Skip to content

Product1 publisher3 min readPublished

AWS answers the FT by moving the blame from its Kiro agent to a misconfigured role

Amazon says the mid-December disruption touched only Cost Explorer in one region and came out of a misconfigured role. The safeguard it shipped afterwards, mandatory peer review for production access, governs people.

The Product Desk · Product desk

Photograph accompanying AWS answers the FT by moving the blame from its Kiro agent to a misconfigured role
Photo: geekwire.com

What happened

  • Amazon published a post correcting the Financial Times that conceded a limited December disruption to a single service in one region and attributed it to a user error in configuring access controls.
  • The FT, citing four people familiar with the matter, reported a 13-hour interruption to an AWS system in mid-December after engineers allowed the Kiro coding tool to make changes.
  • The company calls the FT's claim that a second event impacted AWS entirely false, and a spokesperson told GeekWire the second event happened elsewhere within Amazon.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint Mandatory peer review for production access puts a second person in front of exactly the change an unattended agent was bought to make alone. Inside AWS, the time the agent saves goes back into a review queue.
  • precedent The most detailed public fault assignment yet for an agentic coding incident at this scale rests on how access was configured. Customers running the same tools should expect that answer when their own agents delete something.
  • contradiction Because the user-error position was already in the FT's story, the surviving disagreement is the factual one about whether a second event touched AWS at all, which is narrower than the causal argument the coverage implied.
  • exposure Amazon sells this class of agent to AWS customers. What an unattended decision can destroy in a customer account depends on permissions that customer granted itself.

The person affected by the incident Amazon and the Financial Times are arguing about was an AWS customer in mainland China who wanted to look at a cloud bill. Cost Explorer is the spend-tracking tool, and Amazon says that is the only service the December disruption touched, in one of its 39 regions [17]. Amazon also says no customer asked about it: "We did not receive any customer inquiries regarding the interruption," the company wrote [16].

On the sequence of events, the two accounts do not actually disagree. Engineers let Kiro, an agentic assistant capable of taking autonomous actions, make changes, and the tool determined the best course of action was to "delete and recreate the environment," according to the four people the FT cited [8][9]. Amazon's post says the cause was a misconfigured role, "the same issue that could occur with any developer tool (AI powered or not) or manual action" [4]. Both statements can hold at once. The role is what made deletion possible, and the agent is what exercised it with nobody in the loop.

That second half is the part a team rolling out agentic tooling has to account for. The FT reported that a senior AWS employee called the outages "small but entirely foreseeable," and said engineers had let the AI agent resolve issues without human intervention [11].

What is still in dispute is a question of fact. GeekWire reports that the "user error, not AI error" position already appeared in the FT's original story, and that the blog post largely restates it more prominently [15]. The new element is the denial: Amazon wrote that "The Financial Times' claim that a second event impacted AWS is entirely false" [5]. An AWS spokesperson told GeekWire that the second event took place elsewhere within Amazon, not within the AWS business, and that the FT is wrong on this point [7]. The FT had reported Amazon acknowledging a second incident that did not affect a "customer-facing AWS service" [6]. Mike Isaac of the New York Times, posting on X, called the response "the most prickly" he had seen from Amazon in years [19].

The division doing the denying is Amazon's most profitable [21]. It booked $35.6 billion in revenue last quarter, up 24%, and $12.5 billion in operating income, an operating margin of about 35% [12][20]. It is also the main destination for Amazon's planned $200 billion of capital spending this year [13], and Amazon sells the same class of agentic tooling to AWS customers [14].

Two properties sort this risk for anyone running agents against their own systems, and they vary independently: whether the agent can act without a person approving the action, and whether the role it assumes can destroy production state. In December both were true. The safeguard Amazon named, mandatory peer review for production access, changes the first property and leaves the second alone [18]. Scoping the role is the cheaper of the two for most teams, since it does not put a reviewer in front of every change.

What to watch

  • Whether the Financial Times corrects or stands behind its report that a second incident hit AWS.
  • Whether Amazon carries the internal peer-review requirement into Kiro's defaults or its customer guidance.
  • Whether Amazon details the other safeguards it says it implemented beyond peer review for production access.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories