
From Social Knowledge to Military Power
AI contracts, public money, and democratic accountability
Hamid Akhavi · Evidence cutoff: 26 September 2026 · Editorial review: 27 September 2026
Artificial intelligence is entering military institutions through several doors: general-purpose models, data and decision software, autonomous platforms, and cloud infrastructure. These are connected activities, but they are not one product or one contract. An office assistant, a planning model, and a system connected to the use of force require different assessments.
The central question developed in A New Social Order in the Age of Awareness is relevant here: when knowledge is produced socially, who controls its application? Military procurement makes that question especially urgent. Public institutions finance systems whose operation may depend on private models, proprietary data pipelines, and infrastructure controlled by a small number of suppliers. A government purchase can expand public capability while also deepening dependence on those suppliers.
This report examines ten company profiles and a shared infrastructure layer. It does not treat commercial adoption as proof of public benefit. The evidence establishes contracts, authorizations, and development milestones much more readily than it establishes battlefield effectiveness, civilian protection, or value for money. The interpretation that follows applies the book’s framework; the contract record does not, by itself, prove an entire theory of social change.
How to read the figures
A ceiling is a maximum purchasing limit, not money already paid. An obligation is a commitment of funds; an outlay is a payment. A delivery order is also different from completed delivery. A multi-supplier framework does not award its entire ceiling to each participant.
An authorization permits a system to handle specified information under defined conditions. It does not certify every possible use as accurate, lawful, or safe. A trial demonstrates performance within its test conditions; it does not establish effectiveness across combat environments. Undisclosed expenditure is unknown, not zero.
Amounts remain in their original currencies. Overlapping frameworks, individual orders, and program estimates are not added together. “Confirmed” below identifies the kind of evidence available, not an endorsement of the supplier. Company announcements establish what companies report; they are not independent performance audits.
The frontier-model agreements
On 14 July 2025, CDAO announced partnerships with OpenAI, Anthropic, Google, and xAI, each with a ceiling of up to $200 million. OpenAI had already announced its own award on 16 June. The July announcement should therefore not be presented as the original award date for all four companies. [1] [2]
1. OpenAI — prototype award and classified-access agreement The June 2025 announcement describes a $200 million ceiling for prototype work, including administrative services, acquisition analysis, and cyber defense. It does not establish that $200 million was spent. [2]
OpenAI announced an agreement for classified environments on 28 February 2026, referring to the previous day. Its published account describes cloud deployment, company-operated safeguards, and cleared personnel. A 2 March update added surveillance-related language. These are the company’s representations of its agreement, not an independent audit of enforcement. [3]
Evidence status: agreement announced; total expenditure and operational outcomes not established here. The relevant public question is whether safeguards are enforceable, independently reviewable, and effective when operational pressure conflicts with them. It would be inaccurate to say simply that OpenAI accepted unrestricted use or removed every safeguard.
2. Anthropic — a dispute over permitted uses Anthropic announced a two-year prototype agreement with a ceiling of $200 million in July 2025. That agreement must be distinguished from negotiations over a later direct classified deployment. [4]
On 25 September 2026, a divided D.C. Circuit upheld the Pentagon’s exclusion of Claude under the Federal Acquisition Supply Chain Security Act. The dispute concerned restrictions on autonomous lethal warfare and mass domestic surveillance. The majority accepted the procurement rationale; there was a dissent. This was a specific statutory case, not a universal judicial approval of military AI. [5]
Evidence status: procurement relationship disrupted by a legal and policy conflict. Refusal to accept a use policy is not evidence that a model cannot perform technically. Nor should a private supplier’s ethical position substitute for democratic lawmaking. The deeper issue is how public institutions establish enforceable limits without reducing accountability to a bargain between a ministry and a company.
3. Google — from workplace deployment to classified agreements Google reports that Gemini for Government became available through GenAI.mil in December 2025 for unclassified work. Its description of access for more than three million personnel identifies the eligible workforce, not a verified count of active users. [6]
Google also appears in the Pentagon’s May 2026 classified-network announcement. That announcement establishes participation in an agreement, not completion of every planned deployment. [24]
Evidence status: platform access and participation in classified procurement. Administrative time savings, when reported by a vendor or purchaser, should remain attributed claims. They do not establish better military judgment. Broad adoption makes independent evaluation more necessary, particularly when the same infrastructure supports both ordinary administration and higher-stakes work.
4. xAI / Grok — inexpensive access is not validated reliability The separate GSA OneGov offer made Grok available to federal agencies for $0.42 per organization through March 2027. That promotional access price is not the value of the CDAO prototype agreement. [7]
CDAO’s official rollout announcement identifies Grok for Government on GenAI.mil as an IL5 service and places it alongside Gemini and ChatGPT Mil. IL5 access concerns controlled unclassified information; it should not be described as classified deployment. [8]
Evidence status: government access offered and platform rollout announced. Neither a very low entry price nor accreditation answers questions about bias, misleading output, privacy, or suitability for consequential decisions. Those questions require task-specific evidence and accountable users, with a real ability to reject an output.
5. Microsoft — distinguish the headset program from the cloud IVAS development began in 2018; the Army’s production award to Microsoft followed in March 2021. These are separate milestones. [9]
The Congressional Research Service documents user-acceptance concerns, reported physical symptoms, and the April 2025 transfer of Microsoft’s IVAS contract to Anduril. It also distinguishes the later Soldier Borne Mission Command effort. The roughly $22 billion figure is a potential program/contract scale, not expenditure demonstrated by that figure. [10]
Separately, Microsoft announced in April 2025 that Azure OpenAI had received authorization for IL6 information in its government environment. That is an infrastructure milestone, not proof that all defense applications have passed operational evaluation. [11]
Evidence status: a troubled hardware program and a distinct cloud authorization. Combining them into a single verdict of corporate “success” or “failure” obscures the accountability question: what was promised, what was accepted, and what public resources produced a usable result?
6. Palantir — confirmed enterprise ceiling, production orders to follow The Army’s own announcement confirms the July 2025 enterprise agreement, capped at $10 billion over up to ten years. It explicitly says the cap is not a specific obligation or commitment. The existence of this framework is established by a primary source. [12]
On 1 September 2026, the Army announced TITAN delivery orders totaling $192 million: $127 million to Palantir and $65 million to Anduril. The orders cover eight production systems with an 18-month delivery period, alongside nine retained prototypes. Eight systems ordered does not mean eight production systems delivered. [13]
Evidence status: an officially confirmed purchasing framework and production orders. Claims about extraordinary targeting rates or responsibility for particular strikes require separate evidence. They cannot be inferred from these awards. Software used to interpret intelligence must preserve uncertainty and a traceable human chain of responsibility.
7. Anduril — enterprise access and aircraft-production milestones The Army announced an enterprise contract with Anduril in March 2026 with a potential value of up to $20 billion. It is a mechanism for purchasing technologies, not proof of $20 billion in revenue or public expenditure. [14]
The Air Force’s 17 June announcement identifies CCA development and production contracts for Anduril and General Atomics. A production decision is a meaningful milestone, but it does not demonstrate that projected fleet size, delivery schedules, or lifetime costs have been achieved. [15]
Evidence status: purchasing framework and production commitment. Claims about inexpensive production at scale remain questions for delivered units, audited costs, and independent testing. Private investment narratives and official urgency should not displace evidence about reliability, human control, and the consequences of deployment.
8. Shield AI — autonomy software and a shared Navy competition Shield AI announced a June 2026 production award for Hivemind mission-autonomy software in the CCA program. Its account distinguishes software development from aircraft manufacture and describes continuing development flights. No award price is established in the announcement reviewed here. [16]
Its April Navy announcement describes eligibility to compete with other suppliers for task orders under an $800 million framework for intelligence, surveillance, and reconnaissance services. The full amount is not a guaranteed Shield AI award. [17]
Evidence status: software award and eligibility for additional orders. The ability to operate on an aircraft is not equivalent to demonstrated reliability in every environment. “Human supervision” also needs substance: adequate information, time to intervene, authority to stop, and a record that can be examined after harm.
9. Helsing — procurement and demonstrations, not an audited success rate The Bundeswehr confirms contracts with Helsing and Stark on 26 February 2026. This establishes procurement. Financial totals from overlapping German programs require separate reconciliation before they can be attributed to one supplier. [18]
Helsing announced production of 6,000 HX-2 drones for Ukraine in February 2025; that announcement alone does not establish complete delivery. In November 2025 it described a Cirra–Arexis agreement with Saab Germany in the hundreds of millions of euros, with integration over three years, rather than publishing an exact price. [19] [20]
Saab’s June 2025 release documents three Gripen E flights integrating Helsing’s Centaur agent. These were test flights. [21]
Evidence status: procurement, announced production, and flight trials. Operational-success percentages require an independently assessable definition, denominator, and test conditions. Without them, a percentage cannot support a general judgment about combat effectiveness or civilian safety.
10. Scale AI — planning infrastructure and an expanded ceiling DIU announced the Thunderforge prototype award on 5 March 2025, with initial deployment planned for U.S. Indo-Pacific and European Commands. Its stated scope includes AI-assisted planning and simulation, with Anduril and Microsoft participating. A planned deployment should not be rewritten as independently verified, completed implementation. [22]
Scale announced in May 2026 that its separate CDAO enterprise agreement ceiling rose from $100 million to $500 million. The increase is a procurement-capacity signal, not evidence that expenditure or useful results increased fivefold. [23]
Evidence status: prototype award and company-reported expansion of an enterprise ceiling. Planning systems influence which alternatives decision-makers see. Their assumptions, uncertainty, and excluded options therefore matter as much as the speed with which they produce recommendations.
