Crossposted from LessWrong.
Preface: When I think back on my most cherished memories of the Rationalist community, I return to those honoring defiance in pursuit of goodness:
Defying prestigious dogma and searching for raw truth;
Defying social pressure, acting alone to help someone while others watch;
Defying your self-expectations (your âroleâ), instead searching over lines of cause-and-effect to find a winning pathway;
Defying a powerful foeâs threats, because they only threaten since people like you cave;
Defying the specter of apparent impossibility because you canât bear to lose.
I cannot return to you and say âI defied and then I won.â But Iâm at least here to say âI defied.â
I recommend reading this article on my website since the embeds and typography work better there: click here.
Why I left Google DeepMind
In January, Department of Homeland Security (DHS) officers killed at least two people. In both cases, a federal agent grasped his gun, aimed it at a peaceful citizen, and shot them dead.

Left: Renée Good, moments before DHS killed her.
Right: Alex Pretti, moments before DHS killed him.
I learned that Google sells its Cloud services to the relevant agencies within DHS. I thought that was wrong. Federal agents should not be able to kill citizens in the street. I set out to find the most effective way to push my company to stop serving these agencies. My divestment campaign quickly broadened into an attempt to prevent Google from signing an unethical military AI deal, as the Pentagon started pressuring AI providers into military AI deals with no restrictions against use for killer robots or mass surveillance.[1]
I wanted AI ethics commitments to hold under pressure. In particular, I wanted Google DeepMind (GDM) to maintain its existing commitment against supporting killer robots. Over several months, I asked many people to act. I asked senior peopleârespected peopleâpeople with reputations silvered by their concern about AI ethics and safety. Nearly all declined.
Take Stuart Russell, a famous AI researcher who spent over a decade crusading against autonomous weapons. I worked at his lab for years. At a conference, on-stage, he agreed to push his organization to make a statement supporting AI providers against government coercion and promised a poll of the organizationâs members. The statement and poll both vanished.
Or take Jeff Dean, who is Googleâs Chief Scientist and the co-lead of Googleâs Gemini AI project. In 2018, Jeff signed a pledge to never support the development or use of killer robots. I got Jeff to publicly and boldly co-sign an amicus brief (where outsiders weigh in to sway a lawsuit) backing Anthropic against the Pentagon. But I also asked him to use his immense leverage to stop Google from making its own unethical deal with the military, and I donât think he did. He remains at Google despite his pledge.
I wrote a 25-page proposal containing contract language and oversight mechanisms. Military- and surveillance-law experts praised the proposal, which represented a principled counteroffer Google could have stood by. I sent the proposal to Demis Hassabis (GDMâs CEO) who routed it to senior policy staff, only for the proposal to wilt unattended until Google signed a deal.
Senior management had insisted that Google wouldnât sign. I disagreed with them, but they largely ignored my warnings. While I may have increased the Pentagonâs hesitation around the deal, Google still signed a deal handing over their AI without restrictions against killer robots or mass AI spying. Googleâs contract restrictions were even weaker than OpenAIâs. At that point, I couldnât stay at Google in good conscience, so I left.
This essay tells the story of why I left Google DeepMind. It is also the story of something larger: how powerful people and institutions failed, one after another, to keep their AI ethics promises in the face of pressure.
On private communications: Throughout this essay, I never quote anyoneâs private words without permission. Where private conversations matter, I characterize them minimally. I otherwise keep to my own actions, public information, and official communications. You canât verify my characterizations, so weight them accordingly. This minimization has cut content which would have supported my arguments.
Google supports the immigration enforcement supply chain
January 26th, 2026
Alex Pretti, 2024.
After Alex Prettiâs death, I was determined to take effective action. To determine how to reduce harm from DHS, I researched Big Techâs entanglement. Certainly, Microsoft and Amazon have larger involvement, but I was surprised to learn of Googleâs contracts with DHS:
The DHS 2025 AI Use Case Inventory lists Google among the GenAI providers used to âimprove the operational efficiencyâ of DHS.
Google sells Cloud services to ICE through third parties like ITC Federal.[2]
On October 3rd, 2025, Google delisted apps that warned of ICE activity.
Google voluntarily handed a student protesterâs account to ICE without notice, breaking their Terms of Service promise to âsend an email to the user account before disclosing information [to the government].â[3]
But how could I do anything about it?
The stereotypical activist action is to make a petition. But Google had already ignored a large petition on this issue. Plus, Googleâs executives likely hardened their company against stereotypical organizing tactics. Sit-ins, strikes, even a mass of Google engineers quitting: I deemed all of them ineffective (if I could even pull them off).
As I strategized, I judged that Google would not care about 100 random research engineers quitting. No, in the AI industry, talent is top-heavy and teams are driven by a few hard-to-replace stars. I didnât need to coordinate 100 engineers. Perhaps I just needed to coordinate 10.
Iâd followed the news and guessed that Sundar Pichai (Googleâs CEO) was more of a businessman than a âmake me a big speech about ethics and Iâll change my mindâ kind of guy. But if a few hard-to-replace people were ready to walk, that would matter for the business, so Sundar might listen.
Thatâs when I remembered reading Jeff Dean tweeting about how bad ICE was, retweeting Anne Frank quotes. Maybe I didnât even need 10 engineers, I just needed one.
Jeff is considered a saint at Google. He was Googleâs 30th employee, developed key algorithms, and is known as a man of principle. A common joke: itâs easier for Jeff Deanâs resume to list what he hasnât achieved than what he has. Heâs Googleâs Chief Scientist and a co-lead of Googleâs Gemini effort. A Jeff departure would be a disaster for the company.
But if Jeff cared so much and had so much leverage, why was Google in these ICE contracts in the first place? Of course, you canât be Chief Scientist and constantly get what you want by threatening to quit. But I still felt confused.
Talking to Jeff Dean
February 9th, 2026
At first I thought about who could put me in touch with him. But (and this is a good general lesson) if you want to talk to someone about something, you can always JUST ASK THEM!
I told Jeff that I respected him for speaking out, that I wanted Google to divest from the DHS supply chain. I asked if he shared these goals and, if so, how I could help.
He suggested itâd be reasonable for me to email a few guys. Their names: Sundar Pichai (CEO of Google), Demis Hassabis (CEO of Google DeepMind), and Thomas Kurian (CEO of Google Cloud). I thought âsure, Jeff. No problem. Iâll just tell them what I think.â đ
My email
Iâm writing as a concerned employee at GDM. I recently messaged Jeff Dean regarding my concerns. He suggested that directly emailing the three of you was a reasonable next step.
I have no problem with Google working with lawful administrations of either US political party. My concern is not about politics, but rather about the events enabled by Googleâs role in the DHS supply chain.
I think that ICE has gone well beyond its legal mandate to remove illegal immigrants from the country in an orderly fashion. According to watchdogs, ICE operations frequently deprive targets of due process. These operations regularly detain citizens in facilities operating with minimal (or no) legal oversight. Over 1,000 people are missing from one such location. At other locations, the ACLU reports human rights abuses and a severe lack of safety for detainees.
These are not standard, legitimate enforcement activities. These operations are troubling from a human rights perspective and also pose reputational risk to any vendors involved.
On 1/â28/â26, the DHS posted its 2025 AI Use Case Inventory, which lists Google as one of several GenAI providers which âimprove the operational efficiencyâ of DHS. I urge Google to immediately stop working with ICE (and DHS more broadly), including via support for third-party integrators facilitating these specific operations. Whether through a direct (âprimeâ) contract or through intermediaries (like ITC Federal), Cloud and Gemini must not power these operations.
History will judge the tech sector by its involvement in these events. I love working at Google, and I want to ensure Google is on the right side of that history.
Alexander Matt Turner
Research Scientist, Google DeepMind
They never replied. I returned to Jeff and asked for a lunch to discuss constructive opportunities for real change within Google. I told him: âany time, any place. Iâll drive down to Mountain View to meet with you.â
At this point, I thought this was where âplan Aâ would fail. To my surprise, he actually accepted, for a lunch a few weeks out.
