🔴 REAL INCIDENT: On 2 March 2026, Amazon shoppers saw wrong delivery times at checkout. Internal documents put the damage at nearly 120,000 lost orders and about 1.6 million website errors and name the Q coding assistant as one of the primary contributors. Amazon says only one incident it reviewed was AI-related, and none involved AI-written code (Business Insider, 10 Mar 2026)
What Happened
On 2 March, customers across Amazon's marketplaces added items to their carts and got incorrect delivery times. According to internal documents obtained by Business Insider, the incident led to nearly 120,000 lost orders and roughly 1.6 million website errors.
An internal review named Amazon's AI coding assistant Q as "one of the primary contributors" that triggered the event. One internal document drew the wider lesson:
**"GenAI's usage in control plane operations will accelerate exposure of sharp edges and places where guardrails do not exist. We need investment in control plane safety."**
It wasn't the only bad week. Three days later, on 5 March, a separate outage caused a 99% drop in orders across North American marketplaces and 6.3 million lost orders, per the same documents. That one traced to a production change deployed without Amazon's formal approval process, Modeled Change Management. BI doesn't link it to AI.
Amazon's Side
Amazon disputes the AI framing, and that needs saying plainly.
An Amazon spokesperson told BI that only one incident reviewed at the 10 March meeting was AI-related, and that none of them involved AI-written code. Amazon also said AWS was not involved in any of these incidents, and called the meeting part of a regular weekly review: "As part of normal business, the meeting will include a review of the availability of our website and app."
Those two positions can both be true. "Q was a primary contributor" and "no AI-written code" aren't a contradiction if the assistant was used for something other than writing code, like running operations or proposing changes. The documents point that way: the "sharp edges" warning is about GenAI in control plane operations, not about generated source code. Neither BI nor Amazon spells out exactly what Q did.
Two more details cut both ways. CNBC reported that a bullet in an internal document citing "GenAI-assisted changes" was deleted before the meeting. And the Financial Times reported that junior and mid-level engineers would need senior sign-off on AI-assisted changes. Amazon told BI that claim is not accurate.
Amazon then went further on its own site. In a post titled Correcting the Financial Times report about recent Amazon.com service incidents and AI, Amazon said the FT had "corrected some of its initial assertions." According to Amazon:
- Only one of the recent incidents "involved AI tools in any way," and in that case "the cause was unrelated to AI." Amazon said its systems let an engineering team's user error have broader impact than it should have.
- That one incident came from an engineer "following inaccurate advice that an AI tool inferred from an outdated internal wiki," and none involved AI-written code.
- Reports that AWS was involved, or that Amazon introduced new approval requirements for engineers working with AI tools, are "false."
That last point bears on the title. The two-person review described below comes from Business Insider's reporting on internal documents. Amazon's correction denies new approval requirements for engineers using AI tools. It doesn't mention the 90-day policy by name, but it disputes the idea that Amazon added sign-off rules in response to AI.
Who Ran It / What Broke
Who ran it: Amazon's e-commerce organisation under Dave Treadwell, SVP of e-commerce services. On 10 March he told staff that a "trend of incidents" had emerged since Q3 2025, including "several major" ones in recent weeks.
What broke, per the internal documents, wasn't just one tool:
- "High blast radius changes." Updates spread widely because control planes lacked suitable safeguards.
- Data corruption that took hours to unwind.
- Basic controls missing or bypassed, including the requirement for two people to authorise code changes.
- On 5 March: "No automated pre-deployment validation. Single authorized operator could execute a high-blast-radius config change with no guardrails."
The FT, which read a briefing note for the meeting, listed one contributing factor as "novel GenAI usage for which best practices and safeguards are not yet fully established."
Controlled Friction
Amazon's response is the useful part. Treadwell wrote:
**"We are implementing temporary safety practices which will introduce controlled friction to changes in the most important parts of the Retail experience. In parallel, we will invest in more durable solutions including both deterministic and agentic safeguards."**
According to BI's reporting on internal documents (which Amazon disputes in part; see Amazon's Side), the 90-day temporary policy covers roughly 335 "Tier-1 systems", services that can directly affect consumers and have had multiple order-impacting incidents since last year. Under it:
- Engineers need two people to review their work before code changes.
- Changes go through an internal documenting and approval tool.
- An automated system enforces Amazon's central reliability engineering rules.
- Tier-1 owners and Director- and VP-level leaders must audit all production code change activity in their orgs.
Note the word pairing: deterministic and agentic. Amazon isn't banning AI tools. It's putting rules that behave the same way every time between those tools and production.
Not the Kiro Story
We've already covered the December 2025 AWS Kiro incident, where an AI tool took down a cost calculator for 13 hours (Kiro post). This is a different business (retail, not AWS), a different tool, and a different fix. Amazon says AWS wasn't involved here.
The Governance Gap
AI coding tools let engineers produce far more change than before. The review process was built for human pace. When volume goes up and the checks stay the same, or get skipped, the gap shows up in production.
Amazon's own list doubles as a checklist:
- Two-person review on high-blast-radius systems, enforced by tooling, not by habit.
- Formal change records for anything touching checkout, pricing, delivery promises, or orders.
- Automated pre-deployment validation that can't be waved through by one operator.
- Deterministic gates first, AI-assisted review second.
- Audit what actually shipped, not what people say shipped.
This is where a control layer like Supervaize fits: AI-proposed actions pass through approval rules and leave a record before they touch production.
Takeaway
Amazon's internal documents say an AI assistant helped break checkout delivery times for a day that cost nearly 120,000 orders. Amazon says only one incident was AI-related and no AI-written code was involved. Either way, the company's answer was the same: slow down the most important changes on purpose.
The lesson: AI throughput needs deterministic safeguards before it touches production. "Controlled friction" isn't a step backward. It's the price of moving faster safely.
Sources
- Business Insider (Eugene Kim): Amazon orders 90-day reset after code mishaps cause millions of lost orders (10 Mar 2026). Primary source. 2 Mar and 5 Mar figures, Q line, quotes, 90-day policy, Amazon statements.
- Financial Times: Amazon holds engineering meeting following AI-related outages (10 Mar 2026). Paywalled. "Deep dive" meeting, briefing-note contributing factors, senior sign-off claim.
- CNBC: Amazon plans 'deep dive' internal meeting to address outages (10 Mar 2026). Deleted GenAI bullet; Amazon statement.
- Amazon: *Correcting the Financial Times report about recent Amazon.com service incidents and AI*. Amazon's own account: FT corrections, one AI-tool incident (outdated wiki), no AI-written code, denial of AWS involvement and of new AI approval requirements.
