In July 2025, the Pentagon’s Chief Digital and Artificial Intelligence Office awarded multi-vendor prototype agreements that included Anthropic, OpenAI, Google, and xAI for AI services on defense networks.
Anthropic’s agreement carried restrictions it had negotiated: no mass surveillance of people in the United States, no fully autonomous weapons systems. In January 2026, the Department of Defense ordered Anthropic to remove those restrictions and provide unrestricted use. Anthropic refused.
On February 27, President Trump ordered federal agencies to cease use of Anthropic’s technology, with a six-month phase-out. Defense Secretary Hegseth designated Anthropic a “supply-chain risk to national security” — language historically used for foreign adversary technology.
Shortly after, OpenAI announced a contract to deploy models on classified DoD networks — networks where Anthropic’s models had held significant ground.
Contract language
OpenAI’s published contract stated three restrictions: no mass domestic surveillance, no autonomous weapons direction, no high-stakes automated decisions such as social credit systems. It also accepted the DoD’s “all lawful purposes” standard — the standard Anthropic had rejected.
As Lawfare noted, the fight is about interpretive authority. Under “all lawful purposes,” the customer defines what is lawful. Under Anthropic’s approach, the vendor kept veto power over specific use categories.
A leaked staff memo from Anthropic’s CEO named the concrete gap: the Pentagon asked to delete “a specific phrase about ‘analysis of bulk acquired data’” — the line that addressed the surveillance scenario Anthropic treated as most important.
Policy durability
Vendor policy is not durable governance. Acceptable-use text can change under procurement pressure, executive order, or commercial incentive. Anthropic held its position and received a supply-chain risk designation. OpenAI revised contract terms after public backlash — including language about commercially acquired personal or identifiable information that was not in the original deal. Both positions moved under pressure within weeks.
Contract negotiation has become governance. The Center for American Progress observed that military AI rules are being set in bilateral procurement deals without statutory backing or institutional durability. The forum is the procurement office, not legislation.
Markets moved faster than formal process. Employees signed open letters; users reacted; OpenAI revised language. Outcomes tracked public pressure as much as any durable rulebook.
For sensitive deployments
Evaluate architecture, not the policy snapshot. What data paths exist, what telemetry is collected, what the system can and cannot do by design — those properties matter more than language that can change. That is the same argument as architecture defining the surveillance boundary.
Supply-chain risk designations are operational events. Contractors using Anthropic products faced a six-month compliance clock to remove them. Workflows built around a single vendor become forced migrations under time pressure.
Single-vendor permanence and free interchangeability are both wrong. Anthropic out, OpenAI in, on classified networks, in a news cycle. Switching is not free. Lock-in is not free either.
Until Congress acts, the default remains bilateral negotiation between vendors and agencies — revisable under pressure. Teams that need long-term control should treat that as a structural fact, not a temporary anomaly.