The Pentagon Blacklisted Anthropic in a Memo. Removing Claude From Its Systems Took Seven Months.
The Pentagon gave the BBC a sentence on Monday that reads like the end of a story. The department "has ceased the use of Anthropic products," an official said. It is clean, decisive, and finished. Except the same reporting says Claude was still doing the department's intelligence work as recently as last week.
That gap between the announcement and the reality is the actual story here, and it is not really about Anthropic.
The deadline that came and went
On 27 February 2026, Defence Secretary Pete Hegseth said he would label Anthropic a national security supply chain risk, and announced the Pentagon would stop using it by late August. The formal determination under the Federal Acquisition Supply Chain Security Act followed on 3 March, and the department's chief information officer ordered all Anthropic products pulled from DoW systems inside 180 days. Contractors were told to stop using Claude in defence work too.
That deadline has passed. According to multiple people who spoke to the BBC, including former US defence officials and contractors who have worked closely with the Pentagon on AI, Claude was still being used throughout the whole period of the controversy. It was doing research, analysis and intelligence gathering, and supporting military operations against Iran. Anthropic's Mythos models were part of that, one source said.
The BBC says it is not clear why the department stopped using the tools only now. The architecture of where Claude actually sat explains a good deal of it.
You cannot switch off what you have wired in
Claude was never a standalone app someone could revoke. It sat inside Maven Smart System, the Palantir-operated platform the Pentagon uses as its primary system for organising intelligence and other data. Cameron Stanley, who leads AI work inside the department, described Maven during a demonstration this year as deployed "across the entire department."
The workflow matters. Analysts pull satellite imagery and drone footage into Maven, that data feeds through Claude and other large language models for tasks such as identifying potential military targets, and officials use the output to build the one-page briefs that travel up the chain of command. Recent private demonstrations of Maven for government officials still included Claude, according to another person familiar with the system. Maven is also used by some US allies to share intelligence with Washington.
The contract behind this was worth $200 million, and per the legal record, Anthropic has held it since July 2025 as the first frontier AI company to place models on classified government networks. Its tools had been in US government and military use since 2024.
Lauren Kahn, a senior research analyst at Georgetown's Center for Security and Emerging Technology and a former US defence official, put the mechanics plainly to the BBC. The fact that it took the Pentagon until now to remove all use of Claude "is indicative that these things are not just plug and play," she said. "Once they become integrated it can be painful to remove them."
Two courts, two statutes, two answers
The legal ground under the designation has been moving all year, and it has not settled.
On 27 August, US District Judge Rita Lin in San Francisco struck down the parallel designation made under a different law, 10 U.S.C. § 3252, and called it "illegal and baseless." She found the government had unlawfully retaliated against Anthropic for its advocacy on AI safety in violation of the First Amendment, and denied the company the process the Fifth Amendment required. "Empty invocation of national security is not a blank check to punish and retaliate against government critics," Lin wrote. She blocked the government-wide ban and the order barring contractors from doing any business with Anthropic.
Four weeks later, the D.C. Circuit went the other way on the FASCSA designation. In a 2-1 ruling on 25 September, Judge Gregory Katsas, joined by Judge Neomi Rao, found the Department of War had "ample support" for treating continued Claude use as a national security risk, and rejected the retaliation claim. The court leaned on the argument Hegseth's side had made all along, that the company's safety restrictions were themselves the hazard: "The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail."
Judge Karen LeCraft Henderson dissented. Her objection was to the width of the majority's reading of the word "manipulate" in the statute. Under it, she warned, the government could designate any contractor that enforces disfavoured but lawful contract restrictions a supply chain risk, regardless of good faith. Lawyers at Blank Rome made the same point in blunter terms: on this reading, a SaaS provider that can cut off access for non-payment, or a developer that can push an update, is technically a supply chain risk too.
Anthropic said it respectfully disagrees and is considering its options, including asking the full D.C. Circuit to rehear the case.
One detail stands out against all of it. The court noted that Anthropic's valuation had reportedly climbed past $900 billion since the exclusion took effect. Being thrown out of the Pentagon's supply chain has, so far, cost the company far less in market standing than the designation was meant to.
What it means for a supply chain of any size
Read one way, this is a safety-against-military-use fight, and it is a genuine one. Read it operationally, and it is a story about the distance between a decision and its execution. A vendor can be blacklisted in a memo on a Tuesday. It cannot be un-integrated from a platform on the same schedule, particularly when that platform is the department's primary intelligence-organising layer and the model is wired into target identification and commander-level briefings.
While the courts argued, the Pentagon signed Google, xAI and OpenAI, and OpenAI tools have spread into some military departments in recent months. On 1 May the department announced it had agreements with seven companies to run advanced AI on classified networks, all under the phrase "lawful operational use." A former senior US defence official told the BBC there "was concern with moving beyond Anthropic to OpenAI" when the phase-out was first ordered.
For defence contractors, the practical work is now procedural. The D.C. Circuit decision does not itself act as a contract-level ban; it reaches contractors through FAR 52.204-30 as written into specific contracts, through modifications naming Anthropic as a covered source, and through certification requests. Those requests are already arriving across the defence industrial base with different deadlines, scopes and wording. The hard question is what "as part of the performance of the contract" actually covers: a back-office HR or accounting tool with Claude inside it, or a model embedded in a third-party platform that happens to be used by people working on the contract. Faced with that ambiguity, several contractors may simply decide to remove Anthropic everywhere.
That instinct, to rip out an embedded model entirely rather than scope the removal, is the same one that shows up in every industry once a vendor's technology stops being a product you buy and becomes a component your workflows depend on. The decision is quick. The unwinding is a procurement and integration problem, and it has a schedule of its own.
For hardware and technology companies, the lesson worth taking is that model-layer dependencies behave like any other scarce input in the bill of materials. What matters is knowing where the dependency sits, how deep into the workflow it runs, what it costs to remove, and how long the replacement actually takes once the decision is made. At DMC, we work with hardware teams stress-testing exactly that: sourcing strategy, cost modelling and roadmap planning for the moments when a supply relationship ends faster than the systems built on top of it can follow. If your roadmap has a vendor dependency you have not costed the removal of, let's talk.