The Brief

The Department of Defense has designated Anthropic a “supply chain risk” — a label historically applied only to foreign adversaries — after the AI company refused to allow its Claude model to be used for autonomous weapons or mass domestic surveillance. Anthropic filed two federal lawsuits on Monday alleging the action constitutes First Amendment retaliation and exceeds statutory authority, calling the designation “unprecedented and unlawful.”

The Report

Anthropic, maker of the Claude AI model, sued the Trump administration in two federal courts on Monday after the Pentagon formally designated the company a supply chain risk to national security — effectively blacklisting it from defence work and barring military contractors from using its technology.

The suits, filed in the U.S. District Court for the Northern District of California and the federal appeals court in Washington, D.C., allege the designation was unlawful retaliation for Anthropic’s public advocacy of AI safety guardrails. The complaint accuses the administration of “seeking to destroy the economic value created by one of the world’s fastest-growing private companies” and claims the action threatens “hundreds of millions of dollars” in cancelled contracts and disrupted commercial arrangements.

The conflict escalated over several months. Anthropic held a defence contract valued at up to $200 million, signed last July, and Claude was the first large language model deployed on the Pentagon’s classified networks. But negotiations broke down over two restrictions Anthropic insisted on maintaining: prohibitions against using Claude for mass surveillance of American citizens and for fully autonomous weapons systems. The Pentagon demanded unrestricted access for “all lawful purposes.”

Defence Secretary Pete Hegseth announced the ban on X, accusing Anthropic of “arrogance and betrayal” and ordering an immediate cessation with a six-month phaseout. President Trump directed federal agencies to bar the company’s products and described Anthropic as “leftwing nut jobs.” Anthropic CEO Dario Amodei responded that the company “did not agree” with the designation and saw “no choice but to challenge it in court,” while noting Anthropic had “much more in common with the Department of War than we have differences.”

The designation has drawn criticism from defence analysts and technology industry figures. Michael Sobolik of the Hudson Institute observed that the U.S. was now “treating an American AI company worse than we’re treating a Chinese Communist Party-controlled AI company.” Tim Fist of the Institute for Progress called the action one that “hurts the AI industry and thus US national security for essentially no gain.” A coalition of technology advocacy groups, whose members include Nvidia and Apple, urged Hegseth to reconsider.

The timing has drawn particular scrutiny. Within hours of Hegseth’s announcement, rival OpenAI secured a Pentagon contract for classified network access. CEO Sam Altman later admitted the deal “looked opportunistic and sloppy” and amended the contract to include additional language on surveillance principles — though the company has not released the contract text, and former Pentagon officials have publicly questioned whether the stated restrictions are enforceable. Reports in the Wall Street Journal indicate Claude was already being used for intelligence assessments and targeting decisions in the ongoing U.S.–Iran conflict through Anthropic’s partnership with Palantir.

The supply chain risk designation has previously been applied only to entities like Huawei and Kaspersky Lab. Legal scholars have questioned whether applying it to a domestic company exceeds the statute’s intended scope.


The Angle

The designation is worth examining for what it structurally is rather than what it is politically about. A supply chain risk label exists to protect the defence apparatus from foreign entities whose incentives are misaligned with American security. Applying it to a domestic company that built the model already running on classified networks is not a security decision. It is a procurement dispute resolved through a national security instrument — a tool designed for one context deployed in another because it was available and because there was no institutional friction preventing its use.

The specific terms of the disagreement are narrower than either side’s rhetoric suggests. Anthropic did not refuse to work with the military. It refused to remove two contractual restrictions. The Pentagon did not conclude Anthropic’s technology was dangerous. It concluded Anthropic’s conditions were unacceptable. The gap between those positions was, by most accounts, negotiable. What was not negotiable — and what escalated a contract dispute into a designation normally reserved for state-level adversaries — was the question of who sets the terms under which the most capable AI systems are used.

That question will outlast every person currently involved in this dispute. The supply chain risk statute was written for an era in which the critical technologies were hardware — chips, networking equipment, satellites — produced by companies that were either domestic and trusted or foreign and suspect. The binary held. It does not map onto a technology whose capabilities change quarterly, whose deployment conditions alter its risk profile, and whose most significant applications have not yet been invented. The instrument assumes a static threat. The object it has been applied to is the least static technology in human history.

OpenAI’s rapid entry into the gap is instructive mostly for what it clarifies about the actual market. The Pentagon did not lose access to frontier AI capability for more than a few hours. The question of whether a company can maintain ethical restrictions on its most powerful products in the face of government demand was answered before it was fully asked. The answer, delivered not through policy but through competitive dynamics, was no — or at least, not if a competitor is willing to move faster and ask fewer questions. That the competitor later admitted the move looked “opportunistic and sloppy” and amended the contract does not change the structural lesson. It confirms it.

What this dispute has produced, almost as a byproduct, is the first legal test of whether the government can use national security designations to compel the terms under which private AI companies operate. The First Amendment claim is the headline, but the statutory question underneath it is the one that will matter in five years: can a designation designed to exclude foreign adversaries from the supply chain be repurposed as leverage against domestic companies whose policies the government finds inconvenient? The answer to that question will set the terms for every AI company that follows, long after the current contract is forgotten.

The first serious legal confrontation over who controls the terms under which the most consequential technology in human history is deployed has begun — and it started not with a grand philosophical stand, but with a procurement dispute that outgrew every instrument designed to contain it.