Newly disclosed government records obtained through Freedom of Information Act litigation show that the U.S. Department of Defense sought a customized version of OpenAI's artificial intelligence technology built with minimal refusal rates when handling military commands. The requirement appeared in an updated contract document detailing deliverables for software intended to process national security problem sets, triggering immediate pushback from ethics experts and conflicting explanations from defense officials.
Both OpenAI and the Department of Defense forcefully denied that any executed agreement contains language requiring the removal or lowering of safety guardrails. However, the release of the unredacted contract file—initially verified as an executed agreement by a Department of Justice attorney before being walked back—has exposed deep underlying tensions between military planners seeking unrestrained computational tools and technology developers attempting to maintain ethical boundaries.
Disputed Contract Terms and FOIA Lawsuit Disclosures
The controversial language emerged from records released as part of a Freedom of Information Act lawsuit filed by investigative news outlet The Intercept in partnership with the legal advocacy group Legal Advocates for Safe Science and Technology. The legal filing specifically requested final, executed defense contracts regarding artificial intelligence integration while explicitly requesting that draft materials be excluded. None of the pages released by the government were marked as draft documents.
The clause seeking minimal refusal rates was embedded within version P00003 of a contract, an expansion of a two-year military prototype deal worth up to $200 million initially established in mid-2025. An accompanying document dated February 6, 2026, indicated mutual agreement to the contents of the expanded package. A Justice Department lawyer representing the Pentagon initially confirmed to reporters that the document constituted the finalized, signed version of the contract, before retracting the statement hours later following inquiries to OpenAI.
Pentagon officials subsequently offered shifting explanations for how the document entered the public release. Trevor Tiedeman, a special assistant to the under secretary of war for research and engineering, suggested in an interview that "there might be some stray voltage or wires crossing between whatever FOIA information you may have received versus what actually exists versus what is an executed contract per se." Tiedeman pledged to conduct a complete review of how the record was cleared by defense reviewers and confirmed by government counsel, but subsequently ceased communications without providing the promised accounting or releasing an alternative executed text.
Mission Models and the Question of Safety Guardrails
The disputed contract text specifically defined deliverables under the heading Testing, Evaluation, and Refinement of OpenAI Mission Models. According to the document, OpenAI Mission Models refer to OpenAI models that are designed for national security use cases and have minimal refusal rates. While the paperwork did not delineate the precise operational tasks involved in national security problem sets, standard commercial generative AI platforms include hardcoded refusal protocols designed to block queries involving violence, weapons creation, or autonomous tactical targeting.
For example, commercial iterations of ChatGPT automatically reject operational military prompts, informing users with messages such as, "I can't provide a prioritization scheme for conducting UAV airstrikes against specific enemy combatants." Modifying a large language model to serve tactical intelligence or warfighting functions requires lowering these standard refusals, raising major questions about where systemic safety boundaries are drawn.
Safety researchers warned that altering refusal parameters in military environments carries profound risks. Heidy Khlaaf, chief scientist at the AI Now Institute and a former systems safety engineer at OpenAI, noted that "minimal refusal is likely referring to little or no safeguards on the model being used." Khlaaf emphasized that permitting corporate policy or altered technical guardrails to dictate operational parameters in armed conflict creates severe systemic risk, stating that "it is a worrying development that private corporations are given the power to [make] determinations in warfare that are ultimately state obligations, whether it be for targeting recommendations, or the guardrails deployed to constrain a state’s military use."
Industry-Wide Military Expansion Across Classified Networks
The contract dispute occurs amid a broader push by the Department of Defense to integrate frontier artificial intelligence models directly into warfighting operations. In 2025, OpenAI, Google, xAI, and Anthropic each entered into foundational prototype agreements with the Pentagon to adapt commercial models for defense logistics, intelligence analysis, and battle management. By early 2026, the military sought to deepen these ties by deploying high-capability models directly onto classified defense networks.
OpenAI finalized its updated agreement permitting classified deployment on February 27, 2026. The executed contract update retained the identical heading regarding Testing, Evaluation, and Refinement of OpenAI Mission Models, but the accompanying text in that version was redacted entirely. OpenAI claimed it successfully established firm red lines against using its systems for domestic surveillance or fully autonomous lethal actions, though critics note the overarching framework relies on broad statutory definitions that permit actions deemed lawful by defense authorities.
OpenAI spokesperson Nate Evans firmly rejected assertions that the firm conceded to lower model guardrails, stating, "OpenAI has never agreed to contract language requiring 'minimal refusal rates.' This language does not appear in our executed contract." Evans added, "The document you received appears to be an earlier draft proposed by the Department before we provided feedback. We rejected that language, the department agreed to remove it, and the final executed agreement does not include it." Department of Defense spokesperson Jacob Bliss similarly asserted in a written statement that "the phrase 'minimal refusal rates' does not appear in any active Department of War contract with OpenAI."
Divergent Corporate Paths Amid Pentagon Pressure
The friction surrounding OpenAI's contract highlights contrasting approaches taken by leading artificial intelligence firms when negotiating with defense leadership. Earlier in 2026, rival developer Anthropic engaged in a high-profile standoff with the Pentagon after insisting on explicit contractual terms prohibiting its technology from being integrated into autonomous weapons systems or domestic intelligence gathering. Following the collapse of those negotiations, the Trump administration designated Anthropic a supply-chain risk and initiated steps to bar the firm from federal procurement, a designation that was struck down by a federal judge late last month.
Unlike Anthropic, OpenAI moved quickly to finalize its classified network deployment framework, positioning itself as a key supplier for military computational infrastructure. While OpenAI maintains that its public safety policies prohibit autonomous weapon deployment, the ambiguity surrounding contract drafts and classified addendums has kept the issue under intense public and legal scrutiny.
The Department of Justice has stated that the correct final executed version of the OpenAI contract will eventually be provided through the ongoing FOIA litigation, though government attorneys have not established a definitive timeline for its release. Meanwhile, OpenAI remains entangled in separate federal copyright litigation brought by media outlets including The Intercept, underscoring the complex legal and ethical environment surrounding the commercial AI industry's expanding role in national security.