US defence AI contracts: the clauses that stay secret even from a senator
7 min read
On 1 May 2026 the US Department of Defense — which now signs its own releases as the “War Department” — announced agreements with eight artificial intelligence companies — SpaceX (which now includes xAI), OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services and Oracle — to bring their models inside the Pentagon’s classified networks, at Impact Level 6 and Impact Level 7. The press release explains the goal in a single sentence — the models are meant to “streamline data synthesis, elevate situational understanding, and augment warfighter decision-making in complex operational environments” — and stops there: the text of the contracts does not follow. On 6 July 2026 Senator Elizabeth Warren wrote two letters — to Defense Secretary Pete Hegseth and to the leaders of seven of the eight companies — asking for it. This is not a piece about American politics: what matters to an Italian procurement director or CISO is not who is right in Washington, but the structure of the problem the letters lay bare.
Eight vendors, one standard
The letters describe the contractual standard agreed with the eight companies as “lawful operational use” — “any lawful use”, according to the reporting the senator cites: any use not prohibited by law. Not a list of permitted uses, but the absence of a list of prohibited ones. Behind it sits a precedent we have already covered: Anthropic, which had secured explicit clauses against mass surveillance and lethal autonomous weapons, was designated by the Pentagon a “supply chain risk” after refusing to remove them; on 8 April 2026 a federal court denied Anthropic’s motion to lift that label. The letters cite a news report according to which some Defense officials “hope the new deals will push Anthropic to drop its reservations about the military’s broad ‘any lawful use’ standard”. The detail matters more than the dispute itself: the standard is a matter of negotiation, not a fixed technical fact, and whoever accepts it does so in a market where the more cautious vendor is treated as an obstacle.
The sentence the whole case rests on
To the seven companies, Warren writes: “it is impossible to assess any safeguards and prohibitions that may exist in your company’s agreement with DoD without seeing the full contract, which neither DoD nor your company have made available”. It is the sentence the whole case rests on, and it holds regardless of who says it: a buyer cannot judge a clause it cannot read. In support, the letters cite an analysis by Legal Advocates for Safe Science and Technology dated 2 March 2026, on the contractual language OpenAI disclosed in February: according to the experts cited, nothing in the text on autonomous weapons “does anything at all to constrain [DoD’s] use of” OpenAI’s products. This is not an accusation of ours, nor of the senator’s: it is a technical reading of the only fragment of contract ever to surface.
The follow-up that, so far, isn’t there
Both letters set a deadline for replies: 20 July 2026. We checked the warren.senate.gov newsroom up to 5 August 2026, with a targeted search of the site: no subsequent release on this exchange. Which is not the same as saying no one replied — responses may have arrived in non-public form. What remains out of public view, as of this article, is the text of the contracts.
Eleven questions, one procurement checklist
The letter to the seven companies asks eleven questions. They amount, in effect, to the specification a buyer ought to demand before signing. Below we transpose six of them — numbers 1, 3, 4, 8, 10 and 11 — from the senator’s voice into the buyer’s. These are not verbatim quotations: they are the same questions rewritten so that a procurement office can drop them into a specification as they stand.
- Provide the full text of the agreement you are proposing we sign, including any appendices and subsequent amendments.
- Does the agreement define what is meant by an “AI system”?
- What lawful uses, in your reading of the text, does the agreement allow us to make of your technology?
- As written, would the agreement permit use of your technology for surveillance purposes, or for purposes not explicitly set out in the specification?
- What visibility do your cleared personnel have into the queries being run, the data being processed, and the outputs being generated within our environment, subject to restricted compartmentalisation?
- Do your safety researchers remain “in the loop” before any use we make of the service, or are you informed only after the fact? Can you prevent or terminate a specific use if your team believes it crosses a red line?
The fifth is the heart of everything else. In the original it is question 10, and we reproduce it verbatim because no rewording improves on it: “What visibility do your company’s cleared personnel have into the queries being run, the data being processed, and the outputs being generated within a classified environment governed by strict compartmentalization?” And the sixth, question 11, asks whether the vendor is ‘in the loop’ before use or informed only afterwards, and whether it can block a use it believes crosses a red line.
The technical point: who sees what
Taken together, the two questions say something the rest of the letter only hints at: in a set-up where the model belongs to an outside vendor and runs on an outside vendor’s infrastructure, “which queries were run, which data processed, which outputs generated” is not a question the architecture can answer on its own. The contract answers it — the very clause no one can get shown in full. If a United States senator cannot obtain the text, an Italian company or public body — in defence as much as anywhere else — will not obtain it for its own. The difference between “the vendor promises not to see your data” and “the vendor cannot see it” does not lie in the stated intention: it lies in who administers the infrastructure the queries run on.
The press release itself gives the scale of the problem, describing the internal GenAI.mil platform: “Over 1.3 million Department personnel have used the platform, generating tens of millions of prompts and deploying hundreds of thousands of agents in only five months”. At that volume no verbal undertaking holds: either a register answers the question, or nothing does.
The two axes, applied here
Comply: the six questions above should not remain a questionnaire a vendor signs once and files away. They become a control that actually runs — a register of the queries, the data processed and the outputs generated by the AI systems in use, with date, user, purpose and outcome, produced by the system itself and ready for an inspection. It is not what the vendor declares it does: it is the trail your own system leaves.
Decide: the same system that produces that register brings together the organisation’s scattered data — plant, archives, business systems, sensors, documents — into a single operating model, on which AI agents execute decisions with a human operator in command: for large enterprises, defence, public administration and healthcare the question stops being theoretical. On this point the customer agrees with us: the release promises “an architecture that prevents AI vendor lock”. That is precisely why our systems are multi-model — the model can be swapped whenever you like, if only to compare it — because the value sits in your ontology, your data and your processes. And ownership of the weights is a power the European Commission has already given itself by law: if the model runs inside your own perimeter and the weights are yours, question 10 stops being a question you put to a vendor who might not answer. It becomes a query on your own log. Always in both modes of delivery — on-premise on self-contained machines that do not require deep integration into your network, or a dedicated cloud with a data centre in Italy — and always with joint management: you do not need to already have, in house, someone who administers classified or critical AI systems.
Want to know whether, today, you could actually answer question 10 about your own system — who saw which queries, which data, which outputs? Half an hour, free of charge, to map it out.
Sources
- U.S. Department of Defense — “Classified Networks AI Agreements”, press release, 1 May 2026
- Letter from Senator Elizabeth Warren to Defense Secretary Pete Hegseth, 6 July 2026
- Letter from Senator Elizabeth Warren to Google, Microsoft, xAI, AWS, NVIDIA, Oracle and Reflection AI, 6 July 2026
- U.S. Senate — Warren Presses DoD for Answers on Military AI Contracts, Demands Release of AI Contracts, 7 July 2026