AWS has announced a public preview of AWS Well-Architected Agent, a service designed to inspect AWS environments and prioritize improvements to cost, security, performance and resilience. Rather than presenting a generic review checklist, AWS says the service combines resource configurations, utilization metrics and application topology with business goals supplied by the customer.
The important change is not simply that AWS is adding generative AI to its Well-Architected framework. It is attempting to package architectural advice into an operational workflow: identify an issue, explain its trade-offs, scope the affected resources, and offer console steps, AWS CLI commands or infrastructure-as-code (IaC) changes to address it.
What AWS is offering
The agent analyzes workloads across more than 65 AWS services and produces recommendations at three levels:
- **Resource findings**, including estimated dollar impact where applicable and remediation steps.
- **Application-level findings** that consolidate issues across multiple resources.
- **Architecture patterns**, with suggested design changes and IaC updates.
Teams first create an agent profile that defines the AWS accounts, Regions, applications and optimization pillars in scope. They also provide a customer-managed IAM role, which the service uses to read configurations, metrics and topology. AWS says recommendations are generated within 24 hours of profile creation and refreshed periodically.
The preview also supports pre-deployment reviews. Developers can upload a zipped Terraform, CloudFormation or AWS CDK project and select a Well-Architected lens for analysis. For teams working in code, the service can provide changes to existing IaC templates; recommendations are also available through console and API workflows. AWS points users to its MCP Server and plugins for connecting programmatic access with AI coding tools.
Why this matters to cloud operators
Cloud reviews are often constrained by time and fragmented ownership. FinOps teams may see utilization signals, security teams may see configuration risk, and platform teams may own the Terraform or CDK repository. A tool that joins these inputs into a prioritized queue could reduce the coordination cost of finding relatively clear-cut improvements.
The emphasis on declared business goals is notable. A workload built for availability may reasonably accept more infrastructure cost; a noncritical internal workload may have a different target. In principle, goal-based prioritization is more useful than a long list of best-practice deviations. It also acknowledges that performance, resilience, security and cost choices routinely conflict.
The most useful capability may be the bridge to implementation. If recommendations arrive as reviewed IaC diffs that fit a team’s existing repositories and change controls, they can enter normal engineering workflows. If they remain console guidance, they risk becoming another dashboard that teams check intermittently.
The governance constraint
AWS explicitly cautions that the service’s generative-AI recommendations can be incorrect or incomplete and says customers remain responsible for evaluation, oversight and safeguards. That warning should shape adoption.
Organizations should treat the agent as a triage and drafting layer, not an autonomous production-change system. In particular, teams should validate savings estimates, test IaC changes in lower environments, review permissions and network implications, and ensure that a local optimization does not undermine application-level resilience or compliance requirements.
The required IAM setup also deserves scrutiny. Security and platform leaders will need to limit scope to the accounts, Regions, tags and resources relevant to a review, then verify the permissions and access boundaries before expanding use.
What to watch next
The preview is available through AWS Support in US East (N. Virginia), US East (Ohio) and US West (Oregon), though workloads can be onboarded from any AWS commercial Region. AWS has not positioned it as a replacement for the existing manual Well-Architected Tool, which continues to support user-defined lenses.
For buyers, the key test is whether the agent produces fewer, better-ranked findings that can be converted into safe pull requests or approved operational changes. For AWS, broader adoption will hinge on recommendation quality, coverage of real multi-account environments, and integrations that let platform teams retain their existing review and deployment controls.




