The Consequence Library · How records are made and graded
AWS Cost Explorer suffered a 13-hour customer-facing outage in one region in mid-December 2025 after a production environment was deleted and recreated. Whether that action was an autonomous decision by Amazon's Kiro agentic coding tool or human error with misconfigured access controls is publicly disputed.
Evidence caveat. Causation is disputed by a named party. The outage is confirmed by both sides and independently. The agent-autonomy characterisation rests on four anonymous sources and is denied by Amazon. This record publishes both accounts and adjudicates neither.
What happened
On 20 February 2026 the Financial Times reported, citing four sources, that AWS engineers had given Kiro autonomous access to resolve a customer-facing issue and that Kiro decided the best course was to delete and recreate the environment, causing the outage. The FT further reported it was at least the second AI-involved production outage in months. Amazon publicly rebutted the account the same day, stating the incident involved "user error, specifically misconfigured access controls, not AI", and called the second-incident claim entirely false. Reuters independently confirmed the outage's scope. Amazon subsequently mandated peer review for all production access, whether human- or AI-initiated, alongside additional training and configuration limits.
Where control failed
The cause of the initiating action remains disputed. Amazon attributes the incident to human error and misconfigured access controls. Financial Times sources attributed it to autonomous action by Kiro. Both accounts involve production permissions that permitted deletion and recreation of the environment.
The authority question
The central unresolved issue is who initiated the action and what authority was attached to the credentials used. The public evidence does not resolve whether the action was human or AI initiated.
What could be proven afterward
No logs capable of resolving attribution were produced publicly, leaving two irreconcilable accounts. The provable public record consists of the outage, the policy change, and the competing narratives. Without an authoritative action log binding actor identity to action, causation disputes over agent involvement are unresolvable from outside.
Control state, before and after
Before the consequence
A role carrying production permissions broader than intended, with the two-person approval norm bypassable. No AI-specific pre-action checkpoint on destructive infrastructure operations.
After the consequence
Peer review mandated for all production access, human- or AI-initiated, plus additional training and configuration limits.
Sources
- Secondary: Financial Times, "Amazon service was taken down by AI coding bot", 20 Feb 2026 · https://www.ft.com/content/00c282de-ed14-4acd-a948-bc8d6bdb339d
- Secondary, rebuttal: GeekWire, "Amazon pushes back on Financial Times report blaming AI coding tools for AWS outages", 20 Feb 2026 · https://www.geekwire.com/2026/amazon-pushes-back-on-financial-times-report-blaming-ai-coding-tools-for-aws-outages/
Record history
Published 16 August 2026. Load-bearing facts re-verified against the cited sources on 16 August 2026. Corrections and material changes are appended here with their dates. To report an error in this record, write to hello@regulayer.com with the record slug and the source you believe is authoritative.
This record describes what sources establish about a consequence and the control state around it. It separates confirmed fact from source-stated cause and from architectural analysis, and it makes no claim that any control or product would have prevented the outcome. Gap codes identify a failure class, not a remedy.
