Pentagon rules treat AI code as unverified input
A Defense Department instruction signed August 31 and effective September 8 sets rules for AI-assisted mission software. The instruction says developers remain responsible for the security, function and integrity of code that AI creates or changes. A person must review and approve every safety-critical change.
Verified 12:52 PM PDT · 2 original sources
Teams must give AI code the same review and security testing as human-written code. They must record models, versions and significant datasets in a software evidence package. They cannot send nonpublic defense code or system details to unapproved outside services.
The instruction creates these duties, but it does not show whether every program follows them. An inventory can list a model, but it cannot show whether the model's code was safe. Human approval can turn into a checkbox as the volume of reviews rises. The department has not published compliance results or an example of the rule stopping a deployment.
Contract language, program audits and software evidence packages could show whether teams record their models and datasets. Rejection counts could show how often human reviewers stop AI changes. Post-deployment tests could show how the department checks safety-critical code. Enforcement against unapproved tools would show whether breaking the data rule has consequences.
Audit the story
Original sources
Company claims remain company claims. Follow the reporting and judge the evidence directly.
- U.S. Department of DefenseDoD Instruction 8430.01P: Accelerated Mission Software ↗
- DefenseScoopPentagon sets procedures for AI-assisted software development ↗
Continue the edition