AI Agents at DoD IL5 in 2026: Anthropic Switched Off
August 10, 2026

The Defense Department has authorized Salesforce's Agentforce 360 to operate at Impact Level 5, letting AI agents process controlled unclassified and unclassified national security systems data. Announced August 5, 2026, it came with a condition: Salesforce officials indicated Anthropic's models had to be disabled.
TL;DR
Salesforce disclosed on August 5, 2026 that Agentforce 360 is authorized to operate at DoD Impact Level 5, and that the U.S. Army Human Resources Command is the first DoD component contracted to deploy it in that newly authorized environment.123 (Neither source states when the authorization was granted; August 5 is the announcement date.) IL5 is a data-sensitivity accreditation, not a capability grant: it governs where agents may run and what data they may touch, not what they may decide. The most consequential detail sits in a single paragraph of the trade reporting — Salesforce officials indicated the company had to attest to the Pentagon that Anthropic-supplied generative AI models and capabilities were disabled in order to achieve IL5, at a moment when the government's case for excluding Anthropic is losing in one court and unresolved in another.14 Model choice has become an accreditation condition.
What you'll learn
- What IL5 authorization actually authorizes an AI agent to do, and what it does not
- Why "the platform is authorized" is never true of the whole platform
- Whether this is really the first AI agent platform cleared at IL5
- Why Anthropic's models had to be switched off, and the live legal fight behind that
- What the Army HRC agents are scoped to do, and where humans keep decision authority
- Which of the widely repeated numbers are delivered results and which are projections
- Where the press release's supporting citation diverges from the source it cites
- What the whole episode signals for agentic AI in regulated environments
What IL5 authorization actually means for AI agents
IL5 is an accreditation of the hosting environment and its controls, not a statement about agent autonomy. DoD uses an Impact Level system to classify data sensitivity and to certify that cloud environments are secure enough to hold it. DefenseScoop describes IL5 as "the highest authorization granted to environments built to store and process CUI and NSS data," with IL6 required to process classified defense workloads.1 One correction is worth making to the tier framing that circulated with this news: DISA's Cloud Computing Security Requirements Guide defines Impact Levels 2, 4, 5 and 6 only. IL6 is the top of the published scale and covers classified information up to SECRET; there is no IL7 in the SRG, and references to one describe top-secret environments accredited under other authorities.5 Salesforce said separately that its Missionforce team operates a fully air-gapped top-secret environment, which is a different accreditation path from the IL5 news.1
Getting there is not a paperwork exercise. IL5 sits on a FedRAMP High baseline supplemented by DoD-specific controls from the SRG — commonly summarized as more than 450 security requirements — layered with physical and logical separation of DoD tenants from non-federal customers and a requirement that administrative access to the infrastructure is limited to U.S. persons.5 The IL5-compliant Agentforce 360 platform runs on AWS GovCloud, which Salesforce describes as "a physically and logically isolated region operated exclusively by U.S. personnel."2
What none of that establishes is what an agent may decide. An impact level answers where the workload runs, who may administer it and which categories of data it may touch. Scope of action — which tools an agent may call, which actions need a human, what happens when a tool call fails — lives in the mission owner's own authorization and configuration. That distinction is the one most likely to be lost as this story is retold.
It also gets lost that authorizations are granted to defined boundaries, not to brand names. A footnote in Salesforce's own announcement makes the point concretely: "IL5 authorization for Agentforce 360 excludes Slack, where GovSlack is currently authorized at the IL4 level."2 A product family can carry two impact levels at once. Any team reading a vendor's "we are authorized at IL5" line should ask which components, in which region, under whose authorization to operate.
