OpenAI-Pentagon Agreement: Classified Access and Safety Claims

OpenAI agreed to deploy models on the Pentagon's classified network and described limits on domestic surveillance and autonomous weapons. Compare the Anthropic dispute.

What Altman announced

Late on Friday, February 27, in a post on X, Sam Altman said OpenAI had reached an agreement to deploy its models on the Department of War's classified network. He described OpenAI as building its own "safety stack," engineering controls meant to keep the models from being misused once they are running inside a classified environment OpenAI cannot itself monitor the way it monitors a commercial API. [2][1]

Altman named two conditions he said the deal preserved: "prohibitions on domestic mass surveillance and human responsibility for the use of force, including for autonomous weapon systems." He also said OpenAI would deploy engineers with the Pentagon "to help with our models and to ensure their safety." [1]

Hours after Anthropic was designated a risk

The day before, Dario Amodei had published Anthropic's refusal of the same department's terms, holding back exactly two carve-outs: mass domestic surveillance and fully autonomous weapons. Earlier on the day of OpenAI's announcement, the administration directed agencies to treat Anthropic as a supply chain risk over that refusal, a label until then reserved for foreign adversaries. [1][2]

Atlas interpretation: OpenAI's announcement landed on the department's preferred outcome from that standoff: a frontier lab signed, and it signed within hours of the refusal being punished. Reported side by side, the two conditions Altman named read as close to identical to the two Anthropic would not drop. The department's public complaint about Anthropic had been that a vendor should not constrain how the military uses what it buys, yet the vendor it rewarded made comparable claims about constraining exactly that. [1]

A safety stack is not a binding term

The TechCrunch report describes Altman's prohibitions as engineering commitments, a safety stack and deployed engineers, rather than as contract language. It does not report that the agreement wrote domestic surveillance or autonomous weapons restrictions into anything the department could be held to. [1]

Atlas interpretation: That gap matters more once the department's rationale for punishing Anthropic came apart in court six months later. A judge found the supply chain risk designation was retaliation for the refusal itself, not a security judgment, after finding, among other things, that the department kept pursuing a contract with Anthropic even while calling it a risk. OpenAI's deal is part of why that finding holds together: the department got a vendor willing to describe the same two limits as engineering practice instead of as a term it would accept being bound by, and treated that as the acceptable version of the same request it had just penalized Anthropic for refusing to make binding. [1]

Sources

  1. OpenAI's Sam Altman announces Pentagon deal with 'technical safeguards'

    TechCrunch · Feb 28, 2026

  2. OpenAI strikes deal with Pentagon, hours after rival Anthropic was blacklisted by Trump

    CNBC · Feb 27, 2026