THE CLAUDE WAR | AI, Arms & the First Amendment: How Anthropic Took on the Pentagon and Won A federal judge ruled on August 27 that the Pentagon's actions against Anthropic, including a supply-chain risk designation and an order to sever ties, were unlawful retaliation violating the First Amendment, after the AI company refused to allow its Claude models to enable autonomous weapons or mass surveillance. The dispute, which began over a $200 million contract and escalated with Defense Secretary Pete Hegseth's ultimatum, raises the question of whether a private company can constrain military use of its AI. THE CLAUDE WAR | AI, Arms & the First Amendment: How Anthropic Took on the Pentagon and Won The Pentagon wanted three words. All lawful uses. Anthropic wanted two exceptions. Its artificial-intelligence models could help American soldiers analyse intelligence, defend computer networks, plan operations and perform other national-security work. But the company would not permit Claude to conduct mass surveillance of Americans or empower weapons to select and attack human targets without meaningful human control. Behind those two exceptions waited a question that no contract lawyer could contain. When artificial intelligence enters a war room, who controls its conscience: the elected government fighting the war or the private company that built the machine? The disagreement destroyed a $200 million alliance, provoked an ultimatum from US Defence Secretary Pete Hegseth and transformed Anthropic from an important military technology supplier into an alleged threat to America’s supply chain. President Donald Trump directed federal agencies to stop using the company’s technology. Hegseth announced that contractors working with the military would have to sever commercial relationships with Anthropic. The Vanguard 21 Aug 2026 - Vol 05 | Issue 34 BJP Rearmed for 2029 Read Now The Vanguard /magazine/the-vanguard The label chosen for the company was extraordinary. “Supply-chain risk” was an authority principally designed to protect sensitive American systems from foreign intelligence agencies, terrorists and companies susceptible to hostile control or sabotage. It had never previously been applied to an American company in this manner. Claude had gone from assisting national-security agencies to being treated as though it might turn against them. On August 27, US District Judge Rita Lin ruled that the government had gone too far. “The undisputed record shows that the challenged actions constituted unlawful retaliation in violation of the First Amendment,” she wrote in a 59-page decision, adding that Anthropic had also been denied the process required under the Fifth Amendment. Lin found that Hegseth’s designation violated the statute under which it was issued and was “arbitrary and capricious”. She rejected the government’s attempt to convert Anthropic’s public disagreement into evidence of disloyalty. “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” Lin wrote. The ruling delivers Anthropic an important legal victory. It protects an American company’s right to criticise the government without being driven from the federal marketplace. It exposes the dangers of turning procurement law into a political weapon. It does not answer the question that detonated the conflict: Can a private company tell the world’s most powerful military how it may fight? A $200-Million Alliance Goes to War With Itself Anthropic was hardly a pacifist watching the Pentagon from outside the gates. The company had worked aggressively to bring Claude into national security. In November 2024, it partnered with Palantir and Amazon Web Services to make its artificial-intelligence models available to American defence and intelligence agencies. Claude was subsequently deployed in classified environments, where commercial chatbots ordinarily cannot operate. In July 2025, the Pentagon awarded contracts with ceilings of $200 million each to Anthropic, OpenAI, Google and Elon Musk’s xAI. The aim was to develop agentic AI systems capable of performing complex tasks across military, intelligence and administrative operations. “The adoption of AI is transforming the Department’s ability to support our warfighters and maintain strategic advantage over our adversaries,” Doug Matty, the Pentagon’s chief digital and artificial intelligence officer, said while announcing the contracts. For Anthropic, the agreement brought revenue, legitimacy and access to some of the most demanding applications of artificial intelligence. For the Pentagon, Claude offered a model recognised for advanced reasoning, coding and cybersecurity capabilities. The partnership proved that Anthropic did not oppose military AI. It opposed two potential applications of it. The first was mass domestic surveillance. Artificial intelligence can process telephone records, financial transactions, images, messages, locations and social connections at a scale that would overwhelm human investigators. Give a model enough data and it can search millions of lives for patterns, assign risk and identify people who have never been suspected of a crime. The second was fully autonomous lethal weaponry. Anthropic objected to using present-day models