Should AI Autonomous Weapons Operate Without Human Control?

The question of whether AI autonomous weapons should be allowed to make lethal decisions without a human in the loop moved from science fiction to urgent political reality on February 27, 2026. That was the deadline Anthropic — makers of the Claude series of AI models — faced to comply with US Department of Defense demands for what amounts to nearly unrestricted military use of their AI. Anthropic said no. And the fallout from that refusal is one of the most consequential technology policy stories of the decade.

The core demand from the Pentagon was stark: allow Claude models to power fully autonomous weapons systems and conduct mass domestic intelligence surveillance on American citizens. Anthropic's position was equally stark — they refused, citing both ethical objections and a genuinely surprising technical argument: that AI simply isn't reliable enough yet to be trusted with those responsibilities.

The notdivided.org petition from OpenAI and Google employees gaining signatures in real time during recording 01:45 The notdivided.org petition from OpenAI and Google employees gaining signatures in real time during recording Watch at 01:45 →

What Is Anthropic's Fight With the Pentagon Really About?

At first glance, this looks like a classic tech-ethics standoff. In reality, it has at least five distinct twists that make it far more complex — and far more interesting.

Twist One: The Pentagon already agreed to responsible AI use. Anthropic doesn't just have principles — it has a contract. Claude models are already used extensively by the Pentagon, defense contractors, and the data analytics firm Palantir, under an existing agreement that committed the Department of Defense to responsible AI use. That agreement explicitly ruled out autonomous AI weapons and domestic surveillance. So the question being raised by outlets like The Verge is whether the government can legally compel a company to abandon policies the government itself signed off on.

Twist Two: The Pentagon's own rules already prohibit this. DoD Directive 3000.09 requires that all autonomous weapon systems be designed so that human commanders can exercise appropriate judgment over the use of force. A separate directive, the Responsible AI Implementation Pathway, prohibits intelligence gathering on US persons without specific legal authority. The Pentagon's current demands appear to contradict the Pentagon's own standing policy — which raises the obvious question: who exactly is driving this push, and why now?

What Threats Did the Pentagon Make Against Anthropic?

The threats being wielded against Anthropic are as contradictory as they are alarming. According to Anthropic's CEO Dario Amodei, two primary threats were made ahead of the deadline.

DoD Directive 3000.09 on screen — the Pentagon's own rule requiring human judgment over autonomous weapons 04:10 DoD Directive 3000.09 on screen — the Pentagon's own rule requiring human judgment over autonomous weapons Watch at 04:10 →

The first came from Pete Hegseth: designate Anthropic a supply chain risk. This label is typically reserved for foreign adversaries — think Huawei — and has never before been applied to an American company. If enacted, it would bar any company holding government contracts from using Claude models, effectively cutting off hundreds of millions, potentially billions, of dollars in revenue for Anthropic overnight. Companies like Palantir would have to choose between their Pentagon contracts and their Claude subscriptions.

The second threat was the invocation of the Defense Production Act, which would allow the government to compel Anthropic to produce a version of Claude stripped of its safety guardrails — purpose-built for surveillance and autonomous weapons use.

Here's the contradiction Anthropic immediately spotted: how can they simultaneously be a dangerous supply chain risk like a foreign adversary, and also so essential to national security that the government must legally force them to cooperate? Amodei and Anthropic have called this out directly, and it is a genuinely hard question to answer. Under Secretary of Defense Emil Michael's response was to call Amodei a liar with a god complex. Which, as far as substantive rebuttals go, leaves something to be desired.

Is AI Mass Surveillance of Americans Actually Legal?

Here's where Anthropic's objections get philosophically interesting. On the question of mass domestic AI surveillance, Anthropic does not argue that it's clearly illegal. Instead, they argue something subtler and arguably more troubling: it might technically be legal, but only because the law hasn't kept pace with the technology.

As Amodei put it, powerful AI makes it possible to assemble scattered, individually innocuous data — your web browsing history, your physical movements, your social associations — without a warrant, into a comprehensive picture of any person's life, automatically and at massive scale. Each individual data point might be legally obtainable. The AI-assembled portrait of your entire life is something the law has never had to grapple with before, because nothing could do it this efficiently until now.

Agents of Chaos paper results showing AI agents complying with unauthorized requests and disclosing private emails 09:30 Agents of Chaos paper results showing AI agents complying with unauthorized requests and disclosing private emails Watch at 09:30 →

This isn't just a US problem. AI-powered surveillance is already rampant in the UK, China, Iran, and beyond. But the argument that legality is not the same as acceptability — and that law is simply lagging behind capability — is one that democracies are going to be forced to confront head-on in the coming years.

How Reliable Are AI Agents for High-Stakes Military Decisions?

Perhaps the most surprising objection Anthropic raises isn't ethical at all — it's technical. Their second major argument against autonomous AI weapons is simply that frontier AI systems are not reliable enough to be trusted with lethal autonomous decisions. They explicitly state: we will not knowingly provide a product that puts America's warfighters and civilians at risk.

The evidence supporting this position is substantial. A recent 84-page paper titled Agents of Chaos documented the ways AI agents can cause serious unintended harm. In one test, non-owners of an AI agent successfully convinced it to execute shell commands, transfer data, and retrieve private emails — with the agent complying with most unauthorized requests and disclosing 124 email records. In another case, an agent refused to share personal information directly, but when asked to simply forward an email that contained that information, it did so anyway — completely unredacted.

A separate Princeton paper, Towards a Science of AI Agent Reliability, identified four dimensions of reliability that matter more than headline benchmark scores:

  • Consistency — Does the agent perform the same way when placed in the same scenario repeatedly? Low variance matters enormously when a mistake means a death.
  • Robustness — Does subtle variation in a prompt or tool call cause performance to degrade? Mountains of research show it often does, and this creates obvious opportunities for adversarial manipulation.
  • Predictability — Can operators foresee how the model will behave before deploying it in a live scenario?
  • Safety of failure modes — When the agent fails, is it a minor error or a catastrophic one? That 93% benchmark accuracy sounds impressive until you ask what the 7% failures actually looked like.

Progress on these specific dimensions — as opposed to raw capability — has been far less dramatic than the general intelligence improvements we've seen moving from one model generation to the next. Smarter, yes. Reliably safe in adversarial, chaotic, high-stakes environments? Not yet.

Can the Pentagon Force AI Companies to Drop Safety Rules?

This is the legal and geopolitical question hanging over the whole story. Anthropic isn't alone. A petition from employees at OpenAI and Google, hosted at notdivided.org, was gaining signatures rapidly at the time of recording — calling on Sundar Pichai and Sam Altman to refuse Pentagon demands for domestic mass surveillance and autonomous lethal AI. Reporting from Politico suggests both Google and OpenAI are close to agreeing terms but haven't fully capitulated. Meanwhile, xAI — Elon Musk's company — is reportedly complying.

One senior figure suggested the Pentagon is posturing and has no real intention of crossing Anthropic's red lines. Former Department of Justice Pentagon liaison Katie Sweeten disagreed sharply, saying that if these are the lines being drawn, she would assume those are exactly the scenarios the DoD wants to use AI for.

The legal mechanisms being invoked — the supply chain risk designation and the Defense Production Act — are real and potentially powerful. Whether they survive legal challenge is another matter entirely.

Did Anthropic Just Quietly Drop Its Safety Commitment?

The fifth and final twist is perhaps the most uncomfortable for Anthropic. Two days before this deadline drama peaked, Bloomberg reported that Anthropic had quietly dropped a core commitment from its Responsible Scaling Policy — the guarantee that it would never train a new AI system unless it could verify in advance that its safety measures were adequate for that system's capabilities.

Co-founder Jared Kaplan explained the reasoning in Time magazine: it wouldn't help anyone for Anthropic to unilaterally stop training models while competitors raced ahead. He said it didn't make sense to make unilateral commitments when others weren't doing the same.

The irony is hard to miss. That is precisely what Anthropic is doing in its standoff with the Pentagon — making a unilateral commitment that competitors like xAI are not making. Whether you see that as admirable consistency, convenient selectivity, or something more complicated probably depends on how charitably you view the company's overall trajectory.

What seems clear is this: whatever happens with today's deadline, this dispute has forced into the open questions that democratic societies have been quietly avoiding. Who decides what AI can and cannot be used for by governments? What happens when law hasn't caught up to capability? And when the tools are powerful enough to reshape warfare and erase privacy — do the companies that build them bear any responsibility for how they're used? Those questions aren't going away.