NextFin News - Artificial intelligence has quietly reversed one of the oldest power relationships in national security: the state used to build its own tools, but now the Pentagon and the intelligence community depend on a handful of private companies for the models, the talent, and the compute that define modern warfare. That dependency is the story behind a fresh wave of Washington action — a June 5, 2026 presidential memorandum that threatens to terminate contracts with AI firms that resist administration policy, paired with a planned "strategic reserve" that would draft private-sector AI talent into federal service. The paradox is the point: the harder Washington squeezes, the more it admits it cannot do this alone.
The Situation: Coercion as a Symptom of Dependency
The instrument is National Security Presidential Memorandum 11, titled "Artificial Intelligence in the National Security Enterprise." Signed June 5, 2026, it sets out four pillars — adoption, adaptation, assurance, and accountability — and then reaches for the one lever the executive branch still holds outright: the procurement contract. Section 3 directs the Secretary of War, the Director of National Intelligence, and agency heads to pursue, "to the maximum extent permissible by law, termination for default or for convenience" of contracts with companies that "have repeatedly demonstrated a pattern of conduct that is inconsistent with policies" set by the administration.
That language did not arrive in a vacuum. In July 2025, the Pentagon's Chief Digital and Artificial Intelligence Office split $800 million in contracts evenly among OpenAI, Anthropic, Google, and xAI — $200 million ceilings each — to build what the office called "agentic AI workflows" across "a variety of mission areas." The office said at the time:
"The awards to Anthropic, Google, OpenAI, and xAI — each with a $200M ceiling — will enable the Department to leverage the technology and talent of U.S. frontier AI companies to develop agentic AI workflows across a variety of mission areas."
Six months later, in February 2026, the administration ordered federal agencies to immediately cease using Anthropic's technology after the company resisted military applications of its Claude model, designating it a supply-chain risk and removing it from the government's centralized AI testing platform. A U.S. judge ruled in August 2026 that the blacklisting was unlawful, with Anthropic arguing the designation could cost billions in lost business and reputational harm.
NSPM-11 does more than threaten. It also concedes. Within 120 days of signature — a deadline landing around October 3, 2026 — the Office of Personnel Management must initiate an "AI National Security Strategic Reserve" of non-governmental AI talent to support federal efforts "as needed." The same section encourages agencies to use special hiring and pay authorities and directs the intelligence chief and the war secretary to build an AI curriculum for national-security personnel. The memorandum also rescinds the prior administration's National Security Memorandum 25, signed in October 2024, which had taken a more restrictive stance on AI in the security enterprise.
Read together, the two halves of the policy tell a single story. The stick — contract termination — exists because the carrot alone no longer moves companies that can sell the same models to commercial customers without the legal and reputational baggage of warfighting. The reserve exists because the government cannot hire enough AI talent at government pay scales. The state is not reasserting primacy; it is negotiating from dependency.
The Mechanism: The State Buys Capability It Cannot Own
Past defense revolutions were built on hardware the government owned. The F-35 is manufactured by a prime contractor, but the Air Force holds the airframes, the maintenance depots, and the pilots. Nuclear weapons sit in government silos under government command. AI is different because the capability the military wants lives inside private data centers, in models trained on private data, operated by engineers who can quit and take the expertise to a competitor — or to another country.
This is why the procurement threat in NSPM-11 is structurally weaker than it reads. A termination-for-convenience clause works cleanly when the government can re-solicit the work and another vendor can deliver an equivalent product. With frontier AI, the vendor pool is four companies, all of which held the July 2025 awards. When the buyer has four suppliers and each supplier has hundreds of millions of commercial users, the buyer's monopsony power is largely notional.
The evidence is in the sequence of events. After the Anthropic dispute, OpenAI closed a deal for classified deployments — and its CEO, Sam Altman, later admitted the company "shouldn't have rushed to get this out" and that the arrangement "looked opportunistic and sloppy," before amending it to add explicit limits on surveillance and intelligence-agency use. OpenAI's own description of the agreement is revealing: cloud-only deployment, a safety stack the company itself runs, no "guardrails off" models, no edge deployment that could enable autonomous lethal weapons, and the ability for OpenAI personnel to independently verify that red lines are not crossed. The company did not surrender control; it negotiated the terms under which its model could be used in classified environments — and asked that those terms be made available to all AI companies, effectively writing the industry standard.
