March 11, 2026

The Pentagon Just Handed Google the Keys to Its AI Workforce. Here's What Nobody's Saying Out Loud.

What is actually happening here is not a product launch or a legal squabble. It is the U.S. government choosing, in real time, which companies will build the operating layer for AI inside the world's largest employer. And the consequences — for defense, for AI governance, and for every company trying to do business with the federal government — are enormous.

The Pentagon at dusk with an American flag in the foreground.

Some Key Terms

GenAI.mil: The DoD's enterprise AI platform, launched December 2025, providing secure access to commercial AI models for unclassified work. This is the front door for AI across the entire U.S. military. Over 1 million personnel already use it.

Agent Designer: A new no-code/low-code feature on GenAI.mil that lets users build custom AI agents using plain language. Any DoD employee can now create automated multi-step workflows without writing a single line of code.

Supply Chain Risk (FASCA): A designation under the Federal Acquisition Supply Chain Security Act of 2018, banning a company's products from defense contracts. Usually aimed at foreign adversaries. Anthropic is the first American company ever publicly given this label.

"All Lawful Purposes": The Pentagon's contractual requirement that AI vendors allow unrestricted use of their models for any activity permitted by U.S. law. This is the exact phrase that split the AI industry. Anthropic refused it. OpenAI, Google, and xAI accepted it.

IL5 / CUI: Impact Level 5 and Controlled Unclassified Information — the security classifications GenAI.mil is certified for. This means the platform can handle sensitive (but not classified) defense data — a huge scope of day-to-day military work.

Mental model: Think of GenAI.mil as a government-issued smartphone that every DoD employee carries. Until now, it came with one pre-installed app (Gemini). Agent Designer just turned it into an app store where anyone can build their own tools. The Anthropic fight is about who gets banned from that store — and why.

What Changed: The Facts

Let's separate the timeline from the noise.

December 9, 2025: The DoD launched GenAI.mil with Google Cloud's Gemini for Government as its first enterprise AI tool, certified at IL5 for unclassified work across all 3 million DoD personnel. The platform was positioned as the backbone of the Pentagon's "AI-first workforce" strategy under Defense Secretary Pete Hegseth and CTO Emil Michael.

December 22, 2025: xAI signed an agreement to integrate Grok into GenAI.mil for both unclassified and classified use.

January 29, 2026: Reuters reported the Pentagon and Anthropic were at an impasse over contract terms. The dispute centered on two specific restrictions Anthropic insisted on keeping: no mass domestic surveillance and no fully autonomous weapons. The Pentagon demanded "all lawful purposes" access.

February 22–23, 2026: xAI finalized a deal to deploy Grok in classified military systems, accepting the "all lawful purposes" standard. Until that point, Anthropic's Claude had been the only AI model operating in classified environments.

February 27, 2026: Two things happened on the same day. President Trump directed federal agencies to "immediately cease" all use of Anthropic technology. Hours later, OpenAI announced it had reached its own agreement with the Pentagon for classified deployments — complete with red lines on surveillance, autonomous weapons, and high-stakes automated decisions — but structured through a cloud-only deployment with OpenAI engineers in the loop.

March 4, 2026: The Pentagon formally notified Anthropic that it was designated a supply chain risk under FASCA, effective immediately.

March 9, 2026: Anthropic filed two lawsuits — one in the U.S. District Court for the Northern District of California and one in the D.C. Circuit Court of Appeals — arguing the designation violates the First and Fifth Amendments and exceeds statutory authority.

March 10, 2026: Google announced Agent Designer on GenAI.mil. The same day, Microsoft filed an amicus brief supporting Anthropic, arguing a temporary restraining order is needed to prevent "disruptions to the American military's ongoing use of advanced AI."

That is a lot of movement in 10 weeks. And none of it is random.

What Agent Designer Actually Does

Strip away the press release language and here is what landed on Tuesday.

Agent Designer is a no-code/low-code platform inside Gemini for Government on GenAI.mil. Using natural language — plain English prompts, not programming — DoD personnel can build AI agents that perform multi-step tasks, ingest various data sources, and get shared with teams for immediate deployment.

