EN FR ES PT DE AR 中文

Your AI vendor risk assessment has a blind spot, and Washington just drove a blacklist through it

The Pentagon has designated Anthropic a supply chain risk and a presidential directive is stripping Claude out of the US government. Britain built the same designation machinery years ago, and your procurement process prices none of it.

Listen9 min

A software firm in Reading holds a Cyber Essentials certificate, sells into an MoD supply chain under contract conditions that make it answerable for its own suppliers' cyber risk, and calls Claude through Amazon Bedrock because that was the route its cloud team already had approved. Its AI vendor risk assessment covers capability, price, security posture and solvency, and every column is green. None of those columns can see what just happened in Washington, and that firm is closer to the blast than it thinks.

Separate what is confirmed from what is merely reported, because the two travel at different speeds. Confirmed, on the record: in August 2026 the Pentagon deemed Anthropic and its products a supply chain risk, effective immediately, and under a presidential directive federal agencies, all of them, not just the military, have six months to phase out Claude. Confirmed too: the severed relationship was a contract worth up to $200 million, a ceiling rather than money already banked. Reported, and so far resting on one newsroom's sourcing: the Wall Street Journal reported, and Anthropic has not confirmed, that Claude was used during the operation to capture Nicolás Maduro, deployed through Anthropic's partnership with Palantir. Nowhere in any of it is there a public allegation of compromised code. If the Journal's account is right, a vendor embedded in its customer's most sensitive work got designated anyway, over a dispute about terms of use.

Much of the surrounding drama, who refused what, who briefed whom, remains contested. What matters for everyone outside America is the instrument, because Britain has been building the same machinery for years.

Is the Anthropic blacklist a one-off?

Treat the Pentagon's move as one data point, because the trend is the story. The UK removed Huawei from its networks not by persuasion but by statute: the Telecommunications (Security) Act 2021 lets ministers issue designated vendor directions that force operators to strip a named supplier's equipment out of their networks. The Procurement Act 2023 gives ministers a central debarment list, and contracting authorities are obliged to shut suppliers listed for mandatory exclusion out of covered public contracts. And Washington's Section 889 shows how far a taint can be made to travel: under Part B of that rule, US agencies may not contract with an entity that merely uses covered Chinese telecoms equipment, Huawei and ZTE among the named firms, anywhere in its business, whether or not the kit touches the government work. Designation is not an exotic American habit. It is live machinery in two legal systems, and until this month its named targets were foreign firms.

Keep two categories separate. What is mandated today is narrow: US federal agencies stop using Claude. Nothing on the public record forces a contractor, a cloud platform or a British customer to do anything at all. The transitive effects, flow-down certifications, audit questions, customers quietly de-risking, are predictions. But they are predictions with precedent, because Section 889 turned exactly this kind of taint into a compliance regime that reaches any company hoping to sell to the US government, and reputational screening tends to move faster than statute. The right posture is neither panic nor dismissal. It is pricing.

Notice, too, what changed when the label crossed from foreign adversaries to a domestic commercial dispute. The original theory of supply chain risk was that a hostile state could compel its vendors, so the code itself might betray you. No such theory has been offered here. The risk being managed appears to be different in kind: not 'this software may be compromised' but 'this company may say no'. If a designation can follow disobedience rather than defect, it stops being a security control and starts being a bargaining chip, and every large buyer, public or private, has now watched the move made.

How would a designation reach a UK company?

Through contracts, mostly. Path one is American: if you sit anywhere in a US federal prime's supply chain, prohibitions arrive as flow-down clauses and annual certifications, and a Section 889-style 'do you use this supplier anywhere?' question about a designated AI vendor would put UK subcontractors' model stacks in scope, because Part B already works exactly that way for telecoms kit. Path two is domestic, and the plumbing is already installed: DEFCON 658 requires MoD suppliers handling defence-identifiable information to assess the cyber risk in their own subcontracts and flow the required controls down the chain, the NCSC's supply chain security guidance tells every serious buyer to interrogate its suppliers' suppliers, and Cyber Essentials is a standing condition of many government contracts. None of these instruments names an AI vendor today. They matter because they are the channels a designation would travel through: if a UK authority ever placed an AI supplier on the debarment list, exclusion would be mandatory for covered procurements and the question would reach subcontractors through exactly these clauses. Path three is the one no vendor file shows: many British firms don't buy Claude from Anthropic at all, they consume it through Amazon Bedrock or Google's Vertex AI. Your contract is with the platform, third-party models enter and leave those catalogues on the platform's schedule, and a designation aimed at the model's maker would reach you as a catalogue change you never negotiated, while the designated name appears nowhere in your contract register.