That is the new power relationship in one transaction. The government gets access. The lab keeps the veto.
The Second-Order Effect: A Two-Tier Market for Warfighting AI
The first-order read of NSPM-11 is simple: the state is forcing compliance. The second-order effect is more consequential for investors and for the industry's structure. Contract pressure, plus the promise of classified work, will split the frontier-AI market into two tiers.
Tier one is the compliant lab: it accepts government terms, builds the classified deployment architecture, hires the cleared staff, and wins the follow-on work that follows the initial $200 million awards. Its revenue becomes stickier, its valuation carries a national-security premium, and its models become embedded in military workflows that are expensive to rip out. Tier two is the lab that refuses: it keeps the cleaner ethical posture and the commercial customer base that prefers it, but it forfeits the government channel and, after a supply-chain-risk designation, may find its contractor customers fleeing as well. Anthropic's experience is the template — and the warning.
The asymmetry already shows up in the equity market. Palantir Technologies, the pure-play defense-AI software name, reported second-quarter revenue of $1.935 billion, up 93% from a year earlier, according to its August 3, 2026 earnings release filed with the Securities and Exchange Commission. U.S. government revenue alone grew 90% to $809 million, and the company closed $3.373 billion in total contract value, up 49%. Management raised full-year 2026 revenue guidance to between $8.150 billion and $8.158 billion — a midpoint of $8.154 billion, implying roughly 82% growth — and lifted adjusted free-cash-flow guidance to between $4.5 billion and $4.7 billion. CEO Alex Karp framed the moment in the release:
"Demand for AI sovereignty has now been unleashed. And Palantir is the only company that has demonstrated it can transform tokens into actual economic value."
Attribution matters here: Karp was speaking as the chief executive of a company that has deliberately chosen tier one.
The stock absorbed the results and extended a three-month rally of 69% to trade above $190, reaching an intraday high of $193.67. That repricing is not just about one contract; it is the market assigning a premium to the company that has already chosen tier one.
Broadly, the defense complex is being re-rated on the same logic. The iShares U.S. Aerospace & Defense ETF returned 29.30% over the twelve months through July 31, 2026, and was up 11.8% year-to-date at that point. The multiple expansion is a bet that AI turns defense from a budget cycle into a capability race — and capability races do not end when appropriations plateau.
Cyclical or Structural: This Is a Regime Shift, Not a Budget Wave
It is tempting to read the current defense-AI rally as cyclical — a surge in spending that will mean-revert when budgets tighten or when a procurement scandal hits. That read mistakes the surface for the mechanism. The shift here is structural, and three pieces of evidence support that call.
First, the dependency is technological, not fiscal. Even if defense budgets flatline, the military's demand for AI does not reverse, because the adversary is adopting the same tools. NSPM-11 itself opens by calling AI "among the most transformative technologies to national security in the history of the United States" and frames the race against competitors who deploy "with little regard for appropriate human oversight or civil liberties." A cyclical wave recedes when the driver exhausts itself. An arms race does not.
Second, the switching costs are permanent. Once a command integrates a model into its planning, targeting, and logistics workflows, replacing it is not a procurement decision — it is a retraining of the force. That is the logic behind the "AI for National Security Curriculum" NSPM-11 orders within 120 days: the government is building the human layer that locks the software layer in place.
Third, the talent channel is one-directional. The strategic reserve acknowledges that the government cannot out-hire the labs; it can only borrow. Borrowed talent still flows from the private sector to the state, and the knowledge transfer it creates deepens the state's reliance on the very companies it is trying to coerce.
The cyclical leg does exist — valuations like Palantir's embed years of flawless execution, and any stumble in government adoption cadence would compress multiples. But the cyclical leg sits on top of a structural floor: the state will keep buying, because the alternative is falling behind an adversary that will not.
