OpenAI has signed a landmark contract with the US Department of Defense to deploy ChatGPT across SIPRNet and JWICS classified networks.
What the contract actually covers
OpenAI has signed a landmark contract with the US Department of Defense to deploy ChatGPT across SIPRNet and JWICS classified networks. The deal is valued at $4.2B and centers on bringing a general-purpose AI assistant into environments that already handle secret and top-secret material. SIPRNet carries Secret-level traffic; JWICS carries Top Secret and Sensitive Compartmented Information. Both sit behind strict access controls, air-gapped or tightly gated connectivity, and continuous auditing. Putting ChatGPT on those paths means the model stack, prompts, and outputs must live inside the same security boundary as the rest of the mission systems—not as a SaaS call to an external public endpoint.
For practitioners, the headline number matters less than the deployment model. Classified use typically requires on-prem or government-cloud hosting, approved identity integration, data-loss prevention on both input and output, and clear rules for what operators may paste into the model. Expect the rollout to look more like a controlled enterprise install than a consumer signup flow.
Why classified networks change the product shape
Public ChatGPT assumes internet reachability, rapid model updates, and broad training feedback loops. SIPRNet and JWICS reverse those assumptions. Models may lag public releases while they complete accreditation. Features that phone home for plugins, browsing, or third-party tools will be stripped or replaced with in-boundary equivalents. Logging that would be normal in a commercial tenant—full prompt retention for product improvement—may be restricted or redirected to agency-owned stores with retention schedules tied to classification and need-to-know.
Operators should plan for different failure modes as well. If the service is unavailable on a classified enclave, users cannot fall back to a phone browser. Capacity planning, offline-safe workflows, and human review for high-stakes answers become part of the operating model, not optional extras.
Practical implications for defense and contractor teams
Teams that already work on classified systems will treat this like any other major IT insertion: Authority to Operate (or equivalent), continuous monitoring, and role-based access. The useful early questions are operational, not marketing ones:
- Which mission workflows are approved for AI assistance, and which remain human-only?
- How are prompts and completions labeled, stored, and purged relative to classification?
- Who owns model configuration, system prompts, and allowed tool use inside the enclave?
- How do incident response and insider-threat programs treat model transcripts?
Contractors supporting DoD programs should map existing data-handling clauses to this new surface. Anything that once lived only in email, chat, or document systems can now appear inside ChatGPT sessions; policy and training need to say so explicitly.
How to prepare without waiting on every detail
Organizations that expect access should inventory high-volume, low-ambiguity tasks first: summarizing long classified cables, drafting standard reports from structured inputs, checking checklists against doctrine, and translating between technical and operational language. Those uses benefit from clear ground truth and human sign-off. Avoid treating the model as an authoritative source for targeting, legal determinations, or unreviewed intelligence conclusions until your governance process says otherwise.
Build evaluation harnesses on representative, properly controlled sample data before broad enablement. Measure faithfulness to source documents, refusal behavior on out-of-scope requests, and leakage risk when users try to mix classification levels in one session. Pair that with simple operator guidance: never paste material above the session’s clearance path, cite primary sources in final products, and escalate when the model’s confidence and the mission risk do not match. The $4.2B DoD agreement with OpenAI makes ChatGPT a real platform on SIPRNet and JWICS; the value will come from disciplined use, not from assuming the public product’s habits transfer unchanged.