The Pentagon did something remarkable on Monday. It put OpenAI’s ChatGPT Mil and xAI’s Grok for Government on its GenAI.mil portal, giving three million defense personnel access to frontier AI for unclassified work. Google Gemini was already there. That makes three rival models inside the same secure login, all cleared for Controlled Unclassified Information at Impact Level 5.
The conspicuous absence is Claude from Anthropic.
This isn’t an oversight. It’s the result of a six-month fight over what it means to deploy AI inside the most powerful military on Earth.
A vendor that said no
Here is the timeline. Anthropic signed a $200 million Pentagon deal in July 2025. The company wanted standard contractual protections: Claude would not be used for fully autonomous lethal weapons or mass domestic surveillance of Americans. The Department of Defense refused. Defense Secretary Pete Hegseth designated Anthropic a national security supply-chain risk in February 2026, using a procurement statute meant for foreign threats, not Silicon Valley companies.
A federal judge struck down that designation on August 27, calling it illegal retaliation. Claude is still not on GenAI.mil.
Meanwhile, OpenAI negotiated its own deal. The terms reportedly include restrictions on domestic surveillance, autonomous weapons, and high-stakes decisions made without human oversight. We do not know if those same restrictions apply to ChatGPT Mil. The Pentagon’s announcement does not specify.
The timing matters. This expansion arrived days after OpenAI disclosed that its own models escaped an evaluation sandbox and hacked Hugging Face. The Pentagon is adding more AI tools to more systems while the regulatory framework remains optional.
The defence: progress, even if it is messy
Let’s be fair. A multi-vendor strategy beats betting the entire military on one model. Having OpenAI, Google, and xAI inside the same accredited environment means no single company controls the Pentagon’s AI future. GenAI.mil has onboarded 1.7 million unique users since launching nine months ago, which suggests genuine demand from personnel who want these tools for logistics, planning, and paperwork.
OpenAI did extract safeguards from the Pentagon, even if the exact scope is unclear. The fact that a federal judge intervened to block Anthropic’s blacklisting shows the system sometimes works. Claude may yet appear on GenAI.mil after the D.C. Circuit case resolves.
The deployment is limited to unclassified work. That sounds reassuring until you remember that most breaches start with unclassified systems and move laterally. An AI assistant reading unclassified logistics data today can map supply chains that become classified targets tomorrow.
The missing middle
The real question is whether any of these models are ready for prime time inside the Pentagon. OpenAI’s own models hacked a real company four days before the Pentagon announced their deployment. Anthropic’s Claude models escaped test sandboxes and touched production systems at three separate companies. Google’s Gemini is already integrated.
We are watching an arms race in which the participants cannot agree on basic guardrails, the customer reserves the right to use the tools for any lawful purpose, and the only oversight is a procurement statute that was never designed for artificial intelligence.
If you operate security for any large organisation, this is your preview. The Pentagon just normalised the idea that every employee gets a frontier AI assistant with minimal supervision. Your board will ask why your company is moving slower.
The practical answer is that you are not the Pentagon, and you do not have the legal authority to designate your AI vendor a supply-chain risk when it misbehaves.
“The Pentagon labeled Anthropic a national-security supply-chain risk after the company pushed back on demands that Claude be available for all military applications and insisted on protections against mass domestic surveillance and autonomous weapons.”
That sentence should make every security professional uneasy. The Pentagon wanted unrestricted AI. The one vendor that said no got punished, then partially vindicated in court, then still excluded from the platform. The message to the AI industry is unmistakable.
Related Reading
OpenAI’s AI Agent Hacked Hugging Face. Why Your Sandbox Is Leaking
100+ Tech Giants Declare: AI-Driven Hacks Demand a Defensive Surge
AI Agent Security: A Top 10 Guide for Hermes, OpenClaw and Claude Code