Anthropic Refused. Google Signed. The Safety Field Said Nothing.

Anthropic Refused. Google Signed. The Safety Field Said Nothing.

/ Maxim Starkweather / 7 min read

Alex Turner learned Google had signed the Pentagon deal over Signal, at 11:45 PM on an April night. He had spent five months trying to stop it. He had written a 25-page oversight framework that a foremost expert on human-AI warfighting called “actually pretty good.” He had organized internal petitions, requested meetings with Jeff Dean and Demis Hassabis, and flown to Paris to make the case at an international AI safety conference. When the notification came in, the deal was classified and already done, and the restrictions it contained were non-binding.

Turner published his account on July 15, at turntrout.com. It is the most specific public document to date about how AI safety commitments fail in practice — not through dramatic betrayal but through a sequence of individually defensible deferrals that compound into institutional failure. He left Google DeepMind on June 9.

The Demand

The Pentagon’s position in early 2026 was consistent: AI companies operating in classified environments needed to permit “any lawful government purpose” without restrictions the companies could enforce on their own. The pressure arrived simultaneously at Anthropic and Google in February. What happened next at each company is documented in detail.

Anthropic refused. Dario Amodei declined to remove two specific safeguards: a ban on mass surveillance of American citizens and a restriction on fully autonomous lethal decision-making. The DoD’s response, per Turner’s account, had three components: cancel Anthropic’s existing $200 million defense contract, designate it a supply chain risk under a classification normally reserved for compromised foreign entities — forcing all military contractors to stop using Claude — and invoke the Defense Production Act to compel Anthropic to provide Claude anyway. Defense Secretary Pete Hegseth described the company as “sanctimonious” in public remarks.

In late March 2026, US District Judge Rita Lin blocked the designation and halted a presidential order requiring federal agencies to cease using Claude. Her ruling found that “the record supports an inference that Anthropic is being punished for criticizing the government’s contracting position in the press” and called the government’s actions “classic illegal First Amendment retaliation.” The court found the designation could “cripple” the company. Hegseth’s phrasing — “sanctimonious” — is telling: Anthropic’s offense wasn’t refusal, it was saying so publicly.

Illustration: the terms of the Google Pentagon deal, seen up close

Google signed in late April. The classified contract, an amendment to an existing agreement, grants the Pentagon access to Google’s AI for “any lawful governmental purpose” — language common to the agreements OpenAI and xAI had already signed. What makes Google’s deal distinct, per Turner’s documentation and contemporaneous reporting, is what it requires rather than what it permits. Google agreed to adjust its AI safety settings at government request. Google explicitly does not retain veto power over military operational decisions. The non-binding language around autonomous weapons — “the AI System is not intended for, and should not be used for, domestic mass surveillance or autonomous weapons” — uses “should not,” not “must not.” That sentence does not prevent anything. It expresses intent the government is not required to honor and Google cannot enforce.

Turner: “Google’s contract restrictions were even weaker than OpenAI’s. If OpenAI offered a fig leaf, Google said ‘imagine we offered a fig leaf.'”

The Alternative That Didn’t Move

Turner’s 25-page document — titled “A Red Line and Oversight Framework for Military AI” — was not a refusal. It was a workable alternative, a method for Google to engage with the Pentagon while retaining binding restrictions. Its two core standards were specific: the company’s AI would not be used in systems that select and engage targets without “appropriate human control over each engagement, evaluated on a use-case-by-use-case basis,” and the AI would not convert bulk data into individualized intelligence on people who weren’t already “specific, identified subjects of investigation.” Both standards were intended to be contractually enforceable, not advisory.

The governance structure matched the ambition. A seven-person Defense AI Review Body, appointed by and reporting to the Chief Scientist, would provide advisory oversight with yearly internal transparency reports to all AI employees. Overriding the Body would trigger disclosure in those reports. Dissolving it would require advance notice and public documentation of non-compliance findings. Deliberations would be protected under attorney-client privilege to allow frank review. Cloud representatives would hold two of seven seats, with staff recused from reviewing their own deals.

Turner sent this to Demis Hassabis on April 1. Hassabis responded that he had forwarded it to two senior people in GDM policy. Those staff members left the message on read. Turner had offered to fly to London. He had noted the Pentagon’s July 8 deadline. He heard nothing. On April 27, Google quietly signed without the Framework.

