On April 28, TechCrunch — citing The Wall Street Journal and other outlets — reported that Google has agreed to let the U.S. Department of Defense run its AI on classified networks, with wording that effectively permits “all lawful uses.” Google becomes the third vendor to take a defense AI contract after Anthropic refused the Pentagon’s terms, following OpenAI and xAI. Google did not respond to a request for comment.
The significance is not technical. It is structural: when the largest buyer (the Pentagon) insists on unrestricted use, and the most principled seller (Anthropic) has already been branded a “supply-chain risk,” every remaining AI company faces the same question — do you want the market, or do you want the guardrails? Google just answered with its signature.
What the Deal Covers: “All Lawful Uses” on Classified Networks
Per the WSJ, the agreement lets the DoD deploy Google’s AI tools in classified settings, in practice allowing all lawful uses. The report notes the contract includes language stating Google does not intend its AI to be used for domestic mass surveillance or autonomous weapons — phrasing similar to OpenAI’s defense contract. The WSJ is explicit, though, about what that language is worth: it remains unclear whether such provisions are legally binding or enforceable in any way.
So this is a contract of “in principle anything goes, but please don’t do these two things.” The Pentagon gets the unrestricted access it has demanded all along; Google gets a carve-out statement to serve as public-relations and legal cushioning.
The Anthropic Precedent: The Price of Saying No
The backdrop is the sharpest standoff between the AI industry and government of the past two months. The Pentagon wanted unrestricted-use terms; Anthropic insisted on guardrails against domestic mass surveillance and autonomous weapons, and the negotiation collapsed. In early March, the DoD designated Anthropic a “supply-chain risk” — a label normally reserved for foreign adversaries. Anthropic sued, and in late March a judge froze the designation while the case proceeds.
Meanwhile, the companies willing to cooperate collected their tickets one by one: OpenAI signed its own DoD agreement in early March (at the cost of internal controversy and an executive departure), and xAI’s Grok had already made it onto the Pentagon’s classified systems. Google’s decision effectively settles the contest — among major frontier-AI vendors, only Anthropic, now in litigation, remains outside.
For vendors watching from the sidelines, the sequence reads like a case study in procurement leverage. The buyer never negotiated Anthropic’s guardrails away; it simply reclassified the seller. Once that tool existed on the table, every subsequent negotiation started from a weaker position for whichever vendor cared most about usage limits.
Internal Pushback: 950 Employees Sign a Letter
It is not quiet inside Google either. Roughly 950 employees signed an open letter at notdivided.org urging the company to follow Anthropic’s example and refuse to sell AI to the DoD without comparable guardrails. That is a minority of Google’s headcount, but it continues a long-running split inside big tech over defense work — from Project Maven to now, the script keeps repeating. The echoes of 2018, when employee protests led Google to let its drone-imagery contract lapse, are explicit in the letter’s framing.
What It Means for the AI Procurement Market
Three observations. First, guardrails are shifting from “product feature” to “bargaining chip”: when your counterparty is the single largest government customer, terms negotiation is market-structure negotiation. Second, if the carve-outs are not enforceable, their practical weight is close to declarative text — but that is exactly why they may become the template for future government AI contracts, letting every vendor cooperate “principledly.” There is also a subtler shift at work: the language moves responsibility for misuse from contract terms into intent. A vendor that “does not intend” mass surveillance is not a vendor that has contractually prevented it. Buyers get flexibility, vendors get cover, and nobody gets an enforceable boundary. Third, for startups and suppliers hoping to sell AI into government, the episode sets a clear price of admission: accept all lawful uses.
The final outcome of Anthropic’s lawsuit will determine whether the “supply-chain risk” label can become a routine procurement weapon. That is the thread worth tracking for any AI company that counts government among its customers.
Sources
- Google expands Pentagon’s access to its AI after Anthropic’s refusal — TechCrunch
- Google clears Pentagon to use AI tools in classified settings — The Wall Street Journal
- Employee open letter — NotDivided.org
AI-assisted summary compiled from the sources above, reviewed by a human before publishing.
