
Defense organizations need to decide who can approve AI use before deployment begins. Government leaders define the mission, while provider terms and platform controls shape which applications can reach classified systems.
A defense organization can buy access to a commercial AI model without gaining full control over how that model gets used. The provider establishes acceptable-use policies. The government customer defines the mission, while a platform vendor may connect the model to classified data and operational workflows. When those interests conflict, the organization should already know who has final authority.
JC Christian and I discussed this issue on the AI Builders Podcast, including the disagreement over Claude’s military use and Palantir’s role in classified deployment.
Key Takeaways From the Article
- Defense organizations should define AI decision authority before deployment and document how conflicts between provider terms and mission requirements will be resolved.
- Model providers retain influence after deployment because their usage policies and access terms can determine which defense applications remain available.
- Platform vendors can control how commercial models connect to classified data, creating an additional layer of authority alongside the model provider.
- Diversifying across AI providers reduces operational exposure, though replacing and revalidating a model inside a classified environment can still take considerable time.
Commercial AI Providers Still Influence Military Use
A signed model contract can still leave operational authority unresolved. Anthropic was the first frontier AI company to deploy its models on classified U.S. government networks, and in July 2025 it received a Defense Department agreement with a ceiling of $200 million. That relationship came under strain in early 2026, when the Pentagon sought terms authorizing Claude for any lawful use while Anthropic held firm on restrictions covering fully autonomous weapons and domestic mass surveillance.
The later dispute exposed disagreement over how much authority Anthropic could retain over Claude’s permitted uses once the technology was deployed for defense.
The Model and the Operational Platform Carry Different Authority
The Claude deployment also involved a separate infrastructure relationship with Palantir. Anthropic supplies the model, while Palantir supplies the secure environment that connects it to classified government data and military systems, through an IL6-accredited platform built with AWS. Through this partnership, government customers can access Claude inside classified environments using Palantir AIP on AWS.
Each company controls a different part of the deployment. Control over model access may sit with one organization, while responsibility for integration belongs to another. Deployment approval can rest elsewhere. Assigning authority means accounting for the model agreement and the infrastructure relationship together.
Provider Dependence Can Become a Mission Risk
Ask what happens if a provider changes its terms, loses its access, or refuses a use case the mission needs. An organization built around one model inherits whatever risk comes with that provider's decisions, on a timeline it doesn't control. The Anthropic dispute forced that scenario into the open, even though the Pentagon already held agreements with several frontier AI companies. Multiple provider agreements can coexist with a slow replacement process inside classified systems.
On the podcast, I supported diversifying across AI providers. Dependence on one company’s technology and policies can create security exposure by concentrating critical capabilities in one place.
Evaluate a backup provider well before a dispute forces the question. Revalidating a model inside a classified environment can take considerable time, and that time is exactly what a live mission doesn't have.
Who Holds Final Approval Over Defense AI Use?
Several parties can plausibly claim a piece of this authority, and the Anthropic case shows how unresolved that can stay even after a contract is signed:
- The provider decides which use cases its technology will support.
- The government defines what counts as a lawful military objective.
- Defense leaders decide what moves into operational use.
- Security reviewers assess how a system handles protected information before it gets there.
Undefined authority can delay deployment or leave consequential decisions undocumented.
The Leadership Mandate Must Match the Decision
This division of authority shapes the leadership mandate. A VP of AI, or whoever holds the equivalent title, needs authority that matches the decisions described above. The executive should be able to evaluate provider restrictions and coordinate with government stakeholders. Their mandate must also cover recommendations about what reaches deployment. The hiring specification should state which decisions the executive can make without additional approval.
Questions Defense Leaders Should Answer Before Deployment
- Who can approve or reject a proposed AI use?
- Which provider restrictions apply to the mission you're deploying into?
- How quickly could the organization replace its primary model if it had to?
- Who owns revalidation after a provider or model changes?
- Which decisions require government sign-off before they can move forward?
How Christian & Timbers Assesses Defense AI Leadership
Christian & Timbers begins defense AI leadership searches by defining where decision authority sits and which approvals the executive will own. The mandate determines the experience that receives the greatest weight during candidate assessment.
A VP of AI responsible for provider selection needs experience evaluating technical dependencies and contractual restrictions. A leader overseeing classified deployment also needs judgment shaped by secure operating environments and government requirements.
The firm recruits VP of AI, VP of Engineering, Chief Digital Officer, general manager, and program leadership candidates across defense technology, autonomy, physical AI, and aerospace. Each search examines the decisions candidates have already owned and how their experience fits the organization’s deployment environment.
If your organization is building out defense AI leadership, talk with our team.

Frequently Asked Questions About Defense AI Governance
- Who controls how commercial AI models are used by defense organizations?
Control can be divided across several parties. The provider establishes usage policies, while the government defines mission requirements. A platform vendor may control how the model connects to classified systems. The organization should document each party's authority before deployment.
- Why are defense agencies diversifying across AI providers?
Dependence on one provider exposes an organization to changes in access terms and usage policies. The Pentagon already had agreements with several frontier AI companies before the Anthropic disagreement, but the conflict showed why multiple contracts do not guarantee a quick replacement inside a classified environment.
- What role do secure platforms play in classified AI deployment?
A platform may control how a commercial model connects to classified data and military workflows. The provider establishes the usage policies governing the model.
- Which executive should oversee AI use in a defense company?
The executive needs enough authority to evaluate providers and coordinate with government stakeholders. Their mandate should include deployment decisions.

