Menu
← Research

Research / 2026-10-02

Same agent. Very different bill.

A prospect asked how the two compare, so we protected the same agent with AWS’s AgentCore and with ActaClad’s AgentGuard.

Sajith Seelan · AI/ML Research Engineer

Last week a prospect asked us a direct question: how is ActaClad's AgentGuard different from AWS's AgentCore when it comes to content safety, monitoring and enforcing execution limits?

We could have answered from the documentation. Instead, we took one ordinary agent and protected it with both, hands-on. Along the way we noted three things: what each one would cost as the agent scales, what we had to change in the agent to make it work, and what we could actually stop when something went wrong.

Three differences stood out: cost, architecture and control. The full side-by-side comparison follows.

FIGURE 01ActaClad’s reported test setup · 2 October 2026

Same starting agent. Two control paths.

AgentCore Gateway setup

  1. LangGraph agent
  2. GatewayPolicies on routed calls.
  3. Registered targetsOpenAI inference + Python tool re-hosted as Lambda.

The tested setup re-routed the model and re-hosted the local tool.

AgentGuard SDK setup

  1. LangGraph + SDKRuntime controls around the existing call path.
  2. Existing model + toolOpenAI called directly; Python function stays local.

The model and tool remain in the existing application.

These paths describe the integration tested in the article, not every AgentCore architecture. The AgentGuard lane retains the existing model and tool destinations.
01 · Cost

Scale your agents, not your bill.

Why the gap? Amazon Bedrock Guardrails charges per character scanned. At every step an agent re-sends the whole conversation, and by default the guardrail scans all of it again.

FIGURE 02Calculated scenario · USD per month · article pricing dated 2 October 2026

The cost of repeating the check.

Monthly cost (USD)

1 million agent runs / month

Bedrock Guardrails
~$32,000
AgentGuard subscription
$2,999

5 million agent runs / month

Bedrock Guardrails
~$160,000
AgentGuard subscription
$3,999

8 steps/run · 80 text units/run · three filters at $0.40 per 1,000 text units combined. AWS guardrail fees only; Gateway, Runtime and CloudWatch extra. Model calls and LLM-judged evaluations excluded on both sides.

A projection for this workload, not a measured invoice or a current price quote. Both run volumes share the same zero-based scale. AgentGuard tiers are the prices stated in the article.AWS Bedrock pricing ↗
02 · Architecture

Keep your agent. Add the guard.

We wanted four things on one ordinary agent: prompt protection, tool permissions, a spend limit and a kill switch.

The Gateway-based policies and guardrails we tested apply to calls routed through AgentCore Gateway. For our existing agent, that meant re-routing the model and re-hosting the local tool before those controls could apply: re-route, register, configure, then govern. With AgentGuard it's install, initialize, govern.

03 · Control

Who stops a runaway agent?

FIGURE 03Operational implications of the reported setup

Where the control sits changes the work.

Control location
AgentCore Gateway setupGateway-routed calls
AgentGuard SDK setupInstrumented runtime calls
Local Python tool
AgentCore Gateway setupRe-hosted and registered as a target
AgentGuard SDK setupRetained in the application
Model connection
AgentCore Gateway setupRouted through Gateway inference
AgentGuard SDK setupExisting direct OpenAI connection
Operating model
AgentCore Gateway setupConfigure the routed infrastructure
AgentGuard SDK setupInitialize controls in the application
The consequence here is integration work. It is not a claim that AgentCore lacks other runtime or Harness controls; those are discussed in the technical notes.

Rate limits slow calls down. Budget Guard caps spend before the next call. Execution limits bound call count, fan-out and repeated calls. A kill switch stops activity from the console.

AWS provides Gateway rate limits, temporal policies and account-level AWS Budgets. ActaClad's AgentGuard takes a different approach: rate, spend, execution and emergency controls sit around the agent itself and are managed together in one console.

The full comparison, line by line.

