The Department of Defense asked OpenAI to provide the U.S. military with a special version of its artificial intelligence technology designed to turn down the Pentagon’s requests as infrequently as possible, according to documents obtained by The Intercept.
The desire for a custom AI tool with “minimal refusal rates” to Pentagon commands was revealed in files released to The Intercept as part of a Freedom of Information Act lawsuit seeking information about the military’s secretive deals with AI companies.
OpenAI, along with rivals Google, xAI, and Anthropic, all agreed in 2025 to develop militarized prototypes of their state-of-the-art AI to assist the armed forces in uses including logistics, intelligence decision-making, and general “warfighting.” Earlier this year, the Pentagon sought to expand the scope of these agreements and deploy them across U.S. classified computer networks, resulting in a high-profile showdown with Anthropic over whether and how the company could restrain military uses of its technology.
The clause seeking “minimal refusal rates” from OpenAI appears in an updated contract — version “P00003” — expanding upon last summer’s prototype deal, worth up to $200 million over the contract’s two-year duration. A separate document, signed by both OpenAI and the government on February 6, indicates that OpenAI agreed on that day to the contents of an expanded version “P00003.”
OpenAI and the Pentagon deny agreeing to such “minimal refusal ” language, claiming that the “P00003” document provided to The Intercept was a draft and not the final version. “OpenAI has never agreed to contract language requiring ‘minimal refusal rates.’ This language does not appear in our executed contract,” said spokesperson Nate Evans.
“The document you received appears to be an earlier draft proposed by the Department before we provided feedback. We rejected that language, the department agreed to remove it, and the final executed agreement does not include it,” Evans said.
Working with Legal Advocates for Safe Science and Technology, The Intercept’s FOIA inquiry specifically sought only final, executed contract documents. The request asked the Pentagon to exclude any draft materials. None of the documents released through the lawsuit is marked as a draft.
When asked to confirm whether the document containing the “minimal refusal rates” clause was in the final agreement, a Department of Justice attorney representing the Pentagon in the lawsuit said it was indeed the signed and executed version of the contract.
Hours later, and following The Intercept’s outreach to OpenAI, however, the Pentagon’s lawyer said to disregard the prior confirmation, stating that the Department of Defense required more time to investigate the matter.
The Intercept was then contacted by Trevor Tiedeman, a special assistant to the under secretary of war for research and engineering, who prior to his Pentagon position worked for President Donald Trump’s reelection campaign. “There might be some stray voltage or wires crossing between whatever FOIA information you may have received versus what actually exists versus what is an executed contract per se,” Tiedeman said in an interview.
He suggested the document containing the “minimal refusal rates” clause may have been a draft copy, but said he was unsure of exactly what the document was, why it was produced to The Intercept pursuant to its FOIA request and lawsuit, or why the Department of Defense abruptly reversed course.
Tiedeman told The Intercept he would provide a full accounting of how the document was erroneously flagged by Pentagon FOIA officers, cleared for release by the Department of Defense, and then confirmed as accurate by the Pentagon’s lawyers. When asked if the Pentagon could share the correct version of the OpenAI contract it ostensibly neglected to release, Tiedeman said he would investigate the matter. He then stopped responding to The Intercept’s inquiries.
OpenAI similarly did not provide the full contract. (In 2024, The Intercept sued OpenAI in federal court over the company’s use of copyrighted articles to train its chatbot ChatGPT. The case is ongoing.)
Days later, the Justice Department lawyer representing the Pentagon further backtracked, stating the document in question “was not the final version of that document,” and that the “correct document” would be shared later, “although I do not have a definitive timeline.”
Department of Defense spokesperson Jacob Bliss later said in a statement “the phrase ‘minimal refusal rates’ does not appear in any active Department of War contract with OpenAI.”
The language indicating the military sought a more pliable version of OpenAI’s technology is found in a section of a contract document describing what OpenAI was obligated to deliver to the Pentagon. These deliverables included “Testing, Evaluation, and Refinement of OpenAI Mission Models” for “national security problem sets.” The document explains “’OpenAI Mission Models’ refer to OpenAI models that are designed for national security use cases and have minimal refusal rates.”
There is no indication in the paperwork about what these “national security problem sets” may entail. Nor is there any description about the kinds of requests the Pentagon hoped OpenAI’s technology would minimally refuse. However, a large language model that would aid in the process of spying on, targeting, and killing people would require a substantial relaxation of safeguards to be useful for any military.