The Pentagon CTO's office spelled out use cases explicitly: operators can automatically generate after-action reports, analysts can synthesize CUI images into memos, and comptrollers can build apps to analyze financial data. Eight pre-built agents ship at launch.

This is not a chatbot upgrade. It is a workflow factory. The difference between asking Gemini a question and building an agent with Agent Designer is the difference between asking a colleague for help and hiring an assistant who shows up every day, follows a procedure you wrote, and works across your systems automatically.

In just over one month since GenAI.mil launched, the platform surpassed one million unique users. Five of six military branches have designated it as their primary enterprise AI productivity platform.

Emil Michael, the under secretary of defense for research and engineering, signaled that classified deployment of Google's tools is the next step:

"We're starting with unclassified because that's where most of the users are, and then we'll get to classified and top secret. I have high confidence they're going to be a great partner on all networks."

Read that quote again. Google is not just winning the unclassified layer. It is being positioned for the classified layer too.

Why Anthropic Got Blacklisted (and What It Really Means)

The surface story is simple: Anthropic refused to let the Pentagon use Claude without restrictions, so the Pentagon cut them off. But the actual dynamics are far more tangled and far more consequential.

Anthropic drew two hard lines. No mass surveillance of American citizens. No fully autonomous weapons without human control. CEO Dario Amodei framed these as foundational to the company's mission, stating that supporting national defense should not require enabling capabilities that "would make us more like our autocratic adversaries."

The Pentagon's position is equally blunt: a private contractor does not get to dictate how the U.S. military uses technology within the bounds of the law. A senior defense official told CNBC: "This has always been about one core issue: ensuring the military can use technology for all lawful purposes. The military will not allow a vendor to insert itself into the chain of command."

Here is the part that makes the situation genuinely complicated. Even after the ban, the U.S. military continued using Claude in active combat operations. During the recent strikes on Iran, U.S. Central Command used Claude — through Anthropic's partnership with Palantir — for intelligence analysis, target identification, and battle simulations. Over 1,000 targets were struck in the first 24 hours using AI-assisted targeting. The phase-out is expected to take at least six months because Claude is so deeply embedded in operational systems.

So to be clear: the Pentagon labeled Anthropic a national security threat while simultaneously depending on Anthropic's technology in an active war. That contradiction tells you more about the real dynamics than any press statement.

The OpenAI Deal: Same Red Lines, Different Packaging

OpenAI's agreement — announced the same day Trump banned Anthropic — deserves a close read because it reveals how the same principles can produce opposite outcomes depending on how they are structured.

OpenAI's three red lines are nearly identical to Anthropic's: no mass domestic surveillance, no autonomous weapons systems, and no high-stakes automated decisions like "social credit" systems.

But the structural differences matter. OpenAI's deployment is cloud-only (no edge devices that could enable autonomous weapons). OpenAI retains full control over its safety stack and runs classifiers independently. Cleared OpenAI engineers are embedded with the Pentagon to monitor usage. And the contract language explicitly references current law — meaning even if surveillance or weapons laws change in the future, use of OpenAI systems must still align with today's standards.

Sam Altman publicly stated that OpenAI does not believe Anthropic should be designated a supply chain risk, and that OpenAI asked the Pentagon to extend the same contract terms to all AI labs.

On the surface, the difference between OpenAI's deal and Anthropic's position looks narrow. Both oppose mass surveillance. Both oppose autonomous weapons. The critical gap appears to be in the contractual mechanism: Anthropic wanted explicit prohibitions written by Anthropic. OpenAI embedded its protections through deployment architecture and technical safeguards controlled by OpenAI engineers.

The cynical read: Altman found a way to say "yes" to "all lawful purposes" while engineering a system where the unlawful purposes cannot technically happen. The charitable read: he built a genuinely better mousetrap for safety in classified environments. The honest read: both are probably true.

Google's Quiet Power Play

While Anthropic and OpenAI dominated the headlines, Google executed the most consequential move. It was not dramatic. It was structural.

Google was the first AI provider on GenAI.mil. It now has 1 million-plus active users on the platform. It just shipped the tool that lets those users build their own agents. And it is in active discussions for classified deployment.

