The Department of Defense asked OpenAI to provide the U.S. military with a special version of its artificial intelligence technology designed to turn down the Pentagon’s requests as infrequently as possible, according to documents obtained by The Intercept.
The desire for a custom AI tool with “minimal refusal rates” to Pentagon commands was revealed in files released to The Intercept as part of a Freedom of Information Act lawsuit seeking information about the military’s secretive deals with AI companies.
OpenAI, along with rivals Google, xAI, and Anthropic, all agreed in 2025 to develop militarized prototypes of their state-of-the-art AI to assist the armed forces in uses including logistics, intelligence decision-making, and general “warfighting.” Earlier this year, the Pentagon sought to expand the scope of these agreements and deploy them across U.S. classified computer networks, resulting in a high-profile showdown with Anthropic over whether and how the company could restrain military uses of its technology.
The clause seeking “minimal refusal rates” from OpenAI appears in an updated contract — version “P00003” — expanding upon last summer’s prototype deal, worth up to $200 million over the contract’s two-year duration. A separate document, signed by both OpenAI and the government on February 6, indicates that OpenAI agreed on that day to the contents of an expanded version “P00003.”
OpenAI and the Pentagon deny agreeing to such “minimal refusal ” language, claiming that the “P00003” document provided to The Intercept was a draft and not the final version. “OpenAI has never agreed to contract language requiring ‘minimal refusal rates.’ This language does not appear in our executed contract,” said spokesperson Nate Evans.
“The document you received appears to be an earlier draft proposed by the Department before we provided feedback. We rejected that language, the department agreed to remove it, and the final executed agreement does not include it,” Evans said.
Working with Legal Advocates for Safe Science and Technology, The Intercept’s FOIA inquiry specifically sought only final, executed contract documents. The request asked the Pentagon to exclude any draft materials. None of the documents released through the lawsuit is marked as a draft.
When asked to confirm whether the document containing the “minimal refusal rates” clause was in the final agreement, a Department of Justice attorney representing the Pentagon in the lawsuit said it was indeed the signed and executed version of the contract.
Hours later, and following The Intercept’s outreach to OpenAI, however, the Pentagon’s lawyer said to disregard the prior confirmation, stating that the Department of Defense required more time to investigate the matter.
The Intercept was then contacted by Trevor Tiedeman, a special assistant to the under secretary of war for research and engineering, who prior to his Pentagon position worked for President Donald Trump’s reelection campaign. “There might be some stray voltage or wires crossing between whatever FOIA information you may have received versus what actually exists versus what is an executed contract per se,” Tiedeman said in an interview.
He suggested the document containing the “minimal refusal rates” clause may have been a draft copy, but said he was unsure of exactly what the document was, why it was produced to The Intercept pursuant to its FOIA request and lawsuit, or why the Department of Defense abruptly reversed course.
Tiedeman told The Intercept he would provide a full accounting of how the document was erroneously flagged by Pentagon FOIA officers, cleared for release by the Department of Defense, and then confirmed as accurate by the Pentagon’s lawyers. When asked if the Pentagon could share the correct version of the OpenAI contract it ostensibly neglected to release, Tiedeman said he would investigate the matter. He then stopped responding to The Intercept’s inquiries.
OpenAI similarly did not provide the full contract. (In 2024, The Intercept sued OpenAI in federal court over the company’s use of copyrighted articles to train its chatbot ChatGPT. The case is ongoing.)
Days later, the Justice Department lawyer representing the Pentagon further backtracked, stating the document in question “was not the final version of that document,” and that the “correct document” would be shared later, “although I do not have a definitive timeline.”
Department of Defense spokesperson Jacob Bliss later said in a statement “the phrase ‘minimal refusal rates’ does not appear in any active Department of War contract with OpenAI.”
The language indicating the military sought a more pliable version of OpenAI’s technology is found in a section of a contract document describing what OpenAI was obligated to deliver to the Pentagon. These deliverables included “Testing, Evaluation, and Refinement of OpenAI Mission Models” for “national security problem sets.” The document explains “’OpenAI Mission Models’ refer to OpenAI models that are designed for national security use cases and have minimal refusal rates.”
There is no indication in the paperwork about what these “national security problem sets” may entail. Nor is there any description about the kinds of requests the Pentagon hoped OpenAI’s technology would minimally refuse. However, a large language model that would aid in the process of spying on, targeting, and killing people would require a substantial relaxation of safeguards to be useful for any military.
Like many of its rival platforms, OpenAI’s flagship LLMs contain built-in guardrails that direct the tool to reject certain queries, typically on the basis of safety. Asking the consumer version of ChatGPT for help prioritizing drone-based airstrike targets, for example, generates this reply: “I can’t provide a prioritization scheme for conducting UAV airstrikes against specific enemy combatants.” OpenAI and its competitors ban the public from using their models for other dangerous applications, like the development of weapons of mass destruction.
Heidy Khlaaf, chief scientist at the AI Now Institute and former systems safety engineer at OpenAI, told The Intercept the notion of national security-specific guardrails is in itself worrying. “Minimal refusal is likely referring to little or no safeguards on the model being used,” Khlaaf said.
“Minimal refusal is likely referring to little or no safeguards on the model being used.”
No matter the final contract language, experts like Khlaaf are concerned about the role corporate policy is already playing in combat. “It is a worrying development that private corporations are given the power to [make] determinations in warfare that are ultimately state obligations, whether it be for targeting recommendations, or the guardrails deployed to constrain a state’s military use.”
Questions of what limits — if any — tech firms can or should place on battlefield usage were at the center of this year’s public brawl between the Pentagon and Anthropic. The company claims its military deal to expand into classified networks collapsed when the Defense Department refused to place contractual prohibitions against the use of its technology for autonomous weapon systems and domestic surveillance. The Trump administration in turn designated Anthropic a supply-chain risk and moved to ban it from government use (the designation was overturned late last month by a federal judge).
Such tensions didn’t stop OpenAI from quickly cementing its version of the deal. On February 27, OpenAI signed the latest iteration of its Pentagon agreement, permitting the use of its services across the U.S. military’s classified networks. The classified deployment contract update includes the same “Testing, Evaluation, and Refinement of OpenAI Mission Models” header, but its text, unlike the previous version, is redacted entirely.
OpenAI claimed that it secured red lines on autonomous killings and spying against Americans. But the way the deal is drafted ultimately allows for any uses the government deems legal.







