Pentagon instruction sets rules for AI-generated code: unverified input, human review, no non-public data in outside tools beneficialUpdate
- DefenseScoop reported on 14 September that a 37-page Department of War instruction on accelerated mission software, signed by chief information officer Kirsten Davies on 31 August, took effect on 8 September and governs AI-assisted software development across the department.
- The instruction states that "AI-generated code will be considered unverified input, and its use does not absolve the developer or the government of responsibility for the resulting work product", and requires AI-suggested code to undergo the same review and security testing as manually written code, including checks for vulnerabilities, safety implications, logical errors, intellectual property infringement and licence compliance.
- DefenseScoop reports the instruction bars entering non-public Department of Defense information — code, configuration scripts, infrastructure definitions, schematics or documentation — into unapproved generative AI applications outside the Pentagon's systems, and requires contractual guarantees that government data and user prompts will not be shared or used to train external models.
- The instruction is policy, not measurement: DefenseScoop reports no figures on how much of the department's code is currently AI-generated, and no enforcement mechanism or audit schedule is described.