The shared classified infrastructure
The Pentagon’s 1 May 2026 announcement names AWS, Google, Microsoft, NVIDIA, OpenAI, Reflection, SpaceX, and Oracle. Oracle also announced its participation directly. The announcements concern agreements for classified networks; they do not supply a complete expenditure ledger or independent evidence of full deployment. [24] [25]
A model-access portal, a security authorization, and a classified operational system are different things. Several suppliers can reduce dependence on one model while leaving dependence on a small set of clouds, interfaces, and integrators. Whether diversification actually reduces lock-in is an empirical question, not an automatic benefit of a longer vendor list.
What the book’s framework adds
The book distinguishes technical possibility from social realization. More powerful computation does not automatically produce either liberation or domination. Ownership, institutions, organized participation, and enforceable rights shape the result. These contracts are useful cases through which to examine that argument; they do not make historical change inevitable.
The issue is not resolved by replacing a private monopoly with an unaccountable state monopoly. Public expenditure is not the same as public control. Democratic control requires independent courts and oversight, transparent responsibilities, plural public debate, and meaningful ways to challenge harmful decisions. Secrecy may protect legitimate operational details; it should not eliminate lawful scrutiny of spending, errors, or responsibility.
This also preserves the distinction between legitimate defense under civilian authority and the militarization of social life. The book’s institutional proposals retain defense of people and society against external aggression. They reject the use of security institutions to suppress peaceful political activity or protect an unaccountable center of power. A critical account should assess particular purposes and consequences, rather than declaring every defensive application identical.
The wider opportunity cost matters too. Public investment in military AI must be debated alongside health, education, environmental protection, and civilian infrastructure. Contract totals alone cannot calculate that trade-off, and this report does not claim that every military dollar could be transferred without consequences. It asks who participates in setting priorities and whose needs remain outside the decision.
A public test of success
Account for the money. Publish ceilings, obligations, payments, accepted deliveries, and material contract changes separately. Explain overlapping frameworks so that the same money is not counted twice.
Test outcomes independently. Evaluate error, reliability, security, and effects on people under realistic conditions. The supplier should not be the sole judge of its system; the purchaser should not control every channel through which failure can become known.
Make human responsibility effective. Preserve the ability to question, override, and stop a system. Human approval without time, understanding, or authority can become a formality. Responsibility must remain traceable when institutions and contractors share a workflow.
Protect rights and public oversight. Establish enforceable limits on surveillance and coercive use, scrutiny of conflicts of interest, and access to independent investigation and remedy. Legitimate confidentiality requires accountable oversight with access to the underlying evidence.
Retain social choice. Build exit options, interoperable systems where feasible, and democratic debate over priorities. An expanding supplier market does not itself give citizens control over the uses of socially produced knowledge.
The decisive measure is not how much AI a military institution can buy, or how quickly a model can recommend action. It is whether the institutions using it can demonstrate necessity, effectiveness, protection of human life, and accountability to the society that finances them.
Related reading: AI and Democratic Planning
Sources and method
The contract sources below are distinct from the author’s analytical framework. The text was checked against Volume I and the complete revised chapters 5–10 of Volume II. Announced procurement is distinct from independently validated outcomes. Classified details and undisclosed payments may not be publicly accessible.
- CDAO — Four frontier-AI partnerships, 14 July 2025
- OpenAI — Introducing OpenAI for Government, 16 June 2025
- OpenAI — Classified-network agreement, 28 February; updated 2 March 2026
- Anthropic — Defense prototype agreement, 14 July 2025
- U.S. Court of Appeals, D.C. Circuit — Anthropic v. Department of War, 25 September 2026, No. 26-1049 (PDF)
- Google Cloud — Gemini for Government on GenAI.mil
- GSA — xAI OneGov agreement, 25 September 2025
- CDAO — Official announcement of Grok for Government on GenAI.mil
- U.S. Army — IVAS production contract award, March 2021
- Congressional Research Service — IVAS: Background and Issues for Congress, IF13022
- Microsoft — Azure OpenAI authorization, 16 April 2025
- U.S. Army — Palantir enterprise agreement, 31 July 2025
- U.S. Army — TITAN production orders, 1 September 2026
- U.S. Army — Anduril enterprise contract, March 2026
- U.S. Air Force — CCA contracts, 17 June 2026
- Shield AI — CCA mission-autonomy production award, 17 June 2026
- Bundeswehr — Loitering-munition procurement, 2 June 2026 (German)
- Helsing — Announcement of 6,000 HX-2 drones for Ukraine, 13 February 2025
- Helsing — Cirra–Arexis integration agreement, 19 November 2025
- Saab — Centaur/Gripen E flight trials, 11 June 2025 (PDF)
- Defense Innovation Unit — Thunderforge prototype, 5 March 2025
- Scale AI — CDAO agreement ceiling expansion, 6 May 2026
- U.S. Department of War — Classified Networks AI Agreements, 1 May 2026
- Oracle — Classified-cloud agreement, 1 May 2026