Timeline of the Anthropic–U.S. Department of Defense contract negotiations

From Timelines
Jump to navigation Jump to search

This is a timeline of the AnthropicU.S. Department of Defense contract negotiations, documenting the development of collaboration, conflict, and policy disputes over the military use of frontier AI systems. It traces key events including defense contracts, disagreements over safeguards such as bans on mass surveillance and autonomous weapons, government retaliation, and broader debates about AI governance, national security, and corporate responsibility.

Sample questions

The following are some interesting questions that can be answered by reading this timeline:

  • What early developments set the stage for the relationship between Anthropic and the U.S. military before the conflict erupted?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Prelude".
    • You will see the release of "Claude Gov" for classified national-security work (June 2025) and the Pentagon's $200 million contract awards to Anthropic, Google, OpenAI, and xAI (July 2025).
  • What events set off the public standoff between Anthropic and the Pentagon in February 2026?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Report" and "Negotiation".
    • You will see the Wall Street Journal's February 15 report on Anthropic's objections to Claude's role in the Maduro capture operation, and Hegseth's February 24 ultimatum meeting with Amodei — both preceding the public rupture on February 27.
  • How did Anthropic's own public statements evolve as the dispute escalated?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Company statement".
    • You will see Amodei's February 26 statement laying out the company's red lines, and his February 28 CBS News interview defending that position after Anthropic was labeled a supply-chain risk.
  • What direct actions did the U.S. government take against Anthropic on February 27, 2026?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Government action".
    • You will see Trump's Truth Social directive ordering federal agencies to stop using Anthropic, and Hegseth's declaration barring military contractors from doing business with the company.
  • How did the Pentagon's supply-chain-risk designation actually take legal effect, step by step?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Designation".
    • You will see Hegseth's March 3 Secretarial Determination, distinct from his premature February 27 social media post, followed by the Pentagon's formal notification to Anthropic on March 5.
  • How did OpenAI's relationship with the Pentagon compare to Anthropic's, and how did the broader AI industry position itself relative to the standoff?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Competition" and "Industry support".
    • You will see OpenAI's February 27 classified-network deal and its March 2 contract amendment on domestic surveillance, the Pentagon's May 1 agreements with eight companies excluding Anthropic, and Microsoft's March 12 amicus brief joined by Google, Amazon, Apple, and OpenAI in support of Anthropic's lawsuit.
  • What legal arguments and rulings shaped the courtroom fight over Anthropic's blacklisting?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Legal action", "Legal response", "Court hearing", and "Court ruling".
    • You will see Anthropic's March 9 lawsuits, the government's March 17 defense of the designation, the March 24 preliminary-injunction hearing, Judge Rita Lin's March 26 ruling blocking the ban, and a July 30 hearing on making that injunction permanent.
  • What range of expert and commentator perspectives emerged on the broader implications of the standoff?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Analysis".
    • You will see Kat Duffy and Amos Toh on the legal and oversight risks of escalation, Max Tegmark on AI companies' failure to support binding regulation, the Electronic Frontier Foundation on Congress's failure to legislate privacy protections, a comparison of Anthropic's approach to European AI governance, Ben Thompson's argument on state control over strategically important technology, Kat Duffy's CFR piece on U.S. credibility and the China AI gap, and commentary on why the Pentagon's refusal to accept limited safeguards was telling.
  • How did the public respond to the standoff between Anthropic and OpenAI's differing approaches to Pentagon partnership?
    • Sort the full timeline by "Event type" and look for the group of rows with value "Public reaction".
    • You will see Claude becoming the world's most downloaded app while ChatGPT faced a wave of uninstalls, and OpenAI facing "Delete ChatGPT" campaigns after its own Pentagon deal announcement.
  • Other events are described under the following types: "Operational use", "Policy proposal".

Big picture

Year Event type Details
2025 (July 15) Prelude The Pentagon awards Anthropic, Google, OpenAI, and xAI contracts worth up to $200 million each for frontier AI development, establishing Anthropic as an early, deeply embedded defense partner.
2026 (February 24) Negotiation Defense Secretary Pete Hegseth delivers an ultimatum to Anthropic CEO Dario Amodei: agree to "all lawful use" of Claude (language model) by Friday, or be designated a supply-chain risk.
2026 (February 27) Government action After Amodei's public refusal, Trump orders all federal agencies to stop using Anthropic and Hegseth declares the company a supply-chain risk; OpenAI announces its own competing Pentagon deal the same day.
2026 (March 9) Legal action Anthropic sues the federal government in California and the D.C. Circuit, alleging unconstitutional retaliation.
2026 (March 26) Court ruling Judge Rita Lin blocks the ban, finding the government's actions "appear designed to punish Anthropic" and constitute First Amendment retaliation.
2026 (May 1) Competition The Pentagon signs classified-network agreements with eight rival AI companies, formally excluding Anthropic, even as Trump had signaled a possible thaw weeks earlier.
2026 (July 30) Court hearing Judge Lin says the government's case "seems to have gotten worse," with no new evidence justifying the designation — the dispute remains unresolved.

Full timeline

Inclusion criteria

The timeline covers events directly concerning the relationship, negotiations, and conflict between Anthropic and the U.S. Department of Defense (Department of War) over military use of Anthropic's AI systems — including the terms of that relationship, its public breakdown, the legal fight that followed, and the broader industry and political response specifically triggered by this dispute.

What is included

  • Direct negotiations, contracts, and contract disputes between Anthropic and the DoD/DoW, including named individual meetings (e.g. ultimatums, resumed talks) where a primary or contemporaneous source documents them.
  • Formal government actions taken against Anthropic specifically (designations, directives, formal notifications) and the precise legal/procedural mechanism by which each one took effect, when that mechanism is documented — distinguishing, for example, a public announcement of intent to designate from the legally operative designation itself.
  • Court filings, hearings, and rulings in litigation arising directly from this dispute, including distinct stages of the same case (filing, status conference, preliminary hearing, ruling, appeal, stay motion) as separate rows, and separate rows for legally or jurisdictionally distinct tracks of the same underlying conflict (e.g. parallel designations under different statutes, litigated in different courts).
  • Statements and interviews from Anthropic (CEO or company) directly addressing the dispute.
  • Rival AI companies' own deals or negotiations with the DoD/DoW when they are explicitly framed, by the reporting, as competitive responses to or comparisons with Anthropic's situation — not merely because the company also does business with the Pentagon.
  • Third-party industry actions (amicus briefs, statements, investor pressure, employee letters) that explicitly invoke or are motivated by the Anthropic-DoD dispute, even when the company involved is not Anthropic itself (e.g. a Google employee letter citing Anthropic's blacklisting as context).
  • United States Congress actions (letters, hearings, floor statements) that directly address this dispute.
  • Analysis and commentary pieces from recognized experts, institutions, or publications that substantively engage with the dispute's legal, political, or governance implications — not brief mentions in passing.
  • Backdrop/prelude events that establish the pre-existing relationship between Anthropic and the DoD, even before visible tension (e.g. the original contract award, earlier friction over unrelated policy positions), when they are identified by reporting as relevant context for the later conflict.

