Technology
Can an AI company say no to the State?
The Anthropic–Pentagon dispute is not merely a procurement quarrel. It is an early constitutional test of who governs strategically important artificial intelligence when private technological power collides with sovereign national-security power.
Can a private company build a technology important enough to national defense and still reserve the right to tell the state how that technology may be used?
If an AI laboratory believes a military application is unsafe, does its technical judgment outrank the elected government’s strategic judgment?
Conversely, if the government can punish a frontier-model developer for refusing particular uses, is “national security” becoming a mechanism for converting private innovation into quasi-compulsory state infrastructure?
And when the technology in question may eventually influence surveillance, cyber operations, intelligence analysis, targeting, autonomous systems, and even the tempo of war itself, who should possess the final veto?
These questions moved abruptly from seminar-room speculation to constitutional litigation in 2026. A U.S. federal judge permanently blocked the Pentagon’s designation of Anthropic as a national-security supply-chain risk after the maker of Claude resisted unrestricted military use of its models. The dispute centered on two red lines identified by Anthropic: mass domestic surveillance of Americans and fully autonomous weapons. Judge Rita F. Lin concluded that the government’s response was unlawful, including on First Amendment and administrative-law grounds. Her ruling did not establish that an AI company possesses sovereign authority over national-security policy. It established something narrower but profoundly important: the state cannot simply convert disagreement with a contractor into retaliation by attaching the language of national security to it.
That distinction may become one of the defining institutional questions of the AI age. Frontier AI is increasingly private in ownership, strategic in consequence, expensive to reproduce, and difficult for governments to substitute quickly. The constitutional politics of the twentieth century often asked how democratic states should restrain corporations. Frontier AI adds the reverse question: how should constitutional democracies restrain themselves when they become dependent on corporations that control strategically significant intelligence infrastructure?
A ‘Procurement Dispute’ that became a ‘Constitutional Dispute’
The immediate controversy began as a contracting disagreement. Anthropic had already been working with the U.S. national-security establishment. In 2025, the Department of Defense awarded Anthropic a prototype agreement valued at $200 million to develop frontier AI capabilities for critical national-security challenges across warfighting and enterprise domains. Similar $200 million awards went to other frontier-model providers. The military’s interest was therefore not hypothetical: frontier models were becoming part of the defense technology stack.
The relationship broke down over the permissible-use boundary. Anthropic said it supported lawful national-security uses except for two narrow categories: mass domestic surveillance and fully autonomous weapons. The company argued that contemporary frontier models were not sufficiently reliable to assume lethal autonomy and that large-scale domestic surveillance raised fundamental civil-liberties concerns. The government wanted broader operational discretion. Negotiations failed.
The Pentagon then designated Anthropic a supply-chain risk and sought restrictions that could reach beyond the company’s direct government business into relationships with defense contractors. Anthropic argued that the designation could inflict billions of dollars in lost business and reputational damage. The extraordinary feature was not merely that the government chose another vendor. Governments routinely decline to buy products whose contractual conditions they dislike. The constitutional issue arose because the state allegedly used a national-security designation to penalize the company for its position and public criticism.
Judge Lin’s 59-page ruling drew precisely that line. The court held that the government could not rely on an “empty invocation” of national security as a blank check for retaliation. Earlier in the litigation, the court had found evidence suggesting that the government’s actions went beyond obtaining operational control and instead sought to make an example of Anthropic for its public stance. In August, the court granted Anthropic important claims under the Administrative Procedure Act and rejected the Pentagon’s supply-chain designation.
This is why the case is larger than Anthropic. The judgment does not say that Claude has constitutional rights. It says that the corporation supplying Claude does not lose ordinary constitutional protections merely because its customer is the national-security state.
The ‘new strategic reality’: Intelligence infrastructure is ‘privately built’
The deeper structural problem is that governments no longer monopolize the production of strategically important capabilities. Nuclear weapons were developed through state-led programs. Aircraft carriers, missiles, and fighter aircraft have long involved private contractors, but they are ordinarily designed around state specifications within mature procurement systems. Frontier AI is different. The most capable general-purpose models are largely created first for commercial markets by private laboratories, trained on privately assembled infrastructure, governed through company safety frameworks, and only afterward adapted to state use.
Stanford’s 2026 AI Index reports that industry produced more than 90 percent of notable AI models in 2025. The United States produced 59 notable models that year compared with China’s 35, while global AI compute capacity had grown roughly 3.3 times annually since 2022 to an estimated 17.1 million H100-equivalents. This is not merely another software market. It is an extraordinarily capital-intensive technological system in which a relatively small group of companies controls the frontier.
The economic scale reinforces the political importance. Stanford reports that global corporate AI investment more than doubled in 2025, private investment rose 127.5 percent, and generative AI captured nearly half of private AI funding. Organizational AI adoption reached 88 percent in the surveyed population. At the same time, frontier capability continued to improve rapidly: on Humanity’s Last Exam, frontier-model performance increased by roughly 30 percentage points in a single year. When technical capability accelerates faster than public institutions can legislate, procurement contracts and corporate policies begin doing work that law has not yet done.
This produces an unusual constitutional configuration. The state possesses legal sovereignty, coercive authority, intelligence powers, military command, and democratic legitimacy. The frontier laboratory possesses technical expertise, model weights, safety systems, deployment architecture, scarce engineering talent, and knowledge about failure modes that the state may not independently possess. Neither side is institutionally complete without the other.
The resulting relationship is not ordinary vendor management. It is strategic interdependence.
The company’s argument: Technical capability does not create a ‘duty to enable every lawful use’
Anthropic’s position rests on a proposition that deserves careful treatment: legality is not identical to safety, prudence, or corporate obligation. A government may have legal authority to conduct an activity without possessing an entitlement to compel every private technology provider to facilitate it.
This distinction exists throughout commercial life. A pharmaceutical company is not automatically required to manufacture every lawful compound. A cloud provider can impose acceptable-use restrictions. A bank can decline lawful but high-risk customers within applicable law. A newspaper cannot ordinarily be forced to publish government speech simply because the government considers publication useful. Government contracting necessarily contains negotiation, conditions, refusals, substitutions, and exit.
Frontier AI makes the issue more difficult because a model is not a passive commodity. Its behavior depends on safeguards, system prompts, classifiers, access controls, monitoring, fine-tuning, deployment surfaces, and continuous updates. A demand for “the model” can become a demand for the developer’s ongoing engineering cooperation. Removing safety controls is not equivalent to purchasing an additional truck. It may require the company to participate in creating a different risk posture.
Anthropic’s Responsible Scaling Policy illustrates this institutionalization of private risk governance. First introduced in 2023 and repeatedly revised, the framework links increasing model capabilities to stronger safeguards and risk assessments. As of August 2026, Anthropic had again published an updated risk report and maintained a policy architecture covering catastrophic-risk evaluations, safety thresholds, internal governance, external review, and non-compliance reporting. One need not accept every Anthropic policy choice to recognize the organizational fact: frontier laboratories are building internal quasi-regulatory systems because public regulation remains incomplete.
There is also a competence argument. If the engineers who build a model believe that it is insufficiently reliable to operate a lethal autonomous system without meaningful human control, a government should not casually treat that judgment as ideological obstruction. In high-consequence engineering, dissent can be a safety mechanism.
The State’s argument: National Security cannot be outsourced to ‘corporate conscience’
Yet the opposite argument is equally serious. Democratic states cannot permit a handful of unelected technology executives to become a private security council with veto power over defense policy.
The government bears constitutional and political responsibility for defending the country. Military commanders, civilian defense officials, legislators, and ultimately elected leaders are accountable, however imperfectly, to public institutions. A frontier AI company is accountable primarily through corporate governance, contracts, markets, employees, investors, and law. Its safety policy may be sophisticated, but it is not a constitution. Its board is not Congress. Its CEO is not the commander in chief.
