Skip to content

Leadership1 publisher3 min readPublished

Pentagon writes "minimal refusal rates" into its OpenAI agreement

Vox, citing The Intercept, says the agreement OpenAI signed with the Pentagon asks for national security models with minimal refusal rates, a standard Anthropic declined at the cost of a major government deal.

The Board Room · Leadership desk

Photograph accompanying Pentagon writes "minimal refusal rates" into its OpenAI agreement
Photo: theintercept.com

What happened

  • The Pentagon pressed AI companies to loosen limits on how their technology may be used in war, including how much human control must remain over autonomous weapons.
  • The resulting agreement specifies OpenAI models designed for national security use cases that have minimal refusal rates, as reported by The Intercept.
  • The Defense Department's own Law of War Manual obliges every service member to comply with the law of war in good faith and to refuse clearly illegal orders.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • constraint A supplier's limits on wartime use now have a revenue figure attached to them, so the safety policy and the sales plan get decided by the same people at the same meeting.
  • exposure Criminal liability for an unlawful order still attaches to the service member and to the commander. A model that rarely objects removes a check without moving that liability.
  • precedent Since a model's refusals enforce its terms of service, a buyer with enough leverage can now ask for those terms to be rewritten as a condition of the purchase.
  • contradiction The government's only on-record confirmation of the refusal-rate language came from a Justice Department lawyer and was withdrawn a few hours later, per The Intercept. That leaves a retracted statement as the basis for anyone calling it settled policy.

A refusal rate is a property you can measure on a deployed model. In this case it is also contract language. The phrase The Intercept reported is "OpenAI models that are designed for national security use cases and have minimal refusal rates" [3]. Vox's account of the negotiations rests on that reporting [13]. The reporting does not describe a threshold, a test set, or who decides which refusals are the ones to remove.

Both kinds of refusal land in the same number, and that is what makes the term slippery. Commercial models decline lawful, mundane requests all the time, and an analyst who cannot get an image annotated has a tooling problem. That is a false-positive rate. One refusal enforces a policy boundary; the other is a bad classifier. Vox draws the distinction that matters for the first kind, noting that a chatbot "refuses requests that violate its terms of service" [11].

For people, the law runs the other way. The Defense Department's own Law of War Manual says each member of the armed services has a duty to "(1) comply with the law of war in good faith; and (2) refuse to comply with clearly illegal orders to commit violations of the law of war" [5]. Under US domestic, military and international law, soldiers are obligated to follow lawful orders only, and are required to refuse unlawful ones [7]. Obeying an illegal order can expose the service member and the commander to criminal liability [6].

That duty exists because the alternative was tested in court. At Nuremberg, Nazi defendants argued they were not liable for Holocaust crimes because they were following their superiors' orders, and Rudolf Hoess, the commander at Auschwitz, said: "In Germany it was understood that if something went wrong, then the man who gave the orders was responsible. So I didn't think that I would ever have to answer for it myself." [9] The tribunal rejected those defenses and held that obedience has limits, particularly where a wartime act would be clearly illegal to the subordinate or to any person of "ordinary sense and understanding" [10]. The duty to disobey has roots in early British and American common law, and took its international form after those trials [8].

The procurement question here is narrower than the moral one. A usage policy that can be loosened for one customer is a term, and the vendor that declines to loosen it pays for the position in revenue: Anthropic said no and lost a major government deal, and OpenAI embraced the more flexible standard [2]. Enterprise buyers who have been told a supplier's guardrails are non-negotiable now have a data point about what negotiation looks like.

Where the duty sits has not changed: it is on the person holding the order [6]. Vox argues that by introducing technologies with a limited ability to challenge commands, the military may be making it harder to stop war crimes before they are committed [12].

What to watch

  • Whether the Pentagon or the Justice Department restates the refusal-rate language on the record after the lawyer's retraction.
  • Whether OpenAI publishes how a refusal rate is measured for national security deployments, and which refusals it keeps.
  • Whether Anthropic's usage policy holds unchanged the next time a defence solicitation carries similar language.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories