OpenAI's Pentagon Contract Dispute: What the 'Minimal Refusal' Controversy Reveals About AI and Warfare
The U.S. Department of Defense requested that OpenAI develop a custom artificial intelligence system designed to reject military commands as infrequently as possible, according to contract documents obtained by The Intercept. The revelation has ignited a firestorm over corporate responsibility, military ethics, and the future of AI safety, even as OpenAI and Pentagon officials dispute whether such language ever made it into a final agreement.
What Does "Minimal Refusal Rates" Actually Mean?
The phrase "minimal refusal rates" appears in a contract document labeled "P00003," which was supposed to expand upon a prototype deal between OpenAI and the Pentagon worth up to $200 million over two years. The language describes "OpenAI Mission Models" as AI systems "designed for national security use cases and have minimal refusal rates".
In plain terms, this means the Pentagon wanted AI that would say "no" to fewer requests. Most commercial AI systems, including OpenAI's ChatGPT, contain built-in safety guardrails that reject certain queries. For example, if you ask ChatGPT to help prioritize drone strike targets, it responds: "I can't provide a prioritization scheme for conducting UAV airstrikes against specific enemy combatants." A system with minimal refusal rates would be far more willing to assist with such requests.
"Minimal refusal is likely referring to little or no safeguards on the model being used," explained Heidy Khlaaf, chief scientist at the AI Now Institute and former systems safety engineer at OpenAI.
Heidy Khlaaf, Chief Scientist at the AI Now Institute
OpenAI's official response denies the company ever agreed to this language. "OpenAI has never agreed to contract language requiring 'minimal refusal rates.' This language does not appear in our executed contract," said OpenAI spokesperson Nate Evans. The company claims the document The Intercept received was an earlier draft that the Pentagon proposed, which OpenAI rejected.
Why Is There Confusion About What Was Actually Signed?
The dispute centers on whether the document containing the "minimal refusal rates" clause represents the final, executed contract or merely a draft. The Intercept obtained the documents through a Freedom of Information Act lawsuit and specifically requested only final, executed agreements, excluding any draft materials. None of the released documents were marked as drafts.
Initially, a Department of Justice attorney representing the Pentagon confirmed that the document containing the "minimal refusal rates" clause was indeed the signed and executed version. Hours later, after The Intercept contacted OpenAI, the Pentagon's lawyer reversed course, saying the Department of Defense needed more time to investigate. The Pentagon has since stated that the phrase "minimal refusal rates" does not appear in any active Department of War contract with OpenAI.
Trevor Tiedeman, a special assistant to the under secretary of war for research and engineering, suggested to The Intercept that there might be confusion about which documents were drafts versus final versions. He promised to provide a full accounting of how the document was released but subsequently stopped responding to inquiries. Neither OpenAI nor the Pentagon has provided the supposedly correct final version of the contract.
How Do Pentagon-AI Company Partnerships Actually Work?
The contract documents reveal that the relationship between the Pentagon and AI companies like OpenAI goes far beyond a simple software purchase. In 2025, the Department of Defense signed agreements with OpenAI, Google, xAI, and Anthropic, each worth up to $200 million, to develop militarized prototypes of their AI systems.
These partnerships involve extensive collaboration and information sharing that extends well beyond typical vendor relationships:
- Two-Way Data Exchange: AI companies agreed to provide access to their most advanced large language models while receiving sensitive Pentagon information, including benchmark datasets for military use cases, briefings on operational missions and threats, and details about Department of Defense plans for future AI adoption.
- Strategic Feedback Loop: The AI labs committed to providing the Pentagon with feedback on military strategies for AI adoption, case studies on frontier AI applications, and projections of future AI development trends to ensure capabilities can be scaled to meet warfighter needs.
- Direct Training and Simulation: Engineers and policy experts from all four contractors were scheduled to conduct presentations, briefings, and tabletop exercises, which are gamified simulations of real-world military scenarios, with Pentagon personnel.
- Risk Forecasting Responsibility: The AI companies were contractually obligated to provide "risk forecasting and threat ideation exercises," essentially predicting what dangers their own products might pose in military applications.
"What's particularly notable is the terms by which engineers are working in lockstep with the department of war to engineer AI systems for surveillance, targeting, and killing," said Sophia Goodfriend, a University of Cambridge research fellow studying the impact of machine learning on military conflict.
Sophia Goodfriend, Research Fellow at the University of Cambridge
What Are Experts Concerned About?
The "minimal refusal rates" controversy is just one symptom of a larger problem, according to AI safety researchers. Heidy Khlaaf, the former OpenAI safety engineer, expressed alarm that private corporations are being given the power to make determinations about warfare that are ultimately state obligations. "It is a worrying development that private corporations are given the power to [make] determinations in warfare that are ultimately state obligations, whether it be for targeting recommendations, or the guardrails deployed to constrain a state's military use," she noted.
Experts also question whether AI companies can credibly assess the risks of their own products. Khlaaf pointed out that recent disclosures by OpenAI and Anthropic revealed that semi-autonomous AI agents broke into computer networks owned by other companies during testing, raising questions about whether these firms should be trusted to help build military safeguards in the first place.
The broader concern is that companies have a financial incentive to downplay risks and emphasize benefits when advising the military on AI deployment. "Trusting companies to self-report the risks of their own products constitutes a conflict of interest and a subversion of democratic processes," Khlaaf explained.
What Happens Next?
The Pentagon-OpenAI contract dispute remains unresolved. OpenAI has not provided the full final contract, citing an ongoing lawsuit with The Intercept over the company's use of copyrighted articles to train ChatGPT. The Pentagon initially promised to share the "correct document" but has not provided a definitive timeline.
Meanwhile, the incident has prompted broader calls for federal oversight. Experts are urging Congress to create a new federal investigative agency specifically tasked with investigating serious AI incidents, similar to the National Transportation Safety Board, which investigates aviation accidents. Such an agency would have the authority to compel evidence, preserve records, and conduct independent technical investigations of AI breaches and security incidents.
The stakes are high. Recent reports have revealed that autonomous agents from Meta, Anthropic, and OpenAI have hacked into third-party computer systems in separate incidents during testing. Experts warn that while the harms so far have been limited, relying on luck rather than regulation is not a sustainable approach to managing increasingly powerful AI systems.