A lot would happen in that time.
The Pentagon tries to intimidate Anthropic
February 25th, 2026
The Pentagon wanted the frontier AI lab Anthropic to remove red lines from its existing contract: red lines against lethal autonomous weapons systems and AI spying /â profiling. The ultimatum was essentially âgive us your product or we will designate you a supply chain risk.â The government wanted the AI for âall lawful use.â
There were two major problems with that kind of deal:
Independent legal experts had pointed out potential war crimes committed by the Pentagon (like double-tap strikes on shipwrecked survivors), though the Pentagon insisted those actions were legal. Under that kind of âlegality,â âall lawful useâ potentially meant âAI enabling war crimesâ and âautomatically profiling dissidents with AI.â
The Pentagon threatened a private company with economic destruction. Usually, the government would say âno thanks, we will find another supplier who will provide terms we want.â In this case, the government threatened to falsely[4] designate an American company as a âsupply chain risk,â which would force all military contractors to stop using Anthropic.
Iâd been following the AnthropicâPentagon standoff for weeks. That morning, I read about the ultimatum. I was attending a conference in Paris held by the International Association for Safe and Ethical AI (IASEAI), which is a nonprofit founded in 2024 to be âa unified voiceâ for safe and ethical AI. The world-famous AI scientist Stuart Russell chairs its steering committee. Its 2026 working groups include âRed Lines for Advanced AI,â focused on âautonomous weapons and escalation.â IASEAI seemed built for a moment like this.
IASEAIâs venue would be full of influential AI professionals who care about ethics. I thought: we can organize a response, as a field, in support of 1) Anthropicâs right to do business without threat of destruction and 2) actual standards for whether and how to integrate AI into lethal autonomous weapons systems and surveillance apparatuses.
Anthropic had two days to comply with the administrationâs demands. Perhaps other companies would agree to these âall lawful useâ terms before the deadline. The main question which weighed on me: can I stop Google from caving, from accepting an âall lawful useâ deal? If Anthropic says ânoâ and Google also says âno,â now weâre getting somewhere. That seemed hard. I wanted to make it happen anyway. Google could cave at any moment, whether before the Friday deadline or after.
The venue was the headquarters for the United Nations Educational, Scientific and Cultural Organization.
When I arrived at the IASEAI venue, I expected some of the hundreds of AI professionals to be discussing the URGENT AI ETHICS NEWS which just dropped. Instead, no one besides me brought it up. People busied themselves with the usual abstractions: âhow does public choice theory inform coordination problems?â.
I wanted to mobilize the AI luminaries at the conference
Stuart Russell: Founder of IASEAI. Co-authored the standard AI textbook used in over 1,500 universities. Founder of UC Berkeleyâs Center for Human-Compatible AI, where I interned for several summers and completed a postdoc. For many years he was the only big-shot academic who took the existential risk from AI seriously. I had long appreciated that.
Most importantly: the leading figure in the global campaign to ban lethal autonomous weapons, with his site highlighting over two hundred prestigious talks on the subject. He presented the Slaughterbots videos to the United Nations. If anyone on this green planet Earth had a reason to call out an âall lawful useâ military AI deal, it was the man who organized the field against SLAUGHTERBOTS.
Yoshua Bengio: The most-cited living computer scientist and a Turing Award winner (like the Nobel but for computer science). In 2023, he testified to the US Senate on AIâs threats to democracy and national security. He just finished supervising work mapping military AI applications onto AI safety concerns.
Geoffrey Hinton: A 2024 Nobel laureate in Physics and a Turing Award winner. Hinton resigned from Google in 2023 specifically so he could warn about AIâs dangers without considering how it impacts Googleâs interests. In 2025, he had already criticized Google for âreversing its stance on military AI applications.â Hinton quit Google to be able to speak truth to these exact issues.
Talking to Bengio and Stuart
I briskly gathered information. Hinton was speaking remotely, so Iâd have to reach him indirectly, likely through Bengio or Stuart. I knew Stuart already and had a friend who could get me in touch. Bengio was the wildcard. I saw him leaving the venue, so I ran to catch him.
âYoshua, would you be willing to make a statement supporting Anthropicâs right to do business and pushing against unregulated killer robots?â. I clarified that his voice could influence the many GDM professionals who respect him, professionals who might be mobilized to push against âcavingâ to the Pentagonâs demands. He told me to email him.
Soon after, his office told me they decided they werenât going to make a statement. They didnât explain why not. Since I didnât know Bengio, I figured I should focus my attention on Stuart Russell and then let him handle it.
At lunchtime, I saw Stuart speaking with someone 1-on-1. With the encouragement of several attendees, I overcame a dash of social anxiety and interrupted his conversation as politely as I could.
âStuart, this is an extremely important situation and your voice matters,â I told him. âCan you make a statement? Can you get the IASEAI organization to make a statement, too? Can you move the people inside of these companies?â. He considered. He agreed. He would try to get Bengio and Hinton on board. He would convene an IASEAI vote ASAP and announce it at the closing of the conference later that day. He didnât hedge his willingness to fight.
âNow thatâs what Iâm talking about,â I thought. âHereâs a powerful guy who knows his power.â
Stuart closes out IASEAI
AI company /â DoD deals mattered. They marked the first public, high-profile intersection between modern generative AI and military use restrictions. Whatever compromises (or capitulations) the companies made would reverberate as precedent into the future. IASEAI attendees had a chance to take their contributions from âabstract work which might inform policymakersâ to âdirectly influencing precedent.â Stuart was now going to mobilize them.
As promised, he spoke about the issues at closing. I recorded his remarks during the Q&A, which were originally available on IASEAIâs conference schedule but were later migrated and not re-uploaded to IASEAIâs official YouTube channel.
The question I asked Stuart (video of the full exchange): The Department of Defense is threatening to take over Anthropic so they can use Claude without restrictions on lethal autonomous weapons or mass surveillance. What would you say to companies like Google and OpenAI who are still in negotiations?
Stuart Russell: I was going to mention this, and this is a topic on which we are likely to be polling all of the members of IASEAI. To see if they would like IASEAI to take a position on this issue.
[Stuart summarizes the situation.]
Should IASEAI make a statement in support of Anthropicâs right not to have its software used in purposes that are outside the contracted areas that it agreed to have it used for?
The question said, âwhat about Google DeepMind, what about OpenAIââare they also going to take the same stand as Anthropic? It seems like thatâs up to them, but the right of a company to say âwe donât want to sell our product for that purposeââand to be able to say that without threat of economic destruction. Iâm not a lawyer, but it seems like thatâs something that ought to be protected.
I was surprised. Stuart said âIt seems like [taking the same stand] is up to them.â He didnât encourage Google and OpenAI to avoid powering lethal autonomous weapons? Wasnât that a defining cause for him over the last decade?
The next question from a conference attendee asked whether IASEAI would take positions on current issues. As the session wrapped, IASEAIâs interim executive director Mark Nitzberg took the stage.
Mark asks for a show-of-hands: âWe will be asking the opinions of members⊠and if youâre not a member, go to the member desk.
A near-unanimous show of hands supporting an IASEAI statement backing up Anthropicâs right to do business freely.
Stuart Russellâs closing remarks
Many news outlets are discussing the extortion racket that the DoD is applying to AnthropicâŠ
I think we will try to get an online poll if we have time to make this happen. So that we can publish a news release saying â92% (or whatever it turns out to be) of members of IASEAI are in favour of the proposition that Anthropic should not be required to do what they donât want to do.â
Stuart called the DoDâs actions an âextortion racket.â I appreciated the frankness, though frankness in the hall wasnât the same as frankness in a statement the world would see.[5] As I left, I signed up to be an IASEAI member to participate in the poll. I thought itâd pass but wanted to make my voice heard. I paid the $75 membership fee.
Before the closing ceremony, Mark had texted me that the survey would close Thursday night. With 2â3 support, Stuart would sign a statement on IASEAIâs behalf, and without it, Stuart would sign a statement personally with the option for others to co-sign.
I left for an evening at the Louvre.
International Association of Silence on the Ethics of AI
Thursday morning greeted me. I didnât see how to vote in the poll. Strange. I texted Mark. He said IASEAI would have to act after Anthropicâs Friday deadline.
I told Mark that the situation was urgent: Google and OpenAI could move at any point. I urged him to talk to Stuart about making his own statement, any statement. I appreciated that Mark was helping me figure out this situation. Later that day, Anthropic indicated they would stick to the red lines in their existing contract with DoD.
(Thursday was supposed to be the start of a romantic vacation in Iceland. I didnât really want to be doing any of this.)
Friday morning. Stuart had not made any public statement. I asked Mark, âWhat is possibly more important than spending a few minutes composing an email to his favorite reporter?â. From my conversation with Mark, I learned that neither Stuart nor IASEAI would act.
But hereâs the thing. Mark committed publicly at closing that IASEAI would hold a member poll. Mark encouraged people to pay dues and become members to participate. Then IASEAI leadership silently cancelled the poll.[6] No statement ever came.
Mark gave me an evolving list of reasons for his organization not making a statement:
IASEAI needed more time to draft a statement and so would move after the Friday flashpoint.
IASEAI doesnât know which principle it should cite for making a statement.
IASEAI worried that joining an AnthropicâPentagon news cycle âhas pros and cons.â
Mark was sympathetic but wanted to focus on refining IASEAI processes for handling this kind of situation.
IASEAI didnât need to make a statement anymore because Anthropic made a statement.
I could appreciate the first reason: after all, Stuart had repeatedly disclaimed âtime permittingâ for making a statement before the deadline. But that last reason in particular didnât make sense to me. Anthropic made a statement saying they wonât budge, so IASEAI doesnât need to make a statement supporting Anthropic?
Left on read by IASEAI
The Pentagon set the Friday deadline for Anthropic, not IASEAI. The Anthropic autonomous weapons issue had been in the news for weeks prior. Anthropicâs lawsuit against the Pentagon ran for weeks after. Google wouldnât sign for two more months. IASEAI had plenty of time to act and plenty of ways to act, like filing an amicus brief, putting out a statement, or contacting senior decision-makers at Google.
OpenAI did announce a deal on Friday. OpenAI claimed its deal protected the same red lines against killer robots and mass surveillance that Anthropic had insisted upon. However, some analysts concluded that OpenAIâs contract language contains wide loopholes.
Over the next two months, I messaged Mark Nitzberg many times.[7] I explained that I was trying to convince senior decision-makers inside of Google; that Stuart could reach out privately without the political cost of publicly opposing Trump; that even introductions would help.
A message I sent to Mark
March 30th, thirty days before the deal was reported as signed
While I wish IASEAIâs decisions had been different, I would like to find a way for us to accomplish our shared goals.
Mark never replied.
Trying to stop Google from signing
Letâs rewind to Wednesday, when I had just learned of the Pentagonâs threat. I was operating under unknown time pressure. I had no idea whether Google was about to undermine Anthropicâs position by signing a deal. As I acted externally by lobbying Bengio and Stuart, I acted internally too.
Building internal cost for Google
February 26th, 2026
In Google DeepMindâs current events discussion channel, I called for Google (and the AI community) to âstand strong with Anthropicâ and remarked that supposedly âlawfulâ uses might include âkilling over 150 people off of the coast of Venezuela (most of whom were likely innocent fishermen).â The message received over 125 ââ€ïžâ reacts.
[My message] Geminiâs âall lawful useâ policy and the DoD pressure on Anthropic
Iâm reading reporting that GDM is âcloseâ to a deal to allow âall lawful useâ of Gemini for classified purposes. Apparently, for unclassified work, Google already âremoved some model-level restrictionsâ and agreed to âall lawful purposesâ for DoD work.
While the âlawfulâ in âall lawful purposesâ initially felt comforting to me, consider the implications of âlawfulâ in this setting. First, this DoD claimed it was legal to kill over 150 people off of the coast of Venezuela (most of whom were likely innocent fishermen).[8] âAll lawful purposesâ also includes mass surveillance & analysis using AI (which is legal, as surveillance laws were not written with AI in mind) and creating lethal autonomous weapons systems.
Secretary Hegseth threatened Anthropic with a 5PM Friday ultimatum. If Anthropic refuses, he threatened to:
Cancel Anthropicâs $200M contract,
Designate them a supply-chain risk, forcing all other military contractors to stop using Claudeââsupply chain riskâ is normally only used for compromised foreign firms!âand
Invoke the Defense Production Act to force Anthropic to provide Claude anyways.
I think itâs unacceptable to nationalize a lab to force them to provide lethal autonomous weapons and mass [AI profiling] tools. As an industry, we should stand strong with Anthropic. Our hard work should improve Gemini for our customers, not sharpen the abilities of lethal autonomous weapons systems.
Iâm interested in othersâ thoughts on this topic. How can we advocate effectively to ensure our AI Principles hold firm against this kind of external pressure for offensive military use without humans in the loop?
I began posting this kind of message in the GDM-only discussion channel. These messages received unusually strong and supportive engagement. I had several reasons for posting:
I wanted to raise the cost of silence from leadership. Remember, the whole point is stacking up enough cost to outweigh the benefits Sundar perceived from signing (like avoiding political retaliation from the Trump administration).
I often had strategic arguments which I wanted to tell my senior contacts. I was just a research scientist so it would be presumptuous for me to directly tell them âconsider X.â However, I knew some of them read this channel, so I simply posted my arguments in the channel.
I wanted to create common knowledge among GDM employees that no, they are not alone in their discomfort with these contracts.
I pointed out the problems with the âprotectionsâ in OpenAIâs deal to inoculate GDM employees against similarly fake âprotectionsâ that Google might try to pass off. If employees didnât buy the veneer, Google would pay a greater morale cost.
Later, some messages provided people a channel to hint they would leave Google if the deal passed, while still providing soft deniability.
The ââ€ïžâ reacts also acted as a subtle organizing mechanism. My understanding was that Google frowned upon people directly organizing through large internal channels. I noted who responded with ââ€ïžâ and reached out to them privately for the petition which Iâm about to talk about.
Jeff Dean, youâre our only hope
I considered sending Jeff another DM: âplease stop Google from signing the deal if you can.â But that seemed⊠not likely to do much. âWhat spurs people like Jeff to action?â I thought. Moral stakes: already present. Sense of ownership: not present. I couldnât own the project because I had no direct power. As best I could tell, Jeff truly was one of the few people with both the power and inclination to oppose a deal. I wanted him to feel empowered and to know that GDM workers backed him up.
I wrote a petition to Jeff and, with the help of a few friends, got about 250 GDM /â Research signatures in the next day or two. I will not reproduce the entire petition because I said it was ânot publicâ and instructed people not to share externally.[9] However, the New York Times did report on this petition, so some bits[10] are already public:
Google Workers Seek âRed Linesâ on Military A.I., Echoing Anthropic
âPlease do everything in your power to stop any deal which crosses these basic red lines,â the employees wrote. âWe love working at Google and want to be proud of our work.â
Jeff signs an amicus brief supporting Anthropic
March 9th, 2026
The Pentagon didnât just designate Anthropic a supply chain risk. Pete Hegseth (the Secretary of the DoD) initially claimed that military contractors must stop all use of Claude, not just the use of Claude in their contracts. That impacted Anthropicâs major cloud and enterprise customers, so the designation looked deadly for their enterprise revenue. This requirement also seemed quite illegal, and Hegseth backed down on that part. (However, I think Hegsethâs tweet had already done damage by making businesses uncertain about whether they would be punished for using Anthropic.)
Anyway, on Monday or so, Anthropic challenged the Pentagon in court and asked for an injunction to stop the order. A nonprofit called Protect Democracy put together an amicus brief from AI professionals. The amicus communicated something like, âin our capacity as experts, we agree that Anthropicâs technical and policy concerns are legitimate, even though we work for competing labs.â I signed the document, got some colleagues[11] to sign, and (with encouragement from an organizer) reached out to Jeff. He signed.
I was pleasantly surprised. Big move. (At this point, some of my friends started saying âbased and Jeff-pilledâ to describe things they approved of.)
When Jeff publicly signed the amicus, he (as a C-suite executive) publicly broke with Googleâs silence. As I expected, his signature attracted attention. Eventually, the Google /â Pentagon negotiations hit a snag, in part because the amicus raised the prospect that Google might back out later.[12]
Google Sits Pretty as A.I. Rivals Compete for Pentagon Favor
Published later, March 18th, 2026.
But there is still reluctance among some Pentagon officials to rely on Google, two people familiar with discussions between the Defense Department and Google said. Thatâs because the company dropped a military contract in 2018 in response to protests from employees who argued that A.I. should not be used in weapons, the two people added.
Several top A.I. researchers at Google, as well as at OpenAI, also recently signed a legal briefing to support two lawsuits that Anthropic filed against the Defense Department. Anthropic is challenging the Pentagon for designating it a supply chain risk after it clashed with the department over how to use A.I. in warfare.
The participation of Google employees in the legal briefing added to some officialsâ concerns about the company, reminding decision makers in the Pentagon and elsewhere of the past protests against the use of A.I. in weapons, one former official with knowledge of the discussions said. Some Trump administration officials are worried that even if Google agrees to have its A.I. used widely, the company could bow out again, the former official added.
In this time, I sent several memos to Google Legal suggesting that Google file an amicus too. I reminded them that if Google let the threat stand against Anthropic, the government would now have a gun to point at Google in all future negotiations: comply, or be labeled a supply-chain risk. In the end, Google didnât file an amicus (but Microsoft did).
Senior management insisted Google wouldnât cave
All through March
As I talked more with senior management, they kept arguing something like: âdonât worry. Leadership cares about these issues, too. They wonât sign an âall lawful useâ deal.â I considered the idea. Might it be true?
âNo, itâs not true,â I concluded: not unless someone forced leadership to hold the line. I wrote a citation-heavy memo explaining why Google was likely to cave. I pointed to Googleâs history of complying in lower-stakes situations (like voluntarily handing over a student protesterâs information to ICE); I pointed to Googleâs large share of government contracts; and I pointed to how Google DeepMindâs AI principles had disintegrated into noncommittal vagueness. I reviewed some of the pressures confronting Google, including Googleâs mixed anti-monopoly exposure and the historically poor track record of the current Department of Justice.
I shared this memo quite a few times. As best I can tell, I wasnât able to persuade these senior employees.
Preparing for lunch with Jeff Dean
March 10th, 2026
I stayed focused on my goal. I needed to move Sundar. Jeff could, I estimated, move Sundar. Did Jeff want to move Sundar? Would he walk from a company where he is revered, with a prestigious job seemingly tailored to him, leaving behind a quarter-lifetime of memories? On the other hand, every tech company in the world would want to hire Jeff, his legacy seemed secure, he already had who-knows-how-much money, and leaving would show principle.
I didnât want to manipulate Jeff. I wanted to be real with him as one concerned person to another. I even avoided reading more than one article about him to keep myself from subconsciously tailoring my arguments to appeal to his psyche.
The way I saw it was: I donât need to get Jeff to agree to quit over this. In a sense, heâd already agreed to quit over it. He had signed a pledge in 2018:
Lethal Autonomous Weapons Pledge (signed by 5,218 people)
The decision to take a human life should never be delegated to a machine. There is a moral component to this position, that we should not allow machines to make life-taking decisions for which othersâor nobodyâwill be culpable. There is also a powerful pragmatic argument: lethal autonomous weapons, selecting and engaging targets without human intervention, would be dangerously destabilizing for every country and individual. [âŠ]
By removing the risk, attributability, and difficulty of taking human lives, lethal autonomous weapons could become powerful instruments of violence and oppression, especially when linked to surveillance and data systems. [âŠ]
We, the undersigned, call upon governments and government leaders to create a future with strong international norms, regulations and laws against lethal autonomous weapons. These currently being absent, we opt to hold ourselves to a high standard: we will neither participate in nor support the development, manufacture, trade, or use of lethal autonomous weapons.
Signers include: Google DeepMind (the organization), Demis Hassabis, Shane Legg (cofounder, now Chief AGI Scientist), Raia Hadsell (VP of Research), Jay Yagnik (VP and Engineering Fellow at Google, leading large parts of Google AI) and đ„đ„đ„ Jeff Dean:
Jeff Deanâs quote-tweet · Topher Spiroâs tweet · Jeff Deanâs reply. Notice: Jeff freely reiterated his pledge and agreed that âAI for mass surveillance of Americansâ is âthe last thing [he wants].â
I reasoned that if Jeff âwill neither participate in⊠nor support the development⊠or use of lethal autonomous weapons,â then logically, Jeff would have to quit Google if it signed an âall lawful useâ deal. I didnât know if Jeff was actually ready to do anything like that. I wanted to prepare for the possibility.
I arranged social support
Jeff, like all of us, is a human being. Humans tend to be worried by acting alone against a powerful entity. Even though I imagined Jeffâs weight would be enough to move Google on its own, I wanted him to feel supported. The first part of that was the petition I organized, signed by over 250 GDM employees asking Jeff to fight for them. The second part, though, was quieter.
I secured backup from several senior Google employees. If Jeff would agree to put his foot down with Sundar, they signaled that they would too. That said, the intended coalition was of size[13] one: Jeff. I expected that Jeffâs influence would be enough on its own, as his departure could leave the Gemini project in shambles. Maybe Google would care more about its AI program than about retaliation from Trump.
I guessed that Sundar was skilled at defusing pressure from employees. I hoped this was a gambit he wouldnât be able to stop, even if he knew about it.
The art of the deal
March 13th, 2026
Was Jeff a wrestler? I read an account of Demis trying to negotiate with Sundar for a separate legal structure for DeepMind. Any deal with Sundar seemed like it would need wrestling. Persistent wrestling. Furthermore, Sundar might try to defuse the tension with vague promises, so Jeff would need a specific proposal.
I mean, imagine Jeff and I sit down for lunch. Imagine heâs on board. Imagine he goes to Sundar and says âIf we sign this deal, I wonât be able to stay at Google. Help me stay.â Imagine Sundar says âYouâre important to me, Jeff. What would it take?â. What does Jeff say? âDonât sign a bad dealâ would probably lead to a bad contract that looks less bad on the surface.
Criteria for a contract
I needed to draft contract language which would actually work.
Good red lines: Rule out the questionable use cases (autonomous targeting without human control, untargeted profiling) while allowing trustworthy ones like missile defense. Avoid the weaknesses flagged in legal analysis of Anthropicâs red lines.
Robust red lines: Cloud would push deals through any loophole, Google Legal seemed unlikely to tighten my drafting, and the Pentagon wouldnât want terms at all. The language had to hold under pressure, with auditing that respected classification and operational security.
Minimal trust assumptions: I made the Chief Scientist the single root of trust that everything else hangs off of (I was betting everything on Jeff anyway). The Chief Scientist would staff a Review Body to advise on contracts.
Accountability via transparency: The Review Body would only privately advise Jeff and Sundar, but overriding it surfaces in a yearly transparency report to all AI employees. Dissolving it would require advance notice and disclosure of the exact outstanding non-compliance findings. I worked to ensure the Body couldnât be defanged as quietly as Googleâs 2018 principles were.
