Back to Home

The Model Is the Supply Chain: Pentagon Cuts Claude Off

On October 5, a Defense Department official told the BBC that "the Pentagon has ceased the use of Anthropic products." That closed a loop opened in late February, when Defense Secretary Pete Hegseth designated Anthropic a national security supply-chain risk. The ban matters less than what it reveals about where guardrails sit in a military stack.

Multiple sources in the same BBC report said Claude was still running inside the department as recently as last week, including during US military operations against Iran, embedded in Palantir's Maven Smart System. The on-record statement describes a clean break; the sourcing describes an unwinding deployment.

Two Courts, Two Statutes, Two Answers

The designation has now been litigated twice with opposite outcomes. The D.C. Circuit reviewed the Pentagon's authority under FASCSA, the 2018 Federal Acquisition Supply Chain Security Act, which lets the Defense Secretary block a supplier whose technology poses a security risk. On September 25, a divided panel held 2-1 that the department had "ample support" for designating Claude as one. Judges Gregory Katsas and Neomi Rao formed the majority; Judge Karen LeCraft Henderson dissented.

A month earlier, in California, Judge Rita Lin reviewed the same designation under the 2011 National Defense Authorization Act and reached the opposite conclusion. "The empty invocation of national security is not a blank check to punish and retaliate against government critics," she wrote in a 59-page decision that made permanent her March pause on the government's punitive measures.

Both readings can be correct on their own statute. FASCSA sets notification and disclosure rules for a supplier ban; the NDAA sets different ones. Anthropic argued the department never completed the FASCSA process properly; the D.C. Circuit disagreed. Two federal courts now call the same action lawful and unlawful at once.

The court's language is the raw material. "The company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent," the opinion states. "On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users."

Why a Safety Layer Looks Like a Failure Mode

Read that as an availability spec. Anthropic's usage policy, the clause barring mass domestic surveillance of Americans and fully autonomous lethal weapons, is not a document in a drawer. It is a runtime component that can refuse a request. An operator reads a component that declines work at unpredictable moments as a reliability risk, and the court accepted the Pentagon's framing that an "overly constrained AI model shutting down unexpectedly" could fail military operations.

The Pentagon asked to replace the relevant clause with a provision permitting "all lawful uses." Anthropic declined. The three-day deadline in February, the Trump post ordering agencies off Anthropic, and OpenAI's Pentagon deal hours later all descend from that refusal.

The engineering problem underneath is integration depth. Claude is not a browser tab at the Pentagon. It is plumbed into Maven Smart System, the platform analysts use to organize satellite imagery, drone footage, and other visual data. "Once they become integrated it can be painful to remove them," Lauren Kahn of Georgetown's Center for Security and Emerging Technology told the BBC. Striking a vendor from a procurement list and carving a model out of a live classified workflow are different operations.

  • July 2025: Anthropic wins a $200 million contract for Claude access, and talks begin on expanding deployment through GenAI.mil.
  • Late February 2026: Hegseth gives Anthropic three days to accept "all lawful uses." Anthropic refuses. Trump orders agencies off Anthropic; OpenAI announces a Pentagon deal hours later.
  • March 2026: The supply-chain risk designation lands under FASCSA, the first public use of the label against a US company, with a six-month phaseout attached.
  • August 28, 2026: Judge Lin rules the designation unlawful under the NDAA and makes her March pause permanent.
  • September 25, 2026: The D.C. Circuit upholds the designation 2-1 under FASCSA.
  • October 5, 2026: The Defense Department confirms it has ceased using Anthropic products.

The Blast Radius Is Cloud-Shaped

The restriction is scoped to military systems and defense contractor work, which is why Anthropic can keep expanding elsewhere in government. On September 30 the company took Claude for Government to general availability in a FedRAMP High environment. Agencies can buy direct, through Carahsoft, or via the GSA's OneGov channel, with a reported $1-per-user rate through October 31.

The financial stakes are not decorative. Anthropic reported a $42 billion net loss in 2025 against revenue of $4.6 billion, up roughly twelvefold, and it is reportedly targeting a pre-Thanksgiving IPO near a $2 trillion valuation, raising as much as $100 billion.

The spillover question is whether a procurement label can travel through a hyperscaler. Amazon has invested $13 billion in Anthropic with up to $20 billion more committed, and Anthropic trains and serves Claude on more than a million Trainium2 chips. Alphabet supplies the Google Cloud capacity and TPUs behind an expanded arrangement Anthropic has valued in the tens of billions, with well over a gigawatt expected online in 2026. The bear case is not that Claude disappears; it is that government customers demand separation controls, or that procurement reviews widen from the model to the cloud hosting it.

  • Contract eligibility: whether agencies draw a line between Anthropic's models and the cloud infrastructure serving them.
  • Procurement guidance: any DoD memo defining where "military systems" ends and adjacent government work begins.
  • Appeal paths: Anthropic can seek rehearing by the same D.C. Circuit panel, by the full circuit, or petition the Supreme Court, while its California win survives as a competing precedent.
  • Contractor certifications: how defense suppliers document compliance with a designation that told them not to touch the models.

For now the contradiction is the architecture. The same company is locked out of the Defense Department as a national security risk and signed up by other federal agencies under the government's highest cloud tier. The model did not change. Only the buyer's tolerance for a component that can say no did.

Comments

No comments yet. Be the first to share your thoughts!