400 Pages of Pentagon Contracts: The Intercept Reveals How Deep AI Labs Really Went
FOIA-obtained contracts show OpenAI, Anthropic, Google and xAI agreeing to two-way intelligence sharing, embedded engineers and war-gaming with the Pentagon under $200M prototyping deals signed in July 2025.
The public feud between Anthropic and the Department of Defense made headlines for months, but the contract at the center of the fight stayed sealed. On September 8, The Intercept published the paperwork. Obtained through a Freedom of Information Act lawsuit filed with Legal Advocates for Safe Science and Technology, the release comprises more than 400 pages of documents covering the Pentagon’s deals with Anthropic, Google, OpenAI and xAI — and the picture they paint is of a far more entangled relationship between frontier AI labs and the U.S. military than any of the companies has acknowledged.
What the documents actually are
The contracts were originally signed in July 2025, each worth up to $200 million, under which the four companies agreed to build prototypes of AI tools designed to “improve military advantage, military utility, or enhance military decision making” across the entire armed forces. The applications named in the paperwork span “warfighting” and automated decision-making through logistics and military intelligence. Those prototypes, heavily redacted in the released copies, became the foundation of the AI tools now running on the Department of Defense’s classified networks.
The document set includes at least one contract reflecting OpenAI’s classified-network deployment. The Intercept says it is still waiting for the government to produce equivalent paperwork from the other three contractors — meaning this release is a floor, not a ceiling, on what is known.
A two-way street for data and strategy
The single most consequential provision appears in all four agreements: an “information sharing” clause that creates a genuine two-way exchange, not a simple software sale. The companies didn’t just license access to their best large language models. Under the Google agreement’s phrasing, they committed to “inform DOD and CDAO strategy on frontier AI and AI” — CDAO being the Pentagon’s Chief Digital and Artificial Intelligence Office.
In practice, the labs were cleared to receive sensitive material including “benchmarks datasets for DoD use cases, appropriate briefings on DoD operational missions and threats to inform development / release of technologies,” plus “DoD plans and strategies for future AI adoption.” In the other direction, all four companies pledged to give the Pentagon “feedback on DoD strategies for frontier AI adoption to ensure that AI capabilities can be delivered and scaled to meet the warfighter’s needs,” along with briefings on their own internal operations — “frontier AI model performance, case studies on current or likely future frontier AI applications, or projections of future trends in frontier AI maturation.”
At times the labs were positioned as intelligence sources in their own right: Google was tapped to brief the Pentagon on “AI tactics and techniques of adversaries” of the United States, in both unclassified and classified settings.
Embedded engineers and tabletop war games
The contracts also schedule joint activity that goes well beyond vendor support. Engineers and policy experts from all four contractors are to conduct “tabletop exercises” — gamified simulations of real-world scenarios — together with the Pentagon. Google, for instance, was slated to lead multiple seminars on “responsible AI” deployment for the military. The stated hope was “iterative refinement of frontier AI models to address real-world challenges in areas such as intelligence analysis, cybersecurity, and autonomous systems.”
The February 27 amendments to OpenAI’s contract go further still. New language obtained by The Intercept specifies that OpenAI will embed company engineers within the military to help U.S. government employees deploy and use its AI system — workers who “can be deployed to warfighting support settings including, but not limited to, combatant commands, service components, and theatre components.” Notably, the same amendment contains a “System Oversight” section that is redacted in its entirety. No equivalent oversight section appears in the released documents for xAI or Google.
Labs forecasting their own risks
One of the strangest contractual obligations requires the AI companies to provide “risk forecasting, and threat ideation exercises” — structured predictions about the dangers their own future products might pose. The contracts justify this in striking terms: “Frontier AI labs have advanced risk forecasting tradecraft and a clear vision of the next wave of frontier AI technological developments,” and can “help DoD gain a better understanding of the risks that might be associated with subsequent near-term frontier AI models or features, to avoid strategic surprise.”
