# Same agent. Very different bill.

Research · Sajith Seelan · AI/ML Research Engineer · 2026-10-02

A prospect asked how the two compare, so we protected the same agent with AWS’s AgentCore and with ActaClad’s AgentGuard.



Last week a prospect asked us a direct question: how is ActaClad's AgentGuard different from AWS's AgentCore when it comes to content safety, monitoring and enforcing execution limits?

  

We could have answered from the documentation. Instead, we took one ordinary agent and protected it with both, hands-on. Along the way we noted three things: what each one would cost as the agent scales, what we had to change in the agent to make it work, and what we could actually stop when something went wrong.

  

Three differences stood out: cost, architecture and control. The full side-by-side comparison follows.

### Figure — Same starting agent. Two control paths.

ActaClad’s reported test setup · 2 October 2026

**AgentCore Gateway setup**

LangGraph agent → Gateway (Policies on routed calls.) → Registered targets (OpenAI inference + Python tool re-hosted as Lambda.)

The tested setup re-routed the model and re-hosted the local tool.

**AgentGuard SDK setup**

LangGraph + SDK (Runtime controls around the existing call path.) → Existing model + tool (OpenAI called directly; Python function stays local.)

The model and tool remain in the existing application.

These paths describe the integration tested in the article, not every AgentCore architecture. The AgentGuard lane retains the existing model and tool destinations.

01 · Cost

    

## Scale your agents, not your bill.

  

Why the gap? Amazon Bedrock Guardrails charges per character scanned. At every step an agent re-sends the whole conversation, and by default the guardrail scans all of it again.

### Figure — The cost of repeating the check.

Calculated scenario · USD per month · article pricing dated 2 October 2026

Monthly cost (USD). Shared linear scale: 0 to 160000.

**1 million agent runs / month**
- Bedrock Guardrails: ~$32,000
- AgentGuard subscription: $2,999

**5 million agent runs / month**
- Bedrock Guardrails: ~$160,000
- AgentGuard subscription: $3,999

Conditions: 8 steps/run · 80 text units/run · three filters at $0.40 per 1,000 text units combined. AWS guardrail fees only; Gateway, Runtime and CloudWatch extra. Model calls and LLM-judged evaluations excluded on both sides.

A projection for this workload, not a measured invoice or a current price quote. Both run volumes share the same zero-based scale. AgentGuard tiers are the prices stated in the article.

Source: [AWS Bedrock pricing](https://aws.amazon.com/bedrock/pricing/)

02 · Architecture

    

## Keep your agent. Add the guard.

  

We wanted four things on one ordinary agent: prompt protection, tool permissions, a spend limit and a kill switch.

The Gateway-based policies and guardrails we tested apply to calls routed through AgentCore Gateway. For our existing agent, that meant re-routing the model and re-hosting the local tool before those controls could apply: re-route, register, configure, then govern. With AgentGuard it's install, initialize, govern.

03 · Control

    

## Who stops a runaway agent?

### Figure — Where the control sits changes the work.

Operational implications of the reported setup

**Control location**
- AgentCore Gateway setup: Gateway-routed calls
- AgentGuard SDK setup: Instrumented runtime calls

**Local Python tool**
- AgentCore Gateway setup: Re-hosted and registered as a target
- AgentGuard SDK setup: Retained in the application

**Model connection**
- AgentCore Gateway setup: Routed through Gateway inference
- AgentGuard SDK setup: Existing direct OpenAI connection

**Operating model**
- AgentCore Gateway setup: Configure the routed infrastructure
- AgentGuard SDK setup: Initialize controls in the application

The consequence here is integration work. It is not a claim that AgentCore lacks other runtime or Harness controls; those are discussed in the technical notes.

Rate limits slow calls down. Budget Guard caps spend before the next call. Execution limits bound call count, fan-out and repeated calls. A kill switch stops activity from the console.

AWS provides Gateway rate limits, temporal policies and account-level AWS Budgets. ActaClad's AgentGuard takes a different approach: rate, spend, execution and emergency controls sit around the agent itself and are managed together in one console.

## The full comparison, line by line.

Open the detailed comparison

| Dimension | AWS's AgentCore | ActaClad's AgentGuard | 
| Enforcement model | Gateway policies and guardrails govern Gateway-routed calls; Harness adds controls for Harness-managed agents | Runtime controls applied through the SDK, around the agent's existing call path | 
| Infrastructure portability | AWS-hosted only | Runs wherever your app runs | 
| Model / framework choice | Broad: Bedrock, OpenAI, Gemini, others | Broad: model-agnostic; LangGraph, CrewAI and similar | 
| Execution limits | Harness-managed agents only; iterations, timeout, tokens | Any agent; adds call count, fan-out, cost budget, stuck-loop detection | 
| Real-time dollar budget cap | None found; AWS Budgets is account-wide and refreshes a few times a day | Per project, checked before every call | 
| Kill switch | Manual: Cedar policy, rate limit of 0, or per-session stop; gateway only | One console toggle | 
| Tool-call scanning | Tools registered behind the Gateway; local functions must be re-hosted | No re-hosting required | 
| Cost structure | Per-service, per-unit meters | Flat subscription | 
| Management | Several consoles and APIs | One console | 
| IAM-native agent identity | Yes | Not applicable: identity belongs to the host app | 
| Managed infrastructure | Yes: microVM per session, autoscaling | Not applicable: AgentGuard doesn't host agents |

