Anthropic and the Pentagon: court documents reveal both sides were nearly aligned one week after Trump declared the relationship over
Anthropic is at the center of one of the most revealing lawsuits involving artificial intelligence and the United States government. Last Friday, the company filed two sworn declarations with a federal court in California, directly challenging the Pentagon’s claim that the company poses an unacceptable risk to national security.
The documents argue that the government’s case is built on technical misunderstandings and allegations that were never raised during the months of negotiations that preceded the dispute. The declarations were filed alongside Anthropic’s response in its lawsuit against the Department of Defense, ahead of a hearing scheduled for Tuesday, March 24, before Judge Rita Lin in San Francisco.
What once looked like a promising partnership between the company and the Pentagon has turned into a court case full of contradictions, revealing documents, and unanswered questions. And the most uncomfortable detail for the government’s official story just came to light. 📄
How it all started: the public breakup
The dispute goes back to late February, when President Trump and Defense Secretary Pete Hegseth publicly declared they were cutting ties with Anthropic. The stated reason was that the company had allegedly refused to allow unrestricted military use of its AI technology. That public statement led the government to formalize a supply chain risk designation against Anthropic, classifying it as a national security threat.
This designation is particularly significant because, according to the company itself, it was the first time this kind of classification had ever been applied to an American company. Anthropic claims in its lawsuit that the move amounts to government retaliation against the company’s publicly stated positions on AI safety, which would violate the First Amendment of the U.S. Constitution.
The government, for its part, completely rejected that framing in a 40-page filing submitted earlier the same week. In the Department of Defense’s view, Anthropic’s refusal to allow all lawful military uses of its technology was a business decision, not protected speech, and the risk designation was a straightforward national security assessment with no punitive intent whatsoever.
But the new documents filed by Anthropic put that official narrative in a pretty awkward position. 🤔
The two sworn declarations and what they reveal
The declarations were submitted by two key figures within Anthropic: Sarah Heck, the company’s Head of Policy, and Thiyagu Ramasamy, Head of Public Sector.
Sarah Heck’s testimony
Sarah Heck is no random player in this story. She is a former National Security Council staffer who worked at the White House during the Obama administration before moving through Stripe and landing at Anthropic, where she manages the company’s government relations and public policy work. Heck was personally present at the February 24 meeting where CEO Dario Amodei sat down with Defense Secretary Hegseth and Pentagon Undersecretary Emil Michael.
In her declaration, Heck points to what she describes as a central falsehood in the government’s filings: the claim that Anthropic demanded some kind of approval role over military operations. According to Heck, that assertion is simply not true. At no point during the negotiations did she or any other Anthropic employee state that the company wanted that kind of role, as laid out in her testimony.
Heck also states that the Pentagon’s concern about Anthropic potentially disabling or altering its technology during an operation was never raised during the negotiations. Instead, this allegation appeared for the first time in the government’s court filings, without the company ever having had a chance to respond.
The email that contradicts everything
But the most striking detail in Heck’s declaration centers on an email sent on March 4, exactly one day after the Pentagon formalized the supply chain risk designation against Anthropic. In that email, Undersecretary Emil Michael wrote to CEO Dario Amodei saying the two sides were very close to an agreement on the two issues the government now cites as evidence that Anthropic is a national security threat: its positions on autonomous weapons and mass surveillance of Americans.
Heck attaches this email as evidence in her declaration, and it is worth looking at what happened in the days that followed. On March 5, Amodei published a statement saying the company had been having productive conversations with the Pentagon. The next day, March 6, Michael posted on social media that there were no active negotiations between the Department of Defense and Anthropic. A week later, he told CNBC there was no chance of talks resuming.
The point Heck seems to be making is straightforward: if Anthropic’s position on those two issues is what makes it a national security threat, why was the Pentagon’s own representative saying the two sides were nearly aligned on those very same issues right after the designation was finalized? Heck does not explicitly claim the government used the designation as a bargaining chip in negotiations, but the timeline she lays out leaves that question hanging in the air pretty clearly. 🧐
Thiyagu Ramasamy’s technical testimony
The second declaration brings a different, more technical perspective. Thiyagu Ramasamy joined Anthropic in 2025 after six years at Amazon Web Services, where he managed AI deployments for government clients, including classified environments. At Anthropic, he is credited with building the team that brought Claude models into national security and defense contexts, including the $200 million contract with the Pentagon announced last summer.
Ramasamy directly confronts the government’s claim that Anthropic could theoretically interfere with military operations by disabling its technology or altering its behavior. According to him, that is not technically possible.
The explanation is detailed: once Claude is deployed inside a secure, internet-isolated government system, known as an air-gapped system, operated by a third-party contractor, Anthropic has no access to it. There is no remote kill switch, no backdoor in the system, and no mechanism to push unauthorized updates. Any kind of operational veto is fiction, according to Ramasamy, who explains that a change to the model would require the Pentagon’s explicit approval and a deliberate action to install it.
Anthropic, according to him, cannot even see what government users are typing into the system, let alone extract that data.
Ramasamy also pushes back on the government’s claim that Anthropic’s hiring of foreign nationals would pose a security risk. He notes that company employees went through the government’s own security clearance vetting process, the same type of background check required for access to classified information. According to his declaration, to the best of his knowledge, Anthropic is the only AI company where security-cleared personnel actually built the models designed to run in classified environments.
The impact on the artificial intelligence industry
This case goes far beyond a dispute between Anthropic and the U.S. government. It serves as a warning to every AI technology company that is currently trying to figure out how to build a safe and sustainable government relationship in the United States. The risk of having an active contract turn overnight into a national security threat classification is something no company wants to face, and the precedent this lawsuit could set has enormous implications for the entire industry.
Companies developing large language models, computer vision systems, or any other AI application with dual-use potential, civilian and military at the same time, need to watch this case closely. The fact that Anthropic had well-documented responsible use policies and still became the target of a risk designation shows that good practices alone do not guarantee protection against politically driven decisions.
Another relevant aspect is how quickly political decisions can affect contracts and partnerships in the sector. In traditional markets, a government contract rupture takes months of discussions, audits, and formal reviews. In this case, the shift from strategic partner to national security threat happened extremely fast, at least on paper. That creates a level of uncertainty that could push other AI companies away from pursuing government contracts, right at a time when the Pentagon and other agencies are ramping up their investments in artificial intelligence. 😬
The bigger picture: the global AI race
This episode comes at a particularly sensitive moment. The United States is in an accelerated race to solidify its leadership in artificial intelligence technology, especially in the face of competition from China. In that context, alienating top American AI companies for reasons that appear contradictory is a move that industry analysts are already openly questioning.
Anthropic is one of the few companies in the world capable of developing language models at the cutting edge of the state of the art. Its Claude model is among the most advanced available, and the $200 million Pentagon contract was not just any deal — it was a strategic U.S. government investment in defense technology capability.
If the outcome of this case favors the government and the risk designation stands as valid precedent, the ripple effect on other AI companies could be significant. It could lead companies to simply accept any government conditions without negotiation, fearing retaliation, or at the opposite extreme, to avoid defense sector contracts altogether.
Neither scenario is ideal for the U.S. competitive position in the global artificial intelligence market. 🌐
What comes next in this case
The Tuesday, March 24 hearing before Judge Rita Lin in San Francisco will be the next chapter in this dispute. The sworn declarations from Heck and Ramasamy put additional pressure on the government to explain the contradictions between what was being communicated internally and what was stated publicly.
Anthropic’s defense has used each new revelation to reinforce the argument that the national security risk designation had no solid technical or operational basis. Emil Michael’s email, in particular, is a piece of evidence that is hard to get around, because it comes from inside the government itself and directly contradicts the justification presented for the designation.
The government, meanwhile, maintains its position that Anthropic’s refusal to allow all lawful military uses of its technology justifies the risk designation, and that it was a legitimate national security decision. The question the court will have to resolve is whether there is a consistent factual and technical basis for that classification, or whether it was motivated by factors that go beyond the actual risk assessment.
Regardless of the legal outcome, this case has already left a significant mark on how the AI technology sector views its relationship with the U.S. government. The contradictions documented in court records, the speed at which the relationship deteriorated, and the gap between internal and public communications are elements that will continue to be discussed for a long time.
For anyone following artificial intelligence and its intersections with politics and defense, this is one of the most important cases in recent years — and it is far from over. 🔍
