Skip to content
Cloud Security DeskSearch
Menu

Technical guideAI systems

Treat a cloud model retirement as a security change

Bedrock and Agent Platform fail closed on a model's retirement date, while Foundry can swap a different model in behind the same deployment name. Read the three calendars, compare the replacement's controls and decide per deployment.

Published
Sources checked
Next review
Reading time
16 minutes
Coverage
Amazon Web Services · Microsoft Azure · Google Cloud
A row of upright blocks stands on a long spruce bar. The fourth position is an empty dashed outline with a small panel of three amber slider knobs still wired to it, while a taller blue block with a rounded top slides in from the right with nothing attached.
Conceptual illustration: the controls were set for the model that is leaving, and the replacement arrives without them.

A decision framework for platform and AI engineers who run models on Amazon Bedrock, Microsoft Foundry and Gemini Enterprise Agent Platform, based on official lifecycle policies, retirement tables and security control matrices reviewed October 9, 2026. It compares retirement-day behavior and notice floors, counts published retirement rows, lists the controls a replacement can change and ends with an inventory fragment and a pin, upgrade or migrate rule.

At a glance

Key findings

  • On Amazon Bedrock and Gemini Enterprise Agent Platform a retired model ID stops answering and nothing migrates automatically, while a Microsoft Foundry Standard-family deployment with no upgrade option set is upgraded at retirement, sometimes to a different model family. [1][6][8][11]
  • Documented notice floors fall well short of six months in several classes: 45 days for some Bedrock models launched on or after September 7, 2026 and for Agent Platform short-term models, 60 days for Foundry generally available models and 30 days for Foundry previews. [2][6][11]
  • Of the 79 Azure OpenAI rows in the Foundry retirement schedule on October 9, 2026, 20 retire in the fourth quarter of 2026, and only 18 rows in the whole table name a replacement. [7]
  • Google's per-model security matrix shows controls moving in both directions: text embeddings moved to Gemini Embedding 2 online prediction keep only VPC Service Controls, while batch work moved from Gemini 2.5 Flash to Gemini 3.5 Flash gains CMEK support. [14]
  • Foundry's Models API inverts the portal's stage names: Deprecating means still serving but closed to new customers, and Deprecated means retired with 410 Gone. [6]

A retirement is a change nobody scheduled

A model retirement is a production change with a fixed date that nobody on your team scheduled. On Amazon Bedrock and Gemini Enterprise Agent Platform it arrives as a failure: once the end-of-life or retirement date passes, requests to that model ID stop working, and neither provider moves your traffic for you. On Microsoft Foundry the default arrival is quieter. A Standard, Global Standard or Data Zone Standard deployment whose versionUpgradeOption was never set behaves as OnceCurrentVersionExpired, so on the retirement date the same deployment name keeps answering while a different model serves it. [1][6][8][11]

Neither outcome carries the original approval forward. Content filter settings, data residency and encryption support, the tool-call and output contracts that downstream code parses, and the evaluation evidence were all accepted for one model in one deployment. Microsoft lists refusal behavior, tool-call shape and structured-output adherence among the properties that commonly change when a model is swapped, and Google's migration guide warns that security control support varies by model. [9][15]

The decision a retirement forces is therefore not whether to move, since the date settles that, but how. You can pin the current version and migrate on your own schedule, accept the provider's upgrade as a recorded safety net, or switch to a model you choose and review. The rule argued for here is to migrate deliberately before the date and to treat every automatic path as a fallback that still needs re-attestation. Dates and table contents below were read from the official Bedrock, Foundry and Agent Platform pages on October 9, 2026 and rechecked on October 10, 2026, and all three providers moved dates during 2026, so re-read the tables before planning against them.

What each platform does on the date

Amazon Bedrock uses three states: Active, Legacy and End-of-Life. For models launched before September 7, 2026, a model stays at least 12 months after launch and spends at least six months in Legacy before its EOL date. Legacy narrows access: new customers cannot adopt the model, existing customers may lose access after 15 days of inactivity, and no new Provisioned Throughput can be created. For EOL dates after February 1, 2026, at least three months into Legacy the model enters public extended access at prices the provider sets. On or soon after EOL, requests fail unless you hold a private arrangement with the provider. AWS states that migration will not happen automatically, and lifecycle state can differ by Region. [1]

Models launched on or after September 7, 2026 follow a newer policy. Each model card shows an EOL no sooner than date and a Legacy period of either six months or 45 days, and AWS says most models get six months. GPT-6.1 Sol has no separate Bedrock minimum-availability date at all: it follows OpenAI's first-party lifecycle, including its deprecation notice periods and its exceptions for safety or compliance. [2]