## What the prospect chose

  

We walked the prospect through all of this. All three mattered to them: a bill that doesn't climb with every run, keeping their agent as it is, and real brakes when something goes wrong. They've decided to move forward with ActaClad's AgentGuard. We're grateful for their trust, and glad we answered with a hands-on test rather than a slide.

  

## Which one fits you?

### Choose AWS's AgentCore when…

      

AWS is the agent platform you want to build around, with hosting and gateway infrastructure built in.

    

### Choose ActaClad's AgentGuard when…

      

You already have agents and want runtime trust without changing the platform underneath them, at a price that doesn't grow with every character.

AgentCore helps you build and run agents. AgentGuard helps you trust the agents you already run.

  

Already running an AI agent?
Don't migrate it. Don't re-platform it.
Guard it.

    

Give us one existing agent. We'll show you where ActaClad's AgentGuard adds visibility, controls and runtime limits, without re-platforming it.

    info@actaclad.com

Technical notes

  

How we calculated the bill
    

Workload. One agent run is 8 steps. The conversation grows by about 2,000 characters a step, so the guardrail scans 2k + 4k + … + 16k = 72,000 characters of input per run, plus about 8,000 characters of model output: 80 text units (1 unit = 1,000 characters).

      

AWS. Amazon Bedrock Guardrails list prices for three text policies (content filters $0.15, denied topics $0.15, sensitive-information filters $0.10, per 1,000 text units), with the default configuration that evaluates every message. That's about $0.032 per run. Guardrail fees only; Gateway, Runtime, model and CloudWatch charges are extra.

      

ActaClad's AgentGuard. $2,999 a month at 1M runs and $3,999 at 5M runs: observability, security, evaluation and guardrail checks in one subscription. The agent's own model calls and any LLM-judged evaluations run on your model keys and are billed by your provider, just as model charges sit outside the AWS figure.

      

| Agent runs / month | AWS guardrail fees | AgentGuard | Difference | 
| 1,000,000 | ~$32,000 | $2,999 | ~10× less | 
| 5,000,000 | ~$160,000 | $3,999 | ~40× less |

      

The gap widens with volume and with agent length. A small chatbot with short conversations narrows it.

  

The test setup, step by step
    

On AWS's AgentCore: re-host the Python function as a Lambda or an API behind an OpenAPI spec (a local function isn't a valid gateway target); register the model as an inference target, store its key in AgentCore's credential vault and point the agent at the gateway's /inference endpoint; then write and attach the Cedar policy, rate limit and guardrail through the CLI or control-plane API. Each new tool or model is registered the same way.

      

On ActaClad's AgentGuard: install the SDK, set the environment variables, initialize it against the agent and model. The agent still calls OpenAI directly and the tool stays a local function.

  

AWS's runtime controls in detail
    

Harness has per-invocation settings: maxIterations (default 75), timeoutSeconds (default 3600) and maxTokens, for agents Harness manages.

      

Gateway (since August 2026) has request, token and connection rate limits, and temporal policies that evaluate calls against session history, including totals such as session purchases. AgentCore Payments caps the agent's own payments. We found no USD cap on model spend.

      

Emergency stop: an emergency forbid-all Cedar policy, a rate limit of 0 (up to 30 seconds to take effect), or stopping sessions one at a time.

  

Sources. AWS public documentation and pricing as of October 2, 2026. AgentCore changes often; if we have something wrong or out of date, email info@actaclad.com and we'll correct it here with a note.
    [Bedrock pricing](https://aws.amazon.com/bedrock/pricing/) ·
    [Guardrails with Converse](https://docs.aws.amazon.com/bedrock/latest/userguide/guardrails-use-converse-api.html) ·
    [AgentCore pricing](https://aws.amazon.com/bedrock/agentcore/pricing/) ·
    [Gateway inference targets](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/gateway-targets-inference.html) ·
    [Temporal policies and rate limiting](https://aws.amazon.com/about-aws/whats-new/2026/08/temporal-policies-agentcore/) ·
    [AgentCore Payments](https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/payments.html) ·
    [Harness API](https://docs.aws.amazon.com/bedrock-agentcore-control/latest/APIReference/API_Harness.html) ·
    [AWS Budgets](https://docs.aws.amazon.com/cost-management/latest/userguide/budgets-managing-costs.html).
    

Amazon Bedrock, AgentCore and AWS are trademarks of Amazon.com, Inc. or its affiliates. ActaClad is not affiliated with or endorsed by Amazon.

