Opinion

Why Washington Wants a Firmer Grip on Claude

Anthropic refused to let Claude run mass surveillance or fully autonomous weapons, and the Pentagon blacklisted it. Military AI needs human oversight, and this administration isn't providing it.

Why Washington Wants a Firmer Grip on Claude
Photo by Brecht Corbeel / Unsplash

The federal government is using more AI than it ever has. Over 1.7 million people at the Pentagon use GenAI.mil, the military's internal AI portal, and GSA says its discounted AI deals now cover about 3.5 million federal employees.

Anthropic, the company behind Claude, was the first to get its models onto the government's classified networks. It's also the company the Trump administration has spent most of 2026 trying to push out. In February the Pentagon labeled Anthropic a "supply chain risk," a label usually saved for foreign companies tied to hostile governments, because Anthropic wouldn't drop two conditions on how the military uses Claude. Claude can't be used for mass surveillance of Americans, and it can't run fully autonomous weapons.

The past week has been all over the place. On Friday, a federal appeals court let the Pentagon's label stand. On Sunday, Trump had Anthropic CEO Dario Amodei over for dinner. On Tuesday, Amodei signed a voluntary White House AI pledge alongside the rest of the industry, and by Wednesday morning the White House was reposting that pledge with the president's title printed as "President of the Unites States."

I think AI in the military needs actual moderation. Before an AI system is allowed to take an action, someone should have already worked through whether that action is ethical, a person should make the final call, and whatever the system puts out should be checked by a human. Anthropic's two conditions line up with that. The way this administration has handled AI so far doesn't.

Every AI the government is using

At least 11 companies supply AI models or AI platforms to federal agencies right now, and Anthropic is the only one the Pentagon has blacklisted. This is what's publicly reported as of Sept. 30, 2026.

Company

Model or product

Where it is used

Status

OpenAI

ChatGPT Enterprise; ChatGPT Mil (launched on GPT-5.4)

GenAI.mil since Aug. 31; classified networks under a Feb. 27 agreement; civilian agencies through GSA

New 27-month GSA deal at 50% off token pricing starts Oct. 1

Google

Gemini for Government

First model on GenAI.mil (Dec. 2025); classified networks as of May 1

Offered to agencies at 47 cents per agency through Sept. 2026

xAI (SpaceX's Starshield AI)

Grok for Government

GenAI.mil since Aug. 31; classified networks as of May 1

42 cents per agency through March 2027

Anthropic

Claude, Claude Gov, Claude Enterprise; Mythos 5 (restricted)

Civilian agencies; the FDA's internal tool Elsa is built on Claude; Mythos 5 went to about 100 U.S. companies and agencies that defend critical infrastructure

Barred from Pentagon work after the Sept. 25 appeals ruling; the governmentwide ban is blocked by a California court

Meta

Llama (open-weight)

Discounted GSA deal; GSA's USAi platform

Active

Microsoft

Azure AI services and hosted models

USAi; classified networks since May 1

Active

Amazon Web Services

Hosted models and cloud infrastructure

USAi; classified networks since May 1

Active

Nvidia

Open models

Classified networks since May 1

Agreed to no usage limits beyond what law requires, per Bloomberg

Reflection AI

Open models

Classified networks since May 1

Active

Oracle

Cloud and AI tools

Classified networks, per a Pentagon post

Active

Perplexity

Enterprise Pro for Government

Civilian agencies through GSA

25 cents per agency through April 2027

Agencies are building their own tools on top of these models too. The State Department's StateChat had more than 62,000 users across 98% of diplomatic posts by June, and the Energy Department runs a similar tool called Joulix. GSA's USAi hub puts models from OpenAI, Amazon, Meta, Google, Microsoft, xAI and Anthropic in one place so agencies can test them.

Anthropic's spot on that list is shaky. GSA's own AI page still has an alert saying it will remove Anthropic integrations by Aug. 27, 2026, which happens to be the same day a federal judge ruled the ban behind that alert unlawful.

How the fight started

Anthropic and the Pentagon started out as partners. In July 2025, the Pentagon signed contracts worth up to $200 million each with four AI companies: Anthropic, OpenAI, Google and xAI. Anthropic says the two uses it's refusing now were never part of any of its Pentagon contracts to begin with.

Things went sideways after the Jan. 3 operation that captured Venezuela's Nicolás Maduro. Axios reported that Claude was used during the raid itself, through Anthropic's partnership with Palantir. A Pentagon official later said an Anthropic executive asked Palantir whether Claude had been involved, and the department took that as a sign Anthropic might object. Anthropic denied raising concerns about any specific operation and said its talks with the Pentagon only covered its two hard limits.

After that, the Pentagon wanted an "all lawful purposes" standard for everything, classified or not. Defense Secretary Pete Hegseth threatened to label Anthropic a supply chain risk and to use the Defense Production Act to force the safeguards off. On Feb. 26, Amodei wrote that the company "cannot in good conscience accede" to that.

The next day Trump posted that the country would never let a "RADICAL LEFT, WOKE COMPANY" decide how the military fights. He ordered every federal agency to stop using Anthropic's technology, with six months for agencies like the Pentagon to phase it out. Hegseth then barred military contractors from doing any commercial business with Anthropic at all.

Civilian agencies moved within hours. GSA pulled Anthropic from USAi and its main purchasing schedule, and Treasury, State and Health and Human Services started dropping Claude. That same night, OpenAI CEO Sam Altman announced a deal to put OpenAI's models on the Pentagon's classified network.

Why Washington wants more control

The Pentagon's official reason makes some sense. A military doesn't want to depend on software whose maker could object in the middle of an operation. A senior official told Axios there's a lot of gray area around what counts as "mass surveillance" or an "autonomous weapon," and that working out every use case with a vendor wasn't realistic. Two of the three D.C. Circuit judges agreed that Claude's built-in restrictions could make it unreliable for military work.

OpenAI's deal shows what the Pentagon was actually after, and the answer is less dramatic than "AI with no limits." OpenAI's contract lets the department use its models for all lawful purposes, consistent with the law and existing oversight rules. Altman said the Pentagon accepted the same two principles Anthropic had asked for. OpenAI later tightened the surveillance language and got the department to confirm that intelligence agencies like the NSA would need a separate agreement.

Both deals have limits, so the fight comes down to who gets to enforce them. In OpenAI's case, the limits live in the government's own laws and policies, and Altman reportedly said OpenAI doesn't get to make operational decisions. In Anthropic's case, the limits were Anthropic's terms, and Anthropic enforced them. Nvidia went even further in May and agreed to no usage limits beyond what the law already requires.

Claude was also hard to replace. When this started, it was the only model cleared for fully classified systems, according to The Hill, so the government had every reason to want leverage over the company that made it. Anthropic's Mythos models are some of the strongest cybersecurity tools out right now, and the NSA was reportedly testing Mythos while the rest of the Defense Department was calling Anthropic a security risk.

Politics are a big part of it too. Anthropic has been one of the loudest voices in the industry for slowing frontier AI down and writing rules for it, and Trump has made that personal. Earlier this month he wrote that the only guardrail AI needs is a strong president, and followed it with "We already have tremendous CRIMINAL and REGULATORY power over these companies!" I have a hard time reading that as anything other than a president telling a company he can hurt it.

Why Anthropic won't budge

Calling Anthropic "woke" makes its position sound a lot bigger than it is. The company says it supports using AI for foreign intelligence and counterintelligence, it has never objected to a specific military operation, and it considers partly autonomous weapons, like the ones being used in Ukraine, important for defending democracies.

On surveillance, Anthropic's argument is that the law is behind the technology. The government can already buy Americans' location, browsing and association data without a warrant. A strong AI model can piece those scattered records together into a full picture of someone's life, automatically, for millions of people at once. Anthropic says that's only legal because Congress hasn't gotten around to it yet.

On weapons, the argument is mostly about reliability. Anthropic says current frontier models aren't dependable enough to choose and hit targets with no human involved. It offered to work with the Pentagon on research to get them there, and says the Pentagon turned that down.

