Anthropic, OpenAI, and the Government
A technologist and former AI doomer walks through the government–Anthropic–OpenAI standoff: what each side actually said, why the lines drawn matter, and what it signals for anyone paying attention.
By late February 2026, a standoff between the U.S. government, Anthropic, and OpenAI had spilled into public view: a disputed Department of War contract, an unprecedented "supply chain risk" designation leveled at an American company, a federal directive to cease use of Anthropic's technology, and OpenAI stepping in with a deal hours later.
The analysis here is that of a technologist and cybersecurity professional who came to AI skeptically and came around analytically, not politically. What each party said, what it signals for the industry, and why it matters for anyone taking AI seriously.
Act I
The Department of War Draws a Line
The conflict had been building for months. The Department of War stated its position in clear terms: as the end user of lawfully purchased technology, the government, not vendors, should determine how that technology is used, consistent with applicable law. Vendor terms had to allow "any lawful use" and could not impose product-level or contractual restrictions that went beyond what the law requires. The department framed this as a matter of operational flexibility and ensuring that government missions are not constrained by private companies' policies. Vendors that did not agree to those terms could not compete for the contract.
Critics argue that in practice, complying with those terms would require vendors to drop safeguards that prohibit (1) the use of AI to power fully autonomous weapons, or (2) the use of AI for mass domestic surveillance, restrictions that Anthropic and others had built into their products and contracts.
Anthropic refused. On February 27, 2026, Secretary of Defense Pete Hegseth designated Anthropic a "supply chain risk to national security." President Trump directed all federal agencies to immediately cease use of Anthropic's technology. GSA simultaneously removed Anthropic from USAi.gov and the federal Multiple Award Schedule. [GSA, Feb 27, 2026]
The Department will only contract with AI companies who accede to ‘any lawful use’ and remove safeguards. As the end user, the government, not private contractors, should decide how technology is used for all lawful purposes.
DoD stated position, as cited in Anthropic’s statement and reported by Reuters.
Pete Hegseth
Secretary of Defense · Department of War
Photo: Official DoW portrait, Chad J. McNeeley (U.S. Government, public domain). Wikimedia Commons. Position cited in Anthropic's statement and reported by Reuters.
Trump called Anthropic's stance an attempt to "strong-arm" the Department and "force them to obey their Terms of Service instead of our Constitution," adding: "We don't need it, we don't want it, and will not do business with them again."
Act II
Anthropic Holds the Line
Less than 24 hours before the deadline, Dario Amodei published a statement claiming that Anthropic was not claiming to be anti-military. They were, by their own account, the first frontier AI company to deploy models in U.S. classified networks, at the National Labs, with custom models for national security.
Their objection was narrow: two specific use cases that had never been included in their contracts, and which they believe should not be.
Regardless, these threats do not change our position: we cannot in good conscience accede to their request. Our strong preference is to continue to serve the Department and our warfighters, with our two requested safeguards in place.
Dario Amodei
CEO & Co-founder · Anthropic
Photo: Kimberly White / Getty Images for TechCrunch, TechCrunch Disrupt 2023, San Francisco (CC BY 2.0). Wikimedia Commons.
The two non-negotiable safeguards:
No fully autonomous weapons
"Frontier AI systems are simply not reliable enough to power fully autonomous weapons. We will not knowingly provide a product that puts America's warfighters and civilians at risk." Anthropic offered R&D collaboration toward that future; the Department of War declined.
No mass domestic surveillance
Lawful foreign intelligence: yes. But "using these systems for mass domestic surveillance is incompatible with democratic values. AI-driven mass surveillance presents serious, novel risks to our fundamental liberties."
Amodei also claimed an internal contradiction: the administration simultaneously labeled Anthropic a supply chain risk and invoked the Defense Production Act to compel the company because Claude is essential to national security. "One labels us a security risk; the other labels Claude as essential to national security."
Act III
OpenAI Takes the Deal
Hours after Anthropic was blacklisted, OpenAI announced an agreement with the Department of War for classified deployment. Altman later said the deal was rushed and that the optics were bad.
OpenAI's stated position: they had negotiated guardrails through cloud-only deployment (no edge devices), retained safety stack, cleared OpenAI personnel embedded with the Department, and contract language treating existing surveillance and autonomy laws as a floor. They also publicly stated they do not support Anthropic's supply chain risk designation and asked the government to offer the same terms to all AI labs. [OpenAI statement, Feb 28, 2026]
The open question is whether that agreement is substantively equivalent to Anthropic's, with the same red lines and a different enforcement mechanism, or whether it effectively gives the Department of War what it asked for ("any lawful use," no product-level safeguards) while satisfying optics with contract language and architecture. If the latter, the DoW gets the flexibility it demanded; if the former, OpenAI has drawn a real line. Only deployment and practice will tell.
We really wanted to de-escalate things, and we thought the deal on offer was good. If we are right and this leads to a de-escalation between the DoW and the industry, we will look like geniuses. If not, we will continue to be characterized as rushed and uncareful.
Sam Altman
CEO · OpenAI
Photo: Steve Jurvetson, TED 2025 (CC BY 2.0). Wikimedia Commons.
Critics have pointed out that OpenAI's contract references to Executive Order 12333 may not genuinely prohibit domestic surveillance in practice, given how that order has historically been interpreted. The core uncertainty: do OpenAI's guardrails amount to the same substantive limits Anthropic refused to remove, or do they give the Department of War the "any lawful use" flexibility it demanded, with language that looks like a constraint on paper but does not bind in the same way?
Where Each Party Stands on Anthropic's Two Safeguards
Anthropic's two non-negotiable conditions were: (1) no use of their systems for fully autonomous weapons, and (2) no use for mass domestic surveillance. Below is each party's stated position. For OpenAI, the critical uncertainty is whether their agreement is genuinely akin to Anthropic's (same red lines, different mechanism) or effectively fulfills the Department of War's ask while presenting as alignment.
| Safeguard | Department of War | Anthropic | OpenAI |
|---|---|---|---|
| No fully autonomous weapons | Required vendors to remove this restriction; contract only with those who accede to "any lawful use." | Non-negotiable. Refused to provide systems for this use case; offered R&D collaboration instead. Lost the contract. | States the same red line; says it is enforced via cloud-only deployment (no edge integration with weapons systems), contract terms, and cleared personnel in the loop. |
| No mass domestic surveillance | Required vendors to remove this restriction; contract only with those who accede to "any lawful use." | Non-negotiable. Refused to provide systems for this use case. Lost the contract. | States the same red line; says it is enforced via contract language that references existing surveillance law as a floor. Critics question whether EO 12333 etc. actually prohibit domestic surveillance in practice. |
An Analyst's Read
What This Signals
On Anthropic
It's hard to argue it's performative when it costs you the contract. A vendor that walks away from a reported $200M deal rather than remove two specific guardrails is sending a signal to every enterprise evaluating AI partners: these are the lines we won't sell.
On OpenAI
The central question is whether OpenAI's agreement is substantively the same as Anthropic's red lines, with the same limits and a different enforcement mechanism, or optics: saying the right things while giving the Department of War the "any lawful use" flexibility it demanded. The timing (a deal hours after Anthropic was blacklisted) sharpens that question. If the guardrails hold in practice, the distinction matters. If they do not, the DoW effectively got what it asked for from a different vendor.
Risk-Management Input
The same guardrails that protect users are the ones governments are beginning to pressure vendors to remove. For any enterprise evaluating AI partners for sensitive work, how a vendor responds to that pressure, at real cost, is not an academic distinction. It is a vendor risk signal.
Documented exploitation paths are worth weighing. On mass domestic surveillance: the Snowden disclosures showed bulk collection of Americans' call metadata under Section 215 of the USA PATRIOT Act, including FISC orders compelling carriers to hand over records on an ongoing, daily basis, plus programs like PRISM and the tapping of data-center links. Glenn Greenwald's reporting broke much of that story and his book No Place to Hide (2014) laid out the scope and implications of the surveillance state; the government framed the programs as lawful while critics documented the scale and the risk to civil liberties. [Guardian, Jun 2013] [Greenwald, No Place to Hide] [PCLOB, Section 215]
On autonomous weapons: the ICRC, Human Rights Watch, and others have warned that deploying lethal autonomous systems before adequate legal and technical guardrails are in place creates risks of harm to civilians, loss of meaningful human control, IHL compliance failures, and escalation. Premature deployment, before systems can reliably distinguish combatants from civilians or assess proportionality, is a documented concern. Julian Assange has long argued for transparency around lethal drone programs and executive discretion to kill in secret, warning that when an executive can kill without public decision-making, accountability collapses, a concern that extends to autonomous weapons and delegated lethal force. [ICRC, AWS & IHL] [HRW, 2024] [Assange, drones & transparency] [Risks of AWS]
Bottom Line
We are living through the early stages of something on the order of an industrial revolution. The conditions under which it gets deployed, who controls it, who constrains it, what happens when governments pressure vendors to strip out the safeguards, will determine whether its gains are broadly distributed or narrowly captured.
