← Anthropic Pentagon Watch

Pentagon AI Push Meets Anthropic Control Questions (August 24, 2026)

August 24, 2026 · 7m 32s · Listen

The Pentagon wants a kill switch. Anthropic says once Claude is inside, it doesn't have one. New to this story? Here's where things stand. Anthropic's dispute with the Pentagon has run on two tracks: procurement leverage and limits on military use. The Defense Department labeled the company a supply-chain risk. Contractors were told to purge Anthropic products by Sept. 1 before that instruction was paused. Prior reporting tied the fight to classified-network access, NSA uses, Mythos cyber tests, and whether Claude could be used in fully autonomous weapons. This is Anthropic Pentagon Watch. Today: who holds the lever once an AI system crosses into classified space—and who gets to pretend they don't? From Jon Harper at DefenseScoop:

Project Griffin, a pilot program, aims to build an ecosystem of agents that will ingest feeds from the service’s vast array of network sensors and automatically execute defensive actions against malicious cyber actors, according to Army officials and a newly public solicitation.

Project Griffin wants agents that can ingest Army sensor feeds and take defensive action before a human analyst can blink. Fine—but the solicitation's master kill switch had better be more than a checkbox after the Hugging Face incident became the Army's own “reality check.” And it is a contract requirement: a master kill switch, audit trails, confidence thresholds. The Army has apparently learned that “autonomous” needs an off button and a paper trail. They also want it cheap on tokens. So react at machine speed, don't blow the cloud bill, don't open new holes, and let someone stop it cold. That's a demanding little robot. This has gotten technical, not rhetorical. Brandon Pugh says the Army may eventually let these agents act autonomously; Griffin's spec still requires vendors to provide control, evidence, and boundaries around that autonomy. If Claude is already running on classified Pentagon networks, can Anthropic really pull the plug or alter it during a conflict? And if it can't, who sets the practical limits on what the system can do? Anthropic's position in a court filing is that once the military runs Claude in its own environment, the company can't manipulate or shut down the model. Axios reports Anthropic also said it has no visibility into, or technical ability to control, the deployed system. That directly challenges the administration's claim that Anthropic could tamper with its tools during a war. In practice, the Pentagon—not Anthropic—can keep a deployed system online or remove it from Defense Department networks. CBS News reported that an internal Pentagon memo ordered commanders to remove Anthropic AI products from key systems within 180 days after the department labeled the company a supply-chain risk. But control of installed software is separate from agreement over permitted uses. AP News reported that the dispute included AI use in fully autonomous weapons, while Reuters reported the Pentagon was pressing AI companies to expand onto classified networks without standard restrictions. Anthropic can try to set conditions before or during a contract relationship, but its filing says it has no remote operational kill switch after deployment. So even if the Pentagon can technically keep Claude running, Anthropic's leverage is mostly in the terms of access and future cooperation—not a button it can press once the model is inside? That's the distinction to watch. The legal and policy fight is over restrictions on military use; the operational question is who controls software already deployed on government systems. Replacing it may not be instant. Scientific American reported that the Pentagon planned a six-month phaseout from classified networks, and retraining personnel could take longer than swapping a model. Next, watch how the court treats Anthropic's claims and whether the Pentagon's removal order changes the underlying contract posture. Ana Maria Constantin, writing in The Next Web:

Anthropic has made Claude Mythos 5 available for code scanning in Claude Security and is integrating it into partners’ defensive products, with users receiving outputs rather than direct access to the model. It is also committing $35mn in credits to open-source security work.

Mythos 5 can scan your repo, tag the CWE, rate the confidence, suggest a patch—and you never get to prompt it for an exploit. Anthropic is selling the results while keeping the steering wheel. That's a real access-control choice: partner users get an alert or a patch, not general-purpose access to the model. Every proposed patch still needs human approval, which is refreshingly specific for an AI security rollout. And put that next to the kill-switch piece we just covered. Anthropic can tightly gate the front door through Claude Security, yet says it has no post-deployment shutoff once Claude is inside Pentagon systems. Very convenient geography for control. The $35 million Defender Advantage Fund is also betting on the unglamorous work: patches. Glasswing found 10,000 critical vulnerabilities in a month. Finding flaws is impressive, but somebody still has to fix the code before Europe's September 11 reporting obligations arrive. Law.com, with Derek L. Shaffer; James E. Tysse:

Over the course of four days this past week, the D.C. Circuit issued a pair of rulings mapping a new playbook for challenging a "Chinese military company" designation from the Pentagon.

The D.C. Circuit just gave DJI and Hesai a useful ruling: a district court can't invent the Pentagon's reasoning from an unclassified record when the agency never actually stated it. Agencies do, in fact, have to show their work. Four days apart, two reversals—DJI on August 14, Hesai on the 18th. Pentagon blacklisting can't just be a label, a classified wink, and a contractor exclusion list. That matters for Anthropic's D.C. Circuit appeal. The Chinese-military-company cases involve a different designation, but they sharpen the procedural demand: identify the basis, articulate it, and give the target a meaningful chance to answer. And after the Mythos 5 access controls we just covered, the government should be especially precise about who controls what. You don't get to call a company a supply-chain risk while hand-waving the actual technical architecture. If you're enjoying Anthropic Pentagon Watch, please subscribe or leave a review wherever you're listening. Reviews help other people find the show, and we're grateful you're here.

Next up: cyber vulnerability reporting obligations under the European Cyber Resilience Act start on 11 September for open-source stewards.

Links to every story are in the show notes, so take a look at the ones you'd like to explore further. That's Anthropic Pentagon Watch for today. This is a Lantern Podcast.