Anthropic also pointed out something the administration still hasn't explained. A supply chain risk label means a product is too dangerous to use. A Defense Production Act order means a product is so important the government can force a company to hand it over. The Pentagon threatened Anthropic with both at the same time.

Anthropic isn't a neutral party

Anthropic was the first AI lab on classified networks. It built custom Claude Gov models for national security customers and partnered with Palantir, one of the military's most deeply embedded contractors. Claude was reportedly used during a raid that bombed multiple sites in Caracas, according to reporting summarized by Small Wars Journal. Its policy allows almost all military work and carves out two exceptions.

Safety is also Anthropic's brand, and that brand is worth a lot of money with a public offering on the way. Some of its own engineers were uneasy about Pentagon work too, Axios reported, so backing down would have cost it internally. A company can have mixed reasons and still make the right call.

I've been skeptical of Anthropic before. When the Mythos "sandbox escape" story went viral in April, the headlines were way more dramatic than what actually happened in a controlled test. Still, keeping Mythos limited to vetted security teams through Project Glasswing instead of releasing it to everyone was a smart move, and the two conditions on military use come from that same kind of caution.

Two courts, an export ban and a dinner

Seven months in, where Claude stands with the government depends on which court and which week you're looking at.

Date (2026)

What happened

Sept. 29

Amodei and other tech leaders sign a voluntary White House accord on frontier AI safety; Trump calls it "morally" binding

Sept. 27

Trump hosts Amodei for dinner and calls him highly respected

Sept. 25

The D.C. Circuit rules 2-1 that the Pentagon can keep Anthropic off defense work; Judge Karen Henderson dissents

Sept. 23

Altman and Amodei ask the UN Security Council for shared AI testing standards; the U.S. rejects any "globalist scheme" of control

Aug. 31

ChatGPT Mil and Grok for Government join Gemini on GenAI.mil; Claude is absent

Aug. 27

Judge Rita Lin rules the designation unlawful retaliation and permanently blocks the ban

June 12 to 30

Commerce orders Anthropic to cut foreign nationals off from Fable 5 and Mythos 5, then lifts the order after 19 days

May 1

The Pentagon signs classified AI deals with seven other companies, leaving Anthropic out

March 26

Lin issues a preliminary injunction; federal workers regain access to Claude

The two rulings look like they contradict each other, but they're answering different questions. Judge Lin, in California, found the record strongly suggested the government's stated reasons were pretextual and that the real goal was punishing Anthropic for speaking out. The D.C. Circuit looked at a different law and said what matters is what Anthropic does, whatever the reason. Judge Henderson disagreed, writing that the law was never meant to cover "a contractor's honest and upfront enforcement of restrictions."

The export ban in June is easy to forget, but it matters. Commerce cited a reported jailbreak and ordered Anthropic to block every foreign national from its newest models, including its own non-U.S. employees. Anthropic shut the models off for everyone instead of sorting users by citizenship. Commerce reviewed the models with Anthropic and lifted the controls on June 30, but the government has now shown it can switch off a commercial AI model overnight.

Then this week happened. Weeks after posting about his criminal and regulatory power over AI companies, Trump called Amodei "fantastic", and Anthropic signed a pledge with nothing enforcing it. The day before, House Speaker Mike Johnson had called fears about AI a Chinese psychological operation. The same day as the lunch, Trump also signed an order telling federal agencies to start calling AI "Super Intelligence."

On Wednesday, the White House reposted the signed accord, and the line under Trump's signature read "President of the Unites States of America." It's a typo, and on its own it's small. But this was a one-page document about keeping the most powerful technology in the world in check, signed by the president and six of the biggest names in tech, and apparently nobody read the signature line closely before it went out. If the administration can't get a one-page AI document reviewed before it goes public, I don't have much confidence in how closely it's reviewing what AI does inside the military.

My take

I don't think the military should stay away from AI. It's already useful for things like logistics, paperwork and analysis, and every side of this fight agrees the military should have it. What I care about is how it gets used and who is watching it.

AI in the military has to be moderated. Before a system is allowed to take any action that affects people, the ethics of that action should already be worked out, and a human should approve it. Nothing should be fully autonomous, and every output should be monitored by someone who can catch a mistake before it turns into a decision. These models still get things wrong with complete confidence, and in a military setting a wrong answer can cost lives.

Anthropic's two conditions are pretty close to the minimum version of that. OpenAI says it shares them. If the same two principles are fine in OpenAI's contract and a national security threat in Anthropic's, then the Pentagon's real problem was a company saying no in public and sticking to it.

The supply chain label worries me the most. It exists to keep hostile foreign companies out of U.S. systems. Using it against an American company over a policy disagreement gives every future administration, from either party, a way to punish any contractor that pushes back. Judge Lin caught that. The D.C. Circuit majority decided the government's motive didn't matter.

This administration isn't showing much interest in moderating AI at all. It called Claude a risk while threatening to force Claude into service. The NSA was reportedly testing Anthropic's most powerful model while the Pentagon blacklisted the company. Trump rejected international AI safety standards at the UN, called the industry's own safety pledge "morally" binding, and then put out that pledge with a typo in his own title. None of that looks like a government that's checking the output.

I also don't want to rely on Anthropic, OpenAI or any CEO to keep these limits in place for us. Congress should write them into law. That means requiring a warrant before AI can be run on purchased data about Americans, and requiring a human decision and human review behind any use of lethal force. If those rules existed, companies wouldn't need their own red lines, and no president could call a company woke for having them.

💡
This is an opinion piece. Sourced is not affiliated with, sponsored by or endorsed by Anthropic, OpenAI, Google, xAI, the Department of Defense or any other company or agency mentioned. Company names, logos and product images are used only to identify the subjects being discussed.

Sources

Primary documents & statements

  1. Amodei, Dario. "Statement from Dario Amodei on Our Discussions with the Department of War." Anthropic, 26 Feb. 2026, anthropic.com/news/statement-department-of-war.
  2. "GSA Stands with President Trump on National Security AI Directive." U.S. General Services Administration, 27 Feb. 2026, gsa.gov.
  3. "GSA Expands OneGov AI Offerings with Discounted, Consumption-Based Access to OpenAI's ChatGPT." U.S. General Services Administration, 10 Sept. 2026, gsa.gov.
  4. "Buy AI." U.S. General Services Administration, accessed 30 Sept. 2026, gsa.gov/artificial-intelligence/buy-ai.
  5. "Artificial Intelligence." U.S. General Services Administration, accessed 30 Sept. 2026, gsa.gov/artificial-intelligence.
  6. Congressional Research Service. In Focus IF13217 (on the Anthropic dispute). Congress.gov, IF13217, 2026, congress.gov.
  7. "Project Glasswing." Anthropic, accessed 30 Sept. 2026, anthropic.com/glasswing.

