UPDATE (Mar. 26, 2026):  After publication of this article, a federal court in one of the two Anthropic v. US DoW cases granted Anthropic a preliminary injunction halting DoW’s supply chain risk designation.  The injunction is stayed for a week to allow the government time to appeal, and a ruling in the second Anthropic challenge remains pending.

Anthropic and the U.S. federal government are right now locked in courtroom combat over the government’s ability to exclude the AI company from government contracts for seeking to impose limits on how its tools are used. In a March 24 hearing, a federal judge expressed serious concern that the government may be illegally punishing and retaliating against Anthropic for exercising its free speech. 

However Anthropic’s lawsuit turns out, this conflict exposes a major risk for AI companies as well as companies that simply use AI in their operations. That risk will not go away even if Anthropic prevails. The government has many tools available to it to prevent AI businesses from imposing guardrails on how their models are used. These include a newly proposed set of default contract terms that could affect AI companies, whether or not they do business directly with the U.S. government, as well as potentially costly civil and criminal litigation tools that have not yet been publicly unleashed. 

The Anthropic case and this new contract language have implications for all AI businesses and businesses that use AI, whether or not they make AI tools themselves or do business directly, or even indirectly, with the U.S. government. 

To mitigate these risks, businesses that touch AI need to ensure their compliance and legal departments are familiar with these new rules and policies; take steps to educate their executive, sales and product teams on procedures for dealing with potential ethical issues raised by government demands; and set up internal reporting processes so that issues are detected and managed early.


The conflict between Anthropic and the U.S. government arose from a contract awarded to Anthropic in July 2025 to prototype “frontier AI capabilities that advance U.S. national security.” Under the agreement, Anthropic developed government models of its Claude system designed to support national security users and operate in classified environments. 

During negotiations over the scope of the agreement, the Department of War (DoW) reportedly insisted that Anthropic’s technology be available for all lawful government uses. Anthropic objected to certain potential applications, including the use of its systems to support mass domestic surveillance or fully autonomous lethal weapons.

When negotiations failed to resolve these issues before a February 27, 2026 deadline, the Trump administration ordered federal agencies to cease using Anthropic products. Shortly thereafter, Defense Secretary Pete Hegseth designated Anthropic a “supply chain risk,” a label historically applied to foreign adversaries and companies viewed as security threats. The designation effectively barred Anthropic from DoW contracting and required defense contractors performing Pentagon-related work to certify that they were not using Anthropic technology.[1]

Anthropic filed two suits against the DoW and other agencies, arguing that the designation was unprecedented, unlawful and retaliatory.[2] The company alleges violations of the Administrative Procedure Act as well as constitutional protections including due process and free speech. Anthropic has sought prompt judicial review, citing the immediate operational and contractual consequences of the designation. 

At the March 24 hearing on Anthropic’s request for preliminary injunctive relief, the court reportedly expressed concern about the government’s actions, characterizing aspects of the designation and its consequences as “troubling” while emphasizing that the matter remained under active consideration.[3]

Against this backdrop, in March 2026, the General Services Administration (GSA) proposed a new standardized contract clause for incorporation into the Multiple Award Schedule (MAS) program — a government‑wide contracting vehicle under which the GSA pre-negotiates pricing and terms for commercial products and services that federal agencies may purchase using streamlined procedures.[4] At present, this clause would not apply to all contractors, but it could serve as a model to be incorporated into contracts by the DoW and other agencies. The new language remains open for comment from the public through April 3.                

The proposed clause would require contractors to use only “American AI Systems” (i.e., AI systems developed and produced in the United States), disclose all AI systems used in contract performance, enable government oversight, report AI‑related incidents within 72 hours and — most notably — permit government use of covered AI systems for any lawful government purpose, notwithstanding conflicting commercial license terms.[5]

The proposed clause also contains several technical provisions that may be particularly significant for AI companies. Among other things, the clause would:

  • restrict contractors from using government data or AI system outputs generated in contract performance to train, fine‑tune or otherwise improve commercial models; 
  • require contractors to provide the government with access, auditability and documentation sufficient to evaluate AI system behavior and compliance; 
  • impose short‑fuse incident reporting obligations; 
  • prohibit contractors from relying on discretionary output‑filtering or use‑based controls to limit how the government uses covered AI systems; and
  • prohibit any sort of “manipulation” of models that the government perceives to be driven by diversity, equity and inclusion principles.

Collectively, these requirements could have meaningful implications for model architecture, data segregation practices, licensing terms and internal governance frameworks for companies selling AI capabilities through applicable GSA contracts.

Of particular significance, the proposed clause would place responsibility on contractors for AI systems used in contract performance, including systems provided, operated or licensed by third-party “AI service providers.” It would require contractors to ensure that their use of third‑party AI systems — whether supplied by subcontractors or commercial vendors — complies with the clause’s requirements, effectively pushing compliance obligations down the supply chain.

Know your contracts — in detail

AI companies doing business with the U.S. government, or with prime contractors and subcontractors for the government, should ensure that their legal and compliance teams, executives, product and sales teams, and others on the front line with the government have a clear understanding of the government contracts they are entering into or have already entered into. 

In particular, where a contract permits “all lawful uses,” companies should assume that government customers will interpret that language broadly as carte blanche to use the tools in whatever manner they wish and that the government will take action against contractors that take any steps to try to enforce that “lawful uses” limit to prohibit activity the contractor may believe to be unlawful. 

To the extent contractors are able to obtain more flexibility to create guardrails on limitations on their tools, they should be entitled to rely on those. But they should be clearly documented in formal contracts or in directions from authorized contracting officers. Contractors should be wary of simply accepting oral commitments or even written agreements coming from individuals without sufficient legal authority. And even if the AI business obtains formal commitments, that is still no guarantee the government will not change its mind. 

Escalate concerns early

In this environment, employees who interact with government customers — including engineers, product managers, sales staff and legal teams — should be trained to escalate concerns about uses or misuses of technology by or at the direction of the government. This includes uses that may raise significant legal, regulatory or compliance risks, including ethical considerations. Companies may consider providing anonymous tip line mechanisms like those that exist for other compliance issues. Rapid internal escalation allows senior leadership and counsel to assess risks before disputes arise with government customers and should be encouraged. 

Early and positive engagement with employee concerns is critical. It can help prevent situations in which employees feel forced to either comply with problematic directives or resist them without sufficient institutional support, while also allowing the company to manage risk for directors, officers, employees and the company itself. Engaging with concerned employees, to the extent possible, also reduces the risk that employees feel ignored and take steps against the company, including bringing litigation under not just employment laws but also the federal False Claims Act (FCA). 

Seek legal opinions whether you intend to comply or not

Where a contractor believes that government direction may raise legal or regulatory concerns, the governing regulations provide structured mechanisms to elevate and resolve those issues. As a general matter, only a duly authorized contracting officer has the authority to bind the government or direct changes in performance, and contractors may act at risk when relying on instructions from other government personnel.

If a contractor intends to comply with a request that it believes raises legal or ethical questions, one option is to request clarification or written direction from the authorized contracting officer. The rules contemplate that contracting officers will coordinate with legal counsel and issue written determinations when questions arise regarding contractual obligations or authority.[6] Elevating concerns through this process can help ensure that performance decisions are grounded in authorized government direction rather than informal or potentially ultra vires requests. This is particularly important to protect the AI business from claims brought later by individuals affected by the government action using the companies’ tools. 

Government contractors are not required to comply with directives that would require them to violate the law. Although contractors may sometimes rely on a “following orders” defense when acting under government authorization, that defense generally applies only when the government directive itself is lawful.

Where a contractor believes that compliance would require unlawful conduct and does not intend to comply, obtaining a contemporaneous legal assessment from outside counsel is a key, if not bulletproof, form of protection. While advice of counsel is not necessarily a complete defense, if a company obtains advice from counsel that the order it has received is unlawful, that could serve at a minimum as a defense to a FCA or criminal allegation that the company knowingly violated the law. It will also help inform the contractor about its likely ability to seek contractual relief from the government if the government takes contract actions, such as termination, against the contractor.

In all cases, contractors are generally better positioned when concerns are framed as compliance and authority questions, documented contemporaneously and routed through established FAR or DFARS processes rather than addressed through unilateral technical or operational decisions.

Avoid unapproved technical guardrails

Companies should also be wary of implementing covert technical measures designed to circumvent contractual obligations unless they have clear contractual authority to exercise discretion in implementing guardrails on their tools. 

While developers may wish to impose additional safety guardrails on AI systems, implementing restrictions that deprive the government of agreed-upon functionality could raise significant legal concerns, particularly where contractors have certified compliance or where standardized procurement clauses purport to override commercial licensing or internal usage policies. Such actions could potentially constitute breach of contract or, in certain circumstances, expose the contractor to liability under the FCA or, worse, to criminal prosecution.[7]

Before implementing technical controls that limit system functionality, companies should evaluate whether those controls are consistent with their contractual commitments and clearly disclosed to government customers. And software developers and program managers should be informed that such efforts expose them to severe personal liability. If the contractor does not wish to comply, the safer option would be to pursue termination of the agreement, seek court intervention, or take other similar steps rather than trying to sneak in fixes.

Prepare for whistleblower claims and reputational risk

Given the sensitivity of AI deployments in defense and national security contexts, companies should ensure that internal reporting mechanisms are well established and trusted by employees. Federal law provides protections for employees of federal contractors who report misconduct related to government contracts.[3] Under 41 U.S.C. § 4712, employees of contractors, subcontractors and grantees are protected from retaliation when they disclose evidence of waste, fraud, abuse of authority or violations of law related to federal contracts or grants.

