Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Amazon Bedrock AgentCore vs Gemini Enterprise Agent Platform

Amazon Bedrock AgentCore

AWS platform for building, deploying, and operating AI agents

Gemini Enterprise Agent Platform

Google Cloud platform to build, deploy, govern, and optimize AI agents

Short answer

Each is a cloud provider’s platform to build, deploy, and govern agents: AgentCore on AWS, Agent Platform on Google Cloud.⁠Source 1, Source 2 AgentCore’s registry can be shared with other AWS accounts and bills per record beyond a free tier, while Agent Platform’s registry works per project and is free, with skill scanning billed from January 2027.⁠Source 3, Source 4, Source 5, Source 6

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

Public sources · checked 2 October 2026
  • Offered

Amazon Bedrock AgentCore

  • Build agents: OfferedHarness managed agent loop⁠Source 1
  • Host and run agents: OfferedAgentCore Runtime⁠Source 1
  • Identity and access: OfferedAgentCore Identity workload identities⁠Source 7
  • Registry and governance: OfferedAWS Agent Registry with approvals⁠Source 8
  • Traffic between agents, tools, and models: OfferedAgentCore Gateway⁠Source 9
  • Agents across organizations: OfferedRegistry shared through AWS RAM⁠Source 3

Gemini Enterprise Agent Platform

  • Build agents: OfferedAgent Studio low-code canvas⁠Source 2
  • Host and run agents: OfferedAgent Runtime⁠Source 10
  • Identity and access: OfferedSPIFFE-based Agent Identity⁠Source 11
  • Registry and governance: OfferedAgent Registry⁠Source 12
  • Traffic between agents, tools, and models: OfferedAgent Gateway⁠Source 10
  • Agents across organizations: OfferedGateway calls to outside agents⁠Source 10

At a glance

TopicAmazon Bedrock AgentCoreGemini Enterprise Agent Platform
Builds and hosts agentsBuild agents with a managed harness or the AgentCore SDK; serverless AgentCore Runtime hosts them.⁠Source 1, Source 13Teams can build agents with Agent Studio or the Agent Development Kit and run them on Agent Runtime.⁠Source 2, Source 10
Registry reachCan be shared with other AWS accounts through AWS RAM; can list resources on AWS, on premises, or in other clouds.⁠Source 1, Source 3Works per Google Cloud project; agents in other projects or outside Google Cloud can be added by manual registration.⁠Source 5, Source 14
Agent identityWorkload identities in AgentCore Identity, for agents on Runtime, in self-hosted environments, or in hybrid deployments.⁠Source 7, Source 15SPIFFE-based Agent Identity, which Google lists for Agent Runtime, the Gemini Enterprise app, and Cloud Run.⁠Source 11 Agent Identity is generally available; the Agent Identity API is in preview.⁠Source 16
Pricing modelBy use, per service, with no upfront commitment or minimum fee.⁠Source 4 Registry records above 5,000 a month are billed.⁠Source 4Agent Registry is free; skill scanning is billed from January 2027.⁠Source 6 Agent Runtime is billed per vCPU-hour and GiB-hour of memory.⁠Source 17 Agent Gateway egress is billed at $0.085 per 15,000 requests.⁠Source 17
Generally availableSince October 2025; AWS Agent Registry since August 2026.⁠Source 18Agent Registry and Agent Gateway since 18 June 2026.⁠Source 16

What each one is

Amazon Bedrock AgentCore

Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and model.⁠Source 1 Its modular services work together or alone: Runtime hosts agents, Gateway and Policy control tool access, Identity manages agent identities, and AWS Agent Registry catalogs agents and tools.⁠Source 1, Source 8, Source 15, Source 19, Source 20

Gemini Enterprise Agent Platform

Gemini Enterprise Agent Platform, an evolution of Vertex AI, is Google Cloud’s platform to build, deploy, govern, and optimize agents.⁠Source 2, Source 21 Agent Runtime hosts agents, Agent Registry catalogs them, Agent Identity can give agents on supported runtimes an identity, and Agent Gateway checks traffic against policy.⁠Source 10, Source 11, Source 12

The differences that matter

  1. What each registry finds on its own

    Amazon Bedrock AgentCore

    With AWS Organizations, AWS Agent Registry can record Runtimes and Gateways it detects in member accounts, with nothing to install; others are published as records.⁠Source 8, Source 22