This matters because “safety” itself contains political judgments. What constitutes unacceptable autonomous operation? How much human control is sufficient? When does surveillance become “mass surveillance”? What if an adversary deploys AI-enabled systems with fewer restrictions? What if delaying deployment increases battlefield casualties? What if a model can improve missile defense, cyber defense, or intelligence warning but the company fears dual-use escalation? These are not purely technical questions. They combine engineering evidence with ethics, strategy, law, and democratic choice.
The national-security argument also invokes dependency risk. If the armed forces integrate a proprietary model deeply into planning, logistics, intelligence, or command-support systems, a vendor’s later policy change could become an operational vulnerability. A government cannot rationally build critical military infrastructure around a provider that retains an unlimited unilateral right to disable capability during a crisis.
That concern explains why the Pentagon’s supply-chain logic cannot simply be dismissed. Genuine supply-chain risk is real. The legal problem in the Anthropic case was the way the designation was used and justified, not the proposition that governments may evaluate technological dependency. Indeed, a mature state should assess model availability, cyber compromise, foreign influence, concentration, update control, vendor lock-in, continuity of service, and the possibility that commercial governance could conflict with mission requirements.
The constitutional boundary should, therefore, prevent retaliation without preventing strategic due diligence.
The ‘historical warning’: Google & Project Maven
Anthropic is not the first technology company to discover that military AI creates internal and political conflict. In 2018, Google faced a major employee revolt over Project Maven, a Pentagon initiative involving AI analysis of drone imagery. Roughly 4,000 Google employees reportedly signed a petition opposing the company’s involvement, and some employees resigned. Google subsequently said it would not pursue a follow-on Maven contract and adopted AI principles that included restrictions on weapons-related applications.
The episode appeared at the time to establish a durable Silicon Valley boundary. It did not. By 2025, Google had removed its explicit pledge not to use AI for weapons or surveillance from its published principles, replacing categorical prohibitions with a broader commitment to responsible development consistent with international law and human rights and explicitly acknowledging national-security cooperation.
That evolution is instructive. Corporate ethics policies are not immutable constitutional texts. They change with leadership, competition, geopolitical conditions, employee sentiment, technological maturity, customer demand, and commercial incentives. This weakens the argument that society should simply trust frontier laboratories to define the public interest. But it also strengthens the case for protecting their freedom to articulate and negotiate safety limits: institutional learning requires the ability to dissent without being punished as a security threat.
OpenAI shows that the ‘binary choice is false’
The Anthropic dispute can be misread as a choice between unrestricted state control and corporate refusal. OpenAI’s subsequent agreement with the Pentagon suggests a third possibility: negotiated technical and contractual architecture.
OpenAI publicly described red lines including no mass domestic surveillance, no use of its technology to direct autonomous weapons systems, and no high-stakes automated decisions without required human decision-makers. Its Pentagon arrangement relied not only on policy language but on deployment design: cloud-only access, retention of the company’s safety stack, contractual restrictions, and cleared company personnel in the loop. OpenAI also publicly opposed designating Anthropic a supply-chain risk.
The lesson is institutional rather than corporate. The strongest safeguard is not a press release saying “trust us,” whether issued by a company or a ministry. It is an enforceable architecture in which legal rules, contract terms, technical controls, auditability, human authorization, and termination procedures reinforce one another.
This is precisely how constitutional systems handle dangerous power elsewhere. They do not assume virtue. They distribute authority, impose process, create records, separate functions, and establish review.
‘Autonomous weapons’ make the dispute more than theoretical
The most morally charged part of the Anthropic controversy concerns autonomous weapons because the underlying international debate remains unresolved. In December 2025, the United Nations General Assembly adopted a resolution on lethal autonomous weapons systems by 164 votes to 6, with 7 abstentions. In August 2026, the UN secretary-general and the president of the International Committee of the Red Cross again called for legally binding international rules, warning against delegating life-and-death decisions to machines.