Organizations should therefore ensure that employees understand how to raise concerns internally and that leadership has a clear strategy for addressing situations in which government requests may raise legal or ethical issues. Implementing a robust confidential reporting system and a culture of protecting good-faith whistleblowers is in the best interest of companies because it will lead employees to speak out early.

Maintain clear documentation

Contractors should maintain clear documentation regarding government direction and authorization from individuals with the legal authority to give the direction requested, such as a contracting officer. This may include:

  • written records of government instructions regarding AI deployment;
  • documentation of discussions regarding scope, safeguards or limitations; and
  • formal modification processes for any changes to contractual obligations.

Clear documentation helps protect contractors if disputes later arise regarding whether a particular use was authorized or whether a contractor exceeded the scope of its obligations. Such documentation should be maintained in formal contract files or compliance systems rather than informal communication platforms such as Slack, Teams and WhatsApp.

Understand certification and supply chain obligations

The Anthropic dispute also highlights the importance of carefully reviewing certification requirements and supply chain risk obligations imposed by government agencies.

Defense contractors may be required to certify that they are not using technologies designated as supply chain risks or otherwise restricted by federal policy. Contractors should ensure that certifications accurately reflect the scope of their operations and avoid making assurances that extend beyond what the contract or regulation requires.

Where requirements are unclear, seeking clarification from contracting officers in writing is often preferable to making assumptions that later prove incorrect.

All AI companies, and all companies that use AI, need to monitor the Anthropic dispute, be cognizant of their dealings with the U.S. government (direct or indirect) and set up systems now to deal with the possibility that their tools may be used in ways they are not comfortable with. Taking care to set up those systems and educate employees now, even for early-stage AI startups, will be key to avoiding serious legal and ethical concerns later.


Endnotes

[1] See U.S. Gen. Servs. Admin., “GSA Stands with President Trump on National Security AI Directive” (Feb. 27, 2026), https://www.gsa.gov/about-us/newsroom/news-releases/gsa-stands-with-president-trump-on-national-security-ai-directive-02272026; Complaint for Declaratory and Injunctive Relief ¶¶ 1, 8-12, 104-106, Anthropic, PBC v. U.S. Dep’t of War et al., No. 3:26-cv-01996 (N.D. Cal. filed Mar. 9, 2026), https://www.courthousenews.com/wp-content/uploads/2026/03/anthropic-supply-chain-risk-lawsuit.pdf.

[2] See id., ¶¶ 1, 12-17, 88-103.

[3] See Nathan Bomey, “Judge questions Pentagon's ‘troubling’ Anthropic actions,” Axios (Mar. 24, 2026), https://www.axios.com/2026/03/24/judge-pentagon-anthropic-troubling; see also Shirin Ghaffary, “Judge says it looks like Pentagon was out to 'punish' Anthropic, not protect national security,” Business Insider (Mar. 24, 2026), https://www.businessinsider.com/anthropic-supply-chain-risk-hearing-judge-pentagon-pubish-cripple-2026-3.

[4]  552.239-7001 Basic Safeguarding of Artificial Intelligence Systems, https://buy.gsa.gov/interact/system/files/GSA_Federal_Acquisition%20Service%20Proposed%20Government%20AI%20System%20Terms%20and%20Conditions.pdf.

[5]  Ryan E. Roberts & Townsend L. Bourne, “GSA’s New Proposed ’American AI‘ Clause for Schedule Contracts: What Contractors Need to Know,” Nat’l L. Rev. (Mar. 12, 2026), https://natlawreview.com/article/gsas-new-proposed-american-ai-clause-schedule-contracts-what-contractors-need-know.

[6] See generally Federal Acquisition Regulation (FAR) pt. 33 (Contract Disputes and Appeals) and applicable agency supplements, including FAR §§ 33.204 and 43.102, and applicable agency supplements, including the Defense Federal Acquisition Regulation Supplement (DFARS).

[7] See 31 U.S.C. §§ 3729-3733 (FCA) (imposing liability for material false certifications or fraudulent claims submitted to the federal government).

[8] See 41 U.S.C. § 4712 (prohibiting retaliation against employees of federal contractors, subcontractors, and grantees for protected disclosures).


Key contacts

Austin Manes photo

Austin Manes

Special Counsel, Privacy Counsel, Silicon Valley

Jane Jacobs photo

Jane Jacobs

Senior Associate, Washington, DC

Shreya Ramchandani photo

Shreya Ramchandani

Associate, Silicon Valley

Stay in the know

Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead

Subscribe now
Washington, DC New York Silicon Valley Artificial intelligence Emerging technology Litigation and dispute resolution Defence and national security Government and public sector AI and Emerging Technologies Ralph C. Mayrell Austin Manes Jane Jacobs Shreya Ramchandani