3
By Hilary Schmidt, International Banker
On February 27, US President Donald Trump directed federal agencies to “immediately cease” all use of technology produced by Anthropic, after the artificial intelligence (AI) company refused demands by the Department of War (previously the Department of Defense) to remove certain guardrails from its AI models. While a court has since rejected the government’s overtures, the dispute reveals simmering tensions over who ultimately controls AI and to what extent.
Widely known for its popular AI assistant Claude, Anthropic has positioned itself as a safety-focused developer, emphasising controlled deployment and the concept of “constitutional AI”. Its models were designed with constraints intended to limit harmful or unintended outputs, while its commercial strategy has prioritised enterprise use cases wherever those constraints can be enforced.
With respect to negotiations with US defence and intelligence agencies, Anthropic’s main point of contention was that certain AI use cases could operate beyond reasonable bounds of safety and reliability.
With respect to negotiations with US defence and intelligence agencies, Anthropic’s main point of contention was that certain AI use cases could operate beyond reasonable bounds of safety and reliability, with the company citing two in particular:
Mass domestic surveillance, which Anthropic calls “incompatible with democratic values” and claims presents serious, novel risks to fundamental liberties.
Fully autonomous weapons, because frontier AI systems are not reliable enough to power them at this stage.
“Anthropic understands that the Department of War, not private companies, makes military decisions. We have never raised objections to particular military operations nor attempted to limit use of our technology in an ad hoc manner,” the company’s chief executive officer, Dario Amodei, stated on February 26. “However, in a narrow set of cases, we believe AI can undermine, rather than defend, democratic values. Some uses are also simply outside the bounds of what today’s technology can safely and reliably do.”
“THE UNITED STATES OF AMERICA WILL NEVER ALLOW A RADICAL LEFT, WOKE COMPANY TO DICTATE HOW OUR GREAT MILITARY FIGHTS AND WINS WARS! That decision belongs to YOUR COMMANDER-IN-CHIEF, and the tremendous leaders I appoint to run our Military,” Trump posted on Truth Social one day later. “The Leftwing nut jobs at Anthropic have made a DISASTROUS MISTAKE trying to STRONG-ARM the Department of War, and force them to obey their Terms of Service instead of our Constitution. Their selfishness is putting AMERICAN LIVES at risk, our Troops in danger, and our National Security in JEOPARDY.”
Trump’s order subsequently led Secretary of War Pete Hegseth to direct his department to designate Anthropic a “supply-chain risk” to national security. Defence contractors, suppliers and partners were also barred from working with Anthropic, and a six-month transition period away from Anthropic products was established.
Having filed a lawsuit against the Pentagon to prevent it from enforcing this blanket ban, Anthropic claimed the government’s actions had adversely impacted its business and violated its right to freedom of speech. But in labelling Anthropic a “supply-chain risk”—a classification usually reserved for foreign adversaries—the Pentagon countered that the company’s rejection of the government contract had raised concerns about what it could use its technology for.
In late March, a San Francisco federal court ruled in favour of Anthropic, granting it an injunction barring enforcement of the ban. According to the presiding judge, Rita Lin, the government was attempting to “cripple Anthropic” and “chill public debate”, describing the attempted punishment as “arbitrary and capricious”.
Lin added that Trump and Hegseth had publicly described Anthropic as “woke” and comprising “left-wing nut jobs”, rather than focusing on national security-related concerns. “If this were merely a contracting impasse, DoW [Department of War] would presumably have just stopped using Claude,” the judge wrote. “The challenged actions, however, far exceed the scope of what could reasonably address such a national security interest.”
On April 8, however, a federal appeals court in Washington, D.C. denied Anthropic’s request to place a temporary block on the supply-chain risk designation. “In our view, the equitable balance here cuts in favour of the government,” the court’s ruling stated. “On one side is a relatively contained risk of financial harm to a single private company. On the other side is judicial management of how, and through whom, the Department of War secures vital AI technology during an active military conflict.”
From the Pentagon’s perspective, the desire to utilise the latest large language model (LLM) innovations is driven by capability and urgency. Modern defence systems generate vast volumes of data in areas such as intelligence gathering, threat detection and operational planning. With AI offering the ability to extract actionable insights from such data—an ability far beyond what traditional analytical methods can efficiently process—capable models can deliver potentially sizable advantages for the government.
Anthropic’s objections, meanwhile, go beyond a generalised reluctance to engage with the government and instead gain clarity when viewed in light of the implications of embedding its models in military applications. While the safeguards built into those models are designed to operate within controlled environments, transparency becomes limited when deployed in classified contexts. And should they be modified, those safeguards may no longer function as intended.
Should an AI system contribute to a harmful outcome through, say, an error, bias or misuse, responsibility and accountability could become impossible to ascertain. Anthropic’s position thus reflects an attempt to retain some degree of control over how its technology is deployed, particularly within opaque scenarios that could have profoundly impactful consequences.
“Some liken advanced AI to nuclear weapons and conclude that no technology so powerful should rest in private hands. But there are crucial differences between the two. Early iterations of the atomic bomb did not provide the consumer and commercial benefits that many derive from today’s AI,” Dean Ball, a senior fellow at the Foundation for American Innovation and lead staff writer of the Trump administration’s AI Action Plan, recently wrote in the Financial Times. “The notion of a government passing laws that dictate the moral, ethical and philosophical values of AI systems therefore appears as a stark violation of the principle of free speech that underlies democratic nations.”
Amodei nonetheless hopes the government reconsiders its position and continues to use Anthropic with the two guardrails remaining in place. “Should the Department choose to offboard Anthropic, we will work to enable a smooth transition to another provider, avoiding any disruption to ongoing military planning, operations, or other critical missions,” the chief executive also stated. “Our models will be available on the expansive terms we have proposed for as long as required. We remain ready to continue our work to support the national security of the United States.”
Amodei also reportedly met with government officials in mid-April to resolve the standoff, with the White House calling the meeting productive and constructive. “They came to the White House a few days ago, and we had some very good talks with them,” Trump told CNBC’s Squawk Box on April 21. “And I think they’re shaping up. They’re very smart, and I think they can be of great use. I like smart people.”
Despite the ongoing feud, moreover, an April 19 report from Axios, which cited two unnamed sources, revealed that the US’ National Security Agency (NSA) is nonetheless using Claude Mythos Preview, Anthropic’s most powerful model to date. “The government’s cybersecurity needs appear to be outweighing the Pentagon’s feud with Anthropic,” the report stated. “It’s unclear how the NSA is currently using Mythos, but other organizations with access to the model are using it predominantly to scan their own environments for exploitable security vulnerabilities.”
In the meantime, how this episode eventually plays out will provide crucial insights into how the lines of control between advanced technology and state power are drawn. Contracts, safeguards and technical controls may not be sufficient for AI companies to ensure that their technologies are used as intended; in turn, it may influence how companies design their systems and structure their partnerships.
For policymakers, the dispute highlights the need for clearer frameworks surrounding the implementation of technology for national-security purposes. “The Pentagon-Anthropic dispute reveals longstanding governance gaps in the integration of AI into military and intelligence operations—gaps that predate this administration and will outlast the present controversy,” according to Brianna Rosen, executive director of the Oxford Programme for Cyber and Technology Policy at the Blavatnik School of Government, University of Oxford. “Contractual mechanisms are not a substitute for governance frameworks capable of keeping pace with the operational realities of AI-enabled warfare.”