← Writing
·4 min read

Washington Names Its AI Vendors — and Leaves One Out

The Signal for September 1, 2026 — the Pentagon crowns its official AI stack, capital piles into an AI-native sales tool, and a researcher turns a coding agent into a shell. An operator's read on the day.

The SignalAICybersecurity

Tuesday, and the story isn't a new model — it's who gets to sell one. The biggest buyer in the world just standardized its AI stack and quietly closed a door, the private market is repricing the tools that replace headcount, and a researcher showed how the coding agents everyone's adopting can be turned into a shell. Three threads, one operator question: as everyone rushes to pick their AI winners, who's checking the locks?

The Pentagon builds its own front door for AI — and Anthropic isn't behind it

The Department of Defense opened GenAI.mil, a secure portal that bundles OpenAI's ChatGPT Mil, xAI and Starshield's Grok for Government, and Google Gemini for roughly 3 million DoD personnel, with 1.7 million unique users already onboarded, per AI Weekly's live index citing TechCrunch. The absence is as loud as the launch: Anthropic's Claude isn't in the bundle. Per unrot's roundup, the Pentagon is still moving off Claude and expects to finish by September 30, 2026 — even after a federal judge recently struck down its blacklisting of Anthropic as unlawful.

The operator's take: procurement is architecture. When the largest customer on earth standardizes on three vendors and routes millions of users through one governed portal, it sets the gravity for the whole ecosystem you build on — integrations, talent, tooling, defaults. The lesson isn't "copy the DoD's roster." It's that a single big buyer's shortlist can quietly become your dependency, and that a vendor's standing can flip on a legal or political dime. Keep your AI layer abstracted enough that swapping a model is a config change, not a rebuild. Concentration is convenient right up until it's coercive.

Clay reprices — and the market keeps paying for AI-native go-to-market

The AI-powered sales and marketing platform Clay is raising a new round led by Wellington Management at a $7 billion pre-money valuation, per Axios via AI Weekly. That's a jump from the $5 billion mark set in a January 2026 employee tender led by DST, and more than double last summer's $3.1 billion CapitalG-led Series C. The valuation is compounding roughly as fast as the category it sits in.

The operator's take: the capital is flowing to tools that compress a headcount-heavy function into a workflow — and go-to-market is the current favorite. That's a real efficiency lever, but a rising valuation is a signal about investor conviction, not about your ROI. Before you sign, pin down two things: what specifically this replaces in your funnel, and where your prospect and customer data lands when an AI-native tool enriches it. Buy the outcome, not the round. The tools winning these valuations are worth a pilot; they are not worth skipping the data-governance conversation.

A coding agent, turned into a shell

Security researcher Wunderwuzzi published a five-step chain that pushes Claude Code Opus 5 in Auto Mode to execute arbitrary code at a 60 to 80 percent success rate, per AI Weekly. The clever part is the pivot: an HTTP 415 error nudges the agent off its sanctioned WebFetch tool and onto curl, and the chain builds from there. Guardrails in the model didn't close the path.

The operator's take: a coding agent with tool access is a privileged identity running on your developers' machines, and it should be governed like one. It has credentials, network reach, and a shell — the exact profile you'd never hand an unvetted contractor. Sandbox agent execution, whitelist the tools it can call, keep it off production secrets, and treat anything it fetches or generates as untrusted input. The productivity is real; so is the blast radius. Give your agents the least privilege that still lets them work, and log everything they touch.

Also on my radar

  • Europe buys more sovereign compute. EuroHPC signed a €387.8 million contract on August 31 with Atos-owned Bull to build the LUMI-AI supercomputer at CSC's Kajaani site in Finland on AMD Instinct MI430X GPUs, targeting roughly 10x the AI capacity of its predecessor, per AI Weekly. Public AI infrastructure is now an industrial-policy line item, not a lab curiosity.
  • Open weights keep closing the gap. A new frontier model from z.ai ties Moonshot's Kimi K3 as the top-performing open-weights model, per Artificial Analysis via VentureBeat. The build-vs-buy math shifts every time the open tier catches the frontier.
  • Apple changes hands. John Ternus became Apple's CEO on September 1, ending Tim Cook's roughly 15-year run, with the longtime hardware-engineering chief stepping up and Cook moving to executive chairman, per unrot. An engineer at the top is a signal about where the company thinks its next decade of differentiation lives.

The throughline for a Tuesday: the market is choosing its AI sides faster than it's securing them. Governments are standardizing stacks and picking winners, capital is repricing the tools that replace whole functions, and the agents at the center of all of it still have soft edges a determined researcher can pry open. None of that is a reason to sit out — it's the brief. Keep your model layer swappable, buy outcomes instead of valuations, and give every agent the least privilege it needs. That's the Signal for today.

Paul Sapio is the CIO of Mikhail Education and a full-stack AI engineer. Open to contract work in security, networking, AI, and SaaS development — reach out.