H2O.ai clears Australian government security bar for PROTECTED-level AI workloads
H2O.ai has completed an Information Security Registered Assessors Program (IRAP) assessment for its H2O AI Cloud platform against the March 2026 Australian Government Information Security Manual's PROTECTED level controls. The assessment positions the company among a small group of AI platforms cleared to handle the government's most sensitive data across defence, law enforcement, health, and public sector agencies.
The March 2026 ISM version introduced explicit controls for AI governance and data protection, making the assessment a direct test of whether the platform meets current regulatory expectations rather than legacy security benchmarks. H2O.ai said the result covers predictive, generative, and agentic AI capabilities in a single environment.
What the assessment covers
IRAP assessments evaluate cloud services against Australian government security requirements. Completing one at the PROTECTED level means an independent assessor has verified that H2O.ai's controls align with the ISM's specifications for safeguarding classified-level government information.
The platform's compliance record now spans several jurisdictions. H2O.ai holds FedRAMP High Certification in the U.S., a listing in AWS's Intelligence Community Marketplace, and a SOC 2 Type II and HIPAA/HITECH report with unqualified status. The company has also received strategic investment from NVIDIA.
Australian government use cases
Agencies can use the assessment report as part of their own security authorization process. H2O.ai outlined the workloads the platform is positioned for:
- Fraud, waste, and abuse prevention
- Cybersecurity and insider threat prevention
- Predictive analytics and resource optimization
- Agentic and generative AI applications for citizen services
- Intelligent document processing and automation
In Australia, H2O.ai already supports Commonwealth Bank of Australia and works with delivery partners including xAmplify, Dell, and CAN.B Group. The company has also partnered with NeoCloud provider Sharon AI to accelerate sovereign AI adoption, underpinned by a dedicated NVIDIA government reference architecture.
Leadership response
Sri Ambati, founder and CEO of H2O.ai, said the assessment "brings the world's most reliable, accurate sovereign AI with the trust and security that Australia's top intelligence and sensitive public services need."
Trent Dolphin, Director of Federal Government & ANZ at H2O.ai, pointed to the practical implications for newly appointed Chief AI Officers: "As custodians of Australia's most sensitive government data, newly appointed Chief AI Officers and their teams now have the ability to safely build and scale governed, secure AI capabilities on technology trusted by some of the largest government and banking institutions."
For government teams evaluating sovereign AI options, the IRAP assessment provides a reference point for security authorization. Agencies looking at AI for Government deployments can weigh H2O.ai's compliance posture against other vendors in the market. Policy leads and Chief AI Officers building internal governance frameworks may also find the AI Learning Path for Policy Makers useful for aligning technical capability with regulatory requirements.
Why this matters for government professionals
The IRAP assessment shortens the procurement path for agencies that need AI platforms capable of handling PROTECTED-level data. Instead of starting security reviews from scratch, government teams can reference an existing independent assessment when building their authorization case. The explicit AI governance controls in the March 2026 ISM also signal that security assessors will increasingly scrutinize how AI platforms manage data, models, and agentic workflows - not just infrastructure security. For Chief AI Officers and IT leads, the practical takeaway is to check whether any AI vendor under consideration has been assessed against the current ISM version, not an outdated one.
Your membership also unlocks: