Policy & Regulation

OpenAI Publishes National Security Principles as Government Work Expands

OpenAI has published National Security Principles banning mass surveillance and autonomous weapons use, as it expands cyber and biosecurity partnerships across nine allied governments.

Our approach to government and national security partnerships
Our approach to government and national security partnershipsAI-generated
By Marcus Bennett6 min read

Updated

Why it matters

  • OpenAI's National Security Principles ban its technology from mass domestic surveillance, directing autonomous weapons systems, and high-stakes automated decisions.
  • Under the Daybreak cyber defense program, OpenAI established Trusted Access for Cyber partnerships in the past month with Australia, Canada, Japan, South Korea, France, Germany, Poland, the Netherlands and ENISA.
  • OpenAI expanded trusted access to its GPT-Rosalind model last month for select U.S. government and allied partners in public health and biodefense, and supports legislation on the highest-risk military AI uses.

OpenAI has published a set of National Security Principles that formally defines how the company will allow its AI systems to be used in government, defense, and law enforcement contexts — a move that arrives as the lab deepens military and cyber-defense partnerships across at least nine allied governments and the European Union.

The document, released by the company, sets out contractual and policy red lines for sensitive deployments. OpenAI states that its technology may not be used for mass domestic surveillance, may not direct autonomous weapons systems, and may not make high-stakes automated decisions. Those restrictions, the company says, already apply to its existing agreement with the U.S. Department of War and will govern current and future national security and law enforcement partnerships.

The stakes are considerable. Frontier AI models are moving from consumer and enterprise applications into national security work — cyber defense, biodefense, critical infrastructure protection — where deployment decisions carry consequences for civil liberties, democratic accountability, and the balance of power between states. OpenAI's publication is an attempt by one of the world's leading AI labs to set its own guardrails in a domain where binding legislation in the United States remains largely absent.

What the principles say

OpenAI frames its position around a central claim: democratic societies should be able to use AI to protect people, defend critical infrastructure, deliver public services, and respond to emerging threats. The company specifically points to cyber defense and biological security as areas where AI "can meaningfully advantage defenders."

But the company attaches a condition to that endorsement. "Increasingly capable AI systems must be deployed in ways that reinforce democratic accountability, meaningful human judgment, and the rule of law, and that strengthen democratic institutions rather than concentrate power," OpenAI writes in the published principles.

That language reflects a tension at the heart of the story. The same frontier systems that can accelerate threat detection and public health response can also, if poorly governed, automate surveillance or concentrate decision-making authority in ways that bypass human oversight. OpenAI's answer is a set of self-imposed restrictions — and an explicit call for others to impose stricter ones.

Notably, the company does not claim sole authority over these questions. "Many of the most consequential questions about AI in government, especially in national security, should be answered through the democratic process," OpenAI states. "The role of companies like ours is to help inform those decisions, not make them alone."

On that basis, OpenAI says it supports legislative efforts to establish safeguards around the highest-risk military uses of AI, including domestic surveillance, autonomous weapons systems, and other high-risk applications that directly affect U.S. national security. That is an unusual position for a major AI lab: publicly inviting regulation of its own government business.

How the principles were developed

OpenAI describes the document as the product of a cross-company effort rather than a top-down policy decree. The company engaged David Kris, described as a leading national security expert, to facilitate the process and provide independent judgment. Kris is a former senior U.S. Justice Department official with deep experience in national security law, and his role signals that OpenAI sought external credibility for the framework.

The process also included internal listening sessions across the company, with participation from teams spanning research, safety, policy, and government partnerships. That detail matters for a workforce that has been visibly divided on defense questions in the past — OpenAI's own employees were given a structured channel to shape the policy before publication.

The partnerships behind the policy

The timing of the publication is not accidental. OpenAI says it is releasing the principles "as we expand our work with the U.S. government and allied partners in critical defensive areas, particularly cyber and biosecurity."

The cyber track is the most concrete. Under the company's Daybreak cyber defense program, OpenAI has in the past month established what it calls Trusted Access for Cyber partnerships with Australia, Canada, Japan, the Republic of Korea, France, Germany, Poland, the Netherlands, and EU institutions including ENISA, the EU Agency for Cybersecurity. That list covers most major U.S. intelligence-sharing and defense partners — a de facto allied bloc with privileged access to OpenAI's models for defensive cyber operations.

The UK occupies a separate but parallel position. OpenAI describes a "growing and trusted partnership" with the British government covering cyber work as well as testing and evaluation of AI systems.

Biosecurity is following the same playbook. Last month, OpenAI announced expanded trusted access to a model called GPT-Rosalind for select U.S. government and allied partners supporting public health and biodefense missions. GPT-Rosalind is a specialized deployment — the model name itself signals a focus on biology — and its expansion to allied governments indicates OpenAI sees biodefense as a second major government vertical after cyber.

The principles also cover OpenAI's work with the U.S. Department of War, the department formerly known as the Department of Defense. When OpenAI announced that agreement earlier this year, it articulated the three contractual restrictions that now anchor the published principles: no mass domestic surveillance, no directing autonomous weapons systems, and no high-stakes automated decisions. Today's document confirms those restrictions apply going forward, not just to the existing contract.

Why this matters

OpenAI is effectively publishing the terms of engagement for one of the fastest-growing parts of its business. Government and national security contracts have become a significant arena of competition among frontier labs, and each company's stated limits — or lack of them — shape what governments can procure and how AI gets embedded in defense infrastructure.

The publication also lands in a policy vacuum. The United States has no comprehensive federal statute governing military or national security uses of AI. OpenAI's explicit support for legislation covering domestic surveillance and autonomous weapons gives lawmakers and civil society groups a corporate endorsement they can cite — and a benchmark against which any future law can be measured.

There are open questions the document does not resolve. It does not detail enforcement mechanisms for the contractual restrictions, nor does it specify how OpenAI will audit government partners' compliance over time. The principles themselves acknowledge this gap implicitly by deferring the "most consequential questions" to the democratic process.

What the document does establish is a written, public standard: OpenAI's models can defend networks, support biodefense, and assist public institutions — but under stated limits, with human judgment preserved, and with the company on record asking legislators to make the hardest decisions binding rather than voluntary. As OpenAI's government footprint expands from Washington to Canberra, Ottawa, Tokyo, Seoul, Paris, Berlin, Warsaw, The Hague, and Brussels, that standard is now the reference point against which the company's conduct in national security will be judged.

Source: OpenAI News

Share this article:

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering consumer brands and retail at AI In Context.

108 articles

Related articles

  1. OpenAI Launches Initiative for Democratic AI Oversight in National Security
  2. OpenAI Publishes Frontier Governance Framework for AI Risk
  3. OpenAI's public policy agenda: safety rules, youth protections
  4. OpenAI Rolls Out GPT-5.4-Cyber to Vetted Defenders
  5. OpenAI ships GPT-5.5-Cyber, tiers access for defenders

« Previous articleNext article »