Connect with us

AI

Trump’s AI Memo Bans Vendor Kill Switches for Warfighters

NSPM-11 speeds military AI, but its real payload is a no-disable rule for vendors after Anthropic’s fight, even once a judge vacated the blacklist.

Published

on

President Donald Trump’s June 5 memo bars any vendor from disabling military AI without prior approval. It also gives the Secretary of War 90 days to rewrite the Pentagon’s rules on autonomy in weapons, a clock that ran to September 3.

The White House billed the order as faster adoption for intelligence and warfighting. The clause that lasts is the one that takes the plug out of the lab’s hand.

A Kill Switch the Pentagon Will Not Tolerate

The June 5 national security memorandum, NSPM-11, tells the national security enterprise to make sure “no commercial entity or adversary possesses the capability to prevent use of, disable or degrade, or materially modify” an AI system that troops depend on, unless the federal government knows and approves. It says to do that through contract clauses “or other means.”

Michael Kratsios, director of the White House Office of Science and Technology Policy, put the same point in public the day the memo went out. Multi-vendor buying, he wrote, is there to prevent a single point of failure. Updated guidance on autonomous weapons is there to keep pace with the frontier. And no entity gets to disable or degrade a system warfighters depend on without prior approval.

That is a procurement rule dressed as a speed order. If a model is on a classified net, the company that trained it does not get a quiet off switch when it dislikes a mission. The vendor veto over military AI is what the text is built to kill.

Section 3(b) goes further. The Secretary of War, the Director of National Intelligence, and other agency heads are told, to the maximum extent the law allows, to terminate for default or for convenience contracts with companies that have “repeatedly demonstrated a pattern of conduct” at odds with the memo’s policy, including work done as subcontractors. Waivers can last no longer than 1 year. The agency head, not a deputy, must report each waiver in writing within 30 days.

Four Pillars, Three Clocks and One Rescission

NSPM-11 runs on four named pillars: Adoption, Adaptation, Assurance, and Accountability. Adoption means cutting “unnecessary barriers to rapid deployment” and putting frontier models in front of national security users without delay. Adaptation means taking commercial and open-source tools from many suppliers, large and small, and building in-house only when a commercial product cannot meet the mission.

Assurance is the kill-switch clause, plus testing that the memo says must cover confidentiality, integrity, reliability, availability, and interoperability. Accountability is the civil-liberties paragraph the wire copy led with. AI in this enterprise, the memo says, shall not be developed or used “to censor free speech, embed ideological bias, or conduct unauthorized or unlawful surveillance activities.” Commanders and agency heads stay on the hook.

Trump wrote the acceleration line himself. “Under my Administration, the United States can and will responsibly accelerate the use of AI across intelligence and warfighting domains in line with American values,” the memorandum says. It also rescinds and replaces the Biden-era National Security Memorandum-25, which the White House fact sheet calls a drag on adoption and a source of single-vendor dependence.

THE CLOCKS INSIDE NSPM-11

Task Clock Due date
Update DoD Directive 3000.09 on autonomy in weapon systems 90 days September 3, 2026
CNSS and OMB policy for AI on national security systems 90 days September 3, 2026
Classified annex 90 days September 3, 2026
Roadmap for advanced computing, high-security facilities, and an AI test range 90 days September 3, 2026
Procurement rewrite for rapid onboarding from multiple vendors 120 days October 3, 2026
Partnerships against distillation attacks, plus an AI National Security Strategic Reserve 120 days October 3, 2026

The 90-day block closed September 3. The 120-day block, including the talent reserve of outside experts, runs to October 3. A classified annex was due on the same 90-day mark, so silence on that item is the point of an annex, not proof of delay. The public weapons directive is a different file.

Anthropic’s Two Red Lines and the Contract Fight

The memo did not arrive in a vacuum. In late February, Anthropic, the lab behind Claude, refused to drop two limits on how the Department of War could use its models: mass surveillance of Americans, and fully autonomous weapons. CEO Dario Amodei said frontier systems were “simply not reliable enough” to power fully autonomous weapons, a line later recorded in a Congressional Research Service note on the dispute.

