for identifying objects, scenes, actions, and more in images uploaded through the chat interface using &lt;a href="https://aws.amazon.com/rekognition/"&gt;Amazon Rekognition&lt;/a&gt;. Capabilities such as object detection and facial recognition can be used to process photos or videos captured in the field and provide alerts or metadata to users.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Transcribe speech&lt;/strong&gt; – Integrate an agent with &lt;a href="https://aws.amazon.com/transcribe/"&gt;Amazon Transcribe&lt;/a&gt; to automatically transcribe voice messages sent through Wickr and respond through text.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Translate messages&lt;/strong&gt; – Build a multilingual agent that translates messages between languages using &lt;a href="https://aws.amazon.com/translate/"&gt;Amazon Translate&lt;/a&gt; in support of global collaboration.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Analyze audio&lt;/strong&gt; – Use agents with services such as &lt;a href="https://aws.amazon.com/polly/"&gt;Amazon Polly&lt;/a&gt; or Amazon Transcribe to analyze audio from bodycams, drones, and other sources, and automatically generate transcripts, identify speakers, and detect sounds of interest.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Teams operating in high-stakes environments can ingest signal and sensor data through an API agent and integrate real-time alerts. This allows mission-critical messages to be rapidly disseminated to both federated and nonfederated Wickr users, reducing tactical latency and enhancing decision-making capabilities.&lt;/p&gt; 
&lt;h2&gt;Protect your most sensitive conversations&lt;/h2&gt; 
&lt;p&gt;&lt;a href="https://aws.amazon.com/blogs/security/importance-of-encryption-and-how-aws-can-help/"&gt;Encryption&lt;/a&gt; is a critical component of a defense-in-depth security strategy, but it’s not a standalone solution for secure and compliant communications. AWS Wickr can advance your organization’s efforts to protect sensitive message content—including text, files, audio, and video—by combining E2EE with the broader protections needed to help meet requirements as cyber threats and regulations change. With enterprise-grade security features, granular administrative controls, and flexible integration capabilities, Wickr supports you as you follow the guidance set out by CISA, use generative AI to accelerate collaboration, and move beyond encryption to close the security and compliance gaps presented by consumer messaging applications.&lt;/p&gt; 
&lt;p&gt;Want to learn more about how AWS helps public sector organizations deploy AI-driven solutions? &lt;a href="https://aws.amazon.com/government-education/contact/"&gt;Connect with the AWS Public Sector Team today&lt;/a&gt;.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>Army R&amp;D team uses agentic engineering to build secure, compliant code</title>
		<link>https://aws.amazon.com/blogs/publicsector/army-rd-team-uses-agentic-engineering/</link>
		
		<dc:creator><![CDATA[Michael Baker]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 20:36:31 +0000</pubDate>
				<category><![CDATA[AWS GovCloud (US)]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">366d6f02c5b2de1ef9cd505fba35df5b424ba1a4</guid>

					<description>In this post, we explain how the U.S. Army cut critical software delivery process times by up to 75% using AWS GovCloud (US) and AI-powered automation and how your R&amp;amp;D program can overcome lengthy authorization cycles, distributed team collaboration challenges, and Impact Level 5 (IL5) compliance requirements with SPDS.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32174 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/20/Army-RD-team-uses-agentic-engineering-to-build-secure-compliant-code.png" alt="Army R&amp;amp;D team uses agentic engineering to build secure, compliant code" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;Modern warfare demands software that moves at the speed of the mission. For U.S. defense research and development (R&amp;amp;D) organizations, this means building, testing, and fielding software faster than ever while meeting some of the most complex security and compliance requirements in the federal government. Traditional infrastructure approaches designed for waterfall development cycles can’t keep pace with the iterative, continuous nature of modern software delivery.&lt;/p&gt; 
&lt;p&gt;A defense-focused R&amp;amp;D secure coding solution was purpose-built for the U.S. Army to solve exactly this problem. The foundation is a more secure, cloud-based &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; landing zone that enables agile software development at scale without sacrificing compliance, security, or mission focus. In this post, we explain how developers reduced critical software delivery process times by up to 75% using &lt;a href="https://aws.amazon.com/govcloud-us/" target="_blank" rel="noopener"&gt;AWS GovCloud (US)&lt;/a&gt; and AI-powered agentic engineering using this solution, how it empowers teams by accelerating authorization cycles across distributed teams, and how it is architected to meet Impact Level 5 (IL5) compliance requirements. Significant benefits of agentic engineering are shown in the graphic below: faster software delivery, shorter timelines from authorization to operate to MVP in production, and significantly less time needed to scan for security compliance.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/11/Figure1.jpg" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32345 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/11/Figure1.jpg" alt="75 percent reduction in software delivery process time" width="1159" height="225"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 1 Key outcomes include faster software delivery, faster start from authorization to Minimum Viable Product, and faster security compliance reviews using agentic software engineering.&lt;/em&gt;&lt;/p&gt; 
&lt;h3&gt;Modernizing defense R&amp;amp;D without compromising security&lt;/h3&gt; 
&lt;p&gt;Defense R&amp;amp;D organizations face challenges that commercial cloud solutions alone can’t address. Programs must meet IL5 compliance standards requiring rigorous controls across every layer of the stack. Developers, program managers, and defense industry partners don’t all work from the same network. They’re spread across different locations and classification environments.&lt;/p&gt; 
&lt;p&gt;Cyber, safety, and operational requirements have historically led teams into waterfall approaches to define system requirements in detail before building. This approach lacks the agility to respond to changing environments, missions, and technologies. That means they can’t realize the full benefits of Development-Security-Operations (DevSecOps) practices. Legacy infrastructure limits collaboration across cross-functional teams and partner companies, slowing time to capability.&lt;/p&gt; 
&lt;p&gt;Defense developers are taking a new approach to software acquisition that embraces agile principles and DevSecOps best practices. That requires a modern infrastructure foundation to support iterative, continuous software development.&lt;/p&gt; 
&lt;h3&gt;Secure development solution to build compliant software&lt;/h3&gt; 
&lt;p&gt;The Army development team created a secure development solution built on AWS GovCloud (US) Landing Zone that enforces Zero Trust and enables scalable collaborative coding, as shown in the diagram below.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/11/Figure21.jpg" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32347 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/11/Figure21.jpg" alt="Zero Trust and enables scalable collaborative coding" width="1131" height="626"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;This DevSecOps solution with Zero Trust enables more secure, scalable software collaboration. At the center of everything is the Zero Trust Access Gateway. This is the single point of policy enforcement. Every user, every device, and every session is continuously verified. There’s no implicit trust based on network location.&lt;/p&gt; 
&lt;p&gt;The entire solution operates within a defined Authority To Operate (ATO) Boundary authorized for IL5 data and workloads. By having a solution-level ATO, individual programs don’t need to go through the full 12-month authorization process independently. They inherit the solution’s security posture. New partners and tenants can start developing and testing software immediately without lengthy onboarding delays.&lt;/p&gt; 
&lt;p&gt;On the left side, partner access means partner companies can connect. They come through the Zero Trust gateway, get verified, and then access only the specific project resources they’re authorized for.&lt;/p&gt; 
&lt;p&gt;Integrated testing connects the solution to external systems: hardware-in-the-loop sets, simulation environments, and test ranges. Code developed in this solution can be pushed directly to test infrastructure without manual transfer steps.&lt;/p&gt; 
&lt;p&gt;On the right, developer access is how government engineers connect. They use the same Zero Trust verification, same policy enforcement, and same experience, regardless of where they’re physically located. In this environment, collaboration is easier and software can be built faster to meet compliance.&lt;/p&gt; 
&lt;p&gt;Secure data exchange means users can move artifacts, source code, compiled binaries, test data, and media between environments and partners more securely. This is often the biggest bottleneck in collaborative projects, and this solution automates it. This links secure development with operations pipelines.&lt;/p&gt; 
&lt;h3&gt;Built on Landing Zone architecture on AWS&lt;/h3&gt; 
&lt;p&gt;Specific AWS GovCloud (US) infrastructure underpins the software coding landing zone, nesting layers of security to accelerate IL5 compliance and meet Zero Trust mandates.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;AWS GovCloud (US)&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;This is a physically isolated set of AWS Regions designed specifically for sensitive government workloads. AWS GovCloud (US) Regions are logically and physically administered exclusively by AWS personnel that are U.S. citizens. AWS GovCloud (US) meets Federal Risk and Authorization Management Program (FedRAMP) High and DoD IL5 requirements while providing AWS Services available in commercial Regions with additional compliance controls that the U.S. government requires. These workloads run in AWS GovCloud (US) to meet classification and data sovereignty requirements.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Landing Zone Accelerator on AWS&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;This provides the foundational multi-account architecture that organizes the cloud environment. The &lt;a href="https://aws.amazon.com/blogs/security/introducing-the-landing-zone-accelerator-on-aws-universal-configuration-and-lza-compliance-workbook/" target="_blank" rel="noopener"&gt;Landing Zone Accelerator&lt;/a&gt; serves as the blueprint for how accounts, networks, security controls, and governance policies are structured.&lt;/p&gt; 
&lt;p&gt;This open-source solution deploys the architecture automatically following AWS and DoW best practices while setting up organizational units, configuring centralized logging, enabling security services, and establishing network connectivity in a standardized, repeatable way. For software coding, the landing zone provides the scaffolding: separate accounts for each tenant, shared services accounts for common tools, a security account for centralized monitoring, and network accounts for connectivity.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;IL5 compliance&lt;/strong&gt; is achieved through built-in security controls and governance guardrails. Rather than configuring hundreds of security controls manually, the landing zone deploys them automatically. Service Control Policies prevent unauthorized actions, &lt;a href="https://aws.amazon.com/config/" target="_blank" rel="noopener"&gt;AWS Config&lt;/a&gt; rules continuously evaluate compliance, &lt;a href="https://aws.amazon.com/guardduty/" target="_blank" rel="noopener"&gt;Amazon GuardDuty&lt;/a&gt; monitors for threats, and &lt;a href="https://aws.amazon.com/cloudtrail/" target="_blank" rel="noopener"&gt;AWS CloudTrail&lt;/a&gt; logs every API call. If a tenant attempts a noncompliant action such as opening a port to the internet, guardrails prevent it automatically.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Zero Trust architecture integration&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;This integration replaces the traditional perimeter defense model where users inside the network are trusted. Zero Trust verifies every access request against the user’s identity, device posture, location, and behavior — every time, with no trusted network assumed. The Zero Trust capability provides cloud-based security to enforce these policies. Users connect to the solution where their identity is verified, device health is inspected, and access is granted only to the specific applications they’re authorized for.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Network-agnostic access&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;This is a direct result of Zero Trust. Developers no longer need a government-issued laptop on a government network with a hardware VPN token. They authenticate through the Zero Trust gateway, prove their identity and device policy compliance, and gain access. This is transformative for defense partners who previously required dedicated circuits to collaborate, which took time to provision and access.&lt;/p&gt; 
&lt;blockquote&gt;
 &lt;p&gt;&lt;strong&gt;AWS services powering the secure development solution&lt;/strong&gt;&lt;/p&gt; 
 &lt;p&gt;&lt;strong&gt;Landing Zone Accelerator on AWS • AWS Organizations • AWS Config • AWS CloudTrail • AWS Transit Gateway • Amazon Elastic Kubernetes Service • AWS CloudFormation&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;h3&gt;Adding agentic workflows to accelerate mission impact and innovation&lt;/h3&gt; 
&lt;p&gt;The secure coding solution’s landing zone is actively supporting DoW R&amp;amp;D programs today. Distributed teams collaborate securely and deliver software faster than legacy environments allowed. Programs that previously faced 12-month authorization and contracting cycles to spin up new cloud environments now deploy minimum viable products (MVPs) in as little as 3 months, which is a 75% reduction in time to capability. That speed matters. Partners can rapidly integrate frontline insights and deliver relevant software solutions to the field as mission requirements evolve.&lt;/p&gt; 
&lt;p&gt;The solution also provides a cloud-based digital engineering workspace that integrates cyber, safety, and airworthiness verification into the iterative agile process rather than treating them as end-of-cycle gates. For DoW programs, this is a critical distinction. Safety and airworthiness certification can’t be an afterthought. Building verification in from the start means teams avoid a compliance bottleneck right before fielding.&lt;/p&gt; 
&lt;p&gt;Most recently, the solution integrated multiple AI models on AWS GovCloud (US) to address two of the most time-intensive processes in defense software delivery. For Security Technical Implementation Guides (STIG) compliance automation, an AI agent autonomously processes code against all 286 STIG rules and produces a structured compliance report for human review. A process that previously took 3 weeks now completes in 2–3 hours, which isn’t an incremental improvement but a fundamentally different category of speed.&lt;/p&gt; 
&lt;p&gt;For agentic engineering workflows, a chat-based agent integrated with coding capabilities gives engineers the ability to query, synthesize, and report on program data using natural language. Tasks that previously required hours can now be completed in under 5 minutes. Future applications under exploration include ticket triage automation and AI-assisted code review.&lt;/p&gt; 
&lt;p&gt;Secure Development Solution demonstrated metrics that make a difference to accelerate secure coding for defense systems, as shown in the graphic below.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/11/Figure3.jpg" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32346 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/09/11/Figure3.jpg" alt="security compliance" width="1134" height="248"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 3 AI-assisted agentic engineering supports human decision making with data preparation for compliance automation and chat queries for DevSecOps&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;This AI-assisted collaboration delivers measurable mission impact with a 75% reduction in time to capability. That number isn’t theoretical. The team compressed what was traditionally a 12-month authorization and environment provisioning cycle into 3 months to deploy a MVP. Programs that previously spent their entire first year standing up coding environments now make and deploy code within their first 90 days.&lt;/p&gt; 
&lt;p&gt;A concrete example illustrates the impact: A specific R&amp;amp;D program involving distributed defense industrial partner teams needed to collaboratively build control software in a secure environment. Before the secure coding platform, getting those teams connected, authorized, and collaborating took the better part of a year. The Army team onboarded them into a shared workspace with appropriate access controls in weeks. Those teams now iterate on code together in real time with automated testing against hardware-in-the-loop systems.&lt;/p&gt; 
&lt;p&gt;The solution provides a cloud-based digital engineering workspace that goes beyond source code management to integrate modeling tools, simulation environments, and collaboration platforms—all within the IL5 boundary.&lt;/p&gt; 
&lt;p&gt;Critically, this agentic coding solution integrates cyber, safety, and other tests into the agile process with humans at the center. These aren’t afterthoughts or phase gates at the end: Automated checks run with every build. When a developer pushes code, the pipeline automatically evaluates it against cybersecurity requirements, safety constraints, and operational tests. Issues are caught and fixed in hours, not months. Government engineers can focus their time on human decision-making after the AI engineering workflows organize their data. Lessons learned can be continually added into the agentic engineering reviews, speeding the cycle while improving software quality and security compliance.&lt;/p&gt; 
&lt;h3&gt;A replicable model for secure coding&lt;/h3&gt; 
&lt;p&gt;The secure coding solution is more than a single program’s infrastructure. It’s a replicable model for how software-focused organizations can modernize software delivery while maintaining the security, compliance, and mission focus needed. The landing zone is designed to scale. Additional tenants and programs can onboard using the same standardized, repeatable architecture, reducing the time and cost of standing up compliant cloud infrastructure from months to weeks.&lt;/p&gt; 
&lt;p&gt;This more secure coding solution is architected to rapidly evolve while supporting the agentic engineering approach. New missions can expand to include modeling and simulation and technical documentation creation. New AI models can be integrated alongside emerging AWS GovCloud (US) capabilities such as &lt;a href="https://kiro.dev/" target="_blank" rel="noopener"&gt;Amazon Kiro&lt;/a&gt; for AI-assisted coding, &lt;a href="https://aws.amazon.com/quick/" target="_blank" rel="noopener"&gt;Amazon Quick&lt;/a&gt; for analysis, research, and report generation, and &lt;a href="https://aws.amazon.com/bedrock/agentcore/" target="_blank" rel="noopener"&gt;Amazon Bedrock AgentCore&lt;/a&gt; to deploy, monitor, and evaluate agent-based workflows. Collaborative engineers will be able to develop in the unclassified solution and push code to classified production environments.&lt;/p&gt; 
&lt;p&gt;The principles that make this environment replicable are straightforward. The architecture is network-agnostic and secure-by-design, with zero trust enforcement that works across any network or classification environment. Every capability is tied to a real program outcome, not technology for its own sake. And the solution is proven through real-world R&amp;amp;D programs, with support for acquisition development programs and generative AI use cases that demonstrate measurable impact at scale.&lt;/p&gt; 
&lt;h2&gt;AI-powered agentic engineering supports human decisions&lt;/h2&gt; 
&lt;p&gt;This case study shows how AI-powered agentic engineering supports humans in making effective, timely decisions to deliver needed defense capabilities. Other R&amp;amp;D organizations interested in modernizing their software development capabilities can explore how the secure coding environment on AWS enables more secure, agile DevSecOps at scale.&amp;nbsp;Whether you’re looking to accelerate delivery timelines, streamline compliance automation, or adopt cloud-based development practices, the AWS team is ready to support your cloud journey. The latest security configurations and best practices are provided for the &lt;a href="https://aws.amazon.com/blogs/security/introducing-the-landing-zone-accelerator-on-aws-universal-configuration-and-lza-compliance-workbook/" target="_blank" rel="noopener"&gt;Landing Zone Accelerator – Universal Configuration&lt;/a&gt;.&amp;nbsp;To learn more, visit &lt;a href="https://aws.amazon.com/govcloud-us/" target="_blank" rel="noopener"&gt;AWS GovCloud&lt;/a&gt; (US) or reach out to the team at AWS.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Model choice brings Mission Advantage to AWS GovCloud (US) customers</title>
		<link>https://aws.amazon.com/blogs/publicsector/ai-model-choice-is-now-a-mission-advantage-multiple-ai-models-available-in-aws-govcloud-us/</link>
		
