Amazon Web Services has opened its government cloud to a wider slate of frontier AI models. As of an August 30, 2026 announcement on the AWS Public Sector Blog, Amazon Bedrock inside AWS GovCloud (US) now carries models from Anthropic, Meta, OpenAI, NVIDIA, xAI, and Amazon’s own Nova family, giving federal agencies and cleared contractors a menu that until recently looked thin next to what commercial AWS customers could already reach.
The move matters less as a product update and more as a signal. Government buyers move slowly, and AI vendors have spent two years lobbying for a foothold inside the compliance boundaries that agencies actually operate under. AWS just handed several of them that foothold at once, inside the same regions federal customers already trust for FedRAMP High and Department of Defense workloads.
What AWS actually announced on August 30
The headline post, titled “AI Model Choice is now a Mission Advantage,” ran on the AWS Public Sector Blog and framed the expansion as a direct response to agency demand for model variety rather than a single default option. AWS says GovCloud customers can now reach more than 20 leading models through Amazon Bedrock and Bedrock AgentCore without leaving the compliance boundary that FedRAMP and DoD authorizations require.
Named providers include Anthropic’s Claude models, Meta’s Llama family, OpenAI’s GPT and GPT-OSS models, NVIDIA’s Nemotron line, xAI’s Grok, and Amazon’s own Nova frontier models covering text, image, and multimodal embeddings. The announcement lands inside AWS GovCloud (US), which spans the US-West and US-East regions built specifically for government and regulated-industry workloads that can’t run on standard commercial AWS infrastructure.
The timing is not an accident. AWS marked 15 years of GovCloud (US) on August 16, 2026, with a blog post positioning the region as infrastructure built for “the nation’s most critical missions.” The August 30 model expansion reads as the follow-up act: having built the compliance shell over a decade and a half, AWS is now racing to fill it with every AI provider agencies are asking for.
Which models are actually available where
Availability isn’t uniform across every GovCloud region, and the rollout happened in stages rather than all at once. Anthropic’s Claude 3.5 Sonnet and Claude 3 Haiku have been reachable through Bedrock in AWS GovCloud (US-West) for some time. Meta’s Llama 3 8B and Llama 3 70B sit alongside them. OpenAI’s presence is newer: GPT-OSS 20B and GPT-OSS 120B, plus GPT-5.4, are now listed as available on Bedrock in GovCloud (US-West), according to AWS’s own documentation.
NVIDIA’s Nemotron Nano 9B v2, Nemotron Nano 12B v2, Nemotron Nano 30B, and Nemotron Super 120B round out the open-weight side of the catalog. Separately, AWS’s machine learning blog noted that OpenAI’s GPT-OSS models and NVIDIA’s Nemotron models were already live in AWS GovCloud (US) as of April 29, 2026, meaning the August 30 post is partly a consolidation announcement layered on top of a rollout that had been happening in pieces since spring. AWS also confirmed Grok 4.3 landed on Amazon Bedrock on July 16, 2026, which puts xAI’s newest model in the mix ahead of the broader August summary post.
| Provider | Model(s) named in AWS GovCloud rollout | Category |
|---|---|---|
| Anthropic | Claude 3.5 Sonnet, Claude 3 Haiku | Proprietary, closed-weight |
| Meta | Llama 3 8B, Llama 3 70B | Open-weight |
| OpenAI | GPT-OSS 20B, GPT-OSS 120B, GPT-5.4 | Mixed (open-weight + proprietary) |
| NVIDIA | Nemotron Nano 9B v2, Nano 12B v2, Nano 30B, Super 120B | Open-weight |
| xAI | Grok 4.3 | Proprietary, closed-weight |
| Amazon | Nova (text, image, multimodal embeddings) | Proprietary, closed-weight |
Why GovCloud access is a different bar than commercial Bedrock
Getting a model listed on commercial Amazon Bedrock is a fairly routine engineering exercise. Getting it authorized for AWS GovCloud is not. Agencies operating under FedRAMP High or Department of Defense Impact Level 4 and 5 requirements need documented evidence that data handling, encryption, personnel access, and audit logging all meet a much stricter bar than a typical enterprise SaaS contract demands.
