The Pentagon recently labeled Anthropic, the maker of Claude, a "supply chain risk to national security." That designation has previously only been used against foreign adversaries like Huawei and ZTE. Now it applies to an American AI company that refused to remove two guardrails from its government contract.
If you run a business that touches government work, or if you rely on AI tools from any major provider, why should you care? Because the precedent this sets goes well beyond one company and one contract. Here is what happened, what it means, and why the fallout has actually worked in Anthropic's favor.
What the fight is actually about
Anthropic held a $200 million Pentagon contract signed in July 2025. Claude was the first and only frontier AI model cleared for use on classified U.S. military networks. It was being used in active operations, including intelligence analysis during the Iran conflict.
The Pentagon wanted to renegotiate the contract terms to give the military unrestricted access to Claude for "any lawful purpose." Anthropic agreed to most of it. But the company held firm on two specific restrictions.
First, no fully autonomous weapons. Claude would not direct lethal systems without a human making the final call. Anthropic's position was straightforward: current AI models are not reliable enough for life-or-death decisions without human oversight.
Second, no mass domestic surveillance. Claude would not be used to conduct bulk surveillance of American citizens.
That was it. Two lines. Anthropic's CEO, Dario Amodei, said publicly that those restrictions had not affected a single government mission to date.
How it escalated
Defense Secretary Pete Hegseth met with Amodei on February 24 and gave him a deadline: comply by 5:01 PM on Friday, February 27, or face consequences. On February 26, Amodei said publicly that the company would not budge. The deadline passed.
Within hours, President Trump directed all federal agencies to stop using Anthropic's products. Hegseth formally designated Anthropic a supply chain risk. He called the company "sanctimonious" and accused it of "arrogance and betrayal." Trump labeled Anthropic a "radical left, woke company" on Truth Social.
The designation means that any contractor, supplier, or partner doing business with the U.S. military has to certify they do not use Anthropic's models for defense work. For a company whose tools are embedded across major enterprises and defense contractors, what does that kind of chilling effect look like in practice?
The DeepSeek double standard
Here is where business leaders need to pay close attention. The supply chain risk designation was designed to protect the U.S. from foreign adversaries conducting covert infiltration. It was meant for companies with ties to Beijing or Moscow, not for American companies operating transparently under U.S. law.
DeepSeek, a Chinese AI company whose models store user data on Chinese servers subject to Chinese law and government data requests, has not received a supply chain risk designation. The U.S. Navy banned employees from using DeepSeek on work computers, and the Pentagon did the same after discovering employees were accessing the chatbot. But that is a usage ban. It is not the same thing as weaponizing procurement to force every government-adjacent company to cut ties.
Michael Sobolik at the Hudson Institute put it bluntly: the U.S. is treating an American AI company worse than a Chinese Communist Party-controlled AI company. And the Council on Foreign Relations pointed out the perverse irony that the regulatory risk of using American-made AI just increased for U.S. defense contractors relative to the risk of using Chinese open-weight models.
That should concern anyone building a business on AI tools. When you select a vendor, you are making a bet on that company's ability to operate freely. So what does it tell you when an American company that asked reasonable questions about military use and privacy faces harsher consequences than a foreign competitor with documented ties to an adversarial government?
A company gets to define what its tools can do
I think Anthropic was right to hold these lines. And I think the administration's approach here was wrong.
When you build a product, you get to say what it is good at, what it is capable of, and what it is not designed to do. That is not arrogance. That is responsible engineering. If you sell a drill, you tell the customer it is a drill. You do not let them use it as a hammer and then blame you when something breaks.
Anthropic said: our models are not reliable enough for fully autonomous lethal decisions, and we do not want them used for mass surveillance of our own citizens. Those are reasonable positions grounded in an honest assessment of the technology's current limitations. Every vendor I work with sets boundaries on what their tools can and cannot do. That is how responsible business works.