    Gemini Enterprise Agent Platform

    Agent Registry can register agents on supported Google Cloud runtimes automatically, within one project; agents in other projects or elsewhere need manual registration.⁠Source 14, Source 23

    Google documents an outbound Agent Gateway in a governance project serving Agent Runtime agents in other projects of the same organization and region.⁠Source 24

  2. How tool access is controlled

    Amazon Bedrock AgentCore

    Policy in AgentCore can check each request through AgentCore Gateway against rules written in natural language or Cedar before allowing tool access.⁠Source 20

    Gemini Enterprise Agent Platform

    By default, Agent Gateway blocks an agent’s outbound connections without an IAM policy grant; Model Armor filters can scan prompts and tool responses.⁠Source 10

    Each applies to traffic through its own gateway.⁠Source 10, Source 20 For inbound calls, Agent Gateway can control which clients reach agents, on Agent Runtime only.⁠Source 10

  3. Remote and partner agents

    Amazon Bedrock AgentCore

    A registry can be shared with other AWS accounts, by invitation outside your AWS Organization; resource-based policies can open a Runtime agent to another account.⁠Source 3, Source 25

    Gemini Enterprise Agent Platform

    Agent Runtime agents can call agents anywhere through Agent Gateway; granting another organization IAM access to call them is not publicly documented.⁠Source 10

    Google says A2A agents on Agent Runtime, in preview, can be exposed to untrusted callers if they implement their own authentication and authorization.⁠Source 26

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicAmazon Bedrock AgentCoreGemini Enterprise Agent Platform
Network exposureVPC callers can reach AgentCore over PrivateLink without an internet gateway; Runtime and built-in tools can connect into your VPC.⁠Source 27, Source 28Inbound gateway mode supports only Agent Runtime agents; Identity-Aware Proxy checks outbound gateway calls against IAM access policy.⁠Source 10
IdentityAgent identities are workload identities in AgentCore Identity; calls into Runtime use IAM SigV4 by default, or OAuth JWTs.⁠Source 7, Source 29, Source 30Agent Identity is generally available; its API is in preview.⁠Source 16 It can give agents on supported runtimes SPIFFE-based identities.⁠Source 11
Access changes and revocationAn explicit deny overrides allows on Runtime, Gateway, and Memory; removing an account from a registry share revokes its access.⁠Source 3, Source 25Deny rules override allow rules.⁠Source 31 Deleting an agent leaves its IAM bindings as inactive grants to remove by hand.⁠Source 11
Audit trailCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls; Policy logs its decisions.⁠Source 20, Source 22, Source 32, Source 33Registry admin changes are logged; other calls need Data Access logs on.⁠Source 34, Source 35 Agent Identity adds audit logs for agent actions.⁠Source 11
ComplianceHIPAA eligible; AWS lists it as FedRAMP (Class C and Class D), SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 36, Source 37In scope for ISO 27001, SOC 1, 2, and 3, and PCI DSS; in Google Cloud’s HIPAA BAA.⁠Source 38, Source 39

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Amazon Bedrock AgentCore and Gemini Enterprise Agent Platform compared on 18 criteria
Amazon Bedrock AgentCoreGemini Enterprise Agent Platform
What it is
What it is and who it’s forAWS platform for building, deploying, and operating agents with any framework and model, for taking agents from proof of concept to production.⁠Source 1, Source 13Google Cloud platform to build, deploy, govern, and optimize agents, called an evolution of Vertex AI, for developers and technical teams.⁠Source 2, Source 21
MaturityGenerally available since October 2025.⁠Source 18 AWS Agent Registry generally available since August 2026, and Policy since March 2026.⁠Source 18Google says it launched 22 April 2026.⁠Source 40 Registry and Gateway GA since 18 June 2026.⁠Source 16 Agent Identity is generally available; the Agent Identity API is in preview.⁠Source 16
Control
Agent registry and discoveryAWS Agent Registry catalogs agents, MCP servers, tools, and skills behind an approval workflow, including ones on premises or in other clouds.⁠Source 1, Source 8A per-project catalog of agents, MCP servers, and tools.⁠Source 5, Source 12 Agents on supported Google Cloud runtimes can be registered automatically, others manually.⁠Source 14, Source 23
Identity and access controlAgent identities are workload identities in AgentCore Identity.⁠Source 7 Calls into Runtime use IAM SigV4 by default, or JWTs from any OAuth 2.0 provider.⁠Source 29, Source 30SPIFFE-based Agent Identity for agents on Agent Runtime, the Gemini Enterprise app, or Cloud Run.⁠Source 11 By default, outbound gateway calls need an IAM access policy.⁠Source 10
Ownership, policy, and revocationGateway policies limit an agent’s tools.⁠Source 20 Records need approval unless auto-approval is on; curators can deprecate them.⁠Source 8, Source 22 Owner field: not publicly documented.Allow and deny access policies (deny overrides allow), enforce and dry-run modes, and Model Armor filters.⁠Source 10, Source 31 An owner field is not publicly documented.
Audit log and observabilityCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.⁠Source 22, Source 32, Source 33 Policy logs its decisions.⁠Source 20Registry admin changes get Admin Activity audit logs; other calls need Data Access logs turned on.⁠Source 34, Source 35 Gateway traffic is visible in Cloud Logging.⁠Source 10
Connection
How agents connectAWS calls AgentCore Runtime serverless; Gateway can forward to any HTTP endpoint.⁠Source 1, Source 9 Outbound-only mode for outside agents is not publicly documented.Agent Gateway can govern Agent Runtime and Gemini Enterprise app traffic; outside agents can be listed by endpoint.⁠Source 10, Source 41 Outbound-only: not publicly documented.
Agents across organizationsA registry can be shared with other AWS accounts; those outside your AWS Organization accept an invitation.⁠Source 3 Gateway can front A2A agents at any HTTP endpoint.⁠Source 9Agent Runtime agents can call agents anywhere through Agent Gateway.⁠Source 10 Granting another organization IAM access to call them is not publicly documented.
Protocol supportRuntime agents can serve HTTP, MCP, A2A, or AG-UI.⁠Source 42 Gateway acts as one MCP server over its MCP targets; the Registry validates MCP and A2A records.⁠Source 22, Source 43Agent Registry catalogs MCP servers and A2A agents; Agent Gateway carries MCP and A2A traffic.⁠Source 10, Source 14, Source 44 A2A agents on Agent Runtime are in preview.⁠Source 45
Frameworks, models, and clouds supportedRuntime works with custom and open-source frameworks, naming CrewAI, LangGraph, LlamaIndex, Google ADK, and Strands.⁠Source 1 Identity covers self-hosted agents.⁠Source 15Agent Development Kit or any open-source framework, with Gemini or Model Garden models.⁠Source 46 Agents hosted outside Google Cloud can be registered manually.⁠Source 41
Operations
Deployment options and data residencyAWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.⁠Source 1, Source 47Agent Gateway is managed and regional; agent infrastructure data stays at rest in the selected supported location.⁠Source 48, Source 49 Registry residency reporting is limited.⁠Source 16
Compliance attestationsAWS lists AgentCore as FedRAMP (Class C and Class D) compliant.⁠Source 36, Source 37 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 18, Source 36Google lists Agent Platform in scope for ISO 27001, 27017, and 27018, SOC 1, 2, and 3, and PCI DSS, and in the Google Cloud HIPAA BAA.⁠Source 38, Source 39
Support and SLAAWS says the Amazon Bedrock SLA applies to AgentCore.⁠Source 13 Basic Support is included for all AWS customers.⁠Source 50Google Cloud support packages cover needs such as 24/7 coverage.⁠Source 51 An uptime SLA naming Agent Registry, Gateway, Identity, or Runtime is not publicly documented.
Time and effort to get runningAn AWS account with credentials and permissions for AgentCore API calls.⁠Source 52 The CLI quickstart installs, scaffolds, tests, deploys to AWS, and invokes an agent.⁠Source 52Enable the Agent Registry API in a Google Cloud project, plus the Identity-Aware Proxy API for gateway policy.⁠Source 5 Google recommends dry-run mode in staging.⁠Source 31
Pricing model and public pricesBy use, per service, no upfront commitment.⁠Source 4 Registry: 5,000 records free a month, then $0.400 per 1,000.⁠Source 4 Runtime v1 CPU: $0.0895 per vCPU-hour.⁠Source 4Agent Registry is free; skill scanning is billed from January 2027.⁠Source 6 Agent Runtime: $0.085 per vCPU-hour.⁠Source 17 Agent Gateway egress: $0.085 per 15,000 requests.⁠Source 17
Building
Agent building toolsA managed harness defines an agent from a model, prompt, and tools.⁠Source 1 Code agents using frameworks such as Strands, LangGraph, or Google ADK deploy to Runtime.⁠Source 52Agent Studio (a low-code canvas), the open-source Agent Development Kit, and Agent Garden’s prebuilt agents and templates.⁠Source 2, Source 46 A Managed Agents API is in preview.⁠Source 2
Model accessAWS calls it model-agnostic: any model in or outside Amazon Bedrock, naming OpenAI, Google’s Gemini, Anthropic’s Claude, Amazon Nova, Meta Llama, and Mistral.⁠Source 13More than 200 models, including Gemini, third-party, and open-source models.⁠Source 2 Google says Model Garden supports Anthropic’s Claude.⁠Source 40
Integrations and ecosystemGateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import partner tools bought in AWS Marketplace.⁠Source 13, Source 19Agents in Agent Registry can be made available in the Gemini Enterprise app.⁠Source 48 Google’s own remote MCP servers are registered automatically.⁠Source 44