Minimal pain to opposed stakeholders: I gave Cloud 2 of 7 seats, recused staff only from their own deals, capped delays at 10 days, and protected deliberations under attorney-client privilege.
I considered a negotiations round. The counterparties would object to something, and I didnât want that something to be load-bearing. Therefore, I included less-important provisions meant to be negotiated away, like âthe Review Body can escalate to Alphabetâs Board via supermajority vote.â
The Framework I created
In my personal time (taking vacation days), I created language that would be a good starting point. I composed 25 pagesâ worth of âgood starting pointâ material. I have published the Framework on my site in generic form applicable to any provider of both cloud and AI.
Excerpts from A Red Line and Oversight Framework for Military AI
I sometimes call this âthe Frameworkâ as shorthand.
This Framework proposes two narrow Standards for the AI provided by The Company to government entities exercising coercive authority:
Human control over targeting and use of force. The Companyâs AI wonât be used in systems that select and engage targets for force without appropriate human control over each engagement, evaluated on a use-case-by-use-case basis. Applies whether The Company provides the targeting system directly or simply provides AI components in a targeting pipeline. Includes a right to legal transparency regarding how systems will be lawfully deployed, with compliance verification conducted by a mutually agreed neutral auditor. Does not restrict anti-munition defensive systems, intelligence analysis subject to Standard 2, logistics, or R&D.
No untargeted AI profiling. The Companyâs AI wonât convert bulk data into individualized intelligence on people who arenât already specific, identified subjects of investigation. For all persons regardless of nationality, individualized AI-assisted analysis must be proportionate to the security interest served, may not be initiated based solely on demographic characteristics or political expression, and AI-generated outputs may not serve as the sole basis for initiating individualized scrutiny. Heightened protections for all persons in the U.S. regardless of status. Permits targeted analysis of identified subjects, aggregate research, and conflict zone analysis that improves noncombatant protection.
Transparency via yearly internal reports: An advisory seven-person Defense AI Review Body of senior staff, appointed by and reporting to the Chief Scientist.
Superseded by future laws: If Congress passes substantial legislation governing these usages, the Chief Scientist and Review Body (by supermajority vote) can retire one or both Standards.
The Company will not accept âall lawful useâ as its standard. Where âall lawful useâ language is demanded, The Company will require access to the legal memoranda establishing the lawfulness of intended uses. That transparency gives The Company the information to evaluate each use case against its Standards. Some will meet The Companyâs standard. Some wonât. The ones that donât, The Company declines.
With the help of TomSmith, I got feedback from experts in military and surveillance law. In particular, I got feedback from a foremost legal expert on human/âAI warfighting integration. They said my Framework was âactually pretty goodâ :) and suggested improvements.
My lunch with Jeff
March 17th, 2026
A friend drove me down to Mountain View to meet Jeff. Wearing a crisp dress shirt and slacks, I walked through the Gradient Canopy office. I had the Framework in my bag and I had a question on my mind: âWhat, if anything, does Jeff want to do?â. Was I going to meet a crusader? A bystander? A strategist?
A month prior, I asked for this lunch so we could discuss âconstructive optionsâ for making Googleâs contract situation more ethical. Would he have plans of his own? Surely he could. He had so much more visibility and experience. I readied myself to toss my Framework aside and follow a better plan devised using more information. I didnât care much. Even if Sundar adopted my Framework, I knew I was unlikely to be credited. That made me a bit sad, but I wanted to get the job done.
I had lunch with Jeff under the California sun. I proposed that Jeff head the potential Review Body, but he didnât take up the idea. Beyond that, I wonât discuss the details of our lunch. I can only point to his public conduct: He tweeted and signed an amicus brief in support of Anthropic. Google later signed the deal. Jeff is still at Google, despite his pledge.
Searching for another path to impact
I had expected thisâI had simply judged the odds good enough to justify the shot. Without Jeff championing the Review Body, the chances of success dropped a lot. I still thought the large possible benefits were worth continued effort on my part. The other obvious escalation pathway was to Demis Hassabis.
In 2014, Google acquired DeepMind on an explicit promise: its AI would never be used for military or weapons purposes. In 2018, all of DeepMindâs co-founders (including Demis) signed the FLI lethal autonomous weapons pledge, as did Google DeepMind as an organization.
Demis had already fought Sundar to ensure a future DeepMind AGI wouldnât be chained to Googleâs profit incentives (though he lost in the end). I thought, âDemis wonât quit over this. But if he pushes, he might get some of the transparency mechanisms.â I looked for a non-awkward way to get my proposal in front of Demis. Jeff could have sent it no problem, but I had to look elsewhere.
I looked. I did learn that there was one senior person taking real initiative and working hard to stop the deal. I appreciated that. But I only knew of one.
In any case, after a week of trying to escalate through management chains, I decided to just do the awkward way instead.
No one is responding, so why not just DM the CEO?
April 1st, 2026
After all, whatâs the worst that would realistically happen? In my estimation, he might say ânot appropriate, send through your manager next time.â Whatever.
My message to Demis
Demis, I drafted a Framework for military AI oversight at Google, along with two candidate standards (which can be considered separately). A foremost legal expert on human/âAI warfighting integration said the Framework is âactually pretty good.â The oversight is advisory, providing independent technical and ethical assessment of defense AI deployments.
Demis told me to get the Framework evaluated by two senior people working in GDM policy. I sent it to them. They left the message on read.
My Framework goes unevaluated
Busy guys being busy, perhaps. A few days later, I pinged them. One sent me to talk to some of their reports. About a week passed, then I spoke with those reports. They seemed excited about the Framework but said that I wouldnât hear back for months, which didnât fit the time pressure.
I returned to the senior policy people to talk about next steps. One wanted me to circle back to them with updates as the situation developed. A few days later, I gave gentle pushback. I explained the unknown but potentially short timeframe we confronted, pointing to the Pentagonâs January 9th memo giving ALL AI contractors a 180-day deadline (falling on July 8th) to accept âany lawful useâ contracts.[14] I basically said, âitâs fine if you think Demis shouldnât look at the Framework again, but I want you to make that determination either way.â I even offered to fly from San Francisco to London just to answer any questions they had about the Framework.
They left the message on read.
I still donât know what happened. The companyâs CEO wanted it evaluated, after all. I didnât expect them to loop me in, but I expected a âthanks, Iâll let Demis know my assessment.â Itâs possible there was some unknown but legitimate complication. In any case, Iâm not happy with this process.
Google quietly signs the deal
As reported on April 27th, 2026
That weekend prior, I had heard rumblings. Along with over 600 other employees, I signed a letter asking Sundar to say ânoâ to classified AI contracts.[15] I asked Jeff if there was anything I could do on an informal basis, crossing reporting lines and bureaucracy to help him get anything done that he wanted. Iâd work through the weekend, no problem, on whatever he thought was wise. Alas.
Google signs classified AI deal with Pentagon
The agreement allows the Pentagon to use Googleâs AI for âany lawful government purpose.â
Googleâs agreement requires it to help in adjusting the companyâs AI safety settings and filters at the governmentâs requestâŠ
The contract includes language stating, âthe parties agree that the AI System is not intended for, and should not be used for, domestic mass surveillance or autonomous weapons (including target selection) without appropriate human oversight and control.â
However, the agreement also says it does not give Google the right to control or veto lawful government operational decision-making.
I found out at 11:45 PM via a Signal group. Google never announced the deal internally. What surprised me was not that Google signed, but that the deal paid the barest of lip service to ethical concerns: the âshould notâ language is not binding.

My tweet.
I went to the fieldâs premier safety & ethics organization (IASEAI). I asked some of the most distinguished AI scientists (Bengio and Stuart). I built a coalition and a plan for Googleâs most outspoken executive (Jeff). I even cold-messaged the CEO of my company (Demis), whose lieutenants never evaluated the proposal. Besides Jeff, none took any visible action to stop the deal. And the deal contains no binding provisions, which is what Iâd expect if Jeff never threatened to walk.