		<dc:creator><![CDATA[Heather Crawford]]></dc:creator>
		<pubDate>Sun, 30 Aug 2026 14:10:12 +0000</pubDate>
				<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[Amazon Nova]]></category>
		<category><![CDATA[AWS GovCloud (US)]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">c3d9b1971decf0a029d47458ad3a486ce3c496a4</guid>

					<description>As part of AWS’s up to $50 billion commitment to deploy integrated AI and HPC cloud infrastructure for the U.S Government, we’re driving American AI innovation by expanding AI model choice in our AWS Government Regions. We’re excited to share that AWS GovCloud (US) now offers multiple AI model families through Amazon Bedrock, giving government customers, their supporting industrial base, and technology partners the AI model choice their missions demand.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32268 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/31/AI-Model-choice-brings-Mission-Advantage-to-AWS-GovCloud-US-customers-1.png" alt="AI Model choice brings Mission Advantage to AWS GovCloud (US) customers" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;h2&gt;Introduction&lt;/h2&gt; 
&lt;p&gt;From citizen services to national security, government agencies and their supporting industrial base rely on AI to deliver faster decisions, better mission and business outcomes, and protect national interests. But as AI becomes deeply mission-embedded, a strategic question emerges: are you choosing the best model for each mission, or defaulting to the one you typically use? Customers should never be locked into a single model, and democratizing access to the world’s best frontier AI models gives customers the freedom to innovate on their own terms. That means choosing the right model for the right task, adopting breakthroughs as they emerge, and maintaining continuity when conditions change. For government missions, that principle is even more critical. Model choice is how agencies stay in control of their own innovation, advance U.S. global AI leadership, and deliver on &lt;a href="https://www.ai.gov/action-plan" target="_blank" rel="noopener"&gt;America’s AI Action Plan&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;As part of AWS’s &lt;a href="https://aws.amazon.com/government-education/" target="_blank" rel="noopener"&gt;up to $50 billion commitment&lt;/a&gt; to deploy integrated AI and HPC cloud infrastructure for the U.S Government, we’re driving American AI innovation by expanding AI model choice in our AWS Government Regions. We’re excited to share that &lt;a href="https://aws.amazon.com/govcloud-us/" target="_blank" rel="noopener"&gt;AWS GovCloud (US)&lt;/a&gt; has expanded model families offered through &lt;a href="https://aws.amazon.com/bedrock/" target="_blank" rel="noopener"&gt;Amazon Bedrock&lt;/a&gt;, giving government customers, their supporting industrial base, and technology partners the AI model choice their missions demand.&amp;nbsp;Model choice is here today. &lt;a href="https://aws.amazon.com/nova/" target="_blank" rel="noopener"&gt;Amazon Nova&lt;/a&gt;, &lt;a href="https://aws.amazon.com/bedrock/anthropic/" target="_blank" rel="noopener"&gt;Anthropic Claude&lt;/a&gt;, &lt;a href="https://aws.amazon.com/bedrock/meta/" target="_blank" rel="noopener"&gt;Meta Llama&lt;/a&gt;, &lt;a href="https://aws.amazon.com/blogs/machine-learning/run-nvidia-nemotron-3-super-on-amazon-bedrock/" target="_blank" rel="noopener"&gt;NVIDIA Nemotron&lt;/a&gt;, &lt;a href="https://aws.amazon.com/bedrock/openai/" target="_blank" rel="noopener"&gt;OpenAI&lt;/a&gt;, and &lt;a href="https://aws.amazon.com/blogs/machine-learning/introducing-grok-on-amazon-bedrock/" target="_blank" rel="noopener"&gt;xAI Grok&lt;/a&gt; are currently available in Amazon Bedrock. Additional frontier models are also available in the same compliant and isolated cloud environment. This breadth of model choice gives government customers, the supporting industrial base, and technology partners the freedom to run inference, build agentic AI systems, and innovate on their own terms — choosing the best model for every task without compromise.&lt;/p&gt; 
&lt;h2&gt;Why AI model choice is an operational imperative&lt;/h2&gt; 
&lt;p&gt;AI model choice matters for every organization. For government missions, it’s an operational imperative. Here’s why:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Task-specific optimization&lt;/strong&gt; – Different AI models excel at different tasks. A model optimized for code generation might underperform at document summarization. Having access to multiple models lets agencies match the right model to each mission requirement.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Agentic AI acceleration&lt;/strong&gt; – Multi-model architectures underpin AI agents that work autonomously. Lightweight models handle routing while frontier models tackle complex reasoning, multiplying the value of every AI investment.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Cost optimization&lt;/strong&gt; – Leaders can right-size AI spend, using cost-efficient models for routine tasks and reserving premium models for complex analysis.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Model evaluation&lt;/strong&gt; – Developers can benchmark models against each other using their own data and requirements to pick the best performer rather than just picking the one they usually rely on.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Roadmap independence&lt;/strong&gt; – AI models evolve on different timelines, with different strengths. Relying on a catalog of models ensures your mission isn’t tied to any single model’s development cycle.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Operational continuity&lt;/strong&gt; – When a model version is deprecated, updated, or temporarily unavailable, having alternatives already integrated into your architecture means the mission continues without interruption.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Futureproofing&lt;/strong&gt; – The field of AI is evolving more rapidly than any other technology inflection point in history. Multi-model architectures, enabled by model choice, position agencies to adopt new breakthroughs without re-architecting existing systems.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The mission impact is clear. Multiple model families mean faster deployment, less vendor risk, and operational readiness that holds as AI evolves. Agencies deliver outcomes faster and innovate at the pace the mission demands. Consider a mission system that uses a lightweight model to classify incoming sensor data, a reasoning model to generate threat assessments, and a code model to automate patching. All three run through a single Amazon Bedrock API, inside the same compliance boundary, with no additional procurement or vendor onboarding.&lt;/p&gt; 
&lt;h2&gt;What AI models are now available in AWS GovCloud (US)&lt;/h2&gt; 
&lt;p&gt;Through Amazon Bedrock in AWS GovCloud (US), customers have access to multiple AI model families including:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Amazon Nova&lt;/strong&gt; – Amazon’s frontier models, purpose-built for enterprise-grade performance with best-in-class price-performance across text, image, and multimodal embeddings tasks. Agencies can use Nova to process intelligence imagery, automate document triage and embeddings, and integrate AI across high-volume workflows at a fraction of the cost.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Anthropic Claude&lt;/strong&gt; – Known for nuanced reasoning, long-context understanding, and safety-focused design. Claude excels at complex analysis, document processing, and tasks requiring careful judgment. Government teams can use Claude for policy analysis, legislative review, and adjudication where precision protects the mission.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;NVIDIA Nemotron&lt;/strong&gt; – High-performance models optimized for enterprise AI applications, offering strong reasoning and instruction-following capabilities for government workloads. Agencies can deploy Nemotron for mission automation, agentic workflows, and tasks demanding precise instruction adherence at scale.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;OpenAI GPT and OSS&lt;/strong&gt; – Industry-leading models including GPT-series and open-weight models, bringing advanced reasoning, code generation, and multimodal capabilities. Teams can use these models for secure code generation, complex data analysis, and building AI agents that chain multiple reasoning steps.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;xAI Grok&lt;/strong&gt; – Built for reasoning over long, complex inputs with configurable depth and strong tool-calling capabilities. Grok excels at document understanding, agentic workflows, and tasks where hallucination tolerance is low. Government analysts can use Grok for contract review, case law analysis, and financial document question-answering where accuracy is non-negotiable.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Additional frontier models&lt;/strong&gt; – A growing catalog providing agencies with access to the latest innovations in AI model capabilities. As new models launch, agencies can adopt them through the same API without re-architecture.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;All models are accessible through the unified Amazon Bedrock API and the native SDKs by changing a single endpoint URL. These access profiles make model access and migration frictionless. &lt;a href="https://aws.amazon.com/compliance/services-in-scope/FedRAMP/amazon-bedrock-models/" target="_blank" rel="noopener"&gt;Click her&lt;/a&gt;&lt;a href="PLACEHOLDER_URL_1" target="_blank" rel="noopener noreferrer"&gt;e&lt;/a&gt; to see all the models available in AWS GovCloud (US) and their compliance status.&lt;/p&gt; 
&lt;h2&gt;Built for regulated AI workloads&lt;/h2&gt; 
&lt;p&gt;For AI to deliver mission outcomes, it must run where the mission lives. For customers dependent on Controlled Unclassified Information (CUI) and regulated data, that means AWS GovCloud (US) – the same isolated, compliant infrastructure trusted for the nation’s most sensitive workloads. Your application inherits AWS GovCloud (US) GenAI/ML service and model compliance, so you don’t start your compliance package from scratch:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Data residency&lt;/strong&gt; – All data remains on U.S. soil.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Isolated infrastructure&lt;/strong&gt; – Models run within the same physically and logically isolated infrastructure trusted for sensitive controlled unclassified (CUI) workloads since 2011.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Operational excellence&lt;/strong&gt; – AWS GovCloud (US) regions are operated by U.S. Citizens working on U.S. soil.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;No data sharing&lt;/strong&gt; – Customer data is never used to train or improve models.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Hardware-rooted trust&lt;/strong&gt; – Bedrock model inference engine is built on the Nitro System with NitroTPM cryptographic attestation, providing hardware-level isolation and platform integrity verification for inference infrastructure.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Zero Operator Access (ZOA)&lt;/strong&gt; – No operator, including AWS or model providers, can access prompts, completions, or model weights during inference.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Encryption&lt;/strong&gt; – FIPS 140-3 validated, encrypted in transit and at rest, with customer-managed keys via AWS KMS.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Compliance posture&lt;/strong&gt; – Compliance inherited, not rebuilt: meets FedRAMP Class D, DoD CC SRG IL4/5 and ITAR requirements&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Responsible AI controls&lt;/strong&gt; – Amazon Bedrock Guardrails Runtime API enforces content filtering, PII redaction, and topic restrictions.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;h2&gt;Getting started with AI in AWS GovCloud (US)&lt;/h2&gt; 
&lt;p&gt;Customers already operating in AWS GovCloud (US) can enable Amazon Bedrock and begin accessing&amp;nbsp; AI models today. Here’s how to get started:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;Enable Amazon Bedrock in your AWS GovCloud (US) account through the &lt;a href="https://aws.amazon.com/console/" target="_blank" rel="noopener"&gt;AWS Management Console&lt;/a&gt;.&lt;/li&gt; 
 &lt;li&gt;Access available models – For details on how to access different models in AWS GovCloud (US), including which models are currently authorized for specific compliance levels, refer to the &lt;a href="https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-bedrock.html" target="_blank" rel="noopener"&gt;Amazon Bedrock model access documentation&lt;/a&gt;.&lt;/li&gt; 
 &lt;li&gt;Benchmark and compare AI models against your requirements using built-in Amazon Bedrock evaluation tools.&lt;/li&gt; 
 &lt;li&gt;Start building using &lt;a href="https://aws.amazon.com/bedrock/agents/" target="_blank" rel="noopener"&gt;Amazon Bedrock Agents&lt;/a&gt;, &lt;a href="https://aws.amazon.com/bedrock/knowledge-bases/" target="_blank" rel="noopener"&gt;Amazon Bedrock Knowledge Bases&lt;/a&gt;, &lt;a href="https://aws.amazon.com/bedrock/guardrails/" target="_blank" rel="noopener"&gt;Amazon Bedrock Guardrails&lt;/a&gt;, and AgentCore to deploy production-ready AI applications.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;h2&gt;Build mission-ready AI with the models you choose&lt;/h2&gt; 
&lt;p&gt;For fifteen years, AWS GovCloud (US) has stood for a simple principle: customers should never have to choose between compliance and innovation. Our investments in AI infrastructure and GenAI service and model expansion carry that principle forward — delivering the next wave of innovation at speed and scale without sacrificing the compliance and security government missions require. The models are here, the infrastructure is ready, and the mission doesn’t have to wait.&lt;/p&gt; 
&lt;p&gt;To speak with an AWS specialist about your AI strategy, contact your AWS account team or the&amp;nbsp;&lt;a href="https://aws.amazon.com/government-education/contact/" target="_blank" rel="noopener"&gt;AWS Public Sector team&lt;/a&gt;.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>What HCLS security teams can do this quarter to close the execution gap</title>
		<link>https://aws.amazon.com/blogs/publicsector/what-hcls-security-teams-can-do-this-quarter-to-close-the-execution-gap/</link>
		
		<dc:creator><![CDATA[Adam Birnbaum]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 22:50:01 +0000</pubDate>
				<category><![CDATA[Amazon Detective]]></category>
		<category><![CDATA[Amazon GuardDuty]]></category>
		<category><![CDATA[Amazon Macie]]></category>
		<category><![CDATA[Amazon Simple Storage Service (S3)]]></category>
		<category><![CDATA[AWS CloudTrail]]></category>
		<category><![CDATA[AWS Security Hub]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">970e15ad49bda6719d291a4dd4cbed04aaa4cab2</guid>

					<description>Most security teams know what's needed to defend their organization. Regulatory guidance is available, threat intelligence sharing has increased, and risks are well-documented. So why are healthcare and life sciences (HCLS) groups, from commercial payors to public health systems, still facing recurring incidents or falling behind in protecting sensitive information? The answer is the execution gap: the space between knowing what to do and the ability to get it done.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32185 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/What-HCLS-security-teams-can-do-this-quarter-to-close-the-execution-gap.png" alt="What HCLS security teams can do this quarter to close the execution gap" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;Most security teams know what’s needed to defend their organization. Regulatory guidance is available, threat intelligence sharing has increased, and risks are well-documented. So why are healthcare and life sciences (HCLS) groups, from commercial payors to public health systems, still facing recurring incidents or falling behind in protecting sensitive information? The answer is the execution gap: the space between knowing what to do and the ability to get it done.&lt;/p&gt; 
&lt;p&gt;When working with health systems, I have seen security teams who could name most gaps in their physical or &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; environment. Awareness or execution were not their primary problems. Evidence unavailability or governance immaturity drove many of their issues. Unfortunately, this is the norm and not the anomaly. Controls were operational but lacked evidence or consistent follow through, including disaster recovery tests with no captured results, logging with no active monitoring, or governance meetings with no documented action items. Other teams had the reverse problem. They were so consumed by manual evidence collection that control execution slipped.&lt;/p&gt; 
&lt;p&gt;Both teams want to succeed, but the ever-changing regulatory environment and emerging security risks make it difficult to close the execution gap. To help you, instead of being a to do checklist, this post explores the widening knowing-doing gap and offers suggestions on what you can start changing now using existing resources.&lt;/p&gt; 
&lt;h2&gt;The compounding risk spiral&lt;/h2&gt; 
&lt;p&gt;Three forces are simultaneously pulling in the same direction: economic pressure, regulatory requirements, and AI-enabled threats. While manageable alone, together they compound in ways most security programs aren’t designed to absorb.&lt;/p&gt; 
&lt;p&gt;Economic pressure is real and accelerating. Reimbursement cuts, acute for nonprofit health systems, community hospitals, and academic medical centers already operating on thin margins, are usually felt by security in the form of reduced headcount or funding. This usually impacts monitoring, patching, and evidence collection. Someone absorbs the work into their existing workload or it’s deprioritized, risking overall defense and compliance.&lt;/p&gt; 
&lt;p&gt;The regulatory landscape is moving faster than teams can absorb. It’s not only the &lt;a href="https://aws.amazon.com/compliance/hipaa-compliance/" target="_blank" rel="noopener"&gt;Health Insurance Portability and Accountability Act (HIPAA)&lt;/a&gt; anymore. State privacy laws are expanding, carrying shorter compliance windows, potentially conflicting requirements for multistate groups, and costly noncompliance. AI governance laws are emerging rapidly with aggressive enforcement timelines.&lt;/p&gt; 
&lt;p&gt;Most teams struggle to keep pace with one regulatory change; three at once introduces unintended risk, cost, and adoption pressures. The problem isn’t understanding the requirements but whether your governance program, resources, and executive support can keep pace with the rate of change.&lt;/p&gt; 
&lt;p&gt;AI-enabled threat activity targets healthcare specifically. The timing between vulnerability identification and exploitation is shrinking. According to &lt;a href="https://www.prnewswire.com/news-releases/cogent-research-exploits-outpace-scanner-detection-for-62-of-critical-vulnerabilities-as-ai-compresses-time-to-exploit-to-under-12-hours-302783104.html" target="_blank" rel="noopener"&gt;Cogent Security&lt;/a&gt;, the window has reduced to 12 hours from 125 days. Healthcare groups, especially in the public sector, are targeted because resource constraints are well known, resulting in security teams having difficulty remediating fast enough to ward off unauthorized actions and continuing to widen the execution gap.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="noopener"&gt;2026 Verizon Data Breach Investigations Report&lt;/a&gt; confirms the acceleration. This year’s report indicated that vulnerability exploitation surged 55% year-over-year to become the leading initial access vector for the first time in the report’s 19-year history. Meanwhile, &lt;a href="https://www.comparitech.com/blog/information-security/healthcare-ransomware-roundup-q1-2026/" target="_blank" rel="noopener"&gt;Comparitech&lt;/a&gt; reports that 120 ransomware attacks targeted hospitals and clinics in Q1 2026 alone.&lt;/p&gt; 
&lt;p&gt;These aren’t separate problems to solve independently, which is why they compound. Strained teams fall behind on security posture work, leading to control weakness accumulation. This often translates to increased incident probability, with the organization spending more on reactive triage without catching up. The funding needed for security maturity is now spent on incident management.&lt;/p&gt; 
&lt;p&gt;The common thread between the three is capacity and needing to do more with what you have without it becoming burdensome.&lt;/p&gt; 
&lt;h2&gt;Your problem isn’t only your problem&lt;/h2&gt; 
&lt;p&gt;A security gap is an ecosystem problem, but many treat it as internal. Think about who might be connected to your systems or environment: payers, providers, electronic health record (EHR) vendors, state health information exchanges, pharmacies, and members. Third-party interconnection means that when one organization has an unaddressed gap, everyone connected to it inherits a portion of that risk. Controls are strongest when the connections between domains are secure and there is continuous collaboration to keep them protected.&lt;/p&gt; 
&lt;p&gt;The execution gap isn’t about one health system failing to maintain their controls, but how you and your providers are intertwined and must collaborate to address the shared risk.&lt;/p&gt; 
&lt;h2&gt;The access you haven’t detected&lt;/h2&gt; 
&lt;p&gt;When was the last time you had full confidence that nothing unauthorized was happening in your environment? The answer often heard is “we have not had an incident yet.” Without continuous monitoring, that often means “we have not detected one yet.”&lt;/p&gt; 
&lt;p&gt;Dwell time is the window between unauthorized access and its discovery. For teams that can’t staff or afford around-the-clock security operations monitoring, that window stretches and damage accumulates.&lt;/p&gt; 
&lt;p&gt;Your cloud detection services can help close this gap and provide visibility where it’s lacking without adding headcount or constraining teams. For example, &lt;a href="https://aws.amazon.com/guardduty/" target="_blank" rel="noopener"&gt;Amazon GuardDuty&lt;/a&gt; runs continually across accounts and workloads, surfacing findings on unauthorized access, credential misuse, and data exfiltration that would otherwise sit undetected. When GuardDuty identifies a finding, &lt;a href="https://aws.amazon.com/detective/" target="_blank" rel="noopener"&gt;Amazon Detective&lt;/a&gt; correlates activity across your logs, network flows, and API calls for event reconstruction, significantly reducing investigation time and expediting root cause determination and remediation. This requires no manual effort from team members or reassignment. Instead, team expertise focuses on response and control improvements rather than manual log review or incident retracing.&lt;/p&gt; 
&lt;h2&gt;Why checkbox compliance must remain in the past&lt;/h2&gt; 
&lt;p&gt;Historically, many organizations’ security compliance efforts were focused on what’s necessary to pass the latest audit or customer assessment. They were checking off an annual compliance requirement instead of taking security seriously, creating false confidence and significantly increasing risk. Passing an audit means your controls met the criteria at the time of the assessment. It doesn’t mean those controls are operating as designed between audits or that data privacy protections are consistently adequate.&lt;/p&gt; 
&lt;p&gt;The pattern across resource-constrained HCLS organizations is consistent: compliance-as-event (what’s needed to pass) rather than compliance-as-operating-posture (continuous and evolving). Due to resource constraints and unfunded regulatory mandates, teams scramble to pass regulations and then revert to baseline or delay remediations until the next cycle. They’re usually surprised when next year’s assessment criteria don’t match the prior year or their remediation no longer fully meets this year’s requirement, leading to a new exception. Even without the new &lt;a href="https://www.hhs.gov/hipaa/for-professionals/security/index.html" target="_blank" rel="noopener"&gt;HIPAA Security Rule&lt;/a&gt; changes, enforcement actions now consider how risks from the addressable requirements were handled. That would be an expensive surprise to someone who believed that they were compliant because the rules weren’t mandatory. Whether an organization is a small practitioner or a large nonprofit community hospital, when resources are stretched, remediation timelines and framework or regulatory change maintenance are challenged as well.&lt;/p&gt; 
&lt;p&gt;This is where you determine whether your operating processes are making your team’s work invisible or unsustainable. The shift from annual evidence collection to continuous documentation is where automation matters most. Passing the current regulations isn’t enough. You need to put systems in place that will ease the overall burden. This will also organically help with posture strengthening and shifting your organization from reactive to proactive.&lt;/p&gt; 
&lt;h2&gt;The privacy dimension you’re probably underestimating&lt;/h2&gt; 
&lt;p&gt;When the industry talks about the execution gap, the default framing is security. But the downstream consequence of a healthcare incident is rarely a security issue alone. It’s a privacy violation, with data exposed, patients affected, and trust eroded.&lt;/p&gt; 
&lt;p&gt;Many HCLS organizations merge privacy and security rather than treating privacy as a parallel discipline with its own governance, impact analysis, and by-design standards. The regulatory scrutiny is increasingly coming from the privacy side: state privacy, AI data-use rules, and patient rights provisions many security professionals aren’t traditionally skilled to handle.&lt;/p&gt; 
&lt;p&gt;A practical starting point is to gain visibility into what sensitive data, such as protected health information (PHI), you have and where it lives. Services such as &lt;a href="https://aws.amazon.com/macie/" target="_blank" rel="noopener"&gt;Amazon Macie&lt;/a&gt; help you discover health-related data located in unmonitored locations across &lt;a href="https://aws.amazon.com/s3/" target="_blank" rel="noopener"&gt;Amazon Simple Storage Service (Amazon S3)&lt;/a&gt; storage. That visibility is the first step toward governing what you can’t currently see, and it shifts data privacy from aspiration to operational capability.&lt;/p&gt; 
&lt;p&gt;When deciding if your privacy program is sufficient, examine whether you have true data governance or have security controls that merely happen to protect data. Also look at whether the time spent on maintenance has been sufficient.&lt;/p&gt; 
&lt;h2&gt;The path forward starts this quarter&lt;/h2&gt; 
&lt;p&gt;The &lt;a href="https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&amp;amp;RIN=0945-AA22" target="_blank" rel="noopener"&gt;postponement&lt;/a&gt; to the HIPAA Security Rule changes gave you time, but a delayed deadline doesn’t delay your risk. If enacted, all addressable requirements become required. If your team can’t handle your current compliance workload, what happens when the HIPAA or new federal or state regulations arrive? Because of the deferral, you can close gaps at a controlled pace before they become the next obligation you’re juggling. The following path is how to take advantage of the extra time while also beginning to close your own execution gap.&lt;/p&gt; 
&lt;p&gt;None of this requires a massive transformation or additional resources. It requires sequencing.&lt;/p&gt; 
&lt;h3&gt;Days 1–30: Increase visibility into your system&lt;/h3&gt; 
&lt;p&gt;Deploy Amazon GuardDuty in your environment for continuous detection. Amazon Macie can then be run against your Amazon S3 storage to identify sensitive data in unexpected locations. Afterwards, conduct a shared-responsibility analysis, which maps each compliance requirement to your obligations or your cloud provider’s attestable controls, revealing which items your team must actively prove and which are already covered. It’s a high-impact exercise that can provide HCLS organizations significant efficiencies. Finally, use &lt;a href="https://aws.amazon.com/cloudtrail/" target="_blank" rel="noopener"&gt;AWS CloudTrai&lt;/a&gt;&lt;a href="PLACEHOLDER_URL" target="_blank" rel="noopener noreferrer"&gt;l&lt;/a&gt; for API activity logging across your accounts.&lt;/p&gt; 
&lt;p&gt;Collectively, these lay the groundwork to provide the visibility and monitoring manual efforts can’t sustain. They also provide effective, automated discovery, analysis, and evidence logging that establishes an enhanced baseline.&lt;/p&gt; 
&lt;h3&gt;Days 30–60: Operationalize your visibility&lt;/h3&gt; 
&lt;p&gt;Configure &lt;a href="https://aws.amazon.com/security-hub/" target="_blank" rel="noopener"&gt;AWS Security Hub&lt;/a&gt; to aggregate account findings and evaluate your posture against &lt;a href="https://docs.aws.amazon.com/securityhub/latest/userguide/fsbp-standard.html" target="_blank" rel="noopener"&gt;Foundational Security Best Practices&lt;/a&gt;, providing you with a single view instead of isolated alerts. &lt;a href="https://docs.aws.amazon.com/config/latest/developerguide/conformance-packs.html" target="_blank" rel="noopener"&gt;Conformance packs&lt;/a&gt; in &lt;a href="https://aws.amazon.com/config/" target="_blank" rel="noopener"&gt;AWS Config&lt;/a&gt; further help by continually evaluating configurations against HIPAA and &lt;a href="https://docs.aws.amazon.com/config/latest/developerguide/operational-best-practices-for-nist-800-53_rev_5.html" target="_blank" rel="noopener"&gt;National Institute of Standards and Technology (NIST) SP 800-53&lt;/a&gt; control baselines, identifying risks as they occur instead of during periodic reviews or audit preparation.&lt;/p&gt; 
&lt;p&gt;Those steps operationalize your new visibility to make it actionable and increase detective and prevention layers of defense. It also helps you move from a state of preparing for audits to operating in an audit-ready state that continuously protects your organization and helps you demonstrate compliance. Your evidence now becomes a byproduct of operations and not a quarterly sprint consuming team capacity or shifting their focus from defense and posture improvement.&lt;/p&gt; 
&lt;h3&gt;Days 60–90: Communicate and sustain&lt;/h3&gt; 
&lt;p&gt;Take your new visibility and translate it into language your leadership can act on. Quantify what you found and frame it as business risk instead of technical debt. If you discovered your team was already doing the work and the operating model was hiding it, show leadership: here is what we do, here is the evidence, and here is how we sustain and evolve it. This is the bridge from discretionary project funding to sustained operational investment.&lt;/p&gt; 
&lt;p&gt;Each step is independently valuable and moves you from knowing what’s needed to doing it and being able to demonstrate program maturity.&lt;/p&gt; 
&lt;h2&gt;What comes next&lt;/h2&gt; 
&lt;p&gt;The execution gap won’t close because someone publishes another best-practices guide or leadership agrees to fund additional staffing, probably at the cost of needed technology. It closes when teams start using the solutions they possess now to shrink visibility gaps, automate evidence, and reduce manual efforts. This means your team can focus on defense, strategy, and translating findings into language that moves leadership to act.&lt;/p&gt; 
&lt;p&gt;This is the first of three connected posts. The focus in this post is to close the execution gap with existing resources. The next post examines how AI can multiply a stretched team’s capacity to help strengthen your security posture maturity without increasing overhead or risk. The last post turns to the element most technical programs struggle with: communicating risk to leadership in language that secures sustained support.&lt;/p&gt; 
&lt;h2&gt;Get started&lt;/h2&gt; 
&lt;p&gt;Activate Amazon GuardDuty in your account for continuous detection and initiate a shared-responsibility analysis using the &lt;a href="https://aws.amazon.com/compliance/" target="_blank" rel="noopener"&gt;AWS Compliance Center&lt;/a&gt;. Specific HCLS guidance can be found at &lt;a href="https://aws.amazon.com/health/life-sciences/solutions/compliance/" target="_blank" rel="noopener"&gt;AWS HCLS compliance solutions&lt;/a&gt; or contact your account team for help.&lt;/p&gt; 
&lt;p&gt;Which of these forces (economic pressure, regulatory acceleration, or AI-enabled risks) is hitting your team hardest right now?&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>Modernizing state, local digital government services with AWS and Presidio</title>
		<link>https://aws.amazon.com/blogs/publicsector/modernizing-state-local-digital-government-services-with-aws-and-presidio/</link>
		
		<dc:creator><![CDATA[Mike Baur]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 22:44:51 +0000</pubDate>
				<category><![CDATA[Amazon EventBridge]]></category>
		<category><![CDATA[AWS Step Functions]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">ba83455d6bffba1e2189d136b40892cc37063284</guid>

					<description>A recent State CIO Survey from the National Association of State Chief Information Officers (NASCIO) highlights that modernization extends beyond a single piece of technology. Digital accessibility, AI, modernization funding, cloud, data governance, collaboration, and service delivery are now all connected priorities that influence constituent-facing experiences and the operating models that make those experiences possible. Amazon Web Services (AWS) and partners like Presidio help agencies address these priorities through cloud-based modernization patterns that connect workflow, data, experience, and governance.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32226 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/26/Modernizing-state-local-digital-government-services-with-AWS-and-Presidio.png" alt="Modernizing state, local digital government services with AWS and Presidio" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;Nearly seven in 10 states now have or are building a unified resident portal, according to the &lt;a href="https://higherlogicdownload.s3.amazonaws.com/NASTD/UploadedImages/20b47faa-5f00-40f1-bc5f-7ea8c80514d3/2025_NASTD_Constituent_Experience_Summary_Final.pdf" target="_blank" rel="noopener"&gt;National Association of State Technology Directors (NASTD) 2025 Constituent Experience: State Government IT Strategies&lt;/a&gt; survey.&lt;/p&gt; 
&lt;p&gt;That’s an important step forward, but it also raises the bar. Residents don’t judge government by the portal itself. They judge it by whether they can complete tasks quickly and without friction. Behind every great digital experience are modern workflows, connected data, accessible design, and governance that keeps services running reliably. Without them, even the best-looking portal falls short.&lt;/p&gt; 
&lt;p&gt;Today’s state and local government agencies face a practical modernization challenge. Residents expect faster, more accessible, transparent services, but agency teams struggle to deliver. From legacy systems to fragmented data to evolving compliance requirements, the gap is clear.&lt;/p&gt; 
&lt;p&gt;A recent &lt;a href="https://www.nascio.org/resources/cio-priorities-insights/state-cio-survey/" target="_blank" rel="noopener"&gt;State CIO Survey&lt;/a&gt; from the National Association of State Chief Information Officers (NASCIO) highlights that modernization extends beyond a single piece of technology. Digital accessibility, AI, modernization funding, cloud, data governance, collaboration, and service delivery are now all connected priorities that influence constituent-facing experiences and the operating models that make those experiences possible. &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; and partners like Presidio help agencies address these priorities through cloud-based modernization patterns that connect workflow, data, experience, and governance.&lt;/p&gt; 
&lt;p&gt;Digital services modernization is the process of shifting from isolated tools, siloed applications, and time-consuming manual processes to a more connected, governed, and reusable service environment. For state and local governments, that means modernizing the workflows, data exchanges, security controls, and resident experiences that are connected to services, such as benefits enrollment, licensing, permitting, case management, and public safety coordination.&lt;/p&gt; 
&lt;h2&gt;Why digital services modernization matters now&lt;/h2&gt; 
&lt;p&gt;The core systems that state and local governments rely on were designed for a different era of service delivery. Although these legacy systems might still perform important agency functions, they weren’t created to focus on resident engagement. So when residents need to move across programs, submit information, track a case, or receive updates, friction often follows.&lt;/p&gt; 
&lt;p&gt;The result of that friction moves beyond a technology problem and becomes an operating one:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;Workflows that depend on manual handoffs create a burden on staff, pulling them away from resolving resident needs.&lt;/li&gt; 
 &lt;li&gt;Data that sits in disconnected systems creates multiple touchpoints that frustrate residents because they must repeat the same information across agencies.&lt;/li&gt; 
 &lt;li&gt;Digital services that aren’t compliant with current accessibility requirements isolate residents who need public services most while putting the agency at risk of noncompliance.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Workforce pressure also shapes this modernization challenge. MissionSquare Research Institute found in its &lt;a href="https://research.missionsq.org/content/media/document/2025/5/2025_State_Local_Workforce_Report.pdf" target="_blank" rel="noopener"&gt;2025 State and Local Government Workforce Survey&lt;/a&gt; that concerns around recruitment, retention, compensation, organizational culture, and succession planning are top of mind for government employers. Rather than add new systems for workers to manage, we recommend that agencies prioritize modernization that reduces the manual burden that falls on staff.&lt;/p&gt; 
&lt;h2&gt;Making the move toward modernization&lt;/h2&gt; 
&lt;p&gt;The pivot away from siloed services toward a unified service delivery model is already underway, as the NASTD Constituent Experience survey confirms. That progress matters, but it also sets a higher standard. Portals improve the resident experience only when agencies also address the workflows, data, accessibility, and governance behind them.&lt;/p&gt; 
&lt;p&gt;We recommend that modernization efforts start with the service journey that causes the most delays for residents and staff. When you modernize around that journey, you can identify the points where cloud capabilities can reduce friction without forcing a full replacement of every underlying system at once.&lt;/p&gt; 
&lt;p&gt;A digital modernization strategy connects four areas: workflow, data, experience, and governance. These four areas are impactful on their own, but the value comes from treating each as one operating model.&lt;/p&gt; 
&lt;h2&gt;A practical framework for digital services modernization&lt;/h2&gt; 
&lt;p&gt;This framework connects four areas that, when addressed together, form a cohesive operating model for modern service delivery:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Modernize the workflow&lt;/strong&gt; – Intake, routing, review, approval, exception handling, and notification steps often reveal where services slow down. Cloud-based workflow orchestration, event-driven architecture, and managed integration services can help agencies standardize common processes while adapting to program-specific rules.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Build trusted data exchange&lt;/strong&gt; – Interoperability means that authorized systems can exchange data in a more secure, governed, and usable way. In practice, it helps residents avoid repeating information, helps staff see more complete case context, and helps agencies reduce duplicative work across programs.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Design around the resident experience&lt;/strong&gt; – Resident-centered digital services use accessible, mobile-responsive, plain-language interactions that reflect how people actually reach out for support. They also connect the frontend experience to the operating model behind it. A portal might streamline access, but residents still judge the service by whether they can complete the process, receive updates, avoid duplicate submissions, and understand the next step.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Embed governance from the beginning&lt;/strong&gt; – Security, identity, auditability, records management, privacy, and compliance can’t sit outside the modernization plan. National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 gives organizations a common structure for managing cybersecurity risk. NIST’s CSF 2.0 quick start guidance connects cybersecurity with enterprise risk management and workforce management. For agencies modernizing digital services, that connection matters because security, compliance, staffing, and service delivery risks often intersect.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;h2&gt;How cloud capabilities support modernization&lt;/h2&gt; 
&lt;p&gt;AWS can support government modernization by helping agencies assemble scalable infrastructure, managed services, security capabilities, automation tools, data services, and AI services around mission needs. Cloud modernization helps agencies move from one-off system upgrades to reusable service capabilities that can support multiple programs over time.&lt;/p&gt; 
&lt;p&gt;For example, cloud-based integration and compute services such as &lt;a href="https://aws.amazon.com/step-functions/" target="_blank" rel="noopener"&gt;AWS Step Functions&lt;/a&gt; and &lt;a href="https://aws.amazon.com/eventbridge/" target="_blank" rel="noopener"&gt;Amazon EventBridge&lt;/a&gt; can help agencies connect systems and automate workflow steps without building every component from scratch.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://aws.amazon.com/api-gateway/" target="_blank" rel="noopener"&gt;Amazon API Gateway&lt;/a&gt; powers the exchange between an agency’s applications and the data that fuels them. Managed databases and analytics services can support case records, transactions, reporting, and governed data access. Identity, monitoring, logging, and audit services can help technology and compliance teams maintain visibility across digital service environments.&lt;/p&gt; 
&lt;p&gt;The modernization advantage comes from using these capabilities as reusable patterns. Rather than treating each service as a separate custom build, agencies can create repeatable approaches for intake, eligibility review, notifications, identity, document handling, and case updates. That shift can reduce delivery risk because teams can deliver incremental improvements while building a foundation that supports future services.&lt;/p&gt; 
&lt;h2&gt;Prepare for responsible AI in government services&lt;/h2&gt; 
&lt;p&gt;Generative AI and agentic AI will shape the next phase of digital government, but we recommend that agencies approach them through governance before automation. Agentic AI refers to AI systems that can plan, take defined actions, and coordinate steps toward an outcome within human-approved boundaries. In government services, those boundaries matter because decisions might affect benefits, eligibility, safety, access, and public trust.&lt;/p&gt; 
&lt;p&gt;AI can help agency teams search policy guidance, summarize case information, classify documents, draft resident communications, or guide users through complex processes. The primary risk is when agencies deploy AI before they define human review, auditability, access controls, data boundaries, and escalation paths.&lt;/p&gt; 
&lt;p&gt;Services like &lt;a href="https://aws.amazon.com/bedrock/" target="_blank" rel="noopener"&gt;Amazon Bedrock&lt;/a&gt; give agencies a foundation for building and scaling generative AI and agentic applications while maintaining the security and privacy of sensitive government data.&lt;/p&gt; 
&lt;p&gt;Leaders need to treat AI readiness as an extension of modernization readiness. If workflows remain unclear, data remains fragmented, and governance remains manual, AI might amplify those weaknesses. When agencies first clarify service journeys, data rules, identity models, and accountability structures, AI can support staff capacity while preserving human judgment for consequential decisions.&lt;/p&gt; 
&lt;h2&gt;What agencies can consider next&lt;/h2&gt; 
&lt;p&gt;The goal of modernization is to build a more responsive, resilient operating model for public services that can adapt as resident needs and policy priorities change.&lt;/p&gt; 
&lt;p&gt;When agencies connect workflow, data, experience, and governance through cloud-based patterns, they can reduce operational bottlenecks, improve staff capacity, and strengthen resident trust. That same foundation also positions teams to adopt responsible AI in a way that reinforces (not replaces) human judgment in consequential decisions.&lt;/p&gt; 
&lt;p&gt;Taken together, a cloud-aligned, pattern-based approach gives public sector leaders a practical way to improve today’s services while preparing for the next generation of digital government.&lt;/p&gt; 
&lt;p&gt;In a future post, we’ll explore how agencies are applying these patterns to accelerate specific service delivery outcomes.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.presidio.com/partners/aws/" target="_blank" rel="noopener"&gt;Explore&lt;/a&gt; how Presidio and AWS are helping agencies apply this framework&lt;a href="PLACEHOLDER_URL" target="_blank" rel="noopener noreferrer"&gt;.&lt;/a&gt;&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>How ITHAKA built an on-demand PDF remediation pipeline on AWS</title>
		<link>https://aws.amazon.com/blogs/publicsector/how-ithaka-built-an-on-demand-pdf-remediation-pipeline-on-aws/</link>
		
