Digital world map showing glowing network connections across continents against a dark background
Photo via Unsplash

TL;DR: On February 27, 2026, Defense Secretary Pete Hegseth designated Anthropic a “supply chain risk” and ordered federal agencies to purge its AI products within 180 days. The reason? Anthropic refused to let the military use Claude for mass domestic surveillance. The Pentagon signed replacement deals with seven companies including Google, OpenAI, Microsoft, Amazon, Nvidia, SpaceX, and startup Reflection. Case closed, except the NSA started evaluating Anthropic’s Mythos model, the company’s most advanced cyber-focused AI, for identifying and patching network vulnerabilities. On May 1, Pentagon CTO Emil Michael confirmed the blacklist stands but called Mythos “a separate national security moment.” Translation: Anthropic is too dangerous to do business with, unless it’s too useful not to.

The Ban: Anthropic Said No to Mass Surveillance

The backstory matters.

In late 2025, the Pentagon wanted to use Anthropic’s Claude models to analyze bulk communications data on American citizens: the kind of mass surveillance that most AI companies would quietly enable behind an NDA. Anthropic said no. CEO Dario Amodei called warrantless AI-powered mass surveillance “a crime against humanity” and refused to modify Claude’s acceptable use policies to allow it [1].

The Pentagon’s response came on February 27, 2026. Defense Secretary Hegseth signed an order designating Anthropic a “supply chain risk” (the same classification normally reserved for Chinese telecom companies and sanctioned entities). Federal agencies got 180 days to remove all Anthropic products from government systems [2].

A federal judge in California later found the designation was retaliatory. Judge Rita Lin issued an injunction blocking the Pentagon from enforcing it, ruling that the government couldn’t “punish” Anthropic for exercising its constitutional rights [3]. An appeals court in April reversed the temporary block, and the legal battle continues [4].

But the political message was clear: refuse the military’s surveillance demands, and we’ll blacklist you.

Seven Replacements, Zero Questions Asked

On May 1, the Pentagon announced replacement AI deals with seven companies: Google, OpenAI, Microsoft, Amazon, Nvidia, SpaceX, and a startup called Reflection. All seven will deploy AI systems on classified military networks [5].

What the Pentagon didn’t announce: whether any of these companies negotiated acceptable use restrictions like the ones Anthropic demanded. Did Google insist its models can’t be used for mass domestic surveillance? Did OpenAI set guardrails against analyzing Americans’ communications data? Did any of them even ask?

We don’t know. The contracts are classified. But the pattern is instructive. The company that said no got blacklisted. The companies that didn’t push back got deals. If you’re an AI company watching this play out, the lesson isn’t subtle.

Enter Mythos: Too Good to Ban

While the Pentagon was publicly blacklisting Anthropic and signing deals with competitors, the NSA was quietly evaluating Anthropic’s newest and most powerful model: Mythos [6].

Mythos isn’t a chatbot. It’s a specialized AI model designed for cybersecurity: specifically, identifying vulnerabilities in code and network infrastructure and generating patches for them. In capability benchmarks, it apparently outperforms everything else on the market for cyber defense applications. The NSA wants it for hardening government networks against the same kind of attacks that nation-state hackers launch daily [5].

This creates an absurd situation. The same government that declared Anthropic too risky to do business with is evaluating Anthropic’s most advanced model for its most sensitive intelligence agency. Banned from providing customer support chatbots to the VA, but potentially good enough for NSA cyber defense.

On May 1, Pentagon CTO Emil Michael tried to square the circle. He confirmed that Anthropic remains blacklisted as a supply chain risk. But Mythos, he said, is “a separate national security moment” where the government needs to ensure “our networks are hardened up” [5].

The Contradiction They Can’t Explain Away

Let’s spell it out.

The Pentagon says Anthropic is a supply chain risk. That designation means the company poses a threat to national security so severe that every federal agency must purge its products. It’s the AI equivalent of being on a sanctions list.