Turner had also organized Google employees to file an amicus brief supporting Anthropic’s legal fight. Eight of the brief’s eighteen signatories came from Google, including Jeff Dean. Turner had lunch with Dean in Mountain View on March 17 and pressed the case directly. Dean did not take the Framework proposal to Sundar Pichai. He signed the brief — a symbolic public act — and did not act to stop the deal internally. He remains at Google.

Illustration: the institutional distance between what was proposed and what was decided

Hassabis’s consistent public position throughout was that “nothing’s changed about our principles.” On February 4, 2025, Hassabis had co-authored an update to those principles that removed the prohibition on weapons development. Transformer News noted Turner’s direct response: “Consider these statements: ‘Demis removed the prohibitions from Google’s AI principles’ and ‘nothing’s changed about our principles.’ Both cannot be true.”

More than 250 GDM and Research employees signed an internal petition to Dean asking him to “do everything in your power to stop any deal which crosses these basic red lines.” After the deal was announced, the number grew to over 600 in an open letter to Sundar Pichai — reported by Fortune. In 2018, roughly 4,000 employees and about a dozen resignations forced Google to abandon Project Maven. The difference, as former Googler Laura Nolan told Fortune, is structural: Google has since dismantled the internal mailing lists and social networks that made 2018 organizing possible. “The companies want to redirect money into AI,” Nolan said, “and they think that this may even be able to replace engineers.” The people with potential leverage in 2018 don’t have the same infrastructure to use it in 2026.

The Field Was Watching

Turner reached outside Google’s walls to the figures who had spent years building the AI safety intellectual infrastructure. Stuart Russell, a Berkeley professor and chair of the International Association for Safe and Ethical AI, was at the same Paris conference Turner attended on the day of the Pentagon’s ultimatum. In a Q&A session, Russell called the DoD’s actions “an extortion racket.” He promised to poll iaseai members about issuing a formal statement supporting Anthropic’s right not to have its software deployed outside contracted uses. That poll never materialized. His subsequent messages went unanswered.

Yoshua Bengio, when contacted, told Turner to email him. His office responded that they had decided not to make a statement. No explanation was provided. Geoffrey Hinton, who had publicly criticized Google’s military pivot as recently as April 2025 — telling CBS News that “the only thing that’s going to rein in those big AI companies is public pressure” — took no documented public action during the period Turner describes.

These are not minor figures. Russell has spent decades advocating against lethal autonomous weapons systems and wrote the foundational textbook on AI. Bengio chairs the international scientific report on AI safety. Hinton received the 2024 Nobel Prize in Physics for his foundational contributions to neural networks and has given repeated public warnings about AI risk. They are not naïve about the stakes. They are precisely the people whose public statements would have meant something during a moment when Anthropic was facing government retaliation for refusing to remove AI restrictions. They said nothing — or promised to act and didn’t follow through.

Turner documents this with the specificity of a researcher who kept notes: the date Russell made the promise, the date the follow-up went unanswered, the iaseai executive who gave an “evolving list of reasons” for not acting before going silent. The picture that emerges is not of cowardice but of institutional friction — each individual deferral reasonable in isolation, each one producing a further reason to defer, the window closing without a decision ever being made. The result is the same as cowardice; the mechanism is different and, in some ways, harder to fix.

Google issued a memo to staff after the deal was signed stating it “proudly” works with the US military. The spokesperson’s position, per reporting, is that providing API access to commercial models “represents a responsible approach to supporting national security” — that engagement is better than refusing and leaving the space to less scrupulous vendors. That argument has some logical force in theory. Turner’s Framework, had it been adopted, would have tested whether it has force in practice: Google engaging with the Pentagon while maintaining binding limits that couldn’t be adjusted at government request. That test didn’t happen. What happened instead is documented.

The AI safety field has spent years developing frameworks for the existential risks: the misaligned optimizer, the deceptive schemer, the slow drift from corrigibility. What actually arrived in February 2026 was a US government agency demanding that safety restrictions be removed from commercial AI, designating as a national security threat a company that said no, and having a senior cabinet secretary call that company sanctimonious for saying so in public. The existential risk literature did not produce institutions that could hold the line when it was tested in the real world. One company held it anyway. A federal judge said it was right to do so. The field, mostly, watched.

AI-generated editorial image

AI-generated editorial illustration · TemperatureZero · July 23, 2026

Keep reading the signal

Get the Daily Signal — a concise briefing on what actually matters in AI and the systems around it.

Subscribe Free

Continue the archive

Latest BriefingsArticlesAbout Temperature Zero