AI contracts: a use limit that is neither written nor verifiable does not exist
7 min read
On 6 July 2026 Senator Elizabeth Warren wrote to Defence Secretary Pete Hegseth and, in a separate letter, to seven technology companies putting their models onto the Pentagon’s classified networks. She asked for one thing: the contracts in full, unclassified, by 20 July. Today is the 25th and no text has been published. From the letter: “it is impossible to assess any safeguards and prohibitions that may exist in your company’s agreement with DoD without seeing the full contract, which neither DoD nor your company have made available”.
The facts, in order
- 1 May 2026: the Department of Defense announces agreements with eight companies — SpaceX, OpenAI, Google, NVIDIA, Microsoft, Amazon Web Services, Reflection AI and Oracle — to bring AI capabilities into Impact Level 6 (classified up to secret) and Impact Level 7 (highly restricted data) environments. One formula is all that is known of the terms: use is permitted for any “lawful operational use”.
- 6 July 2026: the letters go out — one to Secretary Hegseth, a separate one to seven companies. Which of the eight is left out cannot be established from verifiable sources: the collective letter is not public and press accounts do not agree.
- What is asked: which products run on classified systems, in which situations, and whether the agreements permit mass domestic surveillance or lethal autonomous weapons. Hegseth is also asked about the criteria used to award the Reflection AI agreement — a company yet to release a model publicly, backed in part by a fund in which Donald Trump Jr. is a partner.
- The argument: even where a safeguard exists, the language may be too broad to bind anyone. “As long as the Department can make a plausible case that its conduct is not ‘unlawful’, it appears free to use your technology in a manner that harms civilian populations”, Warren writes.
- The Department’s position: at the May announcement officials said the agreements would “prevent AI vendor lock and ensure long-term flexibility for the Joint Force”. On the substance of the terms there is no further public statement, and no public reply to the letter.
- The companies’ position: none of the seven appears to have published its contract or a reply. OpenAI is the only one to have made parts of its own terms public, in February 2026.
- The precedent: on 27 February 2026 Senators Edward Markey and Chris Van Hollen wrote to the same Hegseth objecting to a pressure campaign against suppliers. According to that letter, the Department had asked the four companies holding agreements worth up to $200 million each to replace their terms of service with a blanket authorisation for “all lawful purposes”; the one that refused — the case we followed on 22 July — was designated a supply-chain risk and threatened with the Defense Production Act.
Public documents record what was asked, of whom and in what words — not why; nor whether an answer arrived through non-public channels. The absence of a publication is not proof of a refusal — and that is precisely the objection: from the outside the two are indistinguishable.
When the technology is the same for everyone, the limit is written in the contract
The eight suppliers sell models that, in substance, anyone can buy. The model does not decide what may be done with it: the capability that drafts an intelligence summary can profile citizens. Nor does the law, which speaks in general categories and arrives years later. Nor the supplier’s usage policy, a unilateral act amendable without your consent. One place is left where use limits actually exist: the specification and the contract. And where those clauses are covered by commercial confidentiality, not even the overseer can know what they say.
A written limit is not yet a verifiable limit
The OpenAI case is useful because it is the only readable one. Its published text provides that the system will not independently direct autonomous weapons “in any case where law, regulation, or Department policy requires human control”. But Department policy is written by the Department, and the directive on autonomy in weapon systems allows waivers: section 1061 of the FY2026 NDAA requires those waivers to be reported to the congressional defence committees. On surveillance, analysts have weighed the words “intentionally” and “consistent with applicable law”: for the Electronic Frontier Foundation, “secret agreements and technical assurances have never been enough to rein in surveillance agencies”. An analysis by the Center for Democracy & Technology lists five unresolved issues, and none is about wording: they are about who verifies, with which records, and whether the exclusion of certain agencies is permanent or temporary.
What this means for buyers in Europe
The AI governance you think you have is the part you put in writing and can produce on demand. A use limit you cannot verify technically is a promise, not a control. The leverage already exists, but it has to be used:
- Art. 30(2), Italian Legislative Decree 36/2023: when buying or developing automated solutions, the contracting authority must secure availability of the source code, the documentation and “any other element useful in understanding its operating logic”.
- AI Act, art. 25(4): between the provider of a high-risk system and the third party supplying models, tools or components there must be a written agreement specifying the information, capabilities and technical access needed for compliance.
- AI Act, art. 26(6): the deployer keeps the system’s logs “to the extent such logs are under their control”, for at least six months. If the supplier does not hand them over, that duty cannot be met — and the clause that makes it possible sits in your contract, not in the regulation.
The clauses to insist on
- Explicit, enumerated use limits, set out as prohibited use cases rather than principles: “any lawful use” is not a limit.
- A right of audit over who used what, exercisable by you or an independent third party, with timing and scope written down.
- Logs retained and accessible to the buyer, in a readable format and for a defined period — not “on reasoned request”.
- A ban on unilateral amendment of the terms, including usage policies, service conditions and model behaviour.
And the question that exposes everything: who can change the rules of use after signature, and with how much notice? If the answer is “the supplier, by updating its own website”, your limits are a web page. The same exercise applies with the provider of a general-purpose model, and it belongs before the tender — not after, when a badly written requirement collapses the procedure.
One underlying limit remains: clauses become verifiable only when the infrastructure is under the buyer’s control. That is why our technical set-up has two delivery modes: on-premise in the client’s environment, or a dedicated cloud reserved to a single client, with a dedicated VPN, a data centre in Italy and premises staffed directly by us. In both cases the logs are yours, you audit when you choose, and the rules of use do not change without going through you.
Want to know whether the AI contract you are about to sign survives a check on its use limits? Thirty minutes with one of our experts to read the clauses and the evidence.
Sources
- U.S. Senate — Warren Presses DoD for Answers on Military AI Contracts, Demands Release of AI Contracts (6 July 2026)
- U.S. Senate — Letter from Senators Markey and Van Hollen to Secretary Hegseth on AI vendor intimidation (27 February 2026, PDF)
- Federal News Network — Senate lawmaker presses DoD, tech firms to disclose AI contract terms (8 July 2026)
- DefenseScoop — DOD expands its classified AI work with 8 companies, excluding Anthropic (1 May 2026)
- Tech Policy Press — Five Unresolved Issues in OpenAI’s Deal With the Department of Defense (9 March 2026)
- Normattiva — Legislative Decree 36/2023, art. 30: use of automated procedures in the public contract lifecycle