The Pentagon Gave 3 Million Employees AI Access — Just Not Claude, and the Reason Matters

Entercast Consulting·

On August 31, the Pentagon added OpenAI's ChatGPT Mil and Starshield/SpaceX's Grok for Government to GenAI.mil — the internal AI portal that already gave Google's Gemini to the US Department of Defense's 3 million employees. More than 1.7 million users have already been onboarded. It's one of the largest enterprise generative AI rollouts in the world, and it reveals a governance pattern worth studying regardless of your company's size — alongside a notable absence.

What Changed

GenAI.mil launched in December 2025 with only Gemini and has now become multi-vendor, offering sandboxed, secure access to frontier commercial models for sensitive but unclassified work — planning, policy, logistics, administration — without routing data through ordinary consumer AI apps. The core idea: instead of banning generative AI outright (which historically pushes employees toward using tools off the books, with no oversight), the Pentagon built a governed portal with multiple approved models. One absence stands out on that list: Anthropic's Claude isn't on GenAI.mil. In February, the Pentagon asked Anthropic to allow use of the model for "all lawful purposes," including fully autonomous weapon systems and mass domestic surveillance; Anthropic refused those two specific use cases, citing AI's unreliability for operating weapons and the lack of clear regulation for mass surveillance. In response, the Trump administration ordered federal agencies to immediately cease using Anthropic's technology, with the Department of Defense reportedly expecting to complete its migration away from Claude by September 30.

Why It Matters

The practical value here isn't picking a side in the Pentagon-Anthropic dispute — it's recognizing two governance lessons any large company can apply. First: giving controlled, monitored access to multiple approved models curbs "shadow AI" (unsanctioned use of AI tools outside company controls) more effectively than an outright ban — a point already reflected in Gravitee's numbers on the corporate AI governance gap. Second: a vendor's risk posture and usage policies are now, themselves, a selection criterion — not just price or benchmark performance.

The Impact for Brazil

Large Brazilian companies — banks, telecoms, public agencies — face the same binary choice the Pentagon faced: ban generative AI outright (which rarely works) or build a governed "access gateway," with approved models, usage monitoring, and a clear separation between sensitive data and consumer-grade tools. GenAI.mil's multi-vendor portal architecture is replicable at smaller scale with the same principles: sandboxed access, usage auditing, and an explicit policy on which model handles which kind of task — the same rationale we saw with AT&T's model routing, now applied to the access-governance layer.

Entercast's Take

This episode ties together two threads we've followed this week: the trust placed in an AI output (the theme of Forcepoint's finding) and the risk a vendor's stance can pose to the business itself (the theme of Sony and Warner Chappell's lawsuit against Anthropic). Claude's absence from the US government's largest AI portal isn't about which model is "better" — it's about the fact that, in 2026, choosing an AI vendor carries a risk-and-values decision, not just a performance one. The same question applies to any company building its own AI access policy: what kind of use does your vendor accept, and what happens if that policy changes due to a regulatory or commercial decision?