Skip to main content
This guide shows you how to configure AWS Bedrock Guardrails with AI Studio. After completing this setup, AI Studio can use your Bedrock guardrails to filter content, detect PII, and enforce topic policies across your AI agents. For an overview of how guardrails work in AI Studio, see Configure guardrails.

Prerequisites

Before configuring Bedrock guardrails in AI Studio, you need:
  • An AWS account with access to Amazon Bedrock
  • A Bedrock guardrail created in the AWS console
  • AWS credentials with permission to invoke the guardrail
  • Enterprise plan access to AI Studio

Create a Bedrock guardrail in AWS

If you haven’t created a Bedrock guardrail yet, follow these steps in the AWS console:
  1. Navigate to Amazon Bedrock > Guardrails in the AWS console
  2. Select Create guardrail
  3. Configure your guardrail policies:
    • Content filters: Block harmful content categories (hate, insults, sexual, violence)
    • Denied topics: Define custom topics to block
    • Word filters: Block specific words or phrases
    • Sensitive information filters: Detect and block PII types
    • Contextual grounding: Check for hallucinations and relevance
  4. Save your guardrail and note the Guardrail ID and Version
For detailed instructions, see Create a guardrail in the AWS documentation.

Configuration parameters

Configure these parameters when adding a Bedrock guardrail in AI Studio:

Required parameters

Optional parameters

AWS authentication options

AI Studio supports multiple AWS authentication methods for Bedrock guardrails. Use IAM user access keys for straightforward authentication:

Temporary credentials (STS)

Use temporary credentials from AWS Security Token Service:

IAM role assumption

Assume an IAM role for cross-account access or elevated permissions:

Web identity (OIDC)

Use OIDC tokens for container-based or Kubernetes deployments:

Required IAM permissions

The AWS credentials you provide must have permission to invoke your Bedrock guardrail. Create an IAM policy with the following permissions:
For production environments, scope the resource ARN to your specific guardrail:

Guardrail versioning

Bedrock guardrails support versioning, allowing you to test changes before applying them to production: Recommended workflow:
  1. Test guardrail changes using DRAFT version in a development environment
  2. Publish a new version in the AWS console when satisfied
  3. Update production AI Studio configuration to use the new version number

Bedrock guardrail capabilities

AWS Bedrock Guardrails provide several content filtering capabilities:

Content filters

Block content based on harmful categories with configurable thresholds:
  • Hate: Discriminatory or prejudiced content
  • Insults: Demeaning or offensive language
  • Sexual: Sexually explicit content
  • Violence: Violent or threatening content
  • Misconduct: Content promoting illegal activities
  • Prompt attacks: Attempts to manipulate the model

Denied topics

Define custom topics that should be blocked. Useful for:
  • Preventing discussion of competitors
  • Blocking off-topic conversations
  • Enforcing industry-specific restrictions

Sensitive information filters

Detect and block PII types including:
  • Names, addresses, phone numbers
  • Email addresses, URLs
  • Credit card numbers, bank accounts
  • Social Security numbers (US)
  • Driver’s license numbers
  • Passport numbers

Word filters

Block specific words, phrases, or patterns. Supports:
  • Exact word matching
  • Profanity filters
  • Custom blocked terms

Error handling

When Bedrock blocks content, AI Studio returns an error to the agent. The default behavior raises an exception that halts the request. Set disable_exception_on_block: true to return a modified response instead of raising an exception. This is useful for:
  • Chat interfaces where exceptions disrupt the conversation
  • Applications that need to handle blocks gracefully
  • Scenarios where you want to show a custom message to users

Troubleshooting

Common errors

Verify your guardrail

Test your guardrail directly in the AWS console before configuring it in AI Studio:
  1. Navigate to your guardrail in the AWS Bedrock console
  2. Select Test to open the testing interface
  3. Enter sample content that should trigger the guardrail
  4. Verify the guardrail blocks or allows content as expected

Next steps