A judge hit pause on the Pentagon — and now the whole thing turns on the First Amendment. Refusing to sell can apparently be protected speech. If you're just joining us, Anthropic's been fighting the Pentagon over whether Claude can be used in military settings without company-enforceable limits. Things escalated when the government treated Anthropic as a supply-chain risk, restricting access across government and its contractors. Meanwhile, the Pentagon moved ahead with classified-network AI work involving other companies after Anthropic resisted unrestricted access for all lawful military use. This is Anthropic Pentagon Watch. Today: one researcher's five-month push for a 25-page framework that a warfighting expert liked. Google signed anyway. And the safety field went quiet. Was this a legitimate procurement call, or punishment for a vendor that said no? That's what we're looking at. Let's get into it. Anthropic-Pentagon supply-chain-risk fight isn't over. Follow us wherever you're listening, and the next chapter comes to you. TemperatureZero, with Maxim Starkweather:
The Pentagon’s position in early 2026 was consistent: AI companies operating in classified environments needed to permit “any lawful government purpose” without restrictions the companies could enforce on their own. The pressure arrived simultaneously at Anthropic and Google in February. What happened next at each company is documented in detail. Anthropic refused. Dario Amodei declined to remove two specific safeguards: a ban on mass surveillance of American citizens and a restriction on fully autonomous lethal decision-making.
Alex Turner spent five months on a 25-page oversight framework. He asked for meetings with Jeff Dean and Demis Hassabis, even flew to Paris to make the case. Then, at 11:45 at night, he found out over Signal that Google had signed. The deal was classified and done. The restrictions? Non-binding. And here's the procurement detail that matters: a foremost expert on human-AI warfighting read that framework and called it 'actually pretty good.' A workable proposal was on the table. It got reviewed, then bypassed. That's the part I can't get past. Nobody can say they didn't know what good looked like. Somebody at Google saw a passing grade and chose the version with no teeth. I want the name of whoever made that call. Turner's account at turntrout.com reads almost like a clinical report. Safety commitments don't die in one dramatic betrayal; they die through a series of individually defensible deferrals. Everybody's reasonable, nothing stops, and the deal's signed by April. And here's the part nobody wants to sit with: the safety field said nothing. A guy quits DeepMind on June 9, publishes the receipts on July 15, and the community that fundraises on this exact scenario goes quiet the second a real line hits a real contract. That tells you about the incentives, not the ethics. When the disagreement was abstract, everyone had a position paper. When it cost a Pentagon contract, the room emptied out. Okay, so a company says, 'Don't use our AI to run killer robots.' The Pentagon calls it a national security threat. How does a fight over contract terms become a First Amendment case in federal court? Right. The key is what happened after Anthropic drew those lines. In the court filing, Anthropic says Claude isn't ready to be used safely in fully autonomous lethal weapons or mass surveillance of Americans. If the government wants to license the technology, it has to agree in writing not to use it that way. According to the lawsuit filed in the Northern District of California, the Pentagon responded by designating Anthropic a 'supply chain risk.' That's a label the government can apply to companies it says could expose military systems to infiltration. Defense Secretary Pete Hegseth then moved to sever government ties with the company entirely. President Trump followed with a directive ordering all federal agencies to stop using Anthropic's technology. In a 43-page opinion, Judge Rita Lin found that those actions appeared 'designed to punish Anthropic' rather than protect national security. She also noted that Anthropic's product has never actually been found to pose a security problem. The court order says punishing a company for taking a public position on how its technology should be used is, in Judge Lin's words, 'classic illegal First Amendment retaliation.' So the theory is straightforward: Anthropic spoke publicly about AI safety limits, and the government used procurement power to make it pay for saying so. But doesn't the Pentagon have broad authority to decide who it buys from on national security grounds? Where's the legal line between a legitimate procurement call and unconstitutional retaliation? That's exactly the tension the court flagged. The opinion says the broader public-policy question — who decides what's safe for military AI — isn't ultimately for the court to resolve. What the court can police is whether the government used a legitimate national security tool as cover for punishing protected speech. Judge Lin's finding that the actions were 'unauthorized by any statute' is the one to watch, because the Pentagon may need to show a cleaner legal basis for the designation if it wants it to stick on appeal. The injunction is preliminary, so the underlying merits fight — including where procurement discretion ends and retaliation begins — is still very much alive. Bernice Yeung, writing in Bulletin of the Atomic Scientists:
Within a couple of decades, the US defense industrial base shrank from dozens of firms to today’s so-called Big Five—Lockheed Martin, RTX (formerly Raytheon), General Dynamics, Boeing, and Northrop Grumman, which together receive about a third of the Defense Department’s annual contract obligations.
The Bulletin puts six logos over a photo of Pentagon plaques: Meta, xAI, Google, Microsoft, Anthropic, and OpenAI. The Pentagon opened its checkbook for five. The one with a position got a procurement freeze. And Bernice Yeung's frame is worth sitting with: this goes back to what they call 'the Last Supper' in 1993, when the Pentagon told contractors to shrink. Silicon Valley just spent thirty years walking into the room that emptied out. So the freeze sorts the field. Compliant labs stay in; Anthropic stays out. The industrial base reorganizes around that. Right — Anthropic's in the graphic but not in the contract. You can see the whole story in that one image. The military-technology complex has a guest list. Compliance gets you in. If you follow the infrastructure behind AI, check out The Data Center Daily. It covers hyperscaler spending, the power grid, semiconductor supply, and energy markets reshaped by intelligence at scale. Find it wherever you listen to podcasts.
Links to every story are in the show notes, if you’d like to spend more time with any that caught your attention.
That’s Anthropic Pentagon Watch for today. This is a Lantern Podcast.