That’s the backdrop for a separate but related AWS announcement: Anthropic’s Claude models were approved for FedRAMP High and DoD Impact Level 4 and 5 workloads through Amazon Bedrock in AWS GovCloud (US) regions, a milestone Anthropic confirmed on its own site. AWS’s public sector team described the moment plainly: “Amazon Web Services (AWS) is the first cloud provider to achieve FedRAMP High and Department of Defense (DoD) Cloud Computing Security Requirements Guide Impact Level 4 and 5 authorizations for Anthropic’s Claude and Meta’s Llama AI foundation models,” according to the AWS Public Sector Blog.
Thiyagu Ramasamy, Head of Public Sector at Anthropic, put the practical stakes this way: “With Amazon Bedrock’s FedRAMP High and DoD IL4/5 authorization, Claude can now assist defense agencies with their most sensitive missions while ensuring compliance with the strictest security requirements,” as quoted on the AWS Public Sector Blog. That single authorization is the difference between a model being technically demoable to a federal customer and a model being contractually usable on a live defense system handling controlled unclassified information.
AWS’s own May 2025 what’s-new post laid out the practical effect for buyers: “Federal agencies, public sector organizations, and other enterprises with FedRAMP High compliance requirements can now use Amazon Bedrock to access high-performing foundation models (FMs) from Anthropic and Meta,” per the official AWS announcement. The August 2026 expansion extends that same compliance-cleared access to OpenAI, NVIDIA, and xAI’s model families.
The 15-year anniversary framing isn’t incidental
AWS GovCloud (US) launched in 2011 and has spent a decade and a half as the default landing zone for federal, defense, and regulated-industry workloads that can’t sit on standard commercial infrastructure. AWS marked the anniversary on August 16, 2026, with a post stating that GovCloud “gives customers freedom of model choice, with more than 20 leading models available through Amazon Bedrock and Amazon Bedrock AgentCore,” according to the AWS Public Sector Blog.
Reading the two posts together, the pattern is straightforward: AWS used the anniversary to advertise breadth, then followed up two weeks later with the specific provider list. That sequencing suggests the model catalog expansion had been in the works for months and was timed to land during the anniversary news cycle rather than shipping the moment each individual authorization cleared.
What this means for federal AI procurement
Government technology buyers have been stuck choosing between two bad options for the past two years: build on a single vendor’s model and accept lock-in risk, or run a multi-cloud, multi-contract patchwork that multiplies the compliance paperwork every time a new model gets added. A single GovCloud environment offering Claude, Llama, GPT-OSS, GPT-5.4, Nemotron, Grok, and Nova under one authorization boundary collapses that choice into a single procurement vehicle.
For agencies already running FedRAMP High workloads on AWS, the practical shift is that switching models no longer means switching contracts, re-running security assessments, or waiting on a fresh Authority to Operate. An agency evaluating whether Llama’s open weights suit a classification task better than Claude’s closed-weight reasoning can now test both inside the same Bedrock console, inside the same compliance boundary, without a new procurement cycle.
That flexibility also changes the competitive calculus for model providers themselves. Getting listed in AWS GovCloud is now a distribution channel into a buyer segment, federal agencies and defense contractors, that most AI labs cannot reach on their own. Anthropic, Meta, and OpenAI all get a federal sales motion essentially for free by riding AWS’s existing compliance infrastructure rather than building their own government-cloud presence from scratch, a strategy that runs parallel to how AWS has been opening its commercial cloud to outside partners more broadly this year.
Open-weight versus closed-weight: a split catalog
The GovCloud model list splits cleanly along a line that matters for security-conscious buyers: open-weight models like Meta’s Llama 3 family and NVIDIA’s Nemotron line can, in principle, be inspected, fine-tuned, and audited down to the weights. Closed-weight models like Claude, GPT-5.4, Grok 4.3, and Amazon Nova cannot. For classified or near-classified workloads, that distinction sometimes decides which model an agency is even allowed to touch, regardless of benchmark performance.
NVIDIA’s inclusion is worth separating out from the rest of the list, since Nemotron isn’t a single frontier model but a family of smaller, efficiency-tuned variants (9B, 12B, and 30B parameter “Nano” versions, plus a 120B “Super” version). Those sizes suggest NVIDIA is positioning Nemotron for on-premises-adjacent, latency-sensitive government use cases like edge inference on secure networks, rather than trying to compete head-on with GPT-5.4 or Claude on raw reasoning benchmarks.
