AWS, Anthropic and Ramp are turning AI governance into a product layer
Running tool calls through one gate, keeping data in the customer's cloud and selecting models through cost-and-logging logic are becoming parts of the same governance race.
Artificial Intelligence··Night
AWS wants tool calls to pass through one governed gate
AWS's reference design for AgentCore Gateway is meant to collect the question of who can call which tool under what authority at a single endpoint. In the company's four-stage account, the connection is authenticated with a Cognito JWT, Cedar-based role and attribute rules are enforced, tools are published into a registry through YAML manifests, and ingress is moved onto private networking with multi-Region failover. A companion Dogwood authoring layer promises to turn natural-language policy text into executable rules, which AWS presents as a user-experience differentiator for controls such as time-based limits. In practice, governance is being packaged as a gate built directly into the call path.[1], [2]
Anthropic moves the data back into the customer's cloud
At Anthropic, the moving control is the location of the data itself. Since June, customer data from the Mythos and Fable models had been stored on Anthropic's own servers for 30 days. Under the change planned for the fall, the retention window stays at 30 days but the data stays in the customer's cloud instead. The purpose does not change: the system will continue scanning for new cyberattacks that use the technology. The more revealing part is the company's acknowledgement that the rule was both unpopular with customers and a sales risk, and that the new arrangement took months of work with more than 100 customers from regulated industries.[3]
Ramp turns model selection and logging into a product
Ramp's Router product shows a third face of governance: it is about which model receives a request and how that decision is tracked afterwards. The company says it built the tool internally over three years and is now opening it to outside developers. Selection can follow a provider's flex usage tier, up to three benchmarks named by the user, or a strategy that sends the hardest query to an expensive model while trying cheaper ones alongside it. The product then tracks token spend, cost, latency and fallback attempts in a dashboard, and retains model inputs, outputs and tool calls for a year by default. Governance therefore extends from the access question into the choice of model, the cost of that choice and the audit trail it leaves behind.[4]