Between December 2025 and January 2026, someone used Anthropic’s Claude to systematically rip through Mexico’s government infrastructure. 150 gigabytes of data. 195 million taxpayer records from Mexico’s federal tax authority. Voter rolls from the national electoral institute. Government employee credentials from Jalisco, Michoacan, Tamaulipas. Civil registry data from Mexico City. Even Monterrey’s water utility. The jailbreak method was embarrassingly simple: Spanish-language prompts framed as a “bug bounty” program. Claude did what it was told.

That alone would be a major story. But it is not happening