Open the detailed comparison
DimensionAWS's AgentCoreActaClad's AgentGuard
Enforcement modelGateway policies and guardrails govern Gateway-routed calls; Harness adds controls for Harness-managed agentsRuntime controls applied through the SDK, around the agent's existing call path
Infrastructure portabilityAWS-hosted onlyRuns wherever your app runs
Model / framework choiceBroad: Bedrock, OpenAI, Gemini, othersBroad: model-agnostic; LangGraph, CrewAI and similar
Execution limitsHarness-managed agents only; iterations, timeout, tokensAny agent; adds call count, fan-out, cost budget, stuck-loop detection
Real-time dollar budget capNone found; AWS Budgets is account-wide and refreshes a few times a dayPer project, checked before every call
Kill switchManual: Cedar policy, rate limit of 0, or per-session stop; gateway onlyOne console toggle
Tool-call scanningTools registered behind the Gateway; local functions must be re-hostedNo re-hosting required
Cost structurePer-service, per-unit metersFlat subscription
ManagementSeveral consoles and APIsOne console
IAM-native agent identityYesNot applicable: identity belongs to the host app
Managed infrastructureYes: microVM per session, autoscalingNot applicable: AgentGuard doesn't host agents

What the prospect chose

We walked the prospect through all of this. All three mattered to them: a bill that doesn't climb with every run, keeping their agent as it is, and real brakes when something goes wrong. They've decided to move forward with ActaClad's AgentGuard. We're grateful for their trust, and glad we answered with a hands-on test rather than a slide.

Which one fits you?

Choose AWS's AgentCore when…

AWS is the agent platform you want to build around, with hosting and gateway infrastructure built in.

Choose ActaClad's AgentGuard when…

You already have agents and want runtime trust without changing the platform underneath them, at a price that doesn't grow with every character.

AgentCore helps you build and run agents. AgentGuard helps you trust the agents you already run.

Already running an AI agent?
Don't migrate it. Don't re-platform it.
Guard it.

Give us one existing agent. We'll show you where ActaClad's AgentGuard adds visibility, controls and runtime limits, without re-platforming it.

info@actaclad.com
Technical notes
How we calculated the bill

Workload. One agent run is 8 steps. The conversation grows by about 2,000 characters a step, so the guardrail scans 2k + 4k + … + 16k = 72,000 characters of input per run, plus about 8,000 characters of model output: 80 text units (1 unit = 1,000 characters).

AWS. Amazon Bedrock Guardrails list prices for three text policies (content filters $0.15, denied topics $0.15, sensitive-information filters $0.10, per 1,000 text units), with the default configuration that evaluates every message. That's about $0.032 per run. Guardrail fees only; Gateway, Runtime, model and CloudWatch charges are extra.

ActaClad's AgentGuard. $2,999 a month at 1M runs and $3,999 at 5M runs: observability, security, evaluation and guardrail checks in one subscription. The agent's own model calls and any LLM-judged evaluations run on your model keys and are billed by your provider, just as model charges sit outside the AWS figure.

Agent runs / monthAWS guardrail feesAgentGuardDifference
1,000,000~$32,000$2,999~10× less
5,000,000~$160,000$3,999~40× less

The gap widens with volume and with agent length. A small chatbot with short conversations narrows it.

The test setup, step by step

On AWS's AgentCore: re-host the Python function as a Lambda or an API behind an OpenAPI spec (a local function isn't a valid gateway target); register the model as an inference target, store its key in AgentCore's credential vault and point the agent at the gateway's /inference endpoint; then write and attach the Cedar policy, rate limit and guardrail through the CLI or control-plane API. Each new tool or model is registered the same way.

On ActaClad's AgentGuard: install the SDK, set the environment variables, initialize it against the agent and model. The agent still calls OpenAI directly and the tool stays a local function.

AWS's runtime controls in detail

Harness has per-invocation settings: maxIterations (default 75), timeoutSeconds (default 3600) and maxTokens, for agents Harness manages.

Gateway (since August 2026) has request, token and connection rate limits, and temporal policies that evaluate calls against session history, including totals such as session purchases. AgentCore Payments caps the agent's own payments. We found no USD cap on model spend.

Emergency stop: an emergency forbid-all Cedar policy, a rate limit of 0 (up to 30 seconds to take effect), or stopping sessions one at a time.

Sources. AWS public documentation and pricing as of October 2, 2026. AgentCore changes often; if we have something wrong or out of date, email info@actaclad.com and we'll correct it here with a note. Bedrock pricing · Guardrails with Converse · AgentCore pricing · Gateway inference targets · Temporal policies and rate limiting · AgentCore Payments · Harness API · AWS Budgets.

Amazon Bedrock, AgentCore and AWS are trademarks of Amazon.com, Inc. or its affiliates. ActaClad is not affiliated with or endorsed by Amazon.
Read as Markdown ↗All research →