What is excluded

  • Anthropic's business dealings with entities other than the DoD/DoW, even during the same period, unless the reporting explicitly ties them to the DoD dispute (e.g. a compute-supply deal with a third party is excluded even if that third party separately pitches the Pentagon, unless Anthropic's role in that pitch is about the DoD relationship itself).
  • Actions by other U.S. government departments or agencies against Anthropic that are legally and substantively distinct from the DoD dispute (e.g. Commerce Department export-control actions), even if they occur amid the same broader tension between Anthropic and the administration — these belong in a different timeline about Anthropic's government relations more broadly.
  • Claims sourced only to a single non-contemporaneous secondary aggregator, without corroboration from a primary source or a major outlet, especially where the claim is extraordinary relative to what well-sourced contemporaneous reporting shows for the same period. Such claims should be independently verified before inclusion, not included provisionally.
  • Generic market/business coverage of Anthropic (revenue figures, valuation, stock-adjacent commentary) unless directly tied to the financial stakes or evidentiary record of the DoD dispute itself (e.g. revenue-impact figures cited in a court filing are includable; a general revenue-run-rate story is not).
  • Redundant announcements of the same underlying event from multiple outlets, where the additional source adds no new substantive detail — these should be added as additional citations to the existing row rather than new rows.
Year Event type Details
2025 (June 6) Prelude A report describes “Claude Gov,” a specialized version of Anthropic’s AI models designed for U.S. national security agencies and capable of handling classified information. Developed with government feedback, the system supports tasks such as intelligence analysis, strategic planning, and operational assistance within secure environments. The models are customized to better process defense documents and languages relevant to security operations. The initiative reflects growing competition among AI companies for defense contracts, while experts caution that AI systems may produce inaccurate analyses if not carefully supervised.[1]
2025 (July 15) Prelude The U.S. Department of Defense awards Anthropic, along with Google, OpenAI, and xAI, contracts worth up to $200 million each to develop advanced AI tools for national-security applications. The initiative aims to accelerate the Pentagon’s adoption of generative and agentic AI across mission areas, including analysis and operational support. Anthropic’s inclusion highlights its role as a major frontier-AI provider working with defense agencies. The contracts reflect growing competition among leading AI companies to supply the U.S. military with advanced artificial-intelligence capabilities.[2]
2026 (January 16) Report Semafor reports that tension has been building between Anthropic and the Pentagon for weeks, after Defense Secretary Pete Hegseth announced the Pentagon was adding xAI's Grok (chatbot) to its list of generative AI providers and railed against AI models that "won't allow you to fight wars" — a remark a person familiar with his thinking says was specifically directed at Anthropic. The report notes that the Pentagon's new AI acceleration strategy document, unveiled the same day, states the Department "must also utilize models free from usage policy constraints that may limit lawful military applications," language that alarms AI safety advocates, including some at Anthropic. A Defense Department official says the Pentagon will only deploy models "free from ideological constraints that limit lawful military applications." The report also notes earlier friction: Anthropic had previously opposed a White House-backed law that would have preempted state-level AI regulation, and had barred its models from certain law enforcement uses.[3]
2026 (February 15) Report The Wall Street Journal reports that Anthropic had raised concerns with Palantir Technologies about the role its AI technology played in the U.S. military operation to capture Venezuelan President Nicolás Maduro. The report inflames existing tensions, with Defense Secretary Pete Hegseth and other Pentagon officials characterizing it as Anthropic resisting the military's use of its systems. Anthropic responds in a statement: "Anthropic understands that the Department of War, not private companies, makes military decisions. We have never raised objections to particular military operations nor attempted to limit use of our technology in an ad hoc manner."[4]
2026 (February 23) Competition xAI signs an agreement allowing the Pentagon to use its Grok (chatbot) model in classified systems, a Defense official confirms to Axios (website), with the New York Times first reporting the signed deal. xAI agrees to the Pentagon's "all lawful use" standard that Anthropic had refused. A Defense official says the department is accelerating parallel talks with Google and OpenAI as it prepares a possible break with Anthropic, though officials acknowledge replacing Claude (language model) — used in the Maduro raid via Anthropic's Palantir partnership — would be difficult; Google is reportedly "close" to its own deal while OpenAI remains "not close." The news comes as Hegseth prepares to meet Amodei the following day for what sources expect to be a tense ultimatum meeting.[5]
2026 (February 24) Negotiation Defense Secretary Pete Hegseth meets with Anthropic CEO Dario Amodei and delivers an ultimatum: if the company does not agree by 5:01 p.m. the following Friday to let the Pentagon use its technology for "all lawful purposes," Hegseth says he will designate the company a supply-chain risk.[4]
2026 (February 26) Company statement Anthropic CEO Dario Amodei states that the company strongly supports deploying AI to defend the United States and democratic allies, and had already supplied models to U.S. defense and intelligence agencies. Anthropic says it had restricted access to adversaries and supported export controls to preserve democratic technological advantage. However, it refuses to allow two uses: mass domestic surveillance and fully autonomous weapons, citing democratic values and technical safety concerns. The Department of War demands unrestricted lawful use and had threatened sanctions if safeguards remain, a request Anthropic rejects.[6]
2026 (February 27) Government action President Donald Trump posts on Truth Social that the U.S. "will never allow a radical left, woke company to dictate how our great military fights and wins wars," directing all federal agencies to immediately stop using Anthropic's technology. Trump sets a six-month phase-out period and threatens "the full power of the presidency" — including civil and criminal consequences — if the company resists.[7][8]
2026 (February 27) Competition OpenAI CEO Sam Altman announces that the company had reached an agreement with the U.S. Department of War to deploy its AI models on classified government networks. Altman says the department supports OpenAI's safety principles, including prohibitions on domestic mass surveillance and maintaining human responsibility in the use of force. The agreement includes technical safeguards, deployment on cloud networks, and field deployment engineers to oversee model safety. Altman also urges the government to extend similar terms to other AI companies.[9][10]
2026 (February 27) Government action In a public statement on X, U.S. Secretary of War Pete Hegseth sharply criticizes Dario Amodei, accusing the company of arrogance and attempting to impose ideological restrictions on the U.S. military's use of AI. Hegseth directs the Pentagon to designate Anthropic a supply-chain risk and orders that contractors, suppliers, and partners working with the U.S. military be barred from doing business with the company, framing the decision as final. He announces a six-month transition period for federal agencies and military contractors to phase out Anthropic's technology.[11][12]
2026 (February 27) Congressional action United States Senate Committee on Armed Services leaders Roger Wicker and Jack Reed, joined by top Senate defense appropriators Mitch McConnell and Chris Coons, send a letter to Hegseth and Amodei urging both sides to extend negotiations past the Pentagon's 5:01 p.m. deadline, calling the deadline "hasty" and warning that labeling Anthropic a supply-chain risk "without credible evidence" could damage cooperation between the military and Silicon Valley at a time the U.S. "cannot afford to take on any preventable risk" relative to China. "There is no reason to transform this situation into an all-or-nothing moment," the senators write, asking both parties "to extend the negotiating window and work with Congress to find a solution." Axios (website) first reports the letter's existence.[13]
2026 (February 28) Company statement In a CBS News interview, Anthropic CEO Dario Amodei explains the company’s dispute with the U.S. Department of War after being labeled a national-security supply-chain risk. Amodei says Anthropic supports national defense and already provides AI to intelligence and military systems, but refuses two uses: domestic mass surveillance and fully autonomous weapons without human oversight. He argues current AI systems are unreliable for lethal autonomy and that surveillance capabilities may outpace legal safeguards. Amodei describes the Pentagon’s ultimatum as punitive but says Anthropic remains willing to cooperate under its “red line” restrictions and would continue supporting U.S. security.[14]
2026 (February 28) Analysis A publication argues that Anthropic was justified in refusing Pentagon demands to remove safeguards on its AI systems. The author argues that the company’s safeguards—banning domestic mass surveillance and fully autonomous weapons—were modest and reasonable. According to the writer, the Pentagon’s refusal to accept even limited constraints demonstrates why military institutions should not be trusted with unrestricted AI authority. The episode is cited as evidence that stronger regulation and oversight of military AI are urgently needed.[15]
2026 (February 28) Analysis An interview discusses the dispute between Anthropic and the U.S. Department of War over restrictions on military uses of artificial intelligence. Experts Kat Duffy and Amos Toh explain that the conflict reflects broader tensions between rapid military AI adoption and safety safeguards. The experts warn that escalating the conflict—such as labeling Anthropic a supply-chain risk—raises legal questions, damages global trust in U.S. technology, and highlights the need for stronger congressional oversight of military AI.[16]
2026 (February 28) Analysis A publication reports on an interview with MIT physicist Max Tegmark about the conflict between Anthropic and the U.S. government over limits on AI use. Tegmark argues the dispute reflects a broader failure by major AI companies—including Anthropic, OpenAI, and Google DeepMind—to support binding regulation. According to Tegmark, their reliance on voluntary self-governance created a regulatory vacuum that now leaves them vulnerable to political pressure. He warns that rapid AI development without strong oversight could create severe societal and security risks.[17]
2026 (March 1) Public reaction Anthropic’s standoff with the U.S. government culminates in a dramatic public response. After refusing Pentagon demands for unrestricted AI use and being labeled a “supply chain risk,” CEO Dario Amodei defends the decision in a CBS interview. That same day, Claude (language model) becomes the world’s most downloaded app, topping App Store rankings in over 20 countries. The surge reflects widespread public and industry support, while ChatGPT faces backlash, including sharp spikes in uninstalls and negative reviews.[18]
2026 (March 2) Operational use A publication reports that Claude AI was used by United States Central Command during airstrikes on Iran for intelligence analysis, target identification, and battle simulations, even after President Donald Trump had ordered federal agencies to phase out the company’s technology. The report highlights how deeply AI systems are embedded in military infrastructure, making rapid replacement difficult.[19]
2026 (March 2) Competition OpenAI updates its Department of War agreement with additional contract clauses making explicit that its AI tools will not be used to conduct domestic surveillance of U.S. persons, including through commercially acquired personal data. The Department states its intelligence agencies, such as the National Security Agency, would require a separate agreement to use OpenAI's services at all. The Department also announces plans to convene a working group of frontier AI labs, cloud providers, and its own policy and operations teams to continue the dialogue.[10]
2026 (March 2) Public reaction A report states that OpenAI faces a backlash after announcing a Pentagon deal, prompting some users to cancel ChatGPT accounts and switch to Anthropic’s Claude. Online campaigns such as “Delete ChatGPT” and “CancelChatGPT” spread across social media, criticizing OpenAI’s military partnership. At the same time, Claude rose to the top of the Apple App Store productivity rankings in the United States, Canada, and Germany.[20]
2026 (March 2) Analysis A column argues that Anthropic’s AI policies may align better with Europe than with the United States. The dispute arose after President Donald Trump criticized the company’s “woke” restrictions, which prohibit domestic mass surveillance and fully autonomous weapons. Despite political attacks and a planned government phase-out, the U.S. military reportedly continued using Anthropic’s Claude during strikes on Iran. The author suggests that Europe’s regulatory framework, particularly the EU AI Act emphasizing oversight and limits on surveillance, is more compatible with Anthropic’s safety-focused approach than the U.S. political environment.[21]
2026 (March 2) Analysis In a Stratechery analysis, Ben Thompson argues that the conflict between Anthropic and the U.S. government reflects a deeper issue about power and control over advanced AI. Anthropic seeks to restrict uses such as mass surveillance and fully autonomous weapons, while the Pentagon insists on “any lawful use.” Thompson contends that decisions about military capabilities should ultimately belong to elected governments, not private companies. If AI becomes strategically comparable to nuclear weapons, he argues, states will not tolerate independent corporate control over such technology and will assert authority over it.[22]
2026 (March 3) Designation Defense Secretary Pete Hegseth formally designates Anthropic a national-security supply-chain risk via a Secretarial Determination, distinct from and following his February 27 X post directing the designation. The February 27 post is later acknowledged by the government, in court filings, as legally premature — a senior research fellow at the Institute for Law & AI notes it "went far beyond what the law allows him to say" and skipped statutory steps required before a supply-chain-risk designation, with the government's own filings later conceding that "the real supply chain designation came several days later." The March 3 designation is the first time a US company has been publicly designated a supply-chain risk under the statute. Legal filings later reveal the government in fact issued two separate designation letters the same day: this one under 10 U.S.C. § 3252, the narrower Department of War supply-chain statute, and a second under 41 U.S.C. § 4713, the broader Federal Acquisition Supply Chain Security Act covering the entire federal procurement system. Anthropic challenges the two designations in separate courts — the § 3252 designation before Judge Rita Lin in the Northern District of California (case No. 3:26-cv-01996-RFL), and the § 4713 designation directly before the D.C. Circuit Court of Appeals under a separate procurement-review statute (case No. 26-1049) — placing the dispute on two parallel litigation tracks.[23][24]
2026 (March 3) Analysis The Electronic Frontier Foundation argues that leaving privacy protections to depend on the decisions of individual tech CEOs is not sustainable, and that imposing binding restrictions on government surveillance is properly the role of United States Congress and the courts, not private companies. The piece notes Congress has repeatedly failed to close loopholes allowing government purchase of Americans' personal data, citing examples from U.S. Customs and Border Protection and U.S. Immigration and Customs Enforcement, and quotes Anthropic CEO Dario Amodei arguing that legal protections around domestic mass surveillance have not kept pace with current data-broker practices.[25]
2026 (March 5) Negotiation Dario Amodei resumes negotiations with the U.S. Department of Defense regarding terms governing military access to the company’s AI models. By reopening dialogue, both sides signal a willingness to explore a compromise governing military access to Anthropic’s technology. The negotiations focus on defining acceptable uses of advanced AI systems while addressing concerns about national security, operational needs, and safety safeguards in defense applications.[26]
2026 (March 5) Analysis In a Council on Foreign Relations analysis, Kat Duffy argues the Anthropic-Pentagon standoff represents a test of U.S. credibility, contending the Pentagon has not clarified what legal authority it invoked to designate Anthropic a supply-chain risk — likely either Title 10 Section 3252 or the Federal Acquisition Supply Chain Security Act, both designed for foreign-adversary threats and neither obviously authorizing Hegseth's demand that third parties cease all commercial activity with Anthropic. Duffy notes the irony that no Chinese AI firm has received the designation even as Chinese labs — including Alibaba's Qwen, Zhipu AI's GLM-5, and others — rapidly close the capability gap with U.S. models. She criticizes Congress and the broader defense industrial base, including Boeing, Lockheed, Palantir, Amazon, and Google, for staying largely silent, and warns that OpenAI's own deal offers no stronger enforcement guarantee against government overreach than Anthropic's had.[27]
2026 (March 5) Designation The Department of Defense officially notifies Anthropic's leadership that the company has been designated a supply-chain risk, effective immediately — the formal notification required to make the designation binding, six days after Hegseth's February 27 social media post, which a senior department official confirms "wasn't enough to serve as an official designation" on its own. Anthropic becomes the first American company ever publicly named a supply-chain risk, a label traditionally reserved for firms tied to foreign adversaries. The notification comes even as the DOD continues using Claude to support U.S. military operations in Iran. In an interview published the same day, President Trump tells Politico he "fired" Anthropic "like dogs."[28]
2026 (March 7) Policy proposal The administration of Donald Trump drafts new federal guidelines regulating civilian artificial intelligence procurement amid an ongoing dispute with Anthropic. Prepared by the U.S. General Services Administration, the proposed rules would require companies seeking federal civilian contracts to permit “any legal use” of their AI systems and grant the U.S. government an irrevocable license to deploy them for lawful purposes. The initiative forms part of broader efforts to standardize federal procurement of AI technologies.[29]
2026 (March 9) Legal action Anthropic files two lawsuits against the executive branch of the United States and multiple federal agencies — one in federal court in California (case No. 3:26-cv-01996-RFL, challenging the § 3252 designation, the Presidential Directive, and the Hegseth Directive) and one directly before the DC Circuit Court of Appeals (case No. 26-1049, challenging the separate § 4713 FASCSA designation) — after the United States Department of Defense designated the company a "supply chain risk." Anthropic alleges the government's action is unlawful retaliation that violates constitutional free-speech protections and due-process rights, arguing the designation — typically reserved for firms with ties to foreign adversaries — was used as ideological punishment for its public stance on AI safety. The company states in its filing that it "does not have confidence... that Claude would function reliably or safely if used to support lethal autonomous warfare," and seeks judicial invalidation of the designation rather than monetary damages.[30][31][24]
2026 (March 10) Legal action During a status conference, Anthropic attorney Michael Mongan tells the court the Defense Department is causing "real and irreparable harm" to the company, alleging the government has been directly pressuring Anthropic's customers — including university systems and business-to-business companies — to switch to competing AI providers. In a declaration filed the same day, Anthropic CFO Krishna Rao states the DoD has contacted several "portfolio companies about their use of Claude," leaving clients "worried and uncertain," and that the government's action could cost the company "multiple billions of dollars" in 2026 revenue. Microsoft tells Business Insider its own lawyers concluded it can still use Anthropic for non-military-related work, disputing the government's characterization of the designation's scope.[32]
2026 (March 12) Industry support Microsoft files an amicus brief in the San Francisco federal court in support of Anthropic's legal challenge, arguing a temporary restraining order is necessary to prevent serious disruption to suppliers whose products depend on Anthropic's technology; Google, Amazon, Apple, and OpenAI also sign on to the brief. Microsoft states publicly that "everyone wants to ensure AI is not used for mass domestic surveillance or to start a war without human control" while stressing the Pentagon needs reliable access to the country's best technology. The Pentagon's chief technology officer, Emil Michael, tells CNBC the same day that "there's no chance" the agency renegotiates with Anthropic following the designation.[31]
2026 (March 17) Legal response The U.S. government labels Anthropic an “unacceptable” national security risk, arguing that its AI systems could be manipulated or altered in wartime, thereby undermining trust. The government denies Anthropic’s lawsuit, which alleges ideological retaliation and violations of First Amendment rights, and maintains that it is exercising standard vendor selection discretion. The designation is expected to cost Anthropic billions of dollars and affect its customer base. Courts review the dispute at the time, with industry and civil liberties groups supporting the company.[33]
2026 (March 24) Court hearing A preliminary-injunction hearing opens in San Francisco before U.S. District Judge Rita Lin, with Anthropic seeking to halt the Pentagon's ban as unlawful retaliation violating its First Amendment and due-process rights. The White House's filing argues the dispute stems from national-security concerns about Anthropic's "potential future conduct," not retaliation for its public advocacy. Senator Elizabeth Warren and the American Civil Liberties Union publicly back Anthropic's position ahead of the hearing, while legal experts say Anthropic is likely to prevail given the procedural weaknesses in Hegseth's February 27 post.[23]
2026 (March 26) Court ruling A U.S. federal judge blocks an attempt by the administration of Donald Trump to designate Anthropic as a national-security "supply chain risk" and prohibit federal contractors from using its technology. The ruling, issued by U.S. District Judge Rita Lin, halts a presidential directive requiring federal agencies to stop using Anthropic's Claude AI model. Anthropic had argued the designation violated both the Administrative Procedure Act and the First Amendment, characterizing it as retaliation for the company's public advocacy on the ethical use of its technology. Judge Lin agrees, finding the government's actions "appear designed to punish Anthropic" and that penalizing the company for bringing public scrutiny to the government's contracting position constitutes "classic illegal First Amendment retaliation." She also finds that the government had presented no evidence supporting the "supply chain risk" claim and had bypassed the legally required procedures for making that determination. Lin orders the government to desist from applying both the presidential directive and the supply-chain-risk designation, and requires it to submit a report by April 6 detailing its compliance. The case may proceed to the Ninth Circuit Court of Appeals.[34][35]
2026 (April 2) Court ruling The seven-day administrative stay on Judge Rita Lin's March 26 preliminary injunction expires, and the injunction takes full effect — barring enforcement of the Presidential Directive, the Hegseth Directive, and the § 3252 supply-chain-risk designation while the government's appeal proceeds at the Ninth Circuit. Agencies that had begun dropping Anthropic under the Presidential Directive, including the Treasury Department, the Federal Housing Finance Agency, the Department of State, United States Department of Health and Human Services, and Lawrence Livermore National Laboratory, are free to continue using Anthropic unless they independently choose otherwise. The injunction does not require any agency to use Claude — it bars the government from punishing Anthropic for its public advocacy. A separate, parallel designation under 41 U.S.C. § 4713 (FASCSA), which routes through the D.C. Circuit rather than Judge Lin's court, remains unaffected and continues to bar Anthropic from Department of War contracts specifically.[36]
2026 (April 8) Court ruling A three-judge panel of the D.C. Circuit Court of Appeals — Judges Henderson, Katsas, and Rao — denies Anthropic's motion to stay a separate supply-chain-risk designation issued the same day as Judge Lin's underlying designation, this one invoking 41 U.S.C. § 4713 (the Federal Acquisition Supply Chain Security Act), which Anthropic had challenged directly at the D.C. Circuit under 41 U.S.C. § 1327 rather than before Judge Lin. The panel explicitly declines to reach the merits, stating Anthropic "has not shown that the balance of equities cuts in its favor" under the stringent four-factor stay test from Nken v. Holder. It acknowledges Anthropic faces "some degree of irreparable harm," crediting evidence of federal contract terminations, enterprise-customer flight, and billions in projected lost revenue, but discounts Anthropic's First Amendment framing, noting the company had not shown its speech was actually chilled and citing, in a footnote, CEO Dario Amodei's own comment that Anthropic was "#2 in the App Store now!" On the government's side, the panel credits a January 9, 2026 Hegseth memorandum stating the Department "must also utilize models free from usage policy constraints" and invokes national-security deference under Trump v. Hawaii, concluding a stay would "force the United States military to prolong its dealings with an unwanted vendor of critical AI services in the middle of a significant ongoing military conflict." The panel calls Anthropic's petition novel, with "no judicial precedent shedding much light," grants expedited briefing, and orders the parties to address three questions: whether the court has jurisdiction under § 1327; whether the government took a "covered procurement action" against Anthropic; and whether Anthropic can affect its AI models' functioning after delivery to the Department — the same technical question Judge Lin had treated as dispositive in her March 26 ruling, when she found Anthropic "has no ability to access, alter, or shut down the deployed model" inside government systems.[37]
