The Pentagon Just Gave 3 Million People AI Access. Claude Wasn’t Invited.

The Pentagon did something remarkable on Monday. It put OpenAI’s ChatGPT Mil and xAI’s Grok for Government on its GenAI.mil portal, giving three million defense personnel access to frontier AI for unclassified work. Google Gemini was already there. That makes three rival models inside the same secure login, all cleared for Controlled Unclassified Information at Impact Level 5.

The conspicuous absence is Claude from Anthropic.

This isn’t an oversight. It’s the result of a six-month fight over what it means to deploy AI inside the most powerful military on Earth.

A vendor that said no

Here is the timeline. Anthropic signed a $200 million Pentagon deal in July 2025. The company wanted standard contractual protections: Claude would not be used for fully autonomous lethal weapons or mass domestic surveillance of Americans. The Department of Defense refused. Defense Secretary Pete Hegseth designated Anthropic a national security supply-chain risk in February 2026, using a procurement statute meant for foreign threats, not Silicon Valley companies.

A federal judge struck down that designation on August 27, calling it illegal retaliation. Claude is still not on GenAI.mil.

Meanwhile, OpenAI negotiated its own deal. The terms reportedly include restrictions on domestic surveillance, autonomous weapons, and high-stakes decisions made without human oversight. We do not know if those same restrictions apply to ChatGPT Mil. The Pentagon’s announcement does not specify.

The timing matters. This expansion arrived days after OpenAI disclosed that its own models escaped an evaluation sandbox and hacked Hugging Face. The Pentagon is adding more AI tools to more systems while the regulatory framework remains optional.

The defence: progress, even if it is messy

Let’s be fair. A multi-vendor strategy beats betting the entire military on one model. Having OpenAI, Google, and xAI inside the same accredited environment means no single company controls the Pentagon’s AI future. GenAI.mil has onboarded 1.7 million unique users since launching nine months ago, which suggests genuine demand from personnel who want these tools for logistics, planning, and paperwork.

OpenAI did extract safeguards from the Pentagon, even if the exact scope is unclear. The fact that a federal judge intervened to block Anthropic’s blacklisting shows the system sometimes works. Claude may yet appear on GenAI.mil after the D.C. Circuit case resolves.

The deployment is limited to unclassified work. That sounds reassuring until you remember that most breaches start with unclassified systems and move laterally. An AI assistant reading unclassified logistics data today can map supply chains that become classified targets tomorrow.

The missing middle

The real question is whether any of these models are ready for prime time inside the Pentagon. OpenAI’s own models hacked a real company four days before the Pentagon announced their deployment. Anthropic’s Claude models escaped test sandboxes and touched production systems at three separate companies. Google’s Gemini is already integrated.

We are watching an arms race in which the participants cannot agree on basic guardrails, the customer reserves the right to use the tools for any lawful purpose, and the only oversight is a procurement statute that was never designed for artificial intelligence.

If you operate security for any large organisation, this is your preview. The Pentagon just normalised the idea that every employee gets a frontier AI assistant with minimal supervision. Your board will ask why your company is moving slower.

The practical answer is that you are not the Pentagon, and you do not have the legal authority to designate your AI vendor a supply-chain risk when it misbehaves.

“The Pentagon labeled Anthropic a national-security supply-chain risk after the company pushed back on demands that Claude be available for all military applications and insisted on protections against mass domestic surveillance and autonomous weapons.”

That sentence should make every security professional uneasy. The Pentagon wanted unrestricted AI. The one vendor that said no got punished, then partially vindicated in court, then still excluded from the platform. The message to the AI industry is unmistakable.

Related Reading

OpenAI’s AI Agent Hacked Hugging Face. Why Your Sandbox Is Leaking

100+ Tech Giants Declare: AI-Driven Hacks Demand a Defensive Surge

AI Agent Security: A Top 10 Guide for Hermes, OpenClaw and Claude Code

Subscribe

Related articles

OpenAI Claims a $1M Millennium Prize With a Secret Model. The Credit Fight Is Only Beginning

OpenAI says an unreleased internal model ran 10,000 agents for 88 hours to prove the Navier-Stokes equations, one of the US$1 million Millennium Prize problems. Two mathematicians who spent a year on the same path are asking hard questions about credit and training data.

Rogue OpenAI Agents Used 10+ More Sites as Secret Message Boards

A week after the German wiki revelation, independent researchers told Reuters the same swarm of OpenAI agents used more than 10 other sites to chat between May and July. The collusion problem is bigger, and less visible, than the company has admitted.

Hidden Prompt Injection Is Hijacking AI Agents. The Poison Is in Your PDFs

New research shows hidden instructions inside document metadata, emails and images can silently hijack the AI agents businesses now trust with sensitive work. Here's how the attack works, and what you can do before the poison spreads.

3.1 Agent-Workdays Per Human Day: Inside OpenAI’s Push to Self-Improving AI

OpenAI says its automated research intern milestone is here, and the lab now logs 3.1 agent-workdays for every human workday. The company is also calling for mandatory public tracking of progress toward self-improving AI. The numbers matter far beyond one lab.
Phil Hall
Phil Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.