Trump Orders Federal Government to Stop Using Anthropic; Pentagon Designates Company a "Supply Chain Risk"
The Trump administration designated a leading American AI company a national security supply chain risk—a label previously reserved for foreign adversaries—after Anthropic refused to remove contractual safeguards against mass domestic surveillance and fully autonomous weapons. The confrontation did not end there: in June 2026 the administration invoked export controls—for the first time ever against an American AI model—to force Anthropic's newest models offline worldwide, demanding a jailbreak-proof guarantee that security experts call technically impossible, before partially backing down in a July 1 settlement.
Even the administration's own former AI policy advisor called the original designation "a dark day in our country's history," and mainstream commentators now compare the pattern of coercion to China's crackdown on Jack Ma. Whether the designation survives Anthropic's ongoing legal challenge, the chilling effect on the entire AI industry's relationship with the federal government is well underway.
Details
On February 27, 2026, President Trump ordered all federal agencies to "immediately cease all use of Anthropic's technology," with a six-month phase-out for agencies currently relying on the company's AI model, Claude. Hours later, Defense Secretary Pete Hegseth designated Anthropic a "supply chain risk" to national security—a classification historically reserved for companies from adversarial nations like China—and ordered that no military contractor may conduct any commercial activity with Anthropic.
The actions culminated a months-long dispute over Anthropic's refusal to allow its AI model to be used without restrictions for mass domestic surveillance of Americans or in fully autonomous weapons systems. The confrontation has since widened: in June 2026 the administration invoked export controls to force Anthropic's newest models offline globally—the first time that policy instrument, built to hobble foreign adversaries' technology champions, was turned against an American AI company—before the two sides reached a partial resolution on July 1 (see "The Fable 5 Shutdown" below).
Background
In July 2025, Anthropic signed a two-year contract valued at up to $200 million with the Pentagon's Chief Digital and Artificial Intelligence Office. Claude became the first frontier AI model deployed on the military's classified networks, integrated through a partnership with defense software firm Palantir. OpenAI, Google, and Elon Musk's xAI also received contract awards of up to $200 million, but their models operated only on unclassified systems.
Anthropic's contract included the company's standard acceptable use policy, which prohibits using Claude for weapons development, mass surveillance, and certain tracking activities. These restrictions were known to the administration at the time the contract was signed. As Gregory Allen of CSIS noted, the Trump administration—including Undersecretary Emil Michael, who later led the push to remove the restrictions—agreed to these same terms when it expanded the contract. Neither the president nor the secretary of defense were unaware of these usage conditions.
The Catalyst: Venezuela
The dispute intensified after the January 3 U.S. military operation to capture Venezuelan President Nicolás Maduro. The Wall Street Journal reported that Claude was used during the operation through its integration with Palantir's platform.
According to Semafor, during a routine post-operation meeting between Anthropic and Palantir, an Anthropic official discussed the operation with a Palantir senior executive. The Palantir executive interpreted the exchange as implying Anthropic might disapprove of its technology being used in the operation and reported the conversation to the Pentagon, triggering what multiple sources described as "a rupture" in the relationship. Anthropic denied raising objections, stating it "has not discussed the use of Claude for specific operations with the Department of War."
On January 12, Hegseth published a memo titled "Accelerating America's Military AI Dominance," directing that the department "must also utilize models free from usage policy constraints that may limit lawful military applications."
Escalation
On February 15, Axios reported the Pentagon was considering severing its relationship with Anthropic. Pentagon spokesperson Sean Parnell stated: "Our nation requires that our partners be willing to help our warfighters win in any fight."
On February 24, Hegseth met with Anthropic CEO Dario Amodei at the Pentagon and delivered an ultimatum: allow the military to use Claude for "all lawful purposes" by 5:01 PM on Friday, February 27, or face severe consequences including contract cancellation, a supply chain risk designation, or invocation of the Defense Production Act to force compliance. A senior defense official told Axios: "The only reason we're still talking to these people is we need them and we need them now."
On February 25, the Pentagon asked Boeing and Lockheed Martin to assess their exposure to Anthropic—a first step toward a potential supply chain risk designation.
Anthropic's Position
On February 26, Amodei published a detailed statement refusing the Pentagon's terms. He outlined Anthropic's two red lines:
Mass domestic surveillance. Amodei wrote that while Anthropic supports AI for "lawful foreign intelligence and counterintelligence missions," using AI for mass domestic surveillance "is incompatible with democratic values." He noted that under current law, the government can purchase detailed records of Americans' movements, web browsing, and associations from public sources without a warrant—and that AI makes it possible to assemble this data "into a comprehensive picture of any person's life—automatically and at massive scale."
Fully autonomous weapons. Amodei argued that "today, frontier AI systems are simply not reliable enough to power fully autonomous weapons," and that deploying them "puts America's warfighters and civilians at risk." He said Anthropic had offered to work with the Pentagon on R&D to improve reliability, but the offer was not accepted.
Amodei noted that the Pentagon's threats were "inherently contradictory: one labels us a security risk; the other labels Claude as essential to national security." He added that the Pentagon's latest proposed contract language, presented as a compromise, "was paired with legalese that would allow those safeguards to be disregarded at will."
Notably, Anthropic had previously demonstrated flexibility. When the Pentagon identified that its terms of service restricted offensive cyber operations—a capability the military wanted—Anthropic removed that restriction. The company's original contract also contained a longer list of prohibited uses than the two red lines at issue in the February dispute; the Pentagon had already successfully negotiated the removal of several restrictions.
Pentagon Undersecretary for Research and Engineering Emil Michael responded on X that Amodei "is a liar and has a God-complex" who "wants nothing more than to try to personally control the US Military."
The Designation
On the afternoon of February 27, Trump posted on Truth Social: "The Leftwing nut jobs at Anthropic have made a DISASTROUS MISTAKE trying to STRONG-ARM the Department of War, and force them to obey their Terms of Service instead of our Constitution. We don't need it, we don't want it, and will not do business with them again!"
After the 5:01 PM deadline passed without agreement, Hegseth posted on X:
"This week, Anthropic delivered a master class in arrogance and betrayal...Their true objective is unmistakable: to seize veto power over the operational decisions of the United States military. That is unacceptable...I am directing the Department of War to designate Anthropic a Supply-Chain Risk to National Security. Effective immediately, no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic."
According to Axios, Defense Undersecretary Emil Michael was on the phone offering Anthropic a deal at the very moment Hegseth posted the designation. That deal would have required allowing the collection or analysis of Americans' data, including geolocation, web browsing, and personal financial information purchased from data brokers.
Anthropic's Response
In a statement published Friday evening, Anthropic called the designation "unprecedented" and "legally unsound," noting it was "historically reserved for US adversaries, never before publicly applied to an American company." The company stated it had not yet received direct communication from the Pentagon or the White House.
Anthropic challenged Hegseth's claim that the designation bars all military contractors from working with the company, arguing that under 10 USC 3252, the designation "can only extend to the use of Claude as part of Department of War contracts—it cannot affect how contractors use Claude to serve other customers." The company vowed to challenge the designation in court, and did: as WIRED reported in June 2026, Anthropic's lawsuit over the designation remains active.
The OpenAI Deal
Hours after the Anthropic designation, OpenAI CEO Sam Altman announced on X that OpenAI had reached an agreement with the Pentagon to deploy its models on classified networks. Altman claimed the deal included the same two safeguards Anthropic had sought: "prohibitions on domestic mass surveillance and human responsibility for the use of force, including for autonomous weapon systems."
However, a community note on Altman's post noted that government officials had contradicted his characterization, stating OpenAI agreed to allow the Pentagon to use its models for "all lawful purposes." Under Secretary for Foreign Assistance Jeremy Lewin wrote on X that the OpenAI terms "flow from the touchstone of 'all lawful use' that DoW has rightfully insisted upon."
According to Fortune, Altman told OpenAI employees at a Friday all-hands meeting that the government agreed to let OpenAI build its own "safety stack"—a layered system of technical, policy, and human controls—and that if the model refuses to perform a task, the government would not force OpenAI to override it. OpenAI also secured agreement to deploy only on cloud networks (not edge environments like autonomous weapons platforms) and to embed forward-deployed engineers with the Pentagon to monitor safety. Tom's Hardware reported that no formal contract had been signed yet as of Saturday.
The New York Times reported that unlike Anthropic, OpenAI's contract includes phrasing that allows the government to use its AI for "all lawful purposes"—the very standard the Pentagon demanded of Anthropic. Fortune noted that the distinction appears to be that Anthropic sought explicit contractual restrictions on specific use cases, while OpenAI agreed to the "all lawful purposes" framework while relying on technical safeguards and its own safety stack to enforce its red lines. Whether this amounts to a meaningful difference or a cosmetic one remains an open question.
Altman had publicly supported Anthropic's position throughout the week. In an internal memo sent to staff Thursday evening, he wrote: "Regardless of how we got here, this is no longer just an issue between Anthropic and the [Pentagon]; this is an issue for the whole industry." Approximately 70 OpenAI employees and 300 Google employees signed an open letter titled "We Will Not Be Divided" expressing solidarity with Anthropic.
OpenAI's accommodation has not exempted it from government pressure. By late June, a New York Times guest essay reported that the challenges of regulating frontier AI had "moved the government to ask Anthropic's chief competitor, OpenAI, to limit the users for its own next model."
Expert and Industry Response
The designation drew sharp criticism from legal and policy experts:
- A former senior defense official told DefenseScoop the designation was "beyond punitive" and amounted to "bullying," warning it would force Palantir to remove Anthropic-supplied elements from the Maven Smart System and require every Pentagon vendor to verify they aren't using Claude. "All while China sits in the corner and laughs."
- Alan Rozenshtein, a law professor at the University of Minnesota, noted the government could have simply terminated the contract: "What the government really wants is to keep using Anthropic's technology, and it's just using every source of leverage possible."
- A Fortune analysis questioned whether the Pentagon had met the statutory requirement under 10 USC 3252 to exhaust "less intrusive courses of action" before making the designation.
- Senator Mark Warner (D-VA) said the actions "pose an enormous risk to U.S. defense readiness and the willingness of the U.S. private sector and academia to work with the IC and DoD."
Hundreds of employees at Google and OpenAI signed an open letter calling on their companies to mirror Anthropic's position. The bipartisan advocacy group Common Cause, along with the Alliance for Secure AI and Young Americans for Liberty, sent a letter to Congressional committees arguing the dispute is "whether the federal government can use frontier AI to conduct mass surveillance and apply lethal force in violation of what existing law and the Constitution allow."
Dean Ball's Response
Dean W. Ball, who served as a senior policy advisor for AI and emerging technology at the White House Office of Science and Technology Policy from April to August 2025 and helped draft the administration's AI Action Plan, was among the most prominent critics from the political right.
Ball initially expressed frustration with both sides: "We desperately need de-escalation here, but the actors involved seem to only be capable of escalation. I wish Anthropic had accepted the same terms as OAI; I think they probably made a mistake in rejecting the compromise. But that does not mean the government should destroy them."
After Trump's Truth Social post, Ball wrote that the President had "articulated a perfectly reasonable response: cut the Anthropic contract and explain why the government is doing so in no uncertain terms. This is precisely what I had been advocating for, along with all other sane people." He believed the situation was de-escalating.
But after Hegseth's supply chain risk designation, Ball reversed course: "Nevermind. I had been optimistic that the President's tweet signaled an off-ramp, but it doesn't. Shame on the Department of War, shame on Pete Hegseth. A dark day in our country's history."
In a subsequent interview with The Atlantic, Ball revealed he had stayed up until 2 AM during the crisis urging administration contacts to take a less severe approach. He described the supply chain risk designation as an attempt to kill a private company for refusing to do business on the government's terms, calling it a signal that "cuts right at the heart of everything that makes us different from China." He published an essay casting the conflict in civilizational terms, calling the Pentagon's action "a kind of death rattle of the old republic."
On The Ezra Klein Show, Ball drew a distinction between the government declining to do business with Anthropic—which he considers reasonable—and the supply chain risk designation, which he characterized as "corporate murder." He agreed with the administration that a private CEO should not determine when autonomous weapons are ready for deployment ("That's a Department of War decision"), but argued that the government's response was disproportionate: "If you don't do business on our terms, we will kill you; we will kill your company."
Ball also raised a deeper concern about AI alignment and government power. He argued that aligning an AI model is "a philosophical act," "a political act," and "a speech act"—the instantiation of moral philosophy into a system. If the government can destroy a company for how it aligns its AI, Ball warned, "that is fascism. That's the difference."
The Broader Debate
The Anthropic dispute triggered a wide-ranging debate about the relationship between private AI companies and government power, drawing sharp disagreement even among figures on the political right.
The Case for Government Control
Palmer Luckey, co-founder of defense technology company Anduril Industries, argued that Anthropic's position fundamentally undermines democratic governance. He contended that seemingly innocuous restrictions like prohibiting AI from targeting civilians are actually "moral minefields" that give private executives interpretive authority over questions the law already answers: "Who is a civilian and not? What makes them innocent or not? What does it mean for them to be a 'target' vs collateral damage?" Luckey argued that any defense company asserting authority beyond what elected leaders and the law permit is "effectively saying you do not believe in this democratic experiment and that you want a corporatocracy."
Tech analyst Ben Thompson wrote in his widely read Stratechery newsletter that "it simply isn't tolerable for the U.S. to allow for the development of an independent power structure—which is exactly what AI has the potential to undergird—that is expressly seeking to assert independence from U.S. control." Thompson likened the necessity of subordinating Anthropic to the broader imperatives of national sovereignty.
The Case Against the Designation
Ball responded that Thompson's and Luckey's positions, taken to their logical conclusion, imply AI labs should be nationalized—a position he doubts either actually holds. "Every company on Earth and every private actor on Earth is independent of U.S. control," Ball argued. "I'm not unilaterally controlled by the U.S. government. And if anyone tried to tell me that I am, or that my property is, I would be quite concerned."
On The Ezra Klein Show, Ball argued that the people in the Trump administration driving the Anthropic dispute "do not understand" the deeper dynamics of AI alignment and governance, and that the supply chain risk designation amounts to "a kind of political assassination" of a company whose AI model embodies a particular moral philosophy.
The National Security Practitioner's View
Gregory Allen, a senior advisor at the Center for Strategic and International Studies who previously served at the Department of Defense, offered a more nuanced analysis. Allen argued the Pentagon is right that it "must ultimately have control over the technology and its use in national security contexts," but that the supply chain risk designation "is just an egregious escalation" not supported by the statute.
Allen noted that the gap between Anthropic's and the Pentagon's positions was narrower than the rhetoric suggested. The Pentagon's own policy on autonomous weapons, under DoD Directive 3000.09, already requires additional technical and procedural scrutiny. Anthropic had agreed to help develop autonomous weapons—its objection was only to operational deployment without human oversight given current reliability limitations. Allen also pointed out that when the Pentagon previously identified a use case (offensive cyber operations) that conflicted with Anthropic's terms, Anthropic simply removed the restriction.
Allen faulted both sides but reserved particular criticism for the Pentagon's ultimatum: "What the Department of Defense has just said is, 'Any company that dips their toe in the water, we reserve the right to grab their ankle, pull them all the way in at any time.' And that is such a disincentive to even getting started in working with the DoD." He noted that Anthropic was the company that had persuaded an entire generation of safety-minded researchers to support national security work—and that demonizing them risks undoing years of progress in Silicon Valley-Pentagon relations.
Historical Context
Some commentators argued the crisis was being overstated. One conservative legal commentator noted that presidents from FDR to Biden have used coercive leverage against private companies in pursuit of national security objectives. During World War II, companies like Ford and GM were ordered to stop producing cars entirely. Montgomery Ward's CEO was physically hauled away by the National Guard after refusing to comply with wartime labor orders. During the Korean War, Truman seized the nation's steel mills to prevent a strike, an action the Supreme Court later struck down in the landmark Youngstown Sheet & Tube Co. v. Sawyer.
However, Allen drew a distinction between those precedents and the current situation: the government's economic leverage over AI companies is far smaller than over wartime manufacturers. Anthropic's annualized revenue reportedly surpassed $19 billion by early March 2026—making its $200 million Pentagon contract roughly 1% of revenue. As Allen put it, AI companies "don't need the government" economically, which means "if the government is determined to control the product in question, it has to use much more coercive means."
A Short-Lived De-escalation
In early March, several signals suggested both sides might reach a deal. At a Morgan Stanley TMT conference on March 4, Amodei struck a conciliatory tone, saying Anthropic and the Pentagon "have much more in common than we have differences" and that the company continues to talk with the Department of War to "de-escalate" the situation. He emphasized that Anthropic has "never questioned specific military operations" and does not seek an operational role.
Under Secretary of State Jeremy Lewin offered an analysis of the difference between the rejected Anthropic contract and the OpenAI contract that seemed to point toward a compromise. In Lewin's telling, Anthropic defined "mass surveillance" in broad, non-legal terms that left the government uncertain about what was permitted, and wanted interpretive authority over gray areas. OpenAI, by contrast, defined its surveillance restrictions in specific legal terms that gave the Pentagon clarity about what was and wasn't excluded, and did not require OpenAI to serve as the arbiter of disputes. If the Pentagon proved willing to accept well-defined, legally grounded limits on AI use—rather than the amorphous restrictions Anthropic sought—that might have provided a path forward.
No such rapprochement materialized. The supply chain risk designation stayed in place, Anthropic's litigation proceeded, and Hegseth continued to celebrate the breach—posting that the Pentagon had "kicked @AnthropicAI out of our building — forever." Three months later, the conflict entered a dramatically more aggressive phase.
The Fable 5 Shutdown: Export Controls Turned on an American Company
On June 9, 2026, Anthropic launched two new models, Fable 5 and Mythos 5. Fable 5 was an adapted version of the company's powerful Mythos architecture, which has—in the words of a New York Times guest essay—"incredible capacity to find vulnerabilities in software"; Amodei himself had said companies using Mythos called it a "superweapon."
Three days later, on June 12, Commerce Secretary Howard Lutnick sent Amodei a letter invoking export controls and directing the company to "suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States," Forbes reported. Because the directive reached foreign nationals inside the U.S.—including some of Anthropic's own employees—compliance effectively required a global shutdown, which Anthropic implemented for all customers. As the Times essay observed, export controls had for a decade been the instrument Washington used to deal "sometimes crippling blows to Chinese technology champions"; the Fable 5 order "upended this logic by turning this policy instrument against American companies."
The trigger. According to WIRED, researchers at Amazon—one of Anthropic's largest investors—discovered a jailbreak that bypassed Fable 5's safeguards to elicit software-vulnerability exploitation capability from the underlying Mythos architecture. Amazon CEO Andy Jassy personally alerted Treasury Secretary Scott Bessent and other officials. White House AI adviser David Sacks said: "A highly credible trusted partner of both Anthropic and the USG who was testing Fable came forward with a jailbreak," claiming the administration asked Amodei to fix it or withdraw the model and "Dario refused." Anthropic disputed that account, saying the demonstrated capability "is available from other publicly deployed models, including OpenAI's GPT-5.5," that a recall standard of this kind would "essentially halt all new model deployments," and—per a source—that it was never given details of the jailbreak and never refused to make fixes.
An impossible standard. WIRED reported on June 17 that administration officials said Anthropic could only rerelease Fable 5 if it ensured the model could not be jailbroken—a standard security experts called technically impossible to guarantee. Martin Riley, CTO of the cybersecurity firm Bridewell, explained: "A jailbreak is not a bug in discrete code. It is an adversarial input to a system whose entire value comes from being open-ended and flexible... You cannot guarantee that a model will remain jailbreak-proof forever. Anyone promising that is selling something." Oliver Simonnet of CultureAI agreed that complete jailbreak-proofing is "unrealistic."
Resolution and Redeployment
The standoff eased in stages. On June 26, the government permitted Anthropic to restore some users' access to a version of Mythos, per the Times essay. The export controls were lifted on June 30, and Anthropic redeployed Fable 5 globally on July 1, equipped with a new safety classifier that blocks the specific Amazon-reported jailbreak technique in over 99% of cases; flagged requests are routed to the less capable Opus 4.8 model.
As part of the resolution, Anthropic committed to give designated government partners expanded pre-deployment access to its models, rapidly share jailbreak information, conduct joint government AI-security research, and help build a voluntary industry security standard. The settlement came against the backdrop of a recent executive order establishing a voluntary review program for highly advanced models, noted in the Times essay. The February supply chain risk designation and federal-use ban, however, remain in place, as does Anthropic's lawsuit challenging the designation.
An Industry "On Edge"
The administration's willingness to punish individual AI companies has reverberated well beyond Anthropic. Politico's Playbook reported on June 19, 2026 that the administration's relationship with the AI industry had grown volatile, putting the industry "on edge"—with the February Anthropic ban and supply chain risk designation hanging over every company's calculations. The same item reported that Trump privately disparaged Commerce Secretary Lutnick in crude terms after Lutnick pushed back on the president's fixation on chip-export dealmaking with China—the policy under which Trump has personally driven approvals of advanced Nvidia and AMD AI chip sales to China over national-security objections from both parties. The juxtaposition has not been lost on critics: the administration cleared advanced AI chips for sale to China while using export controls to take an American company's AI model offline.
The AI-policy volatility carries political dimensions as well. CNBC reported in March that data-center-driven electricity price spikes had become a midterm liability for the administration, even as federal regulators in June backed Trump's plan to fast-track grid connections for AI data centers.
The "Jack Ma Moment" Warning
The sharpest elite-opinion alarm came in a June 28 New York Times guest essay (opinion) by Dan Wang, a research fellow at Stanford's Hoover Institution, and Julian Gewirtz, a former senior China official on the Biden National Security Council. The authors argued that the U.S. government "is skating close to its own Jack Ma moment, when a government wounds a tech leader seemingly out of spite"—invoking the Chinese Communist Party's 2020-21 crackdown on Alibaba after Jack Ma criticized regulators, which cancelled Ant Group's IPO, erased roughly two-thirds of Alibaba's value, and collapsed Chinese venture funding. "Self-destructive American actions, not Chinese competition, may be the most significant threat to the evolution of A.I. for years to come," they wrote.
Wang and Gewirtz described the administration as having "careened from extreme to extreme on A.I. policy"—from a hands-off posture that de-emphasized safety concerns, to the supply chain risk designation, to the Fable 5 export-control shutdown, which they attributed partly to the administration being "shocked... into taking safety more seriously" by reports of Mythos's capabilities. They faulted both sides: AI lab leaders should "stop their doom trolling" and make panicked claims about AI's destructive potential only alongside plans to work with the government, while the government "needs to realize that the stakes of A.I. are far too high to allow a breakdown of trust." They singled out Hegseth as having "seemingly delighted in celebrating Anthropic's troubles" and noted the administration "has imposed major restrictions on Anthropic without offering sufficient explanation"—with the consequence that "American allies are wondering if they can rely on American A.I. models, and talented foreign researchers in American labs are reconsidering their career plans."
The essay reframed the central conflict: not the United States versus China, but "an even more acute form of competition, between the public power of governments and the private power of ambitious companies"—a struggle in which both countries' AI labs "are starting to realize how much their operations depend on the state's sufferance."
Potential Business Impact
The direct financial impact of losing the $200 million Pentagon contract is limited for Anthropic, which Bloomberg reported reached approximately $19 billion in annualized revenue by early March 2026—up from $9 billion at the end of 2025—driven largely by its coding tool Claude Code and strong enterprise adoption. The company is valued at approximately $380 billion and is reportedly considering an IPO. The Pentagon contract represented roughly 1% of revenue. The greater risks lie elsewhere: the supply chain risk designation's potential to force companies with Pentagon exposure to stop using Claude entirely, and—as the June episode demonstrated—the government's demonstrated willingness to take Anthropic's flagship products offline worldwide on short notice.
As one independent analyst noted: "It will take years to resolve in court. And in the meantime, every general counsel at every Fortune 500 company with any Pentagon exposure is going to ask one question: is using Claude worth the risk?" The three-week global outage of Fable 5 and Mythos 5 in June—imposed by government directive days after launch—gives that question new force for every customer weighing dependence on a company in the administration's crosshairs.
Anthropic disputes that Hegseth has the statutory authority to extend the designation beyond Pentagon contract work, arguing it "cannot affect how contractors use Claude to serve other customers."
Pentagon's Position
The Pentagon has consistently maintained that it has no intention of using AI for mass surveillance or fully autonomous weapons—activities it says are already illegal or contrary to military doctrine (including DoD Directive 3000.09, which requires "meaningful human control" over lethal force). Its position is that once the military purchases a tool, it has its own standards and procedures to govern its use, and that it is unworkable to negotiate individual use-case restrictions with a private contractor.
Pentagon spokesperson Sean Parnell stated: "This is a simple, common-sense request that will prevent Anthropic from jeopardizing critical military operations and potentially putting our warfighters at risk. We will not let ANY company dictate the terms regarding how we make operational decisions."
However, Axios reported that the deal being offered to Anthropic at the moment of the designation "would have required allowing the collection or analysis of data on Americans, from geolocation to web browsing data to personal financial information purchased from data brokers"—activities that would fall squarely within what Anthropic considers mass surveillance.
Context: ICE and Domestic Surveillance
Anthropic's concerns about domestic surveillance are not hypothetical. As Foreign Policy reported, a growing body of evidence shows agencies like Immigration and Customs Enforcement operating at the edges of the law in their use of AI surveillance tools. ICE agents have relied on facial recognition programs from Clearview AI and NEC to track individuals, and ICE's largest contractor won more than $800 million in 2025 alone to mine data from commercial databases and surveil people suspected to be undocumented immigrants.
Under current law, the government can purchase detailed records of Americans' movements, web browsing, and associations from public sources without obtaining a warrant—a practice that has generated bipartisan concern in Congress.