AWS Opens Preview of AI Cloud Reviews With Suggested Fixes and Code Changes
Well-Architected Agent pairs architecture findings with implementation steps. Access requires an AWS Support plan, and AWS warns that its AI recommendations can be wrong or incomplete.
The preview turns AWS architecture reviews into prioritized work plans: the agent weighs customer goals against infrastructure configuration, usage and application topology, then provides implementation options ranging from console steps to code changes. Teams can use it on running workloads or submit infrastructure projects before deployment, potentially bringing reviews into engineering workflows through an API. Its recommendations are not verified fixes, however, and customers must assess them in their own environments.
01
The agent evaluates best practices across more than 65 AWS services and ranks findings by estimated impact and implementation effort, while surfacing tradeoffs across review areas.
02
For running workloads, recommendations arrive within 24 hours of profile creation and are updated periodically; setup requires customer-managed roles that grant access to workload data.
AWS customers can now try an AI service that reviews their cloud environment and supplies suggested fixes—not just a checklist of problems. AWS opened the public preview of Well-Architected Agent on October 1, 2026. The service targets cost, security, performance and resilience, with recommendations AWS says are tailored to customers’ infrastructure and business goals.
A checklist versus a contextual review
The existing AWS Well-Architected Tool remains available for manual architecture reviews, including reviews using customers’ own best-practice criteria. The new agent takes a different approach: AWS says it combines resource configurations, utilization metrics and application topology—the relationships between parts of an application—to assess an environment against best practices across more than 65 AWS services.
Customers declare objectives and provide application context. The agent then ranks recommendations by their impact and the effort required, rather than presenting an undifferentiated set of findings. AWS also says it surfaces tradeoffs between the review areas. The review therefore considers both how resources are configured and what the customer wants the application to achieve.
From one resource to the architecture
AWS describes three levels of recommendations, spanning small resource changes and wider design decisions. Each finding comes with an implementation package, while the recommendation details explain why the change is suggested, its impacts and tradeoffs, and the affected resources.
Individual resources: specific findings with dollar impact where applicable and step-by-step remediation instructions.
Applications: consolidated findings across multiple resources within the application’s scope.
Architecture: broader patterns and designs, accompanied by infrastructure-as-code changes—edits to the files that define cloud infrastructure.
Customers choose how to implement a recommendation: through console walkthroughs, updated infrastructure templates or AWS command-line instructions. For architecture changes, the agent can provide code to copy into an existing codebase. Recommendations are also available through an API, allowing teams to bring them into development and operations workflows rather than work only in the console.
Review running workloads—or code before deployment
Setup begins with an agent profile that defines which accounts, applications and regions to review, plus the review areas and goals. Customers must provision customer-managed access roles so the service can read resource configurations, utilization metrics and application relationships. AWS says resource and application recommendations arrive within 24 hours of profile creation and are updated periodically.
A separate architecture-review route covers workloads before deployment. Customers upload a zipped infrastructure project or repository file in Terraform, AWS CloudFormation or AWS Cloud Development Kit, then select the review criteria. They can also add application details, account and region information, services and tags to narrow the scope and improve the context behind recommendations.
Suggested code is not a verified fix
AWS’s claim that findings come with ready-to-implement fixes carries an important qualification. The company warns that generative AI recommendations may contain errors or incomplete information. Customers remain responsible for evaluating them in their own environment and applying oversight and safeguards. The documented workflow has users roll out the instructions and verify the result; supplied code does not remove that responsibility.
The preview is delivered by AWS Support and requires an AWS Support plan. Access to the agent and its recommendations is available in US East (N. Virginia), US East (Ohio) and US West (Oregon). That access footprint is narrower than the workload scope: customers can onboard workloads from any AWS commercial region and get started through the Well-Architected console.
Sources
aws.amazon.comAnnouncing AWS Well-Architected Agent, an AI-powered intelligence to optimize your cloud environment (preview) | Amazon Web Services
Reader comments
Newest comments first. Replies stay oldest first.