The Defense Department added ChatGPT Mil and Grok for Government to GenAI.mil on Monday, its centralised portal for commercial generative AI. Google’s Gemini for Government products were the first to go live there. There are now three vendors behind one door.
The scale is already real rather than aspirational: more than 1.7 million unique users have been onboarded out of a department of roughly three million people. The stated use cases are deliberately unglamorous — document-heavy routine unclassified work, administration, logistics, planning and policy drafting. ChatGPT Mil is accredited for controlled unclassified information at Impact Level 5, a DoD cloud-security standard for certain sensitive unclassified data.
The security pitch is that staff get frontier models without routing government data through consumer products, and that the military versions are exempt from the data collection that is effectively unavoidable on the public tiers.
Our take: The important design decision here is that GenAI.mil is a portal, not a contract with a winner. Three competing labs sit behind one government-controlled front door, which means the department owns the identity layer, the accreditation boundary and the audit trail, and treats the model itself as the swappable part. That is the opposite of how enterprise software normally gets sold to government, and it is a template every large regulated buyer will now be shown. If the model is the commodity and the portal is the moat, the labs have just agreed to compete on price and capability inside somebody else’s building.
Why 1.7 million is the number to hold onto
Vendor announcements about government AI usually come with a ceiling — a pilot, a component, a number of seats. This one comes with a floor already crossed. Well over half the department has accounts before the two newest models even landed.
That changes what failure looks like. A pilot that disappoints gets quietly wound down. A portal that 1.7 million people already log into cannot be, so the pressure moves from adoption to governance: what gets logged, what is retained, what an accreditation at Impact Level 5 actually permits, and who reviews output before it reaches a decision. Those questions were theoretical while the user count was small.
What to watch
- Whether a fourth vendor is added, and how fast. The speed of the next addition tells you whether the portal is genuinely model-agnostic or shaped around the three incumbents.
- Accreditation drift. Impact Level 5 and CUI define the current boundary. Any move above that line is a much bigger story than a new model going live.
- Usage disclosure. Onboarded accounts are not active users. A published active-usage figure would be the first honest measure of whether this is working.
- Whether other departments copy the shape. One portal, many models, government-owned identity is a pattern that ports easily to civilian agencies and to regulated industry.
Three labs, one login, and the government holding the door. That arrangement is the product.
