AI-Enabled Engineering | AI in the EU series

    Using Kiro with Claude in the EU

    Configure Kiro enterprise identity, profile location and approved models so Claude processing stays within EU Regions.

    Siva SadhuBy Siva SadhuFounder and Principal ConsultantLast checked 29 September 2026
    Enterprise coding workspace connected to approved European Claude regions

    Kiro is AWS’s own AI coding tool, and it runs on Amazon Bedrock. That makes it one of the more straightforward ways to give developers Claude with EU processing, but only if you set it up the right way. Sign in the wrong way, or pick the wrong model, and your prompts are processed in the US.

    The good news is that the rules are clear and documented. In this post I’ll go through what decides where Kiro runs Claude, where your data is stored, and how to roll it out so it stays in the EU.

    Three things decide where Claude runs

    In Kiro, you don’t pick a Region per request. It follows from how people sign in, where your Kiro profile lives, and which model they choose (Kiro: Models).

    1. How users sign in. Only enterprise users who sign in through IAM Identity Center or an external identity provider get a profile Region. Free Tier users and individual subscribers, including people who sign in with GitHub, Google or AWS Builder ID, are always served from the US (Kiro: Models).

    2. Where your Kiro profile is. With an enterprise profile in Europe (Frankfurt), Claude models are served from Kiro’s EU geography. Kiro uses Bedrock cross-Region inference, so a request can be processed in any of these Regions: Frankfurt, Ireland, Paris, Stockholm, Milan or Spain (Kiro: Data protection). All six are EU member states.

    3. Which model is selected. Most named models follow your profile geography, but there are exceptions (<u>Kiro: Models</u>). Auto needs separate treatment: Kiro’s model documentation says Auto is not restricted to the models an administrator has approved. For an EU-only setup, exclude Auto and allow-list the specific EU-served models you have approved.

    ModelWith a Frankfurt profile
    Claude Opus 5.5, Opus 5, Opus 4.x, Sonnet 5, Sonnet 4.x, Haiku 4.5EU
    AutoNot guaranteed. Auto is not restricted to the administrator’s approved-model list. Exclude Auto for EU-only use.
    Claude Fable 5.1 (preview)Not available; it runs only in US East (N. Virginia)
    GPT-5.6 modelsUS, regardless of profile Region
    Any model marked experimentalMay be processed in AWS Regions worldwide

    So “Kiro in Frankfurt” means Claude in the EU only when the identity, profile geography and model choice line up. For a strict setup, use enterprise sign-in, a Frankfurt profile and explicitly approved EU-served models rather than Auto.

    Where your data is stored, and how it’s used

    Processing is only half the question. Kiro also stores some content, and where depends on the type of user (Kiro: Data protection).

    Free Tier and individual subscribersEnterprise users
    Where prompts and responses are storedUS East (N. Virginia)The Region of your Kiro profile
    Used for service improvementYes, unless the user opts outNo
    Prompt logging and usage reportsNot applicableOnly if an admin enables them, written to an S3 bucket in your own AWS account
    Extra abuse-detection storageFree Tier inputs may be kept for up to 60 daysOnly model-specific rules, below

    One model-specific rule matters for Claude. For Claude Fable 5.1, all traffic is kept for up to 30 days for automated abuse detection, and flagged traffic may be reviewed by people at AWS (Kiro: Data protection). That’s another reason to keep Fable off the approved list for EU workloads.

    Enterprise administrators can also encrypt Kiro’s stored data with their own KMS keys instead of AWS-owned keys (Kiro: Data protection).

    Rolling out Kiro so Claude stays in the EU

    1. Set up Kiro Enterprise with a Frankfurt profile. The Kiro console and profile are supported in US East (N. Virginia) and Europe (Frankfurt), plus the two GovCloud Regions, so Frankfurt is the EU option (Kiro: Supported regions).
    2. Sign users in through IAM Identity Center or your identity provider. Your IAM Identity Center instance can be in several Regions, including Frankfurt, Ireland, Paris and Stockholm (Kiro: Supported regions). This is what makes users enterprise users with a profile Region.
    3. Make sure nobody uses personal accounts for company code. Anyone who signs in with GitHub, Google or AWS Builder ID is served from the US and their content may be used for service improvement unless they opt out (Kiro: Data protection). Put this in your acceptable-use policy, and check Kiro’s firewall and data perimeter guidance for technical controls.
    4. Approve only EU-served models. Use model governance to build your approved list from models marked EU for a Frankfurt profile. Leave Auto out of a strict EU-only setup because Kiro does not restrict Auto to the administrator’s approved-model list. Also exclude US-only and experimental models.
    5. Decide on prompt logging deliberately. If you enable it, prompts land in an S3 bucket in your own AWS account (Kiro: Data protection). Put that bucket in an EU Region, and treat it as sensitive data.
    6. Consider customer managed keys if your security team wants control over the encryption of Kiro’s stored data.

    How Kiro compares with running Claude on your own Bedrock account

    Kiro and tools like Claude Code both use Bedrock, but in different ways. With Claude Code on your own Bedrock account, you own the inference profiles, the IAM policies and the CloudTrail logs, as described in Running Claude Code on Amazon Bedrock Inside the EU. With Kiro, AWS runs Bedrock for you as part of the Kiro service, and you control the residency control through your profile Region, sign-in method and approved models instead.

    Neither is better in general. Kiro is quicker to roll out and keeps the EU residency control in a few admin settings. Your own Bedrock account gives you more direct evidence and control, at the cost of more setup.

    Limits to know about

    • New models do not always arrive in the EU at launch. Check Kiro’s current model page before approving a model rather than assuming the newest release follows your profile geography.
    • Experimental models can leave the EU. They may be processed in AWS Regions worldwide, whatever your profile Region (Kiro: Data protection).
    • EU means six Regions, not one. Requests can be processed in any of Kiro’s EU Regions. If you need a single Region, Kiro doesn’t offer that today.
    • Operational signals are collected. Kiro may collect error logs and metrics to run the service, separately from content (Kiro: Data protection).

    Rolling Kiro out across a team?

    Wolkn Minds can help configure the profile, identity and model-governance settings, and work out when Kiro is a better fit than Claude Code on your own Bedrock account.

    Sources

    Measured token flows and cost controls across European cloud regionsNext in the AI in the EU seriesControlling the Cost of Claude on Amazon BedrockUnderstand regional pricing, budgets, cost attribution and quota planning for Claude workloads on Amazon Bedrock.Read next

    Related reading

    Rolling out AI coding tools across your teams?

    An AI Development Readiness Review covers tool and model choice, controls, cost and how the tools fit your delivery process.