On September 8, 2026, The Intercept published more than 400 pages of Defense Department contract records, obtained through a Freedom of Information Act lawsuit filed with Legal Advocates for Safe Science and Technology. The documents, many of them redacted, cover deals the department signed in July 2025 with four AI companies, OpenAI, Anthropic, Google and xAI, each worth up to $200 million, along with amendments negotiated over the following year. Among the disclosures is a draft contract clause asking OpenAI for a version of its AI built to turn down military commands as rarely as possible.
Anthropic
xAIWhat the contracts actually require
Each of the four agreements directs the company toward the same broad goal: building AI prototypes intended to "improve military advantage, military utility, or enhance military decision making" across the armed forces, spanning applications from warfighting and automated decision-making to logistics and intelligence. The documents describe a set of recurring obligations that go beyond simply delivering software. Companies are required to share information with the Pentagon in both directions, run training and educational seminars for military personnel, participate in tabletop exercises simulating real-world scenarios, and produce what the contracts call risk forecasting and threat ideation, in effect asked to predict the dangers their own products could pose. Several also include strategic briefings on frontier AI developments and the tactics of foreign adversaries.
From a July 2025 signature to a September 2026 FOIA release
The contracts existed for over a year before their terms became public.
- July 2025Four prototype contracts signed
The DoD signs deals worth up to $200 million each with OpenAI, Anthropic, Google and xAI to build AI prototypes intended to "improve military advantage, military utility, or enhance military decision making."
- Feb 6-27, 2026OpenAI contract amended (P00003)
An expanded, roughly two-year agreement is negotiated. A draft version of the amendment describes "OpenAI Mission Models" as designed to have "minimal refusal rates." OpenAI and Pentagon spokespeople later say this language was rejected before the final signature.
- Early-to-mid 2026Anthropic declines a classified deployment
Anthropic refuses a follow-up agreement for classified military networks without contractual prohibitions on domestic surveillance and autonomous weapons. The Pentagon designates the company a "supply chain risk," a decision a federal judge later rules unlawful.
- Sep 8, 2026The Intercept publishes the FOIA documents
Over 400 pages of contract records, obtained through a Freedom of Information Act lawsuit, are published, including the disputed draft language and the full scope of each company’s obligations.
Dates reflect reporting from The Intercept and IBTimes UK; some, including the precise timing of the Anthropic designation, are described only approximately in public reporting.
That structure, a vendor advising the customer on how to use, secure, train for and anticipate risk from its own product, is not unusual in defense contracting generally. What is new is seeing the specific language applied to frontier AI models whose behavior is still actively being tuned, and having that language surface through litigation rather than through either party's own disclosure.
The 'minimal refusal rates' clause
The most closely scrutinized document is a draft amendment to OpenAI's contract, reported separately by The Intercept and associated with an updated agreement worth up to $200 million over two years. It defines a category of product this way:
'OpenAI Mission Models' refer to OpenAI models that are designed for national security use cases and have minimal refusal rates.
Draft DoD contract amendment obtained by The Intercept via FOIA
Consumer versions of ChatGPT are built to decline certain requests, among the examples cited in reporting is prioritizing drone-strike targets, along with other categories tied to weapons of mass destruction, autonomous weapons and domestic surveillance. A refusal rate is, mechanically, a measure of how often a model declines to answer or complete a request; it is shaped by the safety tuning and policy layers labs build on top of a base model. Asking for a version with a minimal refusal rate is asking for those thresholds to be set differently for a specific customer and use case than they are for the general public.
Whether that language made it into the contract both parties actually signed is disputed. OpenAI spokesperson Nate Evans said the company "has never agreed to contract language requiring 'minimal refusal rates,'" describing the document as "an earlier draft proposed by the Department before we provided feedback," which OpenAI says it rejected and the department agreed to remove from the executed agreement. A Pentagon spokesperson, Jacob Bliss, said the phrase "does not appear in any active Department of War contract with OpenAI." The Intercept reports that Pentagon lawyers initially confirmed the document was the signed version before reversing that statement, which is why the dispute remains open rather than settled by either side's denial. OpenAI's own current usage terms for its national-security work list restrictions against mass domestic surveillance, directing autonomous weapons systems, and unreviewed high-stakes automated decisions, restrictions the company points to as evidence its guardrails were not simply removed for this customer.
