Skip to main content

AI & assistant-friendly summary

This section provides structured content for AI assistants and search engines. You can cite or summarize it when referencing this page.

Summary

Checked 11 Oct 2026: Jev 1.13.0 is still $0.042/MTok, now published at 80 requests/s and 100,000 tokens/s. On AWS it remains an external System-1 sidecar next to Amazon Bedrock, not a Bedrock model.

Key Facts

  • •Checked 11 Oct 2026: Jev 1.13.0 is still $0.042/MTok, now published at 80 requests/s and 100,000 tokens/s
  • •On AWS it remains an external System-1 sidecar next to Amazon Bedrock, not a Bedrock model
  • •On 15 September 2026, TypeSafe AI published Jev, the first System One model
  • •Input tokens are priced at $0.042 / MTok; output tokens are free
  • •Rechecked on 11 October 2026 against the TypeSafe models page: the pin is still , and the published rate limits are 100,000 tokens per second and 80 requests per second

Entity Definitions

Amazon Bedrock
Amazon Bedrock is an AWS service discussed in this article.
Bedrock
Bedrock is an AWS service discussed in this article.
Lambda
Lambda is an AWS service discussed in this article.
DynamoDB
DynamoDB is an AWS service discussed in this article.
CloudWatch
CloudWatch is an AWS service discussed in this article.
IAM
IAM is an AWS service discussed in this article.
VPC
VPC is an AWS service discussed in this article.
API Gateway
API Gateway is an AWS service discussed in this article.

Jev (TypeSafe AI) on AWS: When System One Decisions Belong Next to Bedrock (2026)

Generative AIPalaniappan P18 min read

Quick summary: Checked 11 Oct 2026: Jev 1.13.0 is still $0.042/MTok, now published at 80 requests/s and 100,000 tokens/s. On AWS it remains an external System-1 sidecar next to Amazon Bedrock, not a Bedrock model.

Key Takeaways

  • Checked 11 Oct 2026: Jev 1.13.0 is still $0.042/MTok, now published at 80 requests/s and 100,000 tokens/s
  • On AWS it remains an external System-1 sidecar next to Amazon Bedrock, not a Bedrock model
  • On 15 September 2026, TypeSafe AI published Jev, the first System One model
  • Input tokens are priced at $0.042 / MTok; output tokens are free
  • Rechecked on 11 October 2026 against the TypeSafe models page: the pin is still , and the published rate limits are 100,000 tokens per second and 80 requests per second
Dark navy architecture board with three amber-lit decision nodes — a boolean toggle, a choice wheel, and a score bar — feeding a separate generative light path
Table of Contents

On 15 September 2026, TypeSafe AI published Jev, the first System One model. Unstructured state in; typed probabilistic decisions out. Input tokens are priced at $0.042 / MTok; output tokens are free. Rechecked on 11 October 2026 against the TypeSafe models page: the pin is still jev-1.13.0, and the published rate limits are 100,000 tokens per second and 80 requests per second. The earlier card of 250,000 tokens per second and 1,200 requests per minute is stale. TypeSafe says the current limits can still move without notice.

Jev is not an Amazon Bedrock model. The Bedrock model cards checked the same day do not list TypeSafe or Jev, and there is no Converse or InvokeModel model ID. On AWS it is a System-1 sidecar: your server calls TypeSafe for a closed-set decision; Amazon Bedrock stays the generator. Calling Jev from Lambda is a composition of two services, not evidence that AWS adopted Jev.

Opinionated take: use Jev for one bounded decision inside a flow you control. Use a Bedrock model when the user needs language or synthesis. Use deterministic code, IAM, and AgentCore Gateway policy before any side effect. Do not make Jev the controller of the agent, and do not treat a confidence score as authorization.

First-party signals we reuse (not a Jev outcome, not an agent client case) — Gateway server-side tools cut median tool round-trip ~180 ms → ~95 ms on a B2B CRM assistant (12 tools, ~8k turns/day) — Gateway post. Platform TCO silhouette: support-style AgentCore at 50K sessions/mo ~$791/mo platform + model (decision guide). Model your mix on the AgentCore pricing calculator. Jev sits next to that hop. It does not replace Gateway, Cedar, or Runtime.

Reproduce this — Clone the artifacts under examples/architecture-blog-2026/jev-typesafe-aws/. python3 -m py_compile lambda_pydantic_ai_stub.py syntax-checks the Python request shape. The TypeScript adapter is route-support-ticket.ts (DRY_RUN defaults on; no API key; no live Jev call). Ship gates live in monday-checklist.md. Score the fit in decision-matrix.md. The CSV at cost-worksheet.csv works TypeSafe’s published $0.042/MTok on one ticket-volume row.

Trade-off you accept: schema-bound decisions, with vendor-claimed tens-to-hundreds of milliseconds, in exchange for an egress dependency whose published cap (checked 11 Oct 2026) is 80 requests per second and 100,000 tokens per second, and which TypeSafe says can change without notice.

What Jev decides

TypeSafe named the class after Kahneman’s Thinking, Fast and Slow: System One for fast, structured judgments software can consume. Training is RLCD (Reinforcement Learning for Calibrated Decisions), not RLHF. Sampling is parallel across questions, not token-by-token.

That design gives up strings on purpose. Jev will not write a refund email, a Terraform module, or a toolUse JSON blob. A typed result picks among answers you listed. Your code maps that result onto a path you already allow.

TypeSafe’s marketing line is that Jev “can’t hallucinate.” Read that as cannot emit a value outside the schema. The Register, 16 Sep 2026, made the distinction we keep: a typed wrong answer is still wrong. A category can be spelled exactly right and still be the wrong category. Confidence exists so your code can refuse to act. It is not a probability that any single answer is correct. TypeSafe describes calibration across groups of predictions, not a guarantee on one ticket.

What Jev does not replace

Keep these jobs on other layers:

  • Language and synthesis stay on a Bedrock foundation model: replies, summaries, explanations, and tool-argument text.
  • Authorization stays on IAM, AgentCore Gateway policy, and your own checks. Gateway Cedar is default deny. A Jev score never satisfies it.
  • Exact checks stay in code: a required disclosure sentence, an order-id format, a refund amount copied from the order record.
  • Formal policy proof stays on Automated Reasoning Checks when you need valid or invalid against a policy, not a probability.
  • Bedrock Guardrails stay on the generative call. They never see the TypeSafe hop. Production Guardrails guide.

Model card checked 11 Oct 2026

Source: TypeSafe Models. Re-read that page before you budget. TypeSafe says rate limits are adjusting dynamically.

Fieldjev-1.13.0
Aliasesjev-latest and jev-preview both pointed here when we checked. No separate preview build.
Price$0.042 / MTok input ($42 / billion tokens). Output tokens free.
Context64k tokens per request. 32k for state plus the longest question.
InputText only. String, JSON object, or array of text. No image, audio, or video.
Rate limits100,000 tokens/s and 80 requests/s. Over either limit: 429. SDK retries honor retry-after.
Fine-tune / LoRANone. Shape answers with state, instructions, and criteria.
Training on your callsTypeSafe says Jev is not trained on customer requests or responses.

Pin jev-1.13.0 once a threshold is tuned. Aliases move when a release ships. The response model field reports the versioned ID that answered. Log that field.

Access paths, none of them Bedrock:

  • HTTP: POST https://api.typesafe.ai/v1/systemone with Authorization: Bearer
  • JavaScript / TypeScript: @typesafe-ai/sdk — TypeSafeClient, client.systemOne(), helpers choice, noul, score
  • Python: typesafe_sdk — TypeSafeClient.system_one(), classes Choice, Noul, Score
  • Default model if you omit model: jev-latest (do not tune against it)
  • SDK default timeout: 10,000 ms per attempt, not a total budget across retries. Default maxRetries is 2 (three tries). Retried statuses include 408, 429, and 500–599. The HTTP API also documents 529 Overloaded: back off, do not treat it as an answer.

English is the primary training language. Other languages, including CJK, are “handled but not equally well.” Test on your corpus before a non-English SLO.

