Google has reached an agreement with the U.S. Department of Defense to supply its artificial intelligence models for classified systems. The Information, citing a person familiar with the matter, reported that the Pentagon can use Google’s tools for “any lawful government purpose” under the deal. That puts Google alongside OpenAI and xAI, both of which have also secured contracts to provide AI models for classified use.
Classified networks support highly sensitive work, including mission planning and weapons targeting. Access to advanced AI is being treated as a core capability. The arrangement also fits into a broader Pentagon procurement effort: in 2025, the department signed contracts worth up to $200 million each with major AI developers, including Anthropic, OpenAI, and Google. Reuters had previously reported that defense officials were pushing AI companies to make their systems available on classified networks without the usual user-facing restrictions.
Safeguards are written into the contract, but the Pentagon holds the final call
According to the report, Google is expected to help modify its AI safety filters at the government’s request. The agreement includes explicit language stating that “the AI System is not intended for, and should not be used for, domestic mass surveillance or autonomous weapons (including target selection) without appropriate human oversight and control.”
The contract also draws a hard line on authority. It says Google does not have the right to “control or veto lawful government operational decision-making,” leaving final decisions on deployment and use with defense officials. Google said it continues to support government agencies in both classified and unclassified work, and added that it remains aligned with the view that AI should not be used for domestic mass surveillance or autonomous weapons without human oversight.
Anthropic remains at odds with the Pentagon over usage limits
The Pentagon has said it does not intend to use AI for mass surveillance of Americans or for fully autonomous weapons, while still maintaining that the government should retain access to AI for any lawful use. That position has clashed with some model providers, especially Anthropic. The company had resisted earlier Pentagon requests to remove safeguards from its Claude models that restrict use in autonomous weapons and domestic surveillance.
The dispute escalated to the point that the Defense Department labeled Anthropic a “supply chain risk”. Even so, interest in its systems inside government agencies has continued. Separate reporting indicates that the National Security Agency obtained access to Anthropic’s advanced “Mythos Preview” model despite that designation. The model is known for strong cyber capabilities and is being used by select organizations to identify vulnerabilities in digital systems.
The standoff between AI developers and defense officials is still unresolved. At issue is how far “all lawful purposes” can extend, and how much of the safety guardrail structure should remain in place inside military environments.

