AI coding tools are becoming useful enough to work directly with source code, terminals, tests, infrastructure files, and development workflows. For organizations building software in regulated environments, however, the question is not only whether an AI coding agent can write code.
The bigger question is where that agent runs, which models it can access, what controls surround the workload, and whether the environment satisfies the organization's compliance requirements.
AWS has now made it possible to run Anthropic's Claude Code with Claude models through Amazon Bedrock in AWS GovCloud (US). AWS specifically describes the setup for organizations with regulatory and compliance requirements, including workloads subject to International Traffic in Arms Regulations (ITAR). Claude Opus 5.5 and Claude Sonnet 5.5 are available for this workflow in AWS GovCloud.
That changes the conversation around AI-assisted software development for government, defense, and other regulated workloads. Developers can use an agentic coding workflow while keeping the development environment inside an AWS-controlled environment designed for higher compliance requirements.
What Claude Code Actually Does
Claude Code is not simply a chatbot that answers programming questions.
It operates as an agentic coding tool that can inspect a codebase, modify files, execute commands, run tests, search Git history, resolve merge conflicts, and work with external development tools.
For example, a developer might give it a task such as:
Investigate the failing authentication tests.
Find the root cause.
Fix the implementation.
Run the relevant test suite.
Show me the files that changed and explain why.The agent can then work through several steps rather than returning a single block of suggested code.
AWS also documents Claude Code working with tools such as the AWS CLI, Terraform, Kubernetes, and Model Context Protocol (MCP) integrations. It can also use project instructions, skills, hooks, and sub-agents to structure larger development workflows.
That distinction matters in regulated environments because the AI system may interact with much more than the source code itself.
It may read configuration files, inspect infrastructure, execute tests, access development tools, and potentially interact with cloud resources.
The environment in which all of that happens therefore becomes part of the security architecture.
Why AWS GovCloud Matters
AWS GovCloud (US) is designed for organizations with specific regulatory, compliance, and data-handling requirements.
Running Claude Code through a standard commercial cloud region may not satisfy every organization's requirements. GovCloud provides a separate AWS environment with additional compliance and authorization pathways for eligible workloads.
AWS currently lists Claude Opus 5.5 and Claude Sonnet 5.5 among the Anthropic models with FedRAMP Class D availability in GovCloud. The same AWS compliance page also lists model availability for DoD Cloud Service Provider SRG Impact Levels 4 and 5. Organizations still need to verify the exact model, service, workload, and authorization requirements applicable to their environment rather than assuming that model availability automatically makes an application compliant.
This distinction is important.
Compliance is not something an AI model automatically provides.
The surrounding infrastructure, identity configuration, logging, data flows, access policies, application architecture, and organizational controls all matter.
Claude Code Through Amazon Bedrock
The basic architecture looks like this:
Developer
|
v
Claude Code
|
v
Amazon Bedrock
|
v
Claude Model
|
v
AWS GovCloud (US)The developer still interacts with Claude Code through a terminal or supported development environment.
The important difference is where the model inference takes place and how the workload is integrated into the organization's AWS environment.
AWS documents two relevant Bedrock endpoint surfaces in GovCloud:
bedrock-runtime
bedrock-mantleThe bedrock-runtime surface uses AWS SDK APIs and supports capabilities such as Guardrails, Knowledge Bases, Agents, and invocation logging. AWS recommends this surface for most new applications where these controls and audit capabilities are important.
The bedrock-mantle surface provides native Anthropic Messages API access and exposes capabilities available through that interface, including server-side tools, background inference, and Projects. AWS currently documents Mantle availability in the US-West GovCloud region.
For a regulated development environment, that distinction is worth understanding before deployment.
Setting Up Claude Code
AWS provides several ways to configure Claude Code with Amazon Bedrock in GovCloud.
One option is the interactive setup flow.
After configuring AWS credentials and opening a project, a developer can start Claude Code and use its login flow to select Amazon Bedrock as the provider.
For a scripted environment, AWS also documents environment-variable configuration.
A simplified configuration looks like this:
export CLAUDE_CODE_USE_BEDROCK=1
export AWS_REGION='us-gov-west-1'
export ANTHROPIC_MODEL='us-gov.anthropic.claude-sonnet-5-5'For a workflow using Claude Opus 5.5, the model can be changed accordingly:
export ANTHROPIC_MODEL='us-gov.anthropic.claude-opus-5-5'Teams that want predictable deployments can also pin the default Opus and Sonnet model identifiers rather than allowing model selection to vary between environments.
The exact model identifiers and availability should always be verified against the current AWS documentation before production deployment.
IAM Still Controls Access
Putting Claude Code inside GovCloud does not eliminate the need for careful IAM design.
AWS documents permissions for the Bedrock runtime workflow including permissions such as:
bedrock:InvokeModel
bedrock:InvokeModelWithResponseStream
bedrock:ListInferenceProfiles
bedrock:GetInferenceProfileThe required permissions depend on the endpoint and configuration being used.
This is an important engineering consideration.
A common mistake with AI development environments is to give the coding agent broad cloud permissions simply because it needs to perform development tasks.
That can create unnecessary blast radius.
A better approach is to define what the agent actually needs.
For example, a development agent may need permission to:
Read source repositories
Run tests
Read selected AWS resources
Invoke approved models
Read infrastructure definitionsIt may not need permission to:
Delete production resources
Modify IAM policies
Change organization-wide networking
Access unrelated customer data
Create arbitrary credentialsThe principle is the same as with any other automated workload: give the identity enough permission to perform its job, but avoid treating the agent as an unrestricted administrator.
Data Protection Is Still an Architecture Problem
One of the more important details in AWS's guidance is that Amazon Bedrock provides data-protection controls, but developers still need to understand the actual data path.
AWS states that Bedrock is designed so customer content is not stored, logged, or used to train AWS models or shared with third parties.
That does not mean developers should send every piece of sensitive information to the agent without thinking about it.
Consider a repository containing:
Application source code
Infrastructure definitions
Internal API specifications
Configuration files
Test data
Security policies
Credentials
Customer informationThe coding agent may need access to some of these resources.
It probably should not have access to all of them.
Good agent design therefore starts with repository hygiene and access boundaries, not with the model configuration alone.
Secrets should remain in appropriate secret-management systems. Production credentials should not be committed into source control. Sensitive datasets should not be unnecessarily copied into development environments simply because an AI agent can process them.
Invocation Logging and Auditability
Auditability is another reason the Bedrock integration matters.
AWS documents invocation logging for the bedrock-runtime path, making it more appropriate when organizations need visibility into model interactions.
For regulated environments, the ability to understand who accessed the service, which identity was used, and what actions occurred can be just as important as model quality.
A mature setup might therefore look like:
Developer
|
v
Corporate Identity
|
v
IAM Role
|
v
Claude Code
|
v
Amazon Bedrock
|
+---- CloudTrail / Audit
|
+---- CloudWatch / Monitoring
|
+---- Guardrails
|
v
Claude ModelThis turns AI-assisted development into something closer to an enterprise-managed service rather than an unmanaged developer utility.
MCP Makes the Agent More Capable
Claude Code can also connect to external tools through the Model Context Protocol.
For example:
Claude Code
|
+---- AWS CLI
|
+---- Terraform
|
+---- Kubernetes
|
+---- MCP serversThat can make the agent considerably more useful.
A developer could ask an agent to investigate an infrastructure issue, inspect the relevant configuration, run validation commands, and then propose a fix.
But MCP also expands the security boundary.
Every additional tool gives the agent another capability.
If an MCP server can modify infrastructure, then the agent potentially has that ability too.
The right question is therefore not:
Can Claude Code connect to this tool?It is:
Should this agent be allowed to use this tool in this environment?That is a much better security question.
A Practical Development Workflow
A regulated team could structure its AI-assisted development workflow like this:
1. Developer Creates a Task
Investigate the failing API authorization tests.2. Claude Code Inspects the Repository
The agent reviews the relevant source files, tests, configuration, and project instructions.