Microsoft Foundry assigns every model one of five stages: Preview, Generally Available, Legacy, Deprecated and Retired. Deprecated means existing customers can still deploy and call the model while new customers cannot, and existing is decided per Azure subscription, so a new subscription in the same tenant does not inherit access. Retired means every inference request returns 410 Gone. Generally available models follow a standard 18-month lifecycle with deprecation at 12 months, while generally available models from Anthropic, DeepSeek, Fireworks and Mistral AI follow 12 months. [6]

Automatic upgrades apply only to Global Standard, Data Zone Standard and Standard deployments. They roll out region by region and can happen even where the new version is not yet separately available in that region or SKU. Provisioned deployments are not upgraded; you migrate them in place over a 20 to 30 minute window or side by side, and batch deployments always migrate side by side. Microsoft's own example shows how far an upgrade reaches: when gpt-4o version 2024-05-13 retires on December 9, 2026, its Standard deployments become gpt-5.6-sol, a different model family behind an unchanged deployment name. [6][9]

Three values of versionUpgradeOption decide what a Standard-family deployment does. OnceNewDefaultVersionAvailable upgrades within two weeks of Microsoft designating a new default version. OnceCurrentVersionExpired upgrades to the current default at retirement. NoAutoUpgrade never upgrades, and the deployment stops working when its version retires. An absent property means null, which Microsoft documents as equivalent to OnceCurrentVersionExpired. The Azure CLI can read the value but cannot change it, so REST, Azure PowerShell or the Foundry portal has to set it. [8]

Gemini Enterprise Agent Platform has two classes. Models in its main tables stay available at least 12 months after release. Short-term models stay active until a replacement launches and a date is announced, which then gives at least 45 days to migrate. Dates may be extended but not moved earlier. For errors caused by a retired model, Google's advice is to point the application at the recommended upgrade, test critical features and redeploy, so every move is a manual change you own. [11]

Figure 01

What happens to traffic on the retirement date

Bedrock and Agent Platform fail closed on the date, while Foundry Standard deployments are swapped to another model unless an option says otherwise. [1][2][6][8][11]

Matrix of eight platform and deployment combinations showing what happens on the retirement date, the notice floor and the rollback or access limit. Bedrock requests fail with no automatic migration; Foundry Standard deployments with no option set are upgraded, NoAutoUpgrade and provisioned deployments return 410 Gone, previews are force-upgraded; Agent Platform calls error until the model ID is changed.

Source. Conceptual summary of documented behavior in the Amazon Bedrock lifecycle pages, the Microsoft Foundry lifecycle policy and model upgrade documentation, and the Gemini Enterprise Agent Platform lifecycle page, reviewed October 9, 2026. [1][2][6][8][11]

Method. Conceptual comparison assembled from the cited policy text; each cell paraphrases one documented rule. No deployment was observed.

Accessible table and figure data
Figure 1 accessible table
DeploymentOn the dateNotice floorAccess limits
Bedrock, launched before Sept 7, 2026Requests fail; no automatic migrationLegacy at least 6 monthsAccess may lapse after 15 idle days
Bedrock, launched on or after Sept 7, 2026Requests fail; no automatic migrationLegacy of 6 months or 45 daysSame Legacy rules; no new Provisioned Throughput
Foundry Standard family, option unsetUpgraded to the replacement or defaultGA notice at least 60 daysDeprecated: closed to new subscriptions
Foundry Standard family, NoAutoUpgradeStops working; 410 GoneGA notice at least 60 daysDeprecated: closed to new subscriptions
Foundry provisionedNot upgraded; 410 Gone unless migratedReplacement in region about 30 days beforeIn-place move takes 20 to 30 minutes
Foundry previewForce-upgraded or retiredAt least 30 daysNo option to stay on the version
Agent Platform, 12-month classCalls error; change the model ID yourselfAt least 12 months after releaseDates may be extended, never moved earlier
Agent Platform, short-term classCalls error; change the model ID yourselfAt least 45 days after a date is postedNo date until a replacement exists
Figure 1 accessible table
DeploymentOn the dateNotice floorAccess limits
Bedrock, launched before Sept 7, 2026Requests fail; no automatic migrationLegacy at least 6 monthsAccess may lapse after 15 idle days
Bedrock, launched on or after Sept 7, 2026Requests fail; no automatic migrationLegacy of 6 months or 45 daysSame Legacy rules; no new Provisioned Throughput
Foundry Standard family, option unsetUpgraded to the replacement or defaultGA notice at least 60 daysDeprecated: closed to new subscriptions
Foundry Standard family, NoAutoUpgradeStops working; 410 GoneGA notice at least 60 daysDeprecated: closed to new subscriptions
Foundry provisionedNot upgraded; 410 Gone unless migratedReplacement in region about 30 days beforeIn-place move takes 20 to 30 minutes
Foundry previewForce-upgraded or retiredAt least 30 daysNo option to stay on the version
Agent Platform, 12-month classCalls error; change the model ID yourselfAt least 12 months after releaseDates may be extended, never moved earlier
Agent Platform, short-term classCalls error; change the model ID yourselfAt least 45 days after a date is postedNo date until a replacement exists

Notice floors are shorter than six months

Bedrock's older policy promised at least six months in Legacy, but the documented floors are shorter in several places, and the shortest one that applies sets the window a re-attestation has to fit.

Foundry's 60-day figure is a notification floor under a lifecycle that is mostly visible in advance. A generally available model's retirement date is set programmatically at launch and exposed through the Models API, Microsoft names the official replacement roughly 90 to 120 days before retirement, and the replacement becomes testable in Global Standard about 90 days before and in provisioned regions about 30 days before. Microsoft also states that retirement dates are not extendable, and it reserves an emergency retirement with shortened notice for a model found to have compliance or security issues. [6]

Google's short-term class compresses lifetimes as well as notice. The two short-term Flash models with posted dates, gemini-3.6-flash and gemini-3.7-flash, were scheduled to run 121 and 168 days from release, against 366 to 529 days for the 12-month-class Gemini models that have fixed dates. That matters for planning because gemini-3.8-flash, the first replacement Google lists for all three Gemini 2.5 models, is itself a short-term model with no retirement date announced. [11]

A reasonable inference from these floors is that an eight-week review cannot begin at the announcement for a 45-day-class model on Bedrock or Agent Platform. Start the successor's review when such a model is adopted, or keep an already approved fallback. No provider states this; it follows from the published minimums.

Documented minimum notice or availability by platform and model class, from Amazon Bedrock, Microsoft Foundry and Gemini Enterprise Agent Platform lifecycle pages reviewed October 9, 2026. [1][2][6][11]
Platform and classDocumented minimumCondition or exception
Bedrock, launched before Sept 7, 2026Legacy at least 6 months before EOLExtended access priced by the provider
Bedrock, launched on or after Sept 7, 2026Legacy of 6 months or 45 daysGPT-6.1 Sol follows OpenAI terms
Foundry, generally availableNotice at least 60 days before retirementEmergency retirement for security issues
Foundry, previewNotice at least 30 daysForce-upgraded; no option to stay
Agent Platform, 12-month classAvailable at least 12 months after releaseDates never moved earlier
Agent Platform, short-term classAt least 45 days after a date is postedNo date until a replacement exists
Figure 02

Short-term Gemini models were scheduled for 121 and 168 days

The two short-term Flash models with posted dates run 121 and 168 days from release; the 12-month-class models with fixed dates run 366 to 529 days. [11]

Horizontal bar chart of days from release to listed retirement for seven Gemini models on Agent Platform: Gemini 2.5 Flash Image 529, Gemini 2.5 Pro 490, Gemini 2.5 Flash 490, Gemini 2.5 Flash-Lite 455, Gemini Live 2.5 Flash native audio 366, all in the 12-month class, then the short-term Gemini 3.7 Flash 168 and Gemini 3.6 Flash 121.

Source. Calculated from release and retirement dates in the Gemini Enterprise Agent Platform model versions and lifecycle tables, last updated October 9, 2026. [11]

Method. Days = retirement date minus release date, in calendar days. Includes only Gemini text, live and image models with a fixed retirement date; excludes models listed as retiring on a date or later, models with no date announced, Veo and embedding models.

Accessible table and figure data
Figure 2 accessible table
Model and classRelease dateRetirement dateDays from release to retirement
Gemini 2.5 Flash Image (12-month)2025-10-022027-03-15529
Gemini 2.5 Pro (12-month)2025-06-172026-10-20490
Gemini 2.5 Flash (12-month)2025-06-172026-10-20490
Gemini 2.5 Flash-Lite (12-month)2025-07-222026-10-20455
Gemini Live 2.5 Flash native audio (12-month)2025-12-122026-12-13366
Gemini 3.7 Flash (short-term)2026-08-132027-01-28168
Gemini 3.6 Flash (short-term)2026-07-212026-11-19121
Figure 2 accessible table
Model and classRelease dateRetirement dateDays from release to retirement
Gemini 2.5 Flash Image (12-month)2025-10-022027-03-15529
Gemini 2.5 Pro (12-month)2025-06-172026-10-20490
Gemini 2.5 Flash (12-month)2025-06-172026-10-20490
Gemini 2.5 Flash-Lite (12-month)2025-07-222026-10-20455
Gemini Live 2.5 Flash native audio (12-month)2025-12-122026-12-13366
Gemini 3.7 Flash (short-term)2026-08-132027-01-28168
Gemini 3.6 Flash (short-term)2026-07-212026-11-19121