Which to choose

Choose Amazon Bedrock AgentCore if

  • Your agents run on AWS, and you want one registry shared across AWS accounts, including accounts outside your AWS Organization.⁠Source 3
  • You want tool-access rules written in natural language or Cedar and checked on each request through AgentCore Gateway.⁠Source 20
  • You want one identity service for agents on Runtime or self-hosted, working with Microsoft Entra ID, Okta, or Amazon Cognito.⁠Source 13, Source 15
  • You need agents in AWS GovCloud (US-West), where AgentCore is generally available, though AWS Agent Registry is not.⁠Source 18, Source 53

Choose Gemini Enterprise Agent Platform if

  • Your agents run on Google Cloud, where agents on supported runtimes, such as Google Kubernetes Engine, can be registered automatically.⁠Source 14, Source 23
  • You want outbound gateway calls blocked by default unless an IAM policy allows them, with Model Armor scanning prompts and tool responses.⁠Source 10
  • You want a registry for agents, MCP servers, and endpoints that is free; skill scanning is billed from January 2027.⁠Source 6
  • You want Agent Studio’s low-code canvas and over 200 models, including Gemini; Google says Model Garden supports Anthropic’s Claude.⁠Source 2, Source 40

Questions buyers ask

Can either one manage agents that run outside its own cloud?

Both can list them: AWS says its registry works with agents on premises or in other clouds, and Google’s Agent Registry adds them by manual registration.⁠Source 1, Source 41 AgentCore Identity covers self-hosted agents; Google lists Agent Identity for Agent Runtime, the Gemini Enterprise app, and Cloud Run.⁠Source 11, Source 15

How is each one priced?

AgentCore is priced by use, per service, with no upfront commitment; Registry records beyond 5,000 a month cost $0.400 per 1,000.⁠Source 4 Google’s Agent Registry is free; skill scanning is billed from January 2027.⁠Source 6 Agent Runtime compute is $0.085 per vCPU-hour, with a monthly free tier.⁠Source 17

Do they support MCP and A2A?

AgentCore Runtime agents can serve MCP or A2A, Gateway acts as an MCP server, and the Registry validates MCP and A2A records.⁠Source 22, Source 42, Source 43 Agent Registry catalogs MCP servers and A2A agents, Agent Gateway carries both, and A2A agents on Agent Runtime are in preview.⁠Source 10, Source 14, Source 44, Source 45

Which models can agents use?

AWS calls AgentCore model-agnostic and names OpenAI, Gemini, Claude, Amazon Nova, Meta Llama, and Mistral models, in or outside Amazon Bedrock.⁠Source 13 Google says Model Garden offers more than 200 models, including Gemini, Anthropic’s Claude, and open-source models.⁠Source 2, Source 40

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

59 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) AWS · checked Back:abcdefghijklmno

