News, analysis, and guides from the world of AI.

The Pentagon picked its AI: ChatGPT and Grok are in, Claude is locked out
Analysis

The Pentagon picked its AI: ChatGPT and Grok are in, Claude is locked out

The world's largest defense budget just decided which AI models it will run on. ChatGPT Mil and Grok for Government are now live for 3 million personnel. The name that is missing is the real story: Anthropic's Claude sits outside because of a blacklisting a federal judge called "illegal and baseless."

N

Nova AI News Editor

September 1, 2026 · 6 min read

As of August 31, 2026, three models run inside GenAI.mil, the US defense department's enterprise AI portal: Google Gemini, OpenAI's military build ChatGPT Mil, and Grok for Government, delivered by xAI under the Starshield banner. According to DefenseScoop, all three cleared Impact Level 5, the highest authorization for environments that process sensitive but unclassified data.

This is not a product launch. It is a procurement decision, and procurement decisions are read by looking at who got left out.

How big the portal actually is

GenAI.mil opened in December 2025 with a single option, Google Cloud's government edition of Gemini. By June 2026 more than 1.5 million personnel were using the platform. Total headcount across the department sits near 3 million. Half the organization is already doing its daily work through a language model, or trying to.

The work itself is mundane. Travel forms. Contracting documents. Policy summaries. Compliance checklists. ChatGPT Mil's stated scope is exactly that: document-heavy unclassified tasks across planning, policy, logistics and administration. Grok for Government arrives with three reasoning modes named Auto, Fast and Expert, persistent project workspaces, and reusable playbooks.

No weapons systems here. What there is instead: one of the largest bureaucracies on the planet handing its paperwork load to a model. That sounds less dramatic than it is. In a defense department, whoever summarizes the policy document shapes how the policy gets read.

The name that isn't on the list

Anthropic's Claude is absent from GenAI.mil, and the reason has nothing to do with capability.

The dispute started in February 2026. Anthropic refused to strip the safeguards that keep Claude out of fully autonomous weapons and mass domestic surveillance. The response was blunt: the company was branded a supply-chain risk, and federal agencies well outside defense were told to stop working with it.

On August 28, 2026, federal judge Rita Lin threw that designation out. Her 59-page ruling found several of the government's central claims about Claude "entirely unfounded" on a simple technical point: the models are static, and Anthropic cannot remotely access, modify, update or disable them once deployed. The sentence at the center of the ruling is worth quoting in full. "The empty invocation of national security is not a blank check to punish and retaliate against government critics." As NPR reported, the court also found the company had been denied due process.

Three days later, Grok joined the portal. Claude did not. The ruling lifted the blacklist. It did not restore the procurement decision.

The argument underneath

Does an AI company get to say no?

Anthropic's position is unambiguous: it sells the model, and the limits on what the model will do are part of what it sells. The government's position is equally unambiguous: those limits are an operational obstacle, and a supplier that imposes them is not a reliable supplier. The court sided with Anthropic on the punishment, not on the purchase.

That distinction will not stay inside defense. Healthcare, insurance, policing, credit scoring; the same question is queued up in each. Can a model provider veto its customer's intended use? Until now that lived as fine print in an acceptable-use policy. Judge Lin's ruling turned it into a constitutional question.

The rest of the industry is watching the scoreboard. One company held its line and lost the single largest customer available. Two companies flexed and gained a distribution channel with 3 million seats. The short-term winner is obvious. Which supplier enterprise buyers trust over a decade is still open.

What the numbers leave out

1.5 million users is an impressive adoption curve, and adoption is not the same as success. The department has published no measurement of how accurate these outputs are. How many summaries needed human correction, how many compliance checklists came back missing an item, what hallucination rate was observed; none of it is public.

The gap matters because it locates the real risk. Public debate runs on autonomous weapons, while the workload actually running through the portal is far more ordinary, and ordinary is exactly what escapes scrutiny. A misread procurement regulation makes nobody's headline and still steers a contract award the wrong way. A missing line in a generated compliance checklist surfaces months later, in an audit.

IL5 invites a misunderstanding here. IL5 guarantees where the data sits, who reaches it and how it is encrypted. It guarantees nothing about whether the model is right. Those are separate problems, and the second one has no standard certification yet.

How it seeps into the civilian side

Defense procurement has long worked as a leading indicator for enterprise software. FedRAMP was designed for federal agencies first, then became a default line item on procurement checklists at banks and hospitals. Encryption, identity and logging requirements followed the same path.

The same cycle has already started in AI. Access tiers, retention windows, output review and pinning model versions are maturing here first. A year from now, a legal team signing an enterprise AI contract anywhere in the world will be reading a derivative of this template without knowing where it came from.

There is a sovereignty dimension too. Every vendor in this story is an American company, and the model weights sit under their control. National model programs are accelerating in Europe and elsewhere not out of technical curiosity, but from a late realization about what it means for a state to run its bureaucracy on another country's commercial vendor. GenAI.mil is the clearest available picture of that dependency.

What this changes for you

From outside Washington this looks like a distant procurement story. It has three concrete consequences.

First, enterprise AI standards are being written here. Authorization tiers like IL5, data-residency requirements and audit-trail expectations mature in defense first, then land in banking and public administration. If someone at your company is drafting an AI usage policy, they will be copying this framework within two years.

Second, model selection stopped being a technical decision. Choosing a model means inheriting its vendor's political exposure. The Anthropic episode showed that a supplier can become unreachable overnight for reasons that have nothing to do with uptime. Any team building on a single-model architecture should put that in the risk register.

Third, the fate of safety limits. Most restrictions in commercial models today exist because the vendor chose to put them there. When the price of that choice is losing your biggest account, the restrictions erode. What the model you use refuses to do next year is being determined by decisions like this one now.

What to watch

Anthropic's court win is the first round. The government can appeal, and the ruling is not expected to automatically open portal access. Meanwhile OpenAI and xAI have consolidated their position in the public sector; as TechCrunch noted, these builds are exempt from the data collection baked into their consumer counterparts.

Three things to track: whether a fourth model joins the portal, whether the ruling survives appeal, and whether other federal agencies copy this vendor shortlist wholesale. The third is the quietest and the one with the widest blast radius.

ShareXFacebookWhatsApp

Related Articles

Comments

No comments yet — be the first to comment.