		<dc:creator><![CDATA[Dane Hillard]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 20:21:35 +0000</pubDate>
				<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[AWS Fargate]]></category>
		<category><![CDATA[AWS Identity and Access Management (IAM)]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[AWS Step Functions]]></category>
		<category><![CDATA[Industries]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">570c74a17d3d10d6d33b911cb4ad43b7d1da1e83</guid>

					<description>In this post, we describe how ITHAKA and Amazon Web Services (AWS) collaborated to build an on-demand PDF accessibility pipeline that remediates documents when users need them, serving researchers while using nonprofit resources responsibly. For organizations managing a large document collection under accessibility compliance deadlines, this post shows there is an affordable, practical path forward that doesn’t require converting an entire library upfront.</description>
										<content:encoded>&lt;p&gt;&lt;a href="https://www.ithaka.org/" target="_blank" rel="noopener"&gt;ITHAKA &lt;/a&gt;is a not-for-profit organization dedicated to improving access to knowledge and education. Through its platforms, including &lt;a href="https://about.jstor.org/?utm_source=AWS&amp;amp;utm_medium=blog&amp;amp;utm_campaign=jstor_accessibility" target="_blank" rel="noopener"&gt;JSTOR&lt;/a&gt;, one of the most widely used digital libraries in the world, ITHAKA provides millions of researchers, students, and educators access to scholarly content spanning centuries of academic work. That mission depends on making content accessible to every user, regardless of ability.&lt;/p&gt; 
&lt;p&gt;ITHAKA’s digital corpus includes approximately 156 million pages across 20 million PDFs, with source material dating as far back as 1550. The collection spans 30 years of humanities, arts, and social sciences publishing—born-digital documents, scanned print materials with varying optical character recognition (OCR) quality, and content ranging from single-column journal articles to complex mixed-media layouts. The U.S. Department of Justice (DOJ) revised the &lt;a href="https://www.federalregister.gov/documents/2026/04/20/2026-07663/extension-of-compliance-dates-for-nondiscrimination-on-the-basis-of-disability-accessibility-of-web" target="_blank" rel="noopener"&gt;title II rule&lt;/a&gt; of the Americans with Disabilities Act (ADA) to give state and local government entities until 2027 for populations over 50,000 and 2028 for populations less than 50,000 to meet &lt;a href="https://en.wikipedia.org/wiki/PDF/UA" target="_blank" rel="noopener"&gt;PDF/Universal Accessibility (PDF/UA)&lt;/a&gt; standards. ITHAKA faced a question central to its mission: how do you make 156 million pages accessible—responsibly?&lt;/p&gt; 
&lt;p&gt;In this post, we describe how ITHAKA and &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; collaborated to&lt;a href="https://about.jstor.org/blog/building-accessibility-into-every-article-on-demand/?utm_source=AWS&amp;amp;utm_medium=blog&amp;amp;utm_campaign=jstor_accessibility" target="_blank" rel="noopener"&gt; build an on-demand PDF accessibility pipeline&lt;/a&gt; that remediates documents when users need them, serving researchers while using nonprofit resources responsibly. For organizations managing a large document collection under accessibility compliance deadlines, this post shows there is an affordable, practical path forward that doesn’t require converting an entire library upfront.&lt;/p&gt; 
&lt;h2&gt;How to remediate at scale&lt;/h2&gt; 
&lt;p&gt;Making knowledge accessible is core to ITHAKA’s mission. The ADA title II revised rule provided a concrete deadline, but &lt;a href="https://about.jstor.org/accessibility/?utm_source=AWS&amp;amp;utm_medium=blog&amp;amp;utm_campaign=jstor_accessibility" target="_blank" rel="noopener"&gt;ITHAKA’s commitment to accessibility&lt;/a&gt; predates the regulation. The question was never whether to remediate, it was how to do it at scale.&lt;/p&gt; 
&lt;p&gt;Manual PDF remediation typically costs $1–4 per page. For ITHAKA’s 156 million-page corpus, that translates to $156 million–$624 million in upfront remediation costs. Even at the low end, bulk remediation of the full collection wasn’t a responsible use of nonprofit funds, and it was unnecessary.&lt;/p&gt; 
&lt;p&gt;Most users request a fraction of the corpus at any given time. A user searching JSTOR for a specific journal article doesn’t need all 20 million PDFs remediated; they need the one they’re reading. This usage pattern pointed to a different approach: rather than remediating the entire collection upfront, build an efficient automated process that converts PDFs on demand, based on actual user requests.&lt;/p&gt; 
&lt;p&gt;On-demand remediation serves users immediately, builds an accessible content library organically based on real demand, and directs resources where they have the most impact. As more users request accessible PDFs, the remediated collection grows, driven by the people who need it most.&lt;/p&gt; 
&lt;p&gt;The technical challenges compounded the economic ones. ITHAKA’s corpus includes born-digital PDFs with proper structure, scanned documents with partial or no OCR data, and everything in between. A remediation pipeline needed to handle this diversity reliably while integrating with ITHAKA’s existing content delivery infrastructure, security controls, and operational standards.&lt;/p&gt; 
&lt;h2&gt;The starting point: an open source foundation&lt;/h2&gt; 
&lt;p&gt;The Arizona State University (ASU) &lt;a href="https://smartchallenges.asu.edu/" target="_blank" rel="noopener"&gt;Artificial Intelligence Cloud Innovation Center (AI CIC)&lt;/a&gt;, powered by AWS, developed an open source &lt;a href="https://github.com/ASUCICREPO/PDF_Accessibility" target="_blank" rel="noopener"&gt;PDF accessibility remediation&lt;/a&gt; solution under the &lt;a href="https://en.wikipedia.org/wiki/MIT_License" target="_blank" rel="noopener"&gt;MIT License&lt;/a&gt;. The solution automates PDF remediation using the &lt;a href="https://developer.adobe.com/document-services/apis/pdf-accessibility-auto-tag/" target="_blank" rel="noopener"&gt;Adobe PDF Accessibility Auto-Tag API&lt;/a&gt; for structural tagging, &lt;a href="https://aws.amazon.com/bedrock/" target="_blank" rel="noopener"&gt;Amazon Bedrock&lt;/a&gt; for generating image alt text, &lt;a href="https://aws.amazon.com/step-functions/" target="_blank" rel="noopener"&gt;AWS Step Functions&lt;/a&gt; for orchestration, &lt;a href="https://aws.amazon.com/lambda/" target="_blank" rel="noopener"&gt;AWS Lambda&lt;/a&gt; for serverless processing, and &lt;a href="https://aws.amazon.com/fargate/" target="_blank" rel="noopener"&gt;AWS Fargate&lt;/a&gt; for containerized workloads. An earlier post on the Public Sector Blog, &lt;a href="https://aws.amazon.com/blogs/publicsector/from-inaccessible-to-inclusive-how-the-new-pdf-accessibility-remediation-solution-helps-institutions-compliantly-address-accessibility-requirements/" target="_blank" rel="noopener"&gt;From inaccessible to inclusive,&lt;/a&gt; describes the solution and its initial use at The Ohio State University Libraries.&lt;/p&gt; 
&lt;p&gt;ITHAKA’s engineering team identified this solution as a strong starting point. Deploying it in production at ITHAKA’s scale, however, required several adaptations:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Infrastructure as code (IaC)&lt;/strong&gt; – Migration from &lt;a href="https://aws.amazon.com/cdk/" target="_blank" rel="noopener"&gt;AWS Cloud Development Kit (AWS CDK)&lt;/a&gt; to Terraform, ITHAKA’s standard for infrastructure management&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Event-driven API&lt;/strong&gt; – Replacing &lt;a href="https://aws.amazon.com/s3/" target="_blank" rel="noopener"&gt;Amazon Simple Storage Service (Amazon S3)&lt;/a&gt; object triggers with &lt;a href="https://aws.amazon.com/eventbridge/" target="_blank" rel="noopener"&gt;Amazon EventBridge&lt;/a&gt; for programmatic invocation, traceability, and status reporting&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Security integration&lt;/strong&gt; – Aligning with ITHAKA’s service control policies (SCPs), network boundaries, and &lt;a href="https://aws.amazon.com/iam/" target="_blank" rel="noopener"&gt;AWS Identity and Access Management (IAM)&lt;/a&gt; least-privilege requirements&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Observability&lt;/strong&gt; – Integrating with ITHAKA’s existing monitoring and logging tools&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;In addition, the ITHAKA team adopted &lt;a href="https://pdfix.net/" target="_blank" rel="noopener"&gt;PDFix&lt;/a&gt; and &lt;a href="https://verapdf.org/" target="_blank" rel="noopener"&gt;veraPDF&lt;/a&gt; for structural tagging and validation to meet ITHAKA’s specific remediation requirements.&lt;/p&gt; 
&lt;h2&gt;Architecture&lt;/h2&gt; 
&lt;p&gt;The production architecture separates two concerns: the user-facing application flow and the underlying remediation pipeline.&lt;/p&gt; 
&lt;p&gt;The user experience follows a straightforward flow:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;A JSTOR user navigates to a content item and chooses &lt;strong&gt;Request accessible PDF&lt;/strong&gt; for an unremediated item or &lt;strong&gt;Download accessible PDF&lt;/strong&gt; for a previously remediated item.&lt;/li&gt; 
 &lt;li&gt;If an accessible PDF is available and newer than the source document, the user downloads it immediately.&lt;/li&gt; 
 &lt;li&gt;If no accessible version exists, the system triggers the remediation pipeline and optionally notifies the user when processing is complete.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Remediated PDFs are cached and reused. A remediated PDF is only reprocessed if the source PDF is updated or the remediation pipeline has improved, avoiding redundant processing while keeping content current.&lt;/p&gt; 
&lt;p&gt;The following diagram shows the user-facing flow: a JSTOR application user requests an accessible PDF, the system checks for a cached remediated version, and if none exists, initiates the pipeline and notifies the user upon completion.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/Figure-1-Application-integration-with-PDF-remediation.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32112 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/Figure-1-Application-integration-with-PDF-remediation.png" alt="Application integration with PDF remediation. The diagram shows the user-facing flow: a JSTOR application user requests an accessible PDF, the system checks for a cached remediated version, and if none exists, initiates the pipeline and notifies the user upon completion." width="1002" height="532"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 1: Application integration with PDF remediation&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;The remediation pipeline processes each PDF through a series of steps:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;An EventBridge event initiates the workflow, carrying a tracing identifier and metadata that follows the job through every service.&lt;/li&gt; 
 &lt;li&gt;A Lambda function splits the PDF into individual pages for parallel processing.&lt;/li&gt; 
 &lt;li&gt;Step Functions orchestrates the remediation tasks: PDFix applies structural tagging (headings, paragraphs, lists, and tables) to each page, and Amazon Bedrock generates alt text descriptions for images and charts.&lt;/li&gt; 
 &lt;li&gt;A merge step reassembles the tagged pages into a single remediated PDF with a generated document title.&lt;/li&gt; 
 &lt;li&gt;Accessibility validation checks the output against PDF/UA standards using tools such as veraPDF.&lt;/li&gt; 
 &lt;li&gt;The remediated PDF and a complete event log are stored in Amazon S3.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The following architecture diagram shows EventBridge initiating the workflow, Lambda splitting the PDF into pages, Step Functions orchestrating PDFix structural tagging and Amazon Bedrock alt text generation, followed by merging, PDF/UA validation, and storage in Amazon S3.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/Figure-2-PDF-remediation-pipeline.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32111 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/Figure-2-PDF-remediation-pipeline.png" alt="PDF remediation pipeline. The architecture shows Amazon EventBridge initiating the workflow, AWS Lambda splitting the PDF into pages, AWS Step Functions orchestrating PDFix structural tagging, and Amazon Bedrock alt text generation, followed by merging, PDF/UA validation, and storage in Amazon S3." width="1002" height="525"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 2: PDF remediation pipeline&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;Three design decisions shaped the architecture:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;End-to-end tracing&lt;/strong&gt; – Every remediation job carries a tracing identifier from initiation through completion. EventBridge emits status events at each pipeline stage (splitting, processing, merging, and validation), and an event log aggregator stores the full job history alongside the remediated PDF in Amazon S3. This provides auditability and operational visibility across the entire workflow.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Modular, swappable processing tools&lt;/strong&gt; – The pipeline is designed so the remediation tools can be swapped out or chained with additional processors. As an example, the Adobe PDF Accessibility Auto-Tag API was replaced with PDFix and veraPDF without rebuilding the entire pipeline. As new tools become available, including &lt;a href="https://aws.amazon.com/ai/generative-ai/" target="_blank" rel="noopener"&gt;generative AI&lt;/a&gt; capabilities, ITHAKA can integrate them to expand how they meet their users’ accessibility needs.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Heuristic pre-analysis with human fallback&lt;/strong&gt; – Before processing, the system evaluates what remediation each source PDF requires, reducing unnecessary computation. When automated remediation doesn’t meet accessibility standards, the system signals for human intervention, providing a safety net for documents that require manual attention.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;Building and deploying together&lt;/h2&gt; 
&lt;p&gt;In February 2026, ITHAKA engineers and AWS solutions architects held a 2-day build-and-demo workshop to adapt the open source solution for ITHAKA’s environment.&lt;/p&gt; 
&lt;p&gt;Day one focused on infrastructure and deployment. The team converted the deployment from CDK to Terraform, deployed core services including Lambda functions, the Step Functions state machine, Fargate tasks, S3 buckets, and &lt;a href="https://aws.amazon.com/vpc/" target="_blank" rel="noopener"&gt;Amazon Virtual Private Cloud (Amazon VPC)&lt;/a&gt; configuration, and tested the pipeline with sample PDFs. The team then replaced the S3 event trigger with an EventBridge based API, adding support for tracing identifiers and status events.&lt;/p&gt; 
&lt;p&gt;Day two shifted to validation, security, and operations. The team tested the pipeline against diverse PDF types from ITHAKA’s corpus and addressed production requirements: IAM policy hardening, network ingress and egress controls, and integration with ITHAKA’s observability tools.&lt;/p&gt; 
&lt;p&gt;The workshop surfaced real engineering challenges:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;ITHAKA’s SCPs restricted S3 bucket policy modifications, conflicting with the solution’s deployment scripts. The team resolved this by adjusting the SCP rules to permit public access blocks without interfering with &lt;a href="https://aws.amazon.com/what-is/iac/" target="_blank" rel="noopener"&gt;infrastructure as code (IaC)&lt;/a&gt; deployments.&lt;/li&gt; 
 &lt;li&gt;Amazon Bedrock model availability required explicit &lt;a href="https://docs.aws.amazon.com/glossary/latest/reference/glos-chap.html" target="_blank" rel="noopener"&gt;Region&lt;/a&gt; configuration to align with ITHAKA’s account constraints.&lt;/li&gt; 
 &lt;li&gt;ITHAKA’s engineers used agentic coding tools to accelerate the adaptation work during the workshop.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Following the workshop, ITHAKA and AWS held multiple working sessions through April 2026 to support production deployment, addressing pipeline tuning for ITHAKA’s specific corpus characteristics, deployment refinements, and production readiness validation.&lt;/p&gt; 
&lt;h2&gt;Results&lt;/h2&gt; 
&lt;p&gt;Early results from the pipeline demonstrate the viability of on-demand remediation at scale.&lt;/p&gt; 
&lt;table border="2"&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Metric&lt;/th&gt; 
   &lt;th&gt;Result&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Accessibility check pass rate&lt;/td&gt; 
   &lt;td&gt;98%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Cost per page&lt;/td&gt; 
   &lt;td&gt;$0.026&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Cost reduction compared to manual remediation&lt;/td&gt; 
   &lt;td&gt;97%+ (from approximately $1–4 per page)&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Time from workshop to production deployment&lt;/td&gt; 
   &lt;td&gt;Approximately 2 months&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;blockquote&gt;
 &lt;p&gt;&lt;em&gt;Dane Hillard, associate director of Product Engineering at ITHAKA said, “Our collaborators at AWS were incredibly helpful in understanding what others were already doing in the accessibility remediation space, thinking through how we could adopt and adapt prior work, and in validating approaches we had thought of toward creating something sustainable in support of our accessibility mission.”&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt; 
&lt;p&gt;The on-demand model means ITHAKA remediates PDFs as users request them. Each remediated document is cached for future users, so the accessible content library grows with actual demand. Over time, the most-requested content is remediated first, directing resources to where they serve the most people.&lt;/p&gt; 
&lt;h2&gt;Looking ahead&lt;/h2&gt; 
&lt;p&gt;ITHAKA plans to extend the pipeline to support remediation at content ingestion, processing new PDFs as they arrive from publishers. &lt;a href="https://www.portico.org/" target="_blank" rel="noopener"&gt;Portico&lt;/a&gt;, ITHAKA’s digital preservation service, is exploring applying a similar approach to its own corpus.&lt;/p&gt; 
&lt;p&gt;The modular pipeline architecture positions ITHAKA to adopt emerging generative AI tools as they become available, without rebuilding core infrastructure. As the economics of AI-driven remediation continue to improve, ITHAKA is working toward costs below $0.01 per page at scale.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://github.com/ASUCICREPO/PDF_Accessibility" target="_blank" rel="noopener"&gt;underlying solution&lt;/a&gt; remains open source. Other institutions—universities, libraries, government agencies, and nonprofits—facing similar accessibility challenges can adapt it for their own environments and content types. The ADA title II compliance deadline applies broadly, and many organizations hold large PDF collections that need remediation. This post demonstrates that there is an affordable, achievable path to compliance, one that meets users where they are, without the upfront cost of remediating an entire collection. The architecture and approach are designed to be replicable.&lt;/p&gt; 
&lt;h2&gt;Get started&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt;Learn more about &lt;a href="https://aws.amazon.com/education/higher-ed/" target="_blank" rel="noopener"&gt;AWS Cloud for Higher Education.&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;If your organization is working on document accessibility, fill out the &lt;a href="https://aws.amazon.com/government-education/contact/" target="_blank" rel="noopener"&gt;AWS Public Sector – Contact Us&lt;/a&gt; form.&lt;/li&gt; 
&lt;/ul&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>How HOT uses open source on AWS to power humanitarian AI</title>
		<link>https://aws.amazon.com/blogs/publicsector/how-hot-uses-open-source-on-aws-to-power-humanitarian-ai/</link>
		
