Agreement with Department of War: cloud-only deployment and explicit guardrails
Key Points
- Cloud-only deployment with OpenAI safety stack
- Explicit ban on domestic surveillance of U.S. persons
- No use for autonomous weapons or high-stakes automated decisions
Summary
OpenAI reached an agreement with the Department of War (DoW) that sets enforceable technical and contractual guardrails for classified AI deployments. The deal mandates cloud-only deployment, an OpenAI-controlled safety stack, cleared OpenAI personnel in the loop, and explicit contract language prohibiting domestic surveillance of U.S. persons, autonomous weapons control, and high-stakes automated decisioning.
Key Points
- Deployment architecture
- Cloud-only deployment; no edge model delivery to prevent use in autonomous weapons.
- OpenAI retains and operates the safety stack and can independently verify compliance (e.g., classifiers, updates).
- Contractual and legal constraints
- Agreement explicitly references Fourth Amendment, National Security Act, FISA, DoD Directive 3000.09, and Posse Comitatus limits.
- Prohibits intentional use for domestic surveillance of U.S. persons, procurement/use of commercially acquired personal/identifiable info, and unconstrained monitoring.
- Requires human control where law/regulation/DoD policy demands it; forbids independent direction of autonomous weapons.
- Contract language is tied to current legal standards so future law changes do not automatically broaden permitted uses.
- Operational controls and oversight
- Cleared, forward-deployed OpenAI engineers and safety/alignment researchers will assist and remain in the loop for classified deployments.
- Multi-layered approach: technical safety stack + contractual protections + personnel oversight.
- Governance and collaboration
- DoW will host a working group with frontier labs, cloud providers, and DoW policy/ops — OpenAI will participate to align on capabilities, privacy, and national security risks.
- Enforcement and remedies
- Standard contractual remedies apply (including termination) if DoW violates terms.
Implications for engineers
- Do not design or plan for edge deployments for this contract scope; assume cloud-only APIs and telemetry.
- Ensure safety-stack components are auditable, updatable, and capable of running classifiers and enforcement checks in deployed environments.
- Prepare for operational processes that include cleared personnel and integration points for in-loop oversight and verification.
- Align logging, access controls, and data handling to satisfy Fourth Amendment, FISA, and DoD directives for private information handling.
Next steps
- Expect working-group outputs and potential common contract templates for other labs.
- Build operational tooling for continuous verification, classifier updates, and cleared-personnel workflows.