For months, the standoff between Anthropic and the Department of Defense looked like a fight over access to Claude. Now, for the first time, the principals’ own words are in the public record — and they show the real argument was something far more consequential: whether an AI company can hold an ethical line on autonomous weapons and domestic surveillance against the most powerful military customer on earth, and what it costs when it does.

Court documents unsealed July 2, 2026, in the U.S. District Court for the Northern District of California — first reported by the Wall Street Journal and published in full by Gizmodo — reveal a tense private exchange between Anthropic CEO Dario Amodei and Emil Michael, the Pentagon’s Under Secretary of Defense for Research and Engineering. The emails trace the final weeks of contract negotiations before the relationship collapsed into litigation, and they establish that the core dispute was never about capabilities. It was about control — specifically, whether the Pentagon could deploy Anthropic’s Claude model for fully autonomous weapons and domestic surveillance programs without restriction.

That is not a small or abstract question. It is the architectural question at the center of how AI will integrate into military kill chains for the next generation. The unsealed court filings now show that the Pentagon’s chief AI negotiator declared talks “very close” the day after the supply-chain risk designation against Anthropic was finalized — and before the company had even been told.

Anthropic’s Two Red Lines: Autonomous Weapons and Domestic Surveillance

From the earliest rounds of talks, Amodei held to two firm restrictions on how the Pentagon could deploy Claude: the model could not be used for fully autonomous weapons systems, and it could not be used for domestic surveillance. These were not vague guidelines buried in a terms-of-service document. They were explicit dealbreakers, restated consistently across months of negotiation.

Understanding why those two lines matter requires understanding what they forbid. DoD Directive 3000.09, the department’s own policy on autonomous weapon systems, defines a fully autonomous system as one that “once activated, can select and engage targets without further intervention by a human operator” — what defense policy analysts call the “human out of the loop” scenario. The directive requires “human judgment over the use of force” but does not require manual human control at every step of an engagement. A human may authorize a weapon’s deployment and then stand back while the system selects and fires autonomously — and that remains compliant with DODD 3000.09.

Anthropic’s redline implicitly demanded something stricter: that Claude not serve as a decision node in any targeting pipeline that operates without a human in the loop at the moment of a lethal decision. Amodei stated publicly that frontier AI systems are “simply not reliable enough to power fully autonomous weapons” — a specific engineering claim, not merely a policy preference, about the current reliability of AI under combat conditions.

The Pentagon’s counterposition was equally consistent. Defense officials wanted access to Claude for “all lawful uses” — a phrase that sounds measured until you recognize what it includes. As Amodei pointed out in the emails, U.S. law does permit domestic surveillance in certain circumstances. Accepting the “all lawful uses” framing would have effectively deleted Anthropic’s two red lines without formally crossing them.

The Emails: What “Not Workable” Looks Like in Writing

The talks began to unravel in January 2026, when Michael emailed Amodei after weeks of silence. His message was direct: he was “hoping that we are closer to engaging with your revised POV” — signaling he expected Anthropic had reconsidered its position.

It had not. Amodei responded by restating the same two restrictions. Michael’s reply offered what amounted to an ultimatum: Anthropic had “one more chance to align on core principles” before the parties would go their separate ways. He also rejected Amodei’s attempt to distinguish between offensive and defensive military applications: “There is no distinction in our world between weapons that are defensive or offensive” — a framing that left Anthropic’s guardrail architecture with no foothold.

When Amodei flagged that the Pentagon’s proposed contract language appeared to “completely remove our redlines,” Michael did not dispute it. He called Anthropic’s guardrails “just not workable.” Defense Secretary Pete Hegseth announced the supply-chain risk designation the following day.

The Timing That a Federal Judge Called “Exceedingly Difficult to Square”

The most significant detail in the unsealed documents is the sequence of events. According to reporting on the court record, the supply-chain risk designation against Anthropic was finalized on a given day. The next day — before Anthropic had been told — Michael emailed Amodei with a draft of Anthropic’s usage terms, writing: “After reviewing with our attorneys and seeing your last draft (thanks for being fast), I think we are very close here.”

Federal Judge Rita Lin quoted that exchange directly in her March 26 ruling granting Anthropic a preliminary injunction, calling it “exceedingly difficult to square” with the government’s simultaneous characterization of Anthropic as hostile and a national security threat. In her 43-page opinion, Lin found that the supply-chain risk memorandum cited Anthropic’s “increasingly hostile manner through the press” as justification — language she described as “classic illegal First Amendment retaliation.”

Her ruling was direct: “Nothing in the governing statute supports the Orwellian notion that an American company may be branded a potential adversary and saboteur of the U.S. for expressing disagreement with the government.”

What “Supply Chain Risk” Actually Means — and Why This Case Is Unprecedented

The supply-chain risk designation used against Anthropic comes from 10 U.S.C. 3252, the Federal Acquisition Supply Chain Security Act. Until February 27, 2026, that authority had never been applied to a domestic U.S. company. Its prior applications targeted firms with ties to foreign adversaries — entities suspected of allowing hostile governments to embed surveillance capabilities in hardware or software destined for U.S. government systems.

Branding Anthropic with that designation required the Pentagon to argue that an American AI company’s refusal to remove its ethical guardrails made it a supply-chain threat equivalent to a foreign adversary. Anthropic’s lawsuit challenged that framing directly, arguing the designation violated its First Amendment rights and exceeded the statute’s authority, which requires the government to use “the least restrictive means” to address supply-chain concerns. If the secretary’s concern was Claude’s reliability in classified operations, Lin noted in her ruling, the department could simply stop using Claude — it had no authority to blacklist the company as a national security threat.