Is Salesforce the first AI agent platform at IL5? No
No — and Salesforce did not claim that, though the claim is easy to over-read. What Collins actually said at a media roundtable was narrower: "We're the first ones, as a commercial software company, bringing an agentic platform that's been productive in the commercial side into the national security environment."1 The company's separate claim about the Army is narrower still, and scoped to its own product: Army HRC "becomes the first Department of War organization to deploy the newly authorized Agentforce Public Sector in Salesforce's Impact Level 5 environment."3 ("Department of War" is a secondary title created by executive order in September 2025; the statutory name is still the Department of Defense.6)
Broaden either sentence into "first AI agents at IL5" and it stops being true. The Palantir Federal Cloud Service — whose stack includes Gotham, Foundry, AIP and Apollo — already held Impact Level 5 and Impact Level 6 provisional authorizations before February 2026, when DISA extended them to on-premises and edge deployments.7 Microsoft 365 Copilot reached general availability in the Office 365 DoD IL5 environment in August 2025, and Microsoft has since been shipping low-code agent building into its government clouds.7 AI, including agent-shaped AI, was operating inside IL5 boundaries well before this announcement.
The defensible reading is that a mainstream commercial CRM's agent stack — the same product line sold to ordinary enterprises — has now been accredited for the DoD's most sensitive unclassified tier, with a named first customer attached. That is a real milestone about the commercial-to-defense pipeline, and not a first for AI at IL5.
Why Anthropic's models had to be switched off
Because the vendor is caught between an accreditation process and an unresolved dispute between the Pentagon and Anthropic. Reporting the announcement, DefenseScoop wrote that in response to reporters' questions, Salesforce officials "suggested that Salesforce had to attest to the Pentagon that generative AI models and capabilities supplied by Anthropic were disabled, in order to achieve IL5."1 Officials said the platform is otherwise model-agnostic and described a policy-driven toggle that could be lifted to include Anthropic if DoD changes its stance.1 Collins framed it as a customer-choice principle with an exception baked in: "Trust is letting our customers choose the model that works for them. There are very strong opinions about models. There are very strong opinions about certain companies. I listen to the customer. The customer wants to choose the model, my job is to make it work."1
The backdrop is messier than most summaries admit, because there is more than one designation. Anthropic publicly refused a Pentagon demand to permit broad military use of Claude in February 2026, after which the administration directed federal agencies to stop using Anthropic products and the Pentagon labelled the company a supply-chain risk.8 Anthropic sued, and the fight split across two statutes and three dockets.4
In the Northern District of California, U.S. District Judge Rita Lin granted a preliminary injunction in March 2026 against the designation issued under 10 U.S.C. § 3252 and the accompanying directives, writing that the government's actions appeared "designed to punish Anthropic" and finding the company likely to succeed on First Amendment retaliation, Fifth Amendment due process and Administrative Procedure Act grounds.4 The government appealed; the Ninth Circuit stayed that appeal in April 2026. A parallel designation under the Federal Acquisition Supply Chain Security Act, 41 U.S.C. § 4713, has not been enjoined — the D.C. Circuit denied Anthropic's emergency stay in April 2026 and had not issued a merits decision as of publication. Cross-motions for summary judgment were argued before Judge Lin on July 30, 2026, with reporting that she signalled she was likely to enjoin the § 3252 designation permanently.4 Breaking Defense reported earlier that the Pentagon's CTO maintained the ban still stood notwithstanding the injunction, and the Congressional Research Service has published its own analysis for Congress.49 In May 2026, DoD expanded classified AI work with eight companies — SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, AWS and Oracle — with Anthropic excluded.10
So a vendor seeking accreditation turned one supplier's models off while one designation sits enjoined, a second sits intact and a merits ruling is pending. Compliance does not wait for appellate clarity; it takes the safest available reading and ships. Whatever the litigation decides, the operational precedent is set: which model providers a platform can reach is now part of what gets accredited, alongside encryption, isolation and personnel screening. Model portability stops being an architectural nicety and becomes a procurement requirement. It is the same governance impulse visible in commercial agent platforms — see how Microsoft Agent 365 built an agent control plane and how OpenAI Presence sells the governed deployment rather than the model — except here the control plane is a federal authorization boundary.
