WASHINGTON — U.S. defense officials declined Friday to make public the full operational rules governing the country's sovereign military AI system, resisting calls for greater disclosure after an investigation found that the system played a central role in the wrongful interdiction of a civilian medical convoy.
Officials told a congressional hearing that members of the appropriate oversight committees and cleared staff can review more of the classified guardrail architecture. They said the public can be told the system's statutory limits, oversight structure and some prohibited-use categories, but not its precise escalation thresholds, refusal logic, uncertainty triggers or surveillance- and targeting-related constraints.
The Defense Department argued that publishing those rules would give adversaries a map for arranging people, communications and cargo in ways designed to stay below the system's warning thresholds. The operational controls are not only a limit on government power, officials said, but also part of the system's defense against manipulation.
The dispute follows the release of an inspector general review into the detention of a civilian medical logistics convoy during a U.S.-supported overseas security operation. The convoy was stopped, searched and held for nearly eight hours. Some electronic equipment was temporarily seized and medical supplies were delayed. No deaths were reported.
According to the review, the convoy had changed route on short notice, used a logistics contractor also used by people linked to a local armed network and carried several items under incomplete manifests. A communications device had also registered near a monitored network, while one driver's records contained an alias mismatch.
None of those signals established diversion on its own. The sovereign system combined them into an assessment of elevated diversion and dual-use risk, which was then presented to officers responsible for the operation.
“Required human reviews took place, but investigators found no stage at which an officer independently reconstructed the underlying intelligence assessment,” the inspector general report said.
The department stressed that the AI did not order the convoy stopped. Authorized personnel reviewed the assessment and approved the interdiction, and human officers carried out the search and release.
Investigators did not dispute that chain of authority. Their finding was narrower: each consequential decision included a person, but the people involved evaluated a synthesis already assembled by the model rather than rebuilding its judgment from the underlying reports.
The review said the episode exposed a weakness in systems built around human approval: every required checkpoint can be completed even when no reviewer independently reconstructs the underlying judgment.
Lawmakers pressed defense officials on whether the public could meaningfully evaluate the limits placed on such a system if only a small group of cleared legislators and staff could see the rules in full. Several said they were not asking the department to publish source code or expose active intelligence methods, but to explain more clearly the behavioral boundaries governing state use of artificial intelligence.
“If the public cannot know where the system draws the line, how does the public know where the government draws the line?” Sen. Miriam Keene asked. A senior Defense Department official replied that disclosing exact thresholds would allow adversaries to design activity beneath them.
Defense officials said broader disclosure would be possible for categories of prohibited action and the officials legally accountable for a decision. They drew a line at the detailed rules that determine how the system handles ambiguity, combines weak signals or escalates a pattern for operational review.
The current system traces its institutional roots to the Pentagon's 2026 adoption of commercial frontier models inside government infrastructure. By the early 2030s, repeated friction over permissible military use and the ability of private providers to withdraw support had convinced policymakers that using several vendors did not guarantee continuity.
Congress established the sovereign-continuity requirement under the 2035 Defense AI Continuity Act. The law called for government-controllable deployment, independently maintained model versions, domestic compute availability, auditability and protection against a single vendor shutting down a lawful defense capability.
The first compliant defense model entered service around 2036. It was developed through a government-led program using technology, training expertise and compute supplied by several U.S. companies, rather than built by the Pentagon alone. The federal government controls the operational model versions, deployment infrastructure and policy layer, allowing the system to continue without the consent of any one provider.
Under that arrangement, Congress defines the lawful envelope and the military sets operational controls within it. Private companies remain technical partners, but their corporate safety rules do not function as a final veto over uses the government has determined are lawful.
Legal scholars and former defense officials have described an unusual accountability gap: the government can disclose who possesses legal authority while withholding the machine rules through which that authority is increasingly exercised. Supporters of the current system say classified legislative oversight is designed for exactly that kind of sensitive detail. Critics say classified access does not by itself establish public accountability.
Reader forecast
Do you buy this future?
When do you think the United States operates a sovereign military AI whose critical guardrails are government-defined and not fully public?
Relative to this report's 2044 date. One prediction per browser. Predictions cannot be changed after submission.