The Vendor You Can't Use
What Anthropic's standoff with Washington teaches the Defense Industrial Base about supply chain risk.

Here's the uncomfortable question every contractor should be sitting with right now: what happens to your program when the government decides your AI vendor is a national security problem — and you're already built on top of them?
That stopped being hypothetical this year. In the span of four months, the U.S. government hit Anthropic with two different national security instruments, through two different agencies, for two different reasons. Neither was a fine. Both reached straight through the company and into the contractors downstream. If you build, secure, or accredit systems for the Defense Industrial Base, this is your story whether you wanted it or not.
Two letters, four months
February: the supply chain risk designation. After negotiations with the Pentagon broke down, Defense Secretary Pete Hegseth designated Anthropic a "supply chain risk," and the President ordered federal agencies to phase out the company's technology over six months. The sticking point wasn't price or performance. Anthropic held two red lines: no mass domestic surveillance of Americans, and no fully autonomous weapons without human control over targeting and firing. The Pentagon wanted access for "any lawful purpose." Anthropic said no, and got blacklisted for it.
That designation matters because of the machinery behind it. It runs on FASCSA and 10 U.S.C. § 3252 — authorities built to push foreign adversaries like Huawei and Kaspersky out of federal supply chains. Anthropic is the first American company to wear the label. And the practical effect lands on you: a supply chain risk designation can require defense contractors to certify they don't use the vendor's products in their government work. Your compliance posture, rewritten by someone else's negotiation.
Anthropic sued in March on administrative-procedure, First Amendment, and due-process grounds. A federal judge in San Francisco called the measures arbitrary and capricious and warned they could cripple the company, in one opinion rejecting the idea that an American firm can be branded a saboteur simply for disagreeing with the government. Then in April, a D.C. Circuit panel declined to pause the blacklisting while the case proceeds — acknowledging likely harm to Anthropic but calling it primarily financial — and ordered the dispute expedited. As of now, it's unresolved and moving through the courts.
June: the export control directive. Days after Anthropic released its most capable models — Fable 5 and the cyber-focused Mythos 5 — the Commerce Department's Bureau of Industry and Security ordered the company to suspend access for any foreign national, anywhere, including its own international employees. Unable to reliably screen users by nationality, Anthropic shut both models off for everyone. First time export controls have been used to pull a major lab's frontier models off the shelf.
The trigger is contested, and that's worth saying plainly. Reporting points to a "jailbreak" concern reportedly raised by Amazon's CEO — essentially getting the model to read a codebase and surface software flaws. Anthropic says the technique is narrow, that the flaws it found were minor and already known, and that other public models do the same thing every day. More than 70 cybersecurity practitioners signed a letter arguing the move took the best tools away from defenders. A separate, single-sourced claim about a China-linked group accessing Mythos is disputed and unconfirmed. The directive letter itself hasn't been made public, so most of the rationale is known secondhand. Read it as a developing story, not a closed case.
Why this lands on the DIB
Strip away the politics and you're left with a procurement and accreditation problem.
The DIB spent the last two years racing to embed AI into workflows — drafting, triage, code review, analysis. Anthropic was an easy default: first frontier lab on classified networks, deep agency adoption, strong safety posture. That adoption is exactly what makes a designation hurt. When the dependency is everywhere, the blast radius of one government letter is everywhere too.
And notice the pattern: two separate authorities, built for foreign threats, aimed at a domestic vendor inside a single year. Supply chain risk for how the model can be used; export control for what the model can do. A contractor sitting downstream doesn't get to litigate either one. You inherit the consequences and the certification language, with little notice and no vote.
The governance lesson
This is what concentrated decision authority looks like when it sits outside your organization. You can run a flawless internal AI governance program — authority mapped, human override defined, accountability documented — and still wake up to a vendor decision made three levels above you that invalidates your stack. Internal control is necessary. It is not sufficient.
The fix isn't predicting which vendor gets sanctioned next. Nobody can. The discipline is structural: know where your single points of failure are before someone else discovers them for you.
What to do Monday morning
Concrete, not theoretical:
Inventory the dependency. Which programs, pipelines, and accredited systems touch a single AI vendor? If you can't answer in an afternoon, that's the finding.
Pressure-test the certification language. If a supply chain designation required you to certify non-use tomorrow, could you comply without halting delivery? Walk that path on paper now.
Build a real fallback, not a slide. Model portability and a tested second source are resilience controls, not procurement nice-to-haves.
Separate capability from access. The Mythos episode shows access can vanish on a Thursday afternoon. Don't design a workflow that only functions with the most capable model in the world.
Brief leadership in risk terms, not AI hype. This is concentration risk and continuity-of-operations risk. Frame it where the board already lives.
The companies that come through this aren't the ones who picked the "right" vendor. They're the ones who assumed any vendor could become the wrong one overnight — and built so a single letter from Washington couldn't take the program down with it.
The opinions and content creation expressed in this article are my own and do not reflect those of my employer. This content is intended for informational purposes only and is based on publicly available information.




Comments