The Counter-Thesis: Washington Still Holds the Ultimate Cards
The strongest case against the "tech firms have new power" thesis is that it overstates the labs' leverage and understates the state's. Washington controls three things no company can match: the budget, the classification system, and the legal regime. NSPM-11's termination language is not a bluff in every case — a contractor whose revenue depends on government work cannot absorb a pattern-of-conduct designation. The strategic reserve, if staffed at scale, could dilute any single lab's gatekeeping role by building an on-call bench of private experts who owe their clearance to the government, not to their employer. And the classification authority means the government decides which models ever see the most sensitive missions — a form of selection power that no vendor controls.
There is also a political limit to corporate leverage. A company that withholds capability from the military during an active campaign faces reputational and regulatory retaliation far beyond any single contract. The market for patriotic capital is real, and it is not fully priced into the labs' valuations.
The answer to this counter-thesis is not that the state is powerless — it is that the state's power is now exercised through negotiation rather than command. The Anthropic episode proves the point in both directions: the government could inflict real damage on the company, yet it could not force the company to change its product, and it took a court ruling to halt the action. Coercion worked as punishment; it did not work as production. The government still got its classified deployment — from a different vendor, on that vendor's terms.
The falsifying signal is concrete: if the AI National Security Strategic Reserve is stood up with meaningful scale — say, more than 1,000 vetted private experts activated within 24 months — and the Pentagon fields indigenous model capability that measurably reduces reliance on the four frontier labs for classified work, then the "private leverage" thesis is wrong and state primacy has been restored. Watch the Office of Personnel Management's reserve implementation reports and any Department of War announcement of a government-owned frontier model. Until then, the burden of proof sits with the restoration-of-state-power case.
What Comes Next: Beneficiaries, the Exposed, and the Signals That Matter
The mechanism cashes out into a clear asymmetry. The beneficiaries are the companies that have already accepted the government's terms and embedded their models in national-security workflows: the defense-AI software pure plays, the hyperscalers with cleared cloud infrastructure, and the primes that can bundle AI into platform contracts. They gain stickier revenue, a valuation premium for security clearance, and a moat that commercial competitors cannot cross.
The exposed are the labs that try to hold the middle — selling to commercial customers while refusing the military channel. They keep the ethical high ground but lose the government channel and, after a supply-chain designation, risk contagion through their contractor customers. They are not doomed; they are simply priced for a different business, and the market will remind them of that.
Split by horizon, the picture diverges. In the short term, sentiment and contract headlines will drive volatility — every NSPM-11 implementation deadline around October 3, 2026 is a potential catalyst, from the procurement-process review to the advanced-computing roadmap and the AI test range. In the medium term, fundamentals will separate the embedded vendors from the aspirational ones: revenue growth, free cash flow, and renewal rates will matter more than the policy narrative. In the long term, the structural call dominates: if AI becomes as central to warfare as the memorandum claims, the companies that control the models and the talent capture a durable rent, and the state pays it.
Three scenarios frame the path. The base case is a two-tier market that hardens: compliant labs win classified follow-ons, dissenters retreat to commercial work, and defense-AI multiples stay elevated but volatile. The upside case is a full alignment: the strategic reserve fails to dilute lab power, the curriculum locks in workflows, and the embedded vendors compound at rates the broader defense sector cannot match. The downside case is a political shock: a court blocks the termination authority, a procurement scandal hits a flagship program, or a lab suffers a catastrophic safety failure in a military deployment — any of which would compress multiples faster than fundamentals justify.
The signal that would break the base case is the same one that falsifies the thesis: a scaled, functioning strategic reserve paired with genuine government-owned frontier capability. The signal that would confirm it is simpler — a second major lab refusing government terms and absorbing the cost, or the government quietly accepting a vendor's guardrails as the industry standard, the way it did with the first.
The final judgment: NSPM-11 looks like a reassertion of state power, but it is really a ratification of private power. The government can terminate a contract; it cannot terminate a dependency. The companies that understand that difference — and price it into their terms before the next negotiation — are the ones that will write the rules of AI warfare, not just follow them.
Explore more exclusive insights at nextfin.ai.
