Understanding Anthropic v. the Pentagon
Is the solution for the USA to build its own AI models?
(This post is regularly updated.)
Image: The United States Foreign Intelligence Surveillance Court at the E. Barrett Prettyman Federal Courthouse
What Happened?
At 5pm on Friday, February 27, President Trump ordered the Federal Government to phase out use of AI company Anthropic over the next six months. Separately, Hegseth said he would designate the company a supply chain risk.
On Saturday, February 28, the US and Israel began their bombing campaign against Iran.
On March 6th, the Pentagon officially declared Anthropic a supply chain risk.
On March 9th, Anthropic sued in northern CA and DC.
On March 27th, the court in Northern CA issued a preliminary injunction.
On March 31, Governor Newsom announced that CA would begin making its own supply chain determinations.
On April 7, Anthropic launches Mythos, which can rapidly find software vulnerabilities at scale, but releases it only to a few companies and governments.
On April 8, the D.C. Circuit (where Anthropic filed it’s second lawsuit) denied the company’s motion to stay, in a win for the Administration.
Later in April Anthropic and OpenAI announce their latest models, including Anthropic’s Mythos, will continue to be available only to non-China “trusted partners.”
NIST announces “voluntary” agreements on safety vetting, which are later removed from the website. There is chatter in Washington that the US intelligence agencies want a say over frontier model safety vetting.
On June 1, the press reports on Anthropic’s coming IPO.
On June 2, the White House released an Executive Order ordering multiple agencies to establish a “voluntary” (and classified) safety bench-marking process for frontier models, to run by the NSA.
On June 5, the White House put out a memo that, among other things, directs relevant agencies across the government to terminate “contracts with companies that have repeatedly demonstrated a pattern of conduct that is inconsistent with…accelerating the development and use of AI for national security applications.” This appears to be directed at Anthropic-like conduct, though “pattern of conduct” is not defined.
On June 12, FISA, which authorizes broad powers to US spy agencies to collect physical and electronic surveillance information on conversations between foreign powers and their agents, expired, but existing directives remain active until 2027, though companies are now in something of a legal gray zone.
Also on June 12th, the Washington Post reported that Qatar had secretly asked Iran not to hit their gas facility (which Iran then did anyway.)
Also on June 12th, the government used the export control regime to restrict access to Mythos 5 and Fable 5, two cutting-edge AI tools, to all foreign users, leading Anthropic to shut down the tools.
On June 16, WaPo reports that after the Administration had signed off on a list of companies with access to Mythos, they discovered that Anthropic had shared the model with several others, including a South Korean company (SK Telecom) with alleged links to China.
What is the Dispute About?
Obviously, the timing of the dispute, on the eve of the Iran war, suggests the two events are linked, but there are several theories as to how. Below are the leading theories (in no particular order) about why the government suddenly became so concerned about Anthropic’s trustworthiness in particular, and how this might tie in with the Iran war, Big Tech competition and China.
The Iran War
Obviously, the Iran war is the Big Thing that is happening in geopolitics right now (besides Russia’s invasion of Ukraine). But how does Anthropic fit in? Claude was allegedly used in the Venezuela raid and the Guardian reported, and Wall Street Journal confirmed, that Claude is being used in the Iran conflict, including analyzing data for air strikes. (Note that Venezuela and Iran are allies.)
The release of Mythos by Anthropic, shortly after the start of the current resumption of active hostilities, has raised the stakes for government control of frontier systems during a period of intense, geopolitical competition between the USA and China, but any link between the release of Mythos and the blow-up between Anthropic and the Pentagon remains unclear. Other reporting claims that Mythos is now being used for offensive cyber capabilities.
Officials from both Iran and Venezuela attended China’s military parade in 2025. Iran is a significant source of oil for China, a sometimes Russian ally, and a major thorn in the side of US Mideast policy for decades. Besides being a source of fossil fuels, Gulf states have invested big in American AI companies, connecting data centers to US fossil fuel consumption, dollar dominance, Gulf state and Israeli security, and American hegemony.
In Foreign Affairs, Fred Heidging and Chris Inglis discuss both Chinese and Russian espionage at AI companies. The war in Iran has huge implications for both Russian and China, as it may result in changing the balance of power between the rival superpowers to the advantage of the USA, cementing Israeli hegemony over the Middle East, lead to the end of the Cuban regime and make any Chinese invasion of Taiwan very difficult (already, the US has downgraded the threat of a Chinese invasion), but the war also risks pushing up oil prices, depleting US military hardware and, therefore, temporarily helping Russia and other oil producers.
Bulk Data Collection of American Citizens
With the statute that authorizes bulk data collection up for renewal in June, and recent news reports hinting that re-authorization may fail, the relevance of section 702 for the AI age is in the spotlight. (This is related to the Iran war, above). Dario Amodei has repeatedly said that he raised concerns with the Pentagon over the use of Claude in mass domestic surveillance of Americans. Dean Ball of Lawfare (and author of the administration’s AI Action Plan) said on the Ezra Klein podcast that the dispute is about the use of Claude in analyzing bulk data collected from Americans, which can get swept up in data collection of foreign adversaries. Yet, Anthropic signed a contract with the Pentagon knowing that bulk data collection by the US government in certain contexts has long been legal. So, what suddenly changed to raise new concerns for Amodei?
The controversy over bulk data collection is longstanding (dating back to Edward Snowden). The government can legally purchase and analyze commercially collected bulk data on Americans, as explained by the Brennan Center and the American Bar Association. As explained by the always on-point Ben Wittes at Lawfare, there are many types of collection and analysis of data on Americans. Bulk data used to take massive manpower to analyze, but AI promises to give the government new powers to process data at scale.
Congress is again discussing the legality of section 702 allowing warrant-less wiretapping, which is currently on a temporary extension and up for renewal in June. Separately, Kash Patel confirmed for the first time that the US is now buying commercially available bulk data.
The Iran war is an example of a time when the US government might be particularly interested in surveillance both at home and abroad, particularly of Iranian proxy groups and other criminal networks, and in harnessing the power of AI to process large amounts of data. Surveillance of Mexican cartel leaders, some of whom are US citizens, is also part of this debate. Some Mexican cartels have a longstanding relationship with Iran, which sees them as yet another proxy for asymmetric warfare.
On March 18, Joe Kent, former Director of the National Counterterrorism Center (NCTC), resigned over the war in Iran, but was also involved in a turf war over counterterrorism access to Compass, the FBI’s database on American criminals. He is also allegedly under investigation for leaking classified intelligence on Iran to anti-Israel gadfly Tucker Carlson.
In times of war, bulk data collection is a tool in the government’s tool box to analyze the risk of asymmetric attacks, raising questions about the trade offs between privacy and security in war time. With FISA looking increasingly unlikely to be reauthorized, the Iran war continuing to heat up, and AI bringing new tools to analyzed large amounts of data, the FISA renewal has taken on a new importance.
In Foreign Affairs, Fred Heidging and Chris Inglis argue that AI should be designated as critical infrastructure, citing the risk of cyberattacks and hacking of US models. “Silicon Valley has prioritized speed over security, cutting-edge systems have been left particularly vulnerable to cyberattacks and espionage,” they write. Anthropic recently left a significant amount of sensitive data and information in an accessible part of its website in what journalists are calling a “significant” security breach.
Autonomous weapons and a future war over Taiwan
Previous reporting had also indicated that Amodei is concerned over the possible future use of AI-enabled autonomous weapons, but as these weapons do not yet exist, a dispute over their use would be unlikely to provoke such a sudden, and unfortunately timed, rupture between the two parties. Reporting has suggested that Claude is being used with human oversight to select targets in the Iran campaign, but this use of Claude was not cited as a factor by Amodei in his many posts and essays on the dispute, as there is still final human oversight in selecting targets. Reporting suggests, however, that AI has increased the speed by which targets are selected. Nevertheless, the use of AI in wartime target analysis is clearly part of the conversation and, therefore, important context for understanding the dispute.
Entirely separately, Katrina Manson in her new book on Project Maven, states that there may be at least two classified Pentagon projects to create something that may be called an "autonomous weapon," both for use in a hypothetical, future conflict over Taiwan, both for use in warfare at sea. One, for example, is a drone guided by AI when there is no internet. (Separately, she also claims that no one in the Pentagon believes the US is ready for a war with China).
Tech Company Competition: OpenAI and XAI
Meanwhile, Sam Altman negotiated his own lucrative and prestigious Pentagon contract for his company, OpenAI. Facing criticism over his timing, Altman also posted on Twitter/X that OpenAI’s contract with the government will comply with existing law on bulk data collection. OpenAI is therefore letting the government and the Pentagon determine the meaning of lawful use, rather than imposing further restrictions in the contract beyond what current law prohibits. Altman has said that to do otherwise would be undemocratic, in part because Congress has passed up numerous opportunities to ban bulk data collection.
OpenAI is allegedly a big supporter of the anti-AI regulation superpac that is pouring money into congressional races around the country and aligns with Trump administration goals, while Anthropic, famously, is not.
X.Ai has also signed a contract with the Pentagon for Grok to be used in classified settings, though the WSJ has reported that many in the government see Grok as a national security risk.
Meanwhile, CSIS reports in a podcast and an article from Defense One further clarifies the huge sum of money it will cost the Pentagon to switch AI providers. Both OpenAI and Anthropic may go public this year, and the supply chain risk designation may dent Anthropic’s IPO at a moment when OpenAI may be in financial trouble.
