The disagreement between the Pentagon and Anthropic was real. The government wanted access to Claude for any lawful military use. Anthropic refused two categories, mass domestic surveillance of Americans and fully autonomous weapons. Anthropic argued that current frontier models were not reliable enough for autonomous lethal use and that mass domestic surveillance crossed a boundary it would not accept. The Pentagon’s position was fundamentally different. A private technology company should not decide which lawful military operations the United States government may conduct. [1], [2], [3]
Neither position requires stupidity or bad faith to understand. The Pentagon could decide Anthropic’s restrictions were incompatible with the mission. It could end the relationship, select another supplier, impose different contractual requirements, or redesign the acquisition model so a critical capability did not depend on terms the government considered incompatible with the mission. It held the authority to say no. What it also held was the authority to designate Anthropic a supply-chain risk. Those are different powers. The problem begins when the conflict between them disappears.
On August 27, U.S. District Judge Rita F. Lin entered summary judgment in the case. She held that the challenged actions constituted unlawful First Amendment retaliation, that Anthropic had been denied the pre-deprivation process required by the Fifth Amendment, and that the supply-chain-risk designation violated the governing statutory scheme and was arbitrary and capricious. [4], [5] The constitutional dispute will attract most of the attention. There is a leadership failure nested inside it that is easier to miss. The authority responsible for escalating the conflict was also one of the parties to it.
The Label Had a Different Job
“Supply-chain risk” is not supposed to mean difficult vendor. The statutory authority invoked by the Pentagon concerns threats to the integrity of protected systems, including the risk that an adversary may sabotage, maliciously introduce unwanted functionality, or otherwise subvert a covered system. [3], [6] That is why the designation carries power.
People downstream are not expected to reconstruct the entire dispute before acting. Procurement systems restrict suppliers. Security teams alter access. Contractors reconsider dependencies. Leaders make risk decisions on the assumption that someone upstream has already established the condition represented by the designation. The label compresses evidence into action. That compression only works if the condition, evidence, and consequence remain aligned.
The Pentagon did raise a legitimate architectural concern. National-security capability should not become dangerously dependent on a supplier’s future updates, support, or contractual terms. But the court record matters. Judge Lin found no support in the administrative record for the claim that Anthropic could reach into models deployed on national-security systems and alter, disable, or control them. The unrebutted evidence said the opposite, and the record showed that the Department of War tested Anthropic’s updates before deployment. [3] That leaves a real dependency question. It does not turn dependency into sabotage.
A vendor may be unacceptable without being hostile. A contract may be untenable without the supplier being compromised. Operational dependence may be dangerous without constituting evidence that the vendor intends to subvert the system. The security mechanism has a narrower job precisely because the consequences attached to it are stronger.
When the Authority Becomes the Pattern
There is a section in Crafting Conflict I called The Mirror Break. The setup is deliberately uncomfortable. A leader has spent considerable effort correcting patterns in a team, but nothing sticks. Eventually someone points out the obvious problem. The leader is exhibiting the same behavior being corrected in everyone else. At that point the leader is no longer merely governing the pattern. The leader has entered it. [7]
The failure is not necessarily malicious. Leaders rationalize their own behavior as urgency. They convince themselves that responsibility, performance, or pressure justifies conduct they would challenge in someone else. Then they keep applying corrective machinery outward while exempting their own behavior from the test. Crafting Conflict treats that as a leadership failure because when the authority carries the pattern it is policing, repair loses credibility. [7]
The Anthropic dispute presents an institutional version of the same problem. The Pentagon was simultaneously the customer in the contracting conflict and the authority capable of imposing an extraordinarily consequential security designation. That does not eliminate its authority. It raises the burden on how that authority is exercised.
Because the government was itself a party to the disagreement, it needed greater discipline in distinguishing the condition it disliked from the condition the security mechanism was designed to identify. Was Anthropic refusing the government’s terms? Was Anthropic creating an unacceptable dependency? Was Anthropic threatening continuity of military capability? Or was Anthropic presenting evidence of the sabotage or subversion risk represented by the statutory designation? Those questions may overlap operationally. They are not interchangeable. The Mirror Break occurs when the authority stops submitting its own actions to the distinctions it imposes on everyone else.
Dissent Is Not Sabotage
Crafting Conflict contains another rule that becomes considerably less metaphorical in this case. Separate dissent from sabotage. [7] That rule exists because conflict corrupts perception remarkably quickly. Resistance begins to feel like obstruction. Obstruction begins to feel intentional. Intentional opposition begins to acquire moral weight. By the time escalation arrives, the authority may no longer be responding only to the original condition. It may also be responding to the experience of being resisted. Power makes that progression dangerous.