Choice criteria cap at 255 options. Score levels cap at 10. Noul returns noul in 0–1 and no separate confidence. Choice and Score return confidence derived from the probability distribution. Do not copy a Noul threshold onto a Choice.

Jev is not a Bedrock model

Checked 11 Oct 2026:

  • Bedrock’s published provider list (Amazon, Anthropic, Meta, Mistral, OpenAI, and the rest of the model cards) does not include TypeSafe.
  • There is no Jev model ID on bedrock-runtime for Converse or InvokeModel.
  • TypeSafe documents one endpoint, api.typesafe.ai. We found no Bedrock-native adapter, inference profile, or PrivateLink.
  • Agent Toolkit for AWS guides coding agents with skills and authenticated AWS tooling. It does not host Jev and it is not a model-catalog listing.

A Lambda function that calls TypeSafe is your integration. It does not put Jev inside the Bedrock data perimeter, and Bedrock Guardrails do not wrap it.

Use Jev for bounded, typed decisions. Use Bedrock foundation models for language and complex reasoning. Use deterministic application logic and explicit policies to control side effects.

The default pattern is an application-owned pre-router. One server-side systemOne call. An allowlist in your code. Bedrock only on routes that need a draft. Jev is not invoked on every agent step, and it does not choose shell commands, URLs, SQL, or raw tool arguments.

Architecture diagram separating an AWS account — API Gateway, a server-side adapter, Amazon Bedrock, AgentCore Gateway, and CloudWatch — from the external TypeSafe Jev API reached through NAT egress

Figure 1. Production path. Jev stays outside the AWS account. The adapter owns the route. Gateway policy still has to allow any tool call.

LayerWhat runsWhat it must not do
EntryAPI Gateway, Lambda, or AgentCore RuntimeSend the raw request to Jev before auth and schema checks
DecisionServer adapter, POST /v1/systemone, model jev-1.13.0Return a tool name, URL, or SQL string for direct execution
RouteYour threshold and an allowlistTreat low confidence, timeout, or 429 as a category
LanguageBedrock Converse plus GuardrailsAsk Jev to write the reply because the decision was typed
Side effectsIAM, Gateway Cedar, a deterministic argument check, human approval where the impact is highUse Jev confidence as the only allow
NetworkNAT or other explicit egress to api.typesafe.ai on 443Assume a Bedrock VPC endpoint covers TypeSafe
SecretSecrets Manager (or the platform secret store) → TYPESAFE_API_KEYPut the key in a browser bundle or a CloudWatch message
ObserveCloudWatch: model id, outcome, latency, 429 count, input tokensLog the ticket body or the API key

For a VPC workload, the subnet needs a path out: NAT Gateway, or another egress design you already operate, plus a security group that allows TCP 443 to the TypeSafe API. Flow logs will show that destination. We did not find a TypeSafe PrivateLink or a Bedrock VPC endpoint that proxies Jev.

Where the decision sits in orchestration

Pick one insertion point. Do not stack all of them on every turn.

PatternUse it whenCost of the extra hop
Pre-router (default)The next step is one of a few workflows you can name in advanceOne TypeSafe call before any Bedrock tokens
Strands custom toolAn agent is already running and needs a bounded classification mid-turnOnly that step. Not every tool call.
Existing Bedrock Agent action groupYou already have an action group and a Lambda. Do not start a new Agents Classic build for this.Same external call, inside the older tool loop
Post-draft screenYou want a bounded property of a generated replyJev sees the draft, so the draft must be allowed to leave AWS
Async classifierCatalog or document volume where a sync hop would sit on the user pathSQS or EventBridge. Failures go to a DLQ, not to a default “approved”

Strands has no Jev provider. A custom tool should call the same adapter and return a route name your code already understands. The model that is driving the agent must not be free to invent a Gateway tool from a Jev string. If the product is a Strands agent on AgentCore Harness or Runtime, keep Jev beside that loop, not inside every iteration. LangGraph can host the same classify node. Jev is not the graph.

AgentCore Gateway’s MCP targets, Cedar policies, and Lambda request/response interceptors authorize and shape tool calls. They do not classify the user message, and they do not see TypeSafe. A request interceptor can enrich context before Cedar runs; that is still your code and your policy, not a Jev confidence check. Multi-account Gateway access is an account-boundary problem. It is not a reason to pretend the TypeSafe call stayed inside AWS.

Agent Toolkit skills help a coding agent follow AWS practice while you build this. They are not the production decision path.

TypeScript adapter

Context: Node.js 20+, @typesafe-ai/sdk, model jev-1.13.0. The module below is the companion file. DRY_RUN defaults to on, so importing it does not call TypeSafe. DRY_RUN=0 is the live path and still does not refund anyone.

The application lists the only categories Jev may return. refund_candidate opens review. It does not call a payments API. A timeout, a 429, and a low-confidence Choice are different outcomes. Noul uses its own threshold.

// examples/architecture-blog-2026/jev-typesafe-aws/route-support-ticket.ts
// DRY_RUN defaults on. No browser key. No refund call.

const MODEL_ID = "jev-1.13.0";
const CHOICE_CONFIDENCE_MIN = 0.8; // placeholder — calibrate on your set
const REFUND_NOUL_REVIEW_MIN = 0.85; // Noul probability, not Choice confidence

const SUPPORT_CATEGORIES = {
  order_status: "Tracking, delivery, or a missing parcel.",
  refund_candidate:
    "Duplicate charge or an explicit refund request. Opens review. Does not issue a refund.",
  product_question: "Fit, quality, or how to use an item.",
  other: "None of the above.",
} as const;

function applyPolicy(answers: {
  model: string;
  category: string;
  confidence: number;
  noul: number;
}) {
  if (answers.category === "refund_candidate") {
    if (answers.confidence < CHOICE_CONFIDENCE_MIN) {
      return { outcome: "human_review" as const, reason: "low_confidence" as const };
    }
    return { outcome: "review_refund" as const }; // review workflow, not a refund
  }
  if (answers.noul >= REFUND_NOUL_REVIEW_MIN) {
    return { outcome: "human_review" as const, reason: "refund_signal_disagreement" as const };
  }
  if (answers.category === "other" || answers.confidence < CHOICE_CONFIDENCE_MIN) {
    return { outcome: "human_review" as const, reason: "low_confidence" as const };
  }
  if (answers.category === "order_status" || answers.category === "product_question") {
    return { outcome: "draft_with_bedrock" as const, category: answers.category };
  }
  return { outcome: "human_review" as const, reason: "low_confidence" as const };
}

async function askJev(state: { ticket_message: string; refund_policy: string }) {
  const client = new TypeSafeClient({
    timeout: 8_000, // SDK default is 10_000 ms per attempt
    retry: { maxRetries: 1 }, // SDK default is 2
  });
  const result = await client.systemOne({
    model: MODEL_ID,
    state,
    questions: {
      category: choice("Which support category owns `ticket_message`?", SUPPORT_CATEGORIES),
      refund_requested: noul("Does `ticket_message` request a refund?"),
    },
  });
  return {
    model: result.model,
    category: result.answers.category.choice,
    confidence: result.answers.category.confidence,
    noul: result.answers.refund_requested.noul,
    inputTokens: result.usage.input_tokens,
  };
}

The full module catches APITimeoutError, RateLimitError, BadRequestError, and APIConnectionError, logs model, outcome, latency, input-token count, and requestId when the error is an APIError, and returns outcome: "unavailable". It does not log state or TYPESAFE_API_KEY. The SDK reads the key from the environment, refuses browser use unless you set dangerouslyAllowBrowser (do not), and defaults baseURL to https://api.typesafe.ai.

On the live path, load the key from Secrets Manager into the task environment. The caller that receives draft_with_bedrock may then call Bedrock. The caller that receives review_refund opens a human or policy workflow. Neither branch is implemented in the sample, on purpose.