Heidy Khlaaf, chief scientist at the AI Now Institute and a former OpenAI safety engineer, told The Intercept this arrangement is a conflict of interest at its core. The risk forecasts produced so far, she argued, tend to “emphasize self-beneficial skewed risks such as a purported AI arms race and speculative ‘existential’ risks” rather than concrete harms, and letting labs arbitrate risk determinations with life-or-death consequences amounts to “a subversion of democratic processes.” Independent assessment, not self-reporting, is what the public actually needs.
The Anthropic rupture, explained
The documents also clarify the timeline of the Anthropic crisis. As the prototyping effort matured, subsequent amendments added new deliverables — descriptions redacted on military-secrecy and corporate-confidentiality grounds. It was during negotiation of those follow-ups that Anthropic refused to sign a deal allowing deployment on classified military networks without contractual prohibitions on domestic spying and autonomous weapons. Secretary of Defense Pete Hegseth responded in March by designating the company a “supply chain risk” and banning its services from government use; a federal judge overturned that ban last month.
The Pentagon quickly signed follow-on agreements with Anthropic’s competitors — Google, OpenAI and xAI — to move their tools onto classified networks. OpenAI’s deal, which CEO Sam Altman described as “definitely rushed,” was finalized February 27, with a company blog post the next day defending the “agreement with the Department of War” and pointing to clauses prohibiting domestic surveillance.
Two draft documents in the release indicate the DoD asked OpenAI to minimize the extent to which its model would refuse military requests. The department and OpenAI both said those were draft materials incorrectly produced, and that the final contract contains no such provision — a dispute that itself illustrates how much texture FOIA litigation can surface.
From ban to buy-side
The institutional whiplash is hard to overstate. OpenAI, founded as a nonprofit “to ensure that artificial general intelligence benefits all of humanity,” explicitly banned “military and warfare” use in its terms of service until roughly two years ago. Google reversed its own prohibition on surveillance applications and “technologies whose principal purpose or implementation is to cause or directly facilitate injury to people” the following year. Both are now, in The Intercept’s phrasing, landing slices of a nearly trillion-dollar Pentagon budget.
Company statements in response to the release leaned on their red lines. OpenAI spokesperson Nate Evans said the company’s tools “are built to support legitimate national security work — including vital cyber defense efforts — while refusing uses that cross the red lines we publicly announced,” citing the signed agreement’s prohibitions on mass domestic surveillance, directing autonomous weapons systems, and high-stakes automated decisions. Anthropic, Google and xAI did not respond to questions.
Why it matters
The Pentagon’s use of these systems in lethal operations is not hypothetical. The Wall Street Journal reported in March that U.S. Central Command used Anthropic’s models during the bombardment of Iran, including for “target identification” — despite the Hegseth ban. Asked whether his company’s tools were used in an airstrike that killed 120 Iranian schoolchildren on the first day of the war, Anthropic CEO Dario Amodei told Bloomberg he simply did not know. An August 24 New York Times report described fully autonomous drones guided by machine-learning software running on Nvidia chips.
“What’s particularly notable is the terms by which engineers are working in lockstep with the department of war to engineer AI systems for surveillance, targeting, and killing,” said Sophia Goodfriend, a Cambridge research fellow who studies the military impact of machine learning. In her reading, the contracts show the labs’ much-advertised “firm red lines” coexisting for years with signed work on autonomous military systems — and cast doubt on how much those contractual limits actually constrain the Pentagon once the software is deployed.
The deeper problem is structural. Oversight of weaponized AI currently runs through trade secrecy and national-security classification, with the vendors themselves serving as risk assessors. Four hundred pages into the record, the public still cannot see what the “System Oversight” section says — or whether it exists at all for three of the four companies involved.
Sources
- [1] https://theintercept.com/2026/09/08/military-ai-weapons-contracts-openai-anthropic-google/
- [2] https://openai.com/index/our-agreement-with-the-department-of-war/
- [3] https://www.cnbc.com/2026/02/18/anthropic-pentagon-ai-defense-war-surveillance.html
- [4] https://www.nytimes.com/2026/05/01/us/politics/pentagon-ai-companies-deals.html