The Contract That Erases Google's Red Lines Without Rewriting Them
The most consequential part of Google's Pentagon deal is not what Google said in its press statement; it is what the contract itself permits. The agreement allows the Pentagon to use Gemini and other Google AI for 'any lawful government purpose,' obligates Google to 'assist in adjusting its AI safety settings and filters at the government's request,' and explicitly denies Google 'any right to control or veto lawful government operational decision-making.' Each clause individually is unremarkable in defense procurement. Stacked together, they form a structure where Google's published safety norms are operationally unenforceable inside the customer environment they most matter in.
Google's public defense leans on its prior policy stance: AI should not be used for domestic mass surveillance or autonomous weaponry without appropriate human oversight. But there is a clean asymmetry here. The policy stance is a unilateral commitment Google can honor only by being able to refuse, throttle, or audit specific uses. The contract removes all three levers. The result is a posture where Google retains the language of its red lines while contractually forfeiting the mechanism to enforce them. That is materially different from OpenAI's deal, which kept three explicit prohibitions written into its agreement: no mass domestic surveillance, no autonomous weapons targeting, no high-stakes automated decisions. Reporting suggests Google's contract carries no equivalent carve-outs.
This is also why the air-gapped, classified nature of the work is not a side detail but the core problem. On classified networks, even Google's own trust and safety teams cannot observe how Gemini is being prompted, retrieved against, or composed with other systems. The employee letter's sharpest line — 'Classified workloads are by definition opaque... no way to ensure that our tools wouldn't be leveraged to cause terrible harms' — is a structural argument, not a moral one. There is no oversight pipe through the SCIF wall.