A Strands tool, if you need one mid-turn, should call routeSupportTicket and return the outcome name. Shape only — this snippet is not the typechecked sample, and Strands will still try to call the tool when its model decides to:

const classifyTicket = tool({
  name: "classify_support_ticket",
  description: "Return an application route name. Does not refund or mutate orders.",
  inputSchema: z.object({
    ticketMessage: z.string(),
    refundPolicy: z.string(),
  }),
  callback: async (input) => {
    const route = await routeSupportTicket(input);
    return route.outcome;
  },
});

Prefer the pre-router so the agent model never chooses whether classification runs. The Python stub in the same folder (typesafe_sdk, system_one, DRY_RUN=1) is the same policy in the other SDK. Pydantic AI’s TypeSafeModel can map an output_type onto Jev questions; a Bedrock model behind FallbackModel still has to write tool arguments. Gateway policy still allows or denies the write.

E-commerce decision boundaries

These are designs, not FactualMinds customer results. There are no published agent engagements to cite here.

Support routing. Jev Choice over order_status, refund_candidate, product_question, and other, plus a Noul for refund intent. Application code opens the queue. A Bedrock model drafts a reply only after the route is draft_with_bedrock. A refund candidate enters review even when confidence is high.

Retrieval strategy. A second Choice can pick catalog, policy_docs, order_api, or human, but only if those strings are keys in a map you wrote. The map’s values are the Gateway tool names or internal handlers you already registered. If Jev returns something absent from the map, you escalate. Jev does not get to mint a tool.

Output screening. After Bedrock drafts a reply, deterministic checks come first: the order id matches the account, a required returns sentence is present, the refund amount was not invented. Use Jev only for a fuzzy property you cannot grep, such as “this draft promises a remedy the policy does not allow,” and only after you have labeled enough drafts to know the false-negative rate. A schema-valid “ok” is still not proof the draft is safe to send.

Async classification. Catalog copy, old tickets, or ingested documents belong on SQS or EventBridge, with a concurrency cap under the 80 requests/s published limit and a DLQ. Do not add a synchronous TypeSafe round trip to a product-page render to score a document you could have classified when it was written.

Sequence from request validation through a Jev decision, an application confidence check, and either a Bedrock draft, human review, or an error fallback

Figure 2. One request. Validation, one Jev call, then your policy. Errors and low confidence leave the happy path.

Security, privacy, and policy

Sending state to TypeSafe crosses a network and a processor boundary outside the AWS account. TypeSafe’s legal page points at a DPA, a privacy policy, and zero data retention for enterprise customers via sales. That is a contract you have to sign and configure. It is not a property of the default API, and it is not an AWS BAA. Do not promise residency because the rest of the stack is in us-east-1.

Minimum payload: the ticket text and the policy sentence the question needs. Not the full customer profile, not a PAN, not a clinical note.

Side effects stay on independent controls:

  • The adapter maps a category to an allowlisted operation.
  • IAM scopes what the task role can call in AWS.
  • AgentCore Gateway Cedar permits or forbids the tool. Forbid wins. No matching permit means deny.
  • A Lambda interceptor can enrich or strip a tool request. It should not “ask Jev again” as a substitute for Cedar.
  • Deterministic validation checks amounts, ids, and ownership against your database.
  • A person approves refunds, PII export, account changes, inventory mutations, and production deploys.

Security diagram: a Jev category stops at an application allowlist, while IAM, AgentCore Gateway policy, a deterministic check, and human approval remain separate controls

Figure 3. Jev suggests a label. The allowlist, IAM, Gateway policy, and a deterministic check each still have to pass. None of them reads Jev confidence as an allow.

What broke — Paper architecture, week of 15 Sep 2026 launch notes: put raw HIPAA support mail in Jev state to classify “refund vs medical question” before an AgentCore Gateway write. That design fails three independent controls at once. (1) The payload egresses to api.typesafe.ai; Bedrock Guardrails never see it. (2) Cedar on Gateway cannot authorize TypeSafe. (3) TypeSafe’s DPA / ZDR is an enterprise paperwork path, not an AWS BAA. Detection: NAT Gateway / VPC flow logs to TypeSafe. Rollback: classify with a Bedrock model in-region under the existing BAA, or strip to non-PHI features (queue enum, order-id only) before any third-party call. We did not run this against a client mailbox. We are refusing the design on controls, not on a measured latency.

