The Pentagon Wants AI with No Limits. Your Community Should Care.
A company that makes AI told the Pentagon no. The Pentagon cancelled its contract and designated it a national security risk — the first American company to get that label. The company sued. A federal judge called the designation First Amendment retaliation. It is still unresolved.
Here's what happened and what it means for communities that already know they're on someone's list.
Updated July 28, 2026. This article was first published in February, while the dispute was still unfolding, and ended on a cliffhanger. The outcome is now in the what actually happened section at the bottom, and several details in the original timeline have been corrected against the record.
What Actually Happened
The timeline is short. The implications are not.
- July 14, 2025: The Pentagon's Chief Digital and AI Office announced prototype agreements with Anthropic, Google, OpenAI, and Elon Musk's xAI. The task: customize AI for military use.
- January 9, 2026: The department issued its AI strategy, pushing acquisition officials to secure broad cross-mission usage rights rather than narrow approved-use licenses — the "all lawful uses" posture.
- February 13-14, 2026: The Wall Street Journal and Axios reported, on anonymous sourcing, that Claude had been used in the January 3 operation to capture Venezuelan President Nicolás Maduro, routed through Palantir. Anthropic did not confirm this. It said it couldn't comment on whether Claude was used in any specific operation, and separately that any use of Claude is required to comply with its usage policies. Those are different statements, and the distinction matters.
- February 15-16: The Pentagon threatened to label Anthropic a "supply chain risk."
- February 19: Emil Michael, Under Secretary of War for Research and Engineering — the department's CTO — told DefenseScoop: "What we're not going to do is let any one company dictate a new set of policies above and beyond what Congress has passed. That is not democratic."
- February 24: Dario Amodei met Defense Secretary Pete Hegseth at the Pentagon. Reporting described an ultimatum with a Friday deadline: agree to unrestricted use for all legal purposes.
- February 27: Anthropic didn't agree. The Pentagon cancelled the contract.
One correction to how this got reported at the time, including here. The "supply chain risk" designation was described as requiring every Pentagon contractor to certify they don't use Claude. That's close to what officials publicly claimed, but the governing statute reaches only "covered systems" and "covered items of supply" — a much narrower category. That gap between the assertion and the statute later became central to the litigation.
What Are the Red Lines?
Anthropic has two stated limits it won't cross. Both matter to this conversation.
The first is mass surveillance of Americans. Anthropic's usage policy prohibits gathering information on an individual or group in order to track, target, or report on their identity. No sweeping social media for targets, no aggregating location data on populations, no automated profiling at scale. This was the one the Pentagon most wanted removed.
The second is fully autonomous weapons — human oversight required in military targeting, no autonomous selection and engagement of targets without a person in the loop.
These weren't philosophical positions. They were contractual limits, and the Pentagon set out to eliminate them. Neither has changed: as of this update, Anthropic's usage policy still carries both.
Why Is the Pentagon Pushing Back?
The department's stated argument was consistency. It wanted every contracted AI model available for "all lawful use cases" without negotiating restrictions model by model.
Emil Michael's framing is worth sitting with: he said it isn't democratic for any one company to set policy above what Congress has passed — that those limits belong to Congress and the agencies, not corporations.
That argument has a logic to it. It also sidesteps the fact that Congress has never voted to authorize AI-powered mass surveillance of Americans. "All lawful uses" lets the department define what's lawful in real time.
The Defense Production Act — the mechanism for compelling companies to produce what the government needs in an emergency — was reportedly under consideration. It was never invoked; the administration went the supply-chain-risk route instead.
That designation is economic pressure. The public framing suggested any contractor touching Claude would be affected, which would have threatened a large share of Anthropic's revenue. As noted above, the statute is narrower than the framing — but the point of the threat was to make saying no too expensive to sustain, and a threat doesn't need to be legally airtight to work.
One note on Anthropic: they took Pentagon money under the same July 2025 agreements. They are not a principled tech company standing up to power. They are a company whose self-interest — maintaining credibility with enterprise customers and regulators — currently lines up with a limit that also happens to protect communities from surveillance. Those are different things. Both can be true.
And the "lone holdout" framing this story attracted deserves puncturing. OpenAI published its own agreement with the department, and it contains explicit carve-outs on domestic surveillance of U.S. persons and on autonomous weapons requiring human control. OpenAI negotiated limits comparable to the ones Anthropic refused to drop, and kept its contract. Whatever separated the two outcomes, it wasn't that only one company had red lines.
Why This Matters to Communities Like Ours
COINTELPRO ran from 1956 to 1971. The FBI used it to surveil, infiltrate, and disrupt Black nationalist and civil rights organizations, the New Left and anti-war groups, the Communist Party USA, the Socialist Workers Party, and white hate groups. The program didn't require evidence of crimes. It required suspicion of dissent.
Being precise here matters, because the sloppy version is easy to dismiss: there was no COINTELPRO program named for gay organizations. FBI surveillance of gay Americans ran through a separate channel — the Bureau's "Sex Deviates" program and its general domestic security files — on the premise that homosexuality was itself a security threat. Gay activists were sometimes swept into COINTELPRO's New Left program when they organized inside broader radical coalitions. Different mechanism, same institution, same logic.
DHS fusion centers have monitored activist groups by aggregating social media activity and communications.
None of this is conspiracy. It's documented. Congressional investigations, FOIA requests, and court cases have established the record.
Historical surveillance programs were limited by cost and labor. Monitoring a group required people: agents, informants, analysts. That friction didn't stop it, but it constrained scale.
AI removes that friction almost entirely.
A system that can scan social media, cross-reference location data, identify social networks, and flag community members for review can do in seconds what used to take weeks. It doesn't get tired. It doesn't need warrants for data that's already been aggregated. And it can operate at a scale that makes the COINTELPRO era look targeted by comparison.
The communities Tactical Snowflakes exists to serve, LGBTQ+ people, immigrants, people of color, political minorities, are the same communities that domestic surveillance programs have targeted first. Every time. That's not coincidence. It's the pattern.
This Isn't New — It's a Pattern
The surveillance infrastructure already exists. This fight is about whether AI gets bolted onto it with zero friction.
- Facial recognition has been deployed against protesters. GAO found that six federal agencies used facial recognition on imagery from the 2020 George Floyd protests. In Baltimore, police ran protest photos through facial recognition to identify people with outstanding warrants and arrest them out of the crowd, and used the social media monitoring tool Geofeedia during the 2015 Freddie Gray protests.
- DHS fusion centers, joint federal-state intelligence operations, have monitored activists, journalists, and community organizers. A 2012 Senate investigation found their reporting was "oftentimes shoddy, rarely timely, sometimes endangering citizens' civil liberties," identified no reporting that uncovered a terrorist threat across 13 months reviewed, and documented improperly retained files on ACLU members and anti-war protesters. In July 2020, DHS intelligence produced reports on journalists covering the Portland protests.
- The FBI's social media monitoring programs scan public posts for keywords tied to domestic extremism. The definition of that category shifts with each administration.
- Private data brokers sell location data, purchase history, and social graphs to government agencies without any requirement that the agency obtain a warrant.
Anthropic's mass surveillance limit is one contractual provision at one company. It is not a structural protection. If it gets removed through pressure, regulatory action, or a future renegotiation, there is nothing else in place to fill the gap — and as the outcome below shows, the capability gets built by whoever says yes regardless.
What You Can Do With This Information
This is not a call to contact your representative. This is practical.
Physical security and digital security are the same thing. The same communities that benefit from knowing how to protect themselves physically also benefit from understanding how they can be identified, tracked, and targeted before anything physical happens.
Think about what data you generate and who can access it. Your location history. Your social graph. What apps know where you go and who you're with. That is the same situational awareness that applies to any other security question.
Community defense is about what you carry and what they know. The communities most likely to need physical self-defense are the same communities most likely to be under digital surveillance. Those two facts are connected.
What actually happened
This article originally ended on a cliffhanger — "watch what happens Friday." Here's how it went.
Anthropic didn't agree. On February 27 the Pentagon cancelled the contract, and on March 4 it formally designated Anthropic a supply chain risk to national security, the first American company to receive that label. Anthropic said it would challenge the designation as not legally sound, and pledged to keep supplying the department at nominal cost during the transition.
On March 9 Anthropic sued in two venues, the Northern District of California and the D.C. Circuit. Later that month the district judge blocked the designation and the associated order cutting federal contracts, finding the record indicated Anthropic had been targeted partly for criticizing the government through the press — which she characterized as classic First Amendment retaliation. On April 8 the D.C. Circuit declined to lift the designation on an emergency basis, explicitly without reaching the merits. In May a D.C. Circuit panel heard argument and was reported divided.
As of late July 2026 this is unresolved. No merits ruling, no settlement, no restored contract. The Defense Production Act was threatened but never invoked. Congress produced letters and a proposed amendment, and no enacted law.
Meanwhile the market moved on. OpenAI's agreement stands, with its own published surveillance and autonomous-weapons carve-outs. Google signed a classified Pentagon AI deal in April, explicitly framed as expanding access after Anthropic's refusal. xAI accepted the broadest terms.
Which is the actual lesson, and it isn't a hopeful one. A single company's contract terms were never going to be a structural protection for anybody. One vendor declined, litigated, and got partial relief in one court. The capability the Pentagon wanted is being built regardless, by companies that said yes. Nothing about that outcome depended on what happens to your data — and nothing about it protects you.
Frequently asked questions
What is the Pentagon–Anthropic dispute about?
The Department of War wanted every AI model it contracts for available for "all lawful uses." Anthropic's contract excluded two things: mass domestic surveillance of Americans and fully autonomous lethal weapons. The department pressed to remove those limits, Anthropic refused, and in February 2026 the contract was cancelled.
Was Anthropic actually designated a national security risk?
Yes. On March 4, 2026 it became the first U.S. company designated a "supply chain risk." Anthropic sued on March 9. A federal district judge blocked the designation, finding indications of First Amendment retaliation, but the D.C. Circuit declined to lift it on an emergency basis in April. The case is unresolved.
Did other AI companies refuse the same terms?
Not exactly, and the framing that Anthropic stood alone is wrong. OpenAI published an agreement containing its own carve-outs on domestic surveillance and autonomous weapons and kept its contract. Google signed a classified deal in April. xAI accepted the broadest terms.
Why does a defense contract dispute matter for surveillance of ordinary people?
Because historical surveillance programs were limited by cost and labor. Monitoring a community took agents, informants, and analysts. AI removes that friction, and the constraint on what gets built is increasingly contractual rather than technical — which means it can be renegotiated.
What can I actually do about this?
Nothing about the contract fight. What you can control is what data you generate and who can reach it: your location history, your social graph, which apps know where you go and who you're with. Our guides to Faraday bags and cell-site simulators cover the practical end.
Related Reading
Disclaimer
This article is educational information, not professional advice.
Firearms law varies by state and county, and it changes. This isn't legal advice — verify current law for your jurisdiction with a qualified source, like your state police or a firearms attorney, before you act.
First-aid content here isn't medical advice and doesn't replace hands-on training. In an emergency, call 911.
Firearms training content doesn't replace qualified in-person instruction.
Some articles are produced with AI assistance and may publish without a person reviewing every line first. They're sourced, but AI-assisted writing can still contain errors — verify anything you plan to rely on.
Found a mistake? Let us know and we'll fix it. Read the full disclaimer.