← Back to all announcements
★★★★★ 25/06/2026

OpenAI GPT, OpenAI GPT OSS, and NVIDIA Nemotron models on Amazon Bedrock receive FedRAMP High and DoD IL-4/5 approval in AWS GovCloud (US)

Federal agencies can now run OpenAI GPT and NVIDIA Nemotron models on sensitive government data with full FedRAMP High and DoD IL-5 authorization.

View original announcement →

Visual Summary

graph TD A{{FedRAMP High & DoD IL-4/5 Models on Bedrock}}:::announced B(Amazon Bedrock):::compute C([Mantle Inference Engine]):::feature D([Zero Operator Access]):::feature E([OpenAI API Compatibility]):::feature F(AWS GovCloud US):::compute G((Federal Agencies)):::external H((DoD Organizations)):::external I([Automated Capacity Mgmt]):::feature G ==>|"deploy apps"| A H ==>|"classified workloads"| A A -->|"runs on"| B B -->|"powered by"| C C -->|"enforces"| D C -->|"provides"| E C -->|"scales via"| I A -->|"isolated within"| F classDef announced fill:#ff9900,stroke:#ec7211,color:#fff,font-weight:bold classDef compute fill:#e3f2fd,stroke:#1565c0,color:#1565c0 classDef storage fill:#e8f5e9,stroke:#2e7d32,color:#2e7d32 classDef feature fill:#fff3e0,stroke:#e65100,color:#e65100 classDef external fill:#f5f5f5,stroke:#616161,color:#616161

What's New

OpenAI GPT, OpenAI GPT OSS, and NVIDIA Nemotron models on Amazon Bedrock have received FedRAMP High and DoD Cloud Computing Security Requirements Guide (CC SRG) Impact Level 4 and 5 approvals within AWS GovCloud (US) Regions. This makes these frontier and open-source models available to federal agencies, defense organizations, and public sector entities that must meet stringent government security and compliance mandates. The models are delivered through Mantle, Amazon Bedrock's next-generation distributed inference engine, ensuring high-performance, secure serverless inference.

How It Works

  • Mantle Inference Engine: The models run on Mantle, a next-generation distributed inference engine built into Amazon Bedrock that provides high-performance serverless inference without requiring customers to manage underlying infrastructure.
  • Zero Operator Access: Mantle enforces a zero-operator-access model, meaning no AWS personnel can access customer data or model inputs/outputs during inference, a critical requirement for government workloads.
  • Automated Capacity Management: Mantle handles capacity scaling automatically, eliminating the need for manual provisioning and ensuring consistent performance under variable government workloads.
  • OpenAI API Compatibility: The inference engine provides out-of-the-box compatibility with OpenAI API specifications, allowing agencies to migrate or integrate existing OpenAI-compatible tooling without code rewrites.
  • AWS GovCloud (US) Isolation: All inference runs within the physically and logically isolated AWS GovCloud (US) Regions, which are restricted to US persons and US-based infrastructure to satisfy ITAR, FedRAMP, and DoD requirements.
  • Compliance Authorization: The models have been formally authorized under FedRAMP High baseline and DoD CC SRG IL-4 (covering Controlled Unclassified Information) and IL-5 (covering National Security Systems data), enabling use with sensitive government data.
  • Amazon Bedrock Security Controls: Standard Bedrock security features—including Guardrails, IAM-based access policies, and VPC integration—remain available to further harden government deployments.

Why It's Important

  • Unlocks Frontier AI for Sensitive Government Data: Federal agencies can now use state-of-the-art OpenAI GPT and NVIDIA Nemotron models on data classified up to DoD IL-5, a threshold previously inaccessible with these commercial frontier models.
  • Reduces Compliance Burden: Pre-authorized FedRAMP High and IL-4/5 status means agencies do not need to independently assess and authorize these models, significantly shortening the Authority to Operate (ATO) process.
  • Enables Defense-Grade Generative AI Applications: DoD components, intelligence-adjacent agencies, and defense contractors can now build production-grade generative AI workflows—RAG pipelines, agents, summarization—on classified-adjacent data without leaving the GovCloud boundary.
  • Broadens Model Choice in Regulated Environments: Previously, government customers were limited to a narrower set of compliant models; this expansion brings leading commercial and open-source models into the compliant portfolio.
  • Supports Zero-Trust and Data Sovereignty Requirements: Zero operator access and GovCloud's US-person-only staffing model directly address zero-trust and data sovereignty mandates increasingly required by federal policy.
  • Accelerates Public Sector AI Modernization: With compliance barriers removed, agencies can move faster from AI pilots to production deployments, supporting broader federal AI modernization initiatives.

How It's Different

  • FedRAMP High + IL-5 Dual Authorization: Unlike standard commercial Bedrock regions, these models carry both FedRAMP High and DoD IL-5 authorization simultaneously, covering a wider range of government use cases in a single service.
  • Mantle's Zero Operator Access vs. Standard Managed Services: Traditional managed AI services may allow provider personnel access for support or debugging; Mantle's architecture explicitly eliminates this, a differentiator for sensitive government workloads.
  • OpenAI Models in a Sovereign Cloud: OpenAI GPT models are typically accessed via OpenAI's commercial API, which does not hold FedRAMP High or DoD IL-5 authorization; this announcement provides a compliant, sovereign alternative on AWS infrastructure.
  • Serverless with No Capacity Planning: Unlike provisioned throughput options that require pre-commitment, Mantle delivers serverless inference with automated capacity management, reducing operational overhead for government IT teams.
  • OpenAI API Spec Compatibility in GovCloud: The native OpenAI API compatibility within a FedRAMP High boundary is unique, allowing agencies to reuse existing OpenAI-compatible SDKs and integrations without modification.
  • Bundled with Full Bedrock Ecosystem: Government users get access to Bedrock Guardrails, Knowledge Bases, Agents, and Data Automation alongside these models—a more complete platform than point-solution model APIs.

When to Prefer It

  • Processing Controlled Unclassified Information (CUI): When an agency needs to run LLM inference on CUI data that requires IL-4 or IL-5 protection, these models are the appropriate choice over commercial-region alternatives.
  • DoD and Intelligence Community Workloads: Defense organizations building AI-assisted decision support, document analysis, or mission planning tools that must remain within DoD CC SRG boundaries should use these models.
  • Migrating from OpenAI Commercial API to a Compliant Environment: Organizations currently using OpenAI APIs in non-compliant environments who need to achieve FedRAMP High authorization can migrate to these Bedrock-hosted models with minimal code changes.
  • Building FedRAMP High SaaS Products for Government: ISVs and system integrators building software products that will be sold to federal agencies and need to inherit FedRAMP High authorization from their cloud provider.
  • Rapid ATO Scenarios: When a program office needs to deploy generative AI quickly and cannot afford a lengthy independent model assessment, leveraging pre-authorized models on Bedrock shortens the ATO timeline.
  • Open-Source Model Deployment Without Infrastructure Management: When agencies want the flexibility of NVIDIA Nemotron open-source models but lack the infrastructure team to self-host them securely at IL-4/5, the serverless Bedrock option is preferable.
  • Multi-Model Evaluation in a Compliant Context: When government data scientists need to benchmark OpenAI GPT, GPT OSS, and Nemotron models against each other using sensitive data, Bedrock's unified compliant environment enables side-by-side evaluation safely.

Availability

  • Status: Generally Available (GA) as of June 25, 2026.
  • Regions: Available in AWS GovCloud (US) Regions (us-gov-west-1 and us-gov-east-1); not available in standard commercial AWS regions under these compliance authorizations.
  • Compliance Authorizations: FedRAMP High baseline and DoD CC SRG Impact Level 4 and Impact Level 5 approved.
  • Models Covered: OpenAI GPT (frontier), OpenAI GPT OSS (open-source variants), and NVIDIA Nemotron model families on Amazon Bedrock.
  • Inference Model: Serverless inference via the Mantle engine; provisioned throughput availability for these models in GovCloud should be confirmed via the Bedrock console or AWS account team.
  • Pricing: Follows Amazon Bedrock's standard on-demand token-based pricing model; GovCloud pricing may differ from commercial regions and should be verified in the AWS GovCloud pricing documentation.
  • Access Requirements: Requires an AWS GovCloud (US) account, which is restricted to US persons and US-based entities; standard AWS commercial accounts cannot access GovCloud resources.
  • Limitations: Specific model versions and feature parity with commercial Bedrock regions (e.g., fine-tuning, batch inference) should be verified in the Amazon Bedrock GovCloud documentation, as not all capabilities may be available at launch.

