Two announcements six days apart moved federal AI from pilot programs to production paths. On August 5, Salesforce announced that the U.S. Army Human Resources Command will deploy autonomous agents under the newly Impact Level 5 (IL5)-authorized Agentforce — the first Department of War organization to do so — supporting 9.2 million soldiers, veterans, civilian staff, and military families. On August 11, FedScoop reported that GSA's promotional OneGov agreements with OpenAI, Google, and Anthropic, priced at roughly $0.47 to $1 per agency, expire September 30. Authorization is no longer the bottleneck, and the discount era is closing. Both facts change how contractors and public-sector operators should plan the next two quarters.
Key takeaways
- IL5 is now precedent. The Army HRC deployment is the first Department of War use of IL5-authorized autonomous agents, covering workloads with highly sensitive controlled unclassified information.
- Human authority stayed in the design. Agents handle routine inquiries; complex benefits and sensitive decisions route to HRC specialists who retain decision-making authority.
- The $1 era ends September 30. Google and OpenAI shift OneGov renewals to per-user and tiered pricing; Anthropic had announced no public renewal terms.
- Adoption is already broad. More than 120 orders have been placed against OneGov AI offerings, and roughly 3.4 million federal employees have access.
- Lock-in is behavioral. Experts quoted by FedScoop warn the real renewal risk is workforce dependency, not technical switching costs.
What the Army's IL5 deployment actually changes
The Army Human Resources Command selected Missionforce National Security, Salesforce's national security unit, to deploy the agents. Per the company, the system provides 24/7 support to 9.2 million people — soldiers, veterans, civilian staff, and military families.
The workflow design matters more than the headline number. Agents respond to routine inquiries, summarize case histories, and surface policy and career information from approved Army sources. Complex benefits questions and sensitive decisions route to HRC specialists, who retain decision-making authority. Bounded agent scope, approved sources only, documented human authority — that split is the template authorizing officials will point to from here.
IL5 authorization covers workloads involving highly sensitive controlled unclassified information (CUI), and Salesforce unveiled a broader set of IL5-authorized agents and apps under Missionforce National Security the same day. The precedent is the point. If autonomous agents can clear DoD CUI requirements for HR workflows, a blanket security no becomes harder to sustain for comparable internal service functions — in government, and in regulated industry generally.
The $1 era of OneGov ends September 30
GSA's promotional OneGov agreements for OpenAI's ChatGPT, Google's Gemini, and Anthropic's Claude expire September 30, 2026. Uptake was substantial. More than 120 orders have been placed against OneGov AI offerings, roughly 3.4 million federal employees have access, and OpenAI reports over 1 million users across federal, state, and local governments.
Renewals will look different. Google and OpenAI are shifting to per-user and tiered pricing models. Anthropic had announced no public renewal terms at the time of the FedScoop report. Former federal CIO Greg Barbaccia expects renewals will not be $1 — his argument is that they should at least be cost-transparent.
The pipeline is not slowing while pricing resets. On July 28, GSA announced a new OneGov agreement with agentic-AI provider CORAS: GARY Insight at 80% off and GARY Execute at 40% off through September 30, 2027, via the Multiple Award Schedule. The discounts are migrating from chat assistants to agentic tooling. The sequence for operators to note: promotional pricing establishes usage, and usage sets the terms of the renewal.
The moat moves from compliance to mission fit
For the past two years, the operating assumption in federal AI has been that compliance is the moat. Vendors who could clear FedRAMP paths and impact-level authorizations held a defensible position; everyone else waited. This month weakened that assumption from both ends. IL5-authorized autonomous agents are running at a Department of War organization, and frontier models sit in millions of federal hands through OneGov.
When authorization patterns become precedent, the differentiator moves downstream — to mission fit, workflow design, and the acceptance criteria a program office writes before go-live. The experts FedScoop quotes point the same direction: the real lock-in risk is behavioral dependency among federal workers, not technical lock-in. Switching costs will live in habits and retraining, not in APIs. Buyers who define what the system must do, in their own workflow terms, keep leverage that a discount never provides.
The hard part of federal AI is no longer getting authorized. It is deciding what you will accept once the agent is running.
What operators should do now
- Cite the precedent. When an authorization review stalls, point to the IL5 pattern: bounded agent scope, approved sources, human decision authority documented in the workflow. The same structure supports approval cases in regulated commercial environments.
- Write acceptance criteria before the renewal call. Decide what the system must do — and what you will decline to accept — before the pricing conversation, not after.
- Model the step-up now. If your current pricing is promotional, budget for per-user tiers and ask for cost transparency in writing.
- Plan for exit. Behavioral dependency is real. Keep prompts, data, and workflows portable enough that a vendor change is expensive, not impossible.
We track the broader picture in our federal AI industry update, and our government and defense practice page describes how we scope deployments inside authorization boundaries. The Army's routing design is the same argument we make in acceptance criteria, not demos. If an authorization decision or a renewal lands on your calendar this quarter, book a consult.