Deep Dive — Anthropic's guardrails cost it the Pentagon, court or not

Share
Deep Dive — Anthropic's guardrails cost it the Pentagon, court or not

The Pentagon "has ceased the use of Anthropic products," a department official said in a statement to the BBC on Monday — the first time the US military has said out loud what it has been working toward since February. The order to phase Claude out was signed by defense secretary Pete Hegseth on February 27 with a six-month deadline attached; the deadline passed in late August with no public explanation, no successor named, and no acknowledgment that anything had changed. What finally forced a statement was persistence: reporters kept asking, and people familiar with the department's AI use kept answering — that as recently as last week, Claude was still doing the work. We covered the confirmation in Pentagon says it has stopped using all Anthropic products this morning; the longer question is what eight months of fighting over two contract clauses actually bought anyone.

This is the most consequential vendor dispute the AI industry has had with a government, and it was never about benchmark scores. A frontier lab told the world's largest defense customer that two uses of its model were off the table; the customer answered with a designation historically reserved for companies based in hostile countries; the lab sued and won one case, lost another, and now — with the legal fights still running — the practical outcome has arrived anyway. The military has moved on, the guardrails stayed on, and both of those facts are harder to reconcile than either side's press releases admit.

Claude's day job inside the Pentagon was the one nobody advertises. Multiple people familiar with the setup told the BBC that analysts fed satellite imagery and drone footage through Claude, inside Palantir's Maven Smart System — the department's primary platform for organizing intelligence — to sort through volume, identify potential military targets, and assemble the one-page briefs that move up the chain of command. Claude's Mythos models were used "throughout the whole period of the controversy," the sources said, across research, analysis and intelligence gathering, and in military operations against Iran. The timing detail that should stop you: Hegseth set the six-month phase-out clock on February 27, one day before the United States and Israel attacked Iran. The model the Pentagon was expelling was, by its own sources' account, load-bearing in the fight it started the next morning. Anthropic had been supplying the government and military since 2024 — the first advanced AI company whose tools ran inside agencies doing classified work — which is exactly why extraction, not acquisition, was the problem.

The terms Anthropic would not sign are small to write down and huge to enforce. The company wanted Claude barred from mass surveillance of Americans and from fully autonomous lethal weapons; the Defense Department, in the words of under secretary Emil Michael, wants defense software available for "all lawful purposes" without constraints the vendor gets to impose. Anthropic refused to drop its conditions, Hegseth designated the company a national-security supply-chain risk on February 27, and the eviction clock started. The statute behind the label was written with foreign adversaries in mind, which is the part Anthropic's lawyers kept returning to — a disagreement about targeting policy is not a supply-chain threat from abroad. Whatever the legal merits, the operational result was decided long before any ruling: when a buyer decides a seller's terms are unacceptable in its domain, the buyer stops buying.

What the department reported and what its own sources described never matched up. At a media roundtable in mid-September, Michael told reporters that "about 90% has transitioned" and that "all of the Maven Smart Systems or Palantir work has been transitioned months ago," with completion due by the end of the month. Last week, according to the BBC's interviews, Claude was still live in Maven. Both statements can hold only if "Maven" means different things to different people inside the building — or if the official progress numbers were always aspirational. Georgetown's Lauren Kahn, a former US defence official, gave the unglamorous explanation: Claude was deeply integrated into Maven, and "these things are not just plug and play. Once they become integrated it can be painful to remove them." The migration was also, by one insider's account to DefenseScoop, a downgrade in practice: a US official said he still pays for Claude personally at home, where twenty minutes of work replaces four hours on government systems, because the military's own tool — the GenAI.mil platform, which added Grok and ChatGPT at the end of August — has no API access and cannot build agents.

The courts produced two answers, and the Pentagon is enforcing the one it likes. In August, Judge Rita Lin of the Northern District of California issued a permanent injunction against the designation, finding the administration had punished Anthropic for its public positions on AI safety — a First Amendment problem — and, separately, a procedural-due-process problem. Then, on September 25, the D.C. Circuit upheld a parallel designation under different law on a 2-1 vote, with Judges Gregory Katsas and Neomi Rao finding the department "had ample support for its conclusion" that Claude's continued integration presented a statutorily covered national-security risk, and Judge Karen LeCraft Henderson dissenting. We ran the full read on Appeals court upholds Pentagon's Anthropic blacklist on a 2-1 vote when it landed; the short version is that one court said the punishment was unlawful while the other said the purchasing power behind it was legitimate, and the department is free to act on the second. Anthropic has said it "respectfully disagrees" and is weighing en banc review or the Supreme Court, and Reuters reports the company puts the blacklisting's cost in the billions of dollars, on top of a reputation bill arriving with its IPO. The August ruling was supposed to be the industry's landmark — our read at the time was The Anthropic–Pentagon ruling isn't a win for one lab. It's a red line for all of them — and what eight more months bought is the sobering part: the right to refuse survived, and the customer did not come back.

