Operational notes Observatory

Anthropic and the Pentagon: banned by contract, used out of necessity

6 min read

Camouflaged military radar dish photographed from below against a clear blue sky
A supplier can be banned on paper and still stay under observation in practice.

On 9 July 2026 the Air Force Research Laboratory sent its contractors a memo with a precise order: purge every Anthropic product and service by 1 September, with an inventory due by 1 August. It is the latest chapter in a saga we covered back in April, when a federal judge had temporarily blocked the Pentagon’s ban. Since then, three things have happened that anyone buying critical technology should watch closely: an appeals court has left the Defense-specific designation standing, Congress has begun to rein in the powers used to impose it, and America’s intelligence apparatus keeps quietly evaluating the software of the very company the administration is expelling.

The facts, in order

  • 26 February 2026: CEO Dario Amodei states that Anthropic will not give up two non-negotiable usage limits: no mass surveillance of American citizens, no fully autonomous weapons, because “frontier AI systems are simply not reliable enough to power fully autonomous weapons.”
  • 3 March 2026: the Department of Defense (renamed the Department of War in 2025) formally designates Anthropic a “supply chain risk” under FASCSA; Secretary Pete Hegseth orders that “no contractor, supplier, or partner doing business with the Pentagon may engage in any commercial activity with the company.”
  • 9 March 2026: Anthropic files two parallel federal suits — in the Northern District of California and before the D.C. Circuit Court of Appeals — calling the action “unprecedented and unlawful.”
  • 26 March 2026: Judge Rita Lin (N.D. Cal.) grants a preliminary injunction against the presidential directive ordering all federal agencies to cut ties with Anthropic.
  • 8 April 2026: the D.C. Circuit instead denies Anthropic a stay of the Defense-specific designation: that legal track stays active, while the broader directive remains blocked. At May’s oral argument, the panel — including Judge Karen LeCraft Henderson — appears divided on the merits.
  • 19 April 2026: Axios reports that the NSA is evaluating Mythos, Anthropic’s new cybersecurity model capable of finding decades-old vulnerabilities in browsers and software infrastructure, despite the blacklist still in force.
  • 1 May 2026: Under Secretary of Defense Emil Michael confirms that “with Anthropic, they’re a supply chain risk” and that “never again will we be single-threaded with any one model” — but he frames the use of Mythos as mere technical evaluation, the kind “the NSA and Commerce evaluate all frontier models, including Chinese frontier models,” not operational deployment.
  • 8 July 2026: the Senate’s draft of the fiscal 2027 National Defense Authorization Act introduces a provision to rein in the Secretary of Defense’s discretionary power to designate supply-chain risks — the first legislative response to the affair.
  • 9-10 July 2026: the Air Force Research Laboratory memo sets 1 September as the deadline for its contractors, four weeks ahead of the Department-wide deadline (29 September) and Hegseth’s original one (27 August).

Nobody disputes the facts themselves: the designation was notified, challenged, suspended for civilian agencies and left standing for Defense by two different courts. The real issue is different: while contractors are ordered to strip the vendor out by September, the same government’s technical offices keep taking a close look at what that vendor can do.

Lesson one: a “supply chain risk” label is not a technical verdict, it is a provisional state

The designation against Anthropic did not arise from a product flaw: it arose from a contractual disagreement over usage limits. This holds for any company: a supplier can be blocked, suspended by a judge, and blocked again on a different track, all within the same quarter. Treating these states as an on/off switch is a risk-analysis mistake. Before depending on a strategic supplier — or excluding one on a sudden decision — you need a map of the states genuinely in force, not a headline. It is the principle we apply when building a data and AI architecture: resilience is measured across intermediate states, not the best or worst case.

Lesson two: declared substitutability collides with capabilities that have no substitute yet

Emil Michael promises the Pentagon will “never again” depend on a single model. In the same month he says it, his own agency is evaluating the model of the company it is expelling, because that specific vulnerability-hunting capability has no ready alternative yet. The lesson for buyers of critical technology is not “always diversify” — it is more exacting: before banning or depending on a supplier, verify which capabilities are genuinely replaceable right away and which would take months of transition — and plan continuity around the latter, not around the general principle. It is the work that should precede any technology choice in a public body or critical infrastructure: knowing, before the crisis, what can be swapped out over a weekend and what cannot.

Lesson three: the rules can change mid-game — and remedies arrive late

Congress is stepping in now, through the NDAA 2027, to rein in a power the Pentagon has already been using since March. Over four months passed between the designation and the first legislative response; a ruling on the merits will likely take longer still. For a company or agency dependent on a discretionary decision by a single public office — Italian, European or American — the remedy channel exists, but it takes time the business does not have. That time is not covered by waiting for a lawsuit’s outcome: it is covered beforehand, with portable data and a replaceable architecture — the logic behind our approach to technological sovereignty, valid for those working in defence as much as in any other regulated sector.

What to do

  1. Map the intermediate states of every critical supplier — suspended, under appeal, banned for one use but not another — instead of treating them as wholesale banned or cleared.
  2. Distinguish genuinely replaceable capabilities from those that are not yet, and focus your continuity plan on the latter.
  3. Write timely notification of regulatory designations or disputes concerning the supplier into your contracts, not just of product changes.
  4. Build the architecture for substitutability, not for trust: portable data, interchangeable components, contractually bound human oversight, regardless of who wins the case.

Want to check how dependent your organisation is on a single AI supplier — and what it would really cost to replace it? Half an hour with one of our experts to map the risks and continuity gaps.

Sources