The N.D. Cal. injunction is currently in force, blocking enforcement of the designation. The D.C. Circuit denied Anthropic’s request for a stay in April, leaving the company in a split legal position: the designation remains nominally active while litigation continues. At D.C. Circuit oral arguments on May 20, Judge Karen LeCraft Henderson called the Pentagon’s move “a spectacular overreach by the Department.”

The Conflict-of-Interest Shadow

The emails arrive alongside a separately troubling financial disclosure. Emil Michael — the official who pressed hardest for Anthropic to remove its guardrails — held between $2 million and $10 million in Perplexity AI stock, a direct competitor to Anthropic, according to financial disclosures reviewed by the Lever and reported by ProPublica. Michael had previously sat on Perplexity’s board, resigning at the start of 2025 but retaining millions in vested and unvested shares.

Michael had also held xAI stock — Elon Musk’s AI company and another Anthropic competitor — worth between $500,000 and $1 million at original disclosure, which he sold on January 9, 2026, for between $5 million and $25 million, a return of between 400% and 4,800%, per Office of Government Ethics filings. The Pentagon subsequently moved to bring xAI’s Grok model onto classified systems — work that had previously been reserved for Anthropic’s Claude.

Whether these financial interests shaped Michael’s negotiating posture is not established by the emails. What is established is that the official pressing hardest for Anthropic to abandon its guardrails held significant equity in Anthropic’s competitors while doing so. Sen. Elizabeth Warren raised the conflict-of-interest question in a letter to Michael during his confirmation hearing.

What the Emails Mean Beyond Washington

Anthropic’s litigation is, on paper, about a specific contract and a specific legal designation. The unsealed emails elevate it into something more structural: a test case for whether AI companies can impose ethical limits on government customers without being branded national security threats for trying.

The question is not merely academic. The EU AI Act is still working through where to draw lines on military and surveillance AI applications. European governments are weighing AI procurement from U.S. labs and asking how much control any American AI company retains once its models enter classified pipelines. The Anthropic-Pentagon case is now the most detailed public answer available — and it shows that a domestic U.S. company, holding to widely accepted ethical limits on autonomous weapons and surveillance, was designated a foreign-adversary-level threat for refusing to drop them.

OpenAI signed a Pentagon deal hours after Anthropic was blacklisted, with CEO Sam Altman later conceding the timing “looked opportunistic and sloppy.” Google signed a similar deal despite 950 of its employees signing an open letter asking it not to. The competitive pressure to abandon ethical limits in exchange for government contracts now has a documented price tag on the other side: Anthropic’s experience shows what happens to a company that doesn’t.

Where the Case Stands Now

As of July 4, 2026, the N.D. Cal. preliminary injunction blocking enforcement of the supply-chain designation remains in effect. The D.C. Circuit case is pending a ruling after May 20 oral arguments. Contract cancellations within the DoD are proceeding on a 180-day timeline, and Anthropic cannot currently serve as a prime contractor or subcontractor on covered DoD systems.

In a separate but related development, the U.S. government lifted export controls on Anthropic’s Claude Fable 5 and Mythos 5 models on July 1, 2026, after a June 12 shutdown triggered by national security concerns about the models’ cyber capabilities. Anthropic agreed to proactively detect and address security risks and inform the government of malicious activity. That resolution does not affect the pending supply-chain designation litigation, which remains unresolved.

The unsealed emails will not settle that litigation. But they do something the months of public statements and court filings had not: they show, in the principals’ own words, where the line was, why it held — and what it cost to hold it.

Frequently Asked Questions

Why did the Pentagon designate Anthropic a supply chain risk?

The Pentagon said Anthropic’s refusal to allow Claude to be used for “all lawful uses” — including fully autonomous weapons and domestic surveillance — made the company an operational risk to military missions. Critics, and Federal Judge Rita Lin, found the real trigger was Anthropic speaking publicly against those uses, which Lin characterized as illegal First Amendment retaliation. The designation is the first ever applied to a domestic U.S. company; it had previously been reserved for foreign adversaries.

What are Anthropic’s AI red lines, and are they enforceable?

Anthropic maintains two hard limits on Claude: no fully autonomous weapons (targeting systems that operate without a human in the decision loop at the moment of engagement) and no domestic mass surveillance. The court record confirms the Pentagon was aware of these limits before signing the initial $200 million contract in July 2025. Anthropic argued in court that it cannot override Claude once the model is deployed on classified networks — meaning enforcement depends on contract language, not real-time monitoring.

What did the unsealed emails actually show?

The most significant finding is the timing. The Pentagon’s supply-chain risk designation against Anthropic was finalized on a given day. The following day — before Anthropic had been told — Pentagon Under Secretary Emil Michael emailed Dario Amodei declaring the two sides “very close” on contract terms. Judge Lin quoted that exchange directly and called it “exceedingly difficult to square” with the government’s simultaneous framing of Anthropic as a hostile national security threat.

Can a U.S. government contractor lose its contracts for publicly criticizing government policy?

Under First Amendment retaliation doctrine established in Supreme Court precedents including Umbehr v. Board of County Commissioners, the government cannot terminate a contractor’s agreement in retaliation for protected speech. Judge Lin found Anthropic met that standard, citing the supply-chain memorandum’s explicit reference to Anthropic’s “increasingly hostile manner through the press” as the trigger for the designation. The government is appealing that finding.