How this compares to Microsoft Azure Government and Google Cloud
AWS is not the only hyperscaler chasing the federal AI procurement dollar. Microsoft has spent years building out Azure Government as a parallel compliance-cleared environment, and Google Cloud has pushed its own government-focused offerings. What sets the August 30 AWS announcement apart is breadth of third-party model choice inside a single compliance boundary, rather than a proprietary-only stack.
Where AWS is explicitly assembling models from five separate outside labs (Anthropic, Meta, OpenAI, NVIDIA, and xAI) alongside its own Nova family, competing government clouds have historically leaned more heavily on a single flagship partnership, such as Microsoft’s deep integration with OpenAI’s models across its Azure Government stack. AWS betting on model plurality rather than a single exclusive partner is a distinct strategic choice, and it’s one that plays to AWS’s traditional selling point of infrastructure neutrality over any single AI bet.
| Milestone | Date | Source |
|---|---|---|
| AWS GovCloud (US) launch | 2011 | AWS Public Sector Blog |
| Claude, Llama get FedRAMP High / DoD IL4-5 approval on Bedrock | May 2025 | AWS “What’s New” announcement |
| OpenAI GPT-OSS and NVIDIA Nemotron live in AWS GovCloud (US) | April 29, 2026 | AWS Machine Learning Blog |
| Grok 4.3 lands on Amazon Bedrock | July 16, 2026 | AWS Bedrock announcement |
| AWS GovCloud (US) 15-year anniversary post (“20+ models”) | August 16, 2026 | AWS Public Sector Blog |
| “AI Model Choice is now a Mission Advantage” post | August 30, 2026 | AWS Public Sector Blog |
The FedRAMP and DoD IL4/5 backstory
FedRAMP High and DoD Impact Level 4/5 aren’t marketing terms, they’re specific, independently audited security frameworks. FedRAMP High governs cloud services that handle the government’s most sensitive unclassified data, covering things like law enforcement and emergency services systems. DoD IL4 and IL5 sit even higher, covering controlled unclassified information tied to national security systems and mission-critical defense operations.
Clearing those bars typically takes AI vendors many months of documentation, third-party assessment, and continuous monitoring commitments before a single customer can touch the model in a live environment. AWS’s role as the underlying infrastructure provider means it absorbs a large share of that compliance burden on behalf of every model provider it lists, which is precisely why the August 30 announcement functions as a multiplier: each new model added to the GovCloud catalog benefits from infrastructure-level authorizations AWS has already spent years building.
Market and competitive impact for AWS
Federal AI spending has been one of the more closely watched growth lines for the major cloud providers heading into the back half of 2026, as agencies under budget pressure look for infrastructure that can host multiple AI vendors without re-running procurement each time. By expanding third-party model choice inside GovCloud, AWS positions Bedrock as the default aggregation layer for federal AI purchasing, a role that, if it holds, gives AWS leverage independent of which individual model wins any given benchmark race.
That aggregation strategy mirrors what AWS has already done in the commercial Bedrock market, where it built its reputation less on having the single best model and more on hosting the broadest set of them under one API and one billing relationship. Bringing that same playbook into GovCloud extends AWS’s existing commercial advantage into a government buying process where switching infrastructure vendors is far harder and far slower than switching commercial cloud contracts.
Risks and open questions
Model availability inside GovCloud doesn’t automatically mean every agency can use every model for every purpose. Individual agencies still run their own Authority to Operate processes on top of the underlying FedRAMP and DoD authorizations, and some model, task combinations will face additional agency-specific review regardless of what’s technically listed in the Bedrock console.
There’s also an open question about how AWS handles version churn. GPT-5.4 sits in the current GovCloud catalog, but OpenAI has already retired several older commercial models elsewhere, and keeping government-cleared model versions in step with the commercial frontier will require repeated re-authorization work every time a lab ships a meaningfully new model. That lag between commercial release and government availability is a structural feature of compliance-gated environments, not a one-time gap that closes after this announcement.
Five predictions for the next 12 months
- Expect Microsoft and Google to respond with their own expanded third-party model rosters inside Azure Government and Google Cloud’s public sector regions within the next two to three quarters, rather than ceding the multi-model narrative to AWS.
- Expect additional labs, particularly open-weight players competing with Meta and NVIDIA, to pursue their own FedRAMP High and DoD IL4/5 authorizations once they see the distribution advantage AWS’s existing partners are capturing.
