Code and Command: The Pentagon's AI-First Military Doctrine and Its Attack Surface- 188
June 7, 2026
The Pentagon has handed OpenAI, Google, Microsoft, Amazon, and SpaceX the keys to its classified networks. More than 1.3 million Department of Defense employees are already using AI for intelligence analysis, targeting, logistics, and operational planning. The stated goal — an "AI-first" military force — is now not a doctrine on paper but a procurement reality. What has received less attention is the paradox embedded in the strategy: the same openness that makes AI-integrated military systems faster and more flexible makes them a more attractive and more consequential target than anything the US military has previously put online.
The contracts include "lawful operational use" clauses requiring vendors to accept any use the Pentagon considers legitimate — including autonomous weapons systems and intelligence operations. This is the point where the integration moves from productivity enhancement into something that raises more fundamental questions about accountability, escalation control, and the legal frameworks governing the use of force. Code is now part of the military chain of command. The ability to deploy, secure, update, and operate AI models inside classified environments has been explicitly designated as national defense infrastructure.
The Army's "Right to Integrate" initiative asks manufacturers of missiles, drones, radars, and sensors to open their software interfaces so AI agents can connect systems in real time, drawing inspiration from Ukraine's battlefield experience, where open APIs enabled rapid integration between drones, sensors, and fire-control systems. That precedent is operationally compelling. It is also the source of what the Pentagon's own doctrine acknowledges as a dangerous paradox: the same openness that enables speed and flexibility expands the attack surface. Every API, cloud platform, and AI integration point becomes a potential entry point for sophisticated adversaries. A compromised AI-enabled military ecosystem could allow attackers to inject false sensor data, manipulate targeting systems, degrade drone communications, or study operational decision patterns — not as hypothetical scenarios but as the logical extension of the supply chain and AI infrastructure attacks that civilian organizations are already experiencing.
The strategic framing extends beyond military technology into questions of technological sovereignty that are more immediately pressing for Europe than for the United States. The gradual incorporation of Amazon, Microsoft, and Google into American defense architecture means civilian digital infrastructure is evolving into a structural extension of military power — and that the organizations controlling the AI models, the data, and the cloud infrastructure supporting national defense are American companies operating under American law. For European states, the question is whether dependence on that infrastructure is compatible with genuine strategic autonomy. The Pentagon's AI-first doctrine does not create that dependence — it formalizes one that already existed. But formalizing it makes the dependency visible in a way that has not previously been politically or strategically unavoidable.