Choosing between AWS Bedrock Agents and LangGraph is a choice between a managed runtime and an open framework, and it is now partly a legacy choice. AWS renamed Bedrock Agents to Amazon Bedrock Agents Classic and closed it to new customers on 30 July 2026, so if you are evaluating it today you cannot sign up for it. AWS points new agent work at Amazon Bedrock AgentCore, a separate service generally available since 13 October 2025, which runs the orchestration loop for you and can also host LangGraph. LangGraph hands you a StateGraph API so you own loops, state, and step caps.
AWS Bedrock Agents vs LangGraph: at a glance
- Availability today: Bedrock Agents Classic is closed to new customers; AgentCore is where new AWS agent work starts. LangGraph installs from PyPI.
- Who runs orchestration: AWS runs it for you; LangGraph runs in infrastructure you operate.
- Control over the loop: Bedrock favors managed simplicity; LangGraph favors explicit, typed state.
- Primary lock-in: Bedrock ties you to AWS infrastructure; LangGraph ties you to one library’s API.
- Portability today: AgentCore hosts LangGraph, and AWS documents replatforming a self-hosted LangGraph agent onto it.
- What neither solves: whether the agent knows what your business means.
| Dimension | AWS Bedrock Agents | LangGraph |
|---|---|---|
| What it is | Managed agent service, now Bedrock Agents Classic in maintenance mode | Open-source orchestration framework |
| Open to new customers | No, closed since 30 July 2026; AgentCore is the current service | Yes |
| Who runs the orchestration | AWS runs the agent loop | You run it in your own infrastructure |
| Control over the agent loop | Limited internal-loop control, managed defaults | Full control of loops, state, and step caps |
| Memory and observability | Managed AgentCore memory and observability | You wire your own checkpointer and tooling |
| Primary lock-in | AWS-infrastructure lock-in | Framework lock-in to the StateGraph API |
| Cost model | Consumption-based vCPU-hour, GB-hour and per-invocation billing | Infrastructure you provision and control |
| Best for | AWS-committed teams wanting minimal ops | Teams needing explicit state and custom control |
The decision both frameworks leave unanswered: your context layer
Before comparing AWS Bedrock Agents and LangGraph feature by feature, it helps to name the one axis neither framework resolves: whether the agent actually knows what your business means. Both are execution substrates. Both run the loop that calls a model, invokes a tool, and returns a result. Neither encodes the definitions, lineage, policy, and ownership that make an answer correct for your organization.
That missing tier is the context layer for enterprise AI: a governed, model-agnostic layer that sits above whichever framework you pick. The comparison below is real and matters for engineering ergonomics, operations, lock-in, cost, and security, so read it fairly. Then return to this thread at the end, because the framework decision and the context decision are not the same decision.
What are AWS Bedrock Agents?
AWS Bedrock Agents is Amazon’s managed agent service, where AWS runs the reasoning-and-action loop on your behalf. You define the agent, attach action groups and knowledge sources, and AWS handles the orchestration runtime, identity through IAM, and managed memory. The trade is operational simplicity for less direct control of the internal loop.
Read the rest of this page knowing what AWS did to that service. AWS renamed it Amazon Bedrock Agents Classic and put it into maintenance mode: closed to new customers from 30 July 2026, with no new features and a frozen model catalogue. AWS has published no end-of-life date, and the API namespace, SDK clients, CloudFormation types and IAM prefixes are unchanged, so existing agents keep running. What changed is that you can no longer start here.
Amazon Bedrock AgentCore is the separate service AWS points new agent work toward, generally available since 13 October 2025. Its documentation describes it as working with any open-source framework and names CrewAI, LangGraph, LlamaIndex, Strands Agents, Google ADK and the OpenAI Agents SDK, alongside CrewAI-style multi-agent patterns. Thirteen components sit under it, including Harness, the config-based managed agent loop AWS recommends as the migration target from Bedrock Agents Classic.
Core components of AWS Bedrock Agents and AgentCore
- Managed orchestration runtime: AWS runs the reasoning-and-action loop for you.
- Action groups: the Classic agent’s callable tools and APIs (20 per agent, adjustable, per AWS quota docs).
- AgentCore Harness: a config-based managed agent loop, and AWS’s recommended route off Bedrock Agents Classic.
- Managed memory and observability: operational and conversational state handled by AgentCore.
- IAM-based access and metering: identity, permissions, and usage tracking through AWS.
- AgentCore Runtime: a framework-agnostic host that can run other frameworks too.
What is LangGraph?
