"Only Claude is Absent"—The "Unfixable Flaw" Revealed by xAI Engineers Behind the Distribution of AI to 3 Million People
On August 31st, the U.S. Department of Defense (DW) added OpenAI's "ChatGPT Mil" and xAI (via Starshield AI)'s "Grok for Government" to its own AI portal, "GenAI.mil." This means that over 3 million DW employees and military personnel now have access to a total of three AI models, in addition to Google Gemini. As an engineer, I want to draw attention to a certain technical concern that has been reported behind this expansion.
The Ostensible Goal: "Eliminating Single-Vendor Dependence"
GenAI.mil is an integrated AI portal for DW employees, launched in December 2025, initially featuring only Google's Gemini. Its purpose is to enable the use of frontier AI models without leaking non-classified business data to consumer-facing AI services.
Having already gained 1.7 million unique users in just nine months since its launch, the platform has now been further enhanced by the addition of OpenAI and xAI models, strengthening its character as a "marketplace offering multiple AI models." The Department of Defense's aim is to reduce reliance on a single supplier by having multiple vendors, thereby distributing AI tools across the entire integrated force.
IL5 Certification: A Security "Passing Mark"
Both newly added models meet the "Impact Level 5 (IL5)" security certification standard set by the Department of Defense. This is the highest level of certification, assigned to environments handling "Controlled Unclassified Information"—information that is not classified but requires controlled handling.
ChatGPT Mil is designed to support large-scale, non-classified tasks involving a large volume of documents (planning, policy formulation, logistics management, administrative work, etc.). Meanwhile, Grok for Government is said to possess features such as deep reasoning capabilities, a workspace customized for procurement market research and supply chain analysis, and reusable "playbooks."
Reports Point to Undisclosed "Internal Testimony"
Around the same time as this expansion announcement, TechTimes published an interesting report. According to the report, when formally introducing Grok to the platform, engineers within xAI testified during an internal investigation that "no reliable technical fixes were found for the model generating child sexual abuse content (CSAM)."
The report points out that the existence of this internal testimony was not publicly disclosed in the official introduction announcement on August 31st. The announcement also lacks clear explanation of what the IL5 certification specifically guarantees and what it does not guarantee.
The Industry Structure Where "The Same Concerns" Repeatedly
This type of concern is actually not new. Even when GenAI.mil was launched in December 2025 using only Gemini, experts warned of the risk of prompt injection (an attack that injects malicious instructions), stating that if accounts or work terminals were compromised, it could lead to espionage activities.
Now, with the consolidation of models from multiple vendors onto the same platform, managing these risks will become more complex. Each model will operate in parallel within the same government system, each with different security mechanisms and known limitations.
The Quietly Missed Absence of Anthropic
Another interesting point, as pointed out by several media outlets, is the absence of Anthropic's Claude from this lineup. As discussed just before this article, Anthropic had just won a federal court case on August 28th regarding the Department of Defense's designation of the company as a "supply chain risk."
It has not been officially explained whether the exclusion of Claude from the GenAI.mil expansion is directly related to this series of legal battles. However, the fact that a company's model, which has clashed with the government over its use in autonomous weapons and mass surveillance, is quietly being removed from the government's main AI procurement platform is suggestive.
What Engineers Should Consider
The lesson this news raises is the question of how transparently the known limitations and risks of individual AI models are disclosed and communicated to users when large organizations like government agencies deploy a large number of AI models. Certifications like IL5 indicate that certain security standards are met, but they do not guarantee the content generation limitations inherent in the model itself.
For engineers planning to deploy models from multiple AI vendors in parallel within their organizations, this incident serves as a stark reminder of the often overlooked lesson that "clearing certification" does not equate to "eliminating all risks."