If the government does not like those terms, what is the right response? Use a different tool. And that is exactly what happened. Hours after Trump announced the ban, OpenAI signed its own Pentagon deal. The government had options. It chose to make an example instead.
The market sided with Anthropic
This is the part that matters if you are a business leader evaluating AI vendor risk. Did the designation hurt Anthropic financially? The numbers say the opposite.
Anthropic's annualized revenue run rate was around $9 billion at the end of 2025. By early March 2026, Bloomberg reported it had nearly doubled to $19 billion. The Pentagon contract was worth up to $200 million, a fraction of that total. The company lost a government contract and gained billions in commercial momentum.
More than a million people signed up for Claude per day in the week after the designation. The app surpassed ChatGPT and Gemini to become the top AI app in over 20 countries on Apple's App Store. Anthropic's share of enterprise AI spending climbed to 40%, up from roughly 4% a year earlier, while OpenAI's share dropped from 50% to 27% over the same period.
Anthropic also announced a $100 million investment in a new Claude Partner Network for 2026, providing training, technical support, and go-to-market resources. The company plans to increase its partner-facing team fivefold. That is not the behavior of a company in retreat.
The enterprise customers spoke, too. Microsoft, Google, Amazon, and Apple all confirmed that Anthropic's AI tools would remain available on their platforms for non-defense work. Palantir, which relies on Claude for significant military and intelligence work, confirmed it would continue using Claude as well.
What this means if you depend on government contracts
If your business depends on federal contracts, you need to track this closely. The supply chain risk designation, if it holds, would require defense contractors to certify they do not use Claude in their Pentagon-related work. Multiple legal analysts have said the designation is unlikely to survive a court challenge based on due process, First Amendment, and statutory scope arguments. But litigation takes time, and the chilling effect on contractor relationships is real and immediate.
Anthropic's lawyers have already flagged an obvious contradiction: the government simultaneously declared Anthropic an acute security risk and then permitted six months of continued use in active military operations. That does not hold together logically, and it suggests the designation was punitive rather than protective.
If you are a contractor or subcontractor, talk to your legal counsel about the actual scope of the designation. Anthropic's own reading, backed by Microsoft's legal team, is that it applies only to Claude's use as a direct part of Pentagon contracts. It does not prohibit using Claude for everything else.
Why I am not changing my approach
There are many strong AI tools available today. While frontier models are converging in capability, I still find what one model does well, another may do better in a different context. But I have always believed that it is not about the tools. It is about the person using them.
A good artisan looks at the job, opens the toolbox, and picks the right tool for that specific task. Sometimes the answer is Claude. Sometimes it is something else. The skill is knowing which tool fits which job, not pledging loyalty to a single vendor.
That said, Anthropic's willingness to hold its position on what its product can and cannot responsibly do actually makes me more confident in the platform, not less. A vendor that tells you honestly where the limits are is more trustworthy than one that tells the government whatever it wants to hear to close the deal.
What to watch next
Two federal courts are now reviewing Anthropic's lawsuits. The company is seeking emergency relief to halt the designation's effects while litigation proceeds. Reports also suggest Anthropic and the Pentagon have quietly reopened talks, which means a negotiated resolution is still possible.
The bigger issue is the "any lawful use" clause the administration wants to require in all federal AI procurement contracts, not just defense. If that becomes standard, every AI company with safety policies will face the same choice Anthropic did. What happens when the vendor you rely on for your day-to-day operations gets that call from Washington? That precedent affects you whether you are a government contractor or not, because it shapes how AI vendors think about the tools they build and the commitments they make to all their customers.
If you want to understand the legal arguments in detail, the Lawfare analysis is worth reading. And if you are evaluating AI vendor risk for your own business, understanding how to assess technology partners is a skill that matters more now than it did six months ago. I have written before about why vendor risk assessments exist and how to approach them.
Track the court filings. Watch what happens with the "any lawful use" language. And make your AI vendor decisions based on the quality and reliability of the tools, not on which company said the right things to the right politicians.