Google Signs Classified Pentagon AI Deal on the Same Terms Anthropic Refused, Isolating the Safety Lab as the Industry's Lone Holdout
Google signed a classified Pentagon AI agreement on April 28, 2026, granting the Department of Defense access to Gemini frontier models for "all lawful uses" — the exact terms Anthropic refused for fourteen months and that the DoD designated as a supply-chain risk in retaliation. 950 Google employees signed an open letter opposing the deal. Anthropic now stands alone among US frontier labs maintaining contractual carve-outs against autonomous weapons and domestic mass surveillance.
Google Joins OpenAI, xAI, and Microsoft as Classified-Tier Pentagon AI Supplier
Google announced on April 28, 2026, that it has signed a classified Department of Defense AI agreement granting the Pentagon access to Google's frontier Gemini models on classified networks for what the contract language describes as "all lawful uses." The deal closes a fourteen-month strategic question for Google, which had been the last major US frontier lab outside Anthropic to have not formalized classified-tier defense procurement.
The agreement places Google alongside OpenAI (which signed in late 2025), Microsoft (which has provided OpenAI models to DoD via Azure Government), and xAI (which signed in February 2026 with the announcement of Grok Defense). Anthropic — the fifth major US frontier lab — remains in active litigation with the DoD over a supply-chain risk designation issued in February in retaliation for Anthropic's refusal to accept the same "all lawful uses" framing.
Pentagon AI Chief Dr. Radha Plumb confirmed the Google agreement in a statement to CNBC, framing it as part of the DoD's strategy to "build a diversified frontier model supplier base for classified network deployments." The Pentagon's annual classified AI spend is estimated at five point seven billion dollars and growing at over forty percent year over year.
What "All Lawful Uses" Means
The phrase "all lawful uses," central to the contract language, is the same phrase that Anthropic refused for fourteen months and that ultimately triggered the supply-chain risk designation. The phrase is doing substantive work that requires careful reading.
"All lawful uses" means: every deployment of Google's frontier models inside the DoD that does not violate United States law, treaty obligations, or executive order. The phrase explicitly does not require deployments to be ethical, prudent, supported by Google's internal review processes, or consistent with Google's published AI principles. It simply requires that the deployment not be illegal under the applicable legal framework — a framework that, in classified DoD contexts, is broader than commercial law and includes:
- Domestic intelligence collection under specific FISA and intelligence authorities
- Autonomous targeting in declared conflict zones under the laws of war, when proper command authority chains are followed
- Cyber operations under authorities granted to specific commands
These three categories include the two specific use cases — domestic mass surveillance and autonomous weapons targeting — that Anthropic refused to support contractually. Google's acceptance of the "all lawful uses" framing does not commit Google to deploying its models for those use cases, but removes contractual restrictions against doing so.
Google's framing of how those use cases will be handled relies on internal governance review processes rather than contractual carve-outs. Whether internal governance produces the same operational restraint that contractual carve-outs would have produced is the central empirical question of the next twelve to twenty-four months.
950 Google Employees Sign Open Letter
In the days before the April 28 announcement, 950 Google employees signed an open letter to CEO Sundar Pichai urging the company to reject the classified deal or, at minimum, adopt contractual carve-outs analogous to Anthropic's position. The letter is the second-largest organized internal protest against a defense contract in Google's history, surpassed only by the four thousand-signature Project Maven letter of 2018, which forced Google to drop a Pentagon computer-vision contract for drone targeting analysis.
The 2026 letter's three specific demands were:
- Contractual carve-outs analogous to Anthropic's position on autonomous weapons and domestic mass surveillance use cases
- Published internal governance criteria detailing which Pentagon deployments will and will not be approved
- Annual transparency reports on which AI models have been deployed in which DoD contexts
None of the three demands were accepted in the contract that was signed.
Sundar Pichai's internal response, posted late on April 28, framed the deal as compatible with Google's AI principles and committed to using internal governance — rather than contractual restriction — as the operational mechanism for translating principles into deployment decisions. The response did not address the contractual carve-out demand and did not commit to transparency reporting.
The Anthropic Standoff Continues
Anthropic's supply-chain risk designation litigation, filed in late February following the Pentagon's designation memorandum, is currently in an injunction phase that prevents the designation from blocking Anthropic's federal market access while the case proceeds. A federal judge granted the injunction on March 19, 2026, finding that the DoD had likely exceeded its authority by using a national security mechanism to compel a particular contractual term unrelated to actual security risk.
The litigation is expected to extend through 2027 or 2028. It will produce key rulings on whether the Pentagon's mechanism for enforcing all-lawful- uses contracting language survives constitutional and administrative law challenge. If the designation is invalidated by final ruling, the all- lawful-uses framing loses its primary enforcement mechanism, and contractual carve-outs become commercially viable again at the federal level.
In the meantime, Anthropic's exclusion from classified federal AI procurement costs the company approximately six hundred to nine hundred million dollars in annual revenue and an additional one to two billion in adjacencies (federal civilian agencies, state and local government, defense contractor enterprise deployments, allied government procurement that mirrors US classification). At Anthropic's thirty billion dollar annualized revenue base, the absolute number is not existential but is strategically significant.
The $40 Billion Coincidence
The April 28 Pentagon deal arrives four days after Google's April 24 announcement of a forty billion dollar capital commitment to Anthropic — ten billion in immediate cash at a three hundred fifty billion dollar valuation, plus thirty billion in milestone-contingent capital and five gigawatts of Google Cloud capacity over five years. The same boardroom that approved the largest single safety-lab capital event in industry history also approved the classified Pentagon deal that Anthropic's safety-aligned positioning had refused.
The two announcements are not contradictory. Read together, they constitute a strategic hedge: Google captures the near-term operational value of the Pentagon's preferred all-lawful-uses framing through direct procurement, while simultaneously capturing the long-term option value of safety-aligned positioning through equity exposure to Anthropic. The capital flows in opposite directions through transactions four days apart, but both flows serve the same hedged strategic posture.
CrashBytes published a long-form analysis of the four-day sequence today — The Pentagon Capitulation Cascade — covering the strategic implications, the four-vendor Pentagon supplier landscape that has now stabilized, the empirical questions about whether internal governance produces operational restraint comparable to contractual carve-outs, and what to track over the next eighteen months.
Industry Implications
With Google's signature, the Pentagon's classified frontier AI supplier base now includes four anchored vendors (OpenAI, Google, xAI, Microsoft) operating under "all lawful uses" terms and one outlier (Anthropic) in litigation over the same terms. The standoff that defined the AI defense conversation through Q1 2026 has functionally resolved in favor of the Pentagon's preferred framing, with Anthropic's contractual position now commercially isolated rather than industry-shaping.
Three structural implications follow:
For frontier AI valuations. Anthropic's three hundred fifty billion dollar valuation, agreed by Google on April 24, includes a substantial premium for safety-aligned positioning under scenarios where contractual carve-outs become valuable (regulatory shifts, salient defense incidents, enterprise preference consolidation). The premium is now real and being paid by buyers with alternatives. AI ethics positioning has become a priced asset class.
For employee protest dynamics. The 950-signature 2026 letter relative to the 4,000-signature 2018 Project Maven letter represents a meaningful proportional decline in internal opposition, even as Google's headcount has roughly doubled. The 2018 organizational dynamic — internal protest forcing executive reversal — has not held in 2026. Whether Google experiences elevated senior safety staff turnover over the next twelve months is now the leading indicator of whether the internal governance pathway is credible to those who would need to enforce it.
For allied procurement. US allies — particularly the UK, Canada, Australia, and Japan — face the same all-lawful-uses-vs-carve-outs choice the DoD made. Early signals from UK MoD AI procurement and Australian DSTG suggest a more carve-out-friendly orientation than the US DoD, which would position Anthropic favorably for allied work even as US classified markets remain inaccessible during litigation.
What to Watch Next
The eighteen-month window beginning April 28, 2026, is the empirical test of whether Anthropic's contractual position or Google's internal-governance position produces better outcomes on the substantive question of how frontier AI gets deployed in classified contexts.
Key indicators:
- Operational deployment data in periodic Pentagon AI category reports — whether autonomous targeting and domestic surveillance use cases appear in Google's deployment categories
- Senior AI safety staff retention at Google over the next twelve months
- Anthropic litigation rulings as the supply-chain risk case proceeds
- Allied government procurement patterns at UK MoD, Australian DSTG, Canadian DND
- Public opinion trajectory on autonomous weapons, domestic surveillance, and frontier AI deployment
CrashBytes will continue to track the Pentagon AI Schism through the Defense Production Act prediction track and the broader AI safety industry coverage.
Sources
- TechCrunch — Google expands Pentagon's access to its AI after Anthropic's refusal (2026-04-28)
- CNBC — Pentagon AI chief confirms work with Google after Anthropic blacklist (2026-04-28)
- Euronews — Google employees urge CEO to reject 'inhumane' classified military AI use (2026-04-28)
- The Hill — Google workers urge CEO to reject classified AI work with Pentagon (2026-04-28)
- Yahoo Finance — Google inks Pentagon deal for classified AI work despite uproar from employees warning of 'irreparable damage' (2026-04-28)
- TechCrunch — Google to invest up to $40B in Anthropic in cash and compute (2026-04-24)
Further Reading
- The Pentagon Capitulation Cascade — Long-form analysis
- Anthropic's Pentagon Ultimatum and the Defense Production Act
- Anthropic Pentagon Blacklist — How OpenAI Set the Terms
- The AI Reckoning — Pentagon Contracts and Protests