AWS says Transcribe now supports your own encryption keys - but tells you almost nothing else
Amazon has quietly added customer-managed KMS keys to Transcribe's custom resources, though its own announcement is so thin it raises more questions than it answers.
Amazon has posted a “what’s new” update saying that Amazon Transcribe, its speech-to-text service, now lets customers use their own customer-managed AWS Key Management Service (KMS) keys to encrypt custom resources, rather than relying solely on AWS-managed keys. That’s the entirety of the confirmed claim, dated 25 September 2026.
What’s actually known
The known fact here is narrow: a feature toggle exists, and it’s been switched on. AWS’s own page offers no explanation of which “custom resources” are covered, what changes for existing users, whether there’s a migration path for anything encrypted under the old AWS-managed keys, or which regions get it first. The page we were pointed to is, in practice, mostly site navigation chrome - menus for re:Invent, Bedrock, EC2 and pricing calculators - with the substantive announcement reduced to a single headline-length sentence. That’s not unusual for AWS’s high-volume changelog, but it does mean there’s nothing here to independently verify beyond “AWS says so.”
What customer-managed keys actually mean
For context: KMS keys are the cryptographic keys AWS uses to encrypt data at rest. By default, many AWS services use “AWS-managed” keys, which Amazon creates, rotates and controls on your behalf. A “customer-managed” key is one you create and control yourself - you decide who can use it, when it rotates, and you can revoke access entirely, which effectively renders the encrypted data unreadable. This matters mainly for organisations with strict compliance obligations (finance, healthcare, government contractors) who need to prove they - not their cloud vendor - hold the keys to their own data, including things transcribed through the service, such as custom vocabularies or tuning resources built to improve accuracy for specialist terminology.
So who is actually affected
Almost certainly not the casual user. This is an enterprise and compliance feature, not a consumer one. If you’ve never touched AWS KMS or don’t know what a “custom vocabulary” in Transcribe is, this change alters nothing about how the service works, its accuracy or its cost for you. It matters to AWS customers - developers and enterprise security teams - who build products on top of Transcribe and need to satisfy auditors that encryption keys never leave their control. Even for that group, the announcement doesn’t specify pricing implications (KMS customer-managed keys typically carry their own per-key and per-request charges on AWS, separate from Transcribe itself), nor does it clarify whether existing custom resources need re-encrypting or whether this only applies going forward.
What to do about it
If you’re an AWS customer already using Transcribe’s custom resources in a regulated environment, this is worth a look at AWS’s documentation before assuming it solves a compliance requirement - the “what’s new” post alone isn’t detailed enough to plan a migration around. For everyone else, this is routine AWS plumbing: a security control being extended to another corner of a sprawling service catalogue, announced in the same terse format AWS uses for hundreds of similar updates each year.
The takeaway
Nothing here is broken, dangerous or newly risky - it’s an incremental security option for a narrow slice of enterprise users. The more interesting story is what AWS didn’t publish: no detail on scope, pricing or migration, which is worth noting before treating any cloud “what’s new” post as the full picture rather than a marketing summary of one.