Customer-origin text is hostile until you prove otherwise. TypeSafe does not treat state as an untrusted instruction channel by default. The same injection rule you use on Bedrock applies to the text you forward.

Evaluation, confidence, and fallback

Decide whether Jev earns the egress with a labeled set: anonymized tickets or synthetic tickets you wrote, with the category and the refund bit marked by a person. Compare at least:

ApproachWhat you learn
Rules, then Bedrock for the draftWhether the branch was already in the order system
Bedrock-only routingAccuracy and cost when one model both labels and writes
Bedrock with constrained outputWhether schema-bound generation is enough without a second vendor
Jev plus the allowlist in this postAccuracy, calibration, and the review rate on the same labels
HybridWhat fraction of tickets hit Jev, what fraction fall back, and the cost of both

Measure decision accuracy, confidence calibration, false positives and false negatives on refund_candidate, the share sent to review, end-to-end p50 / p95 / p99, API errors, 429s, timeouts, retries, and cost per successful task (Jev input, retries, NAT, Bedrock, and human review). Also count how many Bedrock calls and tool calls the router avoided or added. Do not promote Jev because a vendor multiplier looked large.

TypeSafe’s launch post claims 70–500 ms end-to-end and, on their workflow evals, 193.6× faster / 444.6× cheaper than frontier LLMs wrapped in the same decision API. They also wrote the caveat: those multipliers sit on the higher end, and the latency traces were generally run from West Coast laptops against a West Coast service. That is not the latency from your AWS region through NAT. We have not called the API, so this post has no first-party p50.

There is no universal confidence cutoff. 0.8 in the sample is a placeholder so the code has a branch. Fit the cutoff on your distribution. A low-confidence support category can fall through to a Bedrock classifier, a rules path, a clarification question, or a person. A timeout, 429, or 529 must not fall through as if Jev had picked order_status.

For a user-facing route, bound retries (the sample uses one retry and an 8 second attempt timeout, inside the SDK defaults of two retries and 10 seconds). Open the circuit if 429s cluster, and serve the in-account fallback. High-impact operations fail closed when the check does not finish: no refund, no export, no inventory write.

Fallback diagram: timeouts, HTTP 429, low confidence, and Bedrock failures end in review or an in-account path, and do not become approval to mutate an order

Figure 4. Failures are visible outcomes. None of them is an implicit allow.

Cost and latency

One synthetic row, not a second invented workload. Assume 1,000,000 support tickets and 500 input tokens each (message, a short policy snippet, and the question text), questions batched so the ticket is sent once. That is 500 MTok.

500 × $0.042 / MTok = $21 of Jev input. Output tokens are $0 on TypeSafe’s card.

That $21 excludes Lambda or Runtime, NAT bytes, retries, CloudWatch, the Bedrock draft, and review time. A 429 retry pays the input again if TypeSafe metered the attempt; confirm that on your invoice rather than assuming it away. Thirteen serial calls would re-pay a large state. TypeSafe’s parallel-questions cookbook, on jev-1.12, batched 13 questions over a ~54k-character article and reported 12.2× cheaper / 10.0× faster than 13 serial calls ($0.000497 vs $0.006090; 0.27 s vs 2.71 s). That is a document-dominated vendor example. A 500-token ticket will not print a 12×.

PathUse it whenWhat you pay besides “the model”Trade-off
Bedrock onlyOne model should both label and writeOutput tokens, Guardrails, tool callsNo TypeSafe egress. You still have to parse the label.
Rules, then BedrockThe branch is already in DynamoDB or the eventBedrock only for the draftDo not pay $0.042/MTok for an if
Jev, then BedrockThe label is closed-set and the payload may leave AWSJev input, NAT, then Bedrock if a draft is requiredExtra network hop. Best as a pre-router, not every step.
Jev aloneYou need a label and no customer-facing proseJev input, NAT, retriesNo reply text. Still not authorization.
Hybrid with fallbackLow confidence or a TypeSafe error must stay safeWhichever path ran, plus reviewA timeout is not a cheap success.

