← Anthropic Pentagon Watch

Anthropic’s Pentagon Win Still Leaves Claude in Contract Limbo (September 02, 2026)

September 02, 2026 · 8m 7s · Listen

Anthropic beat the Pentagon in court—so why are Claude users still reading the fine print? Quick context before today's development: Anthropic’s dispute with the Pentagon now covers the government’s supply-chain-risk label and Anthropic’s restrictions on military uses of Claude. It also affects whether contractors can keep access to Claude. The Pentagon has added ChatGPT Mil and Grok for Government to GenAI.mil alongside Gemini, while Claude remains outside the portal as the legal fight continues. This is Anthropic Pentagon Watch. Today, it’s a court win, a White House directive, and contractors caught in the middle. This story isn't over: Anthropic-Pentagon supply-chain-risk fight. Follow us wherever you're listening, and the next chapter comes to you. Emilia David, writing in GovInfoSecurity:

The decision, from the U.S. District Court for the District of Northern California Judge Rita F. Lin, will hardly be the last word on the matte, especially because government is almost certain to appeal and litigation is still ongoing in a second, related case in the United States Court of Appeals for the District of Columbia Circuit.

The Anthropic-Pentagon blacklist fight we tracked after Judge Rita Lin’s ruling now moves to contractors waiting on an appeal and D.C. litigation. The court order helps, but contractors still don’t have a procurement permission slip. And the people left holding the bag are the integrators who already built Claude into federal work. GovInfoSecurity says contracts with Federal Acquisition Supply Chain Security Act language may have to wait on the D.C. Circuit—so the Pentagon’s mess gets pushed down the supply chain. These are different cases with different theories. Judge Lin ruled on constitutional and administrative grounds; the D.C. Circuit case challenges the Pentagon’s use of that supply-chain statute. Contractors need to understand both, because an appeal is almost certain and the clause language suddenly matters more than anyone’s victory lap. Anthropic gets the headline. The contractor gets a compliance meeting, outside counsel, and a customer asking whether Claude can stay in the stack. Very efficient system, if your product is uncertainty. If the White House ordered agencies to stop using Anthropic, how can a judge strike down the Pentagon’s blacklist at the same time? And what does that mean for contracts already involving Claude or contractors that use it? Short version: these were related government actions, and the court found the campaign against Anthropic unlawful. The Pentagon labeled Anthropic a national-security “supply-chain risk” after a dispute over restrictions on military uses of Claude, including domestic surveillance and autonomous weapons, according to WIRED and Computerworld. President Trump then directed federal agencies not to use Anthropic technology, while the Pentagon’s designation also put pressure on companies with government contracts. But Judge Rita Lin of the Northern District of California ruled that the government’s actions were unlawful retaliation and vacated the directives against using Anthropic’s technology, Ars Technica reports. Computerworld reports that the judge found no legitimate basis for federal authorities to tell government contractors they could not work with Anthropic. The White House order explains what agencies were told to do; the ruling addresses whether the government could lawfully exclude Anthropic in the first place. So procurement contracts don’t all change overnight. But the ruling does remove the government’s legal basis for treating Anthropic as off-limits? That’s the practical takeaway from the reporting on the ruling: the supply-chain-risk designation and related directives were nullified, undercutting the blanket ban on agencies and contractors using Anthropic. Now watch how the administration implements the order—and whether it tries a different procurement policy with an actual legal footing, rather than the designation the judge rejected. This one's from OpenAI:

This language makes explicit that our tools will not be used to conduct domestic surveillance of U.S. persons, including through the procurement or use of commercially acquired personal or identifiable information. The Department also affirmed that our services will not be used by Department of War intelligence agencies like the NSA. Any services to those agencies would require a new agreement.

OpenAI got its limits written into the Department of War agreement: no domestic surveillance of U.S. persons, including bought personal data, and no NSA access without a separate deal. Contracts: still a surprisingly useful invention. And put that beside the Anthropic mess we just covered: OpenAI has signed terms; contractors using Claude are stuck reading an appeal docket and a White House directive. The integrators carry the whiplash. OpenAI also says it wants this framework available to every AI company. Sensible ask—though a negotiated clause gives vendors and contractors clearer protection than a retaliation ruling the government can keep litigating. Here's one from Hacker News:

Not great? Seems kind of loose language? It isn't OpenAI saying no autonomous weapons use, but only that use must be consistent with laws, regulations, and department policies: "The Department of War may use the AI System for all lawful purposes, consistent with applicable law, operational requirements, and well-established safety and oversight protocols.

Hacker News has the read right. “All lawful purposes” leaves a barn door open for military use; law and Pentagon policy are not hard limits on autonomous weapons. The agreement is strongest where it’s specific—U.S.-person surveillance and NSA access. Its broader operational language deserves much less applause. Over on Hacker News:

For intelligence activities, any handling of private information will comply with the Fourth Amendment, the National Security Act of 1947 and the Foreign Intelligence and Surveillance Act of 1978, Executive Order 12333, and applicable DoD directives requiring a defined foreign intelligence purpose. The AI System shall not be used for unconstrained monitoring of U.S. persons’ private information as consistent with these authorities.

Fourth Amendment, FISA, Executive Order 12333—fine, those are legal guardrails. But “defined foreign intelligence purpose” can cover an enormous amount of surveillance, and AI makes it cheaper to run at scale. Over on Hacker News:

I don't think Anthropic is a saint that will never do anything unethical. I don't think ChatGPT is any better or worse. But I do think my cancelling ChatGPT so I can try Claude, at this time, sends the message I want to send, which is why I did it.

Consumers can vote with subscriptions. Federal buyers, though, need usable contract language, enforceable remedies, and clarity for the contractors actually deploying the system. Have feedback, a story idea, or a correction? Email us at anthropicpentagonwatch at lantern podcasts dot com. Your notes help us make Anthropic Pentagon Watch more useful, so we’d love to hear from you.

We’re watching to see whether the Pentagon appeals Judge Rita Lin’s Aug. 27 order removing Anthropic’s supply-chain-risk designation. We’re also awaiting the D.C. Circuit’s decision on the Federal Acquisition Supply Chain Security Act rationale for Anthropic’s blacklisting.

Links to every story are in the show notes, so take a look at the ones you’d like to read in full. That’s Anthropic Pentagon Watch for today. This is a Lantern Podcast.