Skip to main content
Live
Main content

AI warfare is already here as Anthropic fights Pentagon over autonomous weapons

The DOD has embedded AI in military operations for 70 years; fully autonomous lethal systems remain the final frontier.

Jaeden Schafer
Editor in Chief · · 5 min read
Anthropic logo

Anthropic is fighting the Pentagon over two red lines: no domestic mass surveillance and no weapons that can identify, track, and kill targets with zero human involvement. The standoff began in January 2026 when Defense Secretary Pete Hegseth demanded contract renegotiations allowing the DOD to use contractor AI for any lawful use, erasing prior limits. Anthropic refused, and the Pentagon designated it a military supply chain risk in March 2026, with President Donald Trump temporarily banning federal agencies from using Claude.

The dispute has thrust fully autonomous weapons into public debate, but AI has been embedded in US military operations for 70 years. The DOD funded early AI research in the 2000s to parse unprecedented surveillance data, and by the late 2010s, advanced facial recognition and machine vision systems were in active deployment. Project Maven, launched in November 2017, used AI to analyze drone footage and drew Google as a contractor before employee backlash forced the company out.

At the Convention on Certain Conventional Weapons in Geneva that November, attendees watched Slaughterbots, a short film depicting AI drones executing precision kills without human oversight. The video crystallized a fear that had been abstract: the technology was no longer hypothetical. Platforms with autonomous targeting capabilities already existed in 2017, waiting only for policy to catch up.

Key facts

  • 01Anthropic is the only military AI contractor to ban domestic mass surveillance and fully autonomous lethal weapons.
  • 02The Pentagon designated Anthropic a military supply chain risk in March 2026 after contract renegotiation failed.
  • 03DOD Directive 3000.09, written in 2012, defines autonomous weapons as systems that select and engage targets without human intervention.
  • 04The Phalanx CIWS missile defense system responds in milliseconds, operating without humans in the loop.
  • 05AI kill chains now compress decision cycles to mere seconds, raising questions about compliance with international humanitarian law.

DOD Directive 3000.09, written in 2012, remains the primary policy governing lethal autonomous weapons. It defines such a system as one that can select and engage targets without further human intervention once activated, and mandates that humans exercise appropriate levels of judgment over the use of force. The language is vague enough to accommodate systems that technically comply while eroding meaningful human control.

The Phalanx CIWS, an automated gun system designed to defend naval vessels from incoming missiles, responds in milliseconds without a human in the loop. Some experts argue it does not violate the directive because it operates in a fixed, defense-only environment, engaging threats but not deciding which targets to pursue. That interpretation hinges on reading the directive's and as requiring both selection and engagement autonomy simultaneously, not either one alone.

The distinction between defensive and offensive systems is equally slippery. A nuclear weapon in a silo can be framed as defensive deterrence or offensive strike capability depending on the speaker. Just because a system's primary function is defensive does not make the technology itself non-offensive.

We've kind of crossed the rubicon while we pretend that we haven't.
Andrew Reddie, Associate research professor of public policy at University of California, Berkeley

The Chief Digital and Artificial Intelligence Office issued an update to DOD Directive 3000.09 in 2023, but the core ambiguities remain unresolved. The Biden administration published a national security AI memorandum in 2024, still in force under Trump, but the CDAO itself has been restructured and now reports to Emil Michael, the DOD's undersecretary of research, isolating it further from broader Pentagon oversight.

AI is compressing kill chains to timescales that preclude meaningful human assessment of targets. When those compressed cycles result in civilian deaths, the failure to comply with international humanitarian law crosses into war crime territory. The technology exists; the policy lags decades behind.

Related · from this week
Judge strikes down Pentagon's Anthropic blacklist as illegal retaliation
Jaeden Schafer · 5 min read →

Anthropic is unusual among Pentagon contractors for setting use-case limits at all. The company is not a traditional defense supplier like Northrop Grumman, nor is its AI government-created technology like the Manhattan Project. Silicon Valley's startup ecosystem engaging directly with the DOD creates friction over who sets the boundaries, and there is deep disagreement even within the tech industry over where those boundaries belong.

Anthropic released Mythos, a cybersecurity-focused model, and the relationship with the Pentagon has warmed slightly, but the court battle continues. Whether the company's red lines hold is unclear. The broader pattern is not: AI has crept deeper into military operations every decade since the 2000s, and the rubicon has already been crossed while the policy pretends otherwise.

The stakes are whether AI models will be constrained by meaningful human oversight or whether the definition of autonomy will stretch to accommodate whatever the technology enables. History suggests the latter. Fully autonomous lethal weapons remain the stated red line, but systems that decide or engage separately are already deployed, and the and doing the work in DOD Directive 3000.09 may not survive contact with the next generation of models.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Judge strikes down Pentagon's Anthropic blacklist as illegal retaliation

A federal judge vacated the Department of Defense's supply-chain risk designation, calling the sanctions across nine agencies baseless and unconstitutional.

Jaeden Schafer5 min read
Anthropic logo
Business

Anthropic hits near-$1T valuation while warning AI could destroy the world

Founded in 2021 by OpenAI defectors, Anthropic now sells Claude to the Pentagon and argues that dominating AI is the only way to make it safe.

Jaeden Schafer5 min read
Anthropic logo
Security

Anthropic accuses Alibaba of 28.8M-query distillation attack on Claude

A letter to the Senate Banking Committee calls it the largest known distillation attack on Anthropic to date.

Jaeden Schafer5 min read