Anthropic did not merely disagree with a customer. It refused terms through which a powerful customer sought authority it believed it properly possessed. The Pentagon was entitled to treat that refusal as consequential. It could decide Claude was unusable. It could conclude that dependence on a supplier whose contract retained those restrictions was unacceptable. It could refuse to build military capability around terms that left those use restrictions in place. It could terminate the relationship. Each response addresses the conflict actually present.
A supply-chain-risk designation asserts something else. It tells the rest of the system that the supplier presents a security threat of a defined kind. That assertion needs its own evidence. If opposition to the preferred decision begins serving as evidence that the opposing party itself is dangerous, escalation has ceased clarifying the conflict. Authority is now using its control surface to carry the conflict forward.
This is why “the government had the right to choose another vendor” is not a defense of what happened. It is evidence that the government already possessed mechanisms that addressed the actual conflict without recoding it as a security threat. The government had the authority necessary to stop using Anthropic. It did not need a supply-chain-risk designation to do it.
The Mirror Has to Work Both Ways
There is an uncomfortable requirement buried inside any credible governance system. The control has to work against the authority too. A leader cannot demand evidence from everyone else and substitute conviction when examining their own actions. A security organization cannot insist that classifications correspond to defined conditions while allowing institutional displeasure to satisfy the evidence threshold. A government cannot make its controls trustworthy merely by being the entity authorized to invoke them.
Authority determines who may act. It does not determine whether the action is sound. That distinction becomes most important when the authority is certain that its underlying grievance is legitimate. The Pentagon did have a real concern about control. It did have legitimate reasons to resist contractual restrictions it considered incompatible with military use. It did possess obligations Anthropic does not possess. None of that resolves the Mirror Break.
The correct test is harder. If the same evidence had appeared without the contracting dispute, would it have justified the same supply-chain-risk designation? If another vendor created comparable dependency around updates and support but had never challenged the government’s preferred usage terms, would the Pentagon have treated that vendor as the same security threat? What evidence distinguishes ordinary software dependency from the specific statutory risk being asserted?
Those are mirror questions. They force the authority to remove its own conflict from the analysis and test whether the control still fires. If the designation survives, the security case becomes stronger. If it does not, the authority has discovered something more important than disobedience. It has discovered that it is inside the pattern.
Authority Still Needs Teeth
None of this requires turning Anthropic into the heroic actor in a morality play. Anthropic is a private company making consequential choices about how powerful technology may be used. Its safety judgements are not democratically enacted law. Its executives are not elected national-security officials. A government that surrendered military decision rights wholesale to a model provider would create a different and very serious governance failure.
The Pentagon needs the power to reject vendors. It needs procurement leverage. It needs the ability to impose demanding technical and security requirements. It needs the ability to move rapidly against real supply-chain threats. And it needs credible mechanisms for preventing private suppliers from becoming unaccountable chokepoints inside public power. Those authorities become more important as AI systems move deeper into military operations.
That is precisely why their boundaries matter. When resistance can be routed into the strongest available escalation mechanism, power does not become stronger. It becomes less discriminating. The same security authority that can protect the system can damage the system when the authority using it no longer recognizes itself as a participant in the conflict.
Crafting Conflict makes the leadership standard painfully simple. A system for correcting others fails if the authority refuses to apply its discipline inward. [7] The institutional version should be no different. Before escalation, name the condition. Before classification, establish the evidence. Before using coercive authority, ask whether the mechanism is protecting the system or carrying your own conflict. And when you hold both the grievance and the power to adjudicate it, require the mirror.
Authority does not become trustworthy because it can escalate. It becomes trustworthy when it can survive the mirror.
Artifacts are cheap, judgement is scarce.
Per ignem, veritas.
Sources
[1] Anthropic, “Statement on the comments from Secretary of War Pete Hegseth,” Feb. 27, 2026.
[2] D. Amodei, Anthropic, “Statement from Dario Amodei on our discussions with the Department of War,” Feb. 26, 2026.
[3] Anthropic PBC v. U.S. Department of War et al., Order Granting Motion for Preliminary Injunction, U.S. District Court for the Northern District of California, Mar. 26, 2026.
[4] Anthropic PBC v. U.S. Department of War et al., Order on Cross-Motions for Summary Judgment, U.S. District Court for the Northern District of California, Aug. 27, 2026, Dkt. 250.
[5] C. Martinez and J. Ward, Reuters, “US judge rules Pentagon blacklisting of Anthropic unlawful,” Aug. 27, 2026.
[6] 10 U.S.C. 3252(d)(4), definition of “supply chain risk.”
[7] P. LaPosta, Crafting Conflict Volume 1: Managing Saboteur Patterns in High-Performing Teams, Heron Group LLC, 2025, Field Note 7, “The Mirror Break,” and the Dissent Protocol.



