Formerly known as Wikibon

The Pentagon Just Ran My 5-Pillar Litmus Test on Anthropic. Your Vendor Is Next.

Anthropic v. Department of War through the 5 Pillars. A federal court just defined sovereignty the way I do: control, not capability. Every procurement team now inherits the precedent.

The setup

On January 3, US forces captured Nicolás Maduro. Somewhere in the stack, inside Palantir’s Maven, sat Claude. Weeks later, an Anthropic executive asked whether that use was allowed under the contract. The Pentagon says it clearly was. Anthropic calls it a misunderstanding. Nobody disputes what the question did: the Department and its prime contractor suddenly wondered whether the software would stop working in the middle of a mission [1].

That question is the whole story. Everything after it is paperwork.

Hegseth’s January AI strategy demanded models free of vendor usage-policy constraints, with “any lawful use” written into every AI contract [1]. Anthropic had already given plenty: weapons design, foreign intelligence analysis, offensive cyber. It held two lines. No lethal autonomous warfare. No mass surveillance of Americans [1].

On February 27, the President ordered agencies off Anthropic, and Hegseth announced the supply chain risk designation. OpenAI announced its classified-network deal the same evening [6]. It was the first time the US had ever put that label on an American company [7]. Two days after Anthropic’s refusal, per reporting cited in the opinion itself, Claude was reportedly supporting US strikes on Iran [1]. The supply chain risk was still in the supply chain.

On Friday, the DC Circuit upheld the designation, 2-1 [1][2].

Guillermo Flor’s viral post asks who gets named next. Wrong question. The ruling doesn’t tell you who. It tells you what. And the what is my framework.

What the court actually held

Strip out the politics and read the opinion. Four facts carry it.

  • The vendor steers through training. Anthropic’s own public sector head told the court that model training is the main lever it has over models the Department uses [1].
  • There is no kill switch. Anthropic cannot access, alter or shut down a model once it is delivered to classified systems. The Secretary conceded his decision never depended on that [1].
  • Refusing the upgrade isn’t an option. Anthropic argued the Department could test each new version and stay on the old one. The court’s answer: frontier models move too fast, and the Department cannot run AI systems “trapped in amber” [1]. Anthropic shipped three Claude Gov versions in 2025 alone.
  • Nobody can audit it. The record put the models at 5 to 10 trillion parameters and proprietary, and Anthropic conceded some legitimacy to the opacity concern [1].

Then the line every buyer on earth should tape to the monitor: the statute turns on what the vendor does, not why. The court took Anthropic’s intentions as noble and ruled them irrelevant [1].

Now the part the LinkedIn hot takes skipped. In August, Judge Rita Lin threw out the Pentagon’s parallel designation under the narrower “adversary” statute and found it was unlawful retaliation [4][5]. The DC Circuit said it had no quarrel with her finding that Anthropic acted without bad motive. It upheld the broader designation anyway [1].

So two federal courts agree the vendor did nothing wrong. One of them says that doesn’t matter. That is the most important sentence in sovereignty law this year, and it has nothing to do with Anthropic specifically. Your vendor can be principled, transparent and contractually upfront and still be your supply chain risk, because the risk is the control, not the character.

That isn’t Pentagon doctrine. That is Pillar 3.

Article content
Pete- run the 5 Pillars

Through the 5 Pillars

I’m grading the dependency, not the company. The buyer here is the Department of War.

Territorial: pass, and it didn’t matter

Claude ran on classified networks inside the Department’s own enclaves. Anthropic couldn’t touch it [1]. Air-gapped, on-soil, residency perfect. The Pentagon still lost control. Anyone selling you sovereignty as a data residency map should sit with that. The most territorially sovereign AI deployment in the Western world just failed its sovereignty review.

Operational: pass on the runtime, fail on the roadmap

The Department ran the box. Anthropic ran the release train. Altman summed up the difference in March, saying Anthropic “may have wanted more operational control than we did” [9]. Operating today’s model means little if tomorrow’s model arrives with someone else’s policy trained in, and you can’t refuse tomorrow’s model without falling behind the adversary you bought it to beat.

Technological: hard fail, and this is the decisive one

My test: can you audit, fork, self-host? Self-host, yes. Audit: the record says no. Fork: no. You cannot train a vendor’s constitution out of a closed model. You can only refuse the next one and freeze. One out of three, and a federal court just ruled that one out of three is a national security risk.

Values ship in the weights. If you didn’t train the weights, you didn’t set the values.

Legal: fail, with a twist I enjoyed

In the Dreamforce edition, I wrote that contracts lose to statutes. Usually that’s the buyer’s problem: your data processing agreement against the CLOUD Act. Here the vendor’s usage policy was the contract, and the buyer brought the statute. Contracts lose to statutes. In both directions.

Former CIA director Michael Hayden and retired service chiefs called using this tool against a domestic company a category error [12]. Maybe. But category errors become precedent when an appellate court signs them. And the designation reached past the Department: contractors had to certify Claude out of their DoW workflows [8]. If you’re a systems integrator on federal work, your model choice now carries a jurisdiction you didn’t pick.

Financial: fail, and the invoice is still arriving

The removal memo set 180 days as the outer limit [1]. Reality had other plans. Maven, the Pentagon’s flagship targeting platform with Palantir contracts potentially worth over $1 billion, had prompts and workflows built with Claude and needed parts rebuilt [10]. A contractor CEO put recertification of replacement systems for classified networks at 12 to 18 months, and some staff went back to querying data in Excel [11]. One senior official conceded developers should never have relied on a single tool [11].

That official is running my 72-hour “prohibited, not down” drill six months late.

My favorite footnote: the court doubted Anthropic suffered any reputational harm, pointing to investment offers valuing it above $900 billion [1]. Nothing says national security threat like a near-trillion-dollar valuation. The only balance sheet that took real damage belonged to the buyer.

The part nobody is saying out loud

The Pentagon didn’t become sovereign. It changed landlords.

OpenAI accepted “all lawful purposes” and kept full discretion over its own safety stack [9]. Altman also said his contract carries the same two limits Anthropic was blacklisted for insisting on [7]. Run Friday’s test against both sentences. A vendor that keeps discretion over the safety stack and ships new versions on its own clock is, by the court’s reading, manipulating the product’s design and operation. The only variable left is whether the vendor and the Secretary happen to agree this quarter.

Judge Henderson saw it in dissent. Under the majority’s reading, the replacement vendor gets the same ultimatum: permit whatever the Department deems necessary, or share Anthropic’s fate [1].

So who gets named next? Whoever says no next. The precedent doesn’t punish Anthropic’s values. It punishes having any values the buyer can’t override, and every frontier lab has those. Each one is a single disagreement away.

And remember who the buyer was. The largest budget on the planet, a small army of lawyers, and a court system that defers to it on national security. It still spent six months and counting unwinding one model. You don’t have that leverage. Your procurement team has a renewal date.

The executive TCO

The cost of this exit was never the $200 million contract. It was the rebuild, the recertification and the productivity hole, all triggered by a policy disagreement, not a technical failure.

  • Switching cost is the real price of a frontier dependency. It’s set by how deeply the model is woven into workflows, not by the contract value.
  • Pinning an old version is insurance that depreciates monthly. Amber is not a strategy.
  • The exit is owning a model you can post-train. Open weights as the baseline, your own alignment layer on top, frontier tokens on burst behind a gateway you control. When your values live in your fine-tune and your routing lives in your gateway, a vendor dispute is a config change, not a program rebuild.

That’s the crown jewels argument in one line: own the core, stay movable at the edges. The Pentagon made the model the core. Make it an edge.

Two questions for your vendor estate

If your model vendor refused a use you consider lawful tomorrow, how many days until you’re running without them?

Whose values are in the weights you run, and could you change them if you had to?

If the answers are “we’d find out” and “the vendor’s,” you are the Pentagon in February. Without the Pentagon’s lawyers.

Run your estate before someone runs it for you

Agentcy Labs runs procurement-facing Sovereignty Assessments: your vendor estate through all 5 Pillars, named risk factors, no pass/fail theater. Sovereignty is not binary. It’s control with an acceptable risk sidecar. The Pentagon’s problem wasn’t that it depended on one vendor. It’s that it found out how much during an argument. That’s the ostrich posture, and it’s the only unacceptable one.

When we build the crown jewels layer, you own it outright. Not licensed, not hosted on our terms.

References

[1] Anthropic PBC v. U.S. Department of War, No. 26-1049 (D.C. Cir. Sept. 25, 2026), majority and dissent. https://law.justia.com/cases/federal/appellate-courts/cadc/26-1049/26-1049-2026-09-25.html

[2] Bloomberg Law, “Anthropic Faces Court Setback on US Supply Chain Risk Label.” https://news.bloomberglaw.com/us-law-week/anthropic-faces-court-setback-over-us-supply-chain-risk-label

[3] The Next Web, “US appeals court upholds Pentagon’s supply chain risk label on Anthropic.” https://thenextweb.com/news/anthropic-pentagon-supply-chain-risk-appeals-court-ruling

[4] CNN, “Judge rules the Pentagon’s supply chain risk label for Anthropic unlawful,” Aug. 27, 2026. https://www.cnn.com/2026/08/27/tech/anthropic-pentagon-supply-chain-risk-unlawful-hnk

[5] Nextgov/FCW, “Judge rules Anthropic supply chain risk designation was ‘illegal and baseless.'” https://www.nextgov.com/artificial-intelligence/2026/08/judge-rules-anthropic-supply-chain-risk-designation-was-illegal-and-baseless/415698/

[6] NPR, “OpenAI announces Pentagon deal after Trump bans Anthropic,” Feb. 27, 2026. https://www.npr.org/2026/02/27/nx-s1-5729118/trump-anthropic-pentagon-openai-ai-weapons-ban

[7] Fortune, “OpenAI sweeps in to ink deal with Pentagon as Anthropic is designated a ‘supply chain risk,'” Feb. 28, 2026. https://fortune.com/2026/02/28/openai-pentagon-deal-anthropic-designated-supply-chain-risk-unprecedented-action-damage-its-growth

[8] Axios, “Hegseth to meet Anthropic CEO as Pentagon threatens banishment,” Feb. 23, 2026. https://www.axios.com/2026/02/23/hegseth-dario-pentagon-meeting-antrhopic-claude

[9] Axios, “OpenAI-Pentagon deal faces same safety concerns that plagued Anthropic talks,” Mar. 1, 2026. https://www.axios.com/2026/03/01/openai-pentagon-anthropic-safety

[10] Reuters, “Palantir faces challenge to remove Anthropic from Pentagon’s AI software,” Mar. 4, 2026. https://finance.yahoo.com/news/palantir-faces-challenge-remove-anthropic-213754143.html

[11] Reuters, “Hegseth wants Pentagon to dump Anthropic’s Claude, but military users say it’s not so easy,” Mar. 19, 2026. https://www.usnews.com/news/top-news/articles/2026-03-19/hegseth-wants-pentagon-to-dump-anthropics-claude-but-military-users-say-its-not-so-easy

[12] Fortune, “Pentagon officially defines Anthropic as supply chain risk,” Mar. 6, 2026. https://www.fortune.com/2026/03/06/pentagon-officially-defines-anthropic-as-supply-chain-risk

Article Categories

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.
"Your vote of support is important to us and it helps us keep the content FREE. One click below supports our mission to provide free, deep, and relevant content. "
John Furrier
Co-Founder of theCUBE Research's parent company, SiliconANGLE Media

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well”

Book A Briefing

Fill out the form , and our team will be in touch shortly.
Skip to content