3. The Agent Proposes a Change
Instead of immediately modifying unrelated files, the developer reviews the proposed approach.
4. Claude Code Implements the Fix
The agent changes the required files.
5. Tests Run Automatically
Unit tests
Integration tests
Static analysis
Security checks6. Developer Reviews the Diff
The developer remains responsible for accepting the change.
7. CI/CD Performs the Final Validation
The production pipeline applies the organization's normal approval and security controls.
This is a healthier model than allowing an AI agent to move directly from a natural-language request to production deployment.
Common Mistakes
Assuming GovCloud Automatically Means Compliant
GovCloud provides infrastructure and authorization pathways, but compliance depends on the complete system and applicable requirements.
Always verify the exact service, model, region, data classification, and authorization boundary.
Giving the Agent Administrator Access
A coding agent does not automatically need unrestricted AWS permissions.
Use IAM roles and narrowly scoped policies.
Sending Secrets Into the Agent
Do not expose credentials simply because the agent needs to understand an application.
Use proper secret-management mechanisms and minimize sensitive data exposure.
Ignoring MCP Permissions
MCP integrations can make Claude Code much more useful, but they can also increase its effective privileges.
Review each connected tool as part of the security boundary.
Treating AI-Generated Changes as Trusted Code
The model can make incorrect assumptions.
Code review, automated testing, security scanning, and normal engineering approvals should remain in place.
Advantages and Disadvantages
Advantages
AI-assisted development can operate closer to regulated infrastructure. Teams that previously had restrictions around where AI development workloads could run now have a documented path for using Claude Code with Amazon Bedrock in AWS GovCloud.
AWS security controls remain part of the architecture. IAM, CloudTrail, CloudWatch, Guardrails, and other AWS capabilities can be incorporated into the workflow rather than building an entirely separate AI security layer.
Developers get an agent instead of a simple coding assistant. Claude Code can inspect repositories, modify multiple files, run commands, execute tests, and interact with development tools.
Model access can be managed through AWS. The organization can keep model usage within its existing cloud governance and identity framework.
Disadvantages
The setup is more complicated than using a consumer coding assistant. IAM, model access, regions, endpoint selection, logging, and compliance requirements all need to be configured correctly.
Not every workload automatically qualifies for every authorization. Teams still need to verify the applicable compliance requirements and model status.
More agent capabilities mean a larger security boundary. MCP, shell access, cloud tooling, and infrastructure integrations increase what the agent can potentially do.
Human review remains necessary. A compliant environment does not make AI-generated code automatically correct or secure.
Who Should Consider This?
Claude Code on Amazon Bedrock in AWS GovCloud is particularly relevant to organizations that already operate regulated development environments in AWS.
Examples include:
Government software teams
Defense contractors
ITAR-related development
Regulated enterprise applications
Organizations with strict data-residency requirements
Teams that need centralized AWS identity and audit controlsIt is less compelling for a small application that has no meaningful regulatory, security, or data-residency requirements.
In that situation, the additional infrastructure and governance may provide little practical benefit.
Summary
Claude Code running through Amazon Bedrock in AWS GovCloud gives regulated organizations another way to adopt agentic software development without treating AI coding as an isolated developer-side service.
The important part is not simply that Claude Code is available in GovCloud.
The more meaningful change is the combination of an agentic coding workflow with AWS identity, security, auditing, regional infrastructure, and compliance-oriented controls.
That creates a path for developers to use AI for tasks such as debugging, implementation, testing, repository analysis, infrastructure work, and code maintenance while keeping the workflow inside an environment designed for regulated workloads.
The technology still needs careful engineering.
IAM permissions must be restricted. Sensitive information must be controlled. MCP integrations need review. Generated code needs testing and human approval. Compliance must be evaluated for the complete workload rather than assumed from the cloud region alone.
For organizations that already operate in AWS GovCloud, however, Claude Code on Amazon Bedrock makes AI-assisted development considerably easier to consider as part of a governed engineering workflow.
Join the conversation! Your thoughts help the community grow.