Policy & Regulation
Anthropic pushes back on Pentagon national security claims
Anthropic submitted sworn declarations challenging its "unacceptable risk to national security" designation, arguing the Pentagon’s case relies on technical misunderstandings and contradicts previous internal communications.
Anthropic has submitted two sworn declarations to a California federal court, formally challenging the Pentagon’s “supply-chain risk designation”—a formal government classification indicating a security risk. In the filings, submitted late Friday afternoon, the artificial intelligence company argues that the U.S. government’s case relies on technical misunderstandings and claims that were never raised during negotiations. The legal dispute, which is heading to a hearing on Tuesday, March 24 before Judge Rita Lin in San Francisco, follows a public announcement by President Donald Trump that the relationship with Anthropic had ended. Anthropic’s lawsuit asserts that the designation is government retaliation for the company’s views on AI safety.
The filings include a declaration from Sarah Heck, Anthropic’s Head of Policy. Heck states that the Pentagon told Anthropic the two sides were nearly aligned on the very issues now cited as evidence of a “national security threat.” Specifically, on March 4, Pentagon Under Secretary Emil Michael emailed Anthropic CEO Dario Amodei suggesting alignment. Although Amodei published a statement on March 5, Michael subsequently posted on X that “there is no active Department of War negotiation with Anthropic.” Michael later told CNBC there was “no chance” of renewed talks. Heck also rejected the government’s claim that Anthropic sought an operational veto over military decisions, stating: “At no time during Anthropic’s negotiations with the Department did I or any other Anthropic employee state that the company wanted that kind of role.”
A second declaration from Thiyagu Ramasamy, Anthropic’s Head of Public Sector, addresses the government’s claim that Anthropic could theoretically interfere with military operations by disabling its technology. Ramasamy explains that the company’s $200 million contract with the Pentagon involves “air-gapped” systems—which are physically isolated from unsecured networks. Because these systems are air-gapped, Anthropic has no remote access, making any unilateral disruption technically impossible. Ramasamy also pushed back on concerns regarding the company’s hiring of foreign nationals, noting that Anthropic employees have undergone U.S. government security clearance vetting.
The Department of Defense defended its actions in a 40-page filing. The government maintains that Anthropic’s refusal to allow all lawful military uses of its technology was a business decision, not protected speech. According to the government’s filing, the supply-chain risk designation was a straightforward national security decision rather than retaliation for the company’s public safety positions.
Why it matters
The lawsuit challenges the first-ever supply-chain risk designation applied to an American company, with Anthropic arguing the move is retaliation for its AI safety stance rather than a legitimate security concern.