AI / ML topic Can a Government Agency Just Use ChatGPT?
Running AI in a government cloud: FedRAMP, GovCloud regions, air-gapped models, audit logs and agents, as of September 2026. Same plumbing as anywhere else, with the boundaries drawn in ink.
· ml, government, security, compliance, explainer
Somewhere in a federal agency right now, someone has pasted a paragraph into a chatbot to make it sound less like a memo. Then someone from the security office walks by and asks: where did that paragraph just go?
The model is the same model everywhere. What changes in government is the boundary around it: who runs the servers, whose staff can see the prompts, what the data is allowed to touch, and who signed off.
Everything below is as of September 2026. This field moves fast and the rules move with it, so check the dates before you rely on any of it.
Nothing runs without a signature
Before any system goes live in an agency, an official has to grant an , a formal statement that its remaining risk is acceptable. Doing a full security review of every cloud vendor for every agency would take forever, so does it once and agencies reuse the result.
For years, FedRAMP rated services Low, Moderate or High, by how badly a breach would hurt. New rules that took effect on July 4, 2026 renamed FedRAMP “authorization” to “certification”, partly so nobody confuses FedRAMP’s review with the agency’s own ATO, and moved Low, Moderate and High into Classes B, C and D, with a new pilot Class A. You’ll still see “FedRAMP High” on many vendor pages for a while. The Defense Department adds its own : IL4 and IL5 for , and IL6 for classified work up to Secret.
Four places a model can live
- A certified AI service: FedRAMP fast-tracked chat assistants from August 2025 to April 2026. ChatGPT Enterprise, Gemini for Government and Perplexity were certified. One condition: anything a model learned from customer data had to stay inside the customer’s environment unless the customer said otherwise.
- A model service in a government region: AWS lists Claude, Llama, OpenAI and other models on Bedrock at FedRAMP High (now Class D) and IL4/5 in its regions. Microsoft has had Azure OpenAI at FedRAMP High since 2024.
- A classified cloud: Bedrock runs in AWS’s Top Secret and Secret regions, and Microsoft brought GPT-5.2 to its Secret and Top Secret clouds in January 2026.
- Your own hardware: run an model inside your own boundary, even an one. Google sells Gemini on air-gapped hardware, so “no internet” no longer means “open models only.”
Cost is less of a barrier than it used to be. In August 2025, GSA, the government’s central buyer, struck deals putting ChatGPT Enterprise and Claude in front of agencies for $1 each for a year, and Gemini for Government for 47 cents through 2026. In September 2026, GSA said ChatGPT would move to 50% off pay-as-you-go pricing from October 1.
The rules on top
Two memos from the White House budget office (OMB) in April 2025 set the ground rules. M-25-21 requires testing, impact assessments and human oversight for “high-impact” AI, meaning AI whose output is a principal basis for decisions with a legal, material, binding or significant effect on rights or safety. M-25-22 has agencies write contracts that “permanently prohibit” vendors from training public or commercial models on non-public agency inputs and outputs without the agency’s explicit consent.
Vendor choice is now a policy question too. On February 27, 2026, agencies were directed to stop using Anthropic’s models. After a federal court paused that directive, GSA restored them in April 2026, though an appeals court upheld the Pentagon’s risk label on September 25. The ops lesson applies to any vendor: design so you can swap the model behind your app without re-certifying everything around it.
Proving what happened
In government, “it worked” isn’t enough. You have to show what the model saw and did. In practice that means an of prompts, responses and actions, tied to a person.
OMB’s May 2026 logging memo, M-26-14, doesn’t mention prompts, but it replaced the old M-21-31 rules and requires logs that show who did what to which data, searchable for at least 6 months and retrievable for 12. Those logs will hold sensitive text, so they need the same protection as the data itself.
The agent problem
Chat is the easy case: a person reads every answer. , which act on their own, are arriving in government clouds too. AWS brought Bedrock AgentCore to GovCloud in May 2026, and Microsoft’s Foundry Agent Service reached Azure Government in September.
An agent that can file, send or change records needs and human approval for anything it can’t undo. Least privilege is already a baseline federal control, and both matter more when can steer the agent.
So can they just use ChatGPT?
Increasingly, yes, just not the one on your phone. The same families of models now run in certified services, government regions, classified clouds and air-gapped racks. The work is the plumbing it always was: pick the environment that matches the data, keep the prompts inside the boundary, log everything, and keep a person in charge of anything irreversible. It’s the same job as anywhere else, with more paperwork.
