AWS says Amazon Quick and Amazon Bedrock Knowledge Bases can now check document permissions against their authoritative source at query time, rather than relying only on access data copied during an earlier sync. The practical gain is that revoked access can be reflected in AI answers within moments, AWS says.
AWS AI Watch analysis
What happened
AWS describes a two-stage approach. First, the system uses access-control lists stored in its index to narrow the search results. Then it checks candidate documents against the source, such as Google Drive, and removes anything the user is not authorised to access. Only verified passages are sent to the language model.
The first-stage filter avoids making live permission calls for every document in the index, which AWS says would be too costly at scale. The company’s technical account says the live check is an additional security layer for Amazon Quick and Bedrock Knowledge Bases.
Why it matters
In a retrieval-augmented generation system, an assistant can only keep a sensitive document out of its answer if the search stage respects who is allowed to see it. AWS says periodic permission synchronisation can leave a gap after someone loses access; its query-time check is designed to close that gap before retrieved material reaches the model.
That is a concrete safeguard for organisations connecting AI assistants to shared company files. It is also a design worth scrutinising: a security promise depends on the live checks working correctly across the sources and permission rules an organisation actually uses.
Our read
The useful idea here is not “AI, but secure”, a phrase that should come with a very large asterisk. It is the specific choice to ask the original data source whether access is still allowed, just before its contents enter an AI answer. Teams using these AWS services should check which data sources and permission arrangements their own deployment supports before treating that as a blanket guarantee.
What to watch
- Which connected data sources support the live permission check.
- How the system handles source outages or failed permission checks.
- Whether AWS publishes operational guidance and testing results for different permission setups.
Discussion spark: Should AI knowledge systems fail closed whenever a live permission check cannot be completed, even if that means some answers become unavailable?
Sources and evidence
- Rethinking access control for RAG with Amazon Quick and Amazon Bedrock (7 October 2026, 18:34 UTC)
not affiliated with or endorsed by Amazon Web Services (AWS)