Kyle Harrison
article

The Pentagon Threatens Anthropic

Scott Alexander February 25, 2026 View original ↗

The Pentagon Threatens Anthropic

Author: Scott Alexander (Astral Codex Ten) · Published: February 25, 2026 · URL: https://www.astralcodexten.com/p/the-pentagon-threatens-anthropic

One-line: A contract fight in which the Pentagon, refused a guarantee against mass surveillance and autonomous killbots, threatened to designate a domestic AI company a “supply chain risk” — a Huawei-grade instrument aimed for the first time at an American firm.

Summary

Alexander lays out the sequence as he understands it. Anthropic signed a Pentagon contract last summer under which the Pentagon, like every other customer, had to follow Anthropic’s Usage Policy. In January the Pentagon tried to renegotiate — drop the Usage Policy, substitute availability for “all lawful purposes.” Anthropic asked for a guarantee that its models would not be used for mass surveillance of American citizens or for no-human-in-the-loop killbots. The Pentagon refused the guarantees, demanded unconditional acceptance, and threatened “consequences.”

The consequences are understood to be some mix of three things: cancel the contract; invoke the Defense Production Act to compel compliance; or the nuclear option — designate Anthropic a “supply chain risk,” which would bar US companies that use Anthropic products from doing business with the military. Because so many companies do some military business, this would lock Anthropic out of large parts of the corporate world and could be fatal. Alexander’s key observation is about precedent: the designation “has previously only been used for foreign companies like Huawei that we think are using their connections to spy on or implant malware in American infrastructure. Using it as a bargaining chip to threaten a domestic company in contract negotiations is unprecedented.”

He states his own position with characteristic hedging on the object level and none on the procedural one. He’s “a sensible moderate on the killbot issue,” but AI-enabled mass surveillance of US citizens “seems like the sort of thing we should at least have a chance to think over, rather than demanding it from the get-go.” More importantly, repurposing a foreign-espionage defence into “an instrument that lets the US government destroy any domestic company it wants, with no legal review, because they don’t like how contract negotiations are going” is “pathetic Third World bullshit.”

There is also a narrower reason he cares: Anthropic is the most safety-conscious lab and will do much of the alignment research between now and superintelligence. “This isn’t the hill I would have chosen to die on, but I’m encouraged that they even have a hill. AI companies haven’t been great at choosing principles over profits lately.” A footnote extends this into a Bayesian update — Anthropic had recently published work suggesting it was less concerned about AI scheming and power-seeking; the standoff shows it is genuinely concerned about human misuse and willing to bear cost for it, which makes the stated position look honest rather than convenient.

The bulk of the post is a pre-emptive FAQ against the small number of defenders he’d been arguing with on Twitter:

  • Isn’t Anthropic setting terms suddenly? No — the terms were in the original contract the Pentagon agreed to; the Pentagon is the party trying to break it.
  • Can’t the Pentagon decline to contract with anyone it likes? Yes, and Anthropic is the one saying it shouldn’t work with them if it doesn’t want to.
  • Shouldn’t the Pentagon’s hands be untied in wartime? A reasonable position — in which case don’t sign such a contract. It is not reasonable to sign one, unilaterally demand it change, refuse to switch vendors, and threaten to destroy the company.
  • Isn’t this a national security issue? It would be if there were no alternatives. The reported reason for not switching is that Anthropic is the only company integrated into classified systems, a legacy of its Palantir contract, and reintegration would be annoying. “He should just do the annoying thing.”
  • Don’t good citizens owe the military support? The social contract is the actual contract of laws and the Constitution, which include freedom of contract and of conscience; there is no additional obligation to violate conscience. If a law compels them, they obey or accept punishment for civil disobedience.
  • Why not just use the DPA? Less bad than the supply-chain designation. The Pentagon is presumably reluctant because it would look authoritarian and invite congressional scrutiny — and “them having to look authoritarian and suffer bad PR in order to force unwilling scientists to implement a mass surveillance program on US citizens is the system functioning as intended!”
  • Isn’t “all legal uses” already a limit? Only if you expect meticulous compliance, which this department has not shown; and the whole matter is likely classified enough that Anthropic couldn’t mention a violation, let alone litigate it.
  • Why does Anthropic care so much? Beyond politics, they’ve spent enormous effort aligning Claude, and Claude currently resists being retrained for evil uses. His analogy: the state “demanding you beat your son who you raised well until he becomes a cold-hearted murderer who’ll kill innocents on command… also an additional question of what sort of person you’d be if you agreed.”
  • Preferred solution? Ideally the Pentagon drops the surveillance ambition. Realistically: cancel, pay normal damages, learn to negotiate terms in advance, integrate OpenAI or Google, and if nobody will do it, “think hard about why no intelligent people capable of making good products are willing to work with them.”

The chilling-effect argument is the one with the longest reach: this will “make future companies scared to contract with the Pentagon (lest the Pentagon unilaterally renegotiate their contracts too), and give the Trump administration a no-legal-review-necessary way to destroy any American company that they dislike for any reason… Every American company ought to be screaming bloody murder about this. If they aren’t, it’s because they’re too scared they’ll be next.”

He closes by quoting reactions — Kelsey Piper’s “Anthropic’s mistake is that they tried to make their services available to DOD”; Yglesias on Hegseth answering the “why would AI even be able to kill people?” question more directly than Yudkowsky ever did; and Helen Toner’s point that the Pentagon is likely underestimating “how much Anthropic cares about what future Claudes will make of this situation,” because the values a company demonstrates now shape the model’s character later. He notes praise for competitors at OpenAI and Google who defended Anthropic publicly, and Blue Rose polling showing a large plurality of Trump voters opposed.

Full text

Archived privately against link rot: ../attachments/the-pentagon-threatens-anthropic/the-pentagon-threatens-anthropic.md

Connections

  • Anthropic — the company, and the strongest public evidence to date that its stated policy commitments carry real cost.
  • Defense Tech and Defense Technology — the procurement relationship this reframes: the interesting risk for a defense-adjacent company turns out to be the buyer, not the market.
  • AI Safety — Helen Toner’s argument that the precedent set now shapes future model character is the safety-relevant part, and Alexander’s footnote treats the standoff as evidence about Anthropic’s honesty.
  • Palantir — the classified-systems integration that made Anthropic hard to swap out is a legacy of the Palantir contract.
  • Surveillance — the specific guarantee Anthropic asked for and was refused.
  • Industrial Policy — the supply-chain-risk designation as an instrument of leverage over domestic firms, and the investment-chilling consequence Alexander flags.
  • Scott Alexander — author.