  2. Source 2: Agent Platform overview Google · checked Back:abcdefghij

  3. Source 3: Sharing a registry across accounts with AWS RAM AWS · checked Back:abcdefg

  4. Source 4: Amazon Bedrock AgentCore Pricing AWS · checked Back:abcdefg

  5. Source 5: Set up Agent Registry Google · checked Back:abcd

  6. Source 6: Agent Registry pricing Google · checked Back:abcde

  7. Source 7: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity AWS · checked Back:abcd

  8. Source 8: AWS Agent Registry: Discover and manage agents, tools, and resources AWS · checked Back:abcde

  9. Source 9: HTTP passthrough targets - AgentCore Gateway AWS · checked Back:abc

  10. Source 10: Agent Gateway overview Google · checked Back:abcdefghijklmnopqr

  11. Source 11: Agent Identity overview Google · checked Back:abcdefgh

  12. Source 12: Agent Registry overview Google · checked Back:abc

  13. Source 13: Amazon Bedrock AgentCore FAQs AWS · checked Back:abcdefg

  14. Source 14: Register agents Google · checked Back:abcdef

  15. Source 15: Features of AgentCore Identity AWS · checked Back:abcde

  16. Source 16: Gemini Enterprise Agent Platform release notes Google · checked Back:abcdef

  17. Source 17: Gemini Enterprise Agent Platform pricing Google · checked Back:abcde

  18. Source 18: Release notes - Amazon Bedrock AgentCore AWS · checked Back:abcde

  19. Source 19: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models AWS · checked Back:ab

  20. Source 20: Policy in Amazon Bedrock AgentCore: Control Agent Interactions AWS · checked Back:abcdefg

  21. Source 21: Gemini Enterprise Agent Platform (formerly Vertex AI) Google · checked Back:ab

  22. Source 22: Key capabilities - AWS Agent Registry AWS · checked Back:abcdef

  23. Source 23: Use automatic registration Google · checked Back:abc

  24. Source 24: Set up Agent Gateway Google · checked Back to text

  25. Source 25: Resource-based policies for Amazon Bedrock AgentCore AWS · checked Back:ab

  26. Source 26: Share an agent Google · checked Back to text

  27. Source 27: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore AWS · checked Back to text

  28. Source 28: Configure Amazon Bedrock AgentCore Runtime and tools for VPC AWS · checked Back to text

  29. Source 29: Authenticate and authorize with Inbound Auth and Outbound Auth AWS · checked Back:ab

  30. Source 30: Configure inbound JWT authorizer AWS · checked Back:ab

  31. Source 31: IAM Access policies overview Google · checked Back:abc

  32. Source 32: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail AWS · checked Back:ab

  33. Source 33: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore AWS · checked Back:ab

  34. Source 34: Agent Registry audit logging Google · checked Back:ab

  35. Source 35: Cloud Audit Logs overview Google · checked Back:ab

  36. Source 36: Compliance validation for Amazon Bedrock AgentCore AWS · checked Back:abc

  37. Source 37: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services AWS · checked Back:ab

  38. Source 38: Google Cloud Platform Services in Scope by Compliance Program Google · checked Back:ab

  39. Source 39: HIPAA compliance on Google Cloud Google · checked Back:ab

  40. Source 40: Introducing Gemini Enterprise Agent Platform, powering the next wave of agents Google · checked Back:abcd

  41. Source 41: Use manual registration Google · checked Back:abcd

  42. Source 42: Understand the AgentCore Runtime service contract AWS · checked Back:ab

  43. Source 43: Supported targets for Amazon Bedrock AgentCore gateways AWS · checked Back:ab

  44. Source 44: Register MCP servers Google · checked Back:abc

  45. Source 45: Create an Agent2Agent agent Google · checked Back:ab

  46. Source 46: Build with Gemini Enterprise Agent Platform Google · checked Back:ab

  47. Source 47: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations AWS · checked Back to text

  48. Source 48: Import A2A agents from Agent Registry Google · checked Back:ab

  49. Source 49: Supported locations for agents in Agent Platform Google · checked Back to text

  50. Source 50: Compare AWS Support plans AWS · checked Back to text

  51. Source 51: Getting help for agents Google · checked Back to text

  52. Source 52: Get started with Amazon Bedrock AgentCore AWS · checked Back:abcd

  53. Source 53: Supported AWS Regions - Amazon Bedrock AgentCore AWS · checked Back to text

  54. Source 54: Authenticate to external services using an agent's own identity Google · checked Back to text

  55. Source 55: Why Blocks? Blocks.ai · checked Back to text

  56. Source 56: What is Blocks? Blocks.ai · checked Back to text

  57. Source 57: Your company's private network Blocks.ai · checked Back to text

  58. Source 58: Network requirements Blocks.ai · checked Back to text

  59. Source 59: Solutions: Agent sprawl Blocks.ai · checked Back to text