Securing Amazon Bedrock cross-Region inference: Geographic and global
Machine Learning Blog
This article explains security best practices for Amazon Bedrock cross-Region inference (CRIS), which distributes AI inference processing across multiple AWS Regions.
- Geographic CRIS routes requests within specific geographic boundaries (US, EU, Australia, Japan)
- Global CRIS routes requests across all supported AWS commercial Regions worldwide
- Data remains in source Region; only inference requests travel across Regions with end-to-end encryption
- Geographic CRIS requires IAM access to inference profile and all destination Region models
- Global CRIS uses "unspecified" Region condition for dynamic routing across supported Regions
- SCPs must allow all destination Regions for Geographic CRIS to function properly
- Global CRIS SCPs must include "unspecified" in allowed Regions list
- Organizations can disable Geographic or Global CRIS using deny SCPs targeting specific profiles
- All cross-Region calls logged in source Region with additional inferenceRegion metadata in CloudTrail
- AWS Control Tower users should use Customizations for AWS Control Tower to manage CRIS policies
Organizations can securely implement cross-Region inference by carefully configuring IAM policies and SCPs to balance scalability, compliance, and data residency requirements.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.