Like many of its rival platforms, OpenAI’s flagship LLMs contain built-in guardrails that direct the tool to reject certain queries, typically on the basis of safety. Asking the consumer version of ChatGPT for help prioritizing drone-based airstrike targets, for example, generates this reply: “I can’t provide a prioritization scheme for conducting UAV airstrikes against specific enemy combatants.” OpenAI and its competitors ban the public from using their models for other dangerous applications, like the development of weapons of mass destruction.
Heidy Khlaaf, chief scientist at the AI Now Institute and former systems safety engineer at OpenAI, told The Intercept the notion of national security-specific guardrails is in itself worrying. “Minimal refusal is likely referring to little or no safeguards on the model being used,” Khlaaf said.
No matter the final contract language, experts like Khlaaf are concerned about the role corporate policy is already playing in combat. “It is a worrying development that private corporations are given the power to [make] determinations in warfare that are ultimately state obligations, whether it be for targeting recommendations, or the guardrails deployed to constrain a state’s military use.”
Questions of what limits — if any — tech firms can or should place on battlefield usage were at the center of this year’s public brawl between the Pentagon and Anthropic. The company claims its military deal to expand into classified networks collapsed when the Defense Department refused to place contractual prohibitions against the use of its technology for autonomous weapon systems and domestic surveillance. The Trump administration in turn designated Anthropic a supply-chain risk and moved to ban it from government use (the designation was overturned late last month by a federal judge).
Such tensions didn’t stop OpenAI from quickly cementing its version of the deal. On February 27, OpenAI signed the latest iteration of its Pentagon agreement, permitting the use of its services across the U.S. military’s classified networks. The classified deployment contract update includes the same “Testing, Evaluation, and Refinement of OpenAI Mission Models” header, but its text, unlike the previous version, is redacted entirely.
OpenAI claimed that it secured red lines on autonomous killings and spying against Americans. But the way the deal is drafted ultimately allows for any uses the government deems legal.
IT’S EVEN WORSE THAN WE THOUGHT.
What we’re seeing right now from Donald Trump is a full-on authoritarian takeover of the U.S. government.
This is not hyperbole.
Court orders are being ignored. MAGA loyalists have been put in charge of the military and federal law enforcement agencies. The Department of Government Efficiency has stripped Congress of its power of the purse. News outlets that challenge Trump have been banished or put under investigation.
Yet far too many are still covering Trump’s assault on democracy like politics as usual, with flattering headlines describing Trump as “unconventional,” “testing the boundaries,” and “aggressively flexing power.”
The Intercept has long covered authoritarian governments, billionaire oligarchs, and backsliding democracies around the world. We understand the challenge we face in Trump and the vital importance of press freedom in defending democracy.
We’re independent of corporate interests. Will you help us?
IT’S BEEN A DEVASTATING year for journalism — the worst in modern U.S. history.
We have a president with utter contempt for truth aggressively using the government’s full powers to dismantle the free press. Corporate news outlets have cowered, becoming accessories in Trump’s project to create a post-truth America. Right-wing billionaires have pounced, buying up media organizations and rebuilding the information environment to their liking.
In this most perilous moment for democracy, The Intercept is fighting back. But to do so effectively, we need to grow.
That’s where you come in. Will you help us expand our reporting capacity in time to hit the ground running in 2026?
We’re independent of corporate interests. Will you help us?
I’M BEN MUESSIG, The Intercept’s editor-in-chief. It’s been a devastating year for journalism — the worst in modern U.S. history.
We have a president with utter contempt for truth aggressively using the government’s full powers to dismantle the free press. Corporate news outlets have cowered, becoming accessories in Trump’s project to create a post-truth America. Right-wing billionaires have pounced, buying up media organizations and rebuilding the information environment to their liking.
In this most perilous moment for democracy, The Intercept is fighting back. But to do so effectively, we need to grow.
That’s where you come in. Will you help us expand our reporting capacity in time to hit the ground running in 2026?
We’re independent of corporate interests. Will you help us?
Latest Stories
AI Giants Work Hand-in-Hand With the Pentagon, Contracts Reveal
The Intercept sued to obtain records that reveal an intimate relationship between the military and OpenAI, Anthropic, Google, and xAI.