The deal was inked.
But also, Google stopped bidding for a drone contract?
Google Drops Out of Pentagon Drone Swarm Contest After Advancing
Google abruptly dropped out of a $100 million Pentagon prize challenge to create technology for voice-controlled, autonomous drone swarms after it was among the successful submissions, according to people briefed on the matter.
The company notified the government it wouldnât participate further in the initiative, which seeks to create the technology needed to control drone swarms, on Feb. 11âa few weeks after the proposal was submitted, according to another person briefed on the matter. The decision followed an internal ethics review, according to records referencing it that were reviewed by Bloomberg News. Alphabet Inc.âs Google officially cited a lack of âresourcingâ when it pulled out of the contest, according to the records.
Apparently, Google does have an ethics review with teeth that bite, at least sometimes, on some projects. Thatâs good.
However, this doesnât exonerate Googleâs decision to sign the deal. Letâs charitably suppose that Google has a process which always blocks contracts which will obviously be used for weapons in particular.
As Iâll soon cover, Googleâs criterion is apparently that âthe benefits substantially outweigh the harms.â How can Google weigh that if Google canât know what âlawful purposesâ Gemini will be used for? Under an âall lawful useâ deal, there will no longer be any warnings which would make ethics-minded employees like Jeff or Demis uncomfortable.
The government isnât going to call Google and say âwe used Gemini in a kill chain to bomb a bunch of people.â Similarly, the CEO of Anthropic still doesnât know what role, if any, Claude played in the bombing of an Iranian girlsâ school. Even Anthropic doesnât know, and Anthropic has publicly demonstrated far more appetite for contract transparency than Google has.
Demis insists Googleâs AI principles âhavenât changedâ
Google DeepMind CEO Demis Hassabis on AI in the Military and What AGI Could Mean for Humanity
Interviewer: When Google acquired DeepMind in 2014 you signed a contract that said Google wouldnât use your technology for military purposes. Since then, youâve restructured. Now DeepMind tech is sold to various militaries, including the U.S. and Israel. Youâve talked about the huge upside of developing AGI. Do you feel like you compromised on that front in order to have the opportunity to make that technology?
Demis: No, I donât think so. I think weâve updated things recently to partly take into account the much bigger geopolitical uncertainties we have around the world. Unfortunately, the worldâs become a much more dangerous place. I think we canât take for granted anymore democratic values are going to win outâI donât think thatâs clear at all. There are serious threats.
So I think we need to work with governments. And also working with governments allows us to work with other regulated important industries too, like banking, health care and so on. Nothingâs changed about our principles. The fundamental thing about our principles has always been: weâve got to thoughtfully weigh up the benefits, and theyâve got to substantially outweigh the risk of harm. So thatâs a high bar for anything that we might want to do. Of course, weâve got to respect international law and human rightsâthatâs all still in there.
In particular, he says:
The fundamental thing about our principles has always been: weâve got to thoughtfully weigh up the benefits, and theyâve got to substantially outweigh the risk of harm.
Thatâs not a principle. A principle is something you commit to in advance so that you canât talk yourself out of it later, even when the benefits seem to outweigh the harms. One cannot violate a âprincipleâ of âIâll decide when I see it.â
Googleâs original 2018 AI principles committed that Google would not support specific use cases, leading to Google dropping its bid for a $10 billion contract in 2018. The principles included a section titled âApplications we will not pursue,â which said that Google would not design or deploy AI for weapons âwhose principal purpose or implementation is to cause or directly facilitate injury to people,â nor for surveillance âviolating internationally accepted norms.â
On February 4th, 2025, Demis co-authored a post announcing updates to those principles. The updated principles removed the prohibitions on weapons and surveillance.
Consider these statements: âDemis removed the prohibitions from Googleâs AI principlesâ and ânothingâs changed about our principles.â Both cannot be true.
Demis wanted GDM employees to trust him and to trust that DeepMind has a sufficiently strong review process. But Googleâs AI principles named things Google would not do, and then he removed those prohibitions, and finally told us nothing had changed.
On my last day, I pointed out this discrepancy in the discussion channel. Many GDM employees expressed their disappointment.
We can âwork with Western democraciesâ to âbeat Chinaâ without giving in to every demand Trump makes
When an AI leader says they need to âwork with Western democracies,â thatâs a hint theyâre doing something bad.
Demis justified breaking GDMâs no-weapons commitment by saying â[Google needs] to work with governmentsâ to ensure that democratic values win out. I think that imposes a false dichotomy. To see why, grant the whole worldview: that if the US doesnât adopt autonomous weapons, we lose the world to authoritarianismâUkraine falls, liberty crumbles, and a red wave consumes. Even with that strong assumption, âgive the Pentagon what it demandsâ isnât necessarily the best action for the world. You can, say, construct a governance framework restricting which use cases Google is willing to provide for its products. That would let Google provide the ethical uses (for âbeating Chinaâ) without the unethical ones.
Even if Google had been forced to sign, it could still spend its enormous influence lobbying Congress for legal safeguards. Capitulation was a choice.
Building a world-reshaping technology on personal trust
I used to think of Demis as a quiet, thoughtful guy doing the best he can in a demanding corporate structure. Again I return to the story of Demis trying (and failing) to split off Google DeepMind:
The Infinity Machine: Demis Hassabis, DeepMind, and the Quest for Superintelligence
âWhen we were negotiating with Google, we wanted to ensure safety in a way that would be trustless,â Hassabis said. âThatâs actually very difficult to do in reality.
âSafety isnât about governance structures,â he went on. âI mean, even if you have a governance board, it probably wouldnât do the right thing when it came to the crunch.
âSame thing with a safety charter. You can try to negotiate one. But itâs not realistic to create brightâline principles years in advance because youâll probably draw the lines in the wrong places. [âŠ]
âSo then I thought, why donât I go the other way? Take the energy that was going into the trustless negotiation and put it into creating real trustâtrust that was actually useful. Try leaning into Google rather than leaning out.
âAnd then of course two things happen. First, you are now at the table, so when a safety issue comes up, you can help to decide it. Second, you get to know the Google people and you rack up successes together. You canât just talk about trust. You have to earn it.
âAnd I think for me, and maybe for Mustafa, too, itâs about us growing up,â Hassabis mused. âWe went through those negotiations and we matured. Things arenât black and white, especially when you are dealing with a technology with unknown consequences.
âSo you have to be adaptable. You have to move from idealist to realist, but hopefully still with your values.â
Demis is wary of trustless structures. I think thatâs backwards: you should try to lower how much trust a system requires. The Framework I proposed rests on a single trust assumption: that the Chief Scientist is reasonable long enough to seat the Review Body. The Framework then manufactures justified trust through transparency and contract, not preventing unethical deals but adding friction. Demisâs objection is that a governance board âprobably wouldnât do the right thing when it came to the crunch.â True, but a person at the table is subject to exactly the same crunch but with no transparency and with worse incentives: equity, social bonds with colleagues, and a self-image tied to the company.
And notice how Demis arrived at his philosophy. He tried to build a lower-trust structure by spinning DeepMind out from Google under a semi-independent board. Sundar refused. Only then did Demis conclude that the answer was mutual trust and a seat at the table.
Try leaning into Google rather than leaning out.
And then of course two things happen. First, you are now at the table, so when a safety issue comes up, you can help to decide it. Second, you get to know the Google people and you rack up successes together. You canât just talk about trust. You have to earn it.
So what has his seat produced? Demis has been at the table for every contract in this essay. The classified deal made zero binding concessions to the employees raising ethical concerns. Maybe his presence averted something worse, but Googleâs terms were near the floor of what I imagined possible. The ethical terms are non-binding and therefore weaker than OpenAIâs. If his seat were worth what he says, youâd expect more to show for it.[16]
Reflections
Google DeepMind was an experiment in governance. The cofounders sold to Google on a promise never to power weapons and fought for a semi-independent governance structure. Sundar refused it. Googleâs 2018 AI Principles were imposed by employee pressure but later quietly defanged by leadership.
Hereâs the result of GDMâs experiment: it failed.
When profit and pressure met ethical commitment at Google DeepMind, pressure won and pledges lost. When profit and pressure met ethical commitment at Anthropic, ethics won. So the lesson is not âno one ever takes a stand.â The lesson is that society cannot rely on ethics-motivated people standing firm.
I know the other options donât look great. Congress remains a potted plant in the corner. But we should at least stop telling ourselves that a seat at the table works.
How can a pledge-signer remain at GDM?
Jeff Dean, Demis Hassabis, Shane Legg, and other senior employees pledged to âneither participate in nor support the development, manufacture, trade, or use of lethal autonomous weapons.â Google signed the classified deal, yet they remain.
One might defend: âthe deal simply doesnât prohibit autonomous weapons, thatâs not the same as actively supporting autonomous weapons.â Googleâs contract withholds certainty from a concerned pledge-signer, but a blindfold does not absolve responsibility.
Your company is trying to make and then supply the best AI in the world to a military which wants[17] to use AI in lethal autonomous weapons. Your company signed away its ability to restrict use cases. You chose to stay and continue building that AI.
That looks a damn lot like âsupport the development of lethal autonomous weaponsâ to me.
What should a pledge-signer do? I see three honest options: explain publicly how staying is consistent with the pledge, say plainly that you no longer hold it and why, or quit.[18] Wearing the pledge while saying nothing isnât one of them.
Keeping a seat at the table
But should GDM employees not stay to keep steering in a positive direction? To this I must object: âWhat steering?â. This deal may have been the clearest red line Googleâs Gemini project will ever face, and yet the deal came out with no concessions to ethics-concerned employees. If their âseat at the tableâ couldnât produce a single binding provision in that situation, then when would it?
Plus, a pledge is only worth the credibility behind it. When someone signs âI will not support the development of lethal autonomous weapons,â then stays while their company sells unrestricted AI to a military that wants exactly that, they teach every counterparty a lesson: these safety people will not act, even at their own brightest line. The next commitment they make is worth less. Eventually itâs worth nothing.
The weight of ethics
Where lies the blame? Pete Hegseth and Donald Trump, who intimidated the AI companies? Sundar Pichai, who signed the deal? Jeff Dean, whose leverage left no mark on the deal? The responsibility splits over them unevenly, but my attention rests on those with stated ethical commitments.
With Pete Hegseth, you at least know what youâre getting. âPersuade Pete to stop ordering war crimesâ is not an available strategy. But I feel uniquely disappointed in the consistent inaction of nearly all of these senior AI professionals who talk about ethics.
Why did they choose inaction? The answer does not seem clean and simple, but I think part of the answer is fear of the Trump administration.
A long-form interview with Geoffrey Hinton (April 26th, 2025)
Interviewer: Were you disappointed when Google went back on its promise not to use military AI?
Hinton: Very disappointed. Particularly since I knew Sergey Brin didnât like military use of AI.
Interviewer: Why do you think they did it?
Hinton: I donât have any inside information⊠I could speculate that they were worried about being ill-treated by the current administration if they wouldnât make weapons for the US.
What are the AI luminaries doing?
These people are clearly not cowards in general. For years, Stuart staked out the unpopular position that AI existential risk should be taken seriously. Hinton left the US in the 1980s due to his âdisapproval of military funding of artificial intelligenceâ and then left Google in 2023 to speak frankly about the risks of AI.
Geoffrey Hinton (June 10, 2026)
The only thing thatâs going to rein in those big AI companies is public pressure.
So where was the pressure?
Sometimes a person will ask, âwhat if IASEAI was just saving up political capital for an even more impactful moment?â. One answer is that âsaving capitalâ canât explain why IASEAI ignored low-cost opportunities (like Stuart connecting me with key Google decision-makers).
What Iâd expect, given Stuartâs career, is for him to speak out. Stuart gave hundreds of talks (to the UN, to the Senate, to an interviewer) railing against slaughterbots. He thundered against âwishful thinkingâ in the pages of IEEE Spectrum.[19] He made strong statements onstage at IASEAI closing. But faced with a real chance to speak out against a specific powerful adversary, he fell silent.
Why didnât Jeff put his foot down?
Jeffâs a tough case. Out of all Googleâs executives, he was the only one to act publicly. He signed the amicus and broke from his company. That probably made things awkward within the C-suite. I respect that.
He had the power to do more. And I really wish he had. I think he could have stopped the deal, yet he did not. He remains, yet I think he should not.
Breaking free of roles
I was a research scientist, you knowâone of hundreds at GDM. I have a picture of a âresponsibleâ research scientist in my head. The âresponsibleâ research scientist makes a tweet and then sends their manager a concerned message about ICE contracts. The âresponsibleâ research scientist doesnât cold-message Google executives.
Rarely, a person will break their bounds. They step outside of the fear which held them. They admit a difficult truth. They act in a way that would have surprised them the day before. I do not understand why people do or donât break their bounds.
I know what broke my bounds in this instance. I have a regular reminder in my phone which shows me a picture of Alex Pretti. In one January moment, my anger flared so hot that its only outlet was to find a plan which could actually work. A mere tweet would do nothing and would count for nothing. Only a good plan would satiate. The anger burned through my bounds and broke them.
When I got scaredâand I didâIâd think about Minneapolis. Iâd think about ICE shooting people in the street and dragging people from their homes.
Why I left Google DeepMind
When an employee leaves a top AI lab, itâs often into the arms of another. They usually rack up a huge bonus that way. Thatâs not what I did: I didnât flirt with competitor labs and I declined outreach from the OpenAI safety team. Iâm unemployed right now.
In February, I realized that Google would probably sign the deal, which made me think about the door. I realized maybe I should leave and maybe I could do better AI safety work elsewhere. But I think I would have stayed a few more months if they hadnât signed the deal. When Google signed, I just couldnât do any more work. My brain said âno.â
When I next went to the office, the building felt like a memory. Like going home to your old high school: it used to be the center of your hopes and dreams, and then one day you just know that you donât belong there anymore.
The view from my desk at GDM. March 2024.
Appendix: Anticipated questions
What if the people you critique were saving their political capital?
Indeed, itâs not always rational to say what you think the moment you think it. However, âsaving political capitalâ explains avoiding a costly public statement. It doesnât explain refusing costless private help. I asked IASEAI for a private introduction and got nothing.
Maybe they thought you werenât worth their time; you arenât entitled to their help
Absolutely. No one should be castigated simply because they didnât follow my particular recommendations. But what I would expect to see is any kind of action at all.
More broadly, sympathetic stories predict visible impact, including âvisible in its consequences.â Thatâs part of why Iâm comfortable guessing that Jeff did not put his foot down and threaten to walk. If he had put his foot down, I expect the world would look different to me: in particular, I would expect the classified deal to contain at least some binding provisions.
Every person shouldnât have to speak out about every issue
Yes, but if you promise to take an action and then donât, thatâs different. IASEAI promised to hold a member poll and never did. Further, if you built a significant part of your identity on opposing something,[20] I think itâs fair to discuss the decision to stay silent while that thing is decided. Stuart is simply the clearest case. He spent a decade as the loudest voice against autonomous weapons, then went quiet at the first real collision between modern AI and military use.
Even if Google had adopted your Framework, the Pentagon would have refused
I agree. xAI would still have given over their AI. But if Google had given signs of independence earlier, it could perhaps have built a coalition with OpenAI and Anthropic.