What the three calendars hold through January 2027

The Azure OpenAI table under Foundry Models sold by Azure had 79 rows on October 9, 2026; the page is dated September 21 and was last updated September 23, 2026. Counting rows by retirement quarter puts the two peaks at 20 rows in the fourth quarter of 2026 and 22 in the second quarter of 2027. Only 18 rows name a replacement. In the fourth quarter of 2026, eight do: gpt-4o 2024-05-13 and the seven o-series models retiring on November 19, which point to gpt-5.6-sol or gpt-5.6-terra. The other 12 leave the Replacement column empty, so the schedule by itself does not tell you what an auto-upgraded Standard deployment of those versions becomes. [7]

Bedrock's scheduled table is short and scoped to Regions. On October 10, 2026 it listed six model IDs: Claude Sonnet 4 on October 14, 2026 in 23 Regions, Jamba 1.5 Large and Jamba 1.5 Mini on November 26 in us-east-1, Marengo Embed v2.7 on November 30, Claude Opus 4.1 on January 8, 2027, which entered public extended access on October 8, and Claude Sonnet 4.5 on April 8, 2027 in 31 Regions, which entered Legacy on October 8 and reaches public extended access on January 8, 2027. Seven more model IDs reached EOL between August 19 and September 30, 2026. The Regions column lists only the Regions covered by each announcement, so a Region missing from a row is no promise that the model stays there. [1]

Agent Platform retires the three Gemini 2.5 models on October 20, 2026. Further out, gemini-2.5-flash-image follows on March 15, 2027 and four embedding models, including text-embedding-005, on April 1, 2027. The table merges the near-term rows from all three sources; Bedrock's table has no replacement column. [1][7][11]

Retirements dated October 9, 2026 to January 31, 2027 in the official Bedrock, Foundry (Azure OpenAI) and Agent Platform tables, read October 9, 2026 and rechecked October 10, 2026. Some dates will have passed by the time you read this. [1][7][11]
DatePlatformModel or versionNamed replacement
Oct 14, 2026BedrockClaude Sonnet 4No column
Oct 15, 2026Foundrygpt-4o-mini-transcribe, gpt-4o-mini-tts, gpt-4o-transcribe (2025-03-20); sora-2 (2025-12-08)None listed
Oct 20, 2026Agent Platformgemini-2.5-pro, gemini-2.5-flash, gemini-2.5-flash-litegemini-3.8-flash and others
Oct 23, 2026Foundrygpt-image-1None listed
Nov 15, 2026Foundrycodex-miniNone listed
Nov 19, 2026Foundryo1, o1-pro, o3, o3-deep-research, o3-progpt-5.6-sol
Nov 19, 2026Foundryo3-mini, o4-minigpt-5.6-terra
Nov 19, 2026Agent Platformgemini-3.6-flashgemini-3.8-flash
Nov 26, 2026BedrockJamba 1.5 Large, Jamba 1.5 MiniNo column
Nov 30, 2026BedrockMarengo Embed v2.7No column
Dec 2, 2026Foundrygpt-chat-latest (2026-08-06)None listed
Dec 9, 2026Foundrygpt-4o (2024-05-13)gpt-5.6-sol
Dec 13, 2026Agent Platformgemini-live-2.5-flash-native-audioNone listed
Dec 15 to 16, 2026Foundrytts, tts-hd, whisper, gpt-realtime-mini (2025-12-15), gpt-image-1.5None listed
Jan 8, 2027BedrockClaude Opus 4.1No column
Jan 28, 2027Agent Platformgemini-3.7-flashgemini-3.8-flash
Figure 03

Azure OpenAI retirements peak in late 2026 and mid 2027

Of 79 published rows, 20 retire in the fourth quarter of 2026 and 22 in the second quarter of 2027, and only 18 rows name a replacement. [7]

Stacked horizontal bar chart of Azure OpenAI model version rows in the Foundry retirement schedule by retirement quarter, split by whether a replacement is named: 2026 Q2 6 named and 0 not; Q3 1 and 4; Q4 8 and 12; 2027 Q1 0 and 6; Q2 2 and 20; Q3 0 and 10; Q4 0 and 2; 2028 Q1 0 and 7; no date 1 and 0.

Source. Counted from the Azure OpenAI table in the Microsoft Foundry model retirement schedule (page dated September 21, 2026, updated September 23, 2026), read October 9, 2026. [7]

Method. Each published row is one model version. Rows are grouped by the calendar quarter of the Retirement date column and split by whether the Replacement column names a model. Two gpt-realtime-mini versions appear twice with conflicting dates and both rows are counted. Excludes fine-tuned models and partner tables.

Accessible table and figure data
Figure 3 accessible table
Retirement quarterReplacement namedNo replacement listed
2026 Q260
2026 Q314
2026 Q4812
2027 Q106
2027 Q2220
2027 Q3010
2027 Q402
2028 Q107
No date10
Figure 3 accessible table
Retirement quarterReplacement namedNo replacement listed
2026 Q260
2026 Q314
2026 Q4812
2027 Q106
2027 Q2220
2027 Q3010
2027 Q402
2028 Q107
No date10

When the official sources disagree

The Gemini 2.5 date is the clearest case. The Vertex AI release notes entry of April 2, 2026 says the retirement dates for Gemini 2.5 Pro, Gemini 2.5 Flash-Lite and Gemini 2.5 Flash were updated to October 16, 2026. The current lifecycle table, rechecked on October 10, 2026, and the comparison table in Google's migration guide both say October 20, 2026. The Agent Platform release notes, covering March 31 to October 7, 2026, carry no entry for the later change, though they record a similar move on September 14, 2026, when gemini-2.5-flash-image was extended from October 2, 2026 to March 15, 2027. This article follows the current table: the date changed after the April note, and it moved later, which Google's lifecycle commitment allows. [11][12][13][15]

Bedrock showed the same problem between two AWS pages. On October 9, 2026, the Claude Sonnet 4.5 model card listed the model as Legacy with a model EOL date of April 8, 2027, while the lifecycle page's table of models with a scheduled EOL date had no row for it, even though that page says its dates are the ones that apply for Bedrock usage. By October 10 the table carried the row: Legacy from October 8, 2026, public extended access from January 8, 2027 and EOL on April 8, 2027 in 31 Regions. The two pages now agree, but the table trailed both the model card and the Legacy date it records. The tiebreaker is the one the lifecycle page itself names: call ListFoundationModels or GetFoundationModel in each Region you use and read modelLifecycle. [1][5]

Foundry's schedule has two kinds of defect. Two versions of gpt-realtime-mini appear twice with conflicting dates: 2025-10-06 with April 6, 2027 and September 21, 2026, and 2025-12-15 with June 15, 2027 and December 15, 2026. The chart counts both rows as published. The Lifecycle column also lags: of the 11 rows whose retirement dates had passed by October 9, 2026, six read Retired while five still read Preview or GA. Microsoft's own decision logic for the Models API allows for the same kind of lag, treating any past deprecation.inference date as retired regardless of lifecycleStatus. [6][7]

The rule that follows is to trust the field a platform evaluates over any table, write the fetch date beside every date you plan against, and re-read the tables on a schedule. That field is modelLifecycle per Region on Bedrock and deprecation.inference read with lifecycleStatus on Foundry. The Agent Platform pages reviewed document no per-model retirement field, so a regular diff of its lifecycle table is the control there.

The controls a replacement can change

Content safety configuration is the first thing to re-read. Google's migration guide tells you to note the default content filter settings and change your code if it relies on a default that has changed. In Foundry, a guardrail is an RAI policy assigned to a deployment through the raiPolicyName property; Microsoft Default guardrails such as Default.V2 cannot be edited, and removing a custom guardrail reassigns the Microsoft default. Because the assignment belongs to the deployment rather than the model version, a reasonable reading is that an in-place automatic upgrade keeps it. The pages reviewed do not say so, so read raiPolicyName after the upgrade instead of assuming. A side-by-side deployment is a new resource and starts with whatever raiPolicyName its create request carries. [10][15]

Model behavior changes in ways that look like security failures or hide them. Microsoft names verbosity, reasoning depth, structured-output adherence, tool-call shape, refusal behavior and latency variance as properties that commonly shift, and notes that extra fields, renamed arguments and changed call sequencing surface only in real traces. Google's guide adds two Gemini 3.x behaviors. A function response must carry the id and name of its call, one response per call, and mismatches cause empty responses with finish_reason: STOP in most cases rather than an error. For Gemini 3 Pro and later, a missing thought signature returns an error instead of a warning. A dashboard that counts successful HTTP responses sees neither a refusal regression nor a silent empty answer. [9][15]

