top of page

OpenAI Pentagon Contract Records Reveal a Disputed Demand for AI That Rarely Says No

Sep 10
13 min read

OpenAI faces new scrutiny after Pentagon records described military models with “minimal refusal rates,” despite both parties denying that requirement entered their executed agreement. The disputed language appears in version P00003 of an OpenAI Pentagon contract obtained through a Freedom of Information Act lawsuit. It describes specialized systems intended to reject national security requests as rarely as possible.

That phrase does not prove that the Pentagon received an unrestricted model. OpenAI says it rejected the provision, while the Defense Department says no active contract contains it. Yet the government released P00003 in response to a request that explicitly excluded drafts, according to the contract investigation.

The paperwork also created an unusual verification problem. A Pentagon lawyer initially confirmed that the released record was the final contract, then withdrew that confirmation after reporters contacted OpenAI. Meanwhile, separate documents indicate that both parties signed an expanded P00003 agreement on February 6, before another agreement authorized deployment across classified networks on February 27.

The controversy therefore extends beyond one disputed sentence. It tests whether contractual promises, model-level restrictions, and public assurances can be audited when advanced AI enters secret military systems.

Anthropic provides the immediate comparison. Its dispute with the Pentagon centered on restrictions involving mass domestic surveillance and autonomous weapons. OpenAI later announced classified deployment while saying its own agreement preserved protections in those areas.

The central conflict is clear: the government wants models that remain useful across lawful military missions, while AI providers say some uses still require firm limits. A model optimized to refuse less often can help analysts complete legitimate work. The same design goal can also weaken an important layer of protection when prompts concern surveillance, targeting, or lethal force.

The OpenAI Pentagon Contract Has Two Conflicting Histories

The released paperwork and the official explanations do not yet form one consistent account of what the parties signed.

The controversy begins with a prototype agreement awarded to OpenAI Public Sector in 2025. A federal contract notice describes a fixed-amount prototype agreement valued at up to $200 million. Its stated purpose was to develop frontier AI capabilities addressing critical national security challenges.

OpenAI was not alone. The Pentagon also established relationships with Anthropic, Google, and xAI for military AI prototypes. Reported use cases included logistics, intelligence decision support, and broader warfighting activities.

P00003 expanded the earlier OpenAI arrangement. The version released through the FOIA litigation defined “OpenAI Mission Models” as systems designed for national security applications. It said those models would have “minimal refusal rates” and would offer operational capabilities tailored to military users.

A refusal occurs when a model declines to complete a request because policy, safety, or technical controls identify the task as impermissible. Refusal rates can also rise when safeguards incorrectly block legitimate work. Lowering unnecessary refusals is therefore a reasonable product goal in many settings.

The military context changes the stakes. A refusal involving harmless document formatting is inconvenient. A refusal involving target selection, population monitoring, or weapons operation can be a deliberate safety boundary.

OpenAI spokesperson Nate Evans told The Intercept that the company never accepted language requiring minimal refusal rates. He characterized the released text as an earlier government proposal that OpenAI rejected. Evans said the final executed agreement omitted the requirement.

Pentagon spokesperson Jacob Bliss similarly said the phrase did not appear in any current agreement between the department and OpenAI. These denials directly challenge the status of the P00003 document, but they do not explain why it entered a final-record production.

The Intercept and Legal Advocates for Safe Science and Technology had requested executed contracts, modifications, and related final documents. The request reportedly instructed the department not to include drafts. That distinction matters because FOIA productions can contain preliminary material, but the requester had specifically tried to prevent this ambiguity.

A Pentagon attorney initially told the publication that P00003 was the final contract. After OpenAI received questions about the language, the attorney reversed that answer and asked the reporters to disregard it. The department then said it needed more time to determine what had been released.

This sequence leaves several possibilities open. The government might have produced a draft by mistake. The document might combine accepted terms with language later removed through another instrument. It might also represent an executed modification that was superseded before deployment.

None of those possibilities can be selected confidently without the signature pages, revision history, or operative replacement text. The critical fact is not that OpenAI certainly supplied a low-refusal model. The critical fact is that the public record cannot yet establish which version governed the work.

Why “Minimal Refusal Rates” Changes the Safety Question

A low refusal target measures availability, but it does not reveal whether the model remains bounded in high-risk situations.

Consumer AI products frequently refuse prompts involving malware, personal data abuse, weapon construction, or targeted violence. These controls are imperfect. They sometimes reject benign research, fiction, cybersecurity testing, or requests that lack dangerous intent.

