metir
metir
Docs
Download on App StoreGet it on Google PlayLoginSign Up
Back to Blog
Pentagon AI Contracts
Military AI
OpenAI
Anthropic AI
AI Policy

Pentagon AI Contracts Reveal Push for 'Minimal Refusal' Models

FOIA documents obtained by The Intercept reveal Pentagon AI contracts with OpenAI, Anthropic, Google and xAI, and a disputed push for minimal-refusal military models.

Metir AI TeamSeptember 8, 20269 min read
Pentagon AI Contracts Reveal Push for 'Minimal Refusal' Models

On September 8, 2026, The Intercept published more than 400 pages of Defense Department contract records, obtained through a Freedom of Information Act lawsuit filed with Legal Advocates for Safe Science and Technology. The documents, many of them redacted, cover deals the department signed in July 2025 with four AI companies, OpenAI, Anthropic, Google and xAI, each worth up to $200 million, along with amendments negotiated over the following year. Among the disclosures is a draft contract clause asking OpenAI for a version of its AI built to turn down military commands as rarely as possible.

$200MCeiling per contractFour separate deals
4AI labs under contractOpenAI, Anthropic, Google, xAI
July 2025When the contracts were signed
400+Pages released via FOIAMany sections redacted
OpenAI logoOpenAI
Anthropic logoAnthropic
Google logoGoogle
xAI logoxAI
Four labs signed the same category of Defense Department prototype contract in July 2025. What each has said publicly about military use, and how each has acted since, has diverged.

What the contracts actually require

Each of the four agreements directs the company toward the same broad goal: building AI prototypes intended to "improve military advantage, military utility, or enhance military decision making" across the armed forces, spanning applications from warfighting and automated decision-making to logistics and intelligence. The documents describe a set of recurring obligations that go beyond simply delivering software. Companies are required to share information with the Pentagon in both directions, run training and educational seminars for military personnel, participate in tabletop exercises simulating real-world scenarios, and produce what the contracts call risk forecasting and threat ideation, in effect asked to predict the dangers their own products could pose. Several also include strategic briefings on frontier AI developments and the tactics of foreign adversaries.

From a July 2025 signature to a September 2026 FOIA release

The contracts existed for over a year before their terms became public.

  1. July 2025
    Four prototype contracts signed

    The DoD signs deals worth up to $200 million each with OpenAI, Anthropic, Google and xAI to build AI prototypes intended to "improve military advantage, military utility, or enhance military decision making."

  2. Feb 6-27, 2026
    OpenAI contract amended (P00003)

    An expanded, roughly two-year agreement is negotiated. A draft version of the amendment describes "OpenAI Mission Models" as designed to have "minimal refusal rates." OpenAI and Pentagon spokespeople later say this language was rejected before the final signature.

  3. Early-to-mid 2026
    Anthropic declines a classified deployment

    Anthropic refuses a follow-up agreement for classified military networks without contractual prohibitions on domestic surveillance and autonomous weapons. The Pentagon designates the company a "supply chain risk," a decision a federal judge later rules unlawful.

  4. Sep 8, 2026
    The Intercept publishes the FOIA documents

    Over 400 pages of contract records, obtained through a Freedom of Information Act lawsuit, are published, including the disputed draft language and the full scope of each company’s obligations.

Dates reflect reporting from The Intercept and IBTimes UK; some, including the precise timing of the Anthropic designation, are described only approximately in public reporting.

That structure, a vendor advising the customer on how to use, secure, train for and anticipate risk from its own product, is not unusual in defense contracting generally. What is new is seeing the specific language applied to frontier AI models whose behavior is still actively being tuned, and having that language surface through litigation rather than through either party's own disclosure.

The 'minimal refusal rates' clause

The most closely scrutinized document is a draft amendment to OpenAI's contract, reported separately by The Intercept and associated with an updated agreement worth up to $200 million over two years. It defines a category of product this way:

“

'OpenAI Mission Models' refer to OpenAI models that are designed for national security use cases and have minimal refusal rates.

Draft DoD contract amendment obtained by The Intercept via FOIA

Consumer versions of ChatGPT are built to decline certain requests, among the examples cited in reporting is prioritizing drone-strike targets, along with other categories tied to weapons of mass destruction, autonomous weapons and domestic surveillance. A refusal rate is, mechanically, a measure of how often a model declines to answer or complete a request; it is shaped by the safety tuning and policy layers labs build on top of a base model. Asking for a version with a minimal refusal rate is asking for those thresholds to be set differently for a specific customer and use case than they are for the general public.

Whether that language made it into the contract both parties actually signed is disputed. OpenAI spokesperson Nate Evans said the company "has never agreed to contract language requiring 'minimal refusal rates,'" describing the document as "an earlier draft proposed by the Department before we provided feedback," which OpenAI says it rejected and the department agreed to remove from the executed agreement. A Pentagon spokesperson, Jacob Bliss, said the phrase "does not appear in any active Department of War contract with OpenAI." The Intercept reports that Pentagon lawyers initially confirmed the document was the signed version before reversing that statement, which is why the dispute remains open rather than settled by either side's denial. OpenAI's own current usage terms for its national-security work list restrictions against mass domestic surveillance, directing autonomous weapons systems, and unreviewed high-stakes automated decisions, restrictions the company points to as evidence its guardrails were not simply removed for this customer.

Four labs, four postures

The four companies under contract have not treated their obligations, or their own usage policies, identically. Google is reported to have revised an earlier public pledge against building AI for weapons or surveillance applications, and its contract includes briefing military officials on the AI tactics and techniques of adversaries. Anthropic has held a different line: it declined to sign a follow-up agreement covering classified military networks unless the deal preserved its existing prohibitions on domestic surveillance and autonomous weapons use. xAI's public posture on military use has not been detailed in reporting on these contracts to the same degree as the other three.