The difficulty is that autonomy is not binary. Militaries already use automated defensive systems, targeting assistance, sensor fusion, navigation, threat classification, and decision-support software. The central governance question is where along the chain — from detection to identification to recommendation to engagement — the human must remain authoritative.
The Pentagon itself has long recognized that AI requires governance. Its ethical principles describe military AI as responsible, equitable, traceable, reliable, and governable, including the ability to detect unintended consequences and disengage systems exhibiting unintended behavior. The state and Anthropic were not arguing over whether AI safety exists. They were arguing over who operationalizes it, through what mechanisms, and whose judgment prevails when interpretations diverge.
That is why the constitutional politics of frontier models will increasingly be the politics of control points.
Five principles for a ‘New Constitutional Settlement’
A workable settlement should begin with five principles.
First, the state must retain sovereign authority over national-security policy, but sovereignty does not mean entitlement to every privately created capability on whatever terms the state chooses. Governments may procure, regulate, incentivize, develop alternatives, or — in extraordinary circumstances and under lawful authority — compel. They may not disguise punishment for protected disagreement as neutral security administration.
Second, frontier laboratories should retain the right to establish safety conditions, but those conditions should become more transparent, stable, auditable, and contractually explicit when the company seeks strategic government business. A company cannot simultaneously demand recognition as critical national infrastructure and behave like an ordinary consumer app whose terms may change overnight.
Third, no single vendor should become indispensable. The correct government response to dependency is resilience: multi-vendor procurement, interoperability, open standards where feasible, sovereign evaluation capacity, internal technical expertise, model portability, contingency plans, and investment in public-sector AI capability. The U.S. federal government committed about $793 billion to contracts in fiscal 2025; it has the purchasing scale to shape markets rather than merely submit to them. GAO has also reported that federal agencies more than doubled reported AI use from 2023 to 2024 while still facing shortages of expertise and difficulty understanding AI acquisition costs. Procurement competence is now a national-security capability.
Fourth, high-consequence AI uses require joint governance. For autonomous weapons, intelligence, cyber operations, nuclear-adjacent systems, and domestic surveillance, neither corporate policy nor executive-branch preference should stand alone. Congress, courts, inspectors general, technical evaluators, military lawyers, civil-liberties institutions, and, where appropriate, international law, must form part of the control system.
Fifth, disputes must be processed through law rather than political intimidation. If a company breaches a contract, litigate or terminate according to the contract. If it creates a genuine security vulnerability, document the risk under the relevant statute and provide appropriate process. If its restrictions make it unsuitable for a mission, select another supplier. But branding a domestic technology company a national-security threat because it publicly resists government preferences is a dangerous shortcut.
The ‘hidden risk’: A ‘private ai constitution’
There is, however, a danger on the corporate side that deserves equal emphasis. Frontier companies increasingly publish constitutions, model specifications, safety frameworks, usage policies, preparedness systems, and responsible-scaling policies. These documents can be valuable. But collectively they may become a form of private constitutionalism: rules written by corporations that determine what millions of people, and eventually governments, may ask powerful computational systems to do.
That power should make democracies uncomfortable even when the rules appear benevolent. A company may prohibit one use today and permit it tomorrow. It may define political persuasion, surveillance, weapons assistance, biological-risk information, or cybersecurity access according to standards that have never been enacted by a legislature. Because the model is proprietary, users may have limited ability to contest the decision or understand its technical basis.
The solution is not to abolish corporate safety policies. It is to embed them within public governance. Anthropic itself now argues that AI companies should not be the only institutions deciding whether their systems are safe and supports requirements for public risk evaluations and safety-testing transparency. That principle should be taken seriously even when it constrains the laboratories themselves.
The frontier company should be a constitutional participant, not a constitutional sovereign.
The hidden risk on the ‘other side’: The ‘National-Security exception’ that swallows the rule
Democracies have another recurring temptation: when ordinary legal constraints become inconvenient, national security becomes the vocabulary through which exceptional power is normalized.
There are situations in which secrecy, speed, and executive discretion are indispensable. But frontier AI will touch so many domains — defense, intelligence, cybersecurity, critical infrastructure, biotechnology, communications, and economic security — that an unlimited national-security exception could gradually place enormous portions of technological governance outside meaningful contestation.
Judge Lin’s ruling matters because it rejects that drift at an early stage. A national-security agency may possess broad authority, but broad authority still requires statutory fit, evidence, procedure, and constitutional boundaries. The state does not become weaker when courts require it to justify coercive action. In a constitutional system, justification is part of strength.
Indeed, the long-run military advantage of democratic states may depend partly on preserving the very institutional environment that produces innovative companies: rule of law, credible contracts, freedom to criticize government, scientific openness, entrepreneurial risk-taking, and the ability of technical experts to raise uncomfortable objections. A government that demands loyalty from its AI suppliers may gain compliance while losing candor.
The strategic question is not who wins, but what system emerges
It would be easy to narrate the case as Anthropic versus the Pentagon and ask which side should win. That is too small a frame.
The United States is simultaneously trying to accelerate military AI adoption, compete with China, protect civil liberties, maintain technological leadership, prevent catastrophic AI misuse, and preserve democratic accountability. These objectives can conflict. A governance regime optimized solely for military speed may erode constitutional safeguards. A regime optimized solely for corporate safety preferences may impair legitimate defense requirements. A regime optimized solely for commercial growth may externalize risks onto society.
The correct institutional objective is, therefore, constrained capability: maximize the useful national power generated by frontier AI while ensuring that neither the state nor the company can exercise strategically consequential power without review.
This resembles the logic of checks and balances more than conventional technology regulation. The company checks the state by retaining technical control and the ability to refuse. The state checks the company through law, procurement power, competition policy, regulation, and public alternatives. Courts check retaliatory or ultra vires government action. Legislatures define permissible uses. Technical audits check both sides’ factual claims. Multiple vendors check monopoly dependence. Human authorization checks machine autonomy.
No actor receives absolute authority. That is not inefficiency. It is constitutional engineering.
Before the algorithm receives orders
The Anthropic ruling is best understood not as a victory for corporate power over government, but as an early attempt to prevent one form of power from swallowing another.
Frontier AI companies are becoming strange institutions. They are private corporations, research laboratories, infrastructure operators, safety regulators, geopolitical actors, defense contractors, and potential custodians of systems that may influence consequential human decisions. States are equally conflicted: they are customers, regulators, security guarantors, military users, funders, investigators, and sometimes adversaries in court.
The institutional categories of the industrial age no longer fit comfortably.
Final thoughts
So, can an AI company say no to the state? In a constitutional democracy, sometimes it must be able to. But should a company possess the final word over national-security policy simply because it owns the most capable model? No. Should the state be able to punish a company as a security threat merely because it refuses a disputed use or criticizes government policy? Again, no. And should society accept a future in which decisions about autonomous killing, mass surveillance, cyber operations, or other high-consequence uses are settled through private terms of service and hurried procurement negotiations? Certainly not.
The real challenge is to build institutions before capability outruns them.
Who will define the non-negotiable human role in AI-enabled warfare? Who will decide when a corporate safety restriction is principled risk management and when it becomes private obstruction of legitimate public policy? Who will determine when a government’s national-security claim reflects genuine operational necessity and when it becomes retaliation wrapped in the flag? And if the next generation of frontier models becomes indispensable to military and economic power, will democracies govern them through law, or discover too late that governance has already been divided informally between ministries and machine-learning laboratories?
The Anthropic case has supplied only an early judicial boundary. The larger constitutional settlement has yet to be written.
That settlement will decide something larger than who controls Claude, or any other model. It will decide whether AI becomes another instrument governed by constitutional democracy, or a new source of power around which constitutional democracy is forced to reorganize itself.