What the Army HRC agents will actually do
Answer questions, summarize cases and route work — with humans keeping the decisions that matter. Army HRC supports 9.2 million Soldiers, Veterans and military families, processes more than 1,500 cases per day, and employs more than 3,000 analysts and HR professionals.3 The agents are scoped, in Salesforce's own description, to "respond to routine inquiries, summarize case histories, and surface relevant policy and career information from approved Army sources."3
The limits are stated as plainly as the capabilities, which is unusual in a launch announcement and worth quoting rather than paraphrasing. "Complex matters involving benefits or other sensitive decisions can still be routed to HRC specialists, who retain decision-making authority," the company writes, adding that "AI agents only access preapproved data and follow prescribed workflows."3 Even the flagship logistics scenario in the platform announcement — an agent cross-referencing readiness logs against global supply inventories when a deployed asset flags a component failure — ends with the agent triggering "a secure procurement order for human review," not placing an order.2
That is a narrower autonomy envelope than "autonomous AI execution" suggests, and a sensible one. Retired Maj. Gen. Allan Day, a Salesforce vice president and industry strategy executive, made the case that constraints are the enabler: "Guardrails, to me, built-in means I can accelerate. It's not a speed bump. It's actually something that allows me to go fast."1 Read against 2026's agent reliability research, that is not just marketing — structure has repeatedly outperformed instructions in getting agents to behave.
The numbers, separated: delivered versus projected
Every headline figure in this story is a Salesforce projection, and one of the most-repeated ones is not about the agents at all. The press release lists "$6 million in projected annual savings" — but reads, in full, that the savings come "simply from reductions in manual processing time, improved case routing, and the elimination of redundant legacy systems through Army HRC's Digital Front Door platform before a single Agentforce agent is deployed to production."3 The savings are attributed to the underlying platform consolidation, explicitly prior to agent deployment. Coverage that presents $6 million as an AI-agent result is reporting the opposite of what the source says.
The conversation volume needs the same care, because the two primary sources frame it differently. Salesforce's press release says "over 55 million agent conversations per month" are "projected at full scale."3 DefenseScoop reports Collins saying the company "estimates that the command is also managing more than 55 million conversations per month serving soldiers, civilians, spouses and veterans, which can now be handled by secure AI agents."1 One frames the figure as future agent throughput, the other as existing total volume that agents could take on. Both are Salesforce's own numbers; neither has been independently verified, and it is worth noting the gap rather than picking a side.
The remaining figures are cleaner but still forward-looking: more than 1,500 cases per day are "expected to be supported by automated case summarization," and the Digital Front Door platform "helps HRC resolve 600,000 cases per year more efficiently."3 The commercial context is not a projection. The Army awarded Salesforce an indefinite-delivery/indefinite-quantity vehicle worth up to $5.6 billion over ten years in January 2026, and the HRC work sits under it; Salesforce also took a $1.6 billion VA contract in July 2026.112
The GAO citation does not say what the press release implies
It largely does not. To argue why passive AI is insufficient, Salesforce's announcement cites a Government Accountability Office finding that 74% of U.S. Air Force aircraft missed their depot maintenance deadlines, attributing the problem to being "largely driven by unforeseen parts shortages and siloed data systems."2 The 74% figure is real and checks out: GAO-26-107890, "Air Force Readiness: Actions Needed to Address Depot Maintenance Delays and Staffing Challenges," released May 14, 2026, reports 74%, up from 31% in 2019.12
The diagnosis is where the paraphrase drifts. GAO's own emphasis falls on the Air Force revising target timelines after unplanned work is discovered — making depots appear to hit goals they missed — and on depot staffing, where Hill, Robins and Tinker cannot compete with private-sector pay for skilled technicians, alongside erosion of the Defense Logistics Agency's vendor base.12 "Siloed data systems" is a reasonable adjacent theme; it is not the report's headline finding, and an agent that unifies data does not fix a hiring problem or a metrics-revision practice. The number is sound. The causal chain from that number to "this is why you need agentic AI" is the vendor's, not the auditor's.
What this signals for agentic AI in regulated environments
That the hard part of shipping agents into regulated work is now procurement architecture, not model capability. Three constraints here generalize beyond defense. Authorization boundaries are per-component: Agentforce 360 at IL5 with Slack still at IL4 is the federal version of a problem every regulated buyer has, where one product family spans several compliance regimes and the marketing speaks for all of it. The model layer is now a governed dependency; a platform that cannot swap or disable a provider on policy grounds cannot be accredited when the politics move. And the autonomy that survives review is narrow by design — summarize, retrieve, route, prepare an action for approval — with vendors increasingly willing to say so in the launch material itself.