LangGraph is an open-source orchestration framework where you write the agent’s control flow yourself against a StateGraph API and own loops, state, and step caps. Instead of a provider running the loop, you model the agent as a graph of nodes and edges, with explicit, typed state passing between steps. The trade is more code and operational responsibility for far more control.
What you get in return is written down. The LangGraph documentation describes the graph as durable execution with human-in-the-loop checkpoints and comprehensive memory, built on a state object you define and a set of nodes that read and write it. LangGraph is the layer where the loop is yours to bound: a recursion limit stops a planner from cycling forever, and a checkpointer decides what survives a restart.
That control is a commitment, not a free upgrade. You own the runtime, the persistence backend, the observability wiring, and the patch cadence on an open-source dependency tree. Teams that want none of that are the ones AgentCore is built for. Teams that need the loop to behave a specific way, every time, pick LangGraph knowing what comes with it.
Core components of LangGraph
- StateGraph API: the programming model for defining nodes, edges, and control flow.
- Explicit state management: typed state that passes between steps deterministically.
- Step and loop control: direct caps on iterations to prevent runaway loops.
- Checkpointers: persistence for graph state, including a SQLite checkpoint option.
- Broad ecosystem: interoperability with the wider LangChain ecosystem.
The AI Context Stack, explained
Frameworks orchestrate the agent loop, but the stack has a tier above them. See where governed context fits relative to models, frameworks, and tools.
Get the AI Context Stack briefAWS Bedrock Agents vs LangGraph: how do they compare head-to-head?
AWS Bedrock Agents and LangGraph diverge most on who operates the runtime and how much control you have over the loop, and they converge on the fact that both are substitutable execution substrates. Bedrock optimizes for managed simplicity inside AWS; LangGraph optimizes for explicit control in infrastructure you run. The detailed view below maps nine decision axes so you can weigh genuine strengths on both sides.
| Dimension | AWS Bedrock Agents | LangGraph |
|---|---|---|
| Orchestration model | AWS-managed loop, you configure inputs | You own the StateGraph and write the loop |
| Control over the agent loop | Limited internal-loop control, fewer failure modes to manage | Full control, plus step caps to stop runaway loops |
| Memory | Managed AgentCore memory for operational state | You wire your own checkpointer, including SQLite |
| Observability | Managed AgentCore observability | LangSmith or your own tooling |
| Primary lock-in | AWS-infrastructure lock-in (IAM, metering) | Framework lock-in to one library’s API |
| Cost and TCO model | Consumption-based: $0.0895 per vCPU-hour and $0.00945 per GB-hour on Runtime microVMs, model tokens billed separately | Infrastructure you provision and can tune |
| Throttling and quotas | Published and mostly adjustable: 1,000 TPS on Runtime data-plane APIs, 25 TPS on new sessions, 20 action groups per Classic agent | Self-imposed limits you set in code |
| Security and CVE maturity | AWS-managed patching of the runtime | Open-source supply-chain CVEs you track and patch |
| Availability for new projects | Classic closed 30 July 2026; start on AgentCore | Open, installable today |
Consider a team building a multi-agent revenue-analysis workflow. With Bedrock Agents, AWS’s managed runtime removes the burden of operating the loop, scaling the runtime, and wiring memory, so a small team ships faster. With LangGraph, an explicit max_steps cap and typed state in the StateGraph prevent a planner agent from looping indefinitely when a downstream tool returns ambiguous results. Each framework is indispensable in its lane: Bedrock for managed operations, LangGraph for deterministic control. One axis the table cannot rank, though, is portability of business context, because neither framework, on its own, tells the agent what “revenue” means in your business.
Framework lock-in vs AWS-infrastructure lock-in: which are you choosing?
The structural distinction most comparison pages miss is that AWS Bedrock Agents and LangGraph lock you in differently, and the type of lock-in is a primary decision axis. LangGraph creates framework lock-in: your orchestration logic is written against one library’s StateGraph API, so moving off it means rewriting the control flow. Bedrock Agents and AgentCore create AWS-infrastructure lock-in: IAM, metering, managed memory, and observability are tied to AWS, so moving off it means re-platforming the runtime.
The 2026 picture is less symmetrical than that, and worth stating precisely. AgentCore is documented as framework-agnostic, and AWS has published a walkthrough of moving a self-hosted LangGraph agent onto AgentCore, replatforming it onto Runtime, Gateway and Memory with the graph left intact. That path runs one direction. Going the other way, off Bedrock Agents Classic, AWS’s maintenance-mode documentation offers the AgentCore harness or a code-defined agent, and names Strands, LangChain, the OpenAI Agents SDK and the Claude Agent SDK as framework examples. LangGraph is not on that list, and AWS publishes no tool that converts a Bedrock Agent into a LangGraph graph.