Tags

Servicesbedrock
Typesecurityga-launch
Conceptsgenaillminference
Use Casesgovernment
Providersopenainvidia
GeographyAMERICAS

Related Resources

AI Radar AWS

AWS AI/ML news — curated, researched, explained

An automated intelligence platform that curates, researches, and analyzes AWS AI/ML/GenAI announcements daily. Every report is backed by real research — the system reads linked blog posts and documentation to provide accurate, in-depth analysis.

How Each Report Is Generated

  1. Collection — Daily monitoring of the AWS "What's New" RSS feed
  2. Filtering — AI-powered relevance detection for AI/ML/GenAI topics
  3. Taxonomy Tagging — LLM-based classification across 6 dimensions
  4. Importance Scoring — Point-based system with tag bonuses (1-5 stars)
  5. Research Phase — Follows links to blog posts and documentation
  6. Report Generation — Claude Sonnet produces structured 6-section analysis
  7. Visual Summary — Claude Opus generates Mermaid diagrams for key items
  8. Publishing — Static website rebuilt and deployed via CloudFront

Features

  • Faceted filtering by service, type, concept, and more
  • Multi-dimensional taxonomy with 80+ tags across 6 dimensions
  • Geographic availability badges (Global, APJ, EMEA, AMER) with filtering
  • Timeline visualization of announcement volume
  • PDF export for offline reading
  • Mermaid visual summaries for key announcements
  • Daily automated updates — no manual curation
What makes this different: Each report involves a dedicated research phase where the system reads linked blog posts and AWS documentation pages. This produces analysis that goes beyond the original announcement text.

Technology

Built with Python, AWS Lambda, Amazon Bedrock (Claude Sonnet 4.6, Opus 4.6, Haiku 4.5), S3, CloudFront, WAF, EventBridge, and CDK.

Open Source

This project is open source. Fork it, customize it for your needs, and deploy your own instance.
📦 github.com/bbonik/ai-radar-aws

How Importance Scoring Works

Each announcement receives a point score based on multiple factors. The total score maps to a 1-5 star rating:

1★ < 2 pts 2★ ≥ 2 pts 3★ ≥ 3.5 pts 4★ ≥ 5 pts 5★ ≥ 6.5 pts

Point Breakdown

FactorPointsWhen
Core AI service (Bedrock, AgentCore, SageMaker AI)+4Service named in title
Key AI service (SageMaker, Kiro, QuickSight)+2Service named in title
Other AI-related service+1Default
Blog post link+3Link to aws.amazon.com/blogs/
GitHub samples link+2Link to github.com/aws*
Documentation link+1Link to docs.aws.amazon.com/
New model+1.5Tagged as "new-model"
New service+1Tagged as "new-service"
New feature+0.5Tagged as "new-feature"
Anthropic / OpenAI provider+2Provider explicitly mentioned
Instance / notebook announcement-2Hardware/capacity, not feature
Performance / pricing / security-0.5Incremental updates
Region expansion to APJ+1Expands to Asia Pacific
Region expansion (non-APJ only)-1.5Only expands to other regions

Geographic Relevance Badges

Each announcement card shows a small badge indicating whether the feature is available in your region:

🌐 Global Available in all regions
🌏 APJ Asia Pacific
🌍 EMEA Europe / Middle East / Africa
🌎 AMER Americas (US, Canada, South America)
No badge Geography unknown
How geography is detected: The system detects ALL geographies mentioned in each announcement. If the text mentions specific regions (Tokyo, Frankfurt, Oregon, etc.), the corresponding geography badges are shown. If it says "all regions" or is a new feature with no region specified, it gets the Global badge. Geography is also filterable — click a geo chip to see only announcements available in that region.