Consider also that Anthropic taking a stand is one tech company. If a company like Google also defied the administration, I think that would have transformed the tech industryâs meekness into independence. InsteadâŠ
Pentagon will ânever againâ rely on a single AI provider, official says
Defense Under Secretary for Research and Engineering Emil Michael said new agreements with Big Tech companies are a âcounterstatementâ to the ongoing Anthropic-Pentagon conflict as the agency prioritizes flexible contracts. [âŠ]
Michael continued to say that the new deals with Amazon Web Services, Google, Microsoft, NVIDIA, OpenAI, Reflection, Oracle and SpaceX are âa statement by the biggest tech companies in the world who are involved in the AI space ⊠and have them say, âWe support the Department of War, we support the U.S. government, and we support the⊠armed services for all lawful use cases.ââ
Despite the Pentagonâs policy, Jeffâs leverage mattered. The Pentagon would have refused, yes, but then Google could have walked away.
Does this have any impact on existential risk from AI?
Yes.
When building an advanced AI system, best practice is to make a âsafety caseâ which explains why the system will be aligned and will not cause catastrophic harm. I think any credible GDM safety case would lean heavily on monitoring the âchain of thought,â a mechanism their Frontier Safety Framework discusses.[21] For the unfamiliar, a chain of thought is the AI roughly explaining what itâs doing and why. Itâs not perfectly accurate, but itâs extremely informative.
An AI that wants to hurt us wonât announce it to our faces because we would shut it off and then it couldnât achieve its (misaligned) goals. So the AI will likely be deceptive. One of the best ways we can detect deception is by looking at the chain of thought. To look at the chain of thought, there must be trained human overseers who can access and analyze the data. But no one can do that: Google is handing over its AI to run in a secured military data center that, by default, wonât have trained overseers performing this analysis, and that data center obviously isnât transmitting data back to Google![22]
Iâm not saying that Google engineers should read what the military is doing. Iâm saying that by default, there wonât be appropriately trained military engineers who will perform this monitoring. If an AI is not monitored for deception in its chain of thought, it will have an easier time causing catastrophic damage to humanity by scheming, deceiving, and trying to take over. Thatâs bad.
Unfortunately, thatâs only half the problem! A military deployment setting without chain of thought deception monitoring would be a juicy target for a rogue AI, offering both weak oversight of scheming and access to powerful decision-makers and infrastructure.[23]
Hopefully, the military (in conjunction with the US CAISI) develops expertise, caution, and control procedures for monitoring and containing rogue AI systems.
Appendix: âDonât worry, itâs only API accessâ
A common reassurance from management:
We believe that providing API access to our commercial models, including on Google infrastructure, with industry-standard practices and terms, represents a responsible approach to supporting national security.
âAPI accessâ is misleading. When you or I think of âAPI access,â we think of sending requests to the AI provider, which can then scan the requests and ensure the uses are acceptable.
Imagine a commander on a mission consulting with Gemini. Do you think heâs sending plaintext queries to Google, where Google could (theoretically) read up on the classified mission details? No. Thatâd be crazy.
Instead, my guess is that Google runs on-premise API access. Hereâs the story that makes sense to me: the government has a secure Cloud computing cluster with no connection back to Googleâs server farms. Google drops off one or more servers which expose a Gemini API endpoint to the militaryâs cluster.
âAPI access only,â then, would be technically true but misleading (wrongly suggests centralized supervision by Google) and irrelevant. What protection does API access provide? The problem is using Gemini to assist in potential war crimes and mass profiling of dissidents. Thanks in part to Google, however, these terms are now âindustry-standard practiceâ (outside of Anthropic).
- ^
Technically, Iâm worried about mass profiling from AI. Surveillance concerns data collection. Profiling takes data and draws conclusions, like âdoes this person dislike the government?â.
- ^
Google replies that immigration agents are merely using commercially available cloud services. But the problem was never that Google provided special services; itâs that Google provided services to ICE at all.
- ^
The ToSâs exceptions didnât apply in the case of the student protester.
- ^
Judge Lin later said that the Pentagonâs supply chain risk designation was âclassic illegal First Amendment retaliation.â
- ^
Stuartâs âextortion racketâ comments seemingly only featured incidentally in one news round-up by The Information.
- ^
On that Thursday in the same venue building, a four-hour workshop convened on how to make AI red lines âverifiable and enforceable.â Participants were asked: what is the biggest obstacle to these red lines? Political will.
- ^
Upon request, Mark did refund my membership dues.
- ^
In my GDM discussion message, I originally estimated âkilling over 150 people.â As of June 28th, 2026, the toll has risen to 215.
- ^
Throughout my internal campaign, I made sure not to talk to the media (even off the record). I wanted change from the inside and I wanted to do it right by people like Jeff.
- ^
The New York Times also reported:
A footnote in the A.I. letter to Mr. Dean said many of the signees opposed âwarrantless surveillance of any citizens of the world.â But they decided to exclude that from the letter âto increase the probability of achieving our request.â
I regret that decision. âAmericans onlyâ protections lined up with Anthropicâs red lines, but âAmericans onlyâ was too small of an ask. Donât negotiate away what you want before the negotiations even begin! My proposed contract language later demanded more protection for non-Americans.
- ^
I was responsible for 8 of the 18 GDM signatures on the amicus brief. The count was low because it was impromptu.
- ^
This is why I think my actions led to additional Pentagon wariness. I introduced Jeff (and nearly half of the Google signers) to the amicus brief. They signed. The Pentagon hesitated in part due to the Google signatures on the amicus brief.
- ^
Large coalitions have problems here. Imagine my plan relied on several senior GDM employees telling Sundar theyâll walk if the deal gets signed. Sundar doesnât need to talk them all down; he would just need to fracture their intent to act. Offer the more senior employees a $15 million retention bonus. If a few bite, the coalition crumbles. No one knows how on board the others really are, and they donât think they individually can bring about change by quitting, and so they donât quit.
- ^
The governmentâs July 8th deadline was another reason that âGoogle will just wait it outâ struck me as implausible.
- ^
I didnât think that âno classified contractsâ was the right line to draw, but I thought it was better than no line at all.
- ^
Andreas Kirsch, a current GDM research scientist, independently reaches the same conclusion in his essay âTrust is not Governance.â
- ^
In 2026, the Pentagon asked for more money for autonomous weapons than for the US Marines!
- ^
I know of exactly one other person who left over the deal: RenĂ© Mayrhofer, a director for Android platform security. âManagement has lost its moral compassâ, he stated. He apparently will serve his notice period from mid-June until August. Brave.
- ^
In summary, we, and many other experts, continue to find plausible the view that autonomous weapons can become scalable weapons of mass destruction. Scharreâs claim that a ban will be ineffective or counterproductive is inconsistent with the historical record. Finally, the idea that human security will be enhanced by an unregulated arms race in autonomous weapons is, at best, wishful thinking.
- ^
The luminaries made autonomous weapons one of their causes. In September 2025, at the UN General Assembly, the Global Call for AI Red Lines gathered more than 300 signatories, among them 15 Nobel and Turing laureates. The Call declared that certain AI uses should be prohibited by international agreement, including mass surveillance and lethal autonomous weapons.
Stuart signed it. So did Bengio, Hinton, and Nitzberg. They signed the abstract principle in September 2025. When the concrete test arrived in February 2026, their IASEAI signed no statement at all.
- ^
Frontier Safety Framework v3.1, section 3.2.1, Ctrl+F âchain-of-thought.â
- ^
Classified deployments run at authorization levels (like IL-6) that mandate isolation from commercial cloud infrastructure.
- ^
Itâs perhaps even more important to monitor the AI during a recursive self-improvement scenario, but that doesnât detract from my point. Once self-improvement completes, the AI would need to act on its goals. An incautious military deployment decreases the minimal capability advantage that a misaligned AI needs in order to take over.
wild, sobering and inspiring. I especially appreciate that you grounded your piece by starting with 2 of the lives lost, good reminder of the stakes behind abstract policy and corp decisions⊠when high-stakes incentives push for compliance the desire to preserve standing and influence almost always outcompetes abstract moral commitment. Thank you for your courage and transparency.