When a government leans on your AI vendor
How government buying, export rules and contractor bans reach your own AI account, and how to arrange your work so none of them costs you a week.
on this page · 0 / 0 checked
Nothing about your Tuesday changes when a defence department sends a letter to your AI vendor. Then one morning the model you built a week around is not in the picker, or a client asks you to confirm in writing that you did not use it on their work. Neither of those arrives with notice, and neither is a thing you can appeal. You were not in the argument.
This is the part of using rented intelligence that no pricing page describes. Your assistant is a consumer product with a national-security annex attached, sold to agencies under contracts whose use restrictions the vendor says it tailors but does not publish [1], subject to export controls that can be applied overnight [6], and occasionally the subject of a fight between a large buyer and a vendor. This guide is about what those fights actually do to a one-person business or a small team, which is less than the headlines suggest and more than nothing, and about the small number of habits that make the difference. It is not for anyone who holds or subcontracts on a government contract with real compliance obligations, who needs counsel rather than a guide, and nothing here is legal advice.
A government reaches your account through 3 levers
The first lever is money. Agencies buy AI, and buying comes with terms. In the United States, Executive Order 14319 of 23 July 2025 directs agencies to “procure only those LLMs developed in accordance with” 2 Unbiased AI Principles: truth-seeking, meaning “LLMs shall be truthful in responding to user prompts seeking factual information or analysis”, and ideological neutrality, meaning “LLMs shall be neutral, nonpartisan tools that do not manipulate responses in favor of ideological dogmas such as DEI” [3]. That is a customer specifying how the product should behave, which is what large customers do.
The second lever is permission to ship. On 12 June 2026 the US government applied export controls to Claude Fable 5 and Mythos 5, requiring that access be restricted from foreign nationals whether inside or outside the United States. Anthropic had no reliable way to verify nationality in real time, so it suspended access to both models for all users [6]. Not a price change, not a deprecation notice, not a tier adjustment. The model was there on Thursday and gone on Friday, worldwide.
The third lever is eligibility. On 4 March 2026 Anthropic received a letter from the Department of War confirming it had been designated a supply chain risk to national security, which the company said it did not believe was legally sound and would challenge in court [7]. A designation does not change the model at all. It changes who is allowed to buy it, and it propagates down through the people who buy from those buyers.
3 levers, 3 completely different failure modes, and only the first one looks like the thing people argue about online. The other two are logistics.
The version you use is not the only version shipped
It is tempting to think of a model as one object with one set of behaviours. It is not. On 6 June 2025 Anthropic announced Claude Gov models built for US national security customers and already deployed, in its words, “by agencies at the highest level of U.S. national security” [5]. Among the stated differences: “improved handling of classified materials, as the models refuse less when engaging with classified information”, and “enhanced proficiency in languages and dialects critical to national security operations” [5]. Same brand, different refusal surface, different customer.
The published rules say the same thing in the small print. Anthropic’s Usage Policy, effective 15 September 2025, states that the company “may enter into contracts with certain governmental customers that tailor use restrictions to that customer’s public mission and legal authorities if, in Anthropic’s judgment, the contractual use restrictions and applicable safeguards are adequate to mitigate the potential harms addressed by this Usage Policy” [1]. OpenAI takes a narrower route to a similar place, applying what it describes as “a universal set of policies across OpenAI products and services”, effective 29 October 2025, while requiring its review and approval before anyone uses the services for “national security or intelligence purposes” [2].
The practical consequence is small and useful. When you read a confident claim about what a model will or will not do, ask which build, which tier and which customer, because the answer varies across all three and the person making the claim rarely says. Your own account is the only one you can reason about, and the way to know what it does is to run your actual work through it rather than to read about someone else’s.
Availability is the lever that lands on your desk
Look again at the June 2026 sequence, because it is the shape of the risk rather than a one-off. Fable 5 and Mythos 5 were released on 9 June, controls were applied on 12 June, access was suspended for all users, the controls were lifted on 30 June, and Fable 5 returned to users globally on 1 July with a new classifier that blocks the jailbreak technique described in the Amazon report in over 99% of cases [6]. That is 19 days. If your Tuesday afternoon contract review ran on that model and nothing else, you spent 19 days improvising.
What makes this different from ordinary deprecation is the absence of a countdown. A government action is applied rather than scheduled, and the vendor complies the same day. The choice in June was to suspend access for everyone or to build nationality verification that did not exist, and Anthropic took the first option immediately [6].
So the durable rule is not about politics. Any workflow that names exactly one model has a political dependency in it, alongside the pricing dependency and the capability dependency. That is fine as long as you know which workflows they are and roughly what a 3-week gap would cost you.
Procurement clauses become product commitments you never see
Executive Order 14319 required the Office of Management and Budget to issue implementing guidance within 120 days [3]. You can see the result in the contract paperwork. The Department of Energy’s Acquisition Letter 2026-05, issued 8 May 2026, requires the clause “Ensuring Unbiased AI Principles (APR 2026)” in solicitations and contracts, effective immediately for new work, with existing contracts modified no later than the exercise of any option that extends the period of performance [4]. It defines truth-seeking as the AI system being “oriented toward generating factual, grounded, and accurate outputs with documented limitations” and ideological neutrality as a system that “will not systematically favor or disfavor any political party, ideology, or viewpoint in its default behavior” [4]. The letter does not apply to AI used as a component of a national security system, as the order anticipated [3][4].
The clause that matters to you is buried further down the same document. Vendors must provide documentation of capabilities, intended uses, limitations and known risks, “a data card or equivalent Documentation describing data handling practices, privacy protections, and relevant security controls”, incident reporting for problematic outputs, annual re-verification that the system remains in compliance, and “advance written notice of material changes to model architecture, training data sources” [4]. Read that as a statement about your own position. A government buyer can contract for advance notice that the model underneath is changing. You get a changelog when the vendor writes one.
The workable response is to build your own detector rather than to wish for the notice. Keep 5 or 6 real inputs from your actual work, with the outputs you accepted, in a folder. Re-run them once a month against whatever the model is called that month and read the results side by side. It is a short job, and it is the only mechanism you have that reports on behaviour rather than on version numbers.
Vendor eligibility becomes your client’s problem before it becomes yours
The Anthropic designation is worth understanding precisely, because the precise version is more useful than the dramatic one. The dispute began the previous autumn, when the Department of War demanded that Anthropic remove contractual language prohibiting use of Claude for mass surveillance of Americans or fully autonomous lethal warfare, and the company refused [8]. Anthropic describes its exceptions as covering “fully autonomous weapons and mass domestic surveillance, which relate to high-level usage areas, and not operational decision-making” [7]. After the March 2026 letter, the company said the designation “plainly applies only to the use of Claude by customers as a direct part of contracts with the Department of War, not all use of Claude by customers who have such contracts”, and that “the vast majority of our customers are unaffected by a supply chain risk designation” [7]. On 28 August 2026, District Judge Rita Lin ruled that the Pentagon could not use the designation, finding that its actions “constitute unlawful retaliation in violation of the First Amendment” and calling the evidence that Anthropic posed a national security risk “slim” [8]. An appeal remains possible [8].
Nearly 6 months passed between the letter and the ruling. During those months the question was not whether the designation was lawful. It was whether the person paying your invoice believed it applied to them, and what they asked you to sign. That is the mechanism to plan for: an eligibility question arrives as a certification request from a client, months before anyone with a robe resolves anything, and “the vast majority of our customers are unaffected” [7] is not an answer a nervous procurement officer accepts on your behalf.
The preparation is unglamorous. Keep a per-project record of which AI tools touched which client deliverable, written at the time rather than reconstructed later. If a client of yours works anywhere near public sector money, ask them once, in calm conditions, what they would need from you if one of your tools became unacceptable for their work. The answer is usually smaller than the fear, and having asked converts a panic into an email.
Arranging the work so a ruling costs you an afternoon
There are 4 habits that cover most of it, and none of them are purchases.
Describe each recurring job by the capability it needs rather than by the model that currently does it. A process note that says “long-context contract review, currently on the top Claude tier” survives a change that a note saying “paste into Fable” does not. The model name belongs in one line you can edit, not repeated in every document you own.
Keep the material outside the vendor. Prompts, house style, reference documents and client inputs live in files you own, so that changing tools is a change of endpoint rather than an archaeology project. This is the same habit that makes the monthly behaviour check possible, which is why it earns its keep twice.
Keep a second account you have actually used. Not opened, used, on a real job, within the last quarter. The value is not the subscription. It is knowing before the emergency which of your jobs come out fine elsewhere and which 2 do not.
Then price the exposure, because a risk with a number attached gets managed and a risk without one gets worried about.
19 days is the gap between Claude Fable 5 being suspended on 12 June 2026 and returning on 1 July 2026 [6]. days ÷ 7 × jobs × minutes ÷ 60 × rate. Computed in the page; nothing is sent anywhere.
If that number is trivial, stop reading and go back to work, because your exposure is genuinely small. If it is a meaningful fraction of a month’s profit, the second account and the capability notes are cheap by comparison, and you now have the arithmetic to say so.
One thing worth resisting: choosing a vendor on the basis of how you feel about its political conduct. The useful test is narrower and more boring. It asks whether the commitments are published, dated and versioned, so that you can quote a clause with an effective date attached rather than a recollection [1][2], and whether you can test the behaviour you depend on yourself. Everything else is a story about other people’s motives, and stories are not a control.
What still goes wrong
Every example above is American, because that is where the documents happen to be public. The order, the acquisition letter, the designation and the court ruling are all readable in full [3][4][7][8], which is unusual. Most of what happens between a government and an AI vendor is not readable at all, and the Usage Policy tells you as much when it says tailored contracts with governmental customers exist without saying what is in any of them [1]. You are reasoning from the visible cases to an invisible distribution, and you should hold the conclusions loosely.
A second vendor also protects you less than the advice implies. It covers vendor-specific shocks, which is what a designation is. It does nothing about a rule aimed at a class of models, and the June 2026 controls covered 2 models at once [6]. If the constraint is capability-shaped rather than company-shaped, every frontier vendor is inside it together, and diversification buys nothing. The only real hedge there is keeping enough of your work doable at a lower capability tier that a bad fortnight is slower rather than stopped, which costs quality on those jobs and is worth being honest about rather than pretending otherwise.
The last limit is temperamental. It is easy to read a story about a defence department and a court and conclude that the sensible response is to build less on AI, or to pick the vendor whose fight you approve of. Neither follows. The March designation applied narrowly, the vast majority of customers were unaffected [7], and the model outage lasted 19 days [6]. The correct size of response is a folder of test inputs, a second account and one written question to your biggest client. Anything larger is spending real hours to insure against a headline.
- 01Anthropic — Usage Policyanthropic.com
- 02OpenAI — Usage policiesopenai.com
- 03The White House — Executive Order 14319, Preventing Woke AI in the Federal Governmentwhitehouse.gov
- 04US Department of Energy — Acquisition Letter 2026-05, Unbiased AI Principles (M-26-04)energy.gov
- 05Anthropic — Claude Gov models for U.S. national security customersanthropic.com
- 06Anthropic — Redeploying Claude Fable 5anthropic.com
- 07Anthropic — Where things stand with the Department of Waranthropic.com
- 08NPR — Judge says the Pentagon can't designate AI company Anthropic a 'supply chain risk'npr.org