OpenAI announced on February 28 that the Pentagon can use its models in classified settings, as long as use stays within existing law. My read is blunt: this is not OpenAI beating Anthropic on safety. It is OpenAI choosing the only governance language the US government was likely to accept. “Don’t break the law” fits procurement. “Don’t do certain things even if they are lawful” hands a private vendor too much veto power for Washington’s taste.
The most important line in the piece is the law professor’s point that the published excerpt does not give OpenAI a free-standing right to block otherwise lawful government uses. That is the whole story. A contract that says “follow the 2023 DoD autonomous weapons directive and the Fourth Amendment” is very different from a contract that says “OpenAI may refuse any use it considers mass surveillance.” In the first model, interpretation stays with government lawyers, oversight bodies, and later courts. In the second, part of the switch stays with the model supplier. OpenAI got the deal because it gave ground on that question. It should not pretend otherwise.
I also have doubts about the claim that OpenAI can “embed” its red lines directly into model behavior. The article gives no mechanism. Is this a policy layer, a classifier on prompts, a tool-use gateway, model-side refusal tuning, or post hoc auditing? Not disclosed. Classified deployments make a lot of normal safety practice harder: external red-teaming, cloud logging, independent audit, continuous telemetry. The piece says the Pentagon plans to phase in OpenAI and xAI within six months to replace Claude. Six months is a very aggressive timeline for a first classified rollout that also preserves meaningful vendor controls. I don’t buy the confidence until someone describes the actual control plane.
There is also a broader pattern outside the article. Over the last year, frontier labs have split more clearly on defense posture. Anthropic kept leaning into acceptable-use boundaries. OpenAI has grown more explicit about national security work. Meta has also pushed Llama into government and defense-adjacent channels. That divide is partly moral language, but it is also company structure and incentives. OpenAI now carries enormous revenue expectations and compute capex pressure. A company in that position will struggle to insist on “we can bar lawful uses if we dislike them” when a strategic state customer is on the other side of the table.
The Snowden reference in the piece is the right historical warning. The problem is not only outright illegality. The problem is that surveillance and targeting practices often live in gray zones that institutions treat as lawful until years later. AI changes the economics of those gray zones. It reduces the labor needed for triage, correlation, ranking, anomaly detection, and pattern matching. A legalistic backstop sounds sturdy in a press post. In operational systems, it often means the boundary gets tested first and litigated later.
I also think the article flattens the contrast a bit by casting Anthropic as “moral” and OpenAI as “pragmatic.” That misses the power issue underneath. Anthropic was not only making a moral argument. It was trying to preserve ongoing supplier control over downstream use. OpenAI is not purely pragmatic either. It still says it will not deliver a version stripped of safety controls. So the real fight is over who gets final interpretive authority: the state, the vendor, or some shared mechanism. The piece points at that, but the snippet does not develop it.
Three gaps matter more than the rhetoric. First, what telemetry, audit, and rollback powers OpenAI keeps in classified settings is not disclosed. Second, “no mass domestic surveillance” is undefined here: by task, by user, by dataset, or by output use? Not disclosed. Third, the scope of the Claude replacement is unclear. Is this a narrow workflow swap or a core analytic chain? Also not disclosed.
So my conclusion is simple. OpenAI won access, not a new safety model. It moved the hard conflict from contract negotiation to downstream execution. That fits how Washington buys technology. It also spreads accountability so widely that, if this goes wrong, everyone involved will be able to say they followed process. In practice, the softest part of this deal is not the model. It is the word “lawful.”