AI Labs' Pentagon Contracts Revealed by FOIA Suit
More than 400 pages of Department of Defense contract paperwork with OpenAI, Anthropic, Google and xAI became public on 8 September, obtained by The Intercept through Freedom of Information Act litigation. The deals were signed in July 2025, each worth up to $200 million, and each committing the ...
AI Labs' Pentagon Contracts Revealed by FOIA Suit
More than 400 pages of Department of Defense contract paperwork with OpenAI, Anthropic, Google and xAI became public on 8 September, obtained by The Intercept through Freedom of Information Act litigation. The deals were signed in July 2025, each worth up to $200 million, and each committing the lab to prototype AI tools that "improve military advantage, military utility, or enhance military decision making."
The contracts themselves were public knowledge. The Defense Department announced the four awards at the time. What was not public was the paperwork underneath, and that is where the useful detail lives.
What the documents add
Three things stand out for anyone whose work touches these vendors.
The scope is broader than "productivity tools." The prototypes named in the paperwork span warfighting, automated decision-making, logistics and military intelligence, and The Intercept reports they became the basis for AI tooling now running on DoD classified networks. That is a longer distance from "we sell a chat API" than the original announcements implied.
The Pentagon asked for low refusal rates, and the story is contested. Files released to The Intercept show the Pentagon sought a custom tool with "minimal refusal rates" against its commands. OpenAI has said the phrase never made it into the final signed version. Both things can be true: a request in a draft is not a term in a contract. Treat the drafting history as evidence of what the customer wanted, not of what the vendor agreed to.
Anthropic's classified-network expansion reportedly collapsed over usage limits. Per the reporting, Anthropic wanted contractual prohibitions on autonomous weapons and domestic surveillance, the DoD declined to include them, and the expansion did not proceed. That is a vendor's usage policy meeting a customer with leverage, in public, for once.
Why this matters if you are not building weapons
Most readers here are building apps, not targeting systems. The relevance is not the subject matter. It is what the documents show about how model behaviour gets negotiated.
Every frontier model you call has a refusal boundary. You have probably hit it: a request that looks obviously fine to you, declined for reasons the model will not fully explain. We have written about why models refuse safe questions and why they refuse some requests at all. The usual framing is that the boundary is a fixed property of the model.
These documents show it is a negotiated one. A large enough customer can ask for a version with the boundary moved, and the negotiation over where it sits is a commercial conversation with contract language attached. The boundary you experience through the public API is one setting among several that exist.
That has two practical consequences:
Usage policies are product surfaces, not just legal boilerplate. When a vendor holds a line on prohibited uses under commercial pressure, that is a meaningful signal about how it will treat your own edge cases. When it does not hold, that is also a signal.
"The model won't do that" is a claim about a configuration, not a law of nature. If your product's safety story depends on the model refusing something, the refusal is not your control. Your own checks are.
Reading contract disclosures without overcorrecting
FOIA releases invite two opposite errors. One is treating a draft clause as a signed commitment. The other is dismissing the whole disclosure because one detail is disputed.
A workable middle:
What you are reading | How much weight it carries |
|---|---|
Executed contract terms | High. This is what both parties agreed to. |
Draft language and requirement statements | Medium. Shows customer intent, not vendor agreement. |
Amendments and modifications | High, and often the most informative part. |
A single quoted phrase in coverage | Low on its own. Check whether it survived into the final document. |
Vendor statement responding to coverage | Medium. Note precisely what it denies and what it leaves unaddressed. |
Applied here: the $200 million ceilings and the July 2025 signing dates are contract facts. The "minimal refusal rates" phrasing is a requirement statement that OpenAI says did not survive. Both belong in an accurate summary, with the difference marked.
What to do with this
Nothing urgent. But if you are choosing a model vendor for something where refusal behaviour or data handling matters, this disclosure is a rare look at how these companies behave when a customer with real leverage pushes. That is more informative than any published policy page.
If you are building anything customer-facing on top of these APIs, the durable lesson is the one in how to vet an AI vendor: read what a vendor has actually agreed to, not what it says it believes. And keep tracking this properly rather than by headline, which is the whole point of having a way to keep up with AI news that does not depend on whoever posts loudest.
FAQ
Are these new contracts? No. The four awards were announced publicly in July 2025. What is new is the underlying paperwork, over 400 pages of it, released through The Intercept's FOIA litigation with help from Legal Advocates for Safe Science and Technology.
Did OpenAI agree to build a model with minimal refusal rates? OpenAI says the phrase did not appear in the final signed version. The documents show the Pentagon sought it. Those are compatible claims, and the distinction between requested and agreed language matters here.
Why did Anthropic's classified-network expansion not proceed? According to the reporting, Anthropic sought contractual prohibitions on the use of its technology for autonomous weapons systems and domestic surveillance, and the Defense Department declined to include them.
Does any of this change the public APIs I use? No. These are separate government contracts with their own deployments. The public API behaviour and terms are unchanged by this disclosure.
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


