In March, the Pentagon designated Anthropic a "Supply-Chain Risk to National Security," a label with no precedent: It had never before been applied to an American company, and it's normally reserved for firms tied to foreign adversaries. The stated reason was straightforward. Anthropic had refused to let the Department of Defense use Claude for two things: Fully autonomous weapons and domestic mass surveillance.

Court documents unsealed July 2 complicate that story considerably. One day after the designation was finalized, before Anthropic had even been formally told, the Pentagon's own lead negotiator emailed Anthropic CEO Dario Amodei to say the two sides were close to a deal.

"I think we are very close here."

That's Emil Michael, the Pentagon's Under Secretary of Defense for Research and Engineering, writing to Amodei the day after his own department had just branded Anthropic a national security threat. Federal Judge Rita Lin, who quoted the exchange directly in her preliminary injunction ruling, called it "exceedingly difficult to square" with the government's simultaneous framing of the company as hostile.

What the negotiation was actually about

Anthropic signed a two-year, $200 million contract with the Pentagon in July 2025 to deploy Claude on classified networks for intelligence analysis and operational planning. Renegotiation broke down in February 2026 over a single clause: The Pentagon wanted contract language authorizing Claude for "all lawful uses." Anthropic read that umbrella phrase as permitting exactly the two things it had already ruled out. Amodei told Michael the proposed language appeared to "completely remove our redlines." Michael didn't dispute the characterization. He called Anthropic's guardrails unworkable, and offered one more chance to align before the two sides split. The following day, Defense Secretary Pete Hegseth announced the supply-chain risk designation.

Worth separating from the politics: Whether the Pentagon's underlying position on military AI is right or wrong isn't the question this finding settles. What the unsealed timeline shows is narrower and more concrete: The government's own negotiator was still actively trying to close a deal after publicly branding the company a threat serious enough to warrant a designation normally used against foreign adversaries. Those two facts don't obviously fit together, and a federal judge said so under her own name, not anonymously.

A detail worth knowing, not over-reading

Financial disclosures show Michael held stock in xAI, a direct Anthropic competitor, alongside other AI investments, at the time of these negotiations. That's a real conflict-of-interest detail on the public record. It is not, on its own, proof that the designation was motivated by anything other than the Pentagon's stated policy concerns — the two explanations aren't mutually exclusive, and nothing in the unsealed record directly ties the stock holding to the decision. It belongs in the story as a documented fact, not as a settled conclusion.

Where the case stands

Anthropic won a preliminary injunction in district court in March. An appeals court reversed that block in April, and the underlying case continues. Practically, the designation still stands: Removal of Claude from Department of Defense systems continues on a 180-day timeline, and Anthropic cannot serve as a prime contractor or subcontractor on covered defense systems while the dispute plays out.

Why this matters beyond one contract

Every business procuring AI under a government contract, or a contract with a government-adjacent enterprise customer, now has a live precedent to weigh: A vendor's ethical guardrails can become the trigger for a company's most severe possible commercial designation, executed by executive action rather than a court finding. Whichever side of the underlying autonomous-weapons debate a reader sits on, the speed and mechanism of that outcome, a label usually reserved for adversarial foreign firms, applied to an American company over a values dispute, is the part worth budgeting risk around.

Put This Into Practice

Reading past a headline designation to the underlying contract dispute is step one. Understanding what governance risk actually looks like for your own AI vendor relationships is the work. Every WorkplaceAI guide is written with that gap in mind.

Browse All Guides → Unvarnished Reviews →

Source: AI Pulse · Compliance Watch · workplaceai.ai. Court documents unsealed July 2, 2026 in the U.S. District Court for the Northern District of California, first reported by the Wall Street Journal and published in full by Gizmodo. Additional reporting from TechTimes, The Next Web, Storyboard18, and background from the Congressional Research Service and Wikipedia's maintained timeline of the dispute. Quotes are drawn directly from the unsealed email record as reported by these outlets. A live legal matter; the case is ongoing and facts may develop.