AWS is changing the default L7 protection path, and the real risk is a quiet gap during the handoff if teams assume the old behavior keeps working. The new AWS WAF Anti-DDoS managed rule group starts in Count mode on eligible web ACLs, so it observes traffic first; the current application-layer mitigation path retires on Jan. 1, 2027.
AWS Shield Advanced will begin adding the Anti-DDoS managed rule group on July 27. AWS says it will not interrupt traffic at first, but the new rule group still needs to be validated and tuned before the old mitigation path disappears.
The change gives operators time to compare detections against live traffic, but it also means “enabled” is no longer enough as a control check. If the new rule group is left unreviewed, the protection posture can drift between rollout and retirement.