Rows of illuminated server racks in a dark data center with blue and green LED lights
Photo via Unsplash

TL;DR: On May 1, 2026, the Pentagon announced agreements with seven tech companies to deploy AI on its classified military networks: Google, OpenAI, Microsoft, Amazon Web Services, Nvidia, SpaceX, Oracle, and startup Reflection AI. These models will run on Impact Level 6 and 7 systems, that’s secret and top-secret data. The deals go through GenAI.mil, the Pentagon’s AI portal, which already has 1.3 million users who’ve built hundreds of thousands of AI agents. Only OpenAI publicly negotiated restrictions prohibiting “deliberate tracking, surveillance, or monitoring of U.S. persons.” The rest? They accepted the Pentagon’s “all lawful” use clause, the exact language Anthropic refused, getting itself blacklisted as a supply chain risk. No contract values were disclosed. No surveillance safeguards were announced. The military just got its AI arsenal, and we have almost no idea what rules it operates under.

The Deals: Who Got In and What They Signed

The Department of Defense framed the announcement as a step toward becoming an “AI-first” military force. The agreements cover “warfighting, intelligence and enterprise operations,” designed to “streamline data synthesis, elevate situational understanding, and augment warfighter decision-making” [1].

Translation: these AI systems will help the military analyze intelligence, identify targets, organize logistics, and make battlefield decisions faster. All on classified networks where public oversight is essentially impossible.

Here’s who got deals:

  • Google: Previously partnered with the Pentagon on Project Maven for drone image analysis. Employees protested in 2018. Google didn’t walk away from defense work; it just got quieter about it.
  • OpenAI: Reversed its 2023 ban on military use. Signed a $200 million contract. The only company to publicly negotiate surveillance restrictions [2].
  • Microsoft: Long-standing defense contractor through Azure Government. Already runs classified cloud infrastructure for the Pentagon.
  • Amazon Web Services: Won the $10 billion JEDI cloud contract (later restructured as JWCC). Deep roots in intelligence community infrastructure.
  • Nvidia: Makes the chips everything runs on. Its GPUs power most military AI training.
  • SpaceX: Elon Musk’s company. Already provides Starlink to the military. Now its AI capabilities get classified network access too.
  • Oracle: Database giant with existing government contracts. Part of the JWCC multicloud framework.
  • Reflection AI: A startup. Almost no public information about its capabilities, leadership, or acceptable use policies. The Pentagon gave a largely unknown company access to classified military networks.

Acting Principal Deputy Chief Digital and AI Officer Andrew Mapes said he expects “additional models on classified networks within the next few months” [1]. This is just the first wave.

OpenAI’s Surveillance Restrictions: Better Than Nothing, Barely

OpenAI is the only company that publicly negotiated explicit surveillance restrictions into its Pentagon contract. The revised agreement includes language stating the AI “shall not be intentionally used for domestic surveillance of U.S. persons and nationals,” including “through the procurement or use of commercially acquired personal or identifiable information” [2].

That last part matters. It means the Pentagon can’t use OpenAI’s models to analyze data purchased from data brokers, the kind of warrantless surveillance the government already conducts on a massive scale through companies like Babel Street and LexisNexis.

But the restrictions have gaps:

  • Intelligence agency carveout: OpenAI’s models can’t be used by intelligence agencies without a separate contract modification. That’s not a ban, it’s a speed bump. The NSA just needs to file paperwork.
  • “Intentionally” is doing a lot of work: The restriction only covers “intentional” surveillance. If an AI system analyzing foreign intelligence data happens to sweep up Americans’ communications (as Section 702 programs routinely do) that’s not “intentional” domestic surveillance. It’s incidental collection. Perfectly legal. Completely devastating to privacy.
  • Not yet signed: As of reporting, the revised agreement hadn’t been formally signed [2]. The original “all lawful use” language may still be the operative terms.

Credit where it’s due: OpenAI’s restrictions are more than anyone else negotiated publicly. But “better than nothing” isn’t the same as “adequate.”

“All Lawful Use”: The Clause That Killed Ethics

The Pentagon’s standard contractual requirement is that AI models be available for “all lawful” purposes. That phrase sounds reasonable until you think about what’s currently legal.

Under existing law, the government can legally:

  • Purchase Americans’ location data, browsing history, and app usage from data brokers without a warrant
  • Conduct bulk collection of international communications that sweep up Americans’ data under Section 702 of FISA
  • Use AI to analyze patterns in communications metadata for “foreign intelligence purposes” that happen to involve domestic targets
  • Deploy facial recognition on public surveillance cameras
  • Build profiles of Americans using commercially available data that would require a warrant to obtain directly

All lawful. All surveillance. All now potentially accelerated by the most powerful AI systems ever built, running on classified networks where nobody can audit what they’re actually doing.

This is exactly what Anthropic warned about. CEO Dario Amodei called warrantless AI-powered mass surveillance “a crime against humanity” and refused to let Claude be used this way. The Pentagon’s response: blacklist the company and replace it with seven others who didn’t ask questions [3].

1.3 Million Users, Hundreds of Thousands of AI Agents

The Pentagon isn’t starting from scratch. GenAI.mil, the military’s internal AI portal, already has over 1.3 million users who have built “hundreds of thousands” of AI agents [4]. These new models deploy into an existing infrastructure where military personnel are already building AI-powered tools for intelligence analysis, logistics, and operations.

Think about the scale. Hundreds of thousands of AI agents, running on classified networks, processing secret and top-secret data, built by military users with minimal oversight. Now give those agents access to the most powerful commercial AI models on the planet, models from companies that have either explicitly agreed to “all lawful use” or negotiated restrictions with loopholes you could drive a drone through.

There’s no public reporting requirement for what these agents do. No independent auditor reviewing whether they comply with whatever surveillance restrictions might exist in the classified contract text. No congressional notification when a military AI agent starts analyzing data that includes American citizens’ communications.

The Pentagon’s Responsible AI Principles, adopted in 2020, call for AI that is “governable” and operates with “appropriate levels of judgment and care.” Those principles are non-binding recommendations. The classified contracts are what actually govern behavior. And we can’t read them.

Who Is Reflection AI?

Seven of the eight companies are household names in tech. One isn’t.

Reflection AI is a startup that received classified-network access alongside Google, Microsoft, and Amazon. Public information about the company is thin. Its leadership, funding sources, acceptable use policies, and technical capabilities haven’t been widely reported.

Giving an unknown startup access to Impact Level 6 and 7 systems (the same classification levels that handle secret and top-secret intelligence) raises obvious questions. What vetting process did Reflection go through? What surveillance restrictions, if any, did it agree to? Who are its investors? Does it have acceptable use policies at all?

The Pentagon hasn’t answered any of these questions publicly. When the military’s standard for inclusion is saying yes to “all lawful use,” the bar for access to classified networks appears to be compliance, not capability.

What This Means for You

If you’re an American, your data is already being collected by the intelligence community through Section 702, data broker purchases, and commercial surveillance tools. The Pentagon just gave its 1.3 million AI users access to models powerful enough to analyze all of it at scale.

The one company that drew a line on mass surveillance got punished. The companies that didn’t got rewarded. That sends a clear message to every tech company considering a defense contract: don’t ask about surveillance, don’t negotiate restrictions, and definitely don’t say no.

If you’re an AI company, the lesson is even starker. Anthropic’s supply chain risk designation (for refusing to allow mass surveillance) sits next to seven new deals with companies that accepted “all lawful” use. The Pentagon isn’t subtle about what it values.

And if you’re in Congress: Section 702 just got a 45-day extension with no reform. The Pentagon just deployed commercial AI on classified networks with no public surveillance restrictions. The data broker loophole remains wide open. Every piece of the AI surveillance machine is now in place. The question is whether anyone will do anything about it before the June 14 FISA deadline arrives.

References

  1. Federal News Network: DoD strikes deals with major tech firms to deploy AI on classified networks (May 1, 2026)
  2. SiliconANGLE: OpenAI revises Pentagon contract to address surveillance concerns (March 3, 2026)
  3. CNBC: Pentagon tech chief says Anthropic is still blacklisted, but Mythos is a separate issue (May 1, 2026)
  4. RoboRhythms: The Pentagon Just Picked Seven AI Vendors and Anthropic Wasn’t One (May 2026)
  5. Breaking Defense: Pentagon clears 7 tech firms to deploy their AI on its classified networks (May 2026)
  6. CNN: Pentagon strikes deals with 7 Big Tech companies after shunning Anthropic (May 1, 2026)
  7. Nextgov/FCW: Pentagon makes agreements with 7 companies to add AI to classified networks (May 2026)