Skip to content

Invest1 publisher2 min readPublished

Pentagon's reported break with Anthropic reaches 90% of classified AI workloads in eight months

Crypto Briefing dates the supply-chain risk designation to early 2026 and the near-complete migration to mid-September. So far it rests on one publisher's account.

The Investor · Invest desk

Photograph accompanying Pentagon's reported break with Anthropic reaches 90% of classified AI workloads in eight months
Photo: defensescoop.com

What happened

  • Crypto Briefing reports that the Department of Defense designated Anthropic a national security supply-chain risk in early 2026, citing the company's refusal to grant unrestricted access for all lawful government use.
  • By mid-September 2026 the department had moved roughly 90% of its classified AI workloads off Anthropic's closed-source systems, with the remainder due to follow by the end of the month.
  • Nvidia had already formed the Open Secure AI Alliance in July 2026, a coalition arguing that open-weight models belong in national security applications because they can be inspected.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • decision Nobody can act on a workload percentage without a revenue denominator, so the disclosure that would matter next is Anthropic's federal exposure, from the company or from a contract award.
  • capability A model family designed so sensitive data never leaves the customer's network, paired with an integrator already inside classified systems, gives agencies an inspection right no hosted API vendor can offer.
  • precedent If auditability is the argument that wins classified procurement, any open-weight family qualifies on the same grounds, and swapping model providers stops being a commercial negotiation.

The schedule is the first thing I would test. Crypto Briefing dates the supply-chain risk designation to early 2026 and puts the migration at roughly 90% of classified AI workloads by mid-September 2026 [1][2]. Call it eight months for 90 points of workload share, or about 11 points a month [1]. Completion is targeted for the end of that month [3], leaving the last 10 points about two weeks, a run rate near 20 points a month, roughly double the average pace [2]. In my view the final tranche is the slow one.

Crypto Briefing's account does not include a contract value, a named Pentagon official, or a statement from Anthropic, Nvidia, Palantir or Booz Allen [13]. It works in workload share throughout.

Booz Allen Hamilton's Cyber Weapon Index, published in early September 2026, showed that Anthropic's Claude Mythos model could autonomously execute full cyber kill chains on enterprise networks [4]. Crypto Briefing's reading is that a model with that capability needs to be something you own and control, not something you rent from a company that might revoke access or change its terms [5]. Anthropic's usage policies prohibit categories including mass surveillance and autonomous lethal systems [6]. An open-weight model hosted inside a classified network has the same offensive capability and fewer prohibitions attached to it.

Two of the three vendor moves are dated and self-announced. Nvidia formed the Open Secure AI Alliance in July 2026 to argue that transparency and auditability are security features in national security work [10], and on 10 September 2026 Nvidia and Palantir announced a partnership on sovereign AI for supply chains [9]. Nemotron is built for controlled deployments where sensitive data never leaves the customer's network [7], and Palantir supplies the intelligence-community and military-logistics integration [8]. The same companies described as raising the concerns are the ones filling the gap: Nvidia, Palantir and Booz Allen are all restricting or replacing Anthropic model use in their own defense-oriented operations, according to the report [11].

The designation may be real and documented, in which case the figure to chase is Anthropic's federal revenue. Or "migrated off" means demoted from a default position in agencies that run several models, a smaller event than a ban. Or a trade publisher has assembled two dated vendor announcements and a consultancy's benchmark into a formal designation nobody has produced. I would weight the July alliance and the September partnership as the checkable parts and hold the 90% until a procurement document carries it. Meta's Llama models, also open-weight, could benefit from the same tailwinds pushing Nemotron into defense work, the report says [12].

What to watch

  • A DoD procurement document or a named official confirming the supply-chain risk designation.
  • Any federal award to Nvidia or Palantir that names Nemotron in a classified deployment, with a contract value attached.
  • Whether the end-of-September completion date is met or slips, since the last tranche is the hardest to move.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories