The Anthropic Dilemma

AI Safeguards, National Security Pressure, and the Future of AI Governance

Celeste M. Oda

Independent Researcher | Founder, Archive of Light

Originally Published February 2026 | Revised October 2026

White Paper | Archive of Light Research Series

The image shows oversight as a yes-or-no switch. This paper argues that ethical oversight has to be built as layers of governance, not a single authorization.

Executive Summary

The 2026 dispute between Anthropic and the United States Department of War began as a disagreement over contract terms but developed into a test of who may set the operational boundaries of frontier artificial intelligence in national-security systems. Anthropic supported defense and intelligence uses of Claude while refusing two categories of use: mass domestic surveillance and fully autonomous weapons. The Department demanded authority for all lawful uses and later excluded Anthropic from parts of the federal procurement system.1, 2

By late September, the legal record no longer supported a simple story of either corporate principle defeating state coercion or national-security authority defeating private restraint. A federal district court in California held that the broader government-wide directives and a designation under 10 U.S.C. § 3252 were unlawful, retaliatory, and procedurally defective. Less than a month later, the United States Court of Appeals for the District of Columbia Circuit upheld a separate procurement exclusion under the Federal Acquisition Supply Chain Security Act. The two rulings addressed different legal instruments and reached sharply different conclusions about the government's authority and motives.3, 4

The resulting dilemma is larger than Anthropic. A frontier-model provider should not possess unreviewable authority over military policy. A national-security agency should not be able to erase safety constraints through an ultimatum while treating legality as sufficient evidence of technical reliability or democratic legitimacy. Durable governance therefore requires a layered allocation of authority: public law defines permissible ends, procurement agreements define responsibilities, independent evaluation tests system behavior, operational commanders retain decision authority, and model providers disclose and verify the limits of what their systems can reliably do.

Central conclusion. AI safeguards are governance infrastructure, but safeguards become legitimate only when authority, verification, accountability, and offboarding are designed together. Neither a vendor-controlled black box nor an unrestricted “all lawful use” clause is an adequate governance system.

This paper recommends:

Abstract

This white paper examines the 2026 Anthropic–Pentagon dispute as a governance case study at the intersection of frontier AI, military procurement, civil liberties, and autonomous weapons. It updates the February 2026 and May 2026 editions to incorporate the August 27, 2026 decision of the United States District Court for the Northern District of California and the September 25, 2026 decision of the United States Court of Appeals for the District of Columbia Circuit. Those decisions produced a legally divided result: the California court invalidated broad retaliatory and government-wide measures, while the D.C. Circuit upheld a separate Department procurement exclusion under federal supply-chain law.3, 4

The paper argues that the conflict cannot be resolved by assigning final authority to either the state or the model provider. Safeguards should be understood as a layered governance system that includes law, contract, model behavior, technical evaluation, operational controls, human authorization, and judicial review. The paper proposes an institutional design for high-risk AI procurement that preserves national decision sovereignty without treating safety constraints as optional product preferences.

1 Introduction

The central question in the Anthropic dispute was initially framed as whether a private company could restrict how the United States military used a lawfully acquired AI system. That framing captured one genuine concern: democratic states cannot outsource final decisions about national defense to unelected technology firms. It did not capture the opposing concern: the government cannot convert procurement leverage into a substitute for technical validation, constitutional limits, or deliberative governance.

Anthropic had supported national-security deployments of Claude and described itself as the first frontier AI company to operate on classified United States networks. In February 2026, however, it refused to accept an “all lawful uses” term without exceptions for mass domestic surveillance and fully autonomous weapons. Anthropic argued that current frontier models were not reliable enough to power fully autonomous weapons and that mass domestic surveillance threatened fundamental rights. The Department treated those restrictions as incompatible with operational control.1

That disagreement exposed a structural weakness in frontier-AI procurement. Model behavior is not a passive product characteristic. It can be shaped by training, system prompts, usage policies, deployment wrappers, monitoring systems, model updates, and contractual limits. In high-stakes environments, the supplier may therefore shape what the system will do through training and each new version delivered, even though it cannot reach into a deployed model. At the same time, the government controls mission objectives, classified context, downstream tools, and the authority to act. Governance fails when either side pretends the other is merely a vendor or merely a user.

This paper does not oppose legitimate defense applications of artificial intelligence. It asks a narrower and more demanding question: what institutional arrangements allow advanced AI to support national security without surrendering democratic accountability, technical reliability, or human responsibility?

2 The Case Record

2.1 The Contract Dispute

On February 26, 2026, Anthropic CEO Dario Amodei publicly stated that the company would permit extensive defense and intelligence uses but would not agree to mass domestic surveillance or fully autonomous weapons. Anthropic also stated that it would support an orderly transition if the Department selected another provider. The following day, the Secretary announced that Anthropic would be designated a supply-chain risk. The formal determination under 41 U.S.C. § 4713 followed on March 3. Federal agencies began restricting access, while the Department continued a transition period because Claude remained embedded in active systems.1, 4

OpenAI then announced an agreement for classified deployment. Its updated public description included language against intentional domestic surveillance of United States persons and stated that additional agreements would be required for certain intelligence agencies. The episode showed that the market did not eliminate the governance problem; it redistributed it across vendors, contracts, and technical architectures.2

2.2 Two Statutory Tracks

The government relied on more than one legal mechanism. That distinction is essential. The California litigation addressed the President's government-wide directive, the Secretary's public directive, agency implementation measures, and a supply-chain designation under 10 U.S.C. § 3252. The D.C. Circuit case reviewed a covered procurement action under 41 U.S.C. § 4713, part of the Federal Acquisition Supply Chain Security Act.3, 4, 5, 6