- Expect AWS to keep pairing GovCloud model announcements with Bedrock AgentCore updates, since agent tooling on top of a compliance-cleared model catalog is a stickier sell than raw model access alone.
- Expect version lag to become a recurring friction point, with government customers publicly asking why commercially available frontier models take months to reach GovCloud.
- Expect procurement officers to increasingly treat “number of authorized models in one compliance boundary” as an explicit evaluation criterion in future federal cloud contracts, formalizing what AWS is currently selling as a soft advantage.
The bigger picture for enterprise AI buyers
Even outside government, this announcement is a useful data point for any enterprise AI buyer thinking about vendor lock-in. AWS is effectively demonstrating that a single infrastructure provider can host direct competitors, Anthropic, Meta, OpenAI, NVIDIA, and xAI, under one roof without any of them needing exclusivity. That’s a meaningfully different model from the tighter partnerships some cloud providers have struck with individual AI labs, and it gives commercial customers watching the government rollout a preview of how model plurality might play out in their own procurement decisions over the next year.
It also raises the bar for what “AI-ready cloud” means as a sales pitch. A catalog listing several labs’ models is no longer differentiated on its own, since AWS, Azure, and Google Cloud can all technically claim it, especially as providers race to add features like real-time web search grounding and content provenance tools such as model output watermarking on top of the base catalog. The differentiator increasingly shifts to compliance depth, how fast new models clear FedRAMP High and DoD IL4/5, and how tightly agent orchestration tools like Bedrock AgentCore integrate with that authorized model catalog.
Frequently asked questions
What is AWS GovCloud (US)?
AWS GovCloud (US) is a set of AWS regions, including US-West and US-East, built specifically for US government agencies, contractors, and regulated industries that need to meet FedRAMP High, DoD Impact Level 4/5, and similar compliance requirements that standard commercial AWS regions don’t satisfy.
Which AI models are now available in AWS GovCloud through Amazon Bedrock?
As of the August 30, 2026 announcement, the catalog includes Anthropic’s Claude 3.5 Sonnet and Claude 3 Haiku, Meta’s Llama 3 8B and 70B, OpenAI’s GPT-OSS 20B, GPT-OSS 120B, and GPT-5.4, NVIDIA’s Nemotron Nano and Super models, xAI’s Grok 4.3, and Amazon’s own Nova family.
Is this the first time OpenAI models have been available on AWS?
OpenAI’s GPT-OSS models and NVIDIA’s Nemotron models were reported as already live in AWS GovCloud (US) as of April 29, 2026, according to the AWS Machine Learning Blog. The August 30 announcement consolidates and expands on that earlier rollout with GPT-5.4 added to the mix.
What does FedRAMP High authorization actually mean for these AI models?
FedRAMP High is the strictest tier of the Federal Risk and Authorization Management Program, covering cloud services that handle the government’s most sensitive unclassified data. A model authorized at this level, combined with DoD Impact Level 4/5 clearance, can be used by federal agencies and defense contractors on systems handling controlled unclassified information, something a model without that authorization cannot legally touch.
How is this different from using these AI models on commercial AWS?
Commercial Amazon Bedrock already offered many of these models. The difference in GovCloud is the compliance wrapper: agencies get the same model access but inside an environment independently authorized for FedRAMP High and DoD IL4/5 workloads, which most commercial AWS regions are not certified for.
Does this include open-weight models that agencies can inspect or fine-tune?
Yes. Meta’s Llama 3 family and NVIDIA’s Nemotron line are open-weight, meaning agencies with the right clearance can inspect and fine-tune them more directly than closed-weight models like Claude, GPT-5.4, Grok 4.3, or Amazon Nova.
How does AWS GovCloud’s AI model catalog compare to Microsoft Azure Government?
AWS’s approach leans on hosting multiple competing labs’ models side by side inside one compliance boundary rather than anchoring on a single exclusive AI partner, which is a different strategic posture than the tighter single-vendor integrations other government clouds have historically favored.
Will newer commercial AI models reach AWS GovCloud faster in the future?
AWS hasn’t published a specific timeline commitment. Based on the gap between commercial releases and GovCloud availability seen with GPT-OSS, Nemotron, and Grok 4.3, expect a lag of weeks to months between a model’s commercial launch and its appearance in the compliance-cleared GovCloud catalog.