Four labs, one contract structure, four different postures

Every company signed the same category of prototype deal. What each has said publicly, and what the FOIA record shows, differs.

OpenAI
Public usage policy
Usage policy once barred weapons development broadly; now permits national-security use under contract-specific limits (no mass domestic surveillance, no directing autonomous weapons, no unreviewed high-stakes automated decisions).
What the FOIA record shows
A draft 2026 contract amendment described "OpenAI Mission Models" as built for "minimal refusal rates." OpenAI and Pentagon officials say that language was rejected before the final signature.
Status with the Pentagon
Classified-network deployment agreement finalized in late February 2026.
Anthropic
Public usage policy
Usage policy keeps restrictions on domestic surveillance and fully autonomous weapons in place for Claude, including for government customers.
What the FOIA record shows
Declined a follow-up agreement for classified military networks that did not preserve those restrictions.
Status with the Pentagon
Designated a "supply chain risk" by the Pentagon; a federal judge ruled that designation unlawful retaliation on August 28, 2026. A narrower related case remains on appeal.
Google
Public usage policy
Revised an earlier public pledge against building AI for weapons or surveillance applications, opening the door to a broader range of defense work.
What the FOIA record shows
Contract obligations reported to include briefing military officials on the AI tactics and techniques of adversaries.
Status with the Pentagon
Contract in place since July 2025; no public dispute with the Pentagon reported in the FOIA documents.
xAI
Public usage policy
No detailed public usage-policy statement on military or weapons use has surfaced in reporting on the contracts.
What the FOIA record shows
Named alongside the other three as bound by the same category of obligations in the released documents.
Status with the Pentagon
Contract in place since July 2025; no public dispute with the Pentagon reported in the FOIA documents.

Compiled from public reporting on the released contract documents. Disputed characterizations, such as the "minimal refusal rates" draft language, are noted as disputed.

Then-Secretary of Defense Pete Hegseth speaking at a Pentagon press briefing podium in June 2025
Then-Secretary of Defense Pete Hegseth at a Pentagon briefing on June 22, 2025, weeks before the four AI contracts were signed. His department later designated Anthropic a national-security "supply chain risk" after the company refused to drop use restrictions for classified deployment, a designation a federal judge ruled unlawful retaliation on August 28, 2026. Photo by U.S. Navy Petty Officer 1st Class Alexander Kubitza, DoD.

The Anthropic dispute predates this FOIA release and has already worked through a courtroom: Judge Rita Lin's ruling that the designation was unlawful retaliation is its own story, covered separately. What the newly released contract documents add is context for how that dispute began: it sits inside the same July 2025 contract structure every other lab agreed to, and it shows one company using its refusal to relax stated restrictions as leverage in a negotiation the other three, on the public record so far, did not have in the same way.

What FOIA-revealed oversight does and does not do

Two researchers quoted in the reporting frame the underlying concern in different terms. Heidy Khlaaf of the AI Now Institute described a risk of "subversion of democratic processes when AI labs are allowed to take over the arbitration of risk determinations with life-or-death consequences," pointing at the contracts' risk-forecasting clauses, where a company assesses the dangers of its own technology rather than an independent party doing so. Cambridge fellow Sophia Goodfriend put the same dynamic differently, describing company engineers as "working in lockstep with the department of war," the label the department has also used to describe itself during 2026 alongside its formal name.

The opposing case, made less directly in the reporting but implicit in the contracts themselves, is one of usability and speed. A military customer working through consumer-grade refusal behavior built for a general public that includes minors and untrained users argues it needs a model tuned for legitimate national-security tasks its personnel are authorized to perform, the same argument that underlies why enterprise and government deployments of any software routinely differ from consumer defaults. Neither framing resolves the other. What the FOIA release changes is not the underlying tension between commercial safety guardrails and a military customer's usability requirements, a tension that existed the moment any lab agreed to defense work, but the fact that its specific contract language is now something outside reviewers can examine rather than something each company describes to the public on its own terms.

That distinction, between a company's public usage policy and the actual, sometimes contested, language in a signed government contract, is also the reason multiple readings of this release remain live at once. It is possible both that a draft asked for something no signed contract ultimately contained, and that the request itself reveals what a government customer wanted and may ask for again in a future amendment. FOIA litigation surfaced this document; it did not resolve which of those readings is the complete picture, and neither this reporting nor an outside analysis of it can substitute for the redacted portions of the record that remain unseen.

For organizations outside defense procurement watching this play out, the practical lesson is closer to home than the subject matter suggests: a model's behavior is not fixed by its public name. The same underlying system can ship with materially different refusal thresholds depending on the contract behind it, which is one reason keeping model choice visible and portable, rather than locked to a single vendor's default configuration, as platforms like Metir AI that route across OpenAI, Anthropic, Google and other providers are built to do, matters even for teams with no exposure to national-security work.

Sources:

  • Revealed: The Pentagon's Secret AI Weapons Contracts With OpenAI, Anthropic, and Google | The Intercept
  • The Pentagon Wanted an AI That Rarely Says No | The Intercept
  • AI Giants' Pentagon Military Contracts Revealed via FOIA Lawsuit | International Business Times UK

Image credits

Header image: aerial view of the Pentagon, Arlington, Virginia, May 15, 2023, by U.S. Air Force Staff Sgt. John Wright, DoD, via Wikimedia Commons, public domain (U.S. federal government work). In-body photograph of then-Secretary of Defense Pete Hegseth at a Pentagon press briefing, June 22, 2025, by U.S. Navy Petty Officer 1st Class Alexander Kubitza, Office of the Secretary of Defense, via Wikimedia Commons, public domain (U.S. federal government work).

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of Service
  • Privacy Policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational