The Pentagon Wants an AI That Doesn't Say No
A leaked contract shows the military asked OpenAI for AI with "minimal refusal rates." Then everyone denied it, then walked the denial back.
Ask ChatGPT to help you rank targets for a drone strike and it will refuse. That is by design. It is also, apparently, a problem for the Pentagon.
Documents released through a Freedom of Information Act lawsuit show the Department of Defense asked OpenAI for a version of its AI that refuses as little as possible. Then everyone involved spent a week disagreeing, on the record, about whether that request is even real.
What Actually Happened
In 2025, OpenAI, Google, xAI, and Anthropic all agreed to build military prototypes for the Pentagon. The deals cover logistics, intelligence work, and what the contracts call general "warfighting." OpenAI's piece was worth up to 200 million dollars over two years.
The Intercept sued for records on these contracts. What came back included an updated version of OpenAI's deal, labeled "P00003." Buried in a section describing what OpenAI owed the Pentagon was a description of "OpenAI Mission Models," AI built for national security use and, in the document's own words, designed to have "minimal refusal rates."
OpenAI and the Pentagon both deny that language made it into the final signed contract. A Department of Justice lawyer first confirmed to The Intercept that the document was the executed version. Hours later, after The Intercept contacted OpenAI for comment, the same lawyer walked that back and said the department needed more time to check. A Pentagon spokesperson later said the phrase does not appear in any active contract with OpenAI. Nobody has produced the version they say is correct.
Why "Refusal" Is the Whole Point
Refusals are not a bug in these models. They are one of the only safety features an ordinary person can actually see working. Ask ChatGPT to help prioritize airstrike targets today and it tells you no. Ask it to help build a weapon of mass destruction and it tells you no. Those refusals exist because the companies decided some requests should not get an answer, regardless of who is asking or why.
A model with "minimal refusal rates" is, by definition, a model with fewer of those no's. Heidy Khlaaf, a former OpenAI safety engineer now at the AI Now Institute, put it plainly to The Intercept: "Minimal refusal is likely referring to little or no safeguards on the model being used."
Nobody involved has said what the military actually wants to ask an AI that it cannot ask today. That detail is missing from every document released so far. Left to fill in the blank ourselves, most of us will not land on something reassuring.
Who Actually Sets the Rules of War Now
This is not the first military AI deal to blow up in public this year. Anthropic's own Pentagon agreement collapsed earlier in 2026 after the company refused to drop contractual limits on autonomous weapons and domestic surveillance. The Trump administration responded by formally labeling Anthropic a supply chain risk, a designation a federal judge overturned only last month.
OpenAI took the opposite path. It signed a deal in February covering its use across the military's classified networks and says it secured red lines against autonomous killings and spying on Americans. But the actual deployment contract is redacted in full. As written, it permits any use the government later decides is legal, which is a much lower bar than a red line.
Khlaaf's real worry is bigger than one clause in one contract. It is that a handful of private companies are now the ones deciding what a country can and cannot do in war, a call that used to belong to states and international law, not shareholders. Whether an AI model refuses to help plan a strike is, right now, a business decision made in a conference room. It is not a law made by anyone accountable to voters.
Over to You
Strip away the contract language and this comes down to one question: should a company's safety team get to decide what an AI refuses to do in a war, or should that be written into law instead? What do you think?