News reporting

  1. "Pentagon's Use of Claude During Maduro Raid Sparks Anthropic Feud." Axios, 13 Feb. 2026, axios.com.
  2. "Exclusive: Pentagon Threatens to Cut Off Anthropic in AI Safeguards Dispute." Axios, 15 Feb. 2026, axios.com.
  3. "Anthropic on Shaky Ground with Pentagon amid Feud after Maduro Raid." The Hill, Feb. 2026, thehill.com.
  4. "Pentagon Used Anthropic's Claude in Maduro Venezuela Raid." Small Wars Journal, 17 Feb. 2026, smallwarsjournal.com.
  5. "Trump Cuts Bait on Anthropic, Slams Company as 'WOKE.'" KRON4, 27 Feb. 2026, kron4.com.
  6. "OpenAI Strikes Deal with Pentagon, Hours after Rival Anthropic Was Blacklisted by Trump." CNBC, 27 Feb. 2026, cnbc.com.
  7. "OpenAI CEO Sam Altman Responds to Deal with Department of War." Yahoo News, Mar. 2026, yahoo.com.
  8. "OpenAI CEO Sam Altman Says Company Doesn't 'Get to Make Operational Decisions' on Military's Use of Its Tech." ABC News, Mar. 2026, abcnews.com.
  9. "Pentagon Designates Anthropic a Supply Chain Risk: What Government Contractors Need to Know." Mayer Brown, Mar. 2026, mayerbrown.com.
  10. "Agencies Begin to Shed Anthropic Contracts Following Trump's Directive." Nextgov/FCW, Mar. 2026, nextgov.com.
  11. "Judge Temporarily Blocks Trump Administration's Anthropic Ban." NPR, 26 Mar. 2026, npr.org.
  12. Freedberg, Sydney J., Jr. "Judge Grants Anthropic Preliminary Injunction but Pentagon CTO Says Ban Still Stands." Breaking Defense, 27 Mar. 2026, breakingdefense.com.
  13. "Pentagon Inks Deals with Nvidia, Microsoft, and AWS to Deploy AI on Classified Networks." TechCrunch, 1 May 2026, techcrunch.com.
  14. "Microsoft, Amazon Hand Pentagon More Control Over AI Systems." Bloomberg, 1 May 2026, bloomberg.com.
  15. "Pentagon Expands AI Deals with Microsoft, Amazon, Nvidia, Oracle and Others." Redmondmag, 4 May 2026, redmondmag.com.
  16. "Pentagon Adds Nvidia, Microsoft, Amazon, and Reflection AI to Classified AI Push." eWeek, 5 May 2026, eweek.com.
  17. "Anthropic Says Trump Admin Has Lifted Export Controls on Claude Fable 5 and Mythos 5." CNBC, 30 June 2026, cnbc.com.
  18. "Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls." The Hacker News, July 2026, thehackernews.com.
  19. "State Department Shares GenAI Playbook to Guide Federal AI Adoption." CDO Magazine, 4 Aug. 2026, cdomagazine.tech.
  20. "Anthropic Gets Its First Court Win over the Pentagon's Supply-Chain Risk Label." TechCrunch, 28 Aug. 2026, techcrunch.com.
  21. "Grok and ChatGPT Join Gemini in Pentagon's Enterprise GenAI Portal." DefenseScoop, 31 Aug. 2026, defensescoop.com.
  22. "Pentagon Adds ChatGPT Mil and Grok to Its GenAI.mil AI Portal." WinBuzzer, 3 Sept. 2026, winbuzzer.com.
  23. "OpenAI and Anthropic CEOs Push for AI Cooperation at UN after Trump Rebuffs 'Globalist Scheme' to Control It." CNBC, 23 Sept. 2026, cnbc.com.
  24. Ordonez, Victor. "Federal Appeals Court Upholds Pentagon Designation of Anthropic as Supply Chain Risk." ABC News, 25 Sept. 2026, abcnews.com.
  25. Ray, Siladitya. "Trump Dines with Anthropic CEO Dario Amodei, Despite Earlier Barbs." Forbes, 28 Sept. 2026, forbes.com.
  26. Schulze, Elizabeth, et al. "Trump Says AI Leaders Signed a 'Constitution' to Police Themselves." ABC News, 29 Sept. 2026, abcnews.com.
  27. "Top AI Executives Sign Commitment to 'Self-Police' after Meeting at White House." CNN, 29 Sept. 2026, cnn.com.
  28. Durante, Tom. "White House Re-Shares Trump's AI Accords, Complete with Embarrassing Typo." Mediaite, 30 Sept. 2026, mediaite.com.

Background & analysis

  1. "OneGov Deals Helping Expand Agencies' AI Adoption, GSA Official Says." Nextgov/FCW, Jan. 2026, nextgov.com.
  2. "GSA to Require Agencies to Pay for USAi after Launching It as a Free Service." Nextgov/FCW, Apr. 2026, nextgov.com.
  3. "Mapping the Rise of AI in Federal Health Agencies." Bipartisan Policy Center, 2025, bipartisanpolicy.org.

For reporting comparison

💡
Included to show how politically leaning outlets covered this story, not as primary sources. They may contain framing, opinion or unverified claims. Check them against the primary sources above before relying on them.
  1. Phillips, Morgan. "Maduro Raid Questions Trigger Pentagon Review of Top AI Firm as Potential 'Supply Chain Risk.'" Fox News, 16 Feb. 2026, foxnews.com.