What the label does
On March 5, 2026, the Department of Defense, since renamed the Department of War, notified Anthropic that it had designated the company a supply chain risk. The label is written for foreign adversaries whose hardware or software might be sabotaged from outside. This was the first time it had been applied to an American company. [1]
The practical effect falls on everyone else who does business with the Pentagon, not directly on Anthropic. Legal analyst Amos Toh described the designation's reach: it "could foreclose the company from working with the department in any capacity, and require other defense contractors to unwind Claude from their systems in order to continue their defense work." [2]
Atlas interpretation: That is why the certification requirement matters more than the label itself. Anthropic was never a Pentagon vendor of consequence on its own; the designation reaches every contractor with a Claude integration anywhere in its stack, whether or not the work has anything to do with defense. [2]
A statute built for sabotage, not disagreement
The designation draws on 10 U.S.C. 3252 and the Federal Acquisition Supply Chain Security Act. Toh noted the authority applies only "if the designation is required to reduce the risk that adversaries may sabotage or otherwise subvert a national security system," and questioned whether the department had shown any such risk from Anthropic rather than pursuing what he called the required "less intrusive measures" first. [2]
A former senior defense official called the threat "absurd," pointing out the department was simultaneously arguing Claude was important enough to defense work that it should get unfettered use and dangerous enough to bar entirely. The Information Technology and Innovation Foundation's Daniel Castro warned that using the tool this way, as he put it, "as punishment," risked discouraging other technology firms from working with the military at all. [2]
Atlas interpretation: The statute assumes the risk is technical: a component that could be tampered with before it reaches a weapons system. Applying it here required treating a company's contract terms as the sabotage risk, a use of the label nobody designed it for. [2]
A contract dispute, not a security finding
The department wanted a vendor that would accept any lawful use of its models. Anthropic would not drop two carve-outs. On February 26, CEO Dario Amodei published Anthropic's refusal, writing that "using these systems for mass domestic surveillance is incompatible with democratic values" and that "frontier AI systems are simply not reliable enough to power fully autonomous weapons." He called the threats the department had already made, including invoking the Defense Production Act, "inherently contradictory," and held the position anyway. [4]
The next day, February 27, the administration directed agencies to move toward the designation. Hours later, OpenAI signed its own agreement with the department, saying it had secured prohibitions on domestic mass surveillance and human responsibility for the use of force, close to the same two conditions Anthropic would not drop. The March 5 designation followed a week after Amodei's refusal. [1]
Atlas interpretation: OpenAI getting nearly the same carve-outs Anthropic asked for, without being called a supply chain risk for it, is the detail that turns this from a security story into a leverage story. The label arrived a week after the refusal it was punishing, not after any finding about Anthropic's models. [1]
What was on the table
Anthropic was projecting roughly 14 billion dollars in 2026 revenue, most of it from customers with nothing to do with defense, with more than 500 customers paying at least a million dollars a year. The designation threatened to force any of those customers with a defense relationship to strip Claude out or lose their own Pentagon work. [3]
Anthropic sued four days later, filing in both federal district court in California and the D.C. Circuit, arguing that "the Constitution does not allow the government to wield its enormous power to punish a company for its protected speech" and that "no federal statute authorizes the actions taken here." [3]
Sources
- It's official: The Pentagon has labeled Anthropic a supply-chain risk
TechCrunch · Mar 5, 2026
- Experts raise questions and concerns about Pentagon's threat to blacklist Anthropic amid AI spat
DefenseScoop · Feb 27, 2026
- Anthropic sues in federal court to reverse Trump administration's 'supply chain risk' designation
PBS NewsHour · Mar 9, 2026
- Statement from Dario Amodei on our discussions with the Department of War
Anthropic · Feb 26, 2026