The replacements are named now, and they are the labs that signed. While the litigation ran, the Pentagon signed contracts with Google, xAI and OpenAI; per the BBC's sources, OpenAI's tools have spread faster than the others in recent months across military departments. Michael's version of the transition was triumphant: warfighters on Maven who have seen the newer versions of OpenAI's ChatGPT "liked it a lot better than Anthropic," and they found xAI's Grok "way faster than both of them." The department's internal doctrine has shifted with it — Michael called sole reliance on any single model "one of the mistakes," independent of the Anthropic dispute, and the multi-model ecosystem now excludes Anthropic by design. The Verge has also noted that most AI labs signed the Pentagon's revised terms when they were offered, accepting unconstrained use in exchange for the work. Two of the conditions Anthropic was evicted over — no domestic mass surveillance, no fully autonomous weapons — are therefore not being applied by the vendors now writing those targeting briefs. That is the trade nobody's press release mentions.

The contrarian read is not that Anthropic miscalculated — it is that the refusal had a cost the safety argument doesn't capture. The strongest version of the Pentagon's case never made it into court: a defense department that can have its software constrained by any vendor's terms of service is a department whose operational choices are subject to private veto, and "all lawful purposes" is the kind of demand every procurement officer will make when the alternative is a supplier who can walk. The court protected Anthropic's right to say no; it did not protect Anthropic from the consequences of a customer saying yes to someone else. And the consequences ran in exactly the direction the guardrails were meant to prevent: work that Anthropic refused to do unsupervised is now being done by models with fewer published conditions attached, by companies that took the contract as offered. A principle that changes the vendor while the mission continues has bought a good precedent for the next lab and a weaker set of norms for the targeting pipeline itself. The opposite skeptical read deserves saying too — official migration claims that don't survive basic interviews are a governance problem of their own; if "90% transitioned" coexists with live use in active operations, no oversight body is measuring anything reliably.

The politics arrived upside down. Trump met Dario Amodei twice at the White House last week and called him "great" and "fantastic," while the department whose lawsuit Anthropic is still pursuing finished the eviction; Amodei told reporters that "how we address those risks is still under discussion" but that "if we work with the president, we can win safely." Commerce secretary Howard Lutnick said in early September that Anthropic was "back on the right side" of the administration — days after the California ruling, weeks before the D.C. Circuit went the other way. A thaw at the White House and a courtroom defeat in Washington are not in conflict; they are two channels of the same relationship, and the only channel with a budget is the one doing the buying.

What to watch, in order of datedness. First, Anthropic's next filing: en banc review or a Supreme Court petition, and whether any of it lands before the IPO paperwork does. Second, the named replacement inside Maven — Michael has effectively pointed at ChatGPT, but the department has not put a vendor's name on the targeting stack, and that sentence will eventually be written by someone with a procurement record. Third, the defense contractors: the designation blocks them from using Claude in Pentagon work too, and after months of "still being used last week" surprises, their compliance timeline deserves the same skepticism. And fourth, the thaw — whether the White House warmth produces an actual revision of anything, or just two friendly meetings and a completed eviction.

If a lab can lose the world's largest defense customer over two safety conditions and win in court anyway, is the right to refuse worth the contract? Tell us in the comments.

Read more

Korea probes AI agents in bank hacks as president cites 'signs'

Korea probes AI agents in bank hacks as president cites 'signs'

South Korea opened a formal investigation into whether AI agents drove a wave of bank breaches — and it isn't the only AI story moving money today. President Lee Jae Myung said "signs" point at AI models, and the probe is now at the highest level a national banking sector has seen. Speaking at a cabinet meeting, Lee said that "in some hacking incidents, signs have emerged of AI being used, causing considerable public concern and anxiety," and police have since opened a full-scale investigation

Open Source Radar — October 6: nothing leaves your machine

Open Source Radar — October 6: nothing leaves your machine

Today's trending board is all projects we ran earlier this week, so the fresh signal comes from the Product Hunt launch slate instead — three open-source tools that share one instinct: your phone, your pixels and your MCP traffic should stay on hardware you control. All three verified at the source. iphone-use (Rust, MIT, about 59 stars) is computer-use for a real iPhone: an agent reads the screen as text, taps, swipes and types over WebDriverAgent, and every action comes back with an honest v

DeepSeek nears $12B round with Tencent and CATL ahead of IPO

DeepSeek nears $12B round with Tencent and CATL ahead of IPO

Three stories shape the last 24 hours: a record-scale fundraise at China's most famous model lab, a first-of-its-kind hearing at New York City Hall, and Cohere rebuilding its enterprise agent platform around other people's models. DeepSeek is close to raising at least $12 billion — 80 billion yuan — in a single round that could reach roughly $14.9 billion, after investor demand outstripped the company's own target, with Tencent and battery maker CATL as the biggest contributors, people famili

AI 101 — What are scaling laws?

AI 101 — What are scaling laws?

Scaling laws are the empirical rules describing how an AI model's performance improves in a smooth, predictable curve as three things grow: the size of the model, the amount of data it trains on, and the computing power spent training it. They are not physics — nobody proved them in a lab the way gravity was proven — they are patterns that kept holding every time someone measured them, which is why the entire AI industry now plans around them. The pattern got its canonical statement in a Janua