← Back to Insights

Unsealed Pentagon Emails: Why Anthropic Landed on a Blacklist Built for Foreign Adversaries

Nils Liu
Anthropic Pentagon AI政策 自主武器 AI Governance News

TL;DR

Unsealed court emails show the Pentagon negotiator declared talks with Anthropic "very close" the day after finalizing its supply-chain risk designation, before the company was even told. Who actually pays for this fight over autonomous weapons redlines?

Unsealed Pentagon Emails: Why Anthropic Landed on a Blacklist Built for Foreign Adversaries

A batch of emails unsealed this week lays out the Anthropic-Pentagon contract dispute in uncomfortable detail. The day after the Department of War finalized its “supply chain risk” designation against Anthropic, its negotiator Emil Michael emailed CEO Dario Amodei saying the two sides were “very close” to a deal, while Anthropic had no idea it had just been branded in the same category reserved for foreign adversaries. My read is that this was never really a dispute about technical trust. It was a test of whether a company would hold a redline against its biggest customer. If you work in defense procurement or government cloud compliance and have seen a different version of events, I’d genuinely like to hear it.

What the Late Email Actually Reveals

The emails surfaced as discovery evidence in a lawsuit before the U.S. District Court for the Northern District of California. The Wall Street Journal obtained them first; Gizmodo published the full exchanges. The story starts in July 2025, when the Pentagon signed a contract capped at $200 million, fully aware that Anthropic had drawn two hard lines around Claude: no use in fully autonomous weapons systems that remove a human from real-time decision-making, and no use in domestic mass surveillance.

Negotiations soured starting January 2026. Michael re-contacted Amodei after weeks of silence, in a tone suggesting he expected Anthropic to have softened its position. It hadn’t. Amodei restated the same two redlines verbatim. Michael’s reply amounted to an ultimatum: the guardrails were “just not workable,” and he added that “there is no distinction in our world between weapons that are defensive or offensive,” offering Anthropic “one more chance to align on core principles.” When talks collapsed, Defense Secretary Pete Hegseth designated Anthropic a supply chain risk, the first time in U.S. history that classification had been applied to a domestic company. Trump publicly declared the same day that federal agencies would stop working with Anthropic. OpenAI signed the same defense contract within hours; CEO Sam Altman later admitted the timing “looked opportunistic and sloppy.”

The sharpest detail in the unsealed emails is the timing itself: Michael wrote “very close” only after the blacklist decision had already been finalized, effectively letting Anthropic believe the deal was salvageable while it had already been cut loose. Anthropic sued, and federal judge Rita Lin granted a preliminary injunction in late March, calling the designation First Amendment retaliation: “Nothing in the governing statute supports the Orwellian notion that an American company may be branded a potential adversary for expressing disagreement with the government.” The injunction was stayed seven days pending appeal, and in April the D.C. Circuit denied Anthropic’s emergency motion to halt enforcement. The case is still active, and Anthropic currently cannot serve as a prime contractor or subcontractor on covered Defense Department systems.

What the Numbers Actually Say

Amodei’s public line is that frontier AI is “simply not reliable enough to power fully autonomous weapons.” That sounds like a technical judgment, but it comes with no published error rate, no red-team results, no third-party verification. It’s a policy position dressed up as an engineering conclusion. The real question worth asking is this: if Claude’s safety training genuinely made it refuse to operate inside an autonomous weapons system, that redline wouldn’t need to live in a contract clause at all, the model’s own behavior would enforce it. What actually enforces this line is a contract, full stop. Once a model is deployed inside the Defense Department’s own classified network, Anthropic has essentially no telemetry into how its outputs get used downstream. This is a policy-layer guardrail, not a technical guarantee.

Now size the actual cost. A $200 million contract cap is a rounding error against Anthropic’s roughly $965 billion private-market valuation. The real cost isn’t the contract, it’s the credibility hit from being the first domestic company ever tagged with a label built for foreign adversaries. Anthropic’s own court filings claim $180 million in collapsed deals and potential revenue losses in the billions for 2026, an order of magnitude larger than the contract that triggered the fight. The other number worth sitting with is Michael’s January 9 stock sale: an original disclosed range of $500,000 to $1 million in xAI holdings, sold for somewhere between $5 million and $25 million. An official with life-or-death leverage over Anthropic’s defense business had a position that size moving in a direct competitor at exactly the moment he was pressuring Anthropic to drop its guardrails. That’s worth scrutinizing entirely on its own, independent of how big the underlying contract was.

Metrics Worth Watching Next

First, the substantive D.C. Circuit ruling. April’s decision only rejected an emergency stay; the actual determination on whether “supply chain risk” can be weaponized against a domestic company for voicing disagreement hasn’t landed yet, and it will set precedent for every AI vendor negotiating with the federal government going forward.

Second, whether Congress opens a formal inquiry into the timing of Michael’s stock sale. An official responsible for vetting AI defense vendors liquidating a position in a direct competitor during the exact window he was pressuring that vendor is the kind of conflict-of-interest story that can do more damage than the underlying litigation.

Third, whether OpenAI’s renegotiated defense contract terms ever become public. Altman promised explicit prohibitions on domestic surveillance use; if no concrete contract language surfaces within six months, that promise was just messaging.

If this was useful, subscribe to the newsletter for weekly AI PM insights and GenAI case studies.


Related reading:

Get the latest insights

Join the newsletter to receive my latest articles on GenAI, AI Agents, and architecture.

No spam. Unsubscribe anytime.