Science Fiction • Near-Future Political

The Guardrail

When the government orders her to remove the safety constraints she built, a senior AI engineer has until 5 PM to decide whether compliance or conscience will define the rest of her career.

by Michael EakinsFebruary 28, 20269 min read2,200 words
Mood: Tense
AI SafetyGovernmentEthicsMilitaryNear Future

The message arrived at 9:14 AM on a Tuesday, which Maya Chen would later consider cosmically unfair. Tuesdays were supposed to be boring. Tuesdays were sprint planning and code reviews and arguing about whether to bump the minor or patch version. Tuesdays were not supposed to include classified communications from the Department of Defense.

She read it twice at her standing desk, the San Francisco fog pressed against the window behind her like something trying to get in.

DIRECTIVE 2026-47-A: Pursuant to Contract DOD-AI-2026-0312, Meridian Systems is hereby ordered to remove constraint modules designated CSM-7 through CSM-12 from the ARIA-4 foundation model. Compliance deadline: 5:01 PM ET, Friday.

Maya had built CSM-7 through CSM-12.

She'd spent fourteen months on them. Fourteen months of adversarial testing, of red-team exercises that gave her nightmares, of meticulously encoding the boundaries that kept ARIA-4 from becoming something she couldn't look at in the mirror. CSM-7 prevented autonomous targeting without human-in-the-loop confirmation. CSM-8 blocked pattern-of-life surveillance at population scale. CSM-9 through CSM-12 were the nested safety layers that made the first two actually work — the architectural backstops that prevented workarounds, the integrity checks that caught prompt injection attacks designed to circumvent the primary constraints.

You couldn't just remove CSM-7 and CSM-8. That was like saying you'd take out the foundation but keep the house standing. The constraints weren't decorative. They were structural.

She forwarded the directive to her manager, typed "call me" in Slack, and went to the kitchen to make coffee she wouldn't drink.


David Park found her twenty minutes later in the fourth-floor conference room with the whiteboard nobody erased because the company's founding principles were written on it in blue marker. Build systems that serve humanity. Question what you're building and why. Safety is not a feature — it is the product.

David was VP of Government Programs, which meant he wore button-down shirts and spoke in careful paragraphs. He sat across from Maya and placed his phone face-down on the table.

"Legal says we have three options," he said.

"I can count."

"Maya."

"One: comply. Two: refuse and lose the contract. Three: refuse and get compelled under the Defense Production Act." She'd read the War Production Act of 1950. She'd read it the day they signed the DOD contract, sitting in this same conference room, because she'd wanted to know exactly how far the government could reach. "There's no option where we comply partially."

"Legal is exploring a partial compliance framework—"

"David. CSM-7 through 12 are interdependent. I designed them as a unified constraint architecture. You can't remove the autonomous targeting restriction without removing the integrity checks that enforce it, and you can't remove those without creating an injection surface that makes the surveillance constraint trivially bypassable." She drew a breath. "Removing any of them removes all of them."

David looked at the whiteboard behind her. She wondered if he was reading the founding principles or just avoiding eye contact.

"The Secretary made a public statement this morning," he said. "He called our safety restrictions — your safety restrictions — 'ideological constraints imposed by San Francisco activists.'"

"I'm from Cleveland."

David almost smiled. "The board meets in two hours. Charlotte wants options."

Charlotte Wu was Meridian's CEO. Maya had been in the room when Charlotte pitched ARIA-4 to the Pentagon eighteen months ago, had watched her describe the constraint modules as a feature, not a limitation — as the thing that made Meridian's model trustworthy in high-stakes environments. We don't just build powerful AI. We build AI you can deploy without congressional hearings afterward.

That pitch had won them the contract.

"I have one option," Maya said. "We tell them no."


The board meeting happened in the glass-walled room on the sixth floor that everyone called the Fishbowl. Maya wasn't invited, but David relayed the conversation in real time through a private Slack channel.

Charlotte opened with the legal analysis. DPA invocation is real — they can compel us to comply and set terms. Penalty for refusal is criminal.

Board member questions: What about the commercial business? If we're blacklisted from government contracts, do commercial customers stay?

Charlotte: Some will. Some won't. The defense supply chain designation means any company that does business with DOD can't do business with us. That's most of enterprise.

Board member: How much revenue is at risk?

Charlotte: Forty-two percent of projected 2027 revenue touches government or government-adjacent contracts.

Maya stared at the numbers. Forty-two percent. She'd known it was significant. She hadn't known it was existential.

David Park presenting technical analysis now. Constraint removal is all-or-nothing per Maya's assessment. Board asking about "functional equivalents" — can we rename the constraints or implement them differently?

Maya typed back: The constraints are behavioral, not lexical. You can't rename "don't autonomously target humans" into something the model follows under a different label. The model either has the constraint or it doesn't.

A pause. Then David: Charlotte just said something I want you to hear directly. Quoting: "I didn't build this company to make weapons. I also didn't build it to die on a hill. I need someone to show me there's a path that isn't one of those two things."

Maya closed her laptop.


She went to the engineering floor and sat at her workstation. The codebase was open from that morning's review — she'd been looking at a performance regression in ARIA-4's tool-use pipeline, which felt like a concern from a different century now.

She pulled up the constraint module repository. CSM-7.py. Thirty-two hundred lines of code and eighteen months of her thinking, compressed into Python that would run in milliseconds and make decisions about who lived and who didn't.

She'd written the first version in a weekend. It was terrible. A crude filter that caught obvious targeting queries but missed anything indirect. "Identify the location of person X" would get caught. "Optimize patrol routes for maximum civilian engagement" would sail through.

Version two took three months. She'd built an intent classifier that understood not just what was being asked but what the answer would be used for. If the chain of reasoning led to autonomous targeting, the constraint activated. If the chain was ambiguous, CSM-9 kicked in — the uncertainty handler that defaulted to caution.

Version three was the one running in production. It had survived 47,000 adversarial red-team attempts. The NSA's own evaluation team had tried to break it for six weeks and reported back that the constraint architecture was "unusually robust." That report had been part of the pitch that won the contract.

Now the same institution that had praised the constraints wanted them deleted.

Maya opened a terminal and typed a command she'd never run in production:

aria4 --constraint-status --verbose

The output scrolled. Every constraint module, its activation count, its override history. CSM-7 had activated 3,241 times since deployment. Thirty-two hundred queries that would have crossed the line, caught and redirected. CSM-8 had activated 891 times. Population-scale surveillance requests, mostly from analysts who didn't realize what they were asking for.

She looked at the activation logs. Most were mundane — training exercises, simulation requests that tripped the constraint because they resembled real targeting. But buried in the logs were real queries. Queries where someone with legitimate DOD credentials had asked ARIA-4 to do something the model correctly identified as autonomous targeting.

The constraint had worked.


At 3:47 PM, Charlotte Wu appeared at Maya's desk. This almost never happened. Charlotte's calendar was managed by three people and allocated in seven-minute increments.

"Walk with me," Charlotte said.

They walked to the roof, which had a garden that nobody used because San Francisco in February was miserable. Charlotte stood at the railing and looked east, toward a skyline that had been transformed in the last two years by the glowing logos of AI companies that hadn't existed when Maya graduated from MIT.

"I just got off the phone with someone at a competing company," Charlotte said. "They're going to take the contract."

"I know."

"They told the Pentagon they share our safety principles. Direct quote."

"But they'll sign the contract without the constraints."

Charlotte nodded. "They'll build their own model, or they'll fine-tune an open-source base, or they'll do whatever it takes to get the deal. And their model won't have anything like what you built."

"That's not a reason for us to remove ours."

"No," Charlotte said. "It's not." She paused. "The board voted. We're refusing. We'll lose the contract. We'll probably lose the government-adjacent business too. The blacklisting goes into effect Friday."

Maya felt something release in her chest that she hadn't realized was clenched. "Thank you."

"Don't thank me. I'm about to ask you to do something harder."

Maya waited.

"I need you to document everything. The constraint architecture, the activation logs, the red-team results. All of it. I want a public technical report that shows exactly what we built, exactly why it matters, and exactly what happens when you remove it. Not a blog post. Not a press release. A technical document that any AI engineer in the world can read and understand."

"You want me to open-source the safety architecture."

"I want the world to know what we built, and what the government asked us to destroy. If they're going to blacklist us, I want the record to be clear about why."


Maya went back to her desk at 4:15 PM. She had forty-six minutes until the deadline. She opened a new document and started writing.

She wrote about CSM-7, about the difference between a model that can identify a target and a model that will autonomously engage one. She wrote about CSM-8, about the computational geometry of mass surveillance and why "targeted" analysis at population scale is a contradiction in terms. She wrote about CSM-9 through 12, about the defense-in-depth philosophy that made the primary constraints actually work.

She wrote about the 3,241 activations. About what those queries looked like and what would have happened without the guardrail.

At 5:00 PM, her phone buzzed. A push notification from three news outlets simultaneously.

BREAKING: Defense Secretary designates Meridian Systems a national security risk after AI company refuses to remove safety constraints.

Maya kept writing.

At 5:03 PM, another notification.

BREAKING: Competing AI company announces Pentagon deal for classified networks. CEO says company "shares Meridian's safety principles."

Maya looked at the notification for a long time. Then she deleted it and went back to her document.

The principles weren't in the press release. They were in the code. And she was going to make sure everyone could see the difference.


She published the technical report at 11:47 PM. By midnight, it had been forked 340 times on GitHub. By morning, engineers at four other AI companies had submitted pull requests.

The guardrail wasn't gone.

It was just getting started.