The Risk on the Cyber Desk
The Pentagon designated Anthropic a supply-chain risk, weighed the Defense Production Act against it, and kept working with the model Anthropic would not release publicly, on cybersecurity. Two federal courts have now ruled, in opposite directions.
Contents
In March 2026 the Department of War designated Anthropic a supply-chain risk. The label prevents the U.S. military from using Anthropic’s models and blocks defense contractors from using them in their work for the department. Secretary Pete Hegseth accused the company of trying “to seize veto power over the operational decisions of the United States military.”
That was the official position. A federal judge later listed the others.
How a vendor becomes a threat
Anthropic was a Pentagon supplier before it was a Pentagon risk. It signed a $200 million contract in July 2025, one of four. Google, OpenAI and xAI got the same ceiling. By CNBC’s account, talks collapsed that September while the parties negotiated Claude’s deployment on GenAI.mil, the department’s in-house generative AI platform. The department wanted access “across all lawful purposes.” Anthropic wanted assurance that its models would not be used for fully autonomous weapons or domestic mass surveillance.
Tess Bridgeman, writing at Just Security in March, read the statute Hegseth was presumably invoking, 10 U.S.C. § 3252. It lets the Secretary exclude a company from the most sensitive military IT systems: intelligence, command and control, weapons. She found it “highly unlikely the Secretary can meet the statutory requirements,” because “Both parties have acknowledged contract negotiations broke down over terms of use, not adversarial risks to DoD systems.”
A disagreement over a contract’s terms of use went into the same legal box Congress built for compromised hardware.
What the judge found
On 27 August, Judge Rita Lin of the Northern District of California ruled on one designation. The government’s “words and deeds,” she wrote, “confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government.” And: “The empty invocation of national security is not a blank check to punish and retaliate against government critics.”
Then she laid out what else the government had been doing with the same company. Hegseth had floated applying the Defense Production Act to Anthropic, “which would mean the company was essential to national security rather than a threat to it.” By TechCrunch’s account of the ruling, the department had kept pursuing a contract with Anthropic, and the government was “collaborating with the company’s new model, Mythos, for cybersecurity.”
Mythos is the model Anthropic previewed in April 2026 and declined to release publicly because of its cyber capabilities, offering access only through a trusted-partner program called Glasswing.
The label said threat. The file said partner.
So one company, in one year, held three positions in the same government’s file. A supply-chain risk to be excluded. An asset essential enough to compel. A partner trusted with the model its own maker declined to release publicly. “Though the Department of War is undisputedly free to select the AI vendor of its choice,” Lin wrote, “the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless.”
What the appeals court found
On 25 September the D.C. Circuit ruled the other way on the parallel designation, 2-1. Judge Gregory Katsas, joined by Judge Neomi Rao, upheld it; Judge Karen LeCraft Henderson dissented. Katsas credited Hegseth’s “deeply sobering” concern that “overly constrained” models could shut down unexpectedly, and that Claude might be “subject to manipulation.” Then he stated the principle: “In our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks. In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution.”
The panel stayed its own decision so Anthropic could seek rehearing. “Another federal court has already held the government’s parallel designation unlawful,” the company said.
One court found retaliation dressed as security. The other found that security is the executive’s call to make. Both rulings stand, one stayed, and neither is a finding that Anthropic is a security risk.
The government’s case, at full strength
The department’s argument does not need a villain. A military that buys a model needs it to work on the day it matters, for every lawful purpose, without a vendor’s terms of use deciding which missions qualify. The Pentagon argued that Anthropic could try to control the military’s use of models it had bought and paid for. A supplier that reserves a veto over use is a supplier with a lever on operations, and Katsas held that weighing that lever belongs to the President and the Secretary, not to a judge.
Anthropic’s case is its two exclusions, fully autonomous weapons and domestic mass surveillance, and the fact that it kept arguing them while the label stood. “We remain focused on working productively with the government,” a spokesperson said after the August win.
Who got the platform
On 31 August, four days after Lin’s ruling, the department launched Starshield AI’s Grok for Government on GenAI.mil, the platform where Anthropic’s deployment talks had broken down a year earlier. Over half of the Pentagon’s three million personnel already use it. The Washington Examiner’s explanation was unhedged: “Musk’s AI company has fared well due to his usually positive relationship with President Donald Trump, unlike the combative relationship he has with Anthropic.” Grok got the seat Claude had been negotiating for.
On 30 September Hegseth named Elon Musk, Palmer Luckey of Anduril and Newt Gingrich to co-direct Project Meridian, a 120-day review of the technologies for future wars. The owner of one vendor on GenAI.mil now advises the department that buys from it.
None of that is unlawful, and none of it is hidden. It is procurement working as a regulator: no statute, no rulemaking, no comment period, just a list of who may be bought from, kept by the people doing the buying.
Four days later
On 29 September, four days after the appeals court upheld the blacklist, Dario Amodei signed the White House accord on frontier safety, at the same lunch as the man whose company had taken the platform. The President had already posted that his administration “stopped AI ‘people’ from doing bad, or potentially bad, ’things,’ like Dario (Anthropic!), who is now pretending to be a ‘perfect little angel’ - and we will continue to do so!”
The lab barred as a threat to the military’s supply chain was, by a federal court’s account, working with the same government on cybersecurity through a model too capable to release publicly, and then it was invited to lunch.
The risk designation does not describe the product. It describes the relationship.
The receipts (free, on this site): Dario Amodei · the funding ratchet · the universal capture mechanism