The Pentagon’s AI Rush Is Creating a Security Weakness
The Department of War just announced at the end of August that it is expanding GenAI.mil with ChatGPT Mil and Grok for Government , adding more corporate AI directly into the daily infrastructure of the American military. Both systems are accredited to handle Controlled Unclassified Information at Impact Level 5, and GenAI.mil has already reached more than 1.7 million unique users since launching in December 2025.
This is not a small test anymore. The Department has openly called for an “AI-first” force and says that these tools are meant to accelerate planning, policy, logistics, administration, acquisition, supply chains, and other routine work. The goal is to make AI normal, make it fast, and put it in the hands of as much of the force as possible. That may produce real advantage, but it also creates a basic security problem that every risk analyst at the National Security Agency should be modeling every day. Rapid adoption means more users, more credentials, more stored projects, more data movement, more software connections, and more opportunities for someone outside the United States to find a way in.
The largest risk is not some science-fiction AI turning against the United States, or AI becoming self-aware and misleading users. The risk is data, people, and discipline. Corporate AI is designed to be convenient, and convenience is exactly what can grind down security discipline over time. People interact with conversational AI differently than they do with conventional information systems. Peer-reviewed research on self-disclosure to conversational AI found that users often disclose more information to conversational agents than to humans or traditional questionnaires, particularly when the system feels anonymous, nonjudgmental, or socially safe.
That matters because people ask questions, upload files, copy text, summarize material, save projects, and return to the same system day after day until the interaction feels ordinary. The more ordinary that interaction becomes, the easier it is for security discipline to erode around it. Mass adoption of conversational AI does not automatically violate operational security , but it places greater pressure on it. The Pentagon’s own doctrine warns that data aggregation, routine information systems, and ordinary organizational activity can create exploitable vulnerabilities. GenAI.mil is expanding all three at once.
America has already watched military enthusiasts repeatedly place restricted or sensitive material onto War Thunder forums simply to win arguments about weapons. Give millions of people a tool built around frictionless conversation and then make that tool part of their normal workday, and some portion of them will eventually become too comfortable. Security rules, strict procedures, training, and accreditation can help reduce the risk. None of them can predict all user behavior across millions of interactions. My earlier warning about corporate AI in the military was that normalization itself becomes the vulnerability due to the erosion of standards. The Department of War is now explicitly trying to make frontier AI the standard for daily operations.
More AI systems mean more software, more integrations, more credentials, more stored knowledge, and more places a hostile actor can probe. The National Institute of Standards and Technology explicitly warns that generative AI expands the available attack surface. Pentagon officials have separately said that generative models could aggregate unclassified information in their training data and unintentionally output classified information. A hostile intelligence service does not need to defeat the entire Department of War.
This is not only a Pentagon security problem. It also has international consequences. The United States sits at the center of intelligence-sharing relationships such as the Five Eyes partnership , and those relationships depend on trust that sensitive information will stay protected once it enters American systems. As the Pentagon makes corporate AI part of normal military work, allies have every reason to ask whether more AI access, more stored information, and more data aggregation create new risks on the American side.
China and Russia will be asking a different question: Where is the weakness? The United States may gain speed from AI, but if that speed comes with weaker information discipline, then the advantage can become somebody else’s opportunity.
The critical mistake that intelligence and the military are making is believing that training can solve this problem. Institutional structures can provide reassurance without materially constraining the underlying risk. The same danger applies here. A risk framework matters, but it does not guarantee that routine use will remain careful five years from now. Just because there hasn’t yet been a catastrophic breach from this military AI rollout doesn’t mean that it won’t happen.
Rapid adoption of AI should not be confused with stronger warfighting. The Pentagon should carefully measure AI adoption against its own procedures, identify the security burdens it creates, and mitigate those risks downstream. Every new AI capability creates another thing that has to be defended, and every layer of convenience puts more pressure on the oldest security system the military has as well as on the judgment of the person behind the keyboard. America’s adversaries do not need to invent a superintelligence to exploit this. They only have to wait for discipline to erode.
The post The Pentagon’s AI Rush Is Creating a Security Weakness appeared first on Foreign Policy In Focus .
The Pentagon’s AI Rush Is Creating a Security Weakness
Aggregated summary from an independent source. Read the original at FPIP.