Platform controls can move in either direction, and Google publishes the evidence per model and per feature. The table compares rows from its security controls matrix for migrations a team might make. Two caveats come from the same page: security controls are not supported for preview models at all, and Google's migration comparison lists Gemini 3.1 Pro as a preview model. [14][15]

Deployment type and location can change too. Foundry launches new models in Global Standard first, then Global Provisioned, then Data Zone, and regional Standard and Provisioned last, and successive versions may not be available in the same regions; on Agent Platform, regional endpoint availability varies by model. A replacement that is only offered in a broader processing scope moves where prompts are processed, even when stored data stays put. [6][15]

Some evidence cannot be carried across at all. Tuned models do not move: Google requires a new tuning job for the new Gemini version, Bedrock blocks new fine-tuning jobs once a base model is Legacy, and Foundry's fine-tuned deployments run on their own training and deployment retirement clock. A new tuning job means the training data's handling has to be approved again. Replay also depends on capture you switched on earlier, because Foundry's production content capture is opt-in and never retroactive. [1][9][15]

Change in documented security control support for selected Gemini migration paths, from Google's security controls matrix reviewed October 9, 2026. Embeddings for Text is the matrix's own row label. [14]
Migration pathResidency at restCMEKVPC-SCAccess Transparency
Embeddings for Text online to Gemini Embedding 2 onlineLostLostKeptLost
Gemini 2.5 Flash batch to Gemini 3.5 Flash batchKeptGainedKeptStill unsupported
Gemini 2.5 Flash batch to Gemini 3.8 Flash batchKeptGainedKeptStill unsupported
Gemini 2.5 Flash-Lite batch to Gemini 3.1 Flash-Lite batchKeptStill unsupportedKeptStill unsupported
Gemini 2.5 Flash Live native audio to Gemini 3.8 LiveKeptGainedKeptKept
Any generally available model to a preview modelLostLostLostLost

Find every deployment the calendar touches

The tables say what retires; they do not say what you call. On Bedrock, ListFoundationModels and GetFoundationModel return a modelLifecycle object per Region with status, legacyTime, publicExtendedAccessTime and endOfLifeTime. The status enum holds only ACTIVE and LEGACY, so a script has to compare endOfLifeTime with the current date itself. The AWS/Bedrock CloudWatch namespace adds the usage side: LegacyModelInvocations counts invocations of Legacy models and is published with a ModelId dimension, which separates the Legacy models you call from those that merely exist. [1][3][4]

On Foundry, the deployment list shows each deployment's model name, version, SKU, versionUpgradeOption and raiPolicyName; a deployment with no upgrade option prints null. The Models API, at API version 2024-10-01, returns lifecycleStatus, deprecation.inference and a per-SKU deprecationDate. Read its status names carefully. The API's Deprecating is the portal's Deprecated, still serving and closed to new customers, and the API's Deprecated is the portal's Retired, returning 410 Gone. An alert written against Deprecated fires after the outage, not before it. [6][8]

On Agent Platform, compare the model IDs in your code and configuration with the lifecycle table, then confirm actual use per project and location with the beta Cloud Monitoring metric publisher/online_serving/model_invocation_count. Its monitored resource, aiplatform.googleapis.com/PublisherModel, carries model_user_id and model_version_id labels for grouping. [16][17]

Example fragment based on the Bedrock FoundationModelLifecycle and CloudWatch metric references and Microsoft's deployment and Models API documentation. Read-only; grant list and read permissions such as bedrock:ListFoundationModels, cloudwatch:ListMetrics, Reader on the Foundry resource for the deployment list, and Microsoft.CognitiveServices/locations/models/read at subscription scope for the Models API call, which a role on the resource alone does not cover. az rest replaces {subscriptionId} with the current subscription.
# Example inventory fragment: read-only calls with placeholder names.
# Amazon Bedrock: run once per Region you use.
aws bedrock list-foundation-models --region us-east-1 \
  --query "modelSummaries[?modelLifecycle.status=='LEGACY'].[modelId,modelLifecycle.legacyTime,modelLifecycle.publicExtendedAccessTime,modelLifecycle.endOfLifeTime]" \
  --output table

# Legacy model IDs this account has recently invoked in the Region.
aws cloudwatch list-metrics --region us-east-1 \
  --namespace AWS/Bedrock --metric-name LegacyModelInvocations \
  --query "Metrics[].Dimensions[?Name=='ModelId'].Value[]" --output text

# Microsoft Foundry: version, SKU, upgrade option and guardrail per deployment.
# A null upgrade option behaves as OnceCurrentVersionExpired.
az cognitiveservices account deployment list \
  --resource-group example-rg --name example-foundry \
  --query "[].{deployment:name, model:properties.model.name, version:properties.model.version, sku:sku.name, upgrade:properties.versionUpgradeOption, guardrail:properties.raiPolicyName}" \
  --output table

