Inside a glass-walled enterprise ops room, an admin stamps robot-employee badges on a wall-sized roster while unregistered robots wait in the hallway
Register first, then grant power; an unlisted agent is a shadow hire., AI-generated illustration, not a news photograph

On August 31, AWS made Agent Registry generally available: a private, governed catalog and discovery layer for agents, tools, skills, MCP servers, and custom resources. Console, CLI, and SDK are in; Bedrock AgentCore, Amazon Quick, and Kiro IDE can discover registered capabilities without a context switch.

The Machine Learning Blog states the pain plainly: teams build in isolation with no authoritative inventory, cross-team discovery, or audit trail. The bottleneck moved from running agents to finding and governing them.

[1][2]

What GA adds beyond preview

On top of manual/URL records, approval workflows, semantic and keyword search, and CloudTrail, GA brings CloudFormation / Terraform / CDK, tags for cost and access, AWS RAM cross-account sharing, and organization-wide auto-detection that pulls AgentCore Runtime and Gateway agents into a central draft queue instead of waiting for voluntary registration.

Each registry instance also exposes as an MCP server for IDEs—search for a ticket-routing tool without leaving the editor. Five regions ship first: N. Virginia, Oregon, Ireland, Tokyo, Sydney.

[1][2]

Split the governance and discovery planes

AWS separates an authoritative governance plane (including drafts, rejects, and policy metadata) from a curated discovery plane that only surfaces approved records for high-throughput search. Record types cover MCP, A2A agent cards, skills, and custom JSON. Customer quotes from Southwest, Syngenta, and Amdocs land on the same beat: from scattered tools with no shared ledger to one catalog the org trusts.

Docs add a hard clock: preview assets under the bedrock-agentcore namespace must migrate to agent-registry by September 17 or lose access—a sharper deadline than the launch blog for teams that already piled records into preview.

[2][1]

Why the urgency now

Once agents leave pilots, departments ship independently. Duplication wastes money; the real risk is not knowing who built what, which systems it touches, or how to shut it down. A registry buys visibility and lifecycle, not magic permissions—identity still needs scoped tokens such as AgentCore Identity. Cloud vendors are no longer selling only another runtime; they are selling control over digital employees already loose in the building.

[2]

Take

I read GA as the ID-badge moment for the agent economy: the runtime half is over; the catalog-and-kill-switch half begins. If enterprises treat Registry as a search box without approvals, decommissioning, and identity narrowing, the roster becomes another neglected wiki.

The September 17 namespace migration is a useful stress test—teams willing to move at least know which agents they have on payroll.

[1][2]