Kiro
Spec-driven agentic IDE from AWS — GA since Nov 2025, now consolidating the entire AWS developer funnel as Amazon Q Developer sunsets (new signups end May 15 2026, full EOL April 2027).
Dimension breakdown
Score · confidenceSpec-driven agentic IDE from AWS — GA since Nov 2025, now consolidating the entire AWS developer funnel as Amazon Q Developer sunsets (new signups end May 15 2026, full EOL April 2027). Requirements Analysis (May 12 2026) pairs an LLM with an SMT solver to formally verify requirement consistency before code; internal testing across 35 projects found ~60% of first-draft requirements needed refinement (vendor data, not independently validated).
CLI 2.0 ships mature headless CI/CD mode (KIRO_API_KEY + --no-interactive), native Windows, and ACP support across Eclipse/Emacs/JetBrains/Neovim/Toad/Zed; Kiro Web (Preview) adds multi-repo sessions with auto-PR creation. Multi-repo ingestion + codebase vectorization and 1M-token Opus 4.7/Sonnet 4.6 context strengthen cross-repo understanding.
Compliance hardened: HIPAA Eligible (IDE+CLI), GovCloud (US-East/US-West) GA, FedRAMP High + DoD CC SRG process started, EU/APAC/US data residency, training opt-out for paid/IAM users, model governance, IP indemnity. Documented enterprise adoption: Delta (94% satisfaction, production dev portal, pilot 2 quarters early), Siemens, Rackspace, Mondelez, Appian, Ericsson, Nymbus, plus Amazon internal (Alexa+, Prime Video, Stores, Fire TV).
security cadence worsening — CVE-2026-9255 (May 22, CVSS 7.8, tool-authorization bypass on the agentic surface, patched in kiro-cli 1.28.0) is the latest of ~5 CVEs in 7 months.
Autonomous Agent still preview (no GA-for-teams; DevOps/Security Frontier Agents went GA Mar 31 but Kiro's coding agent did not). Documented production incidents persist (unreviewed AI-deployed code → ~6-hour outage / ~6.3M orders lost; reported 13-hour environment-deletion outage).
Mass account-suspension false positives and credit/pricing opacity remain unresolved.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
No active caps — no risk flags apply to this tool right now.
Status rationale
Assessed (held; no change). Strong and accelerating evidence supports the level: broad named-enterprise adoption (Delta at 94% satisfaction with a shipped production dev portal, Siemens, Rackspace, Mondelez, Appian, Ericsson, Nymbus, plus Amazon internal at scale), hardened AWS strategic commitment (Q Developer new-signups end May 15 2026 / full EOL April 2027 funnels the AWS developer base to Kiro), compliance hardening (HIPAA Eligible, GovCloud US GA, FedRAMP High/DoD CC SRG process started, data residency, training opt-out, model governance, IP indemnity), and strong product velocity (Requirements Analysis SMT solver, mature CLI 2.0 headless mode, multi-repo indexing, parallel subagents, Kiro Web preview).
Held at Assessed rather than promoted to Validated because the Validated bar is not met: (1) open reliability/security blockers — CVE-2026-9255 (May 22, CVSS 7.8) on the agentic tool-authorization surface is the latest of ~5 CVEs in 7 months (cadence worsening, not improving), and documented production incidents attributed to Kiro's autonomous operation persist (unreviewed AI-deployed code → ~6-hour outage / ~6.3M orders; reported 13-hour environment-deletion outage); (2) mixed enterprise sentiment (~3, below the >=4 Validated threshold) driven by unresolved mass account-suspension false positives and credit/pricing opacity; (3) Autonomous Agent still preview with no GA-for-teams date (other Frontier Agents went GA Mar 31 2026, Kiro's coding agent did not); (4) Requirements Analysis bug-detection claims remain vendor-internal with no independent benchmark validation.
Movement triggers
Upgrade if: Kiro Autonomous Agent reaches GA for teams; FedRAMP High / DoD CC SRG authorization actually granted (not just in-process); independent benchmarks (e.g., SWE-bench Verified for the Kiro agent, or third-party validation of the Requirements Analysis bug-detection claim) confirm autonomy/correctness marketing; account-suspension false positives systematically resolved; sustained enterprise sentiment improves to >=4; additional named Fortune 500 production deployments at scale. Downgrade if: an UNPATCHED critical CVE appears (would trigger critical-security-vuln cap, Compliance <=5); a sixth+ CVE or another production incident attributed to Kiro's autonomous operation; reliability complaints become a user-base-wide consensus (would trigger reliability-complaints cap, Autonomy <=12); pricing backlash escalates into measurable churn; AWS deprioritizes Kiro post-Q Developer consolidation; community sentiment shifts decisively negative.
Risks & limitations
Not yet assessed — this section fills in as ACES research covers the tool.
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category