Controlling delegation in agentic AI with Amazon Bedrock Agent Core
Public Sector Blog
This article explains how to control delegation risks in agentic AI systems, particularly for public sector organizations handling sensitive citizen data and compliance requirements.
- Uncontrolled delegation—handing off trust, action, or access without verification—underlies prompt injection, excessive agency, and information disclosure risks
- Real prompt injection attacks use legitimate-looking content buried in documents or emails, not obvious malicious syntax
- Separate instruction channels from data channels; treat retrieved content as untrusted data, not instructions
- Map delegation points in your agent and identify boundary checks at each handoff where data crosses trust boundaries
- Run a 5-minute injection test: embed an instruction in a document, retrieve it, and verify the agent doesn't follow the injected command
- Amazon Bedrock Agent Core enforces authorization and access control boundaries to prevent unauthorized delegation
Controlling delegation through defense-in-depth architecture and structured boundary checks reduces exposure to all three risk categories in agentic AI systems.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Sep 14
2026
2026
Manage end-user OAuth consent for AI agents with Amazon Bedrock AgentCore
Sep 18
2026
2026
Migrating multi-model AI agents to Amazon Bedrock AgentCore runtime
Aug 19
2026
2026
Propagate user authorization context in AI agents with Amazon Bedrock AgentCore
Sep 21
2026
2026
How Benchling secured multi-tenant AI agents with Amazon Bedrock AgentCore
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.