Runtime as featured inForbesRead the article

Runtime vs AWS Bedrock AgentCore

Compare Runtime and Amazon Bedrock AgentCore: modular AWS services for building and running agents vs a finished agent harness for payment ops, risk, and finance teams, in any cloud.

Updated October 7, 20266 min read

TL;DR: AgentCore is a strong, modular set of AWS services for engineers building agents at scale. Runtime is the finished harness for payment and fintech operations teams, with approvals and an audit trail designed for money movement, multi-cloud deployment, and a forward-deployed engineer.

Feature
RuntimeRuntime
AWS Bedrock AgentCoreAWS Bedrock AgentCore
What it isAgent harness for payment teamsModular AWS agent services
Who builds agentsOps, risk, finance, with an FDEDevelopers via API, CLI, SDK
Isolated sessionsOwn computer per agent runDedicated microVM per session
Where it runsYour AWS, GCP, Azure, or self-hostedAWS regions
Frameworks and modelsAny model, harness routing with fallbacksAny framework, any model
Tool-call policy engineRead-only start, RBAC, approvalsPolicy with Cedar-compatible rules
Approvals on money movementBuilt in, routed in Slack or TeamsYou design and build them
Audit trailEvery run, exportable for examinersCloudWatch traces via OpenTelemetry
Payments domain depthBuilt by payments engineersHorizontal, any industry
Getting to productionForward-deployed AI engineerSelf-serve, AWS sales and partners

AgentCore and Runtime at a glance

Amazon Bedrock AgentCore is AWS's agentic platform for building, deploying, and operating agents with any framework and any foundation model. It is a set of modular services you can use together or one at a time: Harness, a managed agent loop configured with a model, prompt, and tools (generally available since June 2026); Runtime, which gives every session its own microVM; Memory; Gateway, which turns APIs and Lambda functions into MCP tools; Identity, which works with Okta, Entra ID, and Cognito; Code Interpreter and Browser; Observability on OpenTelemetry and CloudWatch; Policy and Evaluations, both generally available since March 2026; plus Registry, Optimization, and Payments. It is built for engineering teams that want production-grade agent infrastructure on AWS.

Runtime is the AI agent harness for payment and fintech teams: an operating system for building and running many agents across the org. Anyone in payment ops, risk, compliance, finance, underwriting, onboarding, or support builds agents from their SOPs. Agents work on their own isolated computers, reach your ledger, processor, and bank portals through APIs, databases, MCP servers, and a browser, and stop for a person before anything moves money. It is built for operations leaders who want agents working real queues this quarter.

Good products, different jobs. AgentCore gives engineers excellent parts. Runtime is the finished harness for the teams who run the money.

How they differ

Services to assemble vs a harness to use

AgentCore gives you the right primitives: isolated sessions, memory, identity, a tool gateway, a policy engine, evaluations. You still decide how they fit together, write the agent logic, build the interface ops teams use, and wire approvals into your workflow. AWS describes one use as giving internal developers a paved path to build agents.

Runtime is that paved path, already built for payment operations. The first agent is easy anywhere. Running agents on payment data needs isolated computers, scoped credentials, RBAC, approvals, an audit trail, evals, model routing, fallbacks, and a way for a risk analyst to build and call an agent from Slack or Teams. An engineering team can spend two quarters on that plumbing before the first agent touches real data. Runtime gives it to you on day one, and works with agents you already have.

One cloud vs any cloud

AgentCore runs in AWS regions. Registry can catalog agents and tools hosted elsewhere, but the managed services are AWS services.

Runtime runs agent computers in your AWS, GCP, or Azure account, or fully self-hosted via Helm, and lets you bring your own sandbox provider. If you are an AWS shop, Runtime runs in your AWS account. If your processor integration lives in one cloud and your data warehouse in another, one harness covers both.

Models and harnesses

AgentCore is genuinely open on models and frameworks: Bedrock models, OpenAI, Gemini, and OpenAI-compatible providers, with LangGraph, CrewAI, ADK, Strands, and others. AWS says Harness can switch providers mid-session.

Runtime routes across agent harnesses (Claude Code, Codex, OpenCode) as well as models, with fallbacks when a provider goes down. You can serve open-weight models in your own cloud for PCI and PII work, and card numbers and SSNs are stripped from prompts and logs.