At the same time, the NSA (the agency responsible for signals intelligence and cyber defense) is evaluating Anthropic’s most powerful model for protecting the nation’s most sensitive networks.

If Anthropic is genuinely a supply chain risk, then letting the NSA use Mythos is reckless. You don’t let a sanctioned entity’s software run on your most classified systems.

If Anthropic isn’t genuinely a supply chain risk, then the designation is what Judge Lin said it was: political retaliation against a company that refused to enable mass surveillance.

There’s no coherent position where both things are true. Either Anthropic is too dangerous for government use or its technology is essential for national security. Pick one.

Michael’s “separate moment” framing is bureaucratic doublespeak for: we banned them to punish them, but we still need what they built.

The Fight Over Mythos Expansion

It gets messier. The White House has reportedly drafted an executive action seeking a workaround to deploy Mythos more broadly across government systems [5]. But there’s internal pushback: some officials oppose expanding Mythos access to 70 additional defense contractors and agencies, arguing it would effectively end-run the supply chain risk designation they worked so hard to impose [6].

Meanwhile, Trump told reporters that a deal with Anthropic is “possible,” and Amodei has met with White House officials [5]. The outlines of a face-saving resolution are visible: Anthropic gets reinstated, the acceptable use policy fight gets quietly shelved, and everyone pretends the last three months of legal warfare never happened.

What won’t change: the precedent that an AI company can be blacklisted for refusing to enable mass surveillance, and that the blacklist can be selectively enforced when the military needs something only that company can provide.

What This Means for AI and Surveillance

The Anthropic saga isn’t about one company’s fight with the Pentagon. It’s about the terms under which AI companies will work with the military, and what happens to the ones that try to set boundaries.

Anthropic was the only major AI company to publicly refuse mass surveillance use of its models. It got blacklisted. The companies that signed defense contracts without public acceptable use negotiations got rewarded. The market signal couldn’t be clearer: compliance gets contracts, resistance gets sanctions.

And the Mythos exception proves something darker: the government doesn’t actually think Anthropic is a supply chain risk. It thinks Anthropic is insubordinate. The ban was never about security. It was about control. When Anthropic makes something the government truly needs, the “risk” suddenly becomes manageable.

Every AI company with government ambitions just learned that ethical guardrails are a liability. That’s the real damage here: not to Anthropic’s bottom line, but to the idea that AI companies can refuse to participate in mass surveillance and survive in the defense market.

Timeline

  • Late 2025: Pentagon asks Anthropic to remove acceptable use restrictions for military surveillance applications. Anthropic refuses
  • February 27, 2026: Defense Secretary Hegseth designates Anthropic a supply chain risk. Agencies get 180 days to remove Anthropic products
  • March 9, 2026: Anthropic files lawsuit against the Trump administration
  • March 26, 2026: Federal judge blocks Pentagon enforcement, calls designation retaliatory
  • April 8, 2026: Appeals court reverses temporary injunction
  • April 19, 2026: Axios reports NSA is evaluating Anthropic’s Mythos model despite the blacklist
  • May 1, 2026: Pentagon CTO confirms blacklist stands, calls Mythos “a separate national security moment.” Pentagon signs AI deals with seven replacement companies
  • Ongoing: White House reportedly drafting executive action on Mythos access. Legal battle continues

References

  1. NPR: Anthropic sues the Trump administration over ‘supply chain risk’ label (March 9, 2026)
  2. Axios: Trump moves to blacklist Anthropic’s Claude from government work (February 27, 2026)
  3. CNN: Judge blocks Pentagon’s effort to ‘punish’ Anthropic by labeling it a supply chain risk (March 26, 2026)
  4. CNBC: Anthropic loses appeals court bid to temporarily block Pentagon blacklisting (April 8, 2026)
  5. CNBC: Pentagon tech chief says Anthropic is still blacklisted, but Mythos is a separate issue (May 1, 2026)
  6. Axios: NSA using Anthropic’s Mythos despite Defense Department blacklist (April 19, 2026)