Standing Record · Falsifiable · Dated · Kept

Switched Off Without a Standard

Over four months the U.S. government subjected the AI company that refused the Pentagon's unlimited-use demand to an extraordinary punishment. A dated record of the sequence — including the facts that complicate it — with the government's account given equal weight.

Filed 2026·06·16 Method AI-assisted, sources linked Status All conditions open

While the week's oxygen went to a two-trillion-dollar IPO and a cage match on the White House lawn, a quieter sorting was finishing. Over four months the government banned the one AI company that refused to let its models surveil Americans or guide autonomous weapons1. Other firms reached deals instead — including one that drew the same red lines Anthropic did, the fact that keeps this from being a tidy story.2 June's worldwide halt of Anthropic's two newest models3 came four months later; the government frames it as a separate cyber matter, and it landed the same week a rival's parent rode public markets to new heights.4 This record sets the sequence down, with the government's account given equal weight and the awkward facts left in. It does not assert why. It lays out a pattern consistent with a field being sorted by willingness to be used against citizens, and the evidence that complicates that reading — and writes down what would confirm or break it.

The four-month pattern

The break came in February 2026, after Anthropic refused to let Claude be used for mass surveillance of Americans or to guide autonomous weapons; the Pentagon wanted the technology usable for all lawful purposes without a vendor's limits.1 When Anthropic held its line, the administration ordered every agency to stop using it and designated the company a "supply chain risk" — a label normally reserved for foreign adversaries — and pulled it from federal procurement.5 The Pentagon's own officials reportedly called the designation "ideologically driven," with "no evidence of supply chain risk."6 Anthropic sued, calling it an "unlawful campaign of retaliation" for protected speech; the litigation is ongoing.2 Within hours of the punishment, OpenAI reached its own Pentagon agreement — but reportedly wrote in the same limits on domestic mass surveillance and autonomous force that Anthropic had insisted on, which cuts against any simple punished-for-drawing-limits reading.2 xAI's Grok, which took broader terms, had signed weeks earlier, before the ban. The clean story does not survive those two facts; what survives is narrower and still striking — Anthropic alone drew a designation normally reserved for foreign adversaries. The June halt of Fable 5 and Mythos 5 came four months later.

The government's account, given equal weight

The state's case is not nothing, and a record that hides it is a brief. Officials describe a genuine dual-use danger: the halted capability finds software vulnerabilities, which means it can also help exploit them. The documented trigger was a warning that a partner had jailbroken Fable 5, alongside concern that access to the more capable Mythos class had reached foreign, reportedly China-linked, hands, with model-distillation a further risk. A White House adviser said the controls were issued "reluctantly" after Anthropic declined to fix or pull the model, that the hope is remediation and a lifting of the controls, and — notably — that June was not tied to the February Pentagon dispute.3 Anthropic disputes the characterization, calling the findings minor, known, and reproducible on other public models. Both can be true: a defensible security concern and a months-long retaliation can occupy the same action, and the public record does not cleanly separate them.

Why it isn't the symmetry it looks like

The tidy version — government bans the careful model, shields the harmful one — does not survive inspection, and the record is stronger for saying so. The Justice Department's intervention on the harmful model's side is in a Colorado case, on Equal Protection grounds against an anti-bias law; it is not a shield for that model's documented harms.7 Those harms — nonconsensual deepfakes and alleged CSAM — are being litigated by California, not waved through by Washington.8 And the same administration publicly feuded with that rival's owner in 2025. The alignment that survives all of that is narrower and stranger than favoritism: a sorting by willingness to be used against citizens, regardless of who is liked.

The rule nobody has written

What makes the pattern legible is the absence of the one thing that would let an outsider check whether like cases are treated alike: a published, uniform, capability-based standard, applied to every provider, with a stated technical basis and an independent right of review. It is the remedy the company, security practitioners, and the public could all endorse — and the only version that survives is the universal one. A quiet, company-specific restoration with no general standard would confirm the discretion-tracks-power reading and void the public-interest claim.

The stake

Strip the names away and the capabilities now exist across cooperating vendors and the state: AI tools usable for surveillance, a citizen-data supply open-sourced where it isn't quietly scraped, and a practiced narrative-and-legal apparatus. Whether they are turned on the public before the next election is the open question; that the capabilities exist is not. The record exists so that if the answer comes, it comes against something already written down.

The ledger — what would confirm it, what would break it

  1. Restoration via a transparent, uniform, cross-provider standard. Supports the rule-not-discretion reading. Open.
  2. Restoration via a quiet, company-specific arrangement, no general standard. Supports discretion-tracks-power; voids the public-interest claim. Open.
  3. The defensive capability stays dark while the documented harms are litigated only at the state level. Sharpens the public-cost question. Open.
  4. A published technical basis appears and is capability-general, not provider-specific. Would weaken this record's central claim; revise accordingly. Open.

Sources

  1. [1] Nextgov/FCW; Mayer Brown (Feb–Mar 2026) — the dispute began with Anthropic's refusal of mass-surveillance and autonomous-weapons use; the Pentagon's "all lawful purposes" demand.
  2. [2] Associated Press, via Euronews (Mar 9, 2026) — Anthropic's suit citing "unlawful campaign of retaliation" for protected speech; a rival signing its own Pentagon deal within hours; litigation ongoing.
  3. [3] Anthropic statement; WSJ via Sherwood; David Sacks public statement (Jun 12–13, 2026) — the June export halt; the dual-use cyber capability; the government's "reluctantly / remediate-then-lift" account.
  4. [4] Morningstar via CNBC; Seeking Alpha (Jun 2026) — the rival's parent reaching a ~$2 trillion public valuation the same week; immediate "significantly overvalued" assessments.
  5. [5] Mayer Brown; FedScoop (Feb–Mar 2026) — the agency-wide cease-use order, the "supply chain risk" designation, and removal from GSA procurement (OneGov, USAi).
  6. [6] Government Contracts Law (Haynes Boone) (Mar 2026) — Pentagon officials on record calling the designation "ideologically driven," "no evidence of supply chain risk."
  7. [7] Norton Rose Fulbright (Apr 2026) — DOJ intervention on xAI's side in the Colorado SB24-205 case on Equal Protection grounds; not a harm shield.
  8. [8] California DOJ; Doe 1 et al v. X.AI Corp. (N.D. Cal., 2026) — AG Bonta cease-and-desist; the deepfake/CSAM harms litigated at the state level.