The Pentagon's AI Portal Still Won't Take Claude

The Pentagon's AI Portal Still Won't Take Claude

Days before the Pentagon announced that its secure AI portal now serves ChatGPT and Grok to 3 million military and civilian personnel, a federal judge in California ruled that the label keeping Anthropic out of that same ecosystem was illegal retaliation. The portal launch went ahead anyway. Claude, again, did not make the cut.

That sequencing is the story. The portal announcement everyone covered is real and worth understanding. But the more revealing part is what the Pentagon's shopping list says about what happens to a vendor that attaches conditions to a sale.

What landed this week

GenAI.mil is the Department of Defense's centralized portal for commercial AI models, launched last year with Google Gemini on board. It exists for one reason: to give DoD staff frontier models without routing sensitive government data through consumer channels. The military versions are exempt from the data collection that's effectively unavoidable in consumer tech products. According to the department, the portal already has more than 1.7 million unique users out of 3 million total personnel, which tells you adoption happened well before this week's headlines.

ChatGPT Mil came out of OpenAI's OpenAI for Government program. The department describes it in surprisingly clerical terms: chat, files, projects, custom GPTs, and document-heavy routine unclassified work like administrative tasks, logistics, planning, and policy. Familiar interface, boring jobs, no classified material.

Grok for Government arrived via SpaceX's Starshield AI, and the framing is noticeably different. The press release talks about giving "the warfighter" productivity gains, knowledge continuity, and collaboration, with uses ranging from market research for acquisition professionals to supply-chain management for logisticians. Read the two descriptions side by side. One is a filing tool with a nice chat window. The other is being positioned closer to operations.

The vendor that said no

Anthropic's absence from the portal is documented in the same coverage. The company was designated a supply-chain risk by the Trump administration after it refused to give the Pentagon unrestricted use of its models and insisted on certain safety guardrails. Per the later court reporting, the guardrails in dispute were about two specific uses: fully autonomous weapons and mass surveillance of American citizens.

The Pentagon's side of the argument was that it only intended lawful use, and that Anthropic was trying to control how the military used models it had bought and paid for. Last Thursday evening, US District Judge Rita Lin ruled on the dispute. Her findings were blunt. The designation amounted to "unlawful retaliation" in violation of the First Amendment. The decision was "arbitrary and capricious." Anthropic was denied due process under the Fifth Amendment.

Lin also catalogued the contradictions. Defense Secretary Pete Hegseth had proposed applying the Defense Production Act to Anthropic, a mechanism for companies essential to national security, which sits awkwardly next to calling the same company a threat. The department kept pursuing a contract with the firm. The government is collaborating with Anthropic's Mythos model on cybersecurity. And she noted Anthropic undisputedly lacks any backdoor access to its technology once handed to the DoD. Her line worth pinning to the wall: "The empty invocation of national security is not a blank check to punish and retaliate against government critics."

My read

"Supply-chain risk" is a procurement category with an actual job. It exists to flag real dependencies and real threats in the acquisition chain. Using it to punish a vendor for attaching contract terms turns a risk instrument into a bargaining tool, and Judge Lin saw exactly that. The moment a label can be applied for saying no and removed by a court, every vendor pricing a government deal has to add a political-risk line next to the compliance one.

I keep coming back to the timing. The ruling landed, and three days later the portal expansion shipped without Claude. Maybe that's just administrative reality: onboarding a model takes longer than a news cycle, and an appeal could keep the label functionally alive. Maybe the lineup was the message. I honestly can't tell from the outside, and I suspect the distinction doesn't matter much to the company locked out either way.

There's also a quieter lesson for anyone selling AI to governments. A usage policy reads like product documentation until your customer is the state, at which point refusing two use cases reads as a public position, and a public position is protected speech, and now you're in federal court explaining procurement to a First Amendment judge. Anthropic's terms were ordinary commercial boundaries. The machinery that responded was not ordinary.

And while the argument about military AI usually jumps to autonomous weapons, what's deployed looks a lot like enterprise software: policy drafts, logistics planning, acquisition research, 1.7 million accounts. The scary story and the real story are running on separate tracks, and the real one is already at scale.

What to watch

First, whether the government appeals or formally lifts the designation, and whether Claude eventually shows up on GenAI.mil. Second, whether other AI vendors tighten or quietly drop their usage terms now that they've watched what holding the line costs, and what it won. Third, the contract language in upcoming federal AI solicitations, where usage clauses and indemnification will tell you which lessons the market drew from all this.

The portal will keep adding models. The question that shapes the next decade of defense AI isn't which ones get in. It's whether "no" stays a word a vendor is allowed to say.