Secretary of War Pete Hegseth answered with a supply-chain risk designation on February 27, a label built for foreign sabotage of U.S. systems and not, until then, applied to an American company. Trump ordered agencies to stop using Anthropic’s technology. Anthropic sued on March 9 in the Northern District of California, case 26-cv-01996-RFL, arguing the move was retaliation for speech and a debarment without the hearing the Fifth Amendment requires.

FROM ULTIMATUM TO STANDING RULE

  1. February 27, 2026: Hegseth designates Anthropic a supply-chain risk under 10 U.S.C. § 3252; Trump directs agencies to cease use of its technology.
  2. March 9, 2026: Anthropic files suit in San Francisco and a separate petition in the D.C. Circuit.
  3. March 26, 2026: Judge Rita F. Lin issues a preliminary injunction, finding the designation likely contrary to law and arbitrary.
  4. May 2026: The Department of War announces agreements to put models from eight leading AI companies onto classified networks.
  5. June 2, 2026: Trump signs a companion executive order asking developers to submit covered frontier models for up to 30 days of government cybersecurity review before a wide release, on a voluntary basis.
  6. June 5, 2026: NSPM-11 is signed, with the no-disable clause and the 90-day rewrite of Directive 3000.09.
  7. August 27, 2026: Lin enters final judgment, vacates the § 3252 designation, and converts the injunction into a permanent order.

The sequence is the second-order story. Punishment that named one company ran into a court. A memo that names no company, and that writes the disable ban into every future contract, does not need the label.

Judge Lin Vacated the Blacklist on August 27

Lin’s 59-page opinion treats the technical story the government told as a collapse. The justification, she found, rested on a four-page memo from Under Secretary of War Emil Michael that postdated some of the challenged acts and on a claim the government later dropped, that Anthropic kept a backdoor into deployed models. Anthropic, the court said, “undisputedly lacks any such access.” The models were, as the government conceded, no riskier than any other black-box system.

The empty invocation of national security is not a blank check to punish and retaliate against government critics.

Judge Rita F. Lin, Northern District of California, Anthropic PBC v. U.S. Department of War

She wrote that contemporaneous words and deeds showed a desire to make a public example of Anthropic for “arrogance,” not an articulable fear of sabotage. “Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless.” An IT vendor, she added, does not become a potential adversary because it “asks probing questions or stubbornly insists on particular contracting terms.”

The August 27 order of final relief vacates the § 3252 designation, vacates the clause that had tried to bar defense suppliers from any commercial dealing with Anthropic, and vacates implementing orders at nine agencies. It does not force the Pentagon to buy Claude. Paragraph 14 of the order leaves the Department free to pick another vendor by lawful means. That is the door NSPM-11 walks through.

The field is not clear. A parallel designation under 41 U.S.C. § 4713, the Federal Acquisition Supply Chain Security Act, went to the D.C. Circuit, which heard argument in May and had not issued a merits decision by early September. In early September, Michael still said Anthropic “is still a designated Supply Chain Risk” at the Department of War and for the defense industrial base. One statute was vacated in San Francisco. The other was still live in Washington, and the memo’s contract clauses do not depend on either label.

The Public File on Directive 3000.09 Still Dates to 2023

Section 3(a) told Hegseth to issue, within 90 days, an update to DoD Directive 3000.09, Autonomy in Weapon Systems, and to review it every year. The point, the memo says, is “deliberate adoption of AI systems that respect the chain of command and operational authorities.”

The public text on the Directives Division site remains the January 2023 autonomy directive, signed by then-Deputy Secretary Kathleen Hicks. That version, which reissued a policy first put out in November 2012, says autonomous and semi-autonomous weapons “will be designed to allow commanders and operators to exercise appropriate levels of human judgment over the use of force.” It requires extra senior-level review for covered systems and says they must be able to terminate an engagement or come back to an operator when they cannot stay inside the commander’s limits.