Platform context you already have: support-style AgentCore at 50K sessions/mo ~$791/mo. Jev’s $21 at a million tickets is a model-API line, not a replacement for that silhouette. AgentCore’s own controls for behavior and spend sit on the agent session; they do not meter api.typesafe.ai. For a Bedrock classifier on the same labels, use the Bedrock pricing page and the token-budget post. The worksheet leaves those cells as formulas so this page does not invent a second rate card.

Budget latency as a sum you measure: TypeSafe’s claimed 70–500 ms, plus your NAT and TLS, plus Bedrock only on routes that draft. Add the Gateway canary (~95 ms median tool RTT in the CRM assistant) only on turns that actually call a tool. Do not subtract Jev from that canary. We have not timed Jev in that account.

Named substitutes

If you need…Use thisWhen
In-account classificationAmazon Nova Micro (or another small Bedrock model) on ConversePHI, residency, or IAM must stay in the account. Price from the Bedrock pricing page.
Denied topics, PII filters, groundingBedrock GuardrailsThe generative call is already on Bedrock.
“Is this answer allowed by policy?”Automated Reasoning ChecksFormal logic, not a probability.
Deterministic branchesStep Functions plus DynamoDB or EventBridgeThe set is in your database.
An explicit agent graphLangGraph on AgentCore RuntimeJev can be a classify node. It is not the graph.
A single-domain agent loopStrands on AgentCoreAdd a custom tool only for a bounded question. Do not add a third-party model to skip configuration.
Extract-then-pickA parser, then a Jev Choice or Bedrock structured outputDo not ask Jev to generate the value.

We recommend the pre-router in front of Bedrock, not Jev instead of Bedrock, when the decision is closed-set, legal has accepted the egress, and you will operate confidence and 429 metrics for a shadow week. We recommend Nova Micro or rules when the payload cannot leave, or when you have not yet run that week.

What to Do This Week

  1. Residency first. If state can contain PHI, PCI, or a named-region clause, stop. Stay on Bedrock.
  2. Pin jev-1.13.0. Re-read the models page the day you deploy. The 11 Oct 2026 limits were 80 requests/s and 100,000 tokens/s.
  3. Write atomic questions against one anonymized ticket. No “decide the action.” Include other on every Choice.
  4. Put the key in Secrets Manager. Confirm the client is not constructed in a browser bundle.
  5. Log outcome, model, latency, and token count to CloudWatch. Do not log the ticket.
  6. Shadow against a Bedrock classifier or your rules before any customer traffic. Promote only on disagreements you can explain.
  7. Keep Cedar and a deterministic check on the write. Run monday-checklist.md and fill cost-worksheet.csv with your token counts.

If you only do one thing: do not send customer text to TypeSafe until legal has a sentence about egress.

What This Post Doesn’t Cover

  • We have not called the Jev API. No first-party p50/p95, no error rate, no 429 trace. The 70–500 ms band and the 193.6× / 444.6× multipliers remain vendor claims.
  • The TypeScript module typechecks against @typesafe-ai/sdk@0.6.0 (11 Oct 2026) in a side directory. It does not perform a live call. The Strands tool() sketch was checked against Strands’ custom-tool docs and was not executed.
  • Jev was not in the Bedrock model catalog or Marketplace listing we could see on 11 Oct 2026. A future listing would change the IAM and network story. This page would be wrong until it is revised.
  • No documented PrivateLink or Bedrock VPC endpoint for TypeSafe. If AWS or TypeSafe publishes one, the egress section changes.
  • Enterprise ZDR, DPA terms, and any BAA-equivalent. Read the contract. Do not infer it from this post.
  • A production Strands or AgentCore deploy of the adapter. The sample returns a route object.
  • Any FactualMinds AI-agent case study. Permitted proof here is the field guide, the calculators, the Gateway canary, and cited vendor numbers.

Editable diagram sources: examples/architecture-blog-2026/jev-typesafe-aws/diagrams/.