References & further reading
FedRAMP and DoD first, then the platforms, buying and policy, then logging and agents.
Agency Authorization
Cloud providers work with an agency to get an Authority to Operate; the agency grants it.
Do Once, Use Many - How Agencies Can Reuse a FedRAMP Authorization
A provider is authorized once and any federal agency can reuse the security package; each agency still issues its own ATO.
Understanding Baselines and Impact Levels in FedRAMP
Low, Moderate and High, by how severe the harm from a breach would be.
What's changing in the 2026 Consolidated Rules
Authorization becomes Certification, Low, Moderate and High become Classes B, C and D (plus a new pilot Class A), and new Rev5 certifications stop on June 11, 2027.
Initial Outcome from RFC-0020 FedRAMP Authorization Designations
Class A is a new pilot baseline; Class B takes Li-SaaS and Low, Class C Moderate, Class D High.
DoD Impact Level 5
CUI that needs more protection than IL4, plus National Security Systems.
DoD Impact Level 6
Reserved for information classified up to Secret.
FedRAMP AI Prioritization
Fast-tracked chat assistants for federal workers. ChatGPT Enterprise and API, Gemini for Government and Perplexity came out certified.
Amazon Bedrock models in scope for FedRAMP
Which models on Bedrock are FedRAMP High and DoD IL4/5 in AWS GovCloud (US).
Azure OpenAI Service now authorized for all U.S. Government data classification levels
FedRAMP High and IL4/5 in 2024, IL6 in the Secret cloud and Top Secret in early 2025.
Amazon Bedrock launches with Claude 3.5 Sonnet in the AWS Top Secret cloud
Bedrock generally available in the AWS Top Secret cloud.
Amazon Bedrock is now available
Bedrock at the Secret level.
Announcing GPT-5.2 Availability in Azure for U.S. Government Secret and Top Secret Clouds
GPT-5.2 available in Azure's Secret and Top Secret clouds.
Gemini is now available anywhere
General availability of Gemini on Google Distributed Cloud air-gapped.
32 CFR 2002.14 Safeguarding
CUI Basic is categorized at no less than the moderate confidentiality impact level, the floor the demo uses.
Certification Classes - FedRAMP Consolidated Rules for 2026
Classes describe assurance, not impact level; Class C is presumed adequate for most Low or Moderate agency systems.
GSA Announces New Partnership with OpenAI, Delivering Deep Discount to ChatGPT Gov-Wide Through MAS
ChatGPT Enterprise for $1 per agency for a year.
GSA Strikes Another OneGov Deal with Anthropic to Offer Claude AI to all Branches of Gov for Just $1
Claude for Enterprise and Claude for Government for $1, across all three branches.
GSA, Google Announce Transformative 'Gemini for Government' OneGov Agreement
Gemini for Government at $0.47 per agency.
GSA Expands OneGov AI Offerings with Discounted, Consumption-Based Access to OpenAI's ChatGPT
A 50% discount on token-based ChatGPT usage, no minimums, in a 27-month offer expected to start October 1, 2026.
M-25-21: Accelerating Federal Use of AI through Innovation, Governance, and Public Trust
Chief AI Officers, and minimum practices (testing, impact assessment, human oversight) for high-impact AI.
M-25-22: Driving Efficient Acquisition of Artificial Intelligence in Government
Contracts must permanently prohibit training public or commercial models on non-public agency inputs and outputs, absent explicit agency consent.
GSA Issues Statement on Anthropic Preliminary Injunction
After the February 27 removal and a March 26 court order, GSA restores Anthropic to its prior status.
Pentagon is still calling Anthropic a supply chain risk despite court ruling
After an August court ruling, a Defense Department official said the Pentagon's supply chain risk designation of Anthropic remained in force.
Anthropic loses legal fight to shed DOD's designation as a 'supply-chain risk'
The D.C. Circuit upheld the Pentagon's supply-chain-risk designation of Anthropic, 2–1; Anthropic said it was considering further review.
M-26-14: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats
Rescinds M-21-31. Logs searchable for at least 6 months and retrievable for at least 12.
Amazon Bedrock AgentCore is now available in AWS GovCloud (US-West)
The agent runtime arrives in a government region.
Advancing trusted AI innovation with Agents and new Azure OpenAI models in Azure Government
Microsoft Foundry Agent Service is now available in Azure Government.
Least Privilege (NIST glossary)
Each entity gets only the resources and authorizations its function needs.