Pentagon says Anthropic tools are out, months after blacklist

As recently as last week, Anthropic's Claude was still helping Pentagon analysts sort intelligence, including for military operations against Iran, multiple people familiar with the matter told the BBC. On Monday a Defense Department official told the BBC that the Pentagon "has ceased the use of Anthropic products", months after Defense Secretary Pete Hegseth labeled the company a supply chain risk.
At a glance
- Hegseth promised in February that the Pentagon would stop using Anthropic by late August, and the BBC says it is not clear why the removal took longer than that.
- Sources say Claude was embedded in Maven Smart System, the Palantir-run platform for Pentagon intelligence, where satellite imagery and drone footage went to language models for tasks such as identifying potential targets.
- On 25 September the D.C. Circuit upheld one of the Pentagon's two designations by 2-1, which lets it keep removing Claude, but Anthropic can still seek rehearing or appeal to the Supreme Court.
If you haven't been following the story: the US government and military had used Anthropic's tools since 2024, and Anthropic was the first advanced AI company whose tools were deployed in agencies doing classified work. According to Tech Policy Press, Hegseth demanded unrestricted use of Claude "for all legal purposes" by 5:01 p.m. on 27 February. Anthropic refused, citing concerns about mass surveillance and autonomous weapons. Hegseth then designated it a "national security supply-chain risk", a label the BBC says is typically reserved for companies based in countries that threaten the US.
Claude was built into Palantir's Maven, the Pentagon's main intelligence platform
Several sources told the BBC that Claude was embedded in Maven Smart System. Maven is run by Palantir and is the Pentagon's primary platform for organizing intelligence and other data. Some US allies also use it to share intelligence with the Trump administration. Palantir was founded by Peter Thiel, a billionaire ally of President Donald Trump.
Analysts use Maven to access and organize visual data such as satellite imagery and drone footage. According to sources familiar with the technology, that data was then fed into Claude and other large language models for tasks such as identifying potential military targets. A person who saw a Palantir demonstration of Maven earlier this year said officials often used it to put together one-page briefs that went up the chain of command.
The people who spoke to the BBC described Claude as a critical tool for sorting through vast quantities of information. One said Pentagon employees kept using Claude tools, including the powerful Mythos models, "throughout the whole period of the controversy" with the company.
Hegseth set a six-month deadline on 27 February, one day before the Iran strikes
Hegseth set the six-month phase-out on 27 February, one day before the US and Israel attacked Iran, and said the Pentagon would stop using Anthropic by late August. According to Tech Policy Press, the Washington Post reported on 4 March that Claude was being used in the war against Iran, which means the military was using it in operations while the ban was being put in place.
When the phase-out was ordered, "there was concern with moving beyond Anthropic to OpenAI" and other tools, a former senior US defence official told the BBC. Meanwhile the Pentagon signed contracts with Google, xAI and OpenAI. Two people familiar with AI use in the department say some military departments have adopted OpenAI tools more widely in recent months.
The Pentagon's Monday statement was a reply to a BBC question about its use of Anthropic. The BBC asked after several people said in interviews that Claude was still in wide use. According to the BBC, the details of the department stopping all use of Anthropic's tools had not been reported before.
A 2-1 appeals ruling on 25 September lets the Pentagon keep removing Claude
Anthropic called the designation "unprecedented and unlawful" and sued the Trump administration. The Pentagon had relied on two separate designations, so the case went through two courts. A San Francisco judge ruled one of them illegal. According to Tech Policy Press, Judge Rita Lin granted a preliminary injunction on 26 March, finding that the government's retaliation likely violated the law.
The other case went against Anthropic. Tech Policy Press reports that on 8 April the D.C. Circuit refused Anthropic a stay, citing the interest in not forcing the military to "prolong its dealings with an unwanted vendor of critical AI services in the middle of a significant ongoing military conflict." On 25 September that court upheld the second designation 2-1, which lets the Pentagon keep removing Claude and bars contractors from using it on Defense work.
Meanwhile, relations with the White House appear to be warming. Trump met Amodei twice at the White House last week. Standing beside Trump, Amodei said he still had concerns about AI risks and that "if we work with the president, we can win safely". Trump called him "great" and "fantastic".
Why a model inside Maven could not be unplugged overnight
Lauren Kahn, a senior research analyst at Georgetown's Center for Security and Emerging Technology and a former US defence official, said Claude was so deeply integrated into Maven that removing it quickly would have been difficult. "The fact that it took the Pentagon until now to remove all use of Claude from across the system is indicative that these things are not just plug and play," she said.
Think of the difference between a USB stick and a chip soldered onto a motherboard. A model that sits inside the platform analysts use to view imagery and write briefs is the soldered chip. Replacing it means reworking everything built around it. "Once they become integrated it can be painful to remove them," Kahn added.
The appeals court looked at the problem from another angle. The majority held that the FASCSA definition of supply-chain risk covers a supplier's potential to "manipulate" technology to "deny" or disrupt its function, and that this turns on "what Anthropic does, not why Anthropic does it". Under that reading, Claude's trained-in refusals could qualify. According to Clarkhill, the court also accepted that AI models can be opaque and change quickly, and treated a "clean break" as a reasonable judgment.
The Pentagon's statement leaves out the details that would explain the delay. It does not say when the last Claude workload inside Maven was switched off, what replaced it, or why the August target slipped. In our view, a court endorsing a "clean break" fits poorly with a department that needed more than six months to make one. This reads as evidence that the cost of switching models depends on how deeply each one is built into the systems around it.
What rehearing could still change
The D.C. Circuit's 25 September decision did not take effect immediately, so Anthropic has time to seek rehearing or en banc review by the full court. The company could also go to the Supreme Court. No date for any of these filings has been reported. Until one is filed, the ban on contractors using Claude for Defense work rests on that 2-1 ruling. It is unknown whether a later decision could bring Claude back into Maven.
Related stories
- Claude's refusals made it a supply chain risk, court rules
- Two federal officials, two verdicts on Anthropic
- Anthropic wants Claude users' voice chats for training
- FTC probe of Anthropic and OpenAI follows Hugging Face hack
- Trump adviser's memo puts Dario Amodei at the root of EA
- Altman and Amodei both brief the UN Security Council on AI
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
