A newly circulated governance framework proposes two firm red lines for how an AI company's products can be used in government contracts, paired with an internal review body designed to track compliance without holding formal veto power over any deal.
The first standard bars the company's AI from being used in any system that selects and engages targets for the application of force without appropriate human control over each specific engagement decision, whether the company provides a targeting system directly or supplies an AI component within a larger targeting pipeline. The framework carves out defensive systems that intercept incoming weapons or munitions in flight, along with intelligence analysis that supports but does not replace a human targeting decision. It does not, however, exempt preemptive strikes, counter-force operations, or engagement of launch platforms regardless of how those are officially classified. Whether human control is genuinely appropriate is meant to be judged case by case rather than through a single fixed rule, informed by legal transparency the company would require from a contracting agency about how a given system will be lawfully deployed.
The second standard restricts the company's AI from converting bulk data into individualized profiles or threat assessments on people who are not already specific, identified subjects of investigation. Notably, the restriction applies regardless of a dataset's source, meaning commercially purchased location, financial, or communications data is treated the same as data obtained through direct government collection. For US citizens, lawful permanent residents, and anyone physically located in the US regardless of status, individualized analysis would require specific judicial authorization, with no exception carved out for national security claims. The framework explicitly states that individualized scrutiny cannot be triggered by demographic characteristics or political expression alone, and permits only aggregate statistical research or legitimately targeted analysis of already-identified individuals.
Enforcement runs through a proposed seven-person Defense AI Review Body, drawn mostly from the company's own AI research staff rather than its defense sales division, reporting to the organization's chief scientist. The body's authority is deliberately advisory rather than decisional: it can issue findings that a contract does or does not comply with the two standards, but only the chief scientist or chief executive can authorize proceeding with a contract despite a non-compliance finding, and doing so requires a written explanation. The enforcement mechanism is transparency rather than veto power, with an annual report to employees disclosing how many times leadership overrode a non-compliance finding, and a provision preventing leadership from quietly dismantling or defunding the body without thirty days' advance notice and disclosure of any outstanding findings.
The framework's authors point to a specific legal motivation behind the structure: a recent appellate court ruling upheld a substantial jury verdict against a defense contractor for harms connected to services it provided under government direction, even though the government itself could not be sued due to sovereign immunity. Documented internal review, the framework argues, gives a company a negligence defense and a paper trail it controls the disclosure of, distinct from simply hoping no comparable case arises.
Deployment terms vary by environment. Cloud-based deployments retain the company's full monitoring, safety stack, and ability to suspend service to an end user within a defined window if a violation is suspected. Air-gapped or edge deployments, where the company loses that direct oversight capability, are restricted to non-targeting, non-surveillance applications using models that have had general-purpose targeting and profiling capabilities deliberately removed, with the explicit goal that repurposing such a model would cost more effort than it's worth compared to simply acquiring a capable model through other means.
The framework also builds in its own obsolescence clause: if Congress passes binding legislation with independent enforcement authority meeting or exceeding either standard, the review body can vote, by supermajority, to retire the corresponding company standard in favor of the statutory one, but only in that direction, meaning the company's internal standard remains the floor until legislation actually catches up to it.