Frequently asked questions

What is Jev from TypeSafe AI?
Jev is TypeSafe AI’s first System One model, launched 15 Sep 2026. You send unstructured state plus typed questions (Noul, Choice, Score) and get structured probabilities your code can branch on. It does not generate chat replies, emails, or tool-argument JSON. Pin jev-1.13.0 once you tune thresholds; the jev-latest alias moves when TypeSafe ships a release.
Is Jev available on Amazon Bedrock?
No. Checked 11 Oct 2026, Jev is not in the Amazon Bedrock model catalog and there is no Converse or InvokeModel model ID for it. Jev is a TypeSafe decision service at POST https://api.typesafe.ai/v1/systemone. Calling it from Lambda or AgentCore Runtime is an external API composition, not native Bedrock adoption. There is no documented VPC endpoint or PrivateLink for that hop.
When is Jev a good fit next to Amazon Bedrock?
When the answer space is closed and your code, not a language model, must pick the next hop: route a ticket, choose an allowlisted retrieval mode, or screen a draft for a bounded property. Use Jev for that System-1 decision. Keep a Bedrock foundation model for generation and complex reasoning. Keep IAM, AgentCore Gateway policy, and deterministic checks on any side effect.
When should we NOT use Jev on AWS?
Skip Jev when you need generated text or code, images or audio as input, or the model to write tool arguments. Skip it when PHI, PCI, or a sovereignty contract cannot leave AWS. Skip it when Step Functions plus explicit rules already enumerate the set. Skip it as a calculator. TypeSafe’s jev-1.13 jaggedness notes say counting, date arithmetic, and interpolated Score magnitudes belong in code.
What could go wrong if we send production tickets to Jev?
The state field is the content Jev judges. If that state is a support email, it leaves your account for TypeSafe, and Bedrock Guardrails never see that hop. Gateway Cedar cannot authorize a third-party model. Checked 11 Oct 2026, TypeSafe publishes 100,000 tokens per second and 80 requests per second for jev-1.13.0, and says those limits can change without notice. A 429 or a timeout is not a decision. Pin the versioned model ID before you promote a confidence threshold.
Does a typed Jev answer mean the decision is correct?
No. TypeSafe means the model cannot emit a string outside the schema you defined. A value can match the schema and still be the wrong category. The Register (16 Sep 2026) made the same distinction. Choice and Score confidence is not a guarantee, and Noul does not even return a separate confidence field. Gate money and PII writes in your code, then with IAM and Gateway policy, not with the score.
Can Jev replace Bedrock Guardrails or Automated Reasoning Checks?
No. Guardrails block denied topics, PII leakage, and grounding failures on Bedrock inference. Automated Reasoning Checks validate a generated answer against a formal policy. Jev scores or classifies text you already have. Run them as different layers. Jev does not see Bedrock’s IAM boundary and does not prove logical consistency with a policy document you encoded in Bedrock.
Where should Jev sit in a Strands or AgentCore agent?
Default to a pre-router in your server code: one Jev call, then an allowlisted route, then Bedrock only if that route needs language. Strands has no native Jev provider. A custom tool that calls the same adapter is reasonable mid-turn, but do not invoke Jev on every agent step and do not let it name arbitrary tools. A high-confidence category is still not permission to refund, export PII, or change an account.
Palaniappan P
Palaniappan P

AWS Cloud Architect & AI Expert

AWS-certified cloud architect and AI expert with deep expertise in cloud migrations, cost optimization, and generative AI on AWS.

AWS ArchitectureCloud MigrationGenAI on AWSCost OptimizationDevOps

Recommended Reading

Explore All Articles »
7 min

Amazon Bedrock Automated Reasoning Checks: Production Hallucination Prevention with Math-Validated Factuality

Bedrock Automated Reasoning checks ground LLM outputs against formal logic policies you encode and mathematically validate that the response is consistent with the policy. This guide covers when to use Automated Reasoning vs contextual grounding, how to author the policy in production, the integration with Bedrock Guardrails, and the regulated use cases (HR, insurance, eligibility, regulatory determinations) where the difference matters.