Last week a prospect asked us a direct question: how is ActaClad's AgentGuard different from AWS's AgentCore when it comes to content safety, monitoring and enforcing execution limits?
We could have answered from the documentation. Instead, we took one ordinary agent and protected it with both, hands-on. Along the way we noted three things: what each one would cost as the agent scales, what we had to change in the agent to make it work, and what we could actually stop when something went wrong.
Three differences stood out: cost, architecture and control. The full side-by-side comparison follows.
Same starting agent. Two control paths.
AgentCore Gateway setup
- LangGraph agent
- GatewayPolicies on routed calls.
- Registered targetsOpenAI inference + Python tool re-hosted as Lambda.
The tested setup re-routed the model and re-hosted the local tool.
AgentGuard SDK setup
- LangGraph + SDKRuntime controls around the existing call path.
- Existing model + toolOpenAI called directly; Python function stays local.
The model and tool remain in the existing application.
Scale your agents, not your bill.
Why the gap? Amazon Bedrock Guardrails charges per character scanned. At every step an agent re-sends the whole conversation, and by default the guardrail scans all of it again.
The cost of repeating the check.
Monthly cost (USD)
8 steps/run · 80 text units/run · three filters at $0.40 per 1,000 text units combined. AWS guardrail fees only; Gateway, Runtime and CloudWatch extra. Model calls and LLM-judged evaluations excluded on both sides.
Keep your agent. Add the guard.
We wanted four things on one ordinary agent: prompt protection, tool permissions, a spend limit and a kill switch.
The Gateway-based policies and guardrails we tested apply to calls routed through AgentCore Gateway. For our existing agent, that meant re-routing the model and re-hosting the local tool before those controls could apply: re-route, register, configure, then govern. With AgentGuard it's install, initialize, govern.
Who stops a runaway agent?
Where the control sits changes the work.
- Control location
- AgentCore Gateway setupGateway-routed calls
- AgentGuard SDK setupInstrumented runtime calls
- Local Python tool
- AgentCore Gateway setupRe-hosted and registered as a target
- AgentGuard SDK setupRetained in the application
- Model connection
- AgentCore Gateway setupRouted through Gateway inference
- AgentGuard SDK setupExisting direct OpenAI connection
- Operating model
- AgentCore Gateway setupConfigure the routed infrastructure
- AgentGuard SDK setupInitialize controls in the application
Rate limits slow calls down. Budget Guard caps spend before the next call. Execution limits bound call count, fan-out and repeated calls. A kill switch stops activity from the console.
AWS provides Gateway rate limits, temporal policies and account-level AWS Budgets. ActaClad's AgentGuard takes a different approach: rate, spend, execution and emergency controls sit around the agent itself and are managed together in one console.
The full comparison, line by line.
Open the detailed comparison
| Dimension | AWS's AgentCore | ActaClad's AgentGuard |
|---|---|---|
| Enforcement model | Gateway policies and guardrails govern Gateway-routed calls; Harness adds controls for Harness-managed agents | Runtime controls applied through the SDK, around the agent's existing call path |
| Infrastructure portability | AWS-hosted only | Runs wherever your app runs |
| Model / framework choice | Broad: Bedrock, OpenAI, Gemini, others | Broad: model-agnostic; LangGraph, CrewAI and similar |
| Execution limits | Harness-managed agents only; iterations, timeout, tokens | Any agent; adds call count, fan-out, cost budget, stuck-loop detection |
| Real-time dollar budget cap | None found; AWS Budgets is account-wide and refreshes a few times a day | Per project, checked before every call |
| Kill switch | Manual: Cedar policy, rate limit of 0, or per-session stop; gateway only | One console toggle |
| Tool-call scanning | Tools registered behind the Gateway; local functions must be re-hosted | No re-hosting required |
| Cost structure | Per-service, per-unit meters | Flat subscription |
| Management | Several consoles and APIs | One console |
| IAM-native agent identity | Yes | Not applicable: identity belongs to the host app |
| Managed infrastructure | Yes: microVM per session, autoscaling | Not applicable: AgentGuard doesn't host agents |
What the prospect chose
We walked the prospect through all of this. All three mattered to them: a bill that doesn't climb with every run, keeping their agent as it is, and real brakes when something goes wrong. They've decided to move forward with ActaClad's AgentGuard. We're grateful for their trust, and glad we answered with a hands-on test rather than a slide.
Which one fits you?
Choose AWS's AgentCore when…
AWS is the agent platform you want to build around, with hosting and gateway infrastructure built in.
Choose ActaClad's AgentGuard when…
You already have agents and want runtime trust without changing the platform underneath them, at a price that doesn't grow with every character.
AgentCore helps you build and run agents. AgentGuard helps you trust the agents you already run.
Already running an AI agent?
Don't migrate it. Don't re-platform it.
Guard it.
Give us one existing agent. We'll show you where ActaClad's AgentGuard adds visibility, controls and runtime limits, without re-platforming it.
info@actaclad.comHow we calculated the bill
Workload. One agent run is 8 steps. The conversation grows by about 2,000 characters a step, so the guardrail scans 2k + 4k + … + 16k = 72,000 characters of input per run, plus about 8,000 characters of model output: 80 text units (1 unit = 1,000 characters).
AWS. Amazon Bedrock Guardrails list prices for three text policies (content filters $0.15, denied topics $0.15, sensitive-information filters $0.10, per 1,000 text units), with the default configuration that evaluates every message. That's about $0.032 per run. Guardrail fees only; Gateway, Runtime, model and CloudWatch charges are extra.
ActaClad's AgentGuard. $2,999 a month at 1M runs and $3,999 at 5M runs: observability, security, evaluation and guardrail checks in one subscription. The agent's own model calls and any LLM-judged evaluations run on your model keys and are billed by your provider, just as model charges sit outside the AWS figure.
| Agent runs / month | AWS guardrail fees | AgentGuard | Difference |
|---|---|---|---|
| 1,000,000 | ~$32,000 | $2,999 | ~10× less |
| 5,000,000 | ~$160,000 | $3,999 | ~40× less |
The gap widens with volume and with agent length. A small chatbot with short conversations narrows it.
The test setup, step by step
On AWS's AgentCore: re-host the Python function as a Lambda or an API behind an OpenAPI spec (a local function isn't a valid gateway target); register the model as an inference target, store its key in AgentCore's credential vault and point the agent at the gateway's /inference endpoint; then write and attach the Cedar policy, rate limit and guardrail through the CLI or control-plane API. Each new tool or model is registered the same way.
On ActaClad's AgentGuard: install the SDK, set the environment variables, initialize it against the agent and model. The agent still calls OpenAI directly and the tool stays a local function.
AWS's runtime controls in detail
Harness has per-invocation settings: maxIterations (default 75), timeoutSeconds (default 3600) and maxTokens, for agents Harness manages.
Gateway (since August 2026) has request, token and connection rate limits, and temporal policies that evaluate calls against session history, including totals such as session purchases. AgentCore Payments caps the agent's own payments. We found no USD cap on model spend.
Emergency stop: an emergency forbid-all Cedar policy, a rate limit of 0 (up to 30 seconds to take effect), or stopping sessions one at a time.
Amazon Bedrock, AgentCore and AWS are trademarks of Amazon.com, Inc. or its affiliates. ActaClad is not affiliated with or endorsed by Amazon.