OpenAI GPT, OpenAI GPT OSS, and NVIDIA Nemotron models on Amazon Bedrock receive FedRAMP High and DoD IL-4/5 approval in AWS GovCloud (US)
Federal agencies can now run OpenAI GPT and NVIDIA Nemotron models on sensitive government data with full FedRAMP High and DoD IL-5 authorization.
View original announcement →Visual Summary
What's New
OpenAI GPT, OpenAI GPT OSS, and NVIDIA Nemotron models on Amazon Bedrock have received FedRAMP High and DoD Cloud Computing Security Requirements Guide (CC SRG) Impact Level 4 and 5 approvals within AWS GovCloud (US) Regions. This makes these frontier and open-source models available to federal agencies, defense organizations, and public sector entities that must meet stringent government security and compliance mandates. The models are delivered through Mantle, Amazon Bedrock's next-generation distributed inference engine, ensuring high-performance, secure serverless inference.
How It Works
- Mantle Inference Engine: The models run on Mantle, a next-generation distributed inference engine built into Amazon Bedrock that provides high-performance serverless inference without requiring customers to manage underlying infrastructure.
- Zero Operator Access: Mantle enforces a zero-operator-access model, meaning no AWS personnel can access customer data or model inputs/outputs during inference, a critical requirement for government workloads.
- Automated Capacity Management: Mantle handles capacity scaling automatically, eliminating the need for manual provisioning and ensuring consistent performance under variable government workloads.
- OpenAI API Compatibility: The inference engine provides out-of-the-box compatibility with OpenAI API specifications, allowing agencies to migrate or integrate existing OpenAI-compatible tooling without code rewrites.
- AWS GovCloud (US) Isolation: All inference runs within the physically and logically isolated AWS GovCloud (US) Regions, which are restricted to US persons and US-based infrastructure to satisfy ITAR, FedRAMP, and DoD requirements.
- Compliance Authorization: The models have been formally authorized under FedRAMP High baseline and DoD CC SRG IL-4 (covering Controlled Unclassified Information) and IL-5 (covering National Security Systems data), enabling use with sensitive government data.
- Amazon Bedrock Security Controls: Standard Bedrock security features—including Guardrails, IAM-based access policies, and VPC integration—remain available to further harden government deployments.
Why It's Important
- Unlocks Frontier AI for Sensitive Government Data: Federal agencies can now use state-of-the-art OpenAI GPT and NVIDIA Nemotron models on data classified up to DoD IL-5, a threshold previously inaccessible with these commercial frontier models.
- Reduces Compliance Burden: Pre-authorized FedRAMP High and IL-4/5 status means agencies do not need to independently assess and authorize these models, significantly shortening the Authority to Operate (ATO) process.
- Enables Defense-Grade Generative AI Applications: DoD components, intelligence-adjacent agencies, and defense contractors can now build production-grade generative AI workflows—RAG pipelines, agents, summarization—on classified-adjacent data without leaving the GovCloud boundary.
- Broadens Model Choice in Regulated Environments: Previously, government customers were limited to a narrower set of compliant models; this expansion brings leading commercial and open-source models into the compliant portfolio.
- Supports Zero-Trust and Data Sovereignty Requirements: Zero operator access and GovCloud's US-person-only staffing model directly address zero-trust and data sovereignty mandates increasingly required by federal policy.
- Accelerates Public Sector AI Modernization: With compliance barriers removed, agencies can move faster from AI pilots to production deployments, supporting broader federal AI modernization initiatives.
How It's Different
- FedRAMP High + IL-5 Dual Authorization: Unlike standard commercial Bedrock regions, these models carry both FedRAMP High and DoD IL-5 authorization simultaneously, covering a wider range of government use cases in a single service.
- Mantle's Zero Operator Access vs. Standard Managed Services: Traditional managed AI services may allow provider personnel access for support or debugging; Mantle's architecture explicitly eliminates this, a differentiator for sensitive government workloads.
- OpenAI Models in a Sovereign Cloud: OpenAI GPT models are typically accessed via OpenAI's commercial API, which does not hold FedRAMP High or DoD IL-5 authorization; this announcement provides a compliant, sovereign alternative on AWS infrastructure.