So the real question is not framework lock-in or infrastructure lock-in in isolation. It is portability across either, and what stays portable when you switch. Your orchestration code is framework-specific. Your runtime is provider-specific. The business context your agents depend on, the definitions and policy and lineage, should not be tied to either, which is precisely why teams designing an AI agent stack want it in a portable layer above the framework.
What does AgentCore actually cost, and what are the throttling limits?
AgentCore bills infrastructure by consumption, not by agent step. AWS publishes the rates: $0.0895 per vCPU-hour and $0.00945 per GB-hour for Runtime on microVMs, or EC2 cost plus a 12% management fee on Instances; $0.005 per 1,000 Gateway API invocations; $0.25 per 1,000 new memory events. Model inference tokens are billed separately on top, and AWS states there is no separate orchestration charge for the harness. LangGraph cost is driven by infrastructure you provision and control, which is a different shape of the same question: you pay for what you run either way, and the difference is who sizes it.
AWS publishes the quota numbers too. Bedrock Agents Classic allows 20 action groups per agent, adjustable through Service Quotas. AgentCore has its own table: 1,000 TPS across Runtime data-plane APIs, 25 TPS for new session creation, 5,000 active session workloads per account in N. Virginia and Oregon and 2,500 elsewhere, 100 targets per gateway and 1,000 tools per target, and a hard ceiling of six memory strategies per Memory resource that is not adjustable. Most of the rest are adjustable on request, which is the practical difference from limits you write yourself.
The session hardware ceiling is the one to check before you architect: 2 vCPU and 8 GB per session, with 1 GB of session storage, and neither is adjustable. Sessions on microVMs run up to eight hours; on Instances they persist up to fourteen days. With LangGraph, you control loops and step caps directly, so the limits are the ones you wrote, and the bill is the infrastructure you chose to run them on.
How mature is your context for agents?
Before you commit to a framework, score where your business context stands today and what it takes to make agents accurate in production.
Take the Context Maturity AssessmentHow secure are these frameworks? The LangChain and LangGraph CVE cluster
Security maturity is a fair comparison axis as long as it is framed factually: managed services like Bedrock and AgentCore shift runtime patching to AWS, while open frameworks put supply-chain CVE tracking on your team. Both have real, defensible security postures. The difference is who owns the patch cadence, not whether one framework is inherently unsafe. The open-source LangChain and LangGraph ecosystem has had a documented CVE cluster, and all of the issues below are patched.
According to GitHub Security Advisory GHSA-qh6h-p6c9-ff54, CVE-2026-34070 is a LangChain path traversal flaw (CWE-22) rated CVSS 7.5 High, affecting langchain-core before 1.2.22 and patched in 1.2.22. It was published on 26 March 2026 and sits in the legacy load_prompt functions, which the advisory calls undocumented legacy APIs and has since formally deprecated. It is the kind of file-access issue that managed runtimes patch centrally and self-hosted deployments must patch themselves.
According to GitHub Security Advisory GHSA-9rwj-6rc7-p77c, CVE-2025-67644 is a LangGraph SQLite checkpoint SQL injection flaw (CWE-89) rated CVSS 7.3 High, patched in langgraph-checkpoint-sqlite 3.0.1 and published on 9 December 2025. Metadata filter keys were interpolated into SQL. It affects the SQLite checkpointer specifically, so teams using that persistence option should confirm the patched version. The advisory adds one detail worth carrying: LangSmith deployment customers are not impacted.
The most severe item carries a score discrepancy worth reporting in full. CVE-2025-68664 is a LangChain Core serialization injection that can leak secrets: the National Vulnerability Database rates it 8.2 High and notes explicitly that its score differs from the CNA’s, while GitHub Security Advisory GHSA-c67j-w6g6-q2cm rates the same issue 9.3 Critical. It was published on 23 December 2025 and is patched in langchain-core 0.3.81 and 1.2.5. Report both scores, because they are both authoritative and they diverge.
One caveat on scope. These three are a subset. As of September 2026 the langchain-ai/langchain and langchain-ai/langgraph repositories carry at least nine published advisories each, and four LangGraph advisories post-date the three above. Read the advisory feeds, not a snapshot.
When should you choose Bedrock Agents vs LangGraph?
The decision comes down to team profile, control needs, and portability requirements rather than a single “better” framework. If you are committed to AWS and want minimal operations, lean Bedrock Agents. If you need explicit state and custom multi-agent control, lean LangGraph. The table below maps common situations to a default, with the reasoning.
| Your situation | Lean Bedrock Agents | Lean LangGraph | Why |
|---|---|---|---|
| All-in on AWS, want minimal ops | Yes | Managed runtime removes operational burden | |
| Need explicit state and runaway-loop caps | Yes | StateGraph gives direct control of loops | |
| Need cross-cloud portability | Yes | Or run LangGraph on AgentCore to keep control | |
| Want managed memory and observability out of the box | Yes | AgentCore provides operational state and tooling | |
| Small team prototyping fast | Start simple | Add a framework once the orchestration problem is clear |
There is one honest caveat that bridges to the larger point. Framework choice genuinely matters for engineering ergonomics, operations, lock-in, cost, and security. It does not determine whether the agent knows what your business means. That second question, the one that decides whether the agent is right or merely fluent, lives in a different tier of the stack.
How Atlan approaches the agent stack above Bedrock and LangGraph
The tier above either framework is the Context Layer for AI: a governed, model-agnostic layer that delivers business meaning to any agent, regardless of orchestration framework. This is the only section where Atlan appears, because the comparison above stands on its own. The point here is what neither Bedrock nor LangGraph is designed to do, and where production reliability actually comes from.
Both frameworks orchestrate, but neither encodes what your business means. Joe DosSantos, VP of Enterprise Data and Analytics at Workday, described exactly this gap: “We built a revenue analysis agent and it couldn’t answer one question. We started to realize we were missing this translation layer.” The framework was not the bottleneck. The missing piece was the governed context that tells an agent what “revenue” is, how it is calculated, which sources are authoritative, and who is allowed to see it.
Atlan delivers that as the Context Layer for AI, a governed tier above either framework. Through the Atlan MCP Server, context flows to any agent regardless of orchestration framework, with ownership, lineage, quality scores, and policy applied at query time. The Context Engineering Studio is where that business understanding is built, tested, and shipped. The Context Lakehouse stores it in an Iceberg-native, open, portable format, which is the antidote to both framework lock-in and infrastructure lock-in. This is distinct from AgentCore memory, which holds operational and conversational state; governed business context is definitions, lineage, policy, and ownership.
The outcome is measurable, and it isolates the variable: context, not framework, moves accuracy. At Workday, Atlan reports a 5x improvement in AI response accuracy through MCP-delivered context. Sridher Arumugham, Chief Data and Analytics Officer at DigiKey, put the shift plainly: “Atlan is much more than a catalog of catalogs. It’s more of a context operating system.”
Real stories from real customers: context above the framework
"We're excited to build the future of AI governance with Atlan. All of the work that we did to get to a shared language at Workday can be leveraged by AI via Atlan's MCP server…as part of Atlan's AI Labs, we're co-building the semantic layer that AI needs with new constructs, like context products."
Joe DosSantos, VP of Enterprise Data & Analytics, Workday
"Atlan is much more than a catalog of catalogs. It's more of a context operating system…Atlan enabled us to easily activate metadata for everything from discovery in the marketplace to AI governance to data quality to an MCP server delivering context to AI models."
Sridher Arumugham, Chief Data & Analytics Officer, DigiKey
See governed context delivered to any agent
Watch how a context layer feeds definitions, lineage, and policy to agents on any framework, in a live walkthrough.
Watch the live context demosWhy the framework choice is real but not the reliability decision
The AWS Bedrock Agents vs LangGraph choice is genuine for engineering ergonomics, operations, lock-in, cost, and security, and the honest 2026 answer starts with availability. Bedrock Agents is Bedrock Agents Classic, closed to new customers since 30 July 2026, so for a new project the comparison is really AgentCore against LangGraph. AgentCore can host LangGraph, which makes the runtime decision reversible in one direction. Pick the one that matches your team’s appetite for control and operations.
The decision that actually determines production reliability sits above either framework. It is the governed context layer for enterprise AI, model-agnostic and portable, which is where the accuracy difference comes from. As models and frameworks commoditize, context compounds: performance is a function of intelligence and context, and context is the part you own. Choose your framework on its merits, then invest in the layer that makes whatever you chose actually work.
FAQs about AWS Bedrock Agents vs LangGraph
1. What is the difference between managed agents and open frameworks?
Managed agents like AWS Bedrock Agents run the orchestration loop for you inside the cloud provider’s runtime, trading control for lower operational burden. Open frameworks like LangGraph give you the orchestration code so you own loops, state, and step caps, trading convenience for control. The choice is mostly about how much of the runtime you want to operate yourself.
2. What migration path does AWS document for Bedrock Agents Classic?
The maintenance-mode documentation offers two routes: the AgentCore harness, a config-based managed agent loop that AWS recommends, or a code-defined agent you write yourself. AWS names Strands, LangChain, the OpenAI Agents SDK and the Claude Agent SDK as framework examples for the second route. AWS publishes no tool that converts a Bedrock Agent into a LangGraph graph.
3. Can I run LangGraph on AgentCore?
Yes. Amazon Bedrock AgentCore is documented as framework-agnostic, and AWS names CrewAI, LangGraph, LlamaIndex, Strands Agents, Google ADK and the OpenAI Agents SDK. AWS has published a walkthrough of replatforming a self-hosted LangGraph agent onto AgentCore Runtime, Gateway and Memory with the graph left intact.
4. Is Bedrock Agents the same as AgentCore?
No. They are two services. AWS renamed Bedrock Agents to Amazon Bedrock Agents Classic and put it in maintenance mode: closed to new customers from 30 July 2026, no new features, and a frozen model catalogue, though AWS has published no end-of-life date and the API namespace, SDK clients and IAM prefixes are unchanged. AgentCore is the separate service AWS points new agent work toward.
5. Is LangGraph production-ready in 2026?
LangGraph is used in production and is often called the current leader for explicit state across steps and agents. It also has a documented CVE cluster that was patched, which means production teams own the supply-chain patch cadence. Track the relevant package versions and apply updates promptly.
6. Should you start with a framework or with direct model APIs?
Start with the model API when the workflow is a single call and a response. Reach for LangGraph once you need an explicit loop, typed state passed between steps, and a cap that stops a runaway planner. A framework earns its keep when the orchestration problem is clear enough to describe as a graph.
7. Do I still need a context layer if I use Bedrock or LangGraph?
Yes. Bedrock Agents and LangGraph orchestrate the agent loop, but neither encodes what your business means: definitions, lineage, policy, and ownership. A governed context layer above either framework delivers that business context to any agent, which is where production accuracy and reliability come from.
Sources
- AWS: “Amazon Bedrock Agents Classic maintenance mode,” AWS documentation. https://docs.aws.amazon.com/bedrock/latest/userguide/agents-classic-maintenance-mode.html
- AWS: “What is Amazon Bedrock AgentCore,” AWS documentation. https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/what-is-bedrock-agentcore.html
- AWS: “Amazon Bedrock AgentCore is now generally available” (2025). https://aws.amazon.com/about-aws/whats-new/2025/10/amazon-bedrock-agentcore-available/
- AWS: “Migrate agentic workloads to Amazon Bedrock AgentCore” (2026). https://aws.amazon.com/blogs/machine-learning/migrate-agentic-workloads-to-amazon-bedrock-agentcore/
- AWS: “Build multi-agent systems with LangGraph and Amazon Bedrock” (2026). https://aws.amazon.com/blogs/machine-learning/build-multi-agent-systems-with-langgraph-and-amazon-bedrock/
- AWS: “Amazon Bedrock AgentCore quotas and limits,” AWS documentation. https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html
- AWS: “Amazon Bedrock AgentCore pricing.” https://aws.amazon.com/bedrock/agentcore/pricing/
- AWS: “Amazon Bedrock endpoints and quotas,” AWS General Reference. https://docs.aws.amazon.com/general/latest/gr/bedrock.html
- LangChain: “LangGraph overview,” LangChain documentation. https://docs.langchain.com/oss/python/langgraph/overview
- GitHub Security Advisory: “GHSA-qh6h-p6c9-ff54 (CVE-2026-34070)” (2026). https://github.com/langchain-ai/langchain/security/advisories/GHSA-qh6h-p6c9-ff54
- GitHub Security Advisory: “GHSA-9rwj-6rc7-p77c (CVE-2025-67644)” (2025). https://github.com/langchain-ai/langgraph/security/advisories/GHSA-9rwj-6rc7-p77c
- GitHub Security Advisory: “GHSA-c67j-w6g6-q2cm (CVE-2025-68664)” (2025). https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm
- National Vulnerability Database: “CVE-2025-68664” (2025). https://nvd.nist.gov/vuln/detail/CVE-2025-68664
- GitHub: “langchain-ai/langgraph security advisories.” https://github.com/langchain-ai/langgraph/security/advisories