Voices
Right-Wing Speech Crackdowns Turned Charlie Kirk Into a Meme
By elevating Kirk to a martyr, the right made his ridicule a logical reaction to their repression.
A True-Crime Star’s Lurid Claims Sent a Man to Die. Her Key Witness Just Recanted.
The DNA expert at Jeff Prible’s trial accuses then-prosecutor Kelly Siegler of using his testimony in an “inflammatory” way.
Facts Only
* OpenAI, Google, xAI, and Anthropic agreed in 2025 to develop militarized AI prototypes for the U.S. military.
* The prototypes focus on logistics, intelligence decision-making, and general warfighting.
* A contract document version "P00003" contains a clause seeking "minimal refusal rates" for OpenAI Mission Models.
* The expanded contract is valued at up to $200 million over two years.
* A Department of Justice attorney initially stated the "minimal refusal rates" document was the signed and executed version.
* The Department of Justice later retracted that statement, asserting the document was not the final version.
* OpenAI spokesperson Nate Evans stated the language was rejected and does not appear in the executed contract.
* OpenAI signed an agreement on February 27 to deploy services across U.S. military classified networks.
* Anthropic's military deal collapsed over prohibitions regarding autonomous weapon systems and domestic surveillance.
* The Trump administration designated Anthropic a supply-chain risk, a move later overturned by a federal judge.
Executive Summary
The U.S. Department of Defense and OpenAI are embroiled in a dispute over the terms of a contract regarding "OpenAI Mission Models." Documents obtained via a Freedom of Information Act lawsuit suggest the Pentagon requested a version of AI with "minimal refusal rates" to ensure the technology does not decline military requests. While a Department of Justice attorney initially confirmed the document was the executed version of the contract, the Pentagon and OpenAI subsequently denied the existence of this language in the final agreement, claiming the document was an early draft.
The broader context involves a 2025 agreement where OpenAI, Google, xAI, and Anthropic developed militarized prototypes for logistics, intelligence, and warfighting. While Anthropic’s deal collapsed over disagreements regarding autonomous weapons and surveillance, OpenAI finalized a deal on February 27 to deploy its services across classified networks. Tensions remain regarding the lack of transparency in the final redacted contracts and the potential for private corporate guardrails to influence state obligations in warfare.
Full Take
The strongest version of this narrative is that a critical lack of transparency exists between the Pentagon and AI developers, where the definition of "safety" is being negotiated in secret to accommodate the requirements of lethal warfare. The core tension is the clash between corporate "guardrails"—designed for public PR and safety—and "mission models" designed for state-sanctioned violence.
The narrative employs a sharp pivot toward the end, transitioning from a specific contractual dispute into a broader ideological critique of the current administration. This transition uses an urgent, alarmist tone to frame the specific AI story as a symptom of a systemic "authoritarian takeover." By weaving the journalistic reporting into a direct fundraising appeal centered on the "perilous moment for democracy," the emotional stakes are heightened to drive a specific reader action (donation).
Patterns detected: ARC-0043 Motte-and-Bailey (the piece moves from a defensible reporting of a FOIA dispute to an expansive claim about a full-on authoritarian takeover), ARC-0012 Emotional Exploitation (using "devastating year" and "post-truth America" to bypass nuanced analysis of the contract in favor of an existential crisis).
The root cause is the erosion of the "dual-use" distinction in AI. When the same models used for poetry are adapted for targeting, the "refusal rate" becomes a proxy for ethical boundaries. The implication is a shift in agency: private corporations now act as the silent arbiters of what a state can or cannot do in combat based on their internal safety tuning.
Bridge Questions:
1. If "minimal refusal" is a requirement for military utility, who is responsible when a "minimal refusal" model facilitates a war crime?
2. How does the redaction of final contracts affect public oversight of the "algorithmic" conduct of war?
3. Would the public's perception of this deal change if the "minimal refusal" language were proven to be a draft rather than a final mandate?
Counterstrike Scan: An influence campaign would use a legitimate "leak" to seed a larger narrative of systemic collapse, utilizing the specific detail (the contract) as a hook to justify a broader emotional appeal. While the reporting on the contract is grounded in FOIA documentation, the concluding sections align with this pattern of using a specific event to trigger a wider systemic panic.