None of that is unique to the United States; China's agent regulations impose a different set of constraints on much the same technology. The common thread is that "which model, running where, allowed to do what, approved by whom" is becoming a four-part answer given before an agent ships, not after.
Bottom line
The accreditation is genuinely significant, and almost none of that significance is where the headlines put it. A commercially mainstream agent platform clearing DoD's most sensitive unclassified tier, with a named 9.2-million-person customer already contracted, is a real marker of how fast commercial agent tooling is moving into regulated work.13 But it is not the first AI at IL5, the $6 million is a platform saving explicitly booked before any agent ships, the 55 million conversations are a projection whose two official framings do not match, and the autonomy on offer stops at preparing actions for human approval.237
The durable lesson is the one buried in a single paragraph of DefenseScoop's reporting. To get accredited, a vendor had to certify that one specific model provider was switched off — while the legal basis for excluding that provider sits under a preliminary injunction and on appeal.14 Capability is no longer the gating factor for agents in regulated environments. Provenance is.
Footnotes
-
Brandi Vincent, "Salesforce previews plans to deliver newly authorized 'AI agents' across DOD," DefenseScoop, August 5, 2026. https://defensescoop.com/2026/08/05/salesforce-plans-deliver-newly-authorized-ai-agents-across-dod/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18
-
Salesforce, "Missionforce National Security Unveils IL5-Authorized AI Agents and Apps to Drive Decision Advantage, Readiness, and Enhanced Warfighter Support," August 5, 2026. https://www.salesforce.com/news/press-releases/2026/08/05/dow-agentforce-mission-readiness/ ; VA contract: https://www.salesforce.com/news/press-releases/2026/07/24/missionforce-transforms-veteran-care/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Salesforce, "U.S. Army Human Resources Command Deploys Agentforce to Deliver 24/7 AI-Powered Support to 9.2 Million Soldiers, Veterans, and Military Families," August 5, 2026. https://www.salesforce.com/news/press-releases/2026/08/05/us-army-hrc-agentforce-ai-powered-support/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
FedScoop, "District court temporarily blocks Anthropic ban, supply-chain risk designation." https://fedscoop.com/district-court-temporarily-blocks-anthropic-ban-supply-chain-risk-designation/ ; The Hill, "Judge blocks Pentagon's supply chain risk designation for Anthropic." https://thehill.com/policy/technology/5803486-anthropic-lawsuit-pentagon-claude/ ; Breaking Defense, "Judge grants Anthropic preliminary injunction but Pentagon CTO says ban still stands," March 2026. https://breakingdefense.com/2026/03/judge-grants-anthropic-preliminary-injunction-but-pentagon-cto-says-ban-still-stands/ ; CNBC, "Appeals court rules against Anthropic in Pentagon supply-chain risk case," April 8, 2026 (D.C. Circuit denial of emergency stay of the 41 U.S.C. § 4713 designation). https://www.cnbc.com/2026/04/08/anthropic-pentagon-court-ruling-supply-chain-risk.html ; Jones Walker, "Two courts, two postures: what the D.C. Circuit's stay denial means for the Anthropic litigation." https://www.joneswalker.com/en/insights/blogs/ai-law-blog/two-courts-two-postures-what-the-dc-circuits-stay-denial-means-for-the-anthrop.html ; Vanderbilt AI Law Lab, Anthropic v. DoW litigation tracker (docket status for the N.D. Cal., Ninth Circuit and D.C. Circuit proceedings). https://anthropic-v-dow.vercel.app/ ; Axios, "Judge says Pentagon's case got worse in Anthropic fight," July 30, 2026. https://www.axios.com/2026/07/30/judge-pentagon-case-worse-anthropic ; Courthouse News Service, "Judge likely to rid Anthropic of Pentagon's supply chain risk label." https://www.courthousenews.com/judge-likely-to-rid-anthropic-of-pentagons-supply-chain-risk-label/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Microsoft, "Department of Defense (DoD) Impact Level 5 (IL5)," Microsoft Learn compliance documentation. https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-dod-il5 ; Microsoft, "Department of Defense (DoD) Impact Level 6 (IL6)" (IL6 covers information classified up to SECRET). https://learn.microsoft.com/en-us/azure/compliance/offerings/offering-dod-il6 ; Second Front, "Achieving DoD CC SRG Compliance: Navigating FedRAMP and DISA Impact Levels IL4 vs. IL5." https://www.secondfront.com/resources/blog/achieving-dod-cc-srg-compliance-navigating-fedramp-and-disa-impact-levels-il4-vs-il5/ ; Second Front, "Understanding DoD Cloud Computing Impact Levels" (the CC SRG defines IL2, IL4, IL5 and IL6). https://www.secondfront.com/resources/blog/understanding-dod-cloud-computing-impact-levels/ ↩ ↩2 ↩3 ↩4 ↩5
-
Executive Order 14347, "Restoring the United States Department of War," signed September 5, 2025, established "Department of War" as a secondary title. A statutory rename requires congressional action; the House passed the rename as part of the FY2027 National Defense Authorization Act on July 22, 2026, and no rename had been enacted as of publication. https://en.wikipedia.org/wiki/Executive_Order_14347 ; USAFacts, "Department of Defense or Department of War: Which is it?" https://usafacts.org/articles/department-of-defense-or-department-of-war-which-is-it/ ; The Hill, "House passes NDAA with Department of War rename," July 2026. https://thehill.com/homenews/house/5985402-house-ndaa-passage-department-of-war/ ↩
-
"Palantir Receives DISA Authorization for PFCS Forward, Extending IL5 and IL6 Accreditation to On-Premises and Edge Deployments," Business Wire, February 12, 2026. https://www.businesswire.com/news/home/20260212887851/en/Palantir-Receives-DISA-Authorization-for-PFCS-Forward-Extending-IL5-and-IL6-Accreditation-to-On-Premises-and-Edge-Deployments ; Microsoft, "New AI capabilities available for Government environments," Microsoft Community Hub (Microsoft 365 Copilot general availability in the Office 365 DoD IL5 environment, announced August 14, 2025). https://techcommunity.microsoft.com/blog/publicsectorblog/new-ai-capabilities-available-for-government-environments/4442669 ↩ ↩2 ↩3 ↩4
-
Washington Post, "Anthropic rejects Pentagon demand to allow wide military use of Claude," February 26, 2026. https://www.washingtonpost.com/technology/2026/02/26/anthropic-pentagon-rejects-demand-claude/ ; "A Timeline of the Anthropic-Pentagon Dispute," Tech Policy Press. https://www.techpolicy.press/a-timeline-of-the-anthropic-pentagon-dispute/ ↩
-
Congressional Research Service, "Pentagon-Anthropic Dispute over Autonomous Weapon Systems: Potential Issues for Congress," IN12669. https://www.congress.gov/crs-product/IN12669 ↩
-
Brandi Vincent, "DOD expands its classified AI work with 8 companies — excluding Anthropic — amid ongoing dispute," DefenseScoop, May 1, 2026. https://defensescoop.com/2026/05/01/dod-expands-classified-ai-work-with-8-companies-excluding-anthropic/ ↩
-
Salesforce, "U.S. Army / Department of War Missionforce announcement," January 26, 2026. https://www.salesforce.com/news/press-releases/2026/01/26/us-army-department-of-war-missionforce-announcement/ ; Jon Harper, "Salesforce lands $5.6B Army contract for data analytics, cloud capabilities," DefenseScoop, January 26, 2026. https://defensescoop.com/2026/01/26/salesforce-army-contract-data-analytics-cloud-agentic-ai/ ↩
-
U.S. Government Accountability Office, "Air Force Readiness: Actions Needed to Address Depot Maintenance Delays and Staffing Challenges," GAO-26-107890, released May 14, 2026. https://www.gao.gov/products/gao-26-107890 ; full report PDF: https://www.gao.gov/assets/gao-26-107890.pdf ↩ ↩2