- Serverless with No Capacity Planning: Unlike provisioned throughput options that require pre-commitment, Mantle delivers serverless inference with automated capacity management, reducing operational overhead for government IT teams.
- OpenAI API Spec Compatibility in GovCloud: The native OpenAI API compatibility within a FedRAMP High boundary is unique, allowing agencies to reuse existing OpenAI-compatible SDKs and integrations without modification.
- Bundled with Full Bedrock Ecosystem: Government users get access to Bedrock Guardrails, Knowledge Bases, Agents, and Data Automation alongside these models—a more complete platform than point-solution model APIs.
When to Prefer It
- Processing Controlled Unclassified Information (CUI): When an agency needs to run LLM inference on CUI data that requires IL-4 or IL-5 protection, these models are the appropriate choice over commercial-region alternatives.
- DoD and Intelligence Community Workloads: Defense organizations building AI-assisted decision support, document analysis, or mission planning tools that must remain within DoD CC SRG boundaries should use these models.
- Migrating from OpenAI Commercial API to a Compliant Environment: Organizations currently using OpenAI APIs in non-compliant environments who need to achieve FedRAMP High authorization can migrate to these Bedrock-hosted models with minimal code changes.
- Building FedRAMP High SaaS Products for Government: ISVs and system integrators building software products that will be sold to federal agencies and need to inherit FedRAMP High authorization from their cloud provider.
- Rapid ATO Scenarios: When a program office needs to deploy generative AI quickly and cannot afford a lengthy independent model assessment, leveraging pre-authorized models on Bedrock shortens the ATO timeline.
- Open-Source Model Deployment Without Infrastructure Management: When agencies want the flexibility of NVIDIA Nemotron open-source models but lack the infrastructure team to self-host them securely at IL-4/5, the serverless Bedrock option is preferable.
- Multi-Model Evaluation in a Compliant Context: When government data scientists need to benchmark OpenAI GPT, GPT OSS, and Nemotron models against each other using sensitive data, Bedrock's unified compliant environment enables side-by-side evaluation safely.
Availability
- Status: Generally Available (GA) as of June 25, 2026.
- Regions: Available in AWS GovCloud (US) Regions (us-gov-west-1 and us-gov-east-1); not available in standard commercial AWS regions under these compliance authorizations.
- Compliance Authorizations: FedRAMP High baseline and DoD CC SRG Impact Level 4 and Impact Level 5 approved.
- Models Covered: OpenAI GPT (frontier), OpenAI GPT OSS (open-source variants), and NVIDIA Nemotron model families on Amazon Bedrock.
- Inference Model: Serverless inference via the Mantle engine; provisioned throughput availability for these models in GovCloud should be confirmed via the Bedrock console or AWS account team.
- Pricing: Follows Amazon Bedrock's standard on-demand token-based pricing model; GovCloud pricing may differ from commercial regions and should be verified in the AWS GovCloud pricing documentation.
- Access Requirements: Requires an AWS GovCloud (US) account, which is restricted to US persons and US-based entities; standard AWS commercial accounts cannot access GovCloud resources.
- Limitations: Specific model versions and feature parity with commercial Bedrock regions (e.g., fine-tuning, batch inference) should be verified in the Amazon Bedrock GovCloud documentation, as not all capabilities may be available at launch.
Related Resources
- https://aws.amazon.com/bedrock/?trk=7ecf60df-6136-414c-a7c3-6aa4d2d6019f&sc_channel=ps&ef_id=EAIaIQobChMI0-nJtciglQMVh3JHAR3wnSV-EAAYASAAEgIIGvD_BwE&gads_camp=23532472972&gads_ag=194311072004&gads_ad=795877020842&gads_kw=amazon%20bedrock&gads_matchtype=e&gads_network=g&gads_device=c&gads_geo=9007742&gad_campaignid=23532472972&gclid=EAIaIQobChMI0-nJtciglQMVh3JHAR3wnSV-EAAYASAAEgIIGvD_BwE
- https://docs.aws.amazon.com/bedrock/
- https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-compliance.html