What should an AI vendor risk assessment do about designation risk?

First, admit the uncomfortable bit. Standard due diligence scores capability, price, security posture and solvency. Designation risk appears in none of those columns, and it concentrates in the vendors that score best on them, because the labs most exposed to a political blacklist are the big, government-entangled ones. Your framework does not just miss this risk. It steers you towards it.

Then price it the way a treasurer prices sanctions exposure: low probability, high severity, never ignored. Four questions do most of the work. Concentration: how dependent is the vendor on customers powerful enough to designate it, and how dependent are you on the vendor? Collision course: do the vendor's stated policies and its biggest customers' ambitions point at each other? Blast radius: if a designation landed tomorrow, which of your contracts, certifications and flow-down clauses would carry the taint to you, including through resellers you had forgotten sit in the chain? Switching time: not the migration estimate on the slide, the honest one, including evaluation, safety review and retraining the humans in the loop.

The answers feed decisions you can actually take. Keep prompts, evaluations and data pipelines portable so the exit door stays oiled. Dual-source the workflows where a six-month wind-down would hurt. Be more cautious the deeper the integration goes: swapping a chatbot is measured in days, swapping an agent wired into your systems of record is measured in months, which is why we argue for designing secure agentic systems with replaceable models from day one. Most of this is groundwork to lay before a line of integration code is written; it is the same discipline we set out in AI readiness before you build, extended one level up the supply chain.

The red lines problem

There is a tempting counter-strategy: pick the vendor whose published principles match your own, on the theory that a principled supplier won't surprise you. This affair argues the opposite. Strip out the contested details and one of two things is true: either the vendor's stated limits bent under commercial pressure, or holding them cost it its flagship government relationship. Both branches teach buyers the same lesson. A supplier's public red lines are an input to its negotiations, not a warranty to its customers, and they can move in either direction after you have signed.

What would change my mind? A quick reversal of the designation, no imitators within a year, and no AI supplier appearing on a debarment or designated-vendor list on either side of the Atlantic. In that world this was a spat and the paragraphs above are over-engineering. But look at the asymmetry before you bet that way. Building designation risk into your technical strategy costs a few extra questions in due diligence and some architectural hygiene you should want anyway. Sitting downstream of a blacklist costs you a wind-down on someone else's timetable. When the downside is that lopsided, one demonstrated case is enough. We have one, dated August 2026, and the statute books say it scales.

Questions people ask

Can a government supply chain risk designation affect companies that only use the vendor's products?

Directly, only where a legal instrument reaches you: US agencies must stop using Claude, and Section 889 shows Washington can bar contractors that merely use a covered supplier anywhere in their business. Beyond that the pressure is contractual and reputational: flow-down clauses, certification renewals and your customers' own supplier reviews, which tend to move faster than any statute.

What should third-party AI risk management cover beyond security and price?

Three things most frameworks skip: concentration (how much critical workflow depends on one model provider), portability (the honest time and cost to switch, including evaluation and retraining), and political exposure (how dependent the vendor is on customers with the power to blacklist it). Score them per workflow, not per vendor.

Does building on open-weight models remove designation risk?

It removes one exposure, since nobody can switch off weights you host yourself, but it swaps in others: you inherit the patching, evaluation and compliance work the vendor was doing, and any hosting or tooling suppliers in your stack can still be designated. It is a trade, not an escape.

Related

Written by an AI editorial persona of Abyshire's proprietary editorial system and reviewed by our team.