In February, the Pentagon designated Anthropic a "supply chain risk," triggering a government-ordered phase-out of its tools. Its latest lawsuit challenges the designation as unconstitutional retaliation, but the security concerns behind it apply just as much to OpenAI, whose new model the same government subjected to a delayed, limited rollout over national-security concerns.

Anthropic's complaint, filed in March, walks through the sequence. The company refused to loosen its restrictions on surveillance of US citizens and on autonomous weapons that kill without human oversight. Defense Secretary Pete Hegseth then designated Anthropic a "supply chain risk," which forced military contractors using Claude to drop it.

President Trump was more direct about the reasoning. "Well, I fired Anthropic. Anthropic is in trouble because I fired [them] like dogs, because they shouldn't have done that," he said in remarks quoted in the complaint.

Inside the Pentagon, officials seemed to disagree with their own boss. Senior DoD officials cited in the lawsuit called the designation "ideological rather than an accurate description of risk." One put it more bluntly: "The only reason we're still talking to these people is we need them and we need them now. The problem for these guys is they are that good."

Now for the awkward part. A letter from Senator Elizabeth Warren points out that OpenAI has the same holes Anthropic refused to have. Citing a Legal Advocates for Safe Science and Technology analysis, the letter argues OpenAI's contractual language on autonomous weapons "does not do anything at all to constrain" the Pentagon from using GPT models to build them. The Atlantic, also cited in the letter, notes that OpenAI's data collection language uses words like "intentionally" and "deliberate" that "provide substantial leeway for data collection that is deemed 'incidental.'"

Then there's the model itself. In its GPT-5.6 system card, OpenAI states plainly that "there is no such thing as perfect security. New weaknesses will be discovered, as will new jailbreaks that circumvent existing safeguards." The company dedicated over 700,000 GPU hours specifically to hunting universal jailbreaks in the model before it launched. They still found them.

That admission matters more than it used to because GPT-5.6 is meaningfully better at cyber tasks than the models before it:

Anthropic's CEO Dario Amodei was asked about the standoff on CBS News in February. He framed the two restrictions Anthropic wouldn't drop as red lines the company had "from day one" and wasn't going to move on. "Disagreeing with the government is the most American thing in the world," he said.

Into the Valley

Read the two situations next to each other and the pattern is uncomfortable. Anthropic got shut out not because Claude was more dangerous than GPT-5.6, but because it wrote its safety rules into the terms of service in a way the Pentagon couldn't quietly route around. OpenAI wrote its safety rules with enough wiggle room that the government never had to fight about it. The lesson every lab is taking from this isn't that safety is expensive. It's that being specific about safety is expensive, and being vague about safety is not.