For months, the standoff between Anthropic and the Pentagon looked like a contract fight over access to Claude. Court documents released the week of June 30 tell a different story. The real dispute, laid out in email exchanges between Anthropic chief executive Dario Amodei and Pentagon Undersecretary Emil Michael, was about who gets to decide how the U.S. military uses frontier AI, and whether a company that builds these systems can refuse to sell certain uses to its own government.
The emails surfaced in one of Anthropic's lawsuits against the Department of Defense. The Wall Street Journal first reported them, and Gizmodo published pages from the court record. Together they trace a negotiation that narrowed to two irreconcilable positions.
The two red lines
Amodei's stance stayed fixed across months of talks. He was willing to let the Pentagon deploy Anthropic's models widely, but he drew hard boundaries around two uses: fully autonomous weapons and domestic mass surveillance. He restated those limits in a subsequent CBS News Sunday Morning interview, saying Anthropic had already fielded models "across the intelligence community and the military," while refusing weapons that "fire without any human involvement." His technical argument was that AI today is "nowhere near reliable enough" for that role. On surveillance, his concern was legal as much as ethical.
The Pentagon wanted broader terms. Its draft language sought coverage for "all lawful use cases," a phrase that, on its face, tracks whatever U.S. law permits. Amodei pushed back precisely there. Because U.S. law does allow certain domestic surveillance of Americans, he argued, accepting the "all lawful" framing would "completely remove our redlines" and authorize exactly the uses Anthropic had said it would not support.
'Just not workable'
Michael saw the guardrails as unworkable in practice. After a stretch of silence, he emailed Amodei saying he was "hoping that we are closer to engaging with your revised POV," a signal that he wanted Anthropic to move toward the Pentagon's position. Amodei repeated his limits instead.
Michael's reply was blunt. The proposed guardrails were "just not workable," he wrote, and he offered Anthropic "one more chance to align on core principles." He also rejected the central distinction Amodei was trying to preserve. "There is no distinction in our world between weapons that are defensive or offensive," Michael wrote, an argument that any attempt to sort military uses into permitted and forbidden categories collapses in the field, where the same capability serves both.
The two sides did not close the gap. Defense Secretary Pete Hegseth announced the talks were over, moving to designate Anthropic a supply-chain risk, a label ordinarily reserved for firms tied to foreign adversaries. President Trump posted on Truth Social attacking Anthropic and pressing federal agencies to stop using its technology. Anthropic sued, arguing the moves were retaliation for its stated safety views rather than genuine security policy.
Can a lab constrain its government?
The emails crystallize a question the AI industry has mostly avoided answering out loud: when the customer is the state, how much say does the vendor keep over end use? Anthropic's position is that a private company can and should hold ethical lines even against the Pentagon, and that a contract clause covering "all lawful" uses hands too much away given how permissive some U.S. law is. The Pentagon's position, voiced by Michael, is that a defense supplier cannot carve the battlefield into approved and unapproved uses, and that a vendor imposing its own policy limits on national-security work is offering something the military cannot operate around.
Both arguments have force. Anthropic is not a conscientious objector to defense work. By Amodei's own account, its models are already deployed across the intelligence community and the military, and he has said the company is not categorically opposed to autonomous weapons, particularly if adversaries build them, only that the reliability and oversight are not there yet. Michael's counter is a procurement reality: militaries buy capabilities, not curated slices of them, and a supplier that reserves a veto over use introduces a dependency the Defense Department is unwilling to accept.
That tension is the civil-military AI governance problem in miniature. Frontier models are dual-use by nature, built by commercial labs, and increasingly central to national security. Whoever sets the terms of their military use, the company, the Pentagon, or eventually Congress and the courts, is setting precedent for an entire industry. The Anthropic case is the first time that fight has played out on the public record with named principals and their own words.
What to watch
The lawsuit is ongoing, and its outcome will shape how far a vendor's ethical limits survive contact with a government customer. Watch the litigation over whether the supply-chain-risk designation was retaliatory, any move by Congress to define acceptable military AI uses in statute, and whether rival labs adopt or abandon comparable red lines. For now, one practical signal has already flipped: Fable 5 is back online, a sign that even a public rupture this sharp did not sever the underlying relationship.
"There is no distinction in our world between weapons that are defensive or offensive."— Emil Michael, Pentagon Undersecretary of Defense for Research and Engineering