In June 2026, AWS raised reserved Nvidia GPU Capacity Blocks prices 20% and left Trainium prices unchanged. Bedrock offers model choice one layer above those reservations. A buyer may switch AI models freely and still leave AWS in charge of capacity, permissions, operations and billing.
Key takeaways
- Bedrock makes the cloud control plane—not any single model—the durable checkpoint for APIs, permissions, operations, procurement and billing.
- AWS’s June 2026 pricing split shows that model choice does not erase infrastructure dependence: reserved Nvidia GPU Capacity Blocks rose 20%, while Trainium pricing was unchanged.
- Replacing a model endpoint is not the same as migrating an AI workload; identity policies, evaluations, capacity reservations, deployment history, incident ownership and contracts may remain tied to the provider.
- Cloud exit is possible through self-hosted infrastructure, but it transfers capacity planning, security and operational responsibility to the enterprise.
- Buyers gain bargaining power by testing a production-like workload across the full stack and documenting which policies, records and commitments fail to move.
One API gives security and procurement a fixed checkpoint
When Bedrock became generally available in September 2023, AWS put Amazon and third-party generative-AI models behind one API. The service keeps access, permissions, operations and billing in AWS while application teams choose among hosted endpoints.
An application team can reuse its AWS integration when it tests another hosted model. The team still has to compare behavior, cost, access conditions and production fit.
Security reviews permissions, procurement approves terms and an accountable owner handles failures once model output enters a business process. Bedrock gives each group one AWS checkpoint even as the model list changes.
AWS can reprice execution without touching the catalog
EC2 Capacity Blocks let businesses reserve AI compute in advance. In its June 2026 Capacity Blocks change, AWS applied the increase to reserved Nvidia GPUs and left Trainium unchanged.
Buyers cannot infer from those two prices that AWS intended to steer them toward Trainium. They can see that AWS assigns different prices to hardware paths within the same operating environment.
Through Capacity Blocks, AWS sets which processors buyers can reserve, how far ahead they must commit and what they pay. Cloud providers also secure powered GPU capacity through long-duration commitments, as the contracted megawatt traces.
A procurement team comparing hosted models must include endpoint rates, reservation terms and processor prices. The model benchmark alone cannot price the workload.
Agents enlarge what incident teams must migrate
By Q2 2026, Google was positioning its Gemini Enterprise Agent Platform, built on Vertex AI, as a system for managing the full lifecycle of AI-agent fleets.
Google Cloud also reported $24.8 billion in Q2 2026 revenue, up 82% year over year, and a $514 billion backlog of contracted work not yet recognized as revenue. The company did not isolate the agent platform’s contribution, but the figures establish the scale of the contracted cloud environment around it.
A buyer moving an agent fleet must transfer model calls, identity policies, evaluations, deployment history and incident ownership. Security teams move permissions, ML platform teams move evaluations and operations teams reassign accountability.
Google’s lifecycle product places that work inside the platform managing the agents. A replacement endpoint addresses only one item in the migration plan.
Amazon decides which exits Bedrock supports
Amazon decides which models Bedrock hosts, deploys and supports. Its catalog can contain competitors without giving those competitors control over access terms or operations.
Reporting on the U.S. push for open AI models identified Amazon and Anthropic as notable holdouts among American technology companies. Amazon can offer third-party models in Bedrock while retaining authority over how those models enter and remain in the service.
Enterprises with sovereignty or deployment constraints can place the operating boundary in their own facilities. Chinese vendors were already selling “AI-in-a-box” systems in 2024, when Huawei estimated the Chinese market at roughly $2.3 billion.
An enterprise that chooses that route owns capacity planning, permissions and operations. The option creates an exit from the cloud catalog, but it also transfers the operating burden to the buyer.
AWS must earn back the capacity it finances
AWS must finance GPU capacity before customers reserve and consume it. Since 2022, Alphabet, Microsoft, Amazon, Meta and Oracle accumulated an estimated $1.65 trillion of off-balance-sheet debt, above their estimated $1.35 trillion of on-balance-sheet debt.
The companies must convert those commitments into recurring usage, reservations and services. A buyer can use that need during procurement only if it knows which parts of its workload can move.
Before treating a second model as an exit, the buyer should inventory the model call, identity policy, evaluation system, capacity reservation, incident process and procurement contract. Security should document permissions, the ML platform team should preserve evaluations and deployment history, and procurement should identify commitments tied to the provider.
The buyer should then test one production-like workload across all six layers and record which policies, records and contracts fail to follow. That exercise produces bargaining power a larger model catalog cannot supply on its own.
In June 2026, AWS left Bedrock’s catalog alone and raised the price of reserved Nvidia GPU capacity. A buyer can take the model name out of the building. The reserved GPU block, permission tree, incident owner and consolidated invoice determine whether the workload can follow.
Estimated debt at five U.S. tech giants
| Debt category | Estimated amount | Evidence context |
|---|---|---|
| Off-balance-sheet debt | About $1.65 trillion | Grew roughly eightfold since 2022 |
| On-balance-sheet debt | About $1.35 trillion | Less than the estimated off-balance-sheet total |
Frequently asked questions
How does Amazon Bedrock create lock-in if customers can switch models?
Bedrock lets teams access Amazon and third-party models through one API, but AWS continues to control permissions, supported endpoints, operations and billing. The model can change while the surrounding operating system remains anchored to AWS.
What did AWS’s June 2026 GPU price change reveal?
AWS raised reserved Nvidia GPU Capacity Blocks prices by 20% while leaving Trainium prices unchanged. That split showed that workloads remain exposed to hardware-specific pricing and reservation terms beneath Bedrock’s model catalog.
Is switching to another hosted model a real cloud exit?
Not by itself. A complete migration may also require moving identity policies, evaluations, capacity reservations, deployment records, incident processes and procurement contracts.
What should enterprises compare besides model benchmarks?
They should evaluate endpoint rates, processor prices, reservation terms, access conditions, production behavior and operational portability. The piece recommends testing one production-like workload across all six layers of the stack.
Can an enterprise avoid the cloud control plane entirely?
It can operate models in its own facilities, including through packaged “AI-in-a-box” systems. That creates an exit from the cloud catalog but makes the buyer responsible for capacity, permissions and operations.