AWS has open-sourced Dogwood, a new policy language released under Apache 2.0 that extends the Cedar authorization model to control sequences of AI agent tool calls rather than evaluating each request in isolation. Dogwood adds temporal, history-aware rules that can inspect prior tool-call events and outcomes, enabling controls such as approval requirements before sensitive actions, spending caps across multiple steps, and restrictions triggered after access to sensitive data. AWS said Dogwood works with AgentCore Policy and remains backward-compatible with Cedar.
AWS also cautioned that Dogwood’s temporal model introduces operational and security complexity, including statefulness, concurrency risks, and the loss of Cedar’s automated formal reasoning properties. The company said its reference interpreter is not intended for production authorization use and warned that trustworthy deployments require authenticated event records, trusted timestamps, durable trace storage, logging, tenant isolation, and retention controls to ensure policy decisions over agent activity can be relied upon.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
The MCP 2026-07-28 specification required method and tool-name headers so agent traffic would be visible to HTTP infrastructure. AWS linked Dogwood's release to this specification update.
AWS contributed the Cedar policy language to the CNCF as a sandbox project in late 2025, marking an earlier step in the evolution of its policy tooling.
AWS AgentCore Policy launched at AWS re:Invent in the prior year, providing the policy framework that AWS says supports Dogwood today.
AWS open-sourced Dogwood, a new policy language for governing AI agent tool calls with history-aware temporal rules, and released it under the Apache 2.0 license. AWS said Dogwood is backward-compatible with Cedar and works with AgentCore Policy.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.