The Anthropic–Pentagon Case: Three Lessons for Every AI Buyer
3 min read
The facts first, the lessons after. In July 2025 the US Department of Defense had awarded agreements worth up to $200 million to four AI suppliers — Anthropic, OpenAI, Google and xAI — and Anthropic’s models were already being used by national security agencies for intelligence analysis and planning. Then the relationship broke down: Anthropic demanded explicit clauses preventing the use of its technology for surveillance of American citizens and for autonomous weapons without human oversight. In late February 2026 the White House ordered federal agencies to stop using Anthropic technology; in early March the Pentagon designated it a “supply chain risk”; in late March a federal judge suspended the directive with a preliminary injunction. The legal battle is still ongoing.
We are not taking sides in this dispute. What interests us is that it is the largest stress test ever seen of the relationship between whoever supplies a model and whoever builds on top of it — and the cracks it has revealed concern every company, not just governments.
Lesson 1 — The supplier can change the terms. Or disappear.
The customer in question was the most powerful in the world, and overnight it found itself ordered to shut down a system embedded in its own processes. If it can happen to the Pentagon, it can happen to anyone: a change in supplier policy, a political decision, litigation, a price that triples. The question to ask before signing is not “how good is the model?” but “how much would it cost me to replace it?”. If the answer is “rewrite everything”, you have an architecture problem, not a supplier problem: the model must be a replaceable component, and the value must sit in your data and in your operating model — which no one can revoke.
Lesson 2 — Usage limits belong in the contract, not assumed
At the heart of the clash were usage limits: what the technology can and cannot do. Anthropic wanted them made explicit; the government saw them as interference. Turn the perspective onto your own case: when you buy an AI system, are the limits that matter to you written down anywhere? Who is accountable if the system makes a harmful decision? Can the supplier use your data to train something else? Can it change the model’s behaviour without telling you? In today’s AI contracts these answers are often missing. In tomorrow’s tender specifications they will be there — buyers acting now would do well to get ahead of them.
Lesson 3 — Human oversight is not an abstract principle: it is a clause
It is remarkable that the point on which a supplier risked its most prestigious contract was human oversight of critical actions. It is the same rule that the EU AI Act imposes, and one we apply by design: every critical action passes through an operator. The American case makes one thing precise: that principle must be translated into verifiable mechanics — who approves, what happens if the operator does not respond, where the decision is logged. A principle without mechanics is just a hope.
The European postscript
While supplier and government sue each other in Washington, in Europe the question “who owns the infrastructure my AI runs on?” has stopped being theoretical. This calls for pragmatism, not ideology. Data in Europe, replaceable components, contractually bound human oversight — that is our definition of sovereignty, and it is compatible with any model, American, European or open.
Want to measure how dependent you are on your current AI supplier — and what it would cost to change it? It’s a half-hour conversation.