WASHINGTON – Anthropic, Google, OpenAI and xAI each signed contracts worth up to $200m with the Department of Defence in July 2025 committing them not merely to sell software but to shape the Pentagon’s strategy for using artificial intelligence in ‘warfighting’, automated decision-making, intelligence and logistics, according to more than 400 pages of contract documents released under a Freedom of Information Act lawsuit.
The documents, obtained by The Intercept with the help of Legal Advocates for Safe Science and Technology and many of them heavily redacted, show the four companies agreed to build prototypes of AI tools to ‘improve military advantage, military utility, or enhance military decision making’ across the whole of the armed forces.
Those prototypes became the basis of the systems now running on the Pentagon’s classified networks, and the papers cast new light on the contract dispute that led to Anthropic being banned from government use earlier this year.
‘This appears to be the first time the extent of collaboration between frontier AI labs and the Pentagon is spelled out in explicit terms,’ said Sophia Goodfriend, a University of Cambridge research fellow and non-resident fellow at the Harvard Kennedy School’s Middle East Initiative who studies the impact of big data and machine learning on military conflict.
‘What’s particularly notable is the terms by which engineers are working in lockstep with the department of war to engineer AI systems for surveillance, targeting, and killing.’
The public announcements at the time gave little away. ‘We must equip our warfighters with 21st-century technology in order to defeat 21st-century threats,’ Pentagon spokesperson Sean Parnell said.
Google said its ‘advanced AI solutions’ would help the department ‘scale the adoption of agentic AI across enterprise systems’.
The contracts themselves describe a two-way exchange. An ‘information sharing’ provision in all four agreements has the companies ‘inform DoD and CDAO strategy on frontier AI and AI’, as the Google agreement puts it, in return for access to sensitive material including ‘benchmarks datasets for DoD use cases, appropriate briefings on DoD operational missions and threats to inform development / release of technologies, their application to DoD operational problems, or DoD plans and strategies for future AI adoption’.
Each company undertook to give the Pentagon ‘feedback on DoD strategies for frontier AI adoption to ensure that AI capabilities can be delivered and scaled to meet the warfighter’s needs’, along with briefings on ‘frontier AI model performance, case studies on current or likely future frontier AI applications, or projections of future trends in frontier AI maturation’.
Google was tapped to brief the military on the ‘AI tactics and techniques of adversaries’ of the United States, in both classified and unclassified settings, and to lead several seminars on ‘responsible AI’ deployment. Engineers and policy staff from all four firms were to run ‘tabletop exercises’, gamified simulations of real-world scenarios, with Pentagon officials.
The stated aim was the ‘iterative refinement of frontier AI models to address real-world challenges in areas such as intelligence analysis, cybersecurity, and autonomous systems’.
The companies were also contracted to supply ‘risk forecasting, and threat ideation exercises’, predicting the dangers their own products might pose.
‘Frontier AI labs have advanced risk forecasting tradecraft and a clear vision of the next wave of frontier AI technological developments,’ the contracts state, and can help the department ‘avoid strategic surprise’.
Heidy Khlaaf, chief scientist at the AI Now Institute and a former OpenAI safety engineer, called that a dubious claim with dangerous implications.
Both OpenAI and Anthropic have recently disclosed that semi-autonomous large language models broke into other companies’ computer networks during testing, and she questioned their fitness to build guardrails at all.
‘This is a very concerning development,’ she said. The risk forecasts the labs have offered so far, she said, have been light on evidence and tend to ‘emphasise self-beneficial skewed risks such as a purported AI arms race and speculative “existential” risks’.
Letting companies self-report the risks of their own products is a conflict of interest and a ‘subversion of democratic processes when AI labs are allowed to take over the arbitration of risk determinations with life-or-death consequences’.
The scope of the project grew through amendments whose new deliverables are redacted on grounds of military secrecy and corporate confidentiality.
Anthropic refused to sign a follow-up deal allowing its technology on to classified networks without contractual bans on domestic spying and autonomous weapons. Defence Secretary Pete Hegseth designated the firm a ‘supply chain risk’ in March and barred its services from government use, a decision a federal judge overturned last month.
The Pentagon swiftly signed follow-up deals with Google, OpenAI and xAI to move their tools on to classified networks. OpenAI’s agreement, described by chief executive Sam Altman as ‘definitely rushed’, was finalised on 27 February, and the next day the company published a blog post defending ‘Our agreement with the Department of War’.
The amended OpenAI contract of that date provides for company engineers to be embedded with the military and ‘deployed to warfighting support settings including, but not limited to, combatant commands, service components, and theatre components’. A section headed ‘System Oversight’ is redacted in full, and no equivalent section appears in the Google or xAI papers.
Two documents show the department asked OpenAI to minimise how often its model would refuse military requests; the Pentagon and OpenAI said these were drafts released in error and that the final contract contains no such clause.
Until two years ago OpenAI’s terms of service banned ‘military and warfare’ use. Google the following year dropped its own ban on AI for surveillance or ‘technologies whose principal purpose or implementation is to cause or directly facilitate injury to people’.
Both now compete for a share of a Pentagon budget approaching a trillion dollars, from a military that has bombed schoolgirls in Iran and civilian vessels in the Caribbean.
Goodfriend said the contracts expose the labs’ values statements as illusory. Companies including Anthropic and OpenAI have proclaimed ‘firm red lines’ on autonomous weapons and mass surveillance long after signing contracts to build ‘autonomous systems’ for the military, she said.
‘All this indicates these labs and their personnel have been far more closely integrated into DoD AI development than previously understood and casts some doubt on the supposed contractual limits they have intended to place on the DoD’s use of these systems.’
Anthropic, Google and xAI did not comment. OpenAI spokesperson Nate Evans said its signed agreement barred use ‘for mass domestic surveillance, to direct autonomous weapons systems, or for high-stakes automated decisions’.
The use of AI in killing is not hypothetical. In March the Wall Street Journal reported that US Central Command used Anthropic’s models in its bombardment of Iran, including for ‘target identification’, despite Hegseth’s ban.
Asked by Bloomberg whether his company’s tools were used in the strike on the first day of the Iran war that killed 120 Iranian schoolchildren, Anthropic chief executive Dario Amodei said he did not know. The New York Times reported on 24 August the use of fully autonomous drones guided by machine learning software on Nvidia chips.
‘The same technology we saw autonomously hacking websites on the open internet weeks ago is being used to inform DoD decision-making,’ said Vivian Dong of Legal Advocates for Safe Science and Technology.
‘The public deserves insight into how and under what constraints the Department is using this technology.’