2026 (April 21) Negotiation President Donald Trump tells CNBC that a deal allowing the Department of Defense to use Anthropic's AI models is "possible," saying the company is "shaping up" after "very good talks" during a White House meeting the previous week. The comments follow Anthropic CEO Dario Amodei's meeting with senior administration officials — including White House chief of staff Susie Wiles and Treasury Secretary Scott Bessent — to discuss the company's newly released Mythos model, described by a White House spokesperson as "productive and constructive." Tensions had begun easing after Amodei joined a call with Bessent and Vice President JD Vance in early April on AI cyber readiness.[38]
2026 (April 22) Industry support A group of former senior U.S. national security officials files an amicus brief with the D.C. Circuit supporting Anthropic's petition, arguing the government has inverted the purpose of the supply-chain-risk statutes it invoked. "As a private company, Anthropic has the right to configure its products as it sees fit for lawful uses, just as the Department of Defense has the right to refuse to contract with Anthropic should it prefer a different product," the brief states. "But the Administration's invocations of the supply chain risk statutes to punish Anthropic turn those vital national security authorities on their heads, for it is the Administration—not Anthropic—that has sought to 'introduce unwanted function' to Anthropic's AI system."[39]
2026 (April 27) Industry support More than 600 Google employees, many from Google DeepMind, sign a letter to CEO Sundar Pichai demanding Google reject any classified Pentagon workloads for its AI models, organized after a report by The Information that Google and the Pentagon were discussing deploying Gemini (language model) in classified settings. More than 20 principals, directors, and vice presidents sign openly. "The only way to guarantee that Google does not become associated with such harms is to reject any classified workloads," the letter states. "Otherwise, such uses may occur without our knowledge or the power to stop them." The letter cites Anthropic's ongoing legal battle with the Pentagon over its "supply chain risk" designation as context, noting industry-wide support for Anthropic's position including from Google's own employees. "Classified workloads are by definition opaque," an organizing employee says, warning there would be no way to ensure the tools "wouldn't be leveraged to cause terrible harms or erode civil liberties away from public scrutiny." Organizers draw an explicit parallel to Google's 2018 employee revolt over Project Maven, which led the company to withdraw from that Pentagon drone-analysis program.[40][41]
2026 (May 1) Competition The Pentagon announces formal agreements with eight companies — SpaceX, OpenAI, Google, Nvidia, Reflection AI, Microsoft, Amazon Web Services, and Oracle Corporation — to deploy frontier AI on its classified IL6 and IL7 network environments for "lawful operational use," following the collapse of its Anthropic partnership. Anthropic is excluded; Pentagon CTO Emil Michael says the department realized "it's irresponsible to be reliant on any one partner" after Anthropic "didn't really want to work with us in the way we wanted to work with them," and that it sought a diverse supplier base spanning open-source and proprietary model providers. The move follows the December 2025 launch of the unclassified GenAI.mil platform, which had grown to 1.3 million Department users within five months; Anthropic's models, integrated via Palantir, had been the only ones from the original GenAI.mil partners also deployed on classified networks. Center for Security and Emerging Technology analyst Lauren Kahn calls the expansion "long overdue" and "inevitable," noting Anthropic had been first to pave the way on classified systems. Defense officials tell the New York Times that signing with Anthropic's rivals could bring the company back to the negotiating table, though its newly released cybersecurity-focused Mythos model — which has unsettled government officials and bankers with its ability to find vulnerabilities in well-tested software — has complicated efforts by Trump and Hegseth to keep the company blacklisted.[42][43]
2026 (May 20) Congressional action During a United States Senate Committee on Armed Services Emerging Threats and Capabilities Subcommittee hearing, Senator Mark Kelly presses Under Secretary of Defense for Research and Engineering Emil Michael on the contradiction between designating Anthropic a national-security supply-chain risk under Title 10 Section 3252 — a statute defining such risk as the potential to "sabotage, maliciously introduce unwanted function, or otherwise subvert" national security systems — while U.S. troops continued using Claude in combat operations against Iran since February 28. Michael responds that the Department froze all code updates and access upon the designation to eliminate any risk of a "mid-battle change," but acknowledges the software itself remained in active use. Kelly argues that if the product is safe enough to remain in troops' hands during an active conflict, the "sabotage and subversion" framing used against Anthropic is difficult to justify, and warns the episode sends a "chilling message" that "anybody who questions this administration" gets similarly "branded." Michael states that Anthropic's public questioning of how its software was used in the raid to capture Nicolás Maduro contributed to the Pentagon's view that the company was "not a reliable partner," and that every other major AI provider — Microsoft, OpenAI, Nvidia, and Google — agreed to the Pentagon's "all lawful use" terms where Anthropic did not.[44]
2026 (July 30) Court hearing During a hearing on making the March 26 injunction permanent, U.S. District Judge Rita Lin says the Trump administration's case "seems to have gotten worse" and that she does not "see additional evidence from the government really justifying what it did." Government attorneys argue the supply-chain-risk designation was driven by concern over "AI model poisoning" — the possibility Anthropic could secretly alter its models post-deployment or implant a hidden control mechanism — a claim Anthropic disputes and which Lin says she has seen no basis to suspect. Lin calls the administration's position that it can broadly label any company that criticizes it a "subversive" or "enemy of the state" a "troubling" one. Justice Department lawyers disclose that the Defense Department is winding down its use of Anthropic's products, expecting to complete the process by the end of September — a timeline Lin notes seems inconsistent with the government's claim that Anthropic poses a model-poisoning threat serious enough to justify the designation. Anthropic's two lawsuits, filed in March in federal court in California and in the D.C. Circuit Court of Appeals, both remain ongoing.[45][46]

Meta information on the timeline

How the timeline was built

The initial version of the timeline was written by Sebastian.

Check Detail construction for full timeline in timelines, Inclusion criteria for full timeline in timelines, and Representativeness of events in timelines.

Funding information for this timeline is available.

Feedback and comments

Feedback for the timeline can be provided at the following places:

  • FIXME

What the timeline is still missing

  • The outcome of the government's requested stay at the Ninth Circuit, and the eventual merits rulings from both the Ninth Circuit and D.C. Circuit appeals (D.C. Circuit oral argument was set for May 19, 2026; government's response brief due May 6)

Timeline update strategy

See also

References

  1. Edwards, Benj (6 June 2025). "Anthropic releases custom AI chatbot for classified spy work". Ars Technica. Retrieved 4 March 2026.
  2. Brodkin, Jon (15 July 2025). "Grok's "MechaHitler" meltdown didn't stop xAI from winning $200M military deal". Ars Technica. Retrieved 4 March 2026.
  3. Albergotti, Reed (16 January 2026). "Defense Secretary Pete Hegseth jabs Anthropic over safety policies". Semafor. Retrieved 2 August 2026.
  4. 4.0 4.1 Metz, Cade (7 March 2026). "A Guide to the Pentagon's Dance With Anthropic and OpenAI". The New York Times. Retrieved 2 August 2026.
  5. Lawler, Dave; Curi, Maria (23 February 2026). "Musk's xAI and Pentagon reach deal to use Grok in classified systems". Axios. Retrieved 2 August 2026.
  6. "Statement from Dario Amodei on our discussions with the Department of War". anthropic.com. 26 February 2026. Retrieved 4 March 2026.
  7. Bordelon, Brendan (27 February 2026). "Trump orders all federal agencies to cease using Anthropic". Politico. Retrieved 2 August 2026.
  8. Hadas Gold (27 February 2026). "Trump administration orders military contractors and federal agencies to cease business with Anthropic". CNN. Retrieved 4 March 2026.
  9. Sam Altman (27 February 2026). "Post by Sam Altman on agreement with the Department of War to deploy OpenAI models on classified networks". X (formerly Twitter). Retrieved 4 March 2026.
  10. 10.0 10.1 "Our agreement with the Department of War". OpenAI. 28 February 2026. Retrieved 2 August 2026.
  11. Hegseth, Pete (27 February 2026). "Statement on Anthropic and Department of War policy". X (formerly Twitter). Retrieved 4 March 2026.
  12. Walsh, Joe (27 February 2026). "Hegseth declares Anthropic a supply chain risk, restricting military contractors from doing business with AI giant". CBS News. Retrieved 2 August 2026.
  13. Bordelon, Brendan (27 February 2026). "Senators urge ceasefire in Pentagon's fight with Anthropic". Politico. Retrieved 2 August 2026.
  14. "Read the full transcript of our interview with Anthropic CEO Dario Amodei". CBS News. 28 February 2026. Retrieved 4 March 2026.
  15. Brown, Hayes (28 February 2026). "Anthropic was right not to trust Pete Hegseth". MSNBC (MS Now). Retrieved 4 March 2026.
  16. Hendrix, Justin (28 February 2026). "How to Think About the Anthropic-Pentagon Dispute". Tech Policy Press. Retrieved 4 March 2026.
  17. Loizos, Connie (28 February 2026). "The trap Anthropic built for itself". TechCrunch. Retrieved 4 March 2026.
  18. "Anthropic Refuses Pentagon's AI Demands, Gets Blacklisted — Then Claude Becomes the World's Most Downloaded AI App". Elephas. Retrieved 20 March 2026.
  19. V, Vismaya (2 March 2026). "Anthropic's AI Used in Iran Strikes After Trump Moved to Cut Ties: WSJ". Decrypt. Retrieved 4 March 2026.
  20. Steinschaden, Jakob (2 March 2026). "Users Cancel ChatGPT Over Pentagon Deal as Claude of Anthropic Tops App Store Charts". Trending Topics. Retrieved 4 March 2026.
  21. ten Houten, Merien (2 March 2026). "Anthropic is a better fit for Europe than for the US". IO+. Retrieved 4 March 2026.
  22. "About". Stratechery. Retrieved 4 March 2026.
  23. 23.0 23.1 Hirschfeld, Andy (24 March 2026). "Anthropic challenges US Pentagon's ban in San Francisco court showdown". Al Jazeera. Retrieved 2 August 2026.
  24. 24.0 24.1 Lee, Andrew R.; Ramsden, Michelle; Loring, Jason M.; Ryan, Graham H. (27 April 2026). "Two Courts, Two Postures: What the DC Circuit's Stay Denial Means for the Anthropic-Pentagon Dispute". Jones Walker LLP, AI Law and Policy Navigator. Retrieved 2 August 2026.
  25. Guariglia, Matthew (3 March 2026). "The Anthropic-DOD Conflict: Privacy Protections Shouldn't Depend On the Decisions of a Few Powerful People". Electronic Frontier Foundation. Retrieved 2 August 2026.
  26. Ghaffary, Shirin (5 March 2026). "Anthropic's Amodei Reopens AI Discussions with Pentagon, FT Says". Bloomberg. Retrieved 6 March 2026.
  27. Duffy, Kat (5 March 2026). "Anthropic's Standoff With the Pentagon Is a Test of U.S. Credibility". Council on Foreign Relations. Retrieved 2 August 2026.
  28. Capoot, Ashley (5 March 2026). "Anthropic officially told by DOD that it's a supply chain risk even as Claude used in Iran". CNBC. Retrieved 2 August 2026.
  29. "Amidst the standoff with Anthropic, the United States is drafting strict new guidelines for civilian AI". MEXC News. PANews. 7 March 2026. Retrieved 28 March 2026.
  30. Hays, Kali (9 March 2026). "Anthropic sues US government for calling it a risk". BBC News. Retrieved 12 March 2026.
  31. 31.0 31.1 Gedeon, Joseph (12 March 2026). "Microsoft backs AI firm Anthropic in legal battle against Pentagon". The Guardian. Retrieved 2 August 2026.
  32. Lee, Lloyd (10 March 2026). "Anthropic lawyer says the government is 'pressuring' companies to ditch the AI startup in favor of competitors". Business Insider. Retrieved 2 August 2026.
  33. Frenkel, Sheera (March 17, 2026). "U.S. Says Anthropic Is an 'Unacceptable' National Security Risk". The New York Times. Retrieved 20 March 2026.
  34. Cho, Ellie (28 March 2026). "US District Judge blocks government ban on Anthropic AI". JURIST. Retrieved 28 March 2026.
  35. Somerville, Heather (26 March 2026). "Anthropic Wins Injunction in Court Battle With Trump Administration". The Wall Street Journal. Retrieved 2 August 2026.
  36. Lee, Andrew R.; Ramsden, Michelle; Loring, Jason M.; Ryan, Graham H. (27 April 2026). "Two Courts, Two Postures: What the DC Circuit's Stay Denial Means for the Anthropic-Pentagon Dispute". Jones Walker LLP, AI Law and Policy Navigator. Retrieved 2 August 2026.
  37. Lee, Andrew R.; Ramsden, Michelle; Loring, Jason M.; Ryan, Graham H. (27 April 2026). "Two Courts, Two Postures: What the DC Circuit's Stay Denial Means for the Anthropic-Pentagon Dispute". Jones Walker LLP, AI Law and Policy Navigator. Retrieved 2 August 2026.
  38. Capoot, Ashley (21 April 2026). "Trump says Anthropic is shaping up and a deal is 'possible' for Department of Defense use". CNBC. Retrieved 2 August 2026.
  39. Lee, Andrew R.; Ramsden, Michelle; Loring, Jason M.; Ryan, Graham H. (27 April 2026). "Two Courts, Two Postures: What the DC Circuit's Stay Denial Means for the Anthropic-Pentagon Dispute". Jones Walker LLP, AI Law and Policy Navigator. Retrieved 2 August 2026.
  40. Bonifield, Stevie (27 April 2026). "Google employees ask Sundar Pichai to say no to classified military AI use". The Verge. Retrieved 2 August 2026.
  41. Farrant, Theo (28 April 2026). "Google employees urge CEO to reject 'inhumane' classified military AI use". Euronews. Retrieved 2 August 2026.
  42. "Pentagon inks deals with eight AI companies for classified military work". The Guardian. 1 May 2026. Retrieved 2 August 2026.
  43. Vincent, Brandi (1 May 2026). "DOD expands its classified AI work with 8 companies — excluding Anthropic — amid ongoing dispute". DefenseScoop. Retrieved 2 August 2026.
  44. "WATCH: In SASC Hearing, Kelly Points Out Contradiction in Pentagon's Decision to Brand Anthropic a Risk While Using Its AI for Operations". Office of Senator Mark Kelly. 20 May 2026. Retrieved 2 August 2026.
  45. Kanu, Hassan Ali (30 July 2026). "Trump admin has not justified labeling Anthropic a national security risk, judge says". Politico. Retrieved 2 August 2026.
  46. Roy, Dwaipayan (31 July 2026). "Is Anthropic a 'supply-chain risk'? US judge says otherwise". NewsBytes. Retrieved 2 August 2026.