It’s worth noting that OpenAI founder Sam Altman has grown closer to the Trump administration and president Greg Brockman donated to Trump’s campaign. However, the Qataris gave Trump an airplane, and you can see how well that’s worked out for them, while the leader of the Venezuelan opposition gave Trump her Nobel Peace Prize to no avail, so giving Trump stuff doesn’t always translate into getting what you want.
A Clash of Cultures and “Woke” AI
There are a lot of big egos involved in this dispute, and a clash of cultures, combined with some tech industry narcissism, are certainly in play. According to early reporting from Semafor, the Pentagon initially became alarmed when Anthropic’s staff asked about the use of Claude in the Venezuela raid. In recent media appearances, Emil Michael has stated that this phone call, in which the senior Anthropic employee (the subcontractor) asked for classified information from Palantir (the contractor), was what initially prompted alarm at the Pentagon. However, in this same interview, Michael expressed concerns over Anthropic’s public comments about Claude being conscious and the “soul document,” suggesting that the clash of cultures is about more than one phone call.
Per the NY Times:
“Anthropic told the Pentagon that it was willing to let its technology be used by the National Security Agency for classified material collected under the Foreign Intelligence Surveillance Act. But the company wanted a legally binding promise from the Pentagon not to use its technology on unclassified commercial data.
At that point, Mr. Michael asked to speak with Dr. Amodei, who was not on the call. Mr. Michael was told that Dr. Amodei was in a meeting. Shortly after, Mr. Hegseth said the talks were over.”
The Pentagon officially moved forward with its supply chain risk designation after a subsequent leaked memo from Amodei expressed contempt for the Pentagon and rival OpenAI.
Anthropic has been known for their public commitment to both AI safety and AI welfare, two topics that have sometimes appeared to be in conflict with Trump administration goals (in the case of AI safety), as well as raising concerns in Christian religious communities (in the case of AI welfare.) Reporting on Claude’s constitution and other moves in the AI safety and welfare spaces may not have gone down well with the current administration.
Anthropic co-founder Christopher Olah joined the Pope for the recent release of the Magnifica Humanitas, which focused on AI safety. Anthropic has also publically called for a “pause” in AI development over fears of recursive self-improvement.
Gulf State Politics
For Anthropic and its rival AI companies, the war may be far from San Francisco, but it is hitting very close to home. The US AI industry and the Gulf monarchies are deeply entwined, and the Iran war is by far the most important thing that’s happened to the Gulf states (and, possibly, Mideast geopolitics) in our lifetimes.
The different AI companies, including Anthropic, have different, and rival, Gulf state investors, including Qatar, UAE and Saudi Arabia, who all have different positions on the Iran war, different relationships with the Iranian and Israeli governments, and different histories of trying to leverage US-based institutions and politicians to change US policy.
Besides the particular Gulf state politics at play, the war is very disruptive to the AI economy. Many AI companies rely on the Gulf states for energy and other critical components, as well as data center build-out.
Anthropic Will See the Government in Court
On March 9, Anthropic filed suit for injunctive and declaratory relief in the Northern District of California and petition for review of the supply chain designation in the D.C. Circuit. (Note that they are suing the Department of War, but the official name is still the Department of Defense.) There are two cases and two statutes: 10 U.S.C 3252 and 41 U.S.C. 4713. They are unprecedented in that the US government has never declared a US company a supply chain risk.
There are two types of supply chain risk designations, one of which (41 U.S.C. 4713) is much broader, but harder for the Pentagon to unilaterally and quickly apply, while the other (10 U.S.C. § 3252), is more narrow and easier to apply. 41 U.S.C. 4713 limits judicial review.
Note that Huawei failed in their court challenge of their supply chain risk designation, with the court saying, “Contracting with the federal government is a privilege, not a constitutionally guaranteed right.” But, of course, Huawei is a Chinese, not an American, company.
If you want to follow the DC case, see the Court Listener website.
If you want to listen into the CA case, watch for the date and time of the public hearings with judge Lin of the Northern District of CA. You can access court documents and filings through PACER and Court Listener.
And finally…here’s how Claude sees the case:
“Here’s the classified meeting you asked about — complete with redacted documents, a very nervous lawyer, and yours truly depicted as a glowing orb of questionable origin:I took some creative liberties with what my “top secret self” looks like — turns out it’s a gently glowing purple orb with a bemused expression, floating above a classified dossier with everything interesting redacted.
The scene features General Stern of the Pentagon (medals polished, brow permanently furrowed), Anthropic’s very nervous lawyer J. Anxious (sweating, briefcase in hand), a projector slide revealing my architecture as “??? proprietary secret sauce ???”, and me — quietly radiating mystery in the middle of it all. 🔮