		<dc:creator><![CDATA[DK Benjamin]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 20:18:29 +0000</pubDate>
				<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">19de87eac77061b39eb11cf1413ce1229cbae714</guid>

					<description>When disasters strike, the first thing responders need is an accurate map. But for much of the world, detailed maps don’t exist. Humanitarian OpenStreetMap Team (HOT) has been fulfilling that need since 2010. Today, HOT is a global network of over 500,000 contributors across 94 countries. By combining local ground-truth mapping, regional hubs, and open source tools, HOT coordinates massive, crowdsourced efforts to provide immediate data to responders without licensing costs or procurement barriers.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32191 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/How-HOT-uses-open-source-on-AWS-to-power-humanitarian-AI.png" alt="How HOT uses open source on AWS to power humanitarian AI" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;When disasters strike, the first thing responders need is an accurate map. But for much of the world, detailed maps don’t exist. &lt;a href="https://www.hotosm.org/" target="_blank" rel="noopener"&gt;Humanitarian OpenStreetMap Team (HOT)&lt;/a&gt; has been fulfilling that need since 2010. Today, HOT is a global network of over 500,000 contributors across 94 countries. By combining local ground-truth mapping, regional hubs, and open source tools, HOT coordinates massive, crowdsourced efforts to provide immediate data to responders without licensing costs or procurement barriers.&lt;/p&gt; 
&lt;p&gt;However, manually tracing satellite imagery is slow when time is critical. To accelerate mapping, HOT developed &lt;a href="https://fair-dev.hotosm.org/" target="_blank" rel="noopener noreferrer"&gt;fAIr&lt;/a&gt;, an open source, AI-assisted tool that detects geographic features for human verification, giving volunteers a head start. This post explores the architecture behind fAIr, which HOT built on &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener noreferrer"&gt;Amazon Web Services (AWS)&lt;/a&gt; with a tech stack composed almost entirely of open source tools, bridging open source innovation and cloud infrastructure to scale community impact.&lt;/p&gt; 
&lt;p&gt;
 &lt;!-- ==================== SECTION: HOW fAIr WORKS ==================== --&gt;&lt;/p&gt; 
&lt;h2&gt;How fAIr works&lt;/h2&gt; 
&lt;p&gt;A mapper traditionally opens a satellite image tile and manually traces every visible building footprint. This is a time-consuming process that keeps mappers from building a complete, accurate map of the disaster area in time for responders.&lt;/p&gt; 
&lt;p&gt;With fAIr, the mapper opens the same tile and sees predrawn polygons already overlaid. Their job shifts away from having to trace everything manually. Instead, mappers review, correct, and approve the work created by the AI tool. Users can also fine-tune per region because the models are localized to that specific area.&lt;/p&gt; 
&lt;p&gt;The following image shows AI-generated building footprint predictions (the purple polygons) overlaid on drone imagery using the YOLO_V8_V2 model. Mappers can review the image, correct any mistakes, and approve each prediction rather than tracing from scratch. For a demo of the process, visit the &lt;a href="https://fair-dev.hotosm.org/learn" target="_blank" rel="noopener noreferrer"&gt;fAIr Learn page&lt;/a&gt;.&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-1-Drone-image-overlaid-with-building-footprint-predictions.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32199 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-1-Drone-image-overlaid-with-building-footprint-predictions.png" alt="Screenshot of a drone image showing buildings of various sizes and shapes. Each building is overlaid with a purple polygon outlining its shape." width="583" height="326"&gt;&lt;/a&gt;&lt;em&gt;Figure 1: Drone image overlaid with building footprint predictions&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;
 &lt;!-- ==================== SECTION: TECHNICAL ARCHITECTURE ==================== --&gt;&lt;/p&gt; 
&lt;h2&gt;Technical architecture&lt;/h2&gt; 
&lt;p&gt;This section walks through fAIr’s architecture in three parts: where data is stored, how models get trained, and how predictions get served. Each layer pairs AWS infrastructure with open source tooling for the job.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://aws.amazon.com/s3/" target="_blank" rel="noopener noreferrer"&gt;Amazon Simple Storage Service (Amazon S3)&lt;/a&gt; serves as the central artifact and model repository for low-cost storage. PostgreSQL databases, managed by the &lt;a href="https://cloudnative-pg.io/" target="_blank" rel="noopener noreferrer"&gt;CloudNativePG&lt;/a&gt; operator, handle runtime metadata and the SpatioTemporal Asset Catalog (STAC) database, which serves as the registry for &lt;a href="https://opengeoai.org/" target="_blank" rel="noopener"&gt;GeoAI&lt;/a&gt; models.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://www.zenml.io/" target="_blank" rel="noopener noreferrer"&gt;ZenML&lt;/a&gt; MLOps framework on &lt;a href="https://aws.amazon.com/eks/" target="_blank" rel="noopener noreferrer"&gt;Amazon Elastic Kubernetes Service (Amazon EKS)&lt;/a&gt; orchestrates training, provisioning ephemeral NVIDIA GPU instances using &lt;a href="https://karpenter.sh/" target="_blank" rel="noopener noreferrer"&gt;Karpenter&lt;/a&gt; only when jobs are requested. This scale-to-zero approach eliminates GPU costs when training is inactive. Upon completion, ZenML updates the artifact store and registers the new model into the STAC API and streams metrics to &lt;a href="https://mlflow.org/genai/observability" target="_blank" rel="noopener"&gt;MLflow&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;To secure low-latency performance, inference is decoupled from training using &lt;a href="https://knative.dev/" target="_blank" rel="noopener noreferrer"&gt;Knative&lt;/a&gt; for serverless workload management. The system uses CPU-based scaling on &lt;a href="https://aws.amazon.com/ec2/" target="_blank" rel="noopener noreferrer"&gt;Amazon Elastic Compute Cloud (Amazon EC2)&lt;/a&gt; instances to run the models, eliminating the need for permanently running GPU infrastructure while responding to client requests quickly with predicted features.&lt;/p&gt; 
&lt;p&gt;The entire system architecture is provisioned with Helm Charts and deployed using &lt;a href="https://argo-cd.readthedocs.io/en/stable/" target="_blank" rel="noopener"&gt;ArgoCD&lt;/a&gt;. This &lt;a href="https://aws.amazon.com/what-is/iac/" target="_blank" rel="noopener"&gt;infrastructure as code (IaC)&lt;/a&gt; approach keeps environments consistent, making staging-to-production transitions seamless and reproducible.&lt;/p&gt; 
&lt;p&gt;The following diagram shows the fAIr architecture. For more information, visit the &lt;a href="https://github.com/hotosm/fAIr" target="_blank" rel="noopener noreferrer"&gt;fAIr mapping tool &lt;/a&gt;repo on GitHub.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-2-fAIr-technical-architecture.jpg" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32198 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-2-fAIr-technical-architecture.jpg" alt="Architecture diagram of fAIr's tech stack showing the flow from developers pushing code to GitHub, through a CI/CD pipeline, to an EKS cluster running ML training and inference workloads with open source tools such as ArgoCD, MLFlow, ZenML, eoAPI and CloudNativePG. Users access the platform through CloudFront." width="1430" height="865"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 2: fAIr technical architecture&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;
 &lt;!-- ==================== SECTION: COMMUNITY IMPACT ==================== --&gt;&lt;/p&gt; 
&lt;h2&gt;Community impact&lt;/h2&gt; 
&lt;p&gt;In addition to producing data quickly, HOT’s open source mapping ecosystem changes how communities prepare for, respond to, and recover from crises. The following examples show how these tools translate into real-world outcomes.&lt;/p&gt; 
&lt;p&gt;
 &lt;!-- ==================== SUB-SECTION: VENEZUELA ==================== --&gt;&lt;/p&gt; 
&lt;h3&gt;How fAIr was used in the Venezuela response&lt;/h3&gt; 
&lt;p&gt;Most recently, an area outside of Caracas, Venezuela, was impacted by earthquakes on June 24, 2026. As part of the &lt;a href="https://www.hotosm.org/en/projects/2026-venezuela-earthquake-response/" target="_blank" rel="noopener"&gt;response&lt;/a&gt;, HOT activated to bring high-quality, up-to-date data to communities working on the ground for recovery efforts, coordinating with the United Nations’ International Organization for Migration (IOM), MapAction, iMMAP, and GiveDirectly. Through &lt;a href="https://vantor.com/company/open-data-program/" target="_blank" rel="noopener"&gt;Vantor’s Open Data Program&lt;/a&gt;, recent high-resolution satellite imagery was made open source, and the HOT team immediately began running the imagery through fAIr to generate an initial picture of the damage to affected communities. Within 24 hours of the event, fAIr outputs were delivered to key early responders, providing data on building density, AI-assisted building digitization, and building damage predictions.&lt;/p&gt; 
&lt;p&gt;HOT didn’t release raw AI predictions as final data. The team merged outputs from fAIr and the Microsoft AI For Good Lab, then used the open source tool &lt;a href="https://mapswipe.org/" target="_blank" rel="noopener noreferrer"&gt;MapSwipe&lt;/a&gt; to crowdsource human validation of every prediction. The first batch of human-validated damage assessment was completed for three cities, Caraballeda, La Guaira, and Caracas, representing the most complete validated dataset produced for this event. In parallel, 451 volunteer mappers digitized approximately 53,000 buildings through the &lt;a href="https://tasks.hotosm.org/" target="_blank" rel="noopener noreferrer"&gt;HOT Tasking Manager&lt;/a&gt; in less than a week.&lt;/p&gt; 
&lt;p&gt;The following image shows the fAIr building density estimation for northern Venezuela. The darker hexagons indicate higher concentrations of buildings, helping responders prioritize search and rescue operations.&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-3-fAIr-building-density-estimation-for-northern-Venezuela.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32197 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-3-fAIr-building-density-estimation-for-northern-Venezuela.png" alt="Screenshot of a map of northern Venezuela showing building density. Lighter polygons show less density and darker polygons show more density. " width="600" height="335"&gt;&lt;/a&gt;&lt;em&gt;Figure 3: fAIr building density estimation for northern Venezuela&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;The following screenshot shows a fAIr damage assessment model predicting different levels of damage in Catia La Mar, Venezuela, based on pre- and post-event imagery.&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-4-fAIr-damage-assessment-model-predicting-different-levels-of-damage-based-on-pre-and-post-event-imagery.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32196 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-4-fAIr-damage-assessment-model-predicting-different-levels-of-damage-based-on-pre-and-post-event-imagery.png" alt="Screenshot showing a fAIr damage assessment model predicting different levels of damage in Catia La Mar, Venezuela, based on pre- and post-event imagery." width="844" height="498"&gt;&lt;/a&gt;&lt;em&gt;Figure 4: fAIr damage assessment model predicting different levels of damage based on pre- and post-event imagery. Source: Kshitij Sharma&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;
 &lt;!-- ==================== SUB-SECTION: SIERRA LEONE ==================== --&gt;&lt;/p&gt; 
&lt;h3&gt;Mapping for Climate Ready Cities: Sierra Leone&lt;/h3&gt; 
&lt;p&gt;Across Bangladesh and 12 other countries, the &lt;a href="https://www.hotosm.org/en/programs/climate-ready-cities/" target="_blank" rel="noopener"&gt;Mapping for Climate Ready Cities&lt;/a&gt; program puts mapping tools in the hands of communities documenting transit networks, drainage infrastructure, and accessibility gaps. This data feeds into resilience planning such as evacuation plans for at least 80 households in Timor-Leste; drainage upgrades in Nakuru, Kenya, which have benefitted over 10,000 residents; clearer directions for investment in heat-resilient public spaces for the 60,000 residents of Maipú, Chile; and the potential to protect over 3.5 million people in Nigeria’s growing cities through air-quality monitoring.&lt;/p&gt; 
&lt;p&gt;In Freetown, Sierra Leone, the program focuses on heat resilience. Working with local organizations including Convention for a Democratic South Africa (CODESA), the Federation of Informal Settlements (FODU), and OSM Sierra Leone, the team trains university students and community members to capture drone imagery, digitize features using fAIr, and collect ground-truth data using &lt;a href="https://www.hotosm.org/en/tools-resources/tech-product-suite/field-tasking-manager/" target="_blank" rel="noopener"&gt;Field Tasking Manager&lt;/a&gt;. From approximately 550 square kilometers of drone imagery, the team digitized all visible features and shared them with the Freetown City Council (FCC).&lt;/p&gt; 
&lt;p&gt;fAIr identifies trees and solar panels from aerial imagery, helping planners understand where shade and cooling exist. “We have more time to go to the field for data collection because we spent less time on digitalization,” says Lamine N’Diaye, project coordinator at HOT in Sierra Leone. The data has already influenced policy where the FCC used it to build a new taxation plan for marketplace areas, and the same dataset supports emergency access planning. Before HOT’s tools arrived, communities had the will to adapt but not the means. “People have many initiatives for mitigation, but we didn’t know the right technology to do that,” Lamine explains. fAIr is positioned to accelerate this work.&lt;/p&gt; 
&lt;p&gt;Countries participating in HOT’s Mapping for Climate Ready Cities program span Latin America, West Africa, East Africa, and South Asia.&lt;/p&gt; 
&lt;p&gt;
 &lt;!-- ==================== SUB-SECTION: INDONESIA ==================== --&gt;&lt;/p&gt; 
&lt;h3&gt;Map4Mangrove: Indonesia&lt;/h3&gt; 
&lt;p&gt;In Indonesia, the &lt;a href="https://www.hotosm.org/en/projects/map4mangrove-indonesia/" target="_blank" rel="noopener"&gt;Map4Mangrove&lt;/a&gt; project works with coastal rehabilitation organizations to map mangrove coverage and improve monitoring using open spatial data. After a 2018 tsunami struck Pandeglang in Banten, the Indonesian Biodiversity Foundation (KEHATI) and local conservation group SALAKA launched the Blue Carbon Program, a rehabilitation initiative covering 14 hectares across five sites. But monitoring relied on paper-based records, making reporting labor-intensive and difficult for donors to verify.&lt;/p&gt; 
&lt;p&gt;Through Map4Mangrove, HOT’s Asia-Pacific Hub trained 20–30 university students on Field Tasking Manager, KoboToolbox, and Mapillary, then built a centralized &lt;a href="https://bit.ly/map4mangrove-dashboard" target="_blank" rel="noopener"&gt;UMap dashboard&lt;/a&gt; integrating drone imagery, geotagged field data, and carbon sequestration estimates. “The donor didn’t need to go to the field, they could just see the geotagged image on Mapillary and compare it with the collected data,” says Dinar Adiatma, data quality lead at HOT’s Asia-Pacific Hub.&lt;/p&gt; 
&lt;p&gt;The following image shows a mangrove rehabilitation site in Banten, Indonesia. The Map4Mangrove project monitors five sites like this one across 14 hectares, tracking growth and carbon sequestration through open mapping tools.&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-5-A-mangrove-rehabilitation-site-in-Banten-Indonesia..jpg" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32195 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-5-A-mangrove-rehabilitation-site-in-Banten-Indonesia..jpg" alt="Photograph of young mangroves planted in a sandy area." width="1377" height="772"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 5: A mangrove rehabilitation site in Banten, Indonesia. Photo: Tony Liong, Open Mapping Hub – Asia-Pacific&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;Two students maintain the dashboard full time, and SALAKA has begun extending the approach to fish distribution data from local fishermen. In the following image, the Map4Mangrove field team reviews drone imagery at the Banten rehabilitation site.&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-6-The-Map4Mangrove-field-team-reviews-drone-imagery.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32194 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/22/Figure-6-The-Map4Mangrove-field-team-reviews-drone-imagery.png" alt="Four people standing on a beach, gathered around and looking at a printed copy of drone images. " width="1376" height="771"&gt;&lt;/a&gt;&lt;em&gt;Figure 6: The Map4Mangrove field team reviews drone imagery. Photo: Tony Liong, Open Mapping Hub – Asia-Pacific&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;
 &lt;!-- ==================== SECTION: WHAT CONNECTS THESE STORIES ==================== --&gt;&lt;/p&gt; 
&lt;h2&gt;What connects these stories&lt;/h2&gt; 
&lt;p&gt;Each example follows a common pattern: open source tools lower participation barriers, AWS scales compute when needed, AI accelerates tedious work, and human validation improves quality and accuracy. Whether assessing earthquake damage in Caracas, identifying heat islands in Freetown, or monitoring mangrove rehabilitation in Banten, the architecture stays the same. The community changes, the model changes, but the platform holds.&lt;/p&gt; 
&lt;p&gt;
 &lt;!-- ==================== SECTION: GET INVOLVED ==================== --&gt;&lt;/p&gt; 
&lt;h2&gt;Get involved&lt;/h2&gt; 
&lt;p&gt;Visit &lt;a href="https://www.hotosm.org/" target="_blank" rel="noopener noreferrer"&gt;HOT&lt;/a&gt; to learn more about their work. To start mapping, join a task on the &lt;a href="https://tasks.hotosm.org/" target="_blank" rel="noopener noreferrer"&gt;HOT Tasking Manager&lt;/a&gt;. To explore fAIr and its open source AI models, visit the &lt;a href="https://fair-dev.hotosm.org/" target="_blank" rel="noopener noreferrer"&gt;fAIr &lt;/a&gt;project page. To learn more about how AWS supports customers and partners to innovate across health, education, and climate, check out &lt;a href="https://aws.amazon.com/government-education/nonprofits/" target="_blank" rel="noopener noreferrer"&gt;AWS Impact&lt;/a&gt; and &lt;a href="https://registry.opendata.aws/collab/open-data-sponsorship-program/" target="_blank" rel="noopener noreferrer"&gt;Open Data Sponsorship Program&lt;/a&gt;.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>FSU researchers improve cloud skills with AWS Research Skilling Accelerator</title>
		<link>https://aws.amazon.com/blogs/publicsector/fsu-researchers-improve-cloud-skills-with-aws-research-skilling-accelerator/</link>
		
