Assessment against the Information Security Manual's PROTECTED level controls positions H2O.ai to support security-conscious Australian government and highly regulated agencies
MOUNTAIN VIEW, Calif. — [September, 2, 2026] — H2O.ai, the sovereign enterprise AI platform for predictive, generative and agentic AI, with built-in observability and governance, today announced it has completed an Information Security Registered Assessors Program (IRAP) assessment for H2O AI Cloud against the March 2026 version of the Australian Government Information Security Manual's (ISM) PROTECTED level controls.
This version of the ISM introduced explicit controls for AI governance and data protection, further demonstrating H2O.ai’s readiness to protect the Australian government’s most sensitive data across defence, law enforcement, health, and public sector environments.
H2O.ai is now one of the few AI platforms to have been assessed against the ISM’s PROTECTED level controls across predictive, generative, and agentic AI. The H2O AI Cloud platform combines all three together in a single environment purpose-built for government and regulated industries, enabling agencies to build and deploy AI for citizen centric service and decision support, fraud reduction, cybersecurity, and program integrity while retaining control over their data, infrastructure, and deployment environment.
The milestone extends a compliance and partnership track record H2O.ai has built globally: FedRAMP® High Certification in the U.S., a listing in AWS’s Intelligence Community Marketplace (ICMP) for federal and intelligence community customers, a SOC 2 Type II and HIPAA/HITECH report with unqualified status, and strategic investment from NVIDIA. In Australia, H2O.ai already supports Commonwealth Bank of Australia and works with AI service delivery partners including xAmplify, Dell, and CAN.B Group. H2O.ai has also partnered with NeoCloud provider Sharon AI to accelerate sovereign AI adoption nationally, underpinned by a dedicated NVIDIA government reference architecture.
Agencies can use the resulting assessment report as part of their own security authorization process to evaluate H2O.ai's platform for use cases such as:
- Fraud, waste, and abuse prevention
Fraud, waste, and abuse prevention
- Cybersecurity and insider threat prevention
Cybersecurity and insider threat prevention
- Predictive analytics and resource optimization
Predictive analytics and resource optimization
- Agentic and generative AI applications for citizen services
Agentic and generative AI applications for citizen services
- Intelligent document processing and automation
Intelligent document processing and automation
For more information about H2O.ai, visit https://h2o.ai
FedRAMP® is a registered trademark of the U.S. General Services Administration. Use of the FedRAMP name and mark does not imply endorsement by the U.S. Government.