for targeting or firing decisions without human control. Large language models can fabricate information, misunderstand instructions and behave unpredictably when conditions change. An error in a consumer chatbot may produce a false answer. An error connected to a weapon may produce a corpse. Anthropic argued that these restrictions had always formed part of its relationship with the Pentagon. The company was prepared to permit Claude’s use across a vast range of defence missions. It would not erase the two boundaries. Hegseth viewed the conditions differently. According to the Pentagon, a private contractor could not reserve the authority to decide which lawful military actions the government may undertake. It demanded the ability to use Claude for all lawful purposes and reportedly gave Anthropic a deadline to accept the new terms. Dario Amodei, Anthropic’s co-founder and chief executive, refused. “In a narrow set of cases, we believe AI can undermine, rather than defend, democratic values,” Amodei wrote in a public statement reported by The Washington Post. He maintained that some applications lay beyond what existing technology could perform safely and reliably. “We cannot in good conscience accede to their request,” he said. The language of conscience turned a contracting dispute into a constitutional confrontation. Who Commands the Machine? The Pentagon’s central argument contains genuine force. A military must possess confidence in its chain of command. Generals cannot enter a conflict wondering whether a supplier will object to a mission, modify a crucial system or withdraw assistance when its internal ethics committee disapproves of the operation. A country elects its government. It does not elect the chief executives of its software companies. If every defence contractor could attach its own evolving moral code to military equipment, a state’s capacity to act might become fragmented among corporations. One company could reject a surveillance operation. Another could refuse to support a particular conflict. A third might block the use of its system in a country it considered an aggressor. That concern becomes sharper when the product is deeply embedded in operations. Unlike a rifle or truck delivered to the military, an advanced AI system may require continuing updates, cloud infrastructure, technical assistance, safety tuning and access to the company that created it. Dependence does not end when the contract is signed. The government claimed that Anthropic’s restrictions created uncertainty about whether Claude would remain dependable during wartime. In court filings, it suggested that the company might disable its technology or alter the model’s behaviour if it concluded that its red lines had been crossed. A failure during active military operations, the Justice Department argued in the related Washington litigation, could endanger service members and produce catastrophic national-security consequences. This was the Pentagon’s most serious allegation. It was also the allegation its evidence struggled to support. Anthropic maintained that it could not manipulate a model after it had been installed inside a classified government network. During a July hearing, Lin said she had seen no evidence that the company could alter a delivered model or “flip some kind of kill switch”. The administrative record contained another damaging contradiction. Court documents showed that Pentagon officials formally moved towards declaring Anthropic an unacceptable national-security threat while negotiations with the company still appeared close to resolution. On the day after the designation had reportedly been finalised, an official exchanged drafts of the proposed usage terms with Amodei and told him: “I think we are very close here.” A supplier could not easily be both a looming saboteur and one contractual draft away from agreement. From Contract Dispute to ‘Corporate Murder’ The Pentagon possessed a simple and indisputable option: it could stop using Claude. Anthropic acknowledged that right. Its lawsuits did not ask a court to force the military to retain the company or accept its contractual conditions. The government could reject Anthropic’s red lines, cancel the agreement and choose OpenAI, Google, xAI or another supplier. Hegseth chose a much broader punishment. He designated Anthropic a supply-chain risk under federal law. The administration also directed agencies to discontinue use of its technology and announced restrictions extending beyond Anthropic’s direct defence contracts. The consequences could have travelled through the American economy. A company using Claude for an ordinary commercial purpose could potentially face a choice between keeping Anthropic and obtaining Pentagon business. Software developers might have to remove Claude from products used incidentally by defence suppliers. Partners, investors and customers could interpret the national-security label as evidence that Anthropic’s technology was compromised or that the company itself could not be trusted. One friend-of-the-court brief described the measures as “attempted corporate murder”. Judge Lin declined the murder metaphor but accepted the underlying danger. The evidence, she wrote in her earlier order, showed that the measures would cripple Anthropic. The designation also broke with the history and apparent purpose of the law. Supply-chain authorities protect government systems against the possibility that an adversary might corrupt software, steal data, disrupt operations or insert hidden vulnerabilities. Anthropic’s alleged offence was different. It had publicly disagreed with the government’s contracting position and refused to alter its terms. Government lawyers argued that the company’s criticism contributed to doubts about its reliability. To Lin, that reasoning carried an Orwellian implication: questioning the government could itself become evidence that an American company might sabotage the government. Internal records strengthened Anthropic’s retaliation claim. According to the court, Pentagon documents referred to the company’s “hostile manner through the press”. Trump and Hegseth publicly described Anthropic as “out of control” and “arrogant” and attacked its “sanctimonious rhetoric”. Those descriptions sounded less like a technical risk assessment and more like anger at a company that had taken its case to the public. The First Amendment does not require the government to reward its critics with contracts. It prevents the government from wielding state power to punish them for protected expression. That distinction decided the case. What the Judge Did, and Did Not, Decide Lin’s ruling is sweeping in its condemnation of the Pentagon’s process, but narrower in its practical meaning. She did not rule that Anthropic possesses a constitutional right to supply AI to the military. She did not require the Pentagon to accept the company’s usage restrictions. She did not give Amodei authority over American defence policy. The Pentagon can stop buying Claude. What it cannot do is use a contract dispute as the foundation for a wider government-directed boycott, declare the company a potential saboteur without supporting evidence and punish it for explaining its position publicly. Lin concluded that the government’s actions violated Anthropic’s free-speech rights. She also found a Fifth Amendment problem because the company had received no adequate notice or opportunity to respond before being branded a supply-chain risk. The designation failed at the statutory level as well. The law required the Pentagon to examine whether less intrusive measures could address any genuine threat. Stopping the use of Claude would have been an obvious alternative. The government did not demonstrate why excluding Anthropic across the defence supply chain was necessary. National security receives considerable deference in American courts. Judges are ordinarily reluctant to second-guess military judgments involving classified systems, operational vulnerabilities and wartime risk. Lin’s ruling does not reject that deference. It rejects the idea that officials can obtain it by uttering the phrase “national security” after a political quarrel. Anthropic said it was pleased that the court had declared the designation unlawful and reiterated its desire to work with the government. That conciliatory response reflects an unusual reality. The company sued the Pentagon to reverse a designation that could destroy its defence business because it still wants a defence business. The Lawful-Use Loophole The Pentagon’s demand for “all lawful uses” appears reasonable until one asks what the law currently allows. Technology routinely moves faster than legislation. There is no comprehensive American law governing every military application of generative AI. Existing rules on surveillance, privacy, targeting, weapons review and the laws of war provide constraints, but they were not constructed for models capable of analysing populations, generating military plans or interacting with autonomous systems. The Pentagon’s own policy recognises the danger. Its Directive 3000.09 on autonomy in weapons systems requires commanders and operators to exercise “appropriate levels of human judgment” over the use of force. It also requires realistic testing, safeguards against unintended engagements and compliance with the laws of war. But “appropriate levels” is deliberately flexible. It does not impose an absolute human-in-the-loop requirement for every attack. Nor does it answer how much authority an AI system may exercise while locating, identifying, prioritising or following a potential target before a human approves the final strike. The ethical boundary can move merely by changing the definition of a decision. A machine might not formally pull the trigger. It could still assemble the target list, rank the individuals on it, recommend the weapon, calculate the best moment to strike and present the human operator with a conclusion that must be accepted or rejected within seconds. Human participation may survive on paper while human judgment withers in practice. Mass surveillance presents a similar difficulty. AI does not need to intercept new information to transform state power. It can extract far more meaning from data the government already possesses. A system that joins faces, movements, purchases, messages and associations can create an intimate map of a person without any