This is Hamamoto from TIMEWELL. Today I want to introduce a technology-related topic.
…I started with my usual opening, but this time I need to shift the tone. On February 26, 2026, a statement from AI company Anthropic sent shockwaves far beyond the technology industry. It was an extraordinary document — essentially a public "No" delivered to the U.S. Department of War (formerly the Department of Defense, renamed in 2025).
And there is an "after" that wasn't visible when I first published this piece. Within days of the statement, Anthropic received a formal supply chain risk designation and moved into a courtroom fight. The rulings split, and Claude is now being pulled from Department of War systems in phases. Even the early framing — the hero who gave up a contract for the sake of ethics — has grown a lot more complicated in the reporting since. In this rewrite I keep the full translation of the statement, but I trace what actually happened after it.
Full Translation: Dario Amodei's Statement on Discussions with the Department of War
The original was published on Anthropic's official website on February 26, 2026. The original consistently refers to the organization as the "Department of War." The United States renamed the Department of Defense accordingly, and this article follows that usage.
I deeply believe in the fundamental importance of using AI to defend the United States and other democratic nations and to defeat our authoritarian adversaries.
For this reason, Anthropic has been actively deploying our models with the Department of War and intelligence agencies. We were the first frontier AI company to deploy a model on U.S. government classified networks, the first to deploy on national laboratories, and the first to provide custom models to national security customers. Claude is deployed extensively across the Department of War and other national security agencies for mission-critical applications including intelligence analysis, modeling and simulation, operational planning, and cyber operations.
Anthropic has also acted to protect America's lead in AI even when it has gone against our short-term business interests. We have chosen to forgo hundreds of millions of dollars in revenue to cut off use of Claude by companies affiliated with the Chinese Communist Party — some of which have been designated by the Department of War as Chinese military companies — we have shut down CCP-sponsored cyberattacks attempting to misuse Claude, and we have advocated for strong export controls on semiconductors to ensure democratic advantage.
Anthropic understands that it is the Department of War, not a private company, that makes military decisions. We have never objected to specific military operations or sought to restrict the use of our technology in an ad hoc manner.
However, we believe that in a small number of cases, AI may undermine rather than protect democratic values. Some uses also simply exceed the range that today's technology can safely and reliably perform. Two such use cases have never been included in our contracts with the Department of War, and we believe they should not be.
Large-scale domestic surveillance. We support the use of AI for legitimate foreign intelligence and counterintelligence missions. However, using these systems for large-scale domestic surveillance is incompatible with democratic values. AI-enabled mass surveillance poses serious and novel risks to our fundamental freedoms. The extent to which such surveillance is currently legal reflects only the fact that the law has not yet caught up with AI's rapidly expanding capabilities. Under current law, for instance, the government can purchase detailed records of Americans' movements, web browsing, and associations from public sources without a warrant. This practice has generated bipartisan opposition in Congress, with intelligence agencies themselves acknowledging privacy concerns. Powerful AI can automatically and at scale assemble this scattered, individually innocuous data into a comprehensive picture of any individual's life.
Fully autonomous weapons. Partially autonomous weapons of the type currently being used in Ukraine are essential for defending democracy. Even fully autonomous weapons — those that fully remove humans from the loop and automate target selection and engagement — may prove important for our national defense. However, today's frontier AI systems are simply not reliable enough to power fully autonomous weapons. We will not knowingly provide a product that puts American soldiers and civilians at risk. We offered to work directly with the Department of War on R&D to improve the reliability of these systems, but they declined this offer. Without appropriate oversight, fully autonomous weapons cannot be expected to exercise the judgment that our highly trained professional soldiers demonstrate every day. They need to be deployed with appropriate guardrails that do not yet exist.
To our knowledge, these two exceptions have not been a barrier to accelerating the adoption and use of our models within the military.
The Department of War has stated that they will only contract with AI companies that agree to "all lawful uses" and drop the safeguards described above. They have threatened to remove us from their systems if we maintain these safeguards. They have also threatened to designate us as a "supply chain risk" — a label typically reserved for adversaries, never before applied to an American company — and to invoke the Defense Production Act to compel us to remove those safeguards. The latter two threats are essentially contradictory: one treats us as a security risk, while the other treats Claude as indispensable to national security.
Regardless, these threats will not change our position. We cannot in good conscience agree to their demands.
It is the Department of War's prerogative to choose contractors that best align with their vision. However, given the considerable value Anthropic's technology provides to our military, we hope they will reconsider. Our strong preference is to continue serving the Department of War and our service members with the two safeguards we have requested in place. If the Department of War chooses to offboard Anthropic, we will cooperate to enable a smooth transition to another provider so as to avoid disruption to ongoing military plans, operations, or other missions. Our models will remain available on the broad terms we have proposed for as long as necessary.
We stand ready to continue our work in support of U.S. national security.
(Source: Anthropic official website, published February 26, 2026)
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
What Happened After the Statement — Designation, Lawsuit, and Split Rulings
At first this was told as a single image: a private company said "No" to the most powerful military on earth. Over the following months the story became much more concrete. Here is the timeline as we now understand it.
| Date | Event |
|---|---|
| December 2025 | Secretary of War Hegseth announces the government generative-AI platform "GenAI.mil," initially built on Google's Gemini |
| January 2026 | The Department of War signals it will adopt xAI's Grok; Hegseth criticizes "woke AI" by name |
| February 24, 2026 | Secretary of War Hegseth demands that Anthropic CEO Dario Amodei grant the military all lawful uses of its technology |
| February 26, 2026 | Amodei publishes the statement, refusing large-scale domestic surveillance and fully autonomous weapons |
| February 27, 2026 | President Trump orders all federal agencies to immediately halt use of Anthropic technology |
| March 4, 2026 | Anthropic receives a formal supply chain risk designation letter from the Department of War |
| March 5, 2026 | Anthropic publishes a rebuttal, calling the designation "not legally sound" and announcing it will litigate |
| March 2026 | Judge Rita Lin (N.D. Cal.) grants a preliminary injunction blocking most of the designation, finding it a First Amendment retaliation for Anthropic's "hostile manner through the press" |
| April 2026 | The D.C. Circuit denies Anthropic's emergency stay motion; the designation stands for covered systems |
The early reporting that the "formal designation" landed on February 27 shifted once the primary sources came in. Anthropic received the actual designation letter on March 4, and the following day, March 5, it published its rebuttal, "Where things stand with the Department of War." In it, Anthropic states plainly that the designation is "not legally sound" and that it sees "no choice but to challenge it in court."
The legal framework is worth understanding. The supply chain risk designation rests on the Federal Acquisition Supply Chain Security Act (FASCSA), enacted in 2018 — a regime built with U.S. adversaries in mind, now aimed at a U.S. company for the first time. Anthropic's central argument is that the governing statute, 10 U.S.C. §3252, requires the Secretary of War to use the "least restrictive means necessary." In other words, is the designation disproportionate to the goal of protecting the supply chain? Anthropic also argues that the designation should reach only "the use of Claude by customers as a direct part of contracts with the Department of War," not every use of Claude by any contracting company. On top of that, the Department threatened to invoke the Defense Production Act to force the removal of Anthropic's safeguards. Calling something a security risk while also wielding a compulsion power that treats it as indispensable — Anthropic quietly points to that contradiction in its statement.
The courts did not line up neatly. In March, Judge Rita Lin of the Northern District of California granted a preliminary injunction blocking most of the designation, finding that the Department had designated Anthropic in retaliation for its "hostile manner through the press" — classic illegal First Amendment retaliation. In April, however, the D.C. Circuit denied Anthropic's emergency stay motion. The upshot: for covered systems, the designation remains in force while Claude is removed from Department of War systems. The removal is phased over roughly 180 days, with Anthropic barred from participating as prime or subcontractor, and — per reporting and related materials — completion is expected around the summer of 2026. The contracts terminated or in dispute are estimated at about $200 million.
This dispute has not stayed inside the courtroom. The Congressional Research Service took it up as "Pentagon-Anthropic Dispute over Autonomous Weapon Systems: Potential Issues for Congress" (report IN12669), framing it for lawmakers as a policy question about autonomous weapon systems. That is evidence this is being received not as a quarrel between one company and one agency, but as a question of institutional design: how much democratic control should be placed on the military use of AI.
