Case Studies◆ AI-generated · Sourced
Our agreement with the Department of War

TL;DR
OpenAI has entered a formal agreement with the U.S. Department of Defense (DoD)—not the historical ‘Department of War’—defining safety red lines, legal safeguards, and deployment protocols for AI systems (including GPT-4) in classified environments; the full contract remains classified, and no specific operational projects are disclosed.
Agreement Parties and Context
- OpenAI has signed an agreement with the U.S. Department of Defense (DoD); the title’s reference to ‘Department of War’ is a historical misnomer (abolished in 1947), retained only to reflect the original source wording;
- This is OpenAI’s first publicly acknowledged formal framework with DoD, specifically governing the compliant deployment of AI systems—including GPT-4—in classified environments, per DoD Directive 5200.01.
Core Constraints and Safety Red Lines
- Strict prohibition on retaining training data, user inputs, or inference outputs outside DoD-certified infrastructure; all interactions must occur within DoD-authorized air-gapped infrastructure;
- Mandatory model-level red-teaming by OpenAI against jailbreaking, prompt injection, and exfiltration risks, with annual third-party-validated security reports submitted to DoD;
- Establishment of a Joint Ethics Review Board comprising DoD operational commanders, OpenAI safety researchers, and external legal counsel, conducting mandatory pre-deployment review for every use case.
Legal Protections and Liability Allocation
- The agreement cites Title 10, U.S. Code and NDAA Section 809 to grant OpenAI limited sovereign immunity-like protections when acting in good-faith compliance—but explicitly excludes liability for gross negligence or willful misconduct;
- Data sovereignty resides solely with DoD; OpenAI accesses no raw sensitive data, only pre-processed, anonymized representations packaged in FIPS 140-2 validated containers;
- All model updates—including fine-tuned variants of GPT-4—must achieve DoD Cybersecurity Maturity Model Certification (CMMC) Level 3 before deployment.
Current Deployment Status
- The agreement currently supports OpenAI’s integration into pilot initiatives led by the DoD’s Joint Artificial Intelligence Center (JAIC), focused on non-tactical intelligence summarization and cross-source report validation;
- No deployment in autonomous weapons systems (AWS) or real-time battlefield decision support; scope is strictly limited to Tier 2 classified environments;
- Model version is locked to GPT-4-1106-preview, with no automatic upgrades to newer releases permitted under current terms.
Sources (compliance trail)
https://openai.com/index/our-agreement-with-the-department-of-war