DoD plans classified GenAI.mil expansion as users near 1.7M
The adoption story is nearly over, and the harder governance fight starts at controlled data, model choice and human review.
TL;DR
Nextgov reports the Department of Defense’s GenAI.mil platform has reached almost 1.7 million users and more than 100,000 custom agents. Cameron Stanley, DoD’s chief digital and artificial intelligence officer, said the department plans more models and higher classification levels; OpenAI has said ChatGPT will be eligible for controlled unclassified information (CUI) through GenAI.mil in July. For security and procurement teams, the meaningful shift is commercial models moving deeper into protected DoD workflows.
Nextgov’s headline number is adoption: GenAI.mil is approaching 1.7 million users and has produced more than 100,000 custom agents. Cameron Stanley, the Department of Defense’s chief digital and artificial intelligence officer, told an AWS Summit audience that DoD is adding models and taking the platform to higher classification levels, while describing his office as a “commercial-first” organization that puts vendors closer to warfighter requirements. OpenAI has also said ChatGPT will be eligible for controlled unclassified information (CUI) through GenAI.mil in July.
The less tidy fact is that access is being discussed across several boundaries at once. Nextgov says the platform already hosts capabilities from SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Oracle and Amazon Web Services at Impact Level 6 and 7, and prior reporting put GenAI.mil at 1.3 million active users in April, with use in Impact Level 5 environments for sensitive unclassified data (https://www.nextgov.com/defense/2026/04/pentagon-adds-googles-latest-model-genaimil-usage-soars/413127/). The practitioner question is narrower than the vendor roster: which model can touch CUI, which can run in classified environments, and which human approval step remains mandatory.
Stanley’s warfighter example explains the demand. If an AI workflow can collapse searches across six or seven systems into a near-instant analytic process, commanders will ask for it. The compliance problem is that the same convenience compresses authorization, data-handling and audit decisions into the tool. Procurement and security teams should treat this as a contract and accreditation issue: model-substitution rights, logging, guardrail descriptions and data-use restrictions need to be pinned down before “commercial-first” outruns the controls that make the deployment usable.
Published ·Deep Fathom