Last updated: August 4, 2026
Executive Summary
The shorthand hides the story. Anthropic was not subjected to one clean, market-wide “ban for being too safe.” At least four legal and operational tracks affected the company, each with a different target, mechanism, and procedural status.
The court did not order the Pentagon to use Claude. It preliminarily stopped three broader measures while expressly preserving the Department of War’s ability to choose another provider through lawful means.
The buyer lesson is larger than this dispute. A frontier model can be purchasable in one channel, scheduled for removal in another, restricted by a contract clause, and technically available only after accepting a different data boundary.
“Banned for being too safe” is a good headline and a bad map
The phrase collapses three propositions the public record does not establish: that there was one ban, that “safety” was its legally operative cause, and that the main restrictions all survived in the same form.
The record does show a real policy collision. The Department of War’s January policy directed “any lawful use” terms for contracts through which AI services are procured. Anthropic sought to preserve red lines around mass domestic surveillance and fully autonomous lethal use. That disagreement mattered. But a fight over contract language is not proof that the government planned either use, nor is it a final legal finding about the motive for later government actions.
Some accounts also tied Anthropic’s reward-hacking research to the procurement fight. The paper is real, but the researchers first gave an experimental model knowledge of reward-hacking strategies, then trained it in environments selected because those strategies could work. It was not a report about a customer-facing Claude model suddenly becoming malicious. More importantly, no primary source we opened connected the paper to the February or March government actions.
Sources: January 9 DoW AI Strategy memo; MacDiarmid et al., arXiv:2511.18397; Anthropic research explainer; N.D. Cal. Dkt. 134.
The same company was caught in four different control systems

February public directives
Title 10 designation
Title 41 action
June model-access event
| Track | Established | Still open |
|---|---|---|
| February / Title 10 | Preliminary injunction; California merits motions under submission. | Final merits result; Ninth Circuit status after April 27. |
| Title 41 | Not enjoined by Dkt. 135; D.C. filings continued through August 3. | June 3 decision body; later brief bodies; final disposition. |
| June models | Anthropic and AWS reported staged restoration. | Government directive and lifting instrument. |
| GSA / solicitations | Purchase listing, integration-removal alert, and a four-page solicitation sample coexist. | Reconciliation, legal basis, and prevalence. |
The February directives and Title 10 designation were challenged in the Northern District of California. The Title 41 action went directly to the D.C. Circuit under a different review mechanism. The June event concerned access to newly released models and, on the public evidence available, had a different stated trigger. Shared timing and a shared company name do not establish one legal act or one causal chain.
This separation is not lawyerly housekeeping. It changes the answer to almost every practical question. A contractor may fall outside the Title 10 designation for one use yet encounter a solicitation-level assertion elsewhere. A federal buyer may see Claude in a purchasing catalog while an integration is scheduled for removal. A commercial customer may lose access when a provider cannot enforce a government restriction at the individual-user level.
Sources: 10 U.S.C. § 3252; 41 U.S.C. § 4713; N.D. Cal. Dkt. 135; D.C. Circuit No. 26-1049 docket.
The court stopped broad measures, not the Pentagon’s vendor choice
Judge Rita Lin’s order gave Anthropic substantial preliminary relief, but “preliminary” does real work in that sentence. The court found that Anthropic was likely to succeed and enjoined the February presidential directive, Secretary Hegseth’s directive, and the March 3 Title 10 designation. It did not issue a final merits judgment.
The order also drew a boundary that simplified accounts often omit: the Department of War remained free to stop using Claude and select another AI provider. The injunction restrained specified measures; it did not turn Anthropic into a compulsory supplier.

The contractor scope was narrower than the public rhetoric, too. The opinion records the government’s concession that a contractor using a general Claude Code license to write software for a DoW system was not automatically prohibited by the Section 3252 designation. It also records that contractors would not be terminated merely for using Anthropic on non-DoW work under the challenged measures.
Title 41 remained separate. The March 3 determination invoked an urgent-national-security procedure and took immediate effect within its defined procurement universe. A March 19 letter then provided supporting materials and offered Anthropic 30 days to oppose the action. “No response opportunity at all” is therefore inaccurate; the live dispute concerns timing, adequacy, statutory fit, and the effect of a later reconsideration decision whose full text we did not obtain.
As of the August 4 evidence cutoff, the California summary-judgment motions had been argued and taken under submission. D.C. Circuit briefing activity continued through August 3, but FSR did not obtain the full July 24 and August 3 briefs, and no final merits disposition was identified in the docket snapshot reviewed. Those are limits, not blanks to fill with inference.
The government separately appealed the injunction to the Ninth Circuit. The public mirror we could open ended with an April 27 order staying that appeal and tying the next step to resolution of the D.C. Circuit matter. Because a current Ninth Circuit docket was not available, this article does not claim that the appeal was affirmed, reversed, or later resumed.
Sources: Dkt. 134, preliminary-injunction opinion; Dkt. 135, preliminary-injunction order; D.C. Circuit Appendix Vol. 3, Doc. 2169955, PDF pp. 6–7, 15, 53; N.D. California docket; Ninth Circuit No. 26-2011 public docket.
The government’s strongest argument is continuity of operational control
The government’s case is easy to caricature as “safety is bad.” Its filings make a narrower operational argument: frontier models are opaque, vendors control weights and new releases, and usage restrictions or later model changes can create mission risk. A national-security deployment therefore rests partly on continuing confidence in the vendor, its update process, and its willingness to support the agreed uses.
That is a risk argument, not proof of sabotage or an observed field failure. The filings describe possible failure modes and a collapse of trust; they do not show Anthropic inserting a malicious function or causing an operational refusal in the field.
The same administrative record contains a preliminary Exiger assessment—based largely on open sources—that rated the overall subject risk 4.3, or “medium.” That score does not resolve the government’s operational case. It does leave a visible tension between the designation’s severity and the external due-diligence result.
Anthropic’s strongest response is also more concrete than “we care about safety.” It argues that supply-chain statutes designed around adversarial sabotage are a poor fit for a disclosed contract disagreement; that risks such as opacity and vendor updates are common to frontier-model suppliers; and that the government’s rationale changed as litigation progressed. It also argues that the breadth and timing of the measures support a retaliation theory.
The contract record complicates both morality plays. The filed Anthropic–Palantir addenda permitted a wide range of intelligence, military planning, logistics, operational-support, and defense-industrial uses. They still barred final target determinations or direct tracking for kinetic action, and intelligence-collection decisions without human or machine oversight. These were Anthropic–Palantir documents—not the separate DoW–Anthropic agreement—and they show negotiated boundaries, not a simple refusal to support defense work.
At the preliminary-injunction stage, the court found Anthropic likely to succeed on its challenges to the three enjoined measures. That finding cannot be converted into a settled merits verdict.
Sources: Government respondent brief, D.C. Circuit No. 26-1049; Administrative Record Part 1, AR 217–220; Dkt. 134; D.C. Circuit Appendix Vol. 4, Doc. 2169955, App. 391–406.
Contractors cannot answer this from the headline
The statutory and contract layers do not produce a universal yes or no. Section 3252 is tied to covered procurements, covered systems, and covered items. FAR 52.204-30 operates when an applicable FASCSA order reaches the contract; its subcontract flow-down does not turn every mention of a vendor into an economy-wide prohibition.
At the same time, narrow legal language does not guarantee narrow implementation. Visible sample: four July 2026 DoW solicitation pages checked; not exhaustive. One notice contains Anthropic-removal language, while three additional pages identify contractor-assertion attachments whose bodies FSR did not extract. The first notice involved kitchen fire-suppression systems rather than an AI purchase.
That leaves an implementation conflict. A government filing reported reversal of actions taken under the enjoined measures, and the January policy addressed contracts procuring AI services, yet Anthropic language appeared in a non-AI solicitation. The authority was not identified in the opened notice text. A contractor therefore needs the actual solicitation, task order, clauses, amendments, system designation, and subcontract terms.
Sources: FAR 52.204-30; DFARS 252.239-7018; Dkt. 146 compliance report; January 9 DoW AI Strategy memo; Whiteman AFB notice; Mobile GPR notice; Aviano notice; second Aviano notice.
In Anthropic’s account, the June directive and all-user shutdown were separate acts
Anthropic says the June 12 government directive restricted access to Fable 5 and Mythos 5 by foreign nationals. The company also says it had no reliable way to verify nationality in real time. It therefore suspended both models for all customers.
Those are two actions: a government restriction described by the company, followed by the company’s compliance implementation. Because FSR did not obtain the directive itself, Anthropic’s description must remain attributed. The record we opened did not establish that the February procurement dispute caused the June action or that the June action was retaliation.
Anthropic later said the controls were lifted and access returned in stages. Even “restored” required qualification. Availability differed by model, organization, plan, credits, and cloud. On AWS, Fable 5 and Mythos 5 require a provider_data_share setting; AWS says prompts and completions are then shared with Anthropic and retained for up to 30 days. If a Fable request falls back to an Opus model, the fallback follows a different data-handling rule.
On Anthropic’s account, a restriction aimed at foreign nationals became an all-user outage because the company could not verify nationality in real time. The underlying directive remains unavailable.
The data boundary was no cleaner. Anthropic’s support page says retained Bedrock data “stays in AWS,” while AWS says prompts and completions are shared with Anthropic. The statements may be technically compatible, but neither page explains whether “stays” refers to storage location, processing, or provider access.
Sources: Anthropic, June 12 statement; Anthropic, June 30/July 1 update; AWS model update; AWS Bedrock data-retention documentation; Anthropic covered-model retention documentation.