Guardrails designed for money movement

AgentCore Policy intercepts every tool call at the Gateway and checks it against rules written in natural language or a Cedar-compatible policy language. That is a strong, deterministic control layer. Which payment actions need a human, who approves them, and where the request shows up are design decisions your team still builds.

Runtime starts agents read-only and requires approval before anything moves money: releasing a payout, applying a reserve, booking a ledger entry, replying to a sponsor bank. Approvals arrive where your team works. Every run is recorded end to end, from the trigger through every query, tool call, approval, cost, and result, so the record your sponsor bank or examiner asks for stays with you.

How you get to production

AgentCore is self-serve through the console, CLI, and SDKs, with AWS account teams and partners for larger programs.

Runtime pairs you with a forward-deployed AI engineer from a team that built payment and fintech infrastructure at Hulu's payments team at Disney, Finix, Modern Treasury, and BlackRock's AI quant group. The FDE maps your processes, builds the first agents with your team, sets up guardrails, and trains admins. When a process is solved, agents can turn it into a deterministic script in your repos, so engineers own it if it becomes mission-critical.

Where AgentCore is stronger

  • Infrastructure depth. Per-session microVMs, sessions up to 8 hours on microVMs or 14 days on instances, and fine-grained control of every layer.
  • Policy engine. Cedar-compatible rules enforced on every tool call through the Gateway.
  • Modularity. Use only Memory, only Identity, or only Browser inside an existing stack.
  • AWS integration. IAM, CloudWatch, Lambda, and the rest of your AWS estate, with AWS compliance programs behind it.
  • Breadth. It is horizontal, from voice agents with bidirectional streaming to coding agents, and includes agent payments over x402.

Pricing

AgentCore is consumption-based with no upfront commitment. Runtime microVMs start at $0.0895 per vCPU-hour and $0.00945 per GB-hour, billed per second on active use. Gateway is $0.005 per 1,000 invocations, Policy is $0.000025 per authorization request, and Memory, Evaluations, Browser, and Code Interpreter are metered separately. Model usage is billed on top. The engineering time to build approvals, audit export, and ops-facing interfaces is not on the price list.

Runtime has public tiers: Free ($0, one session), Teams from $99 per seat per month, and Enterprise with custom pricing and self-hosting. The value to weigh it against is the work of the analysts you were about to hire.

Which should you choose

Choose AgentCore if

  • You have a platform team that wants to own agent infrastructure on AWS
  • You are building agents into your product, not back-office operations
  • You want to mix individual services into an existing agent stack
  • You prefer to design your own approvals and audit model

Choose Runtime if

  • Payment ops, risk, compliance, or finance teams need agents on real queues soon
  • Approvals before money moves and an examiner-ready audit trail are requirements
  • You run on more than one cloud, or want your own sandbox provider and models
  • You want a forward-deployed engineer who knows payments, not a parts catalog

You can also run both: engineering keeps building on AgentCore, and operations runs on Runtime in the same AWS account. Rain replaced $250k in vendor spend with Runtime.

See Runtime on your busiest queue

Bring one SOP. A forward-deployed AI engineer builds the first agent with your team, inside your cloud.

Frequently asked questions

What is Amazon Bedrock AgentCore?

AgentCore is a set of AWS services for building, deploying, and operating AI agents with any framework and any foundation model. It includes Harness, Runtime, Memory, Gateway, Identity, Code Interpreter, Browser, Observability, Evaluations, Policy, Registry, Optimization, and Payments, which can be used together or independently.

Does AgentCore only work with Bedrock models?

No. AWS says AgentCore Runtime works with any foundation model in or outside Amazon Bedrock, including OpenAI, Gemini, Claude, Nova, Llama, and Mistral, and with frameworks such as LangGraph, CrewAI, Google ADK, OpenAI Agents SDK, and Strands Agents.

Can Runtime run in my AWS account?

Yes. Runtime can run agent computers in your own AWS account, as well as GCP or Azure, or be fully self-hosted with Helm. Choosing Runtime does not mean leaving AWS.

How long does it take to build payment ops agents on AgentCore?

The first agent can be quick. Running agents on payment data also needs approvals, audit export, RBAC, evals, and an interface ops teams can use. An engineering team can spend two quarters on that work. Runtime provides it on day one.

How is AgentCore priced?

AgentCore is consumption-based with no upfront commitment. Runtime microVMs start at $0.0895 per vCPU-hour and $0.00945 per GB-hour, and services like Gateway, Memory, Policy, and Evaluations are metered separately. Model usage is billed separately.

Related comparisons