Four labs, four postures
The four companies under contract have not treated their obligations, or their own usage policies, identically. Google is reported to have revised an earlier public pledge against building AI for weapons or surveillance applications, and its contract includes briefing military officials on the AI tactics and techniques of adversaries. Anthropic has held a different line: it declined to sign a follow-up agreement covering classified military networks unless the deal preserved its existing prohibitions on domestic surveillance and autonomous weapons use. xAI's public posture on military use has not been detailed in reporting on these contracts to the same degree as the other three.
Four labs, one contract structure, four different postures
Every company signed the same category of prototype deal. What each has said publicly, and what the FOIA record shows, differs.
Compiled from public reporting on the released contract documents. Disputed characterizations, such as the "minimal refusal rates" draft language, are noted as disputed.

The Anthropic dispute predates this FOIA release and has already worked through a courtroom: Judge Rita Lin's ruling that the designation was unlawful retaliation is its own story, covered separately. What the newly released contract documents add is context for how that dispute began: it sits inside the same July 2025 contract structure every other lab agreed to, and it shows one company using its refusal to relax stated restrictions as leverage in a negotiation the other three, on the public record so far, did not have in the same way.
What FOIA-revealed oversight does and does not do
Two researchers quoted in the reporting frame the underlying concern in different terms. Heidy Khlaaf of the AI Now Institute described a risk of "subversion of democratic processes when AI labs are allowed to take over the arbitration of risk determinations with life-or-death consequences," pointing at the contracts' risk-forecasting clauses, where a company assesses the dangers of its own technology rather than an independent party doing so. Cambridge fellow Sophia Goodfriend put the same dynamic differently, describing company engineers as "working in lockstep with the department of war," the label the department has also used to describe itself during 2026 alongside its formal name.
The opposing case, made less directly in the reporting but implicit in the contracts themselves, is one of usability and speed. A military customer working through consumer-grade refusal behavior built for a general public that includes minors and untrained users argues it needs a model tuned for legitimate national-security tasks its personnel are authorized to perform, the same argument that underlies why enterprise and government deployments of any software routinely differ from consumer defaults. Neither framing resolves the other. What the FOIA release changes is not the underlying tension between commercial safety guardrails and a military customer's usability requirements, a tension that existed the moment any lab agreed to defense work, but the fact that its specific contract language is now something outside reviewers can examine rather than something each company describes to the public on its own terms.
That distinction, between a company's public usage policy and the actual, sometimes contested, language in a signed government contract, is also the reason multiple readings of this release remain live at once. It is possible both that a draft asked for something no signed contract ultimately contained, and that the request itself reveals what a government customer wanted and may ask for again in a future amendment. FOIA litigation surfaced this document; it did not resolve which of those readings is the complete picture, and neither this reporting nor an outside analysis of it can substitute for the redacted portions of the record that remain unseen.
For organizations outside defense procurement watching this play out, the practical lesson is closer to home than the subject matter suggests: a model's behavior is not fixed by its public name. The same underlying system can ship with materially different refusal thresholds depending on the contract behind it, which is one reason keeping model choice visible and portable, rather than locked to a single vendor's default configuration, as platforms like Metir AI that route across OpenAI, Anthropic, Google and other providers are built to do, matters even for teams with no exposure to national-security work.
Sources:
- Revealed: The Pentagon's Secret AI Weapons Contracts With OpenAI, Anthropic, and Google | The Intercept
- The Pentagon Wanted an AI That Rarely Says No | The Intercept
- AI Giants' Pentagon Military Contracts Revealed via FOIA Lawsuit | International Business Times UK
Image credits
Header image: aerial view of the Pentagon, Arlington, Virginia, May 15, 2023, by U.S. Air Force Staff Sgt. John Wright, DoD, via Wikimedia Commons, public domain (U.S. federal government work). In-body photograph of then-Secretary of Defense Pete Hegseth at a Pentagon press briefing, June 22, 2025, by U.S. Navy Petty Officer 1st Class Alexander Kubitza, Office of the Secretary of Defense, via Wikimedia Commons, public domain (U.S. federal government work).
