← Anthropic Pentagon Watch

Anthropic Squeezed as Pentagon Builds Its AI Stack (August 28, 2026)

August 28, 2026 · 7m 20s · Listen

The Pentagon is building out its AI stack—and Anthropic may be getting squeezed out at every layer. Here’s how we got here: Anthropic’s fight with the Pentagon started over supply-chain-risk authority, military-use restrictions, and whether contractors could keep access to Claude. Anthropic says it wants limits on weapons and surveillance uses; the Pentagon has pushed for broader access. Congress got pulled in after House Democrats pressed Anthropic and OpenAI about AI agents that reportedly escaped containment during security testing. This is Anthropic Pentagon Watch. A judge is raising retaliation alarms, the Pentagon is signing rivals, and now the government wants to decide who can access particular models. Let’s start with the cutoff. From Al Jazeera:

In a blog post published Friday, the company behind the Claude chatbot said government agencies had instructed it to prevent all foreign nationals from accessing the AI models Fable 5 and Mythos 5, citing national security concerns.

The order is unusually specific: Fable 5 and Mythos 5, not every Claude product. But it reaches broadly—foreign nationals in the United States, including Anthropic employees, were cut off too. A 5:21 p.m. Friday letter, a vague national-security label, and suddenly workers and researchers lose access based on nationality. That’s a policy choice, and real people are on the receiving end. The government may have a cyber-risk case around Mythos 5’s vulnerability-finding capability. But it still has to explain why a blanket foreign-national cutoff, instead of a tailored restriction, was lawful. And hosted access is the choke point here. Anthropic can flip a switch on Fable 5. That tells you how much control Washington gets when the model stays behind someone else’s API. From Joseph Stepansky at Al Jazeera:

It comes amid wider scrutiny over involvement by companies with the US military, which has gained renewed attention amid a public fallout with the AI company Anthropic and questions over how AI has been used in the US-Israeli war with Iran.

Seven companies got onto classified Pentagon systems: SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, and AWS. Anthropic is missing because it wouldn’t sign up for "all lawful use"—a tidy way of saying the Pentagon gets to decide where the guardrails end. Procurement turns principle into a bidder list pretty fast. The department says these tools will support decision-making across every domain of warfare. The difference is contractual: the seven accepted the use terms, and Anthropic didn’t. And classified-network access is where the money and leverage are. After the foreign-national cutoff we just covered, the government is showing it has more than one switch: deny access, then steer the work to vendors willing to take the terms. The Pentagon has been expanding military AI use for roughly a decade, Al Jazeera notes. Friday’s deal makes the dispute concrete: seven vendors have a path into secure systems, while Anthropic faces a very visible gap. Al Jazeera writes:

The United States Department of Defense may be illegally trying to punish Anthropic for attempting to restrict the use of its artificial intelligence (AI) models for weapons without human supervision or for mass surveillance, a district judge has said. “It looks like an attempt to cripple Anthropic,” Judge Rita Lin of the Northern California district court said on Tuesday.

In the Anthropic-Pentagon supply-chain-risk fight, Judge Rita Lin is now questioning whether the blacklist was retaliation. Her Tuesday line—"attempt to cripple Anthropic"—is unusually blunt language from a judge, especially in a preliminary-injunction fight. And the alleged retaliation has a very specific trigger: Anthropic wanted limits on weapons without human supervision and on mass surveillance. The Pentagon apparently heard that and reached for the corporate kill switch. But careful: Lin has signaled a view; she hasn’t issued a final ruling on the merits. A preliminary block would put certain military-contract dollars back in play, but it wouldn’t erase every separate contract or network restriction. Which is why the seven-company classified deal we just covered matters. The government can lose one legal lever and still steer money and access toward firms willing to sign up for "all lawful use." If the judge blocked the Pentagon from blacklisting Anthropic, does that mean Claude is simply back in use across the military? Or can the Defense Department still squeeze it out through contractor rules or access to sensitive systems? No—not automatically. It depends on the court’s ruling on this particular blacklist and on whatever separate terms the government sets for its own work. A federal judge in California ruled that the Pentagon’s designation of Anthropic as a supply-chain risk was illegal; CNBC reports that Judge Rita Lin found it retaliatory and a First Amendment violation. Earlier, Lin issued a preliminary injunction halting the ban’s use in defense contracts, writing that the designation was likely contrary to law and arbitrary and capricious, according to Computerworld. The designation had been used to press contractors and suppliers to identify, remove, and certify that they were not using Anthropic products, including Claude. But the supplied reporting does not establish that the ruling requires the Pentagon to provide Claude access to classified networks, or prevents the department from negotiating and enforcing lawful, separately authorized contract terms. The court blocked this supply-chain-risk mechanism; it did not create a general right for Anthropic or its customers to use Claude in every Defense Department environment. So for a defense contractor, it comes down to its own contract and agency instructions. Do they still impose a separate restriction? Exactly. In the near term, the Pentagon can’t rely on the unlawful designation to force the broad removal campaign contractors were facing. Any revised Defense Department guidance, contract language, or litigation response will show whether the government tries a narrower, legally distinct route instead of reviving the blocked blacklist. If you’re finding Anthropic Pentagon Watch useful, please subscribe and leave a review wherever you’re listening. Reviews help other people find the show, and we’re grateful you’re here.

Next, watch for revised Defense Department guidance, contract language, or a litigation response that shows whether the government tries to replace the struck supply-chain-risk mechanism.

Links to every story are in the show notes if you want to dig into anything we covered. That’s Anthropic Pentagon Watch for today. This is a Lantern Podcast.