← All Posts
AWS28 Sep 2026·11 min read

Amazon Bedrock & Agentic AI: A Beginner's Guide

Srinivasa Rao Maganti — Lead Cloud & DevOps Trainer at CloudTechTrainings

Srinivasa Rao Maganti

Cloud Architect & Lead Trainer, CloudTechTrainings

#Amazon Bedrock#Agentic AI#AgentCore#Generative AI#AWS AI Practitioner#AIF-C01#AWS

Short answer first. Amazon Bedrock is AWS's fully managed service for using foundation models — large language models from Amazon and other providers — through a single API, without running any GPUs yourself. An AI agent is a model that does more than answer: it plans steps, calls tools (APIs, databases, code), and acts on the results. Amazon Bedrock AgentCore is the AWS platform for running those agents securely in production. If you already know core AWS — IAM, VPC, Lambda, CloudWatch — you are closer to building agents than you think.

1
API for many foundation models
8 hrs
max AgentCore Runtime session
2
AWS AI certs to target
0
GPUs to manage

1. Chatbot vs RAG vs Agent — The Plain-English Version

Most confusion about "agentic AI" disappears once you see the three levels side by side. Each level adds one capability on top of the previous one.

LevelWhat It DoesExampleBedrock Feature
Chatbot (plain LLM)Answers from what the model learned during training"Explain what a VPC is"Model invocation (Converse API)
RAG (retrieval-augmented generation)Looks up your own documents first, then answers using them"What is our leave policy?" — answered from your HR PDFsKnowledge Bases
AgentPlans multiple steps, calls tools, and acts on the results"Find last month's top 5 EC2 cost spikes and open a ticket for each"Bedrock Agents / AgentCore

Tip: The One-Line Mental Model

A chatbot talks. RAG talks about your data. An agent talks, decides, and does — which is exactly why agents need IAM permissions, network boundaries, and monitoring like any other production workload.

2. The Bedrock Building Blocks

  • ●Model choice — Amazon Nova plus models from providers such as Anthropic, Meta, Mistral, and others, all behind the same API, so you can swap models without rewriting your app
  • ●Converse API — one consistent request/response format for chatting with any supported model, including tool use (function calling)
  • ●Knowledge Bases — managed RAG: point it at documents in S3, it chunks, embeds, and stores them in a vector store, then retrieves the right passages at question time
  • ●Guardrails — content filters, denied topics, PII redaction, and grounding checks applied to both prompts and responses
  • ●Agents — a configuration-driven way to give a model instructions, tools (action groups backed by Lambda or APIs), and a knowledge base

3. What AgentCore Adds for Production Agents

Building a demo agent on your laptop is easy; running one for real users is not. Who is the agent acting as? What can it access? What happens when a session runs for an hour? How do you know it is giving good answers? AgentCore answers those operational questions. It works with any open-source framework — LangGraph, CrewAI, LlamaIndex, Strands Agents, the OpenAI Agents SDK — and any model, in or outside Bedrock.

AgentCore ServiceWhat It Solves
RuntimeServerless hosting for agents with per-session isolation and sessions of up to 8 hours; supports the Agent-to-Agent (A2A) protocol
MemoryShort-term and long-term memory so an agent remembers context across turns and sessions
GatewayTurns existing APIs and Lambda functions into tools an agent can call
IdentityLets agents act on behalf of a user (or as themselves) with OAuth and secure token storage
Code Interpreter & BrowserSandboxed code execution and a managed browser for agents that need to compute or navigate websites
ObservabilityEnd-to-end traces and metrics in CloudWatch, OpenTelemetry-compatible, so tools like Datadog or Langfuse can consume them
EvaluationsAutomated quality scoring of agent responses, on production traffic and in test workflows (generally available since March 2026)

Note: Notice the Pattern

Every row above maps to a classic cloud skill: hosting (compute), identity (IAM/OAuth), networking (VPC and PrivateLink are supported on all AgentCore services), and monitoring (CloudWatch). Agentic AI does not replace cloud fundamentals — it runs on them.

4. Your First Bedrock Call (10 Minutes)

  1. 1Open the Amazon Bedrock console in a Region where it is available and browse the model catalog — note the exact model ID (or cross-Region inference profile ID) for a low-cost model such as Amazon Nova Lite
  2. 2Some models require you to accept the provider's terms or submit a short use-case form on first use — do that in the console before calling the API
  3. 3Give your IAM user or role permission for bedrock:InvokeModel (the Converse API uses the same permission) — scoped to that model, not "*"
  4. 4Run the call below with the AWS CLI or Python (boto3)
bash
# AWS CLI — replace MODEL_ID with the ID shown in your Region's model catalog
aws bedrock-runtime converse \
  --model-id MODEL_ID \
  --messages '[{"role":"user","content":[{"text":"Explain an AWS VPC in two sentences."}]}]' \
  --inference-config '{"maxTokens":200}'
python
import boto3

client = boto3.client("bedrock-runtime")

response = client.converse(
    modelId="MODEL_ID",  # copy from the Bedrock model catalog in your Region
    messages=[{"role": "user", "content": [{"text": "Explain an AWS VPC in two sentences."}]}],
    inferenceConfig={"maxTokens": 200},
)

print(response["output"]["message"]["content"][0]["text"])
print(response["usage"])  # input/output token counts — this is what you are billed on

Warning: Cost Gotchas for Beginners

On-demand Bedrock bills per input and output token, so short prompts with a maxTokens cap cost very little. The surprise bills come from what sits around the model: a Knowledge Base vector store (some options, such as OpenSearch Serverless, charge a minimum hourly capacity even when idle), agents that loop through many tool calls, and forgotten test resources. Set an AWS Budgets alert before you experiment, and delete lab resources the same day.

5. Where This Fits in Your Career

Here is the honest reality check: companies hiring for GenAI-on-AWS roles still expect you to understand IAM policies, networking, serverless, and monitoring — because that is what an agent in production is built from. The fastest path is not to skip straight to agents; it is to stack AI skills on top of a solid AWS foundation.

StepCertificationWhy It Matters
1AWS Cloud Practitioner (CLF-C02) Core AWS vocabulary, billing, and the shared responsibility model
2AWS Certified AI Practitioner (AIF-C01)Foundational, $100 USD, passing score 700 — AI/ML and GenAI fundamentals, foundation-model applications, responsible AI, and AI security/governance
3Solutions Architect Associate (SAA-C03) The architecture skills (IAM, VPC, Lambda, storage) every production agent depends on
4AWS Certified Generative AI Developer – Professional (AIP-C01)Professional-tier, passing score 750 — building production GenAI and agent solutions on Bedrock; AWS recommends 2+ years of AWS experience and 1 year of hands-on GenAI work

Steps 1 and 3 are where most learners should start. Test yourself with our free CLF-C02 mock exam and SAA-C03 mock exam, and follow the week-by-week plan in our SAA-C03 Study Guide.

A Simple 4-Week Learning Plan

  1. 1Week 1 — AWS foundations: IAM users/roles/policies, a VPC with public and private subnets, S3, and a first Lambda function
  2. 2Week 2 — Bedrock basics: Converse API calls from Python, compare two models on the same prompt, add a Guardrail and see what it blocks
  3. 3Week 3 — RAG: build a Knowledge Base over a handful of your own PDFs in S3 and query it; watch the token usage and delete the vector store afterwards
  4. 4Week 4 — Your first agent: one agent with one tool (a Lambda that reads from DynamoDB), then trace a run end-to-end in CloudWatch

At CloudTechTrainings, our live AWS course covers the foundations agents run on — IAM, VPC, Lambda, S3, and CloudWatch — hands-on, so that Bedrock and AgentCore become the next step rather than a leap. For the IAM side specifically, our S3 bucket policy examples are a good place to practise writing least-privilege policies.

Keep Learning

Frequently Asked Questions

What is Amazon Bedrock?

Amazon Bedrock is a fully managed AWS service that gives you access to foundation models from Amazon and other providers through a single API. You pay per use and never manage GPUs or model servers yourself.

What is the difference between Amazon Bedrock and AgentCore?

Bedrock is where you access and customise foundation models (plus Knowledge Bases, Guardrails, and Agents). Amazon Bedrock AgentCore is the platform for running AI agents in production — Runtime, Memory, Gateway, Identity, Observability, and Evaluations — and it works with any framework and any model, in or outside Bedrock.

What is an AI agent, and how is it different from a chatbot?

A chatbot answers questions. An AI agent plans multiple steps, calls tools such as APIs, databases, or code, and acts on the results. That is why agents need IAM permissions, network controls, and monitoring like any other production workload.

Do I need machine learning experience to use Amazon Bedrock?

No. Bedrock is used through an API, so basic Python and core AWS skills — IAM, S3, Lambda, and CloudWatch — are enough to start. ML knowledge helps later with model evaluation and customisation.

Which AWS certification should I take for generative AI?

Beginners can start with AWS Certified AI Practitioner (AIF-C01), a foundational exam costing $100 USD with a passing score of 700. For production GenAI and agent work, the target is AWS Certified Generative AI Developer – Professional (AIP-C01), which AWS recommends after 2+ years of AWS experience. A Solutions Architect Associate (SAA-C03) in between builds the architecture skills agents depend on.

How much does Amazon Bedrock cost?

On-demand Bedrock pricing is per input and output token and varies by model, so short prompts with a token limit cost very little. Larger bills usually come from surrounding resources such as a Knowledge Base vector store, agents that loop through many tool calls, or forgotten test resources — set an AWS Budgets alert before experimenting.

Ready to Start Your Cloud Journey?

Live batches Mon–Sat — Azure 8:15 – 9:15 AM IST (started 24 august 2026 — join in progress) · AWS 10:30 – 11:45 AM IST (started 31 august 2026 — join in progress). Hands-on labs, exam prep, and community support.

Join Free Demo →WhatsApp Us

Keep Reading

AWS

AWS CLF-C02 Study Guide 2026: How to Pass First Try

A focused study plan for the AWS Cloud Practitioner exam — all 4 scored domains, a realistic 4-week timeline, and exam-day tactics for a certification that assumes zero prior AWS experience.

10 Aug 2026·10 min read
Read →
AWS

AWS SOA-C03 Study Guide 2026: How to Pass First Try

A study plan for the AWS CloudOps Engineer (formerly SysOps Administrator) Associate exam — all 5 domains, an SOA-C03 vs SAA-C03 comparison, and exam-day tactics for an operations-focused certification.

10 Aug 2026·11 min read
Read →