The Pentagon has signed agreements with Nvidia, Microsoft, Amazon Web Services, and Reflection AI to deploy their hardware and models on classified U.S. military networks, the Defense Department said Friday. The deals authorize use inside Impact Level 6 and Impact Level 7 environments, the highest classifications for data systems deemed critical to national security. They follow earlier contracts with Google, SpaceX, and OpenAI, bringing the count of cleared AI vendors well past a half dozen in a matter of weeks.
The DoD said its secure generative AI platform, GenAI.mil, has now been used by more than 1.3 million personnel for unclassified work such as research, document drafting, and data analysis. The new agreements push beyond that perimeter into classified operational use, where IL6 and IL7 systems require physical protection, strict access controls, and continuous audits. The stated goal is to "streamline data synthesis, elevate situational understanding, and augment warfighter decision-making."
"These agreements accelerate the transformation toward establishing the United States military as an AI-first fighting force and will strengthen our warfighters' ability to maintain decision superiority across all domains of warfare," the department said in its statement. The framing is deliberate: the Pentagon is signaling AI is moving from back-office staff work into the kill chain.
Key facts
- 01The Pentagon signed deals with Nvidia, Microsoft, AWS, and Reflection AI to deploy AI models on classified networks.
- 02Models will run inside Impact Level 6 and Impact Level 7 environments, the DoD's highest data security tiers.
- 03GenAI.mil, the Pentagon's enterprise generative AI platform, has reached 1.3 million DoD users.
- 04The deals follow earlier agreements with Google, SpaceX, and OpenAI, and exclude Anthropic, which is fighting the DoD in court.
- 05Anthropic won a March injunction blocking the Pentagon from labeling it a 'supply chain risk.'
The vendor sweep also reflects a clear procurement doctrine. "The Department will continue to build an architecture that prevents AI vendor lock-in and ensures long-term flexibility for the Joint Force," the statement reads, adding that "access to a diverse suite of AI capabilities from across the resilient American technology stack will give warfighters the tools they need to act with confidence and safeguard the nation against any threat."
“GenAI.mil, the Pentagon's secure generative AI platform, has now been used by more than 1.3 million Defense Department personnel for unclassified work like drafting and research.”— Jaeden Schafer
The conspicuous absence is Anthropic. The DoD wanted unrestricted use of Anthropic's models; Anthropic refused, citing internal guardrails against domestic mass surveillance and autonomous weapons applications. The two sides are now in litigation, and in March, Anthropic won an injunction blocking a Pentagon attempt to brand it a "supply chain risk" — a designation that would have effectively ended its federal business.
As we covered last week, the original classified-network awards went to OpenAI, Google, and Nvidia while Anthropic was shut out. Friday's announcement extends that lineup, adding Microsoft and AWS — the two largest cloud operators in federal — alongside Reflection AI, a smaller frontier-model startup. The list reads as a deliberate map of the American AI stack: chips from Nvidia, hyperscale clouds from Microsoft and Amazon, and frontier models from OpenAI, Google, and Reflection.
For Nvidia, the deal locks in another tranche of high-margin demand for accelerator hardware destined for air-gapped facilities. For Microsoft and AWS, classified workloads command premium pricing and have famously sticky retention; once a workload is certified at IL6 or IL7, it rarely moves. Reflection AI is the surprise on the list, getting a federal seat at the table well ahead of its commercial scale.
The Joint Force will use the new tools for what the Pentagon described as "lawful operational use," though the statement did not detail which specific commands or programs go first. IL6 covers classified information up to Secret; IL7 is reserved for the most sensitive national security systems. Running modern frontier models inside those environments requires either on-premises GPU clusters or sovereign cloud regions, both of which Microsoft and AWS already operate for the intelligence community.
The bet is not without friction. Diverse vendor stacks reduce lock-in but multiply integration cost, and military operators will need to evaluate competing models on classified data they cannot share with the labs that built them. Anthropic's stance — that some uses should remain off-limits — is also not a fringe position inside the industry, and other vendors will face the same questions once their models are inside live operational loops. Meanwhile, the litigation between Anthropic and the DoD remains unresolved.
The strategic read is that the Pentagon now treats frontier AI the way it treats jet engines or satellite buses: a critical input where dual-sourcing is policy, not preference. That is good news for Nvidia, Microsoft, and AWS, which collect federal revenue without having to win an exclusive. It is harder news for any lab that wants to set its own ethical terms with the largest customer in the world. The DoD has made clear it would rather buy around a holdout than negotiate with one.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