For buyers, model availability is a stack—not a switch
Enterprise buyers should separate model quality from access reliability. For a given channel, is the model legally purchasable, contractually permitted, technically executable, and acceptable under the buyer’s data policy?
Page snapshots opened on August 4, 2026 illustrate the problem. GSA’s Buy AI page listed Claude Enterprise as available to federal agencies. A separate GSA page said Anthropic system integrations would be removed by August 27, 2026. Those statements may refer to different layers—a purchasing vehicle versus a technical integration—but GSA did not reconcile them on the pages themselves.
Verify the whole access stack
- Authority: Which order, statute, or agency policy applies?
- Contract: Which clause, modification, assertion, and flow-down is actually present?
- Channel: Direct API, enterprise app, cloud marketplace, reseller, or embedded product?
- Execution: Did the selected model answer, refuse, or fall back to another model?
- Data: Who receives, stores, reviews, and retains prompts and outputs?
- Continuity: Has the fallback path been tested rather than merely purchased?

Putting the same provider in several clouds does not create independence if every route still depends on the same policy decision or classifier. Continuity comes from tested workload portability, explicit data rules, model-level observability, and a contract that says what happens when access changes.
Sources: GSA Buy AI; GSA artificial-intelligence page; AWS Bedrock documentation.
FAQ
Was Claude banned by the U.S. government?
Several different actions affected Anthropic. February directives sought broad federal and contractor restrictions, while DoW also used separate Title 10 and Title 41 authorities. A court preliminarily enjoined the February and Title 10 measures. The Title 41 action was not enjoined by Dkt. 135. Separately, Anthropic language appeared in July solicitations under an authority FSR could not identify from the opened notice text.
Did Anthropic win in court?
Anthropic obtained a preliminary injunction against three challenged measures. The order suspended those measures while the case proceeded; it did not require DoW to use Claude. At the August 4 cutoff, the California merits motions were under submission, and FSR had not identified a final merits disposition in the D.C. Circuit snapshot reviewed.
Can defense contractors use Claude?
There is no universal answer. The preliminary opinion records concessions placing some general-license and non-DoW uses outside the challenged Title 10 designation. Yet July solicitation pages showed one removal notice and three contractor-assertion attachments whose bodies FSR did not extract. Contractors need the actual agency, system, order, clause, modification, and subcontract flow-down.
Did the Pentagon demand mass surveillance or autonomous weapons?
The documented government position was that contracts procuring AI services should permit all lawful uses. Anthropic sought exceptions involving mass domestic surveillance and fully autonomous lethal use. The record establishes a dispute over contract boundaries; it does not establish a concrete government plan to deploy Claude for either purpose.
Did Anthropic’s reward-hacking paper cause the dispute?
No opened primary source established that connection. The paper used an experimental setup designed to study reward hacking. The government’s disclosed risk analysis cited different technical material. The study belongs in a separate explanation of training risk, not as the causal opening scene of the procurement dispute.
Why did the June restriction affect every customer?
Anthropic says the government restriction applied to foreign nationals, but the company lacked reliable real-time nationality verification. It therefore suspended the affected models for all users. That is Anthropic’s official account, not the directive itself; the government instrument was not available in the source set FSR opened.
Is Claude available to federal buyers now?
In the August 4, 2026 page snapshots, GSA’s Buy AI page listed Claude Enterprise while another GSA page announced removal of Anthropic system integrations by August 27. These may concern different layers, but the pages did not reconcile them. Availability should be stated with a date, agency, contract vehicle, integration, and model.
Should a commercial buyer leave Anthropic?
The evidence does not support a universal switch recommendation. Buyers should instead identify which workloads would fail under a policy, contract, model, or data-boundary change; test an alternative on those workloads; and define migration triggers. Staying without a tested exit is dependency. Leaving without a workload case is guesswork.
Methodology and evidence limits
Tier C, document-first. FSR reviewed primary court orders, statutes, regulations, party filings, the filed administrative record and contract exhibits, official procurement notices, and current government, Anthropic, and AWS pages. Web sources were checked through August 4, 2026. Party allegations are attributed as allegations; a preliminary finding is not described as a final judgment.
Visible sample: four July SAM.gov opportunity pages were checked. One opened notice contained Anthropic-removal language; three other pages identified contractor-assertion attachments whose bodies FSR did not extract. The sample is not exhaustive and does not establish prevalence across the Defense Industrial Base.
Not obtained in full: the June 12 government directive, June 30 lifting instrument, June 3 Title 41 reconsideration decision, Amazon report, CAISI assessment, July 24 and August 3 appellate brief bodies, the Ninth Circuit docket after April 27, and several SAM attachment texts. Their contents were not reconstructed from model memory or secondary summaries.
Absence rule: “not found” means not found in the defined source set and searches used for this article. It is not proof that no such material exists.
This article is an evidence-bounded procurement and operational-risk analysis, not legal advice. Current status can change with a new court order, contract modification, agency instruction, or platform policy.