Field note · AI & Technology

NSPM-11 Wants the Off-Switch on Your AI System - Not Yours, the Government's

NSPM-11 requires federal approval before an AI vendor can disable its own system. That inverts a standard commercial contract term.

AP
Anuraag Paul
Co-Founder & Chief Sustainability Officer, Newtral
Published
August 9, 2026
Last reviewed
August 9, 2026
Read time
7 min · 1,219 words
Current

On 5 June 2026, the White House signed National Security Presidential Memorandum 11, "Artificial Intelligence in the National Security Enterprise," rescinding and replacing the prior administration's AI national security directive. Most coverage since has read it as a procurement-acceleration memo: faster onboarding, fewer bureaucratic barriers, more vendors. That's accurate as far as it goes. But one clause in the memorandum's Assurance pillar does something coverage hasn't named - it requires AI vendors selling into national-security missions to give up a contract term they almost certainly assumed was theirs to keep.

Section 2(c) states that "the national security enterprise shall ensure, through contractual clauses or other means, that no commercial entity or adversary possesses the capability to prevent use of, disable or degrade, or materially modify without Federal Government knowledge and approval, an AI system that our men and women depend on for their missions." Read that against how commercial AI is normally sold, and the requirement is more specific than "make your AI secure." It's a requirement about who holds the off-switch.

01

What commercial AI contracts normally give the vendor

Cloud, SaaS, and API licensing agreements routinely reserve to the vendor some unilateral capability to suspend, throttle, or terminate a customer's access - for non-payment, for a breach of acceptable-use terms, or simply because the vendor decided to. This is a standard commercial default, not something NSPM-11 states or addresses directly; it follows from how software licensing is ordinarily structured, where the party that built and hosts the system typically keeps some measure of control over who gets to keep using it.

Section 2(c) requires the opposite arrangement for AI systems deployed in national-security missions: before a vendor exercises anything resembling that capability - disabling, degrading, or materially modifying the system - the federal government has to know and approve first. That's not a security best practice layered on top of a normal vendor relationship. It's a redistribution of who holds approval authority over the system's operation, and it runs against the commercial default rather than sitting alongside it.

This reading isn't NSPM-11 describing itself. It follows from placing Section 2(c)'s exact language next to how AI vendor contracts are ordinarily written, and no source consulted for this Article draws that connection - coverage of NSPM-11 treats Section 2(c) as a cybersecurity requirement about detecting tampering and ensuring reliability, not as a clause that reaches into contract structure.

02

The clause has an enforcement mechanism, not just a preference

Section 2(c) would be easy to read as aspirational language if it weren't paired with Section 3(b), which directs the Secretary of War, the Director of National Intelligence, and relevant agency heads to terminate contracts with companies showing "a pattern of conduct that is inconsistent with policies laid out in section 2 of this memorandum." Waivers exist - up to one year, for stated operational reasons - but every waiver has to be reported in writing to the Assistant to the President for National Security Affairs within 30 days. That's a compliance mechanism with a paper trail, not a suggestion agencies can quietly ignore.

Section 3(b) gives Section 2(c) an enforcement mechanism, not just a preference. An AI company already selling - or planning to sell - into this market under its standard commercial terms, the ones that likely include some version of vendor-side suspension or remote-modification rights, now has a specific reason to read those terms again. The requirement isn't hypothetical; it's attached to a clause that authorises pulling the contract.

A targeted search for an existing Defense Federal Acquisition Regulation Supplement clause addressing vendor-retained kill-switch or remote-disable capability specifically found none. That doesn't mean no comparable requirement has ever existed anywhere in federal contracting - it wasn't an exhaustive review, and government contracts have long included termination-for-default and audit provisions that constrain vendor action in other ways. What NSPM-11 does is state this specific requirement - government approval before a vendor disables its own AI system - explicitly and generally for AI, and name a mechanism for enforcing it.

03

Why this cuts differently by contract maturity

For a company that has already built defense-specific contract terms - the ones with security clearance requirements, classified data handling, and government-unique acceptable-use provisions baked in from the start - Section 2(c) is one more clause to check against an already-customised agreement. That's incremental work.

For a company selling the same commercial AI product to enterprise customers and the federal government off the same standard terms, it's a different problem. The suspension and termination rights sitting in that standard agreement's boilerplate were written for a commercial dispute, not a national-security deployment, and they were very likely never reviewed against a requirement like Section 2(c) because no such requirement existed when they were drafted. Section 1 of the memorandum itself notes that "previous administrations imposed undue bureaucracy that hampered the pace of AI adoption, fostered dangerous dependencies on single vendors" - the stated concern is about pace and dependency, not contract asymmetry specifically, but the practical effect of Section 2(c) is that dependency now runs in a specific, checkable direction: toward the government holding approval authority, not the vendor holding suspension authority.

The memorandum also sets a real deadline against this. Section 4(a) requires that within 120 days of signing - by approximately 3 October 2026 - the Secretary of War, the DNI, and agency heads with intelligence-community elements review and update procurement processes "to ensure the rapid onboarding of the most advanced AI models from multiple vendors." Faster onboarding and stricter vendor-control terms are arriving on the same clock. A vendor whose contract terms haven't been checked against Section 2(c) by then isn't positioned to move at the pace the rest of the memorandum is designed to enable.

04

What a well-run AI operation does differently

An AI company with existing or prospective national-security customers should be reading its standard commercial contract for exactly the clauses Section 2(c) targets - suspension rights, remote kill-switch or throttling capability, unilateral modification or update rights that don't require customer sign-off - and checking whether those clauses, as written, would survive a "pattern of conduct" review under Section 3(b). This isn't a security-posture exercise; it's a contract-language exercise, and it sits with legal and commercial teams as much as with security engineering.

It's also worth reading Section 5(e) and 5(f) closely: both set 120-day deadlines for a joint AI risk-management and assurance strategy and for standardized AI Test, Evaluation, Verification, and Validation methodologies, both to be developed before publication. Neither exists yet. A company waiting for that guidance before touching its own contract language is waiting for a document that will arrive, at the earliest, on the same October deadline Section 4(a) sets for procurement reform - after, not before, the pace of onboarding is set to increase.

NSPM-11 doesn't ban vendor-retained control outright, and it doesn't name a single company as failing to comply with anything - none has had the time to be found in breach of a memorandum that is nine weeks old. What it does is put a specific, quotable requirement into a document that a lot of coverage has summarized as "the government wants AI faster." It does - but Section 2(c) is the price of admission, and it's a price stated in contract terms, not in security architecture.

Noa · ESG compliance

Map your disclosures against AI & Technology.

Noa reads your disclosures, traces every number to its source, and flags what's missing.

Book a demo
AP
About the author
Anuraag Paul
Co-Founder & Chief Sustainability Officer, Newtral
View LinkedIn profile →