individual investigator conducting what traditionally looked like surveillance. If such use has not yet been prohibited clearly, “lawful” may describe a regulatory vacuum rather than a democratic endorsement. Anthropic’s red lines attempt to fill that vacuum privately. That may protect citizens and civilians. It also transfers consequential policy decisions to a corporation. The choice is uncomfortable in both directions. Silicon Valley Enters the Chain of Command The dispute also exposes how rapidly America’s AI companies have become defence institutions. OpenAI, Google, xAI and Anthropic received Pentagon contracts within the same programme. Palantir, Microsoft, Amazon and other technology companies provide the infrastructure through which models reach classified systems. In 2026, the Pentagon reportedly struck further agreements with OpenAI, Google, Microsoft, Amazon, Nvidia, xAI and other companies for AI use in sensitive military operations. Anthropic was conspicuously absent. The military has alternatives, but replacing one frontier model is not the same as changing office software. Models differ in reasoning ability, cybersecurity performance, reliability, context capacity and behaviour. Systems and workflows built around one provider may require expensive reconstruction. Contractors forced to remove Claude could suffer costs far beyond the lost subscription. The conflict may now reshape how AI laboratories write their government contracts. If Anthropic’s stand succeeds commercially as well as legally, rivals may feel safer preserving restrictions on surveillance and weapons. If the company wins in court but loses access to the defence market, the lesson may be darker: an AI company may retain its principles or its Pentagon business, but not both. The incentives are formidable. Government contracts provide money, prestige, specialised data and the opportunity to shape military infrastructure that could endure for decades. Companies that enter early may become difficult to dislodge. Those that hesitate may watch competitors define the technical architecture of AI warfare. Ethics can strengthen a consumer brand. In a military procurement contest, ethics can also become a product limitation. Anthropic Has Won Only One Front The August 27 ruling resolves one of the two legal challenges Anthropic filed on March 9. The California case contested the presidential and Pentagon directives and the designation issued under the military-specific supply-chain statute. A separate action before the US Court of Appeals for the District of Columbia Circuit challenges a related designation under the Federal Acquisition Supply Chain Security Act. The second case matters because it could affect Anthropic’s access to civilian government contracts beyond the Pentagon. The appellate court previously declined to suspend that designation while litigation continued, though it has not delivered a final resolution. The Trump administration may also appeal Lin’s ruling. A higher court could narrow her decision, uphold it or examine how much freedom the executive branch possesses when choosing suppliers for sensitive military systems. Anthropic has, therefore, escaped one blacklist without fully escaping the legal war. The broader argument will survive regardless of what happens on appeal. AI companies will continue embedding models inside intelligence networks, military planning systems, autonomous platforms and cybersecurity operations. Governments will demand reliability, control and freedom of action. Developers will confront uses that their technologies can perform before societies have decided whether they should. Every major AI laboratory will eventually encounter its own version of Anthropic’s question: What will the machine refuse to do? The Humans Hidden Inside the Fight Anthropic went to court to protect its right to speak. The dispute began with its attempt to preserve human agency in two places where artificial intelligence could erase it. The first was the life of a citizen. Mass surveillance can reduce a person to a pattern produced by data, observed without knowledge and judged without confrontation. The second was the life of a target. Autonomous weapons can compress recognition, accusation and execution into a process too fast or opaque for meaningful human judgment. The Pentagon argued that an elected government, operating under law, cannot surrender military authority to the conscience of a private supplier. It is right to fear a chain of command dependent on corporate permission. Anthropic argued that law and technology contain dangerous gaps, and that it should not be compelled to remove protections merely because a powerful customer demands a wider licence. It is right to fear a chain of command accelerated by a machine that cannot understand death. Judge Rita Lin decided who had crossed the legal line in this confrontation. The Pentagon could walk away from Claude. It could not brand Anthropic a potential enemy, threaten its existence and call the retaliation national security. The court has protected the company’s right to draw its two red lines. Whether those lines survive the next war may be a decision made far beyond any courtroom. With inputs from ANI