Remember, Google walked away from Project Maven in 2018 after employee protests over using AI for drone surveillance analysis. Seven years later, it is deeper inside the Pentagon's AI infrastructure than any other company. The political and corporate calculus around military AI has shifted dramatically since then.

Agent Designer is particularly significant because of what it enables at scale. It is not Google deploying agents for the military. It is Google giving the military the tools to build and deploy its own agents — which changes the accountability model, the adoption curve, and the stickiness of the platform in fundamental ways.

Once thousands of custom agents are built on GenAI.mil by DoD personnel, tailored to their specific workflows and data sources, switching to a different platform becomes extraordinarily expensive and disruptive. This is the same platform lock-in dynamic we covered in last week's piece on agent control planes — except now it is happening inside the U.S. Department of Defense.

Three months ago, Anthropic was the only company in classified environments. Now it is being replaced by three competitors while fighting for survival in federal court.

The Legal Fight That Will Shape AI Governance

Anthropic's lawsuits are not just about saving a contract. They are testing a legal question that has never been answered: Can the U.S. government punish a domestic technology company for exercising ethical restrictions on its own products?

Anthropic's complaints argue five points: the designation is "arbitrary and capricious" under the Administrative Procedure Act; it violates First Amendment rights (punishing Anthropic for protected speech about AI safety); Trump exceeded Article II authority with his directive; Anthropic was denied due process; and the 17 named federal agencies each exceeded their statutory authority.

The FASCA statute Anthropic is being designated under was designed to protect government supply chains from foreign adversaries. Legal experts have noted that applying it to a domestic company over a policy disagreement — not an espionage or sabotage concern — is unprecedented. Lawyers quoted by The Information said Anthropic "will likely win this suit" because "the supply chain risk designation is mostly meant for foreign companies."

Microsoft's amicus brief — filed the same day as Google's Agent Designer launch — adds a powerful wrinkle. Microsoft, which integrates Anthropic's technology into its own DoD solutions, argued that immediate enforcement would "hamper U.S. warfighters at a critical point in time" and urged a temporary restraining order for all existing contracts.

The hearing on Anthropic's request for a temporary injunction was scheduled for the same afternoon the brief was filed.

If Anthropic wins, it establishes that AI companies retain the right to set usage boundaries on their technology, even for government customers. If Anthropic loses — or if the case is mooted by a settlement — the precedent is the opposite: comply fully or get blacklisted, with your competitors ready to fill the gap.

The Uncomfortable Questions

This is where the narrative gets messy, because both sides have legitimate points and neither is being fully honest about the tradeoffs.

Is the Pentagon right that a private vendor should not have veto power over lawful military operations? If the government legally procures a tool, the tool-maker deciding mid-contract which operations are acceptable creates operational risk. Imagine a weapons manufacturer refusing to let the military use ammunition in a conflict it deems unjust. That is not how procurement works.

Is Anthropic right that "all lawful purposes" is doing extraordinary heavy lifting when the laws governing AI in military contexts have not caught up to the technology's capabilities? What is "lawful" regarding AI-powered bulk data analysis of American citizens? The legal framework is ambiguous at best. Anthropic's concern is not hypothetical. It is about the gap between what the law technically permits and what the technology can actually do.

OpenAI's deal exposes the tension. Altman accepted "all lawful purposes" but built a system that makes the problematic purposes technically impossible — cloud-only, no edge deployment, safety stack under OpenAI control. That is clever engineering. It is also a bet that the current deployment architecture will hold against future government demands to expand access.

Google's move raises the deepest question. Agent Designer hands the agent-building capability directly to DoD users. If a military analyst builds an agent that processes bulk surveillance data, whose guardrail failed? Google provided the platform. The analyst built the agent. The chain of command approved the workflow. The accountability is deliberately distributed in a way that no single entity owns.

What This Means for Federal Contractors

If you are in the federal contracting space, the Anthropic situation rewrites the risk calculus for any company that touches DoD AI.

The supply chain risk designation requires defense vendors and contractors to certify they do not use Anthropic's models in their Pentagon work. Eight of the top ten U.S. companies use Claude in some capacity. The ripple effects are immediate and real.

For small and mid-size contractors, the lesson is stark: your technology stack is now a compliance risk. If you build on a provider that falls out of favor with the current administration, you do not get a negotiation period. You get a certification requirement and a deadline. Diversifying your AI vendor dependencies is no longer optional.

For companies looking to enter the federal AI space, GenAI.mil and Agent Designer represent a massive opportunity and a massive dependency. Building agents and workflows on the platform positions you as part of the ecosystem. Building exclusively on the platform positions you as a hostage to Google's roadmap.

Final Thought

Here is the blunt version. The Pentagon just gave Google's no-code agent builder to over a million people while simultaneously blacklisting the only AI company that said "no" to unrestricted military use.

Whether you think Anthropic is principled or naive, whether you think the Pentagon is pragmatic or overreaching, the structural outcome is the same: the companies that said "yes" are building the infrastructure layer for U.S. military AI. The company that said "no" is in court.

For operators, contractors, and technologists watching this space: the rules of engagement between AI companies and the U.S. government are being written right now — in courtrooms, in contract language, and in the quiet expansion of platforms like GenAI.mil. The time to understand what is being built, and who controls it, is before the next crisis, not during it.

References

  1. Google Cloud Blog: Gemini for Government: Build custom AI agents for unclassified work on GenAI.mil (March 10, 2026)
  2. DefenseScoop: Pentagon says employees can create their own 'custom AI assistants' with new tech (March 10, 2026)
  3. 9to5Google: Gemini agents greenlit for Department of Defense unclassified work (March 10, 2026)
  4. Benzinga: Google Launches AI Agent Builder for Military, Civilians (March 10, 2026)
  5. The Tech Portal: Pentagon to use Google's AI agent builder for unclassified operations (March 11, 2026)
  6. DoD Press Release: The War Department Unleashes AI on New GenAI.mil Platform (December 8, 2025)
  7. Google Cloud Press: CDAO Selects Google Cloud's AI to Power GenAI.mil (December 8, 2025)
  8. GovCIO Media: GenAI.mil Makes Debut as DOW Pushes Commercial AI at Scale (December 14, 2025)
  9. Fox Business: Pentagon launches military AI platform powered by Google Gemini (December 7, 2026)
  10. NPR: Anthropic sues the Trump administration over 'supply chain risk' label (March 9, 2026)
  11. Axios: Anthropic sues Pentagon over rare "supply chain risk" label (March 9, 2026)
  12. AP News: Anthropic seeks to undo 'supply chain risk' designation (March 9, 2026)
  13. Fortune: Anthropic sues the Pentagon after being labeled a threat to national security (March 9, 2026)
  14. Washington Post: Anthropic sues Pentagon over being labeled a national security risk (March 9, 2026)
  15. Lawfare: Anthropic Challenges the Pentagon's Supply Chain Risk Determination (March 9, 2026)
  16. TechCrunch: Pentagon has labeled Anthropic a supply-chain risk (March 5, 2026)
  17. Bloomberg: Pentagon Notifies Anthropic It's Deemed Firm a Supply-Chain Risk (March 5, 2026)
  18. Reuters: Pentagon designates Anthropic a supply chain risk (March 5, 2026)
  19. CNBC: Anthropic officially told by DOD it's a supply chain risk even as Claude used in Iran (March 5, 2026)
  20. OpenAI: Our agreement with the Department of War (February 28, 2026)
  21. NYT: OpenAI Reaches A.I. Agreement With Defense Dept. (February 27, 2026)
  22. CNN: OpenAI strikes deal with Pentagon hours after Trump admin bans Anthropic (February 27, 2026)
  23. Axios: Musk's xAI, Pentagon reach deal to use Grok in classified systems (February 23, 2026)
  24. Reuters: Microsoft files amicus brief in support of Anthropic (March 10, 2026)
  25. The Hill: Microsoft backs Anthropic in lawsuit against Trump admin (March 10, 2026)
  26. Responsible Statecraft: US used 'Claude' to strike over 1000 targets in first 24 hours (March 4, 2026)
  27. CBS News: Anthropic's Claude AI being used in Iran war (March 2, 2026)
  28. Washington Post: Pentagon leverages AI in Iran strikes amid feud with Anthropic (March 4, 2026)
  29. Bloomberg Government: Pentagon Notifies Lawmakers Anthropic Is a [title truncated in source fetch]