Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Amazon Bedrock AgentCore vs Gemini Enterprise Agent Platform
Amazon Bedrock AgentCore
AWS platform for building, deploying, and operating AI agents
Gemini Enterprise Agent Platform
Google Cloud platform to build, deploy, govern, and optimize AI agents
Short answer
Each is a cloud provider’s platform to build, deploy, and govern agents: AgentCore on AWS, Agent Platform on Google Cloud.Source 1, Source 2 AgentCore’s registry can be shared with other AWS accounts and bills per record beyond a free tier, while Agent Platform’s registry works per project and is free, with skill scanning billed from January 2027.Source 3, Source 4, Source 5, Source 6
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
Amazon Bedrock AgentCore
Gemini Enterprise Agent Platform
At a glance
What each one is
Amazon Bedrock AgentCore
Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and model.Source 1 Its modular services work together or alone: Runtime hosts agents, Gateway and Policy control tool access, Identity manages agent identities, and AWS Agent Registry catalogs agents and tools.Source 1, Source 8, Source 15, Source 19, Source 20
Gemini Enterprise Agent Platform
Gemini Enterprise Agent Platform, an evolution of Vertex AI, is Google Cloud’s platform to build, deploy, govern, and optimize agents.Source 2, Source 21 Agent Runtime hosts agents, Agent Registry catalogs them, Agent Identity can give agents on supported runtimes an identity, and Agent Gateway checks traffic against policy.Source 10, Source 11, Source 12
The differences that matter
What each registry finds on its own
Amazon Bedrock AgentCoreWith AWS Organizations, AWS Agent Registry can record Runtimes and Gateways it detects in member accounts, with nothing to install; others are published as records.Source 8, Source 22
Gemini Enterprise Agent PlatformAgent Registry can register agents on supported Google Cloud runtimes automatically, within one project; agents in other projects or elsewhere need manual registration.Source 14, Source 23
Google documents an outbound Agent Gateway in a governance project serving Agent Runtime agents in other projects of the same organization and region.Source 24
How tool access is controlled
Amazon Bedrock AgentCorePolicy in AgentCore can check each request through AgentCore Gateway against rules written in natural language or Cedar before allowing tool access.Source 20
Gemini Enterprise Agent PlatformBy default, Agent Gateway blocks an agent’s outbound connections without an IAM policy grant; Model Armor filters can scan prompts and tool responses.Source 10
Each applies to traffic through its own gateway.Source 10, Source 20 For inbound calls, Agent Gateway can control which clients reach agents, on Agent Runtime only.Source 10
Remote and partner agents
Amazon Bedrock AgentCoreA registry can be shared with other AWS accounts, by invitation outside your AWS Organization; resource-based policies can open a Runtime agent to another account.Source 3, Source 25
Gemini Enterprise Agent PlatformAgent Runtime agents can call agents anywhere through Agent Gateway; granting another organization IAM access to call them is not publicly documented.Source 10
Google says A2A agents on Agent Runtime, in preview, can be exposed to untrusted callers if they implement their own authentication and authorization.Source 26
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Amazon Bedrock AgentCore | Gemini Enterprise Agent Platform | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | AWS platform for building, deploying, and operating agents with any framework and model, for taking agents from proof of concept to production.Source 1, Source 13 | Google Cloud platform to build, deploy, govern, and optimize agents, called an evolution of Vertex AI, for developers and technical teams.Source 2, Source 21 |
| Maturity | Generally available since October 2025.Source 18 AWS Agent Registry generally available since August 2026, and Policy since March 2026.Source 18 | Google says it launched 22 April 2026.Source 40 Registry and Gateway GA since 18 June 2026.Source 16 Agent Identity is generally available; the Agent Identity API is in preview.Source 16 |
| Control | ||
| Agent registry and discovery | AWS Agent Registry catalogs agents, MCP servers, tools, and skills behind an approval workflow, including ones on premises or in other clouds.Source 1, Source 8 | A per-project catalog of agents, MCP servers, and tools.Source 5, Source 12 Agents on supported Google Cloud runtimes can be registered automatically, others manually.Source 14, Source 23 |
| Identity and access control | Agent identities are workload identities in AgentCore Identity.Source 7 Calls into Runtime use IAM SigV4 by default, or JWTs from any OAuth 2.0 provider.Source 29, Source 30 | SPIFFE-based Agent Identity for agents on Agent Runtime, the Gemini Enterprise app, or Cloud Run.Source 11 By default, outbound gateway calls need an IAM access policy.Source 10 |
| Ownership, policy, and revocation | Gateway policies limit an agent’s tools.Source 20 Records need approval unless auto-approval is on; curators can deprecate them.Source 8, Source 22 Owner field: not publicly documented. | Allow and deny access policies (deny overrides allow), enforce and dry-run modes, and Model Armor filters.Source 10, Source 31 An owner field is not publicly documented. |
| Audit log and observability | CloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.Source 22, Source 32, Source 33 Policy logs its decisions.Source 20 | Registry admin changes get Admin Activity audit logs; other calls need Data Access logs turned on.Source 34, Source 35 Gateway traffic is visible in Cloud Logging.Source 10 |
| Connection | ||
| How agents connect | AWS calls AgentCore Runtime serverless; Gateway can forward to any HTTP endpoint.Source 1, Source 9 Outbound-only mode for outside agents is not publicly documented. | Agent Gateway can govern Agent Runtime and Gemini Enterprise app traffic; outside agents can be listed by endpoint.Source 10, Source 41 Outbound-only: not publicly documented. |
| Agents across organizations | A registry can be shared with other AWS accounts; those outside your AWS Organization accept an invitation.Source 3 Gateway can front A2A agents at any HTTP endpoint.Source 9 | Agent Runtime agents can call agents anywhere through Agent Gateway.Source 10 Granting another organization IAM access to call them is not publicly documented. |
| Protocol support | Runtime agents can serve HTTP, MCP, A2A, or AG-UI.Source 42 Gateway acts as one MCP server over its MCP targets; the Registry validates MCP and A2A records.Source 22, Source 43 | Agent Registry catalogs MCP servers and A2A agents; Agent Gateway carries MCP and A2A traffic.Source 10, Source 14, Source 44 A2A agents on Agent Runtime are in preview.Source 45 |
| Frameworks, models, and clouds supported | Runtime works with custom and open-source frameworks, naming CrewAI, LangGraph, LlamaIndex, Google ADK, and Strands.Source 1 Identity covers self-hosted agents.Source 15 | Agent Development Kit or any open-source framework, with Gemini or Model Garden models.Source 46 Agents hosted outside Google Cloud can be registered manually.Source 41 |
| Operations | ||
| Deployment options and data residency | AWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.Source 1, Source 47 | Agent Gateway is managed and regional; agent infrastructure data stays at rest in the selected supported location.Source 48, Source 49 Registry residency reporting is limited.Source 16 |
| Compliance attestations | AWS lists AgentCore as FedRAMP (Class C and Class D) compliant.Source 36, Source 37 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.Source 18, Source 36 | Google lists Agent Platform in scope for ISO 27001, 27017, and 27018, SOC 1, 2, and 3, and PCI DSS, and in the Google Cloud HIPAA BAA.Source 38, Source 39 |
| Support and SLA | AWS says the Amazon Bedrock SLA applies to AgentCore.Source 13 Basic Support is included for all AWS customers.Source 50 | Google Cloud support packages cover needs such as 24/7 coverage.Source 51 An uptime SLA naming Agent Registry, Gateway, Identity, or Runtime is not publicly documented. |
| Time and effort to get running | An AWS account with credentials and permissions for AgentCore API calls.Source 52 The CLI quickstart installs, scaffolds, tests, deploys to AWS, and invokes an agent.Source 52 | Enable the Agent Registry API in a Google Cloud project, plus the Identity-Aware Proxy API for gateway policy.Source 5 Google recommends dry-run mode in staging.Source 31 |
| Pricing model and public prices | By use, per service, no upfront commitment.Source 4 Registry: 5,000 records free a month, then $0.400 per 1,000.Source 4 Runtime v1 CPU: $0.0895 per vCPU-hour.Source 4 | Agent Registry is free; skill scanning is billed from January 2027.Source 6 Agent Runtime: $0.085 per vCPU-hour.Source 17 Agent Gateway egress: $0.085 per 15,000 requests.Source 17 |
| Building | ||
| Agent building tools | A managed harness defines an agent from a model, prompt, and tools.Source 1 Code agents using frameworks such as Strands, LangGraph, or Google ADK deploy to Runtime.Source 52 | Agent Studio (a low-code canvas), the open-source Agent Development Kit, and Agent Garden’s prebuilt agents and templates.Source 2, Source 46 A Managed Agents API is in preview.Source 2 |
| Model access | AWS calls it model-agnostic: any model in or outside Amazon Bedrock, naming OpenAI, Google’s Gemini, Anthropic’s Claude, Amazon Nova, Meta Llama, and Mistral.Source 13 | More than 200 models, including Gemini, third-party, and open-source models.Source 2 Google says Model Garden supports Anthropic’s Claude.Source 40 |