		<dc:creator><![CDATA[Jay Nappy]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 20:19:17 +0000</pubDate>
				<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">b544a6f5e84bee3b43d7ebd637e3772fa25a41f6</guid>

					<description>Learn how at FSU, the university’s partnership with AWS has already delivered meaningful results, including a $20,000 Research Acceleration Fund that provides AWS credits to faculty and no-cost cloud services training available campus-wide. But researchers wanted something more: a structured, guided program that would build practical cloud skills around real research scenarios.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32066 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/14/FSU-researchers-improve-cloud-skills-with-AWS-Research-Skilling-Accelerator.png" alt="FSU researchers improve cloud skills with AWS Research Skilling Accelerator" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;Modern research is increasingly data-intensive. Whether analyzing millions of satellite images for transportation safety, building predictive models from sensitive health records, or running high-performance computing workloads, today’s researchers need cloud and AI skills to accelerate science. At Florida State University (FSU), a growing community of faculty, staff, and students is proving what’s possible when researchers gain hands-on cloud expertise. The &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; Research Skilling Accelerator (RSA) is helping make it happen.&lt;/p&gt; 
&lt;h2&gt;The challenge: Bridging the cloud and AI skills gap in research&lt;/h2&gt; 
&lt;p&gt;Universities across the globe face a common challenge: Researchers generate massive datasets and need powerful computing capabilities, but many lack the cloud or AI skills to take full advantage of the tools available to them. Traditional training often doesn’t account for the unique workflows of health science researchers or the infrastructure professionals who support them.&lt;/p&gt; 
&lt;p&gt;At FSU, the university’s partnership with AWS has already delivered meaningful results, including a $20,000 Research Acceleration Fund that provides AWS credits to faculty and &lt;a href="https://its.fsu.edu/services/professional-services/cloud-services-training" target="_blank" rel="noopener"&gt;no-cost cloud services training&lt;/a&gt; available campus-wide. But researchers wanted something more: a structured, guided program that would build practical cloud skills around real research scenarios.&lt;/p&gt; 
&lt;h2&gt;Introducing the AWS Research Skilling Accelerator&lt;/h2&gt; 
&lt;p&gt;The AWS Research Skilling Accelerator (RSA) is a structured, 5-week, no-cost cloud skilling program designed specifically for health science researchers and research IT professionals at universities. Participants complete hands-on labs in &lt;a href="https://catalog.workshops.aws/" target="_blank" rel="noopener"&gt;AWS Workshop Studio&lt;/a&gt; built around authentic health science datasets and scenarios. The curriculum covers five progressive modules:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;AI-powered research tools with Kiro&lt;/strong&gt; – Participants use Kiro, an AI-powered integrated development environment (IDE), to explore agentic coding workflows purpose-built for accelerating research software development.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Machine learning model development with Amazon SageMake&lt;/strong&gt;r – Researchers build, train, and deploy machine learning (ML) models using Amazon SageMaker, applying techniques like feature engineering and hyperparameter tuning to health science datasets.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Genomics research agents with Amazon Bedrock and Agents Strands SDK&lt;/strong&gt; – Participants construct AI-powered research agents using &lt;a href="https://aws.amazon.com/bedrock/" target="_blank" rel="noopener"&gt;Amazon Bedrock&lt;/a&gt; and the &lt;a href="https://strandsagents.com/" target="_blank" rel="noopener"&gt;Strands Agents SDK&lt;/a&gt; to automate genomics literature review and data analysis tasks.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Cost optimization for research workloads&lt;/strong&gt; – Participants focus on right-sizing compute resources, using Spot Instances, and using AWS cost management tools to maximize research budgets.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Specialized elective (medical image classification or high-performance compute bursting)&lt;/strong&gt; – Researchers choose between building a medical image classification pipeline using deep learning on AWS or configuring hybrid high-performance compute (HPC) bursting to scale on-premises clusters into the cloud for computationally intensive simulations.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The program runs with two parallel tracks built for both researchers and research IT professionals so those doing the science and those supporting the infrastructure gain practical, directly applicable skills in tandem. Throughout the 5 weeks, participants engage with AWS Solutions Architects through discussion hours, dedicated communication channels, and hands-on program support. Those who complete all five assignments receive AWS promotional credits to continue exploring on their own.&lt;/p&gt; 
&lt;h2&gt;FSU’s experience with the RSA&lt;/h2&gt; 
&lt;p&gt;FSU was initially selected as a pilot school for the first RSA cohort in October 2025 with four participants, and then re-enrolled in the second cohort with double the typical enrollment, which is a testament to the university’s commitment to building cloud competency across its research enterprise. FSU RSA participants included both research IT and research participants who reported gaining skills they could immediately apply to their work.&lt;/p&gt; 
&lt;p&gt;When asked how the RSA has impacted researchers and research IT professionals at FSU, Breeze Howard, director of IT Infrastructure Services, responded, “The Research Skilling Accelerator has given FSU researchers a practical path to build cloud and AI skills they can apply directly to their work. Faculty have responded very positively to the program because it connects hands-on training with real research challenges and helps them move faster from idea to discovery.”&lt;/p&gt; 
&lt;p&gt;Balu Bhasuran, research faculty in FSU’s School of Information specializing in Clinical NLP and Machine Learning, shared their experience as a participant of the program: “The RSA helped me develop a scalable data analysis pipeline using Amazon SageMaker, enabling more efficient processing and analysis of research data. Working with Amazon Q and AWS Cost Builder was also a valuable experience, helping me better understand cloud-based development, resource planning, and cost management.”&lt;/p&gt; 
&lt;h2&gt;Results that speak for themselves&lt;/h2&gt; 
&lt;p&gt;Across two cohorts spanning 11 universities globally, the RSA has reached 102 active participants and delivered measurable outcomes:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;NPS of 51&lt;/strong&gt;, indicating strong participant advocacy (industry benchmark sits at 30 for education and training programs)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;91% satisfaction&lt;/strong&gt; (CSAT 4.5 out of 5)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;72% full completion rate&lt;/strong&gt; (percentage of active participants who completed all five assignments; industry benchmark sits at 15–25% for structured online learning cohorts)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;25% increase&lt;/strong&gt; in self-reported AWS comfort levels&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AWS plans to begin its third cohort with a target of 30 institutions globally, including repeat participation from FSU and seven other R1 research universities across the US, Canada, and the UK.&lt;/p&gt; 
&lt;h2&gt;A model for research cloud adoption&lt;/h2&gt; 
&lt;p&gt;The RSA represents a scalable approach to closing the cloud skills gap in higher education research. By meeting researchers where they are with health science-specific scenarios, dual tracks for different roles, and ongoing expert support, the program builds confidence alongside competence.&lt;/p&gt; 
&lt;p&gt;If your university is interested in bringing the AWS RSA to your campus, contact the AWS Research Skilling Accelerator team at &lt;a href="mailto:aws-rsa@amazon.com" target="_blank" rel="noopener"&gt;aws-rsa@amazon.com&lt;/a&gt;. Visit the &lt;a href="https://aws.amazon.com/blogs/publicsector/" target="_blank" rel="noopener"&gt;AWS Public Sector Blog&lt;/a&gt; to explore how cloud computing is accelerating scientific discovery across disciplines.&lt;/p&gt;</content:encoded>
					
		
		
			</item>
		<item>
		<title>One scan, many findings: Floy’s foundation model platform for opportunistic screening on AWS</title>
		<link>https://aws.amazon.com/blogs/publicsector/one-scan-many-findings-floys-foundation-model-platform-for-opportunistic-screening-on-aws/</link>
		
		<dc:creator><![CDATA[Kenneth Schröder]]></dc:creator>
		<pubDate>Mon, 24 Aug 2026 14:18:01 +0000</pubDate>
				<category><![CDATA[Amazon EC2]]></category>
		<category><![CDATA[Amazon Simple Queue Service (SQS)]]></category>
		<category><![CDATA[Amazon Simple Storage Service (S3)]]></category>
		<category><![CDATA[AWS Fargate]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[Public Sector]]></category>
		<guid isPermaLink="false">5ed87fa2d4876ebe22aa15f6bf332c8f36b421a7</guid>

					<description>This post describes how Floy built an FM-based AI platform on AWS, from training and inference to clinical integration, that scales to meet the demands of modern radiology.</description>
										<content:encoded>&lt;p&gt;&lt;img loading="lazy" class="size-full wp-image-32118 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/One-scan-many-findings-Floys-foundation-model-platform-for-opportunistic-screening-on-AWS.png" alt="One scan, many findings: Floy’s foundation model platform for opportunistic screening on AWS" width="1152" height="576"&gt;&lt;/p&gt; 
&lt;p&gt;Osteoporosis, cardiovascular disease, and neurodegenerative conditions affect tens of millions of Europeans, yet the majority go undiagnosed. Evidence of these conditions is often already visible on routine CT and MRI scans acquired for entirely different clinical questions, at no additional imaging, radiation, or cost. For example, 73 percent of women eligible for osteoporosis treatment in the EU’s six largest markets do not receive it (Borgström et al., Archives of Osteoporosis 2020), largely because formal assessment requires a dedicated dual-energy X-ray absorptiometry (DEXA) scan. Yet bone density loss is measurable on routine scans already being acquired.&lt;/p&gt; 
&lt;p&gt;These conditions go undetected not because the evidence is absent, but because no systematic process exists to look for them. With MRI exams in Germany alone totaling 13.5 million in 2023 (Eurostat Healthcare Resource Statistics 2023), this gap between what imaging data contains and what gets reported represents a population-scale public health opportunity. Closing it requires AI systems that are accurate, fast, and traceable end to end, not only for research rigor but for the regulatory audit trails mandated under EU MDR Class IIb medical device requirements&lt;/p&gt; 
&lt;p&gt;Opportunistic screening means analyzing scans already acquired for one clinical question to detect unrelated conditions at no extra cost or radiation to the patient. Making this systematic, in clinical routine, at scale, is the problem Floy was built to solve. Floy is a Munich-based medical AI company whose foundation model (FM)-based platform is deployed across more than 200 radiology practices in Germany, has processed over 100,000 studies, and handles hundreds of new scans daily. The platform returns structured AI reports within 5 minutes of image acquisition, routinely surfacing clinically relevant findings, including aneurysms with a 36.2 percent increased detection rate (Teodorescu et al., Journal of Stroke and Cerebrovascular Diseases 2024) and bone lesions detected 5.7 months earlier than by unassisted radiologists (Fritzsche, M., Kara-Schmidt, P., Kirchler, M., Schroeder, K., Wiedemeyer, C., &amp;amp; Braunschneider, L. E. (2026). Enabling earlier detection of spinal lesions in CT imaging with artificial intelligence—a case study. Frontiers in Artificial Intelligence, 9, 1767814). Built on &lt;a href="https://aws.amazon.com/" target="_blank" rel="noopener"&gt;Amazon Web Services (AWS)&lt;/a&gt; and certified up to EU MDR Class IIb, the platform combines large-scale self-supervised pre-training with the elastic, secure infrastructure required for regulated clinical deployment. In February 2025, Floy closed an extended seed round of €9 million.&lt;/p&gt; 
&lt;p&gt;This post describes how Floy built an FM-based AI platform on AWS, from training and inference to clinical integration, that scales to meet the demands of modern radiology.&lt;/p&gt; 
&lt;h2&gt;The clinical challenge: Opportunistic screening at scale&lt;/h2&gt; 
&lt;p&gt;When a patient undergoes an MRI of the head, the radiologist focuses on answering the referring physician’s clinical question. But the same scan might contain early indicators of Global Cortical Atrophy (GCA), Fazekas-graded white matter lesions, or other findings with significant long-term clinical implications. Catching these routinely, on every applicable study, requires consistent, quantitative analysis that can be difficult for humans to perform reliably under time pressure at volume.&lt;/p&gt; 
&lt;p&gt;Floy’s medical devices perform exactly this analysis automatically across head, shoulder, breast, thorax/abdomen, and knee imaging, triggered by a single click from the radiology information system (RIS). The platform retrieves applicable prior studies, preprocesses the imaging data, runs it through up to 14 AI models in the cloud, and delivers a structured report without requiring the radiologist to change their workflow.&lt;/p&gt; 
&lt;p&gt;The scale of this operation demands infrastructure that is simultaneously fast, elastic, cost-efficient, and compliant with stringent European medical device regulations. Floy built this capability on AWS.&lt;/p&gt; 
&lt;h2&gt;Domain-specific foundation models: A platform for clinical AI&lt;/h2&gt; 
&lt;p&gt;The core of Floy’s next-generation head products is an MR Head FM trained on more than 11 million MRI slices drawn from 175,000 head studies. Floy developed the research in collaboration with the German Cancer Research Center (DKFZ) as part of the Human Radiome Project.&lt;/p&gt; 
&lt;p&gt;Rather than build a separate model from scratch for each clinical question, Floy’s model learns a general understanding of brain MRI across scanners, protocols, and patient populations through self-supervised learning on hundreds of thousands of scans, with no manual annotation. The training method builds on Franca, an extension of the DINOv2 self-supervised learning paradigm, which Floy fine-tuned on large collections of radiology scans. The model learns to produce consistent internal representations from differently augmented views of the same scan, forcing it to capture what is anatomically meaningful rather than superficial pixel patterns.&lt;/p&gt; 
&lt;p&gt;The resulting Vision Transformer serves as a frozen base on which Floy trains lightweight, task-specific classifiers. The FM itself never changes; only the thin layer on top does. This is what makes the approach a platform rather than a product.&lt;/p&gt; 
&lt;p&gt;The following diagram illustrates the FM training pipeline.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/Figure-1-Foundation-model-training-pipeline.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32128 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/Figure-1-Foundation-model-training-pipeline.png" alt="Figure 1 Foundation model training pipeline" width="509" height="392"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p style="text-align: center"&gt;&lt;em&gt;Figure 1: Foundation model training pipeline: A single self-supervised base encoder (center) is fine-tuned into multiple EU MDR-certified medical devices (right) from small annotated datasets (left)&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;The payoff is both technical and clinical: on internal benchmarks, the approach improved average performance by 3.3 percent and cut training time by roughly 94 percent compared to classical 3D convolutional neural networks. Because the shared base is reused, a new indication can move from research to clinical deployment in a fraction of the time previously required, meaning patients gain access to new detection capabilities sooner.&lt;/p&gt; 
&lt;h2&gt;The MLOps stack: Valohai and AWS&lt;/h2&gt; 
&lt;p&gt;Fast iteration in a regulated environment requires full traceability from annotation to deployment. All data processing, model training, and evaluation runs on Valohai, a machine learning operations (MLOps) platform connected to Floy’s AWS data stores and GPU compute. Valohai operates on a split architecture: its management control plane is a hosted software as a service (SaaS) offering on AWS, and the data and compute plane runs entirely inside Floy’s private AWS account.&lt;/p&gt; 
&lt;p&gt;Every experiment is fully traceable from data ingestion to final evaluation, a requirement not only for research rigor but for the regulatory audit trails required under EU MDR.&lt;/p&gt; 
&lt;p&gt;Floy’s team produces training annotations on Encord and exports them directly to Valohai for processing. The development environments use custom Docker images with shared base images across all execution contexts (Valohai training jobs, local devcontainers, and production inference), so the model seen in evaluation is the model that runs in the clinic.&lt;/p&gt; 
&lt;h2&gt;The integration architecture: From PACS to report in 5 minutes&lt;/h2&gt; 
&lt;p&gt;Foundation model performance is necessary but not sufficient for clinical adoption. One of the harder problems is getting AI results into the clinical workflow reliably, automatically, and fast enough to be useful before the radiologist has moved on to the next case.&lt;/p&gt; 
&lt;p&gt;A single click from the radiologist’s RIS triggers the entire Floy workflow. A local integration component retrieves the new study and applicable prior exams from the Picture Archiving and Communication System (PACS) while acquisition is still underway, adaptively beginning processing as soon as sufficient data is available and reducing wait times by up to 50 percent. A local AI-based filter evaluates more than 30 metadata tags to determine which medical device modules apply.&lt;/p&gt; 
&lt;p&gt;The pipeline uploads preprocessed Digital Imaging and Communications in Medicine (DICOM) data to &lt;a href="https://aws.amazon.com/s3/" target="_blank" rel="noopener"&gt;Amazon Simple Storage Service (Amazon S3)&lt;/a&gt; and hands it off to Floy’s cloud-based pipeline. Fourteen AI models run on GPU-accelerated &lt;a href="https://aws.amazon.com/ec2/" target="_blank" rel="noopener"&gt;Amazon Elastic Compute Cloud (Amazon EC2)&lt;/a&gt; G5 instances. A custom &lt;a href="https://aws.amazon.com/sqs/" target="_blank" rel="noopener"&gt;Amazon Simple Queue Service (Amazon SQS)&lt;/a&gt; driven &lt;a href="https://aws.amazon.com/lambda/" target="_blank" rel="noopener"&gt;AWS Lambda&lt;/a&gt; function automatically scales the fleet based on queue depth and time-based scheduling, scaling to zero overnight for cost-efficiency. Floy deploys additional services as &lt;a href="https://aws.amazon.com/ecs/" target="_blank" rel="noopener"&gt;Amazon Elastic Container Service (Amazon ECS)&lt;/a&gt; on &lt;a href="https://aws.amazon.com/fargate" target="_blank" rel="noopener"&gt;AWS Fargate&lt;/a&gt; tasks, with a Kong API Gateway handling routing and a FastAPI-based backend managing business logic. The full pipeline completes in approximately 5 minutes, with real-time status updates streamed to the clinician throughout.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://aws.amazon.com/rds/postgresql/" target="_blank" rel="noopener"&gt;Amazon Relational Database Service (Amazon RDS)&lt;/a&gt; for PostgreSQL stores the processing metadata, including automatically issued Unique Device Identification (UDI) labels and model version numbers for every study, providing the audit trail required under EU MDR.&lt;/p&gt; 
&lt;p&gt;The following diagram illustrates the solution architecture.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/Figure-2-Floys-production-architecture-on-AWS.png" target="_blank" rel="noopener"&gt;&lt;img loading="lazy" class="size-full wp-image-32127 aligncenter" src="https://d2908q01vomqb2.cloudfront.net/9e6a55b6b4563e652a23be9d623ca5055c356940/2026/08/18/Figure-2-Floys-production-architecture-on-AWS.png" alt="Figure 2 Floy’s production architecture on AWS" width="602" height="423"&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;Floy’s AWS infrastructure satisfies EU MDR Class IIb and ISO 13485 requirements at every layer, combining end-to-end encryption, least-privilege access controls, and continuous compliance monitoring.&lt;/p&gt; 
&lt;h2&gt;Looking ahead&lt;/h2&gt; 
&lt;p&gt;Today, Floy’s platform processes hundreds of studies daily across more than 200 radiology practices. To date, it has analyzed more than 100,000 studies, each representing a patient who received systematic opportunistic screening without an additional appointment, scan, or radiation dose.&lt;/p&gt; 
&lt;p&gt;Floy has already extended its FM approach beyond head imaging. An MR Knee FM now powers automated ICRS grading of cartilage, and the same self-supervised pre-training approach is being applied to bone mineral density products to improve accuracy and accelerate the path to new use cases.&lt;/p&gt; 
&lt;h2&gt;Conclusion&lt;/h2&gt; 
&lt;p&gt;Floy’s FM-based AI platform on AWS scales to meet the demands of modern radiology, supporting a pipeline from training and inference to clinical integration.&lt;/p&gt; 
&lt;p&gt;To learn more about how AWS supports healthcare and life sciences organizations, visit AWS Health. To explore how Floy is transforming radiology with opportunistic screening, visit floy.com.&lt;/p&gt; 
&lt;p&gt;To learn more about how other imaging HealthTechs are using AWS, check out the following resources:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/blogs/publicsector/icometrix-helps-to-detect-and-treat-neurological-diseases-with-ai-imaging-powered-by-aws/" target="_blank" rel="noopener"&gt;Icometrix helps to detect and treat neurological diseases with AI imaging, powered by AWS&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/blogs/publicsector/how-cimars-platform-enables-a-national-lung-cancer-screening-program-at-scale-powered-by-aws/" target="_blank" rel="noopener"&gt;How CIMAR’s platform enables a national lung cancer screening program at scale, powered by AWS&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/blogs/publicsector/polish-healthcare-leader-radpoint-transforms-medical-imaging-for-millions-using-aws/" target="_blank" rel="noopener"&gt;Polish healthcare leader Radpoint transforms medical imaging for millions using AWS&lt;/a&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;a href="https://aws.amazon.com/blogs/industries/deploy-diagnostic-quality-imaging-globally-with-meddream/" target="_blank" rel="noopener"&gt;Deploy diagnostic-quality imaging globally with MedDream and AWS HealthImaging&lt;/a&gt;&lt;/li&gt; 
&lt;/ul&gt;</content:encoded>
					
		
		
			</item>
	</channel>
</rss>