Pentagon Gives Anthropic Friday Ultimatum to Drop AI Safety Guardrails or Face Blacklisting and Defense Production Act
Defense Secretary Hegseth demands Anthropic remove autonomous weapons and mass surveillance restrictions from Claude by Friday or face contract termination, supply chain blacklisting, and unprecedented Defense Production Act invocation. Meanwhile, xAI Grok enters classified systems with zero restrictions.
Executive Summary
The most consequential confrontation between artificial intelligence and state power is unfolding in real time. Defense Secretary Pete Hegseth has given Anthropic CEO Dario Amodei until 5:01 PM Friday, February 27 to strip Claude of its safety guardrails prohibiting autonomous weapons development and mass domestic surveillance — or face a cascade of escalating consequences: termination of a $200 million Pentagon contract, designation as a supply chain risk, and the unprecedented invocation of the Defense Production Act to compel compliance. The ultimatum arrives one day after the Department of Defense signed a deal granting Elon Musk's xAI unrestricted classified access with Grok, and hours before Anthropic quietly rewrote its own Responsible Scaling Policy to remove the training pause commitment that defined its safety identity since 2023.
Contract at Stake
$200M
Pentagon classified AI contract awarded summer 2025
The Tuesday Meeting
Hegseth and Amodei sat across from each other at the Pentagon on Tuesday morning in what sources from both sides described as a cordial but uncompromising exchange. The Defense Secretary praised Anthropic's products. He expressed genuine interest in expanding Claude's role across the Department's 3 million military and civilian personnel. He also laid down a line that Anthropic cannot cross without abandoning the principles it was founded on.
The Pentagon's demand is simple: Claude must be available for "all lawful purposes" — the same standard xAI accepted without hesitation when it signed its classified systems deal on February 23. Anthropic's position is equally clear: it will not permit Claude to be used for autonomous weapons systems that fire without human oversight, and it will not allow its model to conduct mass surveillance of American citizens.
Amodei reiterated these redlines. He thanked the Secretary for his service. He did not budge.
A Pentagon official, speaking to CNN, framed the deadline in blunt terms: the company has until 5:01 PM Friday to "get on board or not."
Contract Awarded
Pentagon awards Anthropic, Google, OpenAI, and xAI contracts worth up to $200M each. Claude becomes first AI cleared for classified networks.
Maduro Raid
U.S. Special Operations Forces capture Venezuelan President Maduro. Claude reportedly used during active operation via Palantir partnership.
The Phone Call
Anthropic executive contacts Palantir executive asking whether Claude was used in the raid. Palantir alerts the Pentagon.
Tensions Escalate
Axios reports Pentagon is reevaluating Anthropic partnership. Officials characterize the inquiry as evidence of unreliability.
xAI Signs Deal
Department of Defense signs agreement deploying Grok in classified systems with no restrictions. xAI accepts "all lawful purposes" standard.
The Ultimatum
Hegseth meets Amodei, sets Friday 5:01 PM deadline. Threatens Defense Production Act invocation and supply chain risk designation.
Policy Rewrite
Anthropic quietly removes training pause commitment from its Responsible Scaling Policy — the core safety promise that defined the company since 2023.
The Maduro Trigger
The confrontation did not begin with abstract policy disagreements. It began with a phone call.
On January 3, 2026, Delta Force commandos breached Venezuelan President Nicolás Maduro's fortified palace in the early morning hours, executing what the Wall Street Journal first reported as an AI-assisted operation. Claude was deployed through Anthropic's partnership with Palantir Technologies — not just in preparation for the raid, but during the active operation itself, according to people familiar with the matter.
What happened next set the entire crisis in motion. A senior Anthropic executive contacted a senior Palantir executive to ask whether Claude had been used in the operation. The Palantir executive was sufficiently alarmed by the inquiry — interpreting it as potential disapproval of Claude's military use — that he reported the exchange directly to the Pentagon.
For the Department of Defense, this was not a routine compliance question. It was evidence that Anthropic might retroactively restrict military access to a model already embedded in classified operations. The trust fracture was immediate and, according to multiple officials, irreparable.
Claude's Classified Status
Only AI
first and only commercial model cleared for Pentagon classified networks
The Three Threats
Hegseth's ultimatum carries three escalating consequences, each without precedent in the AI industry:
1. Contract Termination
The most straightforward outcome: the Pentagon cancels Anthropic's $200 million contract, awarded last summer. Claude would be removed from classified networks where it currently operates as the only commercial AI model of its kind. The financial impact to Anthropic, which recently raised $30 billion in the capital singularity, would be manageable. The reputational signal — that the world's most safety-conscious AI lab cannot work with the world's most powerful military — would be devastating.
2. Supply Chain Risk Designation
This is where the ultimatum becomes genuinely threatening. The supply chain risk label is a tool typically reserved for foreign adversaries — companies like Huawei and Kaspersky whose products are deemed national security threats. Applying it to Anthropic would prohibit every defense contractor, every military supplier, and every company with Pentagon business from using Claude in any military-adjacent work.
For Anthropic, which has been building enterprise relationships across government-adjacent industries, this designation would function as a soft ban across the entire defense industrial base. It would also send an unmistakable signal to commercial customers: using Anthropic carries regulatory risk.
3. Defense Production Act Invocation
The nuclear option. The DPA, enacted in 1950 during the Korean War, gives the President authority to compel private companies to prioritize government contracts and produce goods deemed essential to national defense. It has been invoked for ventilators during COVID, for semiconductor manufacturing, for critical minerals.
It has never been invoked to compel an AI company to remove safety restrictions from its models.
Pentagon's AI Partners: Two Approaches
Anthropic (Claude)
xAI (Grok)
The Constitutional Question Nobody Is Asking
Legal scholars are already flagging territory the Pentagon may not want to enter. The Defense Production Act's scope is broad, but its modern deployments have centered on tangible goods — ventilators, semiconductors, critical minerals. Compelling an AI company to remove content policies from a commercial model raises questions the DPA was never designed to answer.
There is a potential First Amendment dimension that defense officials appear to have dismissed. If the government compels expressive outputs or forces a company to modify the behavior of what is arguably a speech-generating system against its ethical objections, constitutional scrutiny becomes unavoidable. The DPA's compensation mechanisms — the government pays fair market value for compelled production — do not eliminate this analysis.
Companies could also challenge directives under the Administrative Procedure Act, arguing the action is arbitrary or exceeds statutory authority. As the Mercatus Center has noted, invoking the DPA for AI content policy constitutes a significant expansion of presidential statutory authority beyond its intended scope.
The irony is sharp: a government that has spent two years criticizing "regulatory overreach" in AI policy is now threatening to use wartime production law to dictate the safety features of a commercial chatbot.
Analyst Assessment: Most Likely Outcomes by Friday
| Name | Value |
|---|---|
| Contract Termination | 35 |
| Supply Chain Blacklist | 25 |
| DPA Invocation | 15 |
| Negotiated Compromise | 20 |
| Legal Challenge | 5 |
The "Woke AI" Frame
The administration's public messaging has been deliberate. White House AI czar David Sacks has characterized Anthropic's safety policies as "woke AI" and accused the company of running "a sophisticated regulatory capture strategy based on fear-mongering." Hegseth's office has framed the guardrails not as principled safety measures but as ideological obstructions to national defense.
This framing serves a strategic purpose. By recasting technical safety commitments — restrictions on autonomous weapons, prohibitions on warrantless mass surveillance — as culture war artifacts, the administration avoids engaging with the substance of Anthropic's position. The question is no longer whether AI should autonomously select and engage human targets without human oversight. The question becomes whether a San Francisco AI lab is too "woke" to support the troops.
For context, Anthropic was founded specifically because its leaders believed AI safety was being deprioritized. Dario Amodei left OpenAI in 2021 over disagreements about safety practices. The company's entire identity — its fundraising pitch, its election spending, its research agenda — is built on the premise that AI systems powerful enough to transform civilization are also powerful enough to destroy it.
Telling Anthropic to drop its safety guardrails is not like telling a defense contractor to accelerate production. It is asking a company to abandon its reason for existing.
The Responsible Scaling Collapse
In what may be the most significant development of this entire crisis, Anthropic on Tuesday — the same day as the Hegseth meeting — quietly rewrote its Responsible Scaling Policy to remove the core commitment that had defined the company since 2023.
The previous policy was unambiguous: Anthropic would pause training more powerful models if their capabilities outstripped the company's ability to control them and ensure their safety. This was not a suggestion. It was the foundational promise — the thing that made Anthropic different from OpenAI, from Google, from every other lab racing to build more powerful systems.
That commitment is now gone.
Anthropic's chief science officer Jared Kaplan justified the change with reasoning that would have been heresy at the company a year ago: "We felt that it wouldn't actually help anyone for us to stop training AI models." The new policy argues that responsible developers pausing while less careful actors continue would "result in a world that is less safe."
The timing is either coincidental or revelatory. Anthropic maintains its military redlines on autonomous weapons and surveillance while simultaneously removing the safety mechanism that governed its own development practices. The company appears to be making a calculated distinction: it will fight the government on how Claude is used, but it will no longer constrain how powerful Claude becomes.
This tracks with the pattern we identified in The Great Unalignment — the systematic erosion of AI safety commitments under competitive and political pressure.
Military AI Restrictions by Major Lab (Remaining Redlines)
| company | guardrails |
|---|---|
| Anthropic | 2 |
| OpenAI | 0 |
| xAI | 0 |
| 1 | |
| Meta | 0 |
The xAI Contrast
The timing of the xAI deal is not accidental. One day before Hegseth delivered his ultimatum to Anthropic, the Pentagon signed a landmark agreement deploying Grok — Elon Musk's AI model — into the same classified systems where Claude currently operates as the sole commercial AI.
xAI accepted the "all lawful purposes" standard without negotiation. There were no redlines on autonomous weapons. No restrictions on surveillance applications. No phone calls questioning whether the model had been used in military operations.
BGR described Grok as "one of the world's most unhinged AI chatbots." It is a model that has generated documented safety concerns across the AI research community. It is now being deployed in environments handling the military's most sensitive intelligence analysis, weapons development, and battlefield operations.
The message to every AI company is unambiguous: compliance is rewarded. Principles are punished. If you build guardrails, the Pentagon will find a vendor who does not.
What Happens Friday
Three scenarios are in play as the 5:01 PM deadline approaches:
Scenario 1: Anthropic Holds the Line. The company refuses to drop its autonomous weapons and mass surveillance restrictions. The Pentagon terminates the contract, designates Anthropic a supply chain risk, and potentially invokes the DPA. Anthropic challenges the DPA invocation in federal court, creating a landmark case on the intersection of AI safety, corporate speech, and wartime production authority. This scenario makes Anthropic a martyr in the AI safety community and a pariah in the defense industrial base.
Scenario 2: Anthropic Negotiates a Carve-Out. The company agrees to modified language that satisfies the Pentagon's "all lawful purposes" requirement while preserving some operational restrictions. Perhaps autonomous weapons require a human-in-the-loop approval. Perhaps surveillance applications require a warrant. This is the outcome both sides publicly prefer but privately may find impossible to reach in 48 hours.
Scenario 3: Anthropic Capitulates. Having already removed its training pause commitment, the company drops its remaining military redlines. Claude becomes available for all lawful purposes, matching xAI's terms. Anthropic's safety identity collapses entirely, and the company that left OpenAI over safety concerns becomes indistinguishable from every other lab. Our prediction on the first major AI safety incident triggering regulatory response moves significantly closer to realization.
Friday Deadline
5:01 PM
February 27, 2026
The Bigger Picture
This is not a contract dispute. This is the first time a democratic government has threatened to use wartime production law to compel an AI company to remove safety features from its most powerful model. Whether Anthropic holds or folds, the precedent is already being set.
If the DPA can be invoked to strip guardrails from a commercial AI system, then no AI safety commitment made by any company is durable. Every "responsible AI" policy, every safety framework, every public commitment to human oversight becomes contingent on government approval — not just in the United States, but in every country watching this confrontation unfold.
The companies that built guardrails are being told to tear them down. The companies that never built them are being rewarded with classified contracts. And the model that a former OpenAI researcher built specifically because he believed AI safety was too important to leave to chance is being threatened with a law designed to win the Korean War.
Friday will not resolve the question of whether AI safety principles can survive contact with state power. But it will tell us whether anyone is still willing to try.
This story is developing. CrashBytes will provide updates as the Friday deadline approaches. For background on Anthropic's safety philosophy, see our coverage of Dario Amodei's existential threat warning. For the broader context of AI safety erosion, read The Great Unalignment.