Anthropic's recent clash with the government didn't change that assessment. It sharpened it. OpenAI shouldn't compromise its responsibility on the cutting edge in exchange for government favor. And the people who learn to wield these tools seriously, and help others do the same, are going to be in a genuinely different position than those who don't.
Sources
This article is set as of March 2026. Linked sources and events reflect that timeline. Quotes are from the cited primary sources or from reporting that attributes them to the named officials.
- Dario Amodei, "Statement on our discussions with the Department of War," Anthropic, Feb 26, 2026
- OpenAI, "Our agreement with the Department of War," Feb 28, 2026
- TechCrunch, "OpenAI reveals more details about its agreement with the Pentagon," Mar 1, 2026
- GSA, "GSA Stands with President Trump on National Security AI Directive," Feb 27, 2026
- Reuters, "Pentagon clashes with Anthropic over military AI use," Jan 29, 2026
- Defense One, "Trump directs government to 'immediately cease' using Anthropic technology," Feb 27, 2026
- NPR, "OpenAI announces Pentagon deal after Trump bans Anthropic," Feb 27, 2026
- Documented exploitation paths & risk literature (Risk-Management Input):
- The Guardian, "NSA collecting phone records of millions of Verizon customers daily," Jun 6, 2013
- Glenn Greenwald, No Place to Hide: Edward Snowden, the NSA, and the U.S. Surveillance State (Metropolitan Books, 2014)
- PCLOB, "Report on the Telephone Records Program under Section 215 of the USA PATRIOT Act"
- ICRC, "Autonomous Weapon Systems and International Humanitarian Law: Selected Issues"
- Human Rights Watch, "Resounding Support for a 'Killer Robots' Treaty," May 2024
- Julian Assange (Real Time with Bill Maher), "WikiLeaks Founder Slams Drones, Targeted Killings," Feb 2013
- Campaign to Stop Killer Robots, "The Risks of Autonomous Weapons"
- Photos: Pete Hegseth, official DoW portrait by Chad J. McNeeley (U.S. Government, public domain) via Wikimedia Commons. Dario Amodei, photo by Kimberly White / Getty Images for TechCrunch, TechCrunch Disrupt 2023 (CC BY 2.0) via Wikimedia Commons. Sam Altman, photo by Steve Jurvetson, TED 2025 (CC BY 2.0) via Wikimedia Commons.
A note from the author
A couple of years ago, I advocated against implementing AI altogether in the corporate enterprise environment I was in. It wasn't until just the past year or so that I realized how helpful it could be when used to augment the individual, rather than the individual being fuel to augment the product. It optimized tedious processes, streamlined menial tasks, and freed up mental bandwidth to think more expansively. That shift is what finally made it possible for me to commit to entrepreneurship.
I believe AI can do monumental good when we use it to build: to create, to ship, to serve customers and solve problems that used to require far more capital or manpower. As a small business owner, AI has leveled the playing field in ways that were previously inconceivable. Many of the same tools that help me analyze risk and draft policy also help me ship a product and reach people I couldn’t have reached a few years ago. That’s why the stakes in this standoff matter to me. I want that leveling to continue, and I want it to happen in a world where the technology is wielded responsibly, not stripped of guardrails because one buyer demanded it. Building with AI is the opportunity. Doing it wisely is the condition.
The bigger picture: treat AI like any tool
A car is a vehicular weapon when operated under intoxication. A gun is inherently a weapon, and yet in the right hands it saves lives. Nuclear weapons serve no constructive force in themselves; in my opinion, their only positive role is as a deterrent.
The same logic applies to AI. The technology is not inherently good or evil: it is capable of enormous benefit and enormous harm. What we do with it, who builds it, who constrains it, and for what purpose is what matters.
This standoff is, at its core, a fight over who gets to define "responsible." Anthropic's refusal to sell certain use cases, even at a $200M cost, is one answer. The private sector rewarding that refusal would be another.
For organizations building AI-native systems that need to document controls against NIST AI RMF, and produce the authorization documentation to back it up, that work lands in SSP Development. The full scope of what FEDLIN covers is in the Capability Statement.
Working with clients on SOC 2 or NIST 800-53 remediation?
FEDLIN handles the implementation layer — controls deployed, evidence wired, artifacts ready before the audit window opens.
Subscribe to Security Insights
Get enterprise security tips, compliance guides, and best practices delivered to your inbox.