“Appropriate levels of human judgment” is a phrase the services have lived with for more than a decade. It is also a phrase that does not, on its face, ban a weapon that selects and engages a target once a human has set the mission. A rewrite on a 90-day shot clock is where that ambiguity either hardens into a human trigger or loosens into software that fires inside a box someone drew last week.

No public successor to the January 2023 directive has been posted. If Hegseth signed a new 3000.09 and kept it off the public site, the force is flying on guidance the rest of the country cannot read. If he missed the September 3 mark, the old text is still the one contractors and allies can cite.

What OpenAI Wrote Into Its War Department Contract

Other labs did not all walk. The White House fact sheet says that in May the Department of War announced classified-network deals with eight of the world’s leading AI companies. OpenAI later published the language it said it had put in its own agreement.

The Department, OpenAI wrote, “may use the AI System for all lawful purposes, consistent with applicable law, operational requirements, and well-established safety and oversight protocols.” The same passage says the system will not be used “to independently direct autonomous weapons in any case where law, regulation, or Department policy requires human control,” and will not take other high-stakes decisions that those same authorities reserve for a person. It cites Directive 3000.09 dated January 25, 2023, and the testing that directive requires. For intelligence work, it points at the Fourth Amendment, FISA, Executive Order 12333, and a defined foreign intelligence purpose. It also states there will be no use for mass domestic surveillance.

That is the bargain NSPM-11 makes rational. A lab can still write limits that look like existing law and existing Pentagon policy. What it cannot keep, if it wants the work, is a private right to cut the model off when a use is lawful but ugly. The louder complaint after February was never that the Pentagon may decline a vendor. It was that a U.S. lab got a saboteur’s label for insisting on terms. Lin closed the label. The memo keeps the terms.

If the government truly has no plan to run mass surveillance or a weapon with no human in the loop, putting those sentences in a contract is cheap. Refusing to write them, then calling them already illegal, is how this fight started. OpenAI’s posted language shows one way through: cite 3000.09, cite the surveillance statutes, and still say “all lawful purposes.” Anthropic wanted the red lines in its own voice. The memo is written for the first path.

Sen. Gallego Asked About Friendly Fire First

Sen. Ruben Gallego, an Arizona Democrat and Marine veteran, sent Hegseth a letter on June 12, a week after the memo, with six questions on civilian harm and a request for answers by June 26. He warned that a rushed rewrite of 3000.09, or a squeeze on test and evaluation, could raise the odds of friendly fire and of civilian harm that costs the United States access, basing, or overflight.

GALLEGO’S QUESTIONS ON AUTONOMY

  • Friendly fire: How will the updated directive stop U.S. troops from being hit by autonomous weapons, semi-autonomous weapons, or AI targeting advice?
  • Adversary bait: Has the Department assessed whether rivals will try to cause an autonomy incident that costs the United States basing or overflight?
  • Manipulation: How does rapid adoption sit next to the risk that an enemy will spoof a system into harming civilians or partners?
  • Host-nation civilians: What safeguards cover people who live where these systems will operate?
  • Allies: Have partners been briefed when autonomous weapons will be fielded in or through their territory, and how often?
  • Staffing: Does the Defense Autonomous Warfare Group have people whose job is civilian-harm mitigation on these systems?

Those questions still hang over a public file that shows January 2023. Gallego copied Emil Michael and Lt. Gen. Stephen M. Marks, director of the Defense Autonomous Warfare Group. The memo’s own Assurance pillar talks about systems that are “reliable, robust, steerable, and controllable.” Steerability is a lab word. Friendly fire is a unit word. The 90-day rewrite was supposed to translate one into the other.

The 120-day work is still on the calendar. By October 3 the Department is supposed to have a procurement path that onboards frontier models from several vendors, plus partnerships against distillation attacks and a bench of outside AI talent. Multi-vendor buying is how you stop a single lab from becoming a single point of failure. It is also how you make sure the next argument with a safety team does not take a model off a net in the middle of a war.

Lin told the government it may choose its vendors. NSPM-11 tells those vendors that, once chosen, they do not get to pull the plug. The public weapons directive, for now, is still the one from 2023.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending