Latest Trending Discover Timelines Categories
All explainers

Technology explainer

Can an AI Company Refuse Certain Military Uses of Its Model?

An AI supplier can reject proposed military work or negotiate limits before signing. After deployment, the contract, hosting model, procurement law and technical controls determine who can restrict use, suspend access or demand continuity.

Yes, an AI company can usually refuse a proposed military use before it signs a contract, just as another commercial supplier can decline work or negotiate conditions. Once a contract exists, however, neither side can simply replace the agreed terms with its preferred policy. The answer then depends on the contract, the law governing public procurement, the way the model is delivered and any lawful national-security powers available to the state.

Short answer

An AI provider may set an acceptable-use policy, exclude certain applications and decide which customers it will serve. A government may reject those restrictions, choose another supplier, build its own system or negotiate stronger rights over access and continuity. If the parties sign a contract, that agreement defines what the provider must deliver and how either side can suspend, modify or end the service.

A company’s public safety policy is not automatically superior to a signed government contract. But a government contract also does not automatically give the state unlimited control over the company’s technology. Compulsion, penalties or exclusion from future work require a valid contractual or legal basis and, in many legal systems, a fair procedure.

Why is military AI different from ordinary software?

A conventional software licence usually defines users, features, security obligations and support. A frontier AI model adds uncertainty because its behaviour is probabilistic, its capabilities can change between versions, and the same general system may support harmless administration, intelligence analysis, cyber defence or decisions involving force.

This creates three kinds of dependency:

  • Operational dependency: a military unit may rely on the model during a mission, so sudden withdrawal or a changed response can disrupt work.
  • Technical dependency: the provider may control model updates, filters, computing infrastructure and the API needed to run it.
  • policy dependency: the supplier’s rules may define which prompts, data or applications are permitted, even when the customer considers the activity lawful.

The central issue is therefore not whether a company can “command” a military. It cannot. The issue is whether the government accepted a private dependency without securing the contractual and technical control needed for the intended mission.

Before a contract: the company can negotiate or walk away

A private provider can normally decide not to submit a bid or can propose conditions such as:

  • no use for selecting or engaging human targets without meaningful human judgment;
  • no mass domestic surveillance;
  • limits on offensive cyber operations;
  • approved security environments and data-handling rules;
  • human review for high-impact outputs;
  • testing, audit and incident-reporting requirements.

The government does not have to accept these conditions. It may decide that the restrictions conflict with mission requirements, invite other bids, procure a narrower capability or fund an internally controlled alternative. At this stage, refusal is principally a commercial and policy decision, subject to laws that may apply to discrimination, sanctions, export controls or regulated industries.

After signing: the contract becomes the operating rulebook

Once the parties sign, the important question is no longer what either side’s general policy says. It is what the contract incorporates.

A robust military AI agreement should define:

  • Permitted and prohibited uses: concrete scenarios are more useful than broad phrases such as “all lawful purposes.”
  • Service continuity: uptime, support, version changes, emergency access and the circumstances in which service can be suspended.
  • Model control: whether the system runs through the provider’s cloud, on government infrastructure or from model weights delivered under licence.
  • Safeguard control: who may change filters, approval gates, system prompts and monitoring rules.
  • Data rights: whether sensitive inputs are retained, used for training, inspected by staff or transferred across borders.
  • Testing and assurance: how performance, cybersecurity, bias, traceability and failure modes are evaluated before deployment and after updates.
  • Exit and transition: notice periods, data export, replacement assistance and the rights that survive termination.
  • Dispute procedures: escalation, cure periods, suspension, termination and appeal rights.

If a provider later blocks a use that the contract clearly permits, the customer may have remedies for non-performance. If the government demands a use that the contract excludes, it may need to renegotiate, change supplier or rely on a separate legal authority. Neither side should discover this boundary during an operation.

Can safeguards actually stop a military use?

That depends on how the model is deployed.

Provider-hosted service

When the military accesses a model through an external API, the supplier may be able to inspect traffic, enforce filters, change the model, rate-limit requests or disable access. This gives the provider substantial technical control, but it also creates a continuity and supply-chain risk for the customer.

Dedicated or government-hosted deployment

If the model runs in a protected government environment, the supplier may have less visibility and less ability to intervene instantly. Contractual restrictions can still bind the customer, but enforcement relies more on access controls, audit logs, licensing terms and institutional oversight than on a remote switch.

Delivered model weights

When the customer possesses model weights and the computing environment, the provider may have little practical ability to prevent a use after delivery. The remaining controls are legal, organizational and technical measures implemented by the customer. This arrangement improves sovereign control but transfers more responsibility for cybersecurity, updates, evaluation and misuse prevention to the government.

What does meaningful human control mean here?

Human review is not merely placing a person near the system. A useful human-in-the-loop system gives the operator enough information, authority and time to question or reject the AI output. In military settings, the required degree of judgment depends on the task.

An AI system that summarizes maintenance records poses different risks from one that recommends targets. For decisions involving force, meaningful control may require verified sensor data, an explanation of uncertainty, clear rules of engagement, positive human authorization and a safe way to abort. Fast automation can make nominal approval meaningless if a person cannot understand the evidence before acting.

International humanitarian law binds states and people who conduct hostilities. A vendor’s policy can add safeguards, but it cannot transfer the government’s legal responsibility to the software company or to the model.

Can a government compel the company?

Sometimes a state has emergency, defence-production, export-control, intelligence or requisition powers that affect private companies. Their scope varies sharply by country and circumstance. Such powers may require priority production, preservation of records, technical assistance or restrictions on exports. They do not create a universal rule that any government may demand any AI use from any provider.

Ordinary procurement powers are also significant but narrower. A government can often terminate a contract under defined clauses, decline to renew it, exclude a non-performing product from a particular system or seek damages. Those actions still must follow the governing contract and law. A national-security label cannot safely substitute for evidence and procedure merely because the dispute concerns defence.

Why governments worry about private vetoes

A military needs predictable access to systems it has integrated into planning, intelligence or command workflows. Officials may reasonably object if a provider can change policy overnight, replace the model without testing, misclassify legitimate activity or suspend service during a crisis.

The risk becomes more serious when:

  • only one supplier can provide the capability;
  • the system is deeply connected to classified data and workflows;
  • switching models requires months of testing;
  • the provider alone controls updates or authentication;
  • the contract does not guarantee transition support.

The answer is not necessarily to remove every safeguard. It is to design for continuity through multiple suppliers, portable interfaces, version controls, government-controlled logs, fallback procedures and clear change-management rules.

Why companies worry about unrestricted clauses

“Any lawful use” sounds precise, but legality can be disputed, change between jurisdictions or remain uncertain until a court rules. A broad clause may also expose a supplier to reputational damage, employee departures, investor concerns, export restrictions and responsibility for failures the model was never designed to handle.

Technical risk matters as much as ethics. A general-purpose model may hallucinate, follow manipulated input, leak sensitive information or behave differently after an update. Refusing a high-risk use can therefore reflect a safety judgment about capability, not an attempt to set foreign or defence policy.

A practical way to divide responsibility

  1. The state defines the mission and legal authority. Elected institutions and military command remain responsible for deciding what the operation is meant to achieve.
  2. The provider states technical limits honestly. It should disclose known failure modes, testing boundaries, update effects and uses the product was not validated to perform.
  3. The contract turns policy into precise obligations. Restrictions, availability, data rights and change control should be written before deployment.
  4. The system preserves accountable human judgment. Higher-risk decisions require stronger review, authority and records.
  5. The architecture assumes that suppliers can fail or leave. Replacement, fallback and data portability reduce the power of any single vendor.
  6. Disputes follow lawful procedures. Security concerns may justify urgent action, but evidence, documented authority and review remain essential.

What the Anthropic dispute illustrates

The dispute covered in NewTqnia’s report on the Pentagon and Anthropic arose from proposed limits involving fully autonomous weapons and mass domestic surveillance. The court decision described there did not grant AI companies a general veto over military policy. It addressed whether a particular supply-chain designation and the procedure used to impose it were lawful.

The case is a useful example, not a universal answer. Other countries have different procurement rules, emergency powers and constitutional protections, and future appeals may change the legal position in that dispute. The durable lesson is simpler: governments should not place mission-critical authority inside vague vendor terms, and AI companies should not promise capabilities or access boundaries that the contract does not clearly support.

Questions to ask before adopting a military AI model

  • Which exact tasks may the model perform, advise on or never control?
  • Who can change the model, filters or system instructions?
  • Can the service continue if the external network or supplier becomes unavailable?
  • What happens to classified or personal data?
  • How is each consequential output reviewed and logged?
  • What testing is repeated after an update?
  • How quickly can another model replace this one?
  • Which law and dispute process govern a suspension?

If these questions have no precise answers, the problem is not only AI safety. It is weak system design and weak procurement.

First appeared in

Judge Rules the Pentagon’s Anthropic Blacklist Unlawful

A new version of NewTqnia is ready.