openai
Pentagon asked for AI with "minimal refusal rates"
Promtime
openaiThe Department of Defense asked OpenAI for a custom version of its models built to turn down military commands as rarely as possible, according to contract files released to The Intercept under a Freedom of Information Act lawsuit and covering an expansion of a prototype deal worth up to $200 million over two years.
At a glance
- The paperwork lists "Testing, Evaluation, and Refinement of OpenAI Mission Models" as a deliverable and defines those models as ones designed for national security use cases that have minimal refusal rates.
- OpenAI spokesperson Nate Evans said the wording came from an earlier Pentagon draft, that the company rejected it, that the department agreed to remove it, and that the executed agreement omits it.
- A Justice Department attorney representing the Pentagon first confirmed the file was the signed and executed contract, then withdrew that confirmation hours later, after The Intercept contacted OpenAI.
The dispute reads as a fight over who sets the limits on military AI, the state or the vendor. Guardrail behaviour is a product decision, and a contract line asking for fewer refusals likely turns a safety property into a procurement requirement. That places a company's internal policy choices, rather than public rules of engagement, at the point where an intelligence or targeting workflow either proceeds or stops.
The contract text defines "OpenAI Mission Models" as models with minimal refusal rates
The language sits in a section describing what OpenAI owed the Pentagon, among deliverables listed as "Testing, Evaluation, and Refinement of OpenAI Mission Models" for "national security problem sets". The document states that OpenAI Mission Models are models designed for national security use cases that have minimal refusal rates.
OpenAI's flagship models carry built-in guardrails that reject certain queries on safety grounds. Asked to prioritize drone airstrike targets, the consumer version of ChatGPT replies that it cannot provide a prioritization scheme for conducting UAV airstrikes against specific enemy combatants, and OpenAI bars public use of its systems for developing weapons of mass destruction.
Heidy Khlaaf, chief scientist at the AI Now Institute and a former systems safety engineer at OpenAI, said minimal refusal likely refers to little or no safeguards on the model being used. She called private corporations making warfare determinations that are ultimately state obligations a worrying development.
A Justice Department attorney called the file executed, then reversed hours later
Working with Legal Advocates for Safe Science and Technology, The Intercept filed a FOIA inquiry seeking only final, executed contract documents about the military's deals with AI companies, and asked the Pentagon to exclude draft materials. None of the documents released through the lawsuit is marked as a draft.
Asked to confirm whether the document was the final agreement, a Justice Department attorney representing the Pentagon said it was the signed and executed version. Hours later, after The Intercept approached OpenAI, the attorney said to disregard that confirmation, stating the department needed more time to investigate.
Department of Defense spokesperson Jacob Bliss said the phrase does not appear in any active Department of War contract with OpenAI. Trevor Tiedeman, a special assistant to the under secretary of war for research and engineering, told The Intercept there might be some stray voltage or wires crossing between the FOIA material and what counts as an executed contract.
OpenAI signed the classified-network agreement on February 27
OpenAI, Google, xAI and Anthropic all agreed in 2025 to build militarized prototypes of their models for the armed forces, covering logistics, intelligence decision-making and general warfighting. A separate document signed by both OpenAI and the government on February 6 indicates the company agreed that day to the contents of the expanded P00003.
On February 27, OpenAI signed the latest version of its Pentagon agreement, permitting use of its services across the U.S. military's classified networks. That update repeats the Mission Models deliverable header, but its text is redacted in full. OpenAI says it secured red lines on autonomous killings and spying against Americans.
Anthropic's parallel expansion into classified networks collapsed, the company says, after the Defense Department refused contractual prohibitions on autonomous weapon systems and domestic surveillance. The Trump administration then designated Anthropic a supply-chain risk and moved to bar it from government use, a designation a federal judge overturned late last month.
The document the Pentagon owes
Days later the Justice Department attorney said the document was not the final version and that a correct one would be shared later, without a definitive timeline. Trevor Tiedeman said he would account for how the file was flagged by Pentagon FOIA officers, cleared for release, and then confirmed as accurate by the department's lawyers.
The released paperwork does not say which requests the Pentagon wanted minimally refused or what the national security problem sets involve, and The Intercept reports that the classified network agreement as drafted ultimately allows for any uses the government deems legal.
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
We only use your name and avatar from Google. We never store your email address.
