OFICIAL AWS What's New

Amazon Transcribe adds customer-managed KMS keys for custom resources

What happened
Based on AWS What's New · Sep 25, 2026

Amazon Transcribe now supports customer-managed AWS KMS keys for encrypting custom resources, replacing the default AWS-owned encryption with user-controlled keys for enhanced security and compliance.

Amazon Transcribe adds customer-managed KMS keys for custom resources
AWS What's New — Amazon Web Services
Key points
·
Amazon Transcribe now allows customer-managed AWS KMS keys for encrypting custom resources instead of default AWS-owned keys
·
Users can supply their own symmetric KMS keys when creating or updating custom vocabularies and language models
·
Every key use is logged in AWS CloudTrail, and users can disable keys or transition resources to different keys

Amazon Transcribe has introduced the ability to encrypt custom vocabularies, vocabulary filters, and language models using customer-managed AWS KMS keys. Previously, these resources were encrypted with an AWS-owned key by default, meaning users had no control over the encryption keys. The new option allows customers to supply their own symmetric KMS keys when creating or updating these custom resources, ensuring the stored artifacts are encrypted under a key they own and manage. Users who do not provide a key will continue using the AWS-owned key without any required action.

With customer-managed keys, users gain full control over key permissions, determining which principals and services can encrypt or decrypt the custom resources. This shift provides greater flexibility in managing access and enhances security by aligning encryption practices with organizational policies. Every interaction with the key is logged in AWS CloudTrail, offering a detailed audit trail for compliance and monitoring purposes. This transparency supports regulatory requirements and internal governance standards.

The feature enables users to disable keys or transition resources to different keys on their own schedule, allowing for dynamic access management. This capability is particularly useful for organizations with evolving security policies or those undergoing audits. The ability to revoke access promptly adds an additional layer of control over sensitive data stored in custom resources. No immediate action is required unless users choose to opt in and adopt customer-managed keys.

This encryption enhancement is available across all AWS Regions where Amazon Transcribe is offered. Customers interested in implementing this feature can refer to the Amazon Transcribe Developer Guide for detailed instructions and best practices. The change reflects Amazon’s ongoing efforts to provide users with greater control over data security and compliance in cloud-based transcription services.

Original source → Deals on Clipraptor.com →