When people build a product, do they retain any moral responsibility for how it is used?
Anthropic answered yes. It provided Claude for military and national-security work while refusing two uses: fully autonomous weapons and mass domestic surveillance. The Pentagon demanded an “all lawful uses” term. The conflict that followed was not simply about whether the government could use Claude. It was about whether the people who made Claude could still decide what they would not help the government do with it. The D.C. Circuit opinion documents the demand and Anthropic’s refusal.
That question became harder because Claude was already part of an operational battlefield system. It also became obscured by several distinct government actions—a government-wide ban, restrictions affecting defense contractors, a Pentagon procurement exclusion, and later export controls on foreign nationals—that are easily collapsed into one story.
They are not the same exercise of power. Separating them shows where each decision came from and who was required to live with it.
What Anthropic Actually Refused
Anthropic did not say that the U.S. government, the military, or national-security agencies could not use Claude. In its own account, the company said Claude was already used for intelligence analysis, modeling and simulation, operational planning, and cyber operations. It also said it would support a transition if the Pentagon selected another provider. Anthropic described its position as supporting national security while maintaining two narrow exceptions.
Its refusal concerned two categories of use. Anthropic would not agree to let Claude be used for fully autonomous weapons or mass domestic surveillance, even if a particular use was lawful. That is different from denying the government the product altogether. It is closer to a manufacturer saying: you may buy and use what we make, but we will not authorize these purposes.
What “Supply-Chain Risk” Meant in Practice
The phrase “supply-chain risk” can make the government’s response sound like one action. It was several.
First, President Trump directed every federal agency to “immediately cease all use” of Anthropic technology. Hegseth separately directed military contractors, suppliers, and partners to stop commercial activity with Anthropic—even activity unrelated to their defense contracts. Those were the sweeping measures that sought to isolate the company beyond the disputed Pentagon deployment. The California court’s decision describes those directives and their reach.
Second, the Pentagon used federal supply-chain law to remove Claude from its own systems and prohibit contractors from using Anthropic products while performing work for the Department. In plain terms, the designation functioned as a procurement exclusion: a contractor could not use Claude to deliver the affected Pentagon work. Defense offices began asking contractors to certify that they were removing Anthropic products from military systems and not using them to perform those contracts. The D.C. Circuit opinion defines the covered procurement action, and Federal News Network documented the resulting certification demands.
Even before the broad measures were blocked, they affected decisions outside the original contract negotiation. The California court found that defense contractors began assessing—and often terminating—their reliance on Anthropic. A contractor serving the Food and Drug Administration switched to another model, and industry groups described “contracts terminated, partnerships frozen, workflows thrown into disarray.” That is what it means to say the government threatened Anthropic’s relationships beyond the immediate dispute: other organizations began distancing themselves because association with Anthropic could jeopardize government work. Those examples appear in the court’s account of the resulting harm.
Judge Rita Lin later ruled that the broader campaign had been used to punish Anthropic for criticizing the government’s position. The court found the measures retaliatory, procedurally defective, and unlawful. The opinion said the record contained “no discussion of Anthropic’s untrustworthiness” before the contract dispute became public. The Associated Press summarized the ruling and its separation from Anthropic’s narrower D.C. case.
The September D.C. Circuit decision addressed that separate, narrower procurement action. It held that the Pentagon could treat Anthropic’s retained restrictions as a risk within the Department’s own supply chain and remove Claude from the affected systems and contracts. The court described the relevant authority as permitting procurement action when it is “necessary to protect national security by reducing supply chain risk.” The D.C. Circuit opinion explains that statutory test and the Pentagon’s determination.
The D.C. Circuit did not reinstate the government-wide ban or the broader contractor boycott. It upheld the Pentagon’s own procurement exclusion. That narrower action is what survived—not where the government started.
Legal Does Not Settle Ethical
The phrase “all lawful uses” makes the disagreement sound simpler than it is.
Legality sets a boundary on what government may do. It does not answer every question about what a person or company should help make possible.
People make those judgments whenever they design a product, write acceptable-use rules, choose customers, set permissions, or refuse a contract. Engineers, publishers, cloud providers, and equipment manufacturers may all confront uses that are legal but inconsistent with their professional obligations or moral judgment.
AI companies cannot claim responsibility when their safeguards work and then deny responsibility for deciding which safeguards should exist. Product design already distributes power. Refusal is one of the ways people exercise responsibility for that power.
That does not mean the maker’s judgment automatically overrides everyone else’s. A government customer also has responsibilities. It must decide whether a supplier’s constraints create unacceptable operational risk, especially when lives and national security are involved. Anthropic says some uses should remain off limits; the Pentagon says an outside vendor should not retain a veto over lawful military operations.
The Battlefield System Already Existed
This was not a theoretical disagreement about a future military capability. The Defense Department established Project Maven in 2017 to bring computer algorithms into combat operations. Years later, Anthropic publicly described Claude as “integrated into mission workflows on classified networks” through Palantir. Before the bombing campaign in Iran, the combined system was already operational and in daily use across much of the military. The Defense Department documented Maven’s original combat deployment, and Anthropic documented the later Claude-Palantir integration.
Maven was built to process intelligence, generate possible targets, produce coordinates, prioritize targets, and accelerate decisions that once took far longer. Palantir’s 2024 investor materials said Army leaders hoped to use Maven to make “one thousand high-quality decisions on the battlefield in one hour.” The Pentagon’s stated position was that humans retained final authority over what to strike. But the system was designed to shape the information, recommendations, and timing on which those human decisions depended. Palantir’s own description placed battlefield decision speed at the center of the system’s value.
That chronology sharpens the ethical dispute. Anthropic was not objecting before its technology entered military operations. Its product was already part of the government’s battlefield decision infrastructure. The disagreement concerned whether the people who made the model could still draw limits around particular uses after helping make that infrastructure possible.
The later strike on the elementary school in Minab makes the stakes concrete, but it should not be used to claim more than the evidence shows. The school appeared on a U.S. target list, and a preliminary investigation pointed to mistaken or outdated intelligence. Claude-powered Maven was being used in the Iran campaign, but public reporting has not established whether Maven or Claude generated, recommended, or prioritized that specific target. The Washington Post’s investigation documents both the target-list failure and the unresolved role of AI.
The supported claim is still significant: the government had operationalized AI-assisted battlefield decision-making before the strike, and Anthropic’s model was part of that system. The unresolved question is how, if at all, the system affected the decision to bomb the school.
A Government Restricting Users Is a Different Exercise of Power
The dispute became more complicated in June, three months before the D.C. Circuit ruling. The U.S. government placed export controls on Anthropic’s new Fable 5 and Mythos 5 models. The order required Anthropic to block access by foreign nationals whether they were inside or outside the United States, including Anthropic’s own foreign-national employees. Anthropic’s account explains who the order covered and how access later resumed.
Anthropic did not originate that restriction as an ethical judgment about foreign users. It complied with a government order. The controls were later lifted, allowing Fable 5 to return broadly while Mythos 5 resumed under narrower conditions.
This was not simply a ban on everyone outside the United States. Nationality, not physical location alone, was the operative distinction. A foreign national inside the United States was covered; an American citizen abroad was not necessarily covered on that basis. More importantly, the authority ran in the opposite direction.
In the Pentagon dispute, the product maker said: we will not authorize two uses of our product.
In the June export-control order, the government said: you may not provide these products to this broad class of people.
One was a company’s ethical and contractual boundary around purpose. The other was a sovereign restriction on access based on national-security authority and nationality.
Treating both as “Anthropic banned someone” erases who made the choice, whom it applied to, and what kind of power was being exercised.
Choosing a Use Is Not the Same as Choosing a User
A use restriction asks what the product may be used to do. A user restriction asks who may have access to it. The first can follow the product into a particular task. The second can exclude a person before the purpose of the use is considered.
Both restrictions can be justified badly or well. Both can produce serious consequences. But they require different evidence and different ethical arguments.
If a company refuses to support autonomous weapons, we should ask whether the boundary is clear, consistently applied, and technically enforceable. If a government blocks foreign nationals from a model, we should ask whether nationality is an appropriate proxy for risk, whether the scope is proportionate, and what happens to researchers, employees, businesses, and allied countries caught inside the rule.
Those questions should not be collapsed into a generic debate about whether restrictions are good or bad.
The People Behind the Product Are Still Making Choices
It is tempting to describe product restrictions as if the technology itself arrived with fixed limits. It did not. People chose the training, safeguards, deployment model, customers, and contract terms. Government officials chose their operational requirements, procurement response, and export controls. Judges then decided which uses of government power fit within the law.
The D.C. Circuit ruling gives the Pentagon substantial authority to reject a supplier from its own supply chain when it considers that supplier’s limits incompatible with military needs. A separate California ruling found that broader government actions against Anthropic crossed constitutional and administrative-law boundaries. Those decisions answer important legal questions, but they do not eliminate the ethical one.
The people who make consequential products have to decide what they are willing to help others do with them. Customers can reject those limits. Governments can regulate access. Courts can police the boundaries of public power.
None of that makes the maker’s original choice morally neutral.
The most important part of this dispute may be that Anthropic made its choice visible: some uses remained unacceptable to the people responsible for the product, even when the proposed customer was the U.S. government and the proposed uses were lawful.