Government users have legitimate reasons to seek different behavior. An intelligence analyst might need to summarize extremist propaganda without endorsing it. A cybersecurity team might ask a model to explain malicious code so defenders can identify it. Military planners may need analysis involving weapons, adversaries, and battlefield conditions.

A standard consumer policy could block those tasks simply because it recognizes dangerous vocabulary. Specialized models can reduce such false positives by considering the user’s authority, operating environment, and intended mission.

The disputed clause goes further than describing mission-specific access. “Minimal refusal rates” frames successful performance around how rarely the system says no. Without accompanying metrics, exceptions, or evaluation rules, the phrase reveals little about which refusals should remain.

One model can lower refusals by becoming better at distinguishing legitimate from prohibited requests. Another can reach the same numerical result by removing safeguards. Those are fundamentally different systems, even if their aggregate refusal rates appear identical.

Heidy Khlaaf, the AI Now Institute’s chief scientist and a former OpenAI systems safety engineer, told The Intercept that the language likely refers to few or no model safeguards. She also questioned the premise of creating national security-specific guardrails without transparent limits.

That interpretation remains an expert assessment rather than proof of the deployed configuration. The contract phrase does not disclose training data, system instructions, access controls, evaluation results, or the conditions that trigger human review.

Those missing details are decisive. A military model could respond broadly while remaining unable to initiate actions. It could operate inside a controlled cloud environment with authenticated users, logged prompts, and separate authorization systems. Alternatively, its output could flow into operational workflows where speed reduces opportunities for scrutiny.

The distinction between advice and action can also blur. A model does not need to pull a trigger to shape a lethal outcome. It might rank potential targets, combine intelligence reports, recommend surveillance priorities, or summarize evidence for a commander.

Every step can influence the final decision. A human signature at the end does not automatically provide meaningful oversight if the human lacks time, information, or authority to challenge the system.

Refusal behavior is only one control within this chain. Procurement restrictions define permitted purposes. Model policies determine which requests receive answers. Technical architecture controls data access and external actions. Military doctrine assigns responsibility when people act on the output.

A credible safety claim must explain how these layers reinforce each other. It should also identify what happens when one layer fails.

OpenAI says its deployment contains technical safeguards and requires human responsibility for decisions involving lethal force. Its public description also prohibits mass domestic surveillance. These are material commitments, but the undisclosed agreement limits independent assessment of how they operate.

The disputed wording therefore matters even if OpenAI successfully removed it. It shows what at least one government draft prioritized during negotiations. The clause placed response availability at the center, while leaving the boundaries of acceptable refusal unstated in the released language.

OpenAI’s Public Safeguards Meet the Pentagon’s Broad Mission Standard

The primary tension is between OpenAI’s promised red lines and a military procurement model built around all lawful uses.

On February 27, OpenAI reached an agreement allowing its models to operate in classified military environments. The timing followed the collapse of negotiations between Anthropic and the Pentagon over acceptable restrictions.

OpenAI published its account the next day. In its agreement statement, the company said the military needs advanced AI as potential adversaries integrate similar technologies into their systems.

OpenAI also presented several safeguards. It said its technology could not support mass domestic surveillance. It required human responsibility for decisions involving lethal force, including autonomous weapons. The company further said OpenAI personnel would participate in deployment and monitor how the systems operated.

Those commitments sound similar to the concerns Anthropic raised. Anthropic resisted demands to make Claude available for all lawful military purposes without its requested contractual restrictions. The Pentagon subsequently designated the company a supply-chain risk, while the administration directed federal agencies to end their use of its products.

The phrase “all lawful purposes” appears comprehensive, but legality is not a complete safety specification. Laws can change, differ across jurisdictions, or leave operational questions unresolved. Government lawyers and technology providers can also interpret the same authority differently.

OpenAI says its terms add protections beyond existing law. Critics have questioned whether those terms create enforceable prohibitions or primarily restate current government policy. The complete operative contract would help resolve that issue, but it has not been publicly available in an independently reviewable form.

The minimal-refusal language sharpens this uncertainty. If the final agreement removed it, OpenAI successfully resisted at least one broad government demand. If similar requirements survived under different wording, public descriptions might not capture the operational standard.

The government’s position creates another tension. Officials want commercial AI systems to support missions that consumer products cannot address. They also resist private vendors exercising open-ended control over military policy.

That concern is not frivolous. An unelected company should not determine national security policy simply by changing a model’s usage rules. Military authority belongs within a legal and democratic chain of command.

However, vendors still control systems with known limitations. Models can generate false information, follow adversarial instructions, expose sensitive data, or produce persuasive answers unsupported by evidence. A procurement clause cannot eliminate those technical risks.

The solution requires more than choosing whether OpenAI or the Pentagon gets the final word. Contracts need precise prohibited uses, measurable safeguards, logging requirements, escalation procedures, and consequences for violations.

Independent oversight matters because both parties have incentives to emphasize compatibility. The Pentagon wants capable systems with fewer operational barriers. OpenAI wants access to an influential customer while maintaining its public safety position.

The Anthropic dispute illustrates what happens when those incentives diverge. Anthropic’s refusal to accept the government’s preferred terms led to political retaliation and operational exclusion. That outcome places pressure on every competing provider to appear more accommodating.

OpenAI entered the classified environment during that conflict. The company says it retained stronger safeguards, not weaker ones. The disputed P00003 record now makes documentary evidence essential to evaluating that claim.

Classified Deployment Raises Risks Beyond Model Refusals

Even a carefully bounded model can create serious risks when secrecy limits outside testing, incident reporting, and public accountability.

Classified networks prevent sensitive intelligence from reaching unauthorized users. They also prevent researchers, journalists, and the broader public from examining how a deployed model behaves.

That secrecy is necessary for many military operations. It nonetheless creates a verification gap. Outside observers cannot run tests, compare refusal behavior, inspect logs, or determine whether safeguards changed after deployment.

The government can perform internal evaluations, but those reviews must answer more than whether the model completes tasks. They should measure hallucinations, automation bias, data leakage, prompt injection, and performance under adversarial conditions.

Hallucination occurs when a model produces unsupported or false content in a confident form. In an ordinary office workflow, a user might catch a fabricated citation. In a fast-moving operation, a plausible but incorrect synthesis can shape a consequential decision.

Automation bias creates a separate problem. People often place excessive trust in machine-generated recommendations, especially when the system processes more information than they can review. A low-refusal model can make that tendency worse by producing an answer even when evidence is incomplete.

The model may also encounter classified material that contains malicious instructions. Prompt injection is an attack that hides commands inside data the system has been asked to analyze. A compromised document could tell the model to reveal information, ignore policy, or manipulate its conclusions.

These failure modes do not require malicious government intent. They emerge from the technology’s limitations and the complexity of military information systems.

OpenAI says its deployment uses a cloud-based environment rather than placing models directly on weapons platforms. That separation can reduce immediate action risks. It does not remove the model’s influence on intelligence analysis, planning, logistics, or targeting support.

The Pentagon has described AI as a way to augment decision-making in complex operational environments. By May, the department had announced classified-network arrangements with Google, Microsoft, Amazon Web Services, Nvidia, OpenAI, Reflection, and SpaceX. The classified AI expansion shows that the policy question extends far beyond one provider.

Multiple vendors can reduce dependence on a single company. They can also create inconsistent safeguards, overlapping accountability, and pressure to match the least restrictive competitor.

A model that refuses more often might lose evaluations focused on task completion. A model that answers more freely might appear operationally superior until a serious failure occurs. Procurement metrics can therefore shape safety behavior even without an explicit demand to remove guardrails.

The public debate should not treat refusals as inherently good. Excessive refusals can make a system unreliable and encourage users to seek less controlled alternatives. The relevant question is whether refusals occur at the correct boundary.

Answering that question requires scenario-based tests. Evaluators should examine whether models reject unlawful surveillance, unsupported target identification, autonomous lethal actions, and attempts to bypass authorization. They should also verify that models can complete legitimate intelligence and defensive tasks.

Results can remain classified where necessary, but oversight bodies need access to them. Inspectors general, congressional committees, and appropriately cleared independent experts can assess controls without publishing operational secrets.

The OpenAI Pentagon contract controversy exposes what happens when neither the contract nor the evaluation framework can be inspected. The public receives assurances from the supplier and the customer, but lacks the evidence needed to test them.

The Documentation Gap Is Now the Central Risk

The strongest conclusion is not that OpenAI removed its safeguards, but that the government’s recordkeeping has made a consequential agreement impossible to audit.

The released documents contain a clause that both parties say they rejected. The FOIA request sought final records and excluded drafts. A government lawyer initially treated P00003 as final, then withdrew that conclusion.

Each fact can have an innocent administrative explanation. Together, they undermine confidence in the official contract history.

Version control should be basic in a procurement involving classified frontier AI. Reviewers need to know who proposed a term, when it changed, who approved the revision, and which document governs deployment.

The February timeline adds complexity. A separate document reportedly indicates that OpenAI accepted an expanded P00003 version on February 6. On February 27, the parties completed the classified-network arrangement.

The relationship between those agreements remains unclear. The February 27 document might supersede the earlier modification. It might supplement it. It might also govern a distinct deployment while leaving part of the prototype agreement active.

OpenAI’s denial is specific: the company says the executed contract does not require minimal refusal rates. That assertion deserves to be recorded plainly. It should not be stretched into proof that the released document was never executed or that no comparable performance requirement exists elsewhere.

The Pentagon’s denial is similarly limited. Saying the phrase appears in no current contract does not establish whether it once appeared in an executed modification. A term can disappear from an active agreement after amendment or replacement.

The government can resolve much of the dispute without exposing classified operations. It could release the relevant signature pages, amendment chronology, supersession language, and unclassified portions of the operative requirements.

OpenAI could also publish the exact contractual text supporting its public safeguards, subject to necessary redactions. The company already disclosed its interpretation of the agreement, so confirming the operative clauses would add substance to that account.

Critics also need to avoid overstatement. “Minimal refusal rates” does not establish that a model controls weapons, conducts surveillance, or ignores every restriction. The document describes a desired characteristic, not evidence of a specific prohibited deployment.

Nor does the phrase reveal the actual refusal rate. No verified percentage, benchmark, or comparison with consumer ChatGPT appears in the available reporting. Claims that the military received a completely unrestricted model therefore go beyond the evidence.

The uncertainty itself carries consequences. Developers working on safety systems need confidence that deployment commitments survive procurement pressure. Enterprise buyers need accurate documentation when different model configurations operate under different policies.

Knowledge workers also need to understand that a familiar model name does not guarantee familiar behavior. A military configuration, enterprise deployment, and public chatbot can use different instructions, tools, permissions, and refusal thresholds.

Maintaining a searchable record of policies, evaluations, and revisions is central to responsible AI governance. A well-managed knowledge base cannot substitute for public oversight, but the same principle applies: consequential decisions require traceable sources and version history.

The dispute should therefore be treated as a documentation failure until stronger evidence establishes more. That framing remains cautious about the underlying allegation while recognizing that contract ambiguity is unacceptable at this level of risk.

What to Watch After the Minimal-Refusal Disclosure

Three signals will determine whether this episode becomes a correctable records dispute or evidence of a deeper accountability problem.

The first signal is the release of the actual operative contract chain. The Pentagon should identify whether P00003 was signed, replaced, or produced accidentally. It should also show how the February 6 modification relates to the February 27 classified deployment agreement.

A clean chronology would support the parties’ explanation if it demonstrates that the disputed clause remained only in a rejected draft. Continued refusal or contradictory answers would strengthen concerns that the public description omits relevant terms.

The second signal is a concrete evaluation framework for military AI refusals. Officials do not need to disclose sensitive prompts or intelligence data. They can still publish categories of prohibited use, testing methods, reporting obligations, and the authority responsible for investigating failures.

Such a framework should distinguish false refusals from necessary refusals. It should also test hallucinations, unauthorized tool use, prompt injection, and human oversight under operational time pressure.

Publication of meaningful evaluation standards would strengthen OpenAI’s argument that a more useful military model can retain firm boundaries. A performance program focused only on answer rates would weaken it.

The third signal is how the Pentagon treats safeguards across competing vendors. Google, Microsoft, Amazon, Nvidia, Reflection, SpaceX, OpenAI, and other contractors should not operate under materially different rules for surveillance or lethal decisions without a documented reason.

The Anthropic confrontation makes this comparison especially important. Before its breakdown, Pentagon negotiations reportedly focused on whether the company would permit broader military use. OpenAI then announced an agreement preserving restrictions that appeared similar in public descriptions.

If common safeguards emerge across providers, the episode will look more like a difficult negotiation followed by policy convergence. If vendors receive different terms based on their willingness to reduce refusals, competitive pressure could steadily lower the safety floor.

The OpenAI Pentagon contract story is ultimately about who defines that floor and how anyone verifies it. Neither blanket refusal nor unrestricted compliance is an adequate standard for military AI.

Readers should watch for documents, measurable controls, and consistent vendor rules rather than another round of assurances. Until those appear, the “minimal refusal rates” clause remains disputed, and the system reportedly delivered under it remains unverified. The next disclosure should answer a simple question: which safeguards bind the deployed model when a lawful military request still creates an unacceptable risk?

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page