T1#military#award#ethics

AI Goes to War — OpenAI Policy Reversal and the Anthropic-Palantir-AWS Pact

Anduril autonomous Sentry tower deployed on a California hillside
SourceElectronic Frontier Foundation (Wikimedia Commons) · CC BY 3.0 · View on Commons

Metadata

Date
Decade
2020s
Tier
T1
Sources
11
Connections
04
Tags
#military#award#ethics

2024 was the year generative AI shed its claim to be a "peaceful Silicon Valley tool" and was openly redefined as critical national-security infrastructure of the United States.

Three moments—January, June, November—mark the shift.

10 January — OpenAI Removes "Military and Warfare"

The policy changed on 10 January; Sam Biddle of The Intercept found and reported it on 12 January.

As The Intercept described it: up until 10 January, OpenAI's usage policies page banned "activity that has high risk of physical harm, including," specifically "weapons development" and "military and warfare." The rewritten policy kept an injunction not to "use our service to harm yourself or others" and offered "develop or use weapons" as an example — but the blanket ban on military and warfare had vanished.

OpenAI spokesperson Niko Felix explained by email: "A principle like 'Don't harm others' is broad yet easily grasped and relevant in numerous contexts." Asked whether the vaguer "harm" ban still covered all military use, he did not answer directly, writing instead that "Any use of our technology, including by the military, to '[develop] or [use] weapons, [injure] others or [destroy] property, or [engage] in unauthorized activities that violate the security of any service or system,' is disallowed." In a follow-up he said OpenAI wanted to pursue "national security use cases that align with our mission," citing a plan to build "cybersecurity tools" with DARPA, and that "the goal with our policy update is to provide clarity and the ability to have these discussions."

Heidy Khlaaf of Trail of Bits, quoted in the same piece, put the difference plainly: "the former clearly outlines that weapons development, and military and warfare is disallowed, while the latter emphasizes flexibility and compliance with the law." Legality, not safety, was now the axis — and, as she noted, developing weapons and conducting warfare is lawful to various extents.

26 June — Anthropic Carves Government Exceptions Into Its Usage Policy

Anthropic's move into government began in June, not November. On 26 June 2024 it announced that Claude 3 Haiku and Claude 3 Sonnet were available in the AWS Marketplace for the US Intelligence Community and in AWS GovCloud.

The contractual language mattered more than the infrastructure. Anthropic said it had written "a set of contractual exceptions to our general Usage Policy that are carefully calibrated to enable beneficial uses by carefully selected government agencies." Those exceptions permit "legally authorized foreign intelligence analysis" — the examples given being combating human trafficking, identifying covert influence or sabotage campaigns, and "providing warning in advance of potential military activities, opening a window for diplomacy to prevent or deter them." Restrictions on "disinformation campaigns, the design or use of weapons, censorship, and malicious cyber operations" were said to remain, and the carve-out applied only to models at ASL-2 under the Responsible Scaling Policy.

7 November — Anthropic, Palantir, AWS, and Classified Environments

On 7 November 2024, Anthropic and Palantir Technologies announced a partnership with Amazon Web Services covering the Claude 3 and 3.5 family. Claude would run inside Palantir's AI Platform (AIP), brokered through Amazon SageMaker and hosted in Palantir's Impact Level 6 (IL6) accredited environment — the Defense Information Systems Agency's classification for Secret-level workloads, held by only a handful of companies. Claude had become accessible within AIP earlier that month.

The press release listed the uses: "processing vast amounts of complex data rapidly, elevating data driven insights, identifying patterns and trends more effectively, streamlining document review and preparation, and helping U.S. officials to make more informed decisions in time-sensitive situations while preserving their decision-making authorities." That last clause — decision authority stays with the officials — was the whole of the safety framing in the announcement; there was no explicit "no lethal decisions delegated to the machine" provision here. The guardrails lived in the June usage-policy carve-outs.

Palantir CTO Shyam Sankar: "Palantir is proud to be the first industry partner to bring Claude models to classified environments." The picture of the safety-flagged Anthropic becoming a contractor to national intelligence agencies registered widely.

Air-Gapped GPT-4, Maven, and Llama

Across 2024 the same direction set in across the industry.

  • Microsoft (7 May): deployed GPT-4 into an isolated, air-gapped Azure Government Top Secret cloud, physically severed from the internet — reported as the first large language model environment built specifically for classified workloads.
  • Palantir (29 May): won a US$480 million US Army prototype contract for the Maven Smart System, extending the Project Maven target-detection stack to five combatant commands; contract modifications later pushed the total past US$1.3 billion.
  • Meta (4 November): opened Llama to US government agencies and defence contractors including Lockheed Martin, Booz Allen Hamilton and Palantir.

The Silicon Valley norm that had refused military work—epitomised by Google employees' 2018 protest against Project Maven—reversed almost completely in the post-ChatGPT competition. Google itself struck the 2018 pledges not to build "weapons" or surveillance "violating internationally accepted norms" from its AI Principles on 4 February 2025, not in 2024; DeepMind CEO Demis Hassabis and Kent Walker justified the change by pointing to a global competition for AI leadership in an increasingly complex geopolitical landscape, and argued that democracies should lead.

Same Models, New Vocabulary

Technically, no leap. The same Claude, the same Llama, the same ChatGPT—different licences, different customers, different operating environments.

What changed was the industry's vocabulary. From "Responsible AI" to "Sovereign AI"; from "Safety" to "Security". This is not just wording. It reflects a shift in the norm governing AI development—from ethics toward national strategy.

Geoffrey Hinton, awarded the 2024 Nobel Prize in Physics on 8 October, put this into his banquet speech on 10 December — not the Nobel lecture — listing among the short-term risks that "In the near future AI may be used to create terrible new viruses and horrendous lethal weapons that decide by themselves who to kill or maim," and adding that "All of these short-term risks require urgent and forceful attention from governments and international organizations." He did not call for a specific weapons treaty. He did end on distrust of the firms: "if they are created by companies motivated by short-term profits, our safety will not be the top priority."

2024 was the year the generative-AI industry stopped talking about its intentions and showed its customers.

Afterwards — Contracts Outrun the Norms, Then Collide With Them

The door opened in 2024 was institutionalised over the next two years.

  • 4 December 2024: OpenAI partnered with defence manufacturer Anduril on counter-unmanned-aircraft (counter-UAS) systems.
  • 4 February 2025: Google deleted the weapons and surveillance pledges from its AI Principles.
  • 14 July 2025: the Pentagon's Chief Digital and Artificial Intelligence Office awarded agentic-AI contracts worth up to US$200 million each to Anthropic, Google, OpenAI and xAI.

In 2026 that trajectory hit a wall. The dispute was over two exceptions Anthropic had attached to its July contract: Claude could not be used for mass domestic surveillance of Americans, nor in fully autonomous weapons able to select and engage targets without human intervention. The Pentagon wanted them gone — it wanted Claude available "for all lawful purposes."

On 27 February 2026 President Trump directed every federal agency to cease using Anthropic's technology, with a six-month phaseout — posting about an hour before a Pentagon deadline that had demanded Anthropic back down. Shortly after that deadline passed, Defense Secretary Pete Hegseth posted: "I am directing the Department of War to designate Anthropic a Supply-Chain Risk to National Security. Effective immediately, no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic." No American company had been designated this way before. Within hours OpenAI announced a Defense Department deal to put its own models on classified networks.

Anthropic said it had negotiated "in good faith" for months and supported "all lawful uses of AI for national security aside from the two narrow exceptions," which "to the best of our knowledge... have not affected a single government mission to date." It sued. On 26 March 2026 Judge Rita Lin of the Northern District of California granted a preliminary injunction, writing that the record "strongly suggests that the reasons given for designating Anthropic a supply chain risk were pretextual and that [the government's] real motive was unlawful retaliation." The government appealed; as of August 2026 the litigation is unresolved.

The 2024 story summarised as "the AI companies married the military" had a sequel — and the question in it is whether a vendor can draw the line in its own contract.

Sources

Last updated:

Share