Anthropic just got cleared for 100-plus federal orgs and hired the woman who built AWS GovCloud — three weeks after Washington called it a supply-chain risk. If you're just joining, here's where we are. Commerce ordered Anthropic to cut off foreign-national access to Fable 5 and Mythos 5 after reporting about a contested jailbreak tied to offensive cyber capability. Access came back in stages, Fable eventually came back worldwide — and we still didn't know whether Washington's safety checks would become a permanent condition for releasing a frontier model. This is Anthropic Pentagon Watch. Today — a revolving-door hire, a product beta nobody's named the security tier for, and Lawfare finally saying out loud why the Pentagon went after them. Let's start with Teresa Carlson. If Anthropic binding AI regulation push matters to you, hit follow — we'll be back on it soon. Explosion, with Daniel Park:
The Trump administration has given the green light to over 100 U.S. companies and government agencies to use Anthropic’s cutting-edge AI model, Mythos 5. This follows weeks of discussions between the White House and the San Francisco-based AI company.
So, the latest: Mythos 5 access is now cleared for more than 100 U.S. organizations, per TechCrunch and the Seoul Economic Daily writeup. And important detail — that clearance extends to non-American employees at those orgs. Weeks of negotiations, a hundred-plus orgs, and this nice soft pharma-approval metaphor. But nobody published what actually got Mythos cleared. Wired skips that part too — access was limited or suspended, then restored for a select group. Restored under what standard? We don't know. The clearance came before any measurement framework. A hundred agencies signed off on a model against criteria that don't exist on paper. What exactly did they approve? And the export-control framing is almost quaint here — they're gating a model that non-citizen employees at cleared orgs can now touch. That's a very porous fence. Here's FedScoop:
Longtime IT industry leader Teresa Carlson has joined Anthropic to lead its public sector strategy as the artificial intelligence company navigates relationships with the U.S. and other governments. Carlson — who is known for her past leadership at Microsoft and Amazon Web Services — is now Anthropic’s global head of public sector, the Claude maker shared Tuesday.
Teresa Carlson. A decade running federal sales at Microsoft, another decade building AWS GovCloud. The title says public sector strategy. The résumé says she knows exactly which doors open and who's standing behind them. Per FedScoop, it's the first time the company has even had that title. And the timing matters — right after 100-plus orgs get cleared for Mythos, they bring in someone who's spent twenty years inside the federal contracting machine. And from the two biggest hyperscaler contractors in the space, no less. That's a revolving-door pipeline with a LinkedIn bio attached. I want to know which agencies already have warm relationships with her, and whether any of them sat on that clearance list. I'd read it as counter-procurement. Carlson knows blacklisting from the inside — how a supply-chain designation actually bites, and how you fight one. This goes way past comms; it's the machine Anthropic needs if it wants to survive the next designation. From Lawfare:
When Anthropic, the U.S. company behind the Claude artificial intelligence (AI) tool, refused to allow its product to be used for mass domestic surveillance or fully autonomous weapons, the Department of Defense took the extraordinary step of designating the company a “supply chain” risk—a move that would bar Pentagon contractors from doing business with Anthropic.
Lawfare takes the fight we've been circling all week and zooms out. Yes, there are legal hooks — First Amendment, the APA — but they argue those can miss the deeper problem: what happens when core governance runs on a vendor's model. And Lawfare puts the quiet part on the record. DoD branded Anthropic a supply-chain risk because the company said no to mass domestic surveillance and no to fully autonomous weapons. That's the sequence, sourced. Which reframes the injunction fight in front of Judge Lin. If the designation was a policy dispute dressed as a security finding, the Pentagon has to show a judge actual evidence on the merits — and now there's a serious legal outlet arguing this reaches constitutional stakes, beyond a contract fight. So walk it forward. They punished the contractor for refusing autonomous weapons, and now — alongside the Carlson hire we just hit — that same contractor is cleared to a hundred-plus agencies. You brand a company a threat, then hand it the government's whole desktop. Pick one. The emergency's cooling, but Lawfare's governance question is getting bigger. Every agency now running on Claude is a governance dependency nobody voted on. Here's Claude by Anthropic:
Claude Code and Claude Cowork are now available in public beta in Claude for Government Desktop, built on the same application our commercial customers use and delivered through a FedRAMP High authorized environment. With Claude Code, public sector teams can build and modernize the software systems that underpin public services.
The July 7 government blog gives us the missing piece from earlier — FedRAMP High. Claude Code and Claude Cowork, public beta, running inference inside a FedRAMP High authorized environment. So that's the tier. FedRAMP High is real, I'll give them that. But read the fine print — RFP reviews, casework, memo drafting. This goes beyond coding infrastructure. They're doing the actual government paperwork now. The interesting part is the governance layer — tamper-evident audit logs, per-department spending controls, documentation built to support the agency ATO process. They've engineered this to slide straight through authorization. Right, and pair that with the Carlson hire we just talked about. She knows the ATO process cold from AWS GovCloud. So the product ships with audit logs and the person who built the federal cloud playbook walks in the same week? That's a machine, fully assembled. Conversation history stored locally on the agency-managed device, inference inside the boundary. On paper that's a clean data-sovereignty story. On paper. From Del Schlangen at Orion Policy Institute:
Over the next eighteen days the government reversed itself in stages, first restoring Mythos to a set of approved partners, then lifting the controls entirely, a walk-back as unstandardized as the original ban. By July 1, Fable was back online worldwide. Whether any step along the way was justified is difficult to know, because none of it could be checked against a systematic public record of what AI actually does in real cyber intrusions.
Here's the tell in this Orion brief: Commerce banned Fable and Mythos on June 12 over a jailbreak that unlocked offensive cyber capability — then Anthropic turned around and said those same capabilities live in rival models that got zero enforcement. Same risk, one target. And Orion's point is that nobody could check any of it. The ban, the staged reversal, the July 1 restore — none of it ran against a real measurement standard. Eighteen days. Full global shutdown to full global restore, in stages, and Orion calls the walk-back as unstandardized as the ban itself. So what changed between June 12 and July 1? Not the model. Which lines up uncomfortably with the 100-plus-org clearance we hit earlier — access granted before anyone published what counts as clearance. Orion's saying the measurement framework still doesn't exist. Right. They cleared it for a hundred-plus orgs without a yardstick. Confidence is free when nobody's grading you. Got a tip, a story idea, or a correction for us? Send it to anthropicpentagonwatch at lantern podcasts dot com. We read what comes in, and it helps sharpen the next briefing.
What we’re watching next: whether the final cyber reporting rule adds questions about AI’s role in real intrusions.
We’ve put links to every story from today’s briefing in the show notes, so if you want to dig into any of it, you can pick it up there. That’s Anthropic Pentagon Watch for today. This is a Lantern Podcast.