Governments pay close attention to artificial intelligence built by commercial technology companies for one structural reason: the same models, chips and engineering talent serve civilian and military purposes with very little modification. That is what makes AI a dual use technology, and dual use technologies have historically attracted export controls, procurement rules and published ethics frameworks. All three now exist for AI, and all three are public documents you can read yourself.
This article deliberately sticks to what is documented. Reporting on this subject is full of paraphrased remarks and anonymous sourcing, and the underlying primary record is both public and more precise than the coverage of it. Where a claim cannot be traced to an official document, it is left out here.
Why AI counts as a national security technology
Dual use is the whole of it. A model that identifies objects in video can sort your photo library or process surveillance footage. A cluster that trains a language model can also run simulations. A chip designed for recommendation systems is the same chip that accelerates anything else built on the same mathematics. There is no meaningful technical line between the civilian and military versions, which means policy has to draw the line somewhere else: at who may buy the hardware, at who may receive the technology, and at what the buyer promises to do with it.
That is why the policy instruments look the way they do. You cannot regulate a matrix multiplication, so governments regulate compute, contracts and conduct instead.
Project Maven and the pattern it set
On 26 April 2017 the Deputy Secretary of Defense signed a memorandum establishing an algorithmic warfare team, publicly known as Project Maven. The stated objective was to turn the enormous volume of data available to the Department of Defense into actionable intelligence and insights at speed.
The first assignment was concrete rather than speculative. The team was to apply computer vision to full motion video collected by tactical drones, automating object detection and classification so that analysts spent less time watching footage and more time on judgment. The intelligence workflow it targeted is called processing, exploitation and dissemination, and the bottleneck was human attention.
Maven matters here not because of any single contract but because it set the template. A military organization identified a capability that existed commercially, bought it rather than building it, and in doing so created a relationship between defense requirements and a commercial engineering roadmap. Every subsequent argument about technology companies and defense work is a variation on that arrangement.
Export controls: regulating the compute
The most consequential US policy lever is not procurement, it is export control. The Bureau of Industry and Security within the Commerce Department restricts exports of advanced computing semiconductors and semiconductor manufacturing equipment, and it has repeatedly expanded those restrictions and added companies to the Entity List.
The reasoning is published rather than inferred. In a January 2025 action, the Bureau stated that advanced AI capabilities, facilitated by supercomputing and built on advanced semiconductors, present US national security concerns because they can be used to improve the speed and accuracy of military decision making, planning, and logistics. The same action described the controls as crafted to limit efforts to obtain the advanced computing semiconductors needed to develop and produce technologies such as AI used in military applications.
Two things follow for anyone building with AI commercially. First, the hardware supply chain is a regulated space, so who you buy from and where your capacity sits are compliance questions and not only procurement questions. Second, this is the most actively revised area of AI policy, with rules amended, replaced and rescinded frequently enough that the version you read last year may not be current.
The rulebooks that governments publish
Alongside restrictions, governments publish expectations. Two US documents are referenced constantly and both are short enough to read in an afternoon.
The Department of Defense adopted five ethical principles for artificial intelligence on 24 February 2020, applying to combat and noncombat uses alike.
| Principle | What the Department commits to |
|---|---|
| Responsible | Personnel exercise appropriate levels of judgment and care and remain responsible for development, deployment and use. |
| Equitable | Deliberate steps are taken to minimize unintended bias in AI capabilities. |
| Traceable | Relevant personnel understand the technology and the processes behind it, with transparent and auditable methodologies, data sources, design procedure and documentation. |
| Reliable | Capabilities have explicit and clearly stated uses, and their safety, security and effectiveness are tested and assured within those uses throughout their lifetimes. |
| Governable | Systems are engineered to detect and avoid unintended consequences, and can be disengaged or deactivated when they behave unexpectedly. |
The National Institute of Standards and Technology published the AI Risk Management Framework, document NIST.AI.100-1, on 26 January 2023. It is explicitly voluntary, intended to improve the ability to incorporate trustworthiness considerations into the design, development, use and evaluation of AI products, services and systems. Its structure is four core functions: Govern, Map, Measure and Manage. Because it is voluntary and sector neutral, it has become the common vocabulary that procurement documents and internal policies borrow from, which is a larger practical influence than its legal status suggests.
What companies publish in response
Commercial AI developers publish their own frameworks, and those documents change over time. Google is the clearest example because both versions are public.
In a post dated 7 June 2018, Google set out AI principles that included a list of applications it said it would not pursue. That list named weapons or other technologies whose principal purpose or implementation is to cause or directly facilitate injury to people, alongside technologies likely to cause overall harm, surveillance violating international norms, and uses contravening international law and human rights principles. The same post drew a distinction, stating that while the company was not developing AI for use in weapons, it would continue its work with governments and the military in many other areas, listing cybersecurity, training, military recruitment, veterans’ healthcare, and search and rescue.
Google’s currently published AI principles page is organized differently, around three principles: bold innovation, responsible development and deployment, and collaborative progress. The current page describes human oversight, due diligence and feedback mechanisms, and says the company develops and deploys models where the likely overall benefits substantially outweigh the foreseeable risks. Google also publishes annual Responsible AI Progress Reports.
The useful observation is not about any one company. It is that voluntary corporate commitments are revisable documents, published by the party they bind, with no external enforcement. Read them as statements of current intent rather than as constraints of the kind an export regulation imposes.
What this means if you build with AI
Know where your compute is and where it came from. Hardware and cloud capacity sit inside a regulated supply chain, and that is now a standard part of vendor due diligence rather than an exotic concern.
Expect the government frameworks in your paperwork. The NIST functions and language resembling the Defense Department’s five principles turn up in enterprise questionnaires and public sector contracts regardless of whether you sell to government.
Do not treat a vendor’s published principles as a guarantee. They are unilateral and revisable. If a limit matters to your organization, it belongs in your contract, not in a citation to someone’s blog post.
Check dates on everything. This policy area moves faster than almost any other, and a confident summary written eighteen months ago may describe rules that no longer exist.
Frequently asked questions
What is Project Maven?
A Department of Defense effort established by a memorandum dated 26 April 2017 to apply machine learning to military data. Its stated objective was to turn the enormous volume of data available to the Department into actionable intelligence and insights at speed, beginning with computer vision applied to full motion video from tactical drones.
Why does the US control exports of AI chips?
Because the Commerce Department’s stated position is that advanced AI capabilities, built on advanced semiconductors, present national security concerns since they can improve the speed and accuracy of military decision making, planning and logistics. Controlling the hardware is treated as a practical way to control the capability.
Is the NIST AI Risk Management Framework legally binding?
No. NIST describes it as intended for voluntary use. Its influence comes from adoption: procurement documents, contracts and internal governance policies borrow its four functions and its vocabulary, so many organizations end up following it through commercial pressure rather than legal obligation.
Do the Defense Department’s AI principles apply to contractors?
The principles were adopted by the Department for its own development, deployment and use of AI, covering both combat and noncombat applications. How they reach a supplier depends on the terms of the specific contract, which is where obligations of that kind are actually created.
Have technology companies changed their AI policies over time?
Yes, and openly. Google’s 2018 principles included a published list of applications it would not pursue, and its current principles page is organized around three broader principles instead. Both documents are public, which is the point: these are revisable statements of intent rather than fixed commitments.
The bottom line
Governments watch commercial AI because there is no technical boundary separating civilian capability from military capability, so the levers available to them are hardware, contracts and published expectations. Export controls on advanced computing chips are the hard instrument. Ethics principles and risk frameworks are the soft one, and their real influence comes from being copied into procurement language.
If you need to reason about this seriously, read the sources: the Defense Department’s five AI ethical principles, the NIST AI Risk Management Framework, and the Bureau of Industry and Security announcement on advanced computing controls. For related coverage of how large platform obligations reach ordinary users, see our explainers on the EU Android choice screens and how Google preview programs work, plus our notes on changes to Search Console reporting.
