OFICIAL AWS What's New

Amazon Quick adds deny by default for custom permissions

What happened
Based on AWS What's New · Aug 19, 2026

AWS Quick introduces deny-by-default for custom AI permissions, automatically restricting new capabilities unless explicitly allowed by administrators.

Amazon Quick adds deny by default for custom permissions
AWS What's New — Amazon Web Services
Key points
·
Amazon Quick custom permissions now include deny by default, a governance setting that automatically restricts new AI capabilities before they reach users.
·
\n \nPreviously, new AI capabilities the company is available to all users on release, requiring administrators to react after the fact.
·
With deny by default, administrators restrict the AI capability category in a custom permissions profile and assign it to users, roles, or the entire account.
·
Quick then denies any new AI capability at launch for those users.

Amazon Quick has added a deny-by-default governance setting for custom permissions, which automatically blocks new AI capabilities for users unless administrators explicitly allow them. Previously, new capabilities were enabled by default upon release, requiring manual intervention to restrict access. This change shifts control to administrators, who can now preemptively restrict entire categories of AI features before they become available to users. The restriction applies only to the configured profile and does not affect other profiles or regions.

Administrators can enable deny-by-default through the Amazon Quick interface in the Manage account section or via the AWS CLI. Once activated, any new AI capability within a restricted category is denied at launch for the assigned users, roles, or accounts. Existing capabilities in the restricted category are also blocked, requiring explicit approval before use. This approach ensures tighter control over AI feature adoption and reduces the risk of unintended access.

The deny-by-default setting is now available in all AWS Regions where Amazon Quick is supported. Administrators can configure it at the profile level, allowing granular control over which users or roles have access to specific AI capabilities. This feature is designed to help organizations enforce governance policies and limit exposure to new features until they are vetted for compliance or security requirements.

To implement deny-by-default, administrators must first identify the AI capability categories they wish to restrict. They then assign the restriction to a custom permissions profile and apply it to users, roles, or the entire account. New capabilities in the restricted category are denied by default, and administrators must explicitly allow each one before users can access them. This provides a proactive approach to managing AI feature rollouts within AWS environments.

Original source → Deals on Clipraptor.com →