The Pentagon wants $30 million for an AI lie detector

Share
The Pentagon wants $30 million for an AI lie detector

The US military is polygraphing its own officers over press leaks, and now it wants machine learning to improve the instrument. Also today: the creator of Ruby on Rails retires from hand-writing code, and Gemini starts phoning businesses for you.

The Pentagon has asked Congress for $30.3 million over five years to build an AI-powered successor to the polygraph, to be run by the agency that screens federal employees. The line item sits in the Defense Department's FY2027 budget justification for the Defense Counterintelligence and Security Agency, under a project called Polygraph Next — also written as Polygraph+. It requests $6.421 million in FY2027 followed by $6.449 million, $6.158 million, $5.660 million and $5.654 million, summing to $30,342,000 with no end cost stated. The document's own description is the interesting part: by pairing "non-contact sensing systems and AI/ML-based scoring algorithms," it says, the program will "address emerging challenges in personnel vetting and insider threat detection." A pilot phase is penciled in from the first quarter of FY2028 through the third quarter of FY2029. Congress has not approved any of it yet, and the DCSA did not answer questions about which technologies it would actually use.

The timing is not accidental. Under Defense Secretary Pete Hegseth, the Pentagon has leaned on polygraphs to hunt leakers: around 50 members of the Joint Staff were tested in early September after coverage of depleted US munitions stockpiles in the war with Iran. Earlier work points at the intended mechanics — in 2023 the Defense Innovation Unit shortlisted Presage Technologies, which claims to read heart and breathing rate off ordinary cameras, and Altec Research, whose prototype tracks head movement, facial skin temperature and pore activity.

Our take: the flaw is not that the AI will be bad. It is that there is nothing for it to learn from. A polygraph measures stress, not deception, and no one has ground-truth labels for the tests already on file — so a model trained on them inherits the instrument's uncertainty and wraps it in a confidence score. Kyri Kotsoglou of Northumbria Law School calls the combination "the worst of both worlds," uncertainty layered on top of invalidity. The scale is what should worry people: the department employs 2.8 million staff, and the American Polygraph Association's own claimed 80–94% accuracy still produces tens of thousands of false accusations at that population. The instrument's real function has always been deterrence — as Erasmus University's Sophie van der Zee puts it, "if you know how it works, you can beat it," and it only works if people believe it does. The debate we covered this morning — Deep Dive: the US built an AI gate with no law and no staff — is the same shape: capability arriving well ahead of the standard that would govern it.


David Heinemeier Hansson, the creator of Ruby on Rails, told his own conference he has stopped writing code by hand — and says he hasn't written a line since around March. The announcement came in the opening keynote at Rails World 2026 in Austin on September 23, and DHH, who has spent 25 years as a professional programmer, framed it as a career change rather than a loss: "English is a better programming language than Ruby," he told the room, calling the shift "the biggest thing that has happened in the history of computing." The numbers he offered are striking, if imperfect — roughly 150,000 lines of agent-written code in August against a hand-written personal average near 30,000 a year, with Ruby down to about 3% of his output. His company, 37signals, now treats manual coding as an exceptional state, and he said its HEY rewrite in Rust runs at 99% less CPU and 95% less memory.

Treat the comparisons as directional rather than measured: the line counts set agent-written Rust against hand-written Ruby, an apples-to-oranges pairing DHH concedes, and "by the end of the year, virtually all programmers" is a prediction, not a finding. The Rails community's reaction is the more useful signal — Ruby Weekly devoted an issue to it, developer write-ups pushed back on the history he used to make the case, and the Rails Foundation changed its motto from "Code to IPO" to "Prompt to IPO." We have run the same experiment in a more controlled setting: Copilot made Okta's engineers faster but not more productive — individual hours saved, company output unmoved.


Google is testing a feature that lets Gemini place real phone calls to businesses on your behalf. Called "Call for Me," it is an early preview for Pixel 11 owners in the US with a Gemini subscription running the beta version of the Phone app. The assistant dials from your own number and handles the ordinary errands — reservations, stock checks, appointments, waiting on hold through a phone menu — while you watch a live transcript and can take over mid-call. It will not call emergency services, and Google says it is starting small because "real-world conversations are nuanced." A narrower version, "Ask for Me," shipped last year for price and availability enquiries; Meta's Muse and Instinct have since added call-making of their own.

What matters here is disclosure, not capability. Someone answering that call hears a synthetic voice on a stranger's number with no reliable way to know it is not a person, which is the same social contract question we hit when Gemini 3.8 Live gave Google's AI a talking face. Google's answer so far is scale discipline, and that may be the right one.

What to watch: whether the Polygraph Next funding survives Congress, and whether DCSA names the sensing technology before the pilot starts in FY2028.

Would you sit for an AI-scored lie detector at work if the alternative were losing the job? Tell us in the comments.

Sources: MIT Technology Review · DoD FY2027 DCSA budget justification, p.53 (PDF) · Inside Defense · AntiPolygraph.org · The Decoder · Ruby Weekly #818 · Rails World 2026 keynote · TechCrunch · The Verge · WIRED

Read more