# Models API: "Deprecating" still serves; "Deprecated" is retired (410 Gone).
# Also treat any past deprecation.inference date as retired.
az rest --method get \
  --url "https://management.azure.com/subscriptions/{subscriptionId}/providers/Microsoft.CognitiveServices/locations/eastus/models?api-version=2024-10-01" \
  --query "value[?model.lifecycleStatus=='Deprecating' || model.lifecycleStatus=='Deprecated'].[model.name, model.version, model.lifecycleStatus, model.deprecation.inference]" \
  --output table

Re-attest the replacement before it serves users

Treat the replacement as a new release with its own record, not as maintenance on the old one. Microsoft's migration process orders the work in a way that suits a security review: freeze a dataset and success criteria, replay the current workload unchanged on the target to isolate what the model changed, then adapt prompts, tool definitions and schemas, and score source and target on the same frozen set before rollout. The evidence falls into these groups. [9]

  • Guardrails and filters: read the guardrail actually in force on the new or upgraded deployment, such as raiPolicyName on Foundry or the content filter settings your Gemini requests send, and rerun both the attack corpus and the benign corpus against it. [10][15]
  • Refusals and harmful-content handling: score the source model first as the baseline, then the target, on the same frozen inputs, so a change in refusals is measured before users notice it. [9]
  • Tool calls and structured output: replay real multi-turn traces and check argument names, extra fields, call order and, on Gemini 3.x, that every function response carries the matching id and name. [9][15]
  • Platform controls: compare the replacement's row in Google's security matrix, its Foundry deployment type and processing scope, and its Bedrock Regions with what the original approval assumed. [1][6][14]
  • Logging and capture: confirm request logging, content capture and retention on the new deployment, since a side-by-side deployment is a separate resource.
  • Capacity and rollback: secure target-model quota before a provisioned or batch move, and keep the old deployment reachable for the rollback window; Microsoft says embedded teams typically want about 30 days. [9]
  • Graders and judges: if a model scores the migration, check its own retirement date; a judge that retires mid-migration changes the measurement.

Pin, accept the upgrade, or migrate

Apply the decision per deployment, not per model, because the same model can sit behind a provisioned deployment with no upgrade path and a Standard deployment that will be swapped on the date. The default answer is to migrate before the date on your own schedule. Microsoft itself describes auto-upgrade as a safety net for pay-as-you-go deployments, not a migration plan. [9]

Pinning with NoAutoUpgrade is the right setting when serving an unreviewed model is worse than an outage: a deployment that makes regulated decisions, an agent that holds write tools, or output parsed by a strict consumer. It turns the retirement date into a hard deadline that ends in 410 Gone, so it needs a named owner and an alarm set well before that date. Bedrock and Agent Platform document no automatic upgrade, so every model ID there is effectively pinned. [1][6][8][11]

Leaving the default, OnceCurrentVersionExpired, is defensible for low-risk Standard deployments where continuity matters more than fidelity, provided the upgrade target is known and its controls were compared in advance. That condition fails more often than it appears to: for 12 of the 20 Azure OpenAI rows retiring in the fourth quarter of 2026, the schedule names no replacement. Keep OnceNewDefaultVersionAvailable off anything covered by a security approval. Microsoft recommends it for early testing, and it lets the model change within two weeks of a new default with no retirement involved. [7][8]

The obvious choice is wrong in two more cases. A provider's named replacement can be a short-term model, as gemini-3.8-flash is for Gemini 2.5, which commits you to another migration on a 45-day floor. And a workload that stops calling a Bedrock Legacy model after cutover may lose access after 15 idle days, which quietly closes the rollback path you planned to keep. [1][11]

Figure 04

Choose the retirement path for each deployment

Migrate deliberately by default; pin when an unreviewed model is worse than an outage, and treat automatic upgrades as a safety net. [1][6][8][9][11][14]

Decision tree with five questions answered per deployment: whether retirement swaps the model behind the deployment, whether an unreviewed model is worse than an outage, whether the replacement keeps every control you rely on, whether it is a short-term, preview or 45-day-class model, and whether rollback needs the old model after cutover.

Source. Conceptual decision aid based on the Bedrock, Foundry and Agent Platform lifecycle documentation and Google's security controls matrix, reviewed October 9, 2026. [1][6][8][9][11][14]

Method. Conceptual ordering of documented rules. Each question is answered independently for each deployment, not each model.

Accessible table and figure data
Figure 4 accessible table
QuestionYes, thenNo, then
Does retirement swap the model behind this deployment?set the Foundry upgrade option on purposeexpect calls to fail on the date unless you move
Is an unreviewed model worse than an outage here?pin with NoAutoUpgrade and own the deadlinekeep upgrade at retirement as a recorded safety net
Does the replacement keep every control you rely on?replay traffic and rerun filter testschoose another model or record an approved exception
Is the replacement short-term, preview or 45-day class?start its successor review at adoptionrecord its retirement date as the next review trigger
Will rollback need the old model after cutover?keep it reachable; idle Bedrock access can lapse in 15 daysdelete the old deployment and confirm retirement
Figure 4 accessible table
QuestionYes, thenNo, then
Does retirement swap the model behind this deployment?set the Foundry upgrade option on purposeexpect calls to fail on the date unless you move
Is an unreviewed model worse than an outage here?pin with NoAutoUpgrade and own the deadlinekeep upgrade at retirement as a recorded safety net
Does the replacement keep every control you rely on?replay traffic and rerun filter testschoose another model or record an approved exception
Is the replacement short-term, preview or 45-day class?start its successor review at adoptionrecord its retirement date as the next review trigger
Will rollback need the old model after cutover?keep it reachable; idle Bedrock access can lapse in 15 daysdelete the old deployment and confirm retirement

Prepare for the next retirement notice

Work through these steps for every deployment that a table or API marks as Legacy, Deprecated or dated. First, join your inventory to the tables and lifecycle fields, write each date down with the day you read it, and give each deployment an owner, not each model. Second, set the Foundry upgrade option explicitly on every Standard-family deployment, so the retirement behavior is a written decision rather than a null. Third, compare the replacement's control row with the original approval before any quality testing starts.

Fourth, replay captured traffic unchanged on the replacement, then adapt prompts, tool definitions and schemas, then score both models on the same frozen set. Fifth, cut over in stages while the old model is still reachable, remembering that an idle Bedrock Legacy model can drop out of reach after 15 days. Sixth, delete the old deployment, confirm through the API that its version is retired, and record the replacement's own retirement date and notice class in the release record as the next review trigger.

This order stops applying in two situations. A provider-declared emergency retirement overrides the documented floors, so handle it as an incident with its own owner. Preview models sit outside the order entirely: Microsoft force-upgrades or retires them with at least 30 days of notice and Google supports none of its security controls on them, so keep previews out of approved production paths. [6][14]

Method and provenance

Source-led analysis of Amazon Bedrock, Microsoft Foundry and Gemini Enterprise Agent Platform lifecycle policies, retirement tables, API references and security control documentation, with row counts and day counts calculated from the official tables. Sources were reviewed on October 9, 2026, and the Bedrock, Foundry and Agent Platform lifecycle tables were rechecked on October 10, 2026.

No cloud account, deployment or model was configured, upgraded or called. Retirement dates, replacements and control support are as published on October 9 and 10, 2026 and change often; counts are tallies of published rows, including two duplicated Foundry rows with conflicting dates. Whether a Foundry guardrail assignment persists through an automatic upgrade is not stated in the pages reviewed and is presented as an inference.

AI assistance. AI assisted research synthesis, row counting, drafting, diagram planning and visual production, with deterministic editorial checks. No personal deployment experience, independent human review or live test is claimed.

Published under the Cloud Security Desk organizational byline. Read the practitioner guide policy.

References

  1. Model lifecycle (Legacy), Amazon Bedrock User Guide Amazon Web Services. Accessed .
  2. Model lifecycle, Amazon Bedrock User Guide Amazon Web Services. Accessed .
  3. FoundationModelLifecycle, Amazon Bedrock API Reference Amazon Web Services. Accessed .
  4. Monitor bedrock-runtime inference using CloudWatch metrics Amazon Web Services. Accessed .
  5. Claude Sonnet 4.5 model card, Amazon Bedrock User Guide Amazon Web Services. Accessed .
  6. Microsoft Foundry Models lifecycle and support policy Microsoft. Accessed .
  7. Model retirement schedule (Microsoft Foundry) Microsoft. Accessed .
  8. Model migration process (Microsoft Foundry) Microsoft. Accessed .
  9. Vertex AI release notes (Generative AI on Vertex AI) Google Cloud. Accessed .
  10. Gemini Enterprise Agent Platform release notes Google Cloud. Accessed .
  11. Migrate to the latest Gemini models Google Cloud. Accessed .
  12. Google Cloud metrics: A or B (Cloud Monitoring) Google Cloud. Accessed .
  13. Monitored resource types (Cloud Monitoring) Google Cloud. Accessed .