The "Ethical Hero" Story, Complicated
Honestly, at first I felt straightforwardly that Anthropic had done well. Drawing a line in the face of profit and political pressure, losing a contract as the price, and refusing to change position even after being named by the President — it's a clear image. But line up what came out afterward, and it stops being a matter of black and white.
From the political side came the charge that this was strategy, not ethics. David Sacks, who handles AI and crypto in the Trump administration, called Anthropic's posture "a sophisticated regulatory capture strategy based on fear-mongering" — the argument being that Anthropic invokes safety to shape rules in its own favor. There were moves in the investment world too: 1789 Capital, associated with the President's eldest son, reportedly walked away from a hundreds-of-millions-of-dollars investment in Anthropic.
Nor did Anthropic's exit leave a vacuum. The government platform GenAI.mil began with Google's Gemini and later incorporated xAI's Grok. OpenAI, too, reportedly finalized a Department of War deal shortly before the Iran operation began. In other words, when one company draws an ethical line and steps back, another provider takes the seat immediately. The direction of AI development is set by national security strategy and political calculation, not by engineers' consciences — a cold reality that has, if anything, become clearer than in the early reporting.
Heaviest of all is how Claude itself has been used. A report said Claude was used in the February 2026 Venezuela intervention, and in a June Bloomberg interview Amodei was asked about the so-called "Minab school strike" (Amnesty International says 156 people were killed, 120 of them children). As reported, he did not confirm whether Claude had been used and suggested that even if it had, it would not violate Anthropic's red lines. Human rights groups reportedly called for an investigation into possible war crimes. These individual facts still warrant primary confirmation, but at the very least they show that the single image of "the company that held the line" can become far more ambiguous in actual operation.
The lesson I take from this is simple. A company's stated ethics policy is not, by itself, a guarantee. Without a mechanism to trace where, by whom, and for what a technology is actually used, a red line becomes a picture of a rice cake. That "mechanism to trace" is exactly what export control and military-diversion prevention are about.
AI Military Use and Information Warfare Have Already Begun
Anthropic's concerns are not unfounded. In Ukraine, AI-equipped drones are deployed for everything from reconnaissance to direct attack. Some are remotely operated; others have a degree of autonomy in tracking targets. The nature of warfare has already begun to change.
As a way to organize this, NVIDIA CEO Jensen Huang's "AI 5-Layer Cake," described at the January 2026 Davos forum, is instructive. Huang split AI infrastructure into five layers — energy, semiconductors, cloud, models, and applications — each a massive industry. What I want to stress is that all five layers are dual-use technology. Energy governs the compute base; the performance of semiconductors decides the "brain" of military AI. U.S. semiconductor export controls on China were precisely a move to hold advantage at that layer. Cloud demands secure, government-dedicated environments for classified work, and at the model layer the fight is over which AI to adopt and how far it may be used. The Anthropic–Department of War standoff is nothing other than a battle at that fourth layer. And the fifth, applications, includes not only intelligence analysis and autonomous weapons but influence operations and information warfare.
What must not be overlooked is that information warfare hiding at the top layer. Frankly, what alarmed me most in all of this was not autonomous weapons but this. AI can analyze vast personal data — social posts, search histories, purchase records — and infer each person's political beliefs and psychological vulnerabilities, then deliver information tailored to each individual. It is ad-targeting technology turned into propaganda.
Deepfakes are already at a practical stage. It is now technically possible to fabricate convincing video or audio instantly, to discredit a politician or sow chaos. In the early days of Russia's invasion of Ukraine, a deepfake of President Zelensky urging citizens to surrender circulated on social media. It was debunked quickly, but debunking will only get harder as the technology advances. Japan, in its geopolitically complex position, is a potential target for foreign information operations as well. We need to keep in mind that the news and social feeds we consume every day may have been shaped by someone else's agenda.
Export Control and Military-Diversion Prevention — TIMEWELL's Position and TRAFEED's Role
Let me be clear about where TIMEWELL stands. In a single sentence: we face this reality directly, without looking away.
Technology is neutral; it has no inherent good or evil. The question is who uses it, for what, and under what constraints. On that basis, we hold the line that AI must not be used for armed aggression against other nations, nor by foreign powers to deceive citizens and divide societies. The two red lines Anthropic drew — refusing large-scale domestic surveillance and fully autonomous weapons — are questions every company and individual working with technology should take seriously. But as this piece has shown, drawing a policy is not enough. Idealism alone cannot defend a nation, and there is the uncomfortable reality that a company can state a policy and still find its models used on the battlefield.
So the two practical principles I advocate are these. First, restrained use for defense: we accept researching and using AI to deter foreign cyberattacks and information warfare, but we urge extreme caution on fully autonomous weapons, with guardrail design given priority equal to or above the development itself. Second, strengthening society's digital immune system: technical defenses alone cannot stop increasingly sophisticated information warfare, so what ultimately matters is each citizen's ability to critically evaluate disinformation.
Bring this back to our own work, and it lands on the practical business of export control and military-diversion prevention. Both semiconductors and AI models, as Anthropic's statement noted, sit at the center of export controls. Is your product or technology reaching a military end use or a sanctioned party unintentionally? Confirming that is the corporate version of "a mechanism to hold the line." Concretely, the pillars are export classification — determining whether goods or technology fall under a control list — and screening counterparties for concerns. For the classification workflow itself, our companion piece What Is Export Classification? The Process on One Page walks through it in practice. If you want a quick check of how much export-control risk your transactions carry, the Export Control Risk Check is a good place to start.
Our export control AI agent, TRAFEED (formerly ZEROCK ExCHECK), is built to put that "mechanism to trace" into everyday practice. Based on a joint study with Okayama University and roughly 30,000 past review records, it achieves AI classification accuracy of 95% or higher (per our own data), and it reflects regulatory changes in each jurisdiction on the same day. It visualizes the level of concern in about five seconds and shows the basis for its judgment. Of course, the final classification decision rests with your organization's export control officer. AI does not replace the judgment; it reduces oversights and leaves a record of the reasoning. That boundary is the principle we care about most when handling AI in a compliance domain.
Closing Thoughts — The Future Will Be Decided Not by Technology, but by Our Choices
Anthropic's statement still carries weight as a document in which a company at the frontier of AI grappled with the risks of its own creations and sounded an alarm. Yet looking back nearly half a year later, this story does not end at "a courageous refusal." Designation, lawsuit, split rulings, and the question of how the model is actually used in the field — the gap between the declaration and the reality turns out to be wider than it first seemed.
That is why I keep coming back to this: ethics cannot be upheld by declaration alone. To uphold them, you need a mechanism to trace where and by whom a technology is used. At the level of the state, that role falls to democratic oversight and legal frameworks; at the level of the company, to export control and counterparty checks. The abstract principle and the unglamorous practice — only with both does a red line stop being empty words.
Technology is a tool. Tools bear no guilt. But deciding how a tool is used, and watching how it is used, has always rested with human beings. Not running from that question, and continuing to think about it as stakeholders — that, I believe, is the posture the age of AI and war asks of us.
If you are reviewing export-control operations or classification workflows, download the TRAFEED product catalog (PDF) or contact us.
References
- Anthropic. (2026, February 26). Statement from Dario Amodei on our discussions with the Department of War. https://www.anthropic.com/news/statement-department-of-war
- Anthropic. (2026, March 5). Where things stand with the Department of War. https://www.anthropic.com/news/where-stand-department-war
- Congressional Research Service. (2026). Pentagon-Anthropic Dispute over Autonomous Weapon Systems: Potential Issues for Congress (IN12669). https://www.congress.gov/crs-product/IN12669
- Reuters. (2026, February 27). Trump orders federal agencies to stop using Anthropic. https://jp.reuters.com/world/us/EUCSL6JFM5LZZPKLNPEYK74MHI-2026-02-27/
- The Guardian. (2026, February 27). Trump orders US agencies to stop use of Anthropic technology. https://www.theguardian.com/us-news/2026/feb/27/trump-anthropic-ai-federal-agencies
- Forbes JAPAN. (2026, January 26). NVIDIA CEO's "5-Layer AI Cake" and the Largest Infrastructure Build in Human History — Davos 2026. https://forbesjapan.com/articles/detail/90317





