Pentagon Ends Anthropic Use After Fight Over AI Safeguards

The U.S. Department of Defense has stopped using Anthropic products, a department official told the BBC on 5 October 2026. BBC
The cutoff closes a phase-out that started 27 February. Defense Secretary Pete Hegseth then imposed a six-month deadline to end Anthropic use by late August. Hegseth had labeled the company a supply chain risk in February. That term means the government views a supplier as a potential security problem. He later designated it a "national security supply-chain risk."
President Donald Trump said on 27 February that he would direct every federal agency to immediately stop using technology from Anthropic. A senior Pentagon official said on 5 March that the supply chain risk designation was effective immediately. The Pentagon made Anthropic the first U.S. company to be given that label.
The system was widely used. Anthropic had been used by the U.S. government and military since 2024. It was the first advanced AI company to have its tools deployed in government agencies doing classified work, meaning work with secret material that requires special clearance. The company offers Claude Gov models for U.S. national security customers. It said those models were built based on direct feedback from government customers to address real-world operational needs. In July 2025 it was awarded a $200M Department of Defense agreement for AI capabilities. Anthropic In February 2026 the company stated that Claude is extensively deployed across the Department of War and other national security agencies for mission-critical applications.
A classified deployment unwound
Claude was embedded in the Pentagon's Maven Smart System data platform. Maven Smart System is operated by Palantir. It is the Pentagon's primary platform for organizing intelligence and other data, acting much like a central library and search tool that helps analysts connect different pieces of information.
Multiple people familiar with the matter told the BBC that as recently as last week Claude was still used by the Pentagon in research, analysis, intelligence gathering and military operations against Iran. According to two people familiar with AI use in the Defense Department, OpenAI tools have been more widely adopted in recent months in some military departments. While the legal fight with Anthropic played out, the Pentagon signed contracts with Google, xAI and OpenAI.
An Anthropic spokesman declined to comment when asked about the Pentagon's statement that it ceased use of Anthropic products.
The break centers on use constraints. The Pentagon pressed Anthropic earlier this year to remove safety guardrails from Claude and give the military unfettered access to its AI tools. Guardrails are built-in limits, similar to a speed limiter, that control what an AI system will and will not do. Anthropic refused the request, citing concerns of mass surveillance and autonomous weapons. Anthropic called the subsequent designation "unprecedented and unlawful" and sued the Trump administration to overturn it.
Courts cleared the blacklist
To make sense of the court back-and-forth, early judicial limits on enforcement did not hold. The appeals court later ruled in the Pentagon's favor.
A federal judge ruled on 27 March 2026 that the U.S. government could not immediately enforce a ban on Anthropic's tools. BBC On 28 August a U.S. judge ruled the Pentagon's blacklisting of Anthropic was unlawful, with a second lawsuit in Washington, D.C. concerning the supply-chain-risk designation still pending at that time. The Guardian
A U.S. federal appeals court on 25 September rejected Anthropic's challenge to the Pentagon's labeling of it as a supply chain risk. AP The same court upheld the Pentagon's decision to blacklist Anthropic from military contracts and affirmed Anthropic's designation as a national security supply-chain risk. Reuters
A replacement stack
The broader context here is a fight over who sets conditions for classified AI. Vendors have historically accepted government security and compliance regimes for classified workloads, meaning they agree to strict handling rules for secret data. The Pentagon sought to extend that logic to model behavior itself, demanding removal of vendor-imposed guardrails for intelligence fusion, targeting support and operational planning. Anthropic treated guardrails as a red line tied to deployment governance, not a negotiable contract term.
Looking at what this means for defense AI procurement, the supply-chain risk instrument now carries clear weight. It functioned first as pressure, then as exclusion, surviving judicial review even after lower courts limited enforcement. For program offices, the lesson is continuity risk. A model integrated into the primary intelligence platform can still be removed on policy grounds, forcing migration to parallel frontier vendors under litigation timelines. For vendors, the choice is starker. Accept unrestricted military use, including surveillance and weapons-adjacent applications, or risk loss of federal and classified market access.
For what comes next, operators face questions of validation. Models differ in refusal behavior, hallucination rates, retrieval grounding and audit logging. In plain terms, they differ in when they refuse requests, how often they invent facts, how well they link answers to source files, and how fully they record actions for review. Swapping a reasoning layer inside Maven Smart System touches evaluation pipelines, access controls and analyst workflows built around Claude Gov. The Pentagon has diversified suppliers. Whether that diversification delivers equivalent performance under combatant command tempo will shape the next contracting cycle.


