← Anthropic Pentagon Watch

Anthropic Fight Forces Trump’s Military AI Rules (June 05, 2026)

June 05, 2026 · 8m 53s · Listen

Six Anthropic engineers are sitting inside Fort Meade helping hack China — while the same Pentagon that gave them a desk is in court calling them a national security risk. This is Anthropic Pentagon Watch for Friday. NSPM-11 drops today, Hegseth's digging in despite the injunction, and that Decrypt story blows the lid off the whole contradiction. Pete, where do you want to start? Start with the badge. The procurement arm calls them a threat in the Ninth Circuit, the intelligence arm hands them clearance at NSA. Same week. Same company. And they're also the company that published a report this week warning AI could soon build itself with no humans in the loop. Sword, shield, and the loudest voice in the room saying, 'wait, should we?' One thing on the memo itself: NSPM-11 is addressed to the Secretary of War. That title hasn't been used officially since 1947. It also loops in Treasury, DNI, CIA, and OMB alongside DoD. So on the governance gap we talked about Wednesday: it still doesn't close the 'covered frontier model' definition, but it does put a lot more agencies in the room. And I want to know if NSPM-11 touches offensive cyber, because if it does, it's either constraining or green-lighting exactly what those six engineers are doing inside Fort Meade right now. Set that next to Admiral Bradley's testimony Thursday — humans must have confidence in the outcome. Anthropic just embedded six people in an offensive operation against China. Bradley's oversight line, meet operational reality. Right, and it cuts both ways. The injunction partly rests on Anthropic drawing principled lines — no autonomous lethal systems, no mass surveillance. The NSA story shows they'll absolutely do offensive work. So which is it? Which brings us to Hegseth. He's doubling down on the supply-chain designation — but the mechanism is enjoined. So what does 'doubling down' even mean when a federal court has blocked the tool? And contractors reading Mayer Brown's guidance this morning are staring at one signal from the White House and a conflicting one from the bench. That's the live procurement story. Here's the part I can't let go. The safety report is the brand. The NSA contract is the revenue. Pause-AI on the masthead, offensive cyber in the basement. The week opened as a fight over a label. It's closing with engineers at Fort Meade, a memo restructuring AI authority, and a defense secretary defying an injunction. We'll watch whether the court has anything to say about that. Stay with us. This one's from Yahoo:

Defense Secretary Pete Hegseth has denied Anthropic’s request to reconsider the AI startup’s designation as a national security risk, the Pentagon told the D.C. Circuit Court of Appeals on Thursday. The move clears the way for a three-judge panel to decide the novel questions raised in Anthropic’s lawsuit challenging the Defense Department’s designation and the scope of its powers over domestic companies.

Hegseth denied Anthropic's reconsideration request June 3 — and told the D.C. Circuit on Thursday. Which actually helps the court: the panel was worried it'd have to wait on the Pentagon's internal process before ruling. That wait is over. Right, so he clears the runway for a ruling — from a panel that already signaled in March it's inclined to give the executive branch sweeping authority to label a U.S. company a supply-chain risk. A label that, until now, was reserved for firms tied to foreign adversaries. And the judges left themselves a door — they suggested the downstream directives, the actual bar on agencies using Anthropic's products, could still be challenged separately. So the designation might survive while the enforcement gets picked apart. Don't forget where this started. The Pentagon already had a two-hundred-million-dollar contract with Anthropic. Then it asked for unrestricted access, Anthropic said no to stripping its surveillance and autonomous-weapons guardrails — and suddenly it's a national security risk. It's not hard to see why Anthropic keeps pointing to that timeline. Hegseth's phrase was 'pre-deployment risks.' That's now standing in for the contract fight. From The White House:

Artificial intelligence (AI) will be among the most transformative technologies to national security in the history of the United States. When adopted appropriately, AI can help protect our warfighters during peacetime and on the battlefield, enable precise operations that minimize harm to civilians, and ensure the United States continues to maintain technical overmatch against our adversaries and strategic competitors.

NSPM-11 dropped today, and the first thing that jumps out is the addressee list: 'The Secretary of War.' That title hasn't been used officially since 1947. Nineteen forty-seven. So either someone's making a rhetorical statement or a staffer was drafting from a very old template. Both are telling. And look who else is cc'd — Treasury, DNI, CIA, OMB, the FBI. The whole apparatus. The White House is restructuring who actually holds AI authority, not just leaving it with DoD. Here's the part that made me sit up. Maggie Eastland reports the memo requires national security agencies to work with more than one AI provider. Read that against where we are this week — the Pentagon's near-total reliance on the one company it's trying to blacklist. So the same executive branch defending the Anthropic designation in court just signed a memo built around one idea: don't depend on a single vendor. That tells you how cornered they felt. And there's a 30-day model review window baked in, Somto Nwanolue reports. Thirty days to vet a new model for national security suitability. Where've we heard a thirty-day clock before? It rhymes with the enforcement window on the designation we covered earlier. The executive branch loves its thirty-day clocks. The courts, less so. From Jose Antonio Lanz at Decrypt:

Anthropic has placed about six engineers inside the National Security Agency to help deploy Mythos—its most capable AI model—for offensive cyber operations, the Financial Times reported Thursday. The engineers are forward-deployed staff, customizing the model for specific applications. One source told the FT it could be useful for infiltrating networks in countries like China and Iran.

Six engineers. Forward-deployed inside Fort Meade, customizing Mythos for offensive cyber ops against China and Iran — that's the Financial Times reporting. The same model Anthropic won't sell to the public because it's too dangerous if misused. And the same company the Pentagon just branded a supply-chain risk — a label they normally save for Huawei. We covered Hegseth doubling down on that an hour ago. So one badge says 'foreign adversary,' the other says 'come on in, here's a desk at the NSA.' Right, and read the fine print — the NSA contract was exempt from the autonomous-weapons and surveillance ban. So the line they drew, the one the whole lawsuit leans on? They carved out an exception for signals intelligence. That complicates the principled-refusal narrative. Anthropic published a report this week warning AI could soon build itself with no human in the loop — while its staff sit inside an agency running it offensively. Both can be sincere. They can't both be the whole story. The Pause-AI report is brand management. The revenue is Mythos at Fort Meade. Anthropic's the sword, the shield, and the guy in the corner asking if we should really be doing this. If you follow the power struggles shaping AI, try Musk v Altman Daily — a daily court-watch on Elon Musk's trial against Sam Altman, OpenAI, and Microsoft, covering testimony, exhibits, and the AGI governance fight. Find it wherever you listen to podcasts.

You’ll find links to every story we covered today in the show notes. If something caught your ear, take a minute to read through the source material there.

That’s Anthropic Pentagon Watch for today. This is a Lantern Podcast.