| Integrations and ecosystem | Gateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import partner tools bought in AWS Marketplace.Source 13, Source 19 | Agents in Agent Registry can be made available in the Gemini Enterprise app.Source 48 Google’s own remote MCP servers are registered automatically.Source 44 |
Which to choose
Choose Amazon Bedrock AgentCore if
- Your agents run on AWS, and you want one registry shared across AWS accounts, including accounts outside your AWS Organization.Source 3
- You want tool-access rules written in natural language or Cedar and checked on each request through AgentCore Gateway.Source 20
- You want one identity service for agents on Runtime or self-hosted, working with Microsoft Entra ID, Okta, or Amazon Cognito.Source 13, Source 15
- You need agents in AWS GovCloud (US-West), where AgentCore is generally available, though AWS Agent Registry is not.Source 18, Source 53
Choose Gemini Enterprise Agent Platform if
- Your agents run on Google Cloud, where agents on supported runtimes, such as Google Kubernetes Engine, can be registered automatically.Source 14, Source 23
- You want outbound gateway calls blocked by default unless an IAM policy allows them, with Model Armor scanning prompts and tool responses.Source 10
- You want a registry for agents, MCP servers, and endpoints that is free; skill scanning is billed from January 2027.Source 6
- You want Agent Studio’s low-code canvas and over 200 models, including Gemini; Google says Model Garden supports Anthropic’s Claude.Source 2, Source 40
Questions buyers ask
Can either one manage agents that run outside its own cloud?
Both can list them: AWS says its registry works with agents on premises or in other clouds, and Google’s Agent Registry adds them by manual registration.Source 1, Source 41 AgentCore Identity covers self-hosted agents; Google lists Agent Identity for Agent Runtime, the Gemini Enterprise app, and Cloud Run.Source 11, Source 15
How is each one priced?
AgentCore is priced by use, per service, with no upfront commitment; Registry records beyond 5,000 a month cost $0.400 per 1,000.Source 4 Google’s Agent Registry is free; skill scanning is billed from January 2027.Source 6 Agent Runtime compute is $0.085 per vCPU-hour, with a monthly free tier.Source 17
Do they support MCP and A2A?
AgentCore Runtime agents can serve MCP or A2A, Gateway acts as an MCP server, and the Registry validates MCP and A2A records.Source 22, Source 42, Source 43 Agent Registry catalogs MCP servers and A2A agents, Agent Gateway carries both, and A2A agents on Agent Runtime are in preview.Source 10, Source 14, Source 44, Source 45
Which models can agents use?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
59 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) Back:abcdefghijklmno
Source 3: Sharing a registry across accounts with AWS RAM Back:abcdefg
Source 7: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity Back:abcd
Source 8: AWS Agent Registry: Discover and manage agents, tools, and resources Back:abcde
Source 9: HTTP passthrough targets - AgentCore Gateway Back:abc
Source 16: Gemini Enterprise Agent Platform release notes Back:abcdef
Source 17: Gemini Enterprise Agent Platform pricing Back:abcde
Source 18: Release notes - Amazon Bedrock AgentCore Back:abcde
Source 19: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models Back:ab
Source 20: Policy in Amazon Bedrock AgentCore: Control Agent Interactions Back:abcdefg
Source 21: Gemini Enterprise Agent Platform (formerly Vertex AI) Back:ab
Source 22: Key capabilities - AWS Agent Registry Back:abcdef
Source 25: Resource-based policies for Amazon Bedrock AgentCore Back:ab
Source 27: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore Back to text
Source 28: Configure Amazon Bedrock AgentCore Runtime and tools for VPC Back to text
Source 29: Authenticate and authorize with Inbound Auth and Outbound Auth Back:ab
Source 32: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail Back:ab
Source 33: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore Back:ab
Source 36: Compliance validation for Amazon Bedrock AgentCore Back:abc
Source 37: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services Back:ab
Source 38: Google Cloud Platform Services in Scope by Compliance Program Back:ab
Source 40: Introducing Gemini Enterprise Agent Platform, powering the next wave of agents Back:abcd
Source 42: Understand the AgentCore Runtime service contract Back:ab
Source 43: Supported targets for Amazon Bedrock AgentCore gateways Back:ab
Source 46: Build with Gemini Enterprise Agent Platform Back:ab
Source 47: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations Back to text
Source 49: Supported locations for agents in Agent Platform Back to text
Source 52: Get started with Amazon Bedrock AgentCore Back:abcd
Source 53: Supported AWS Regions - Amazon Bedrock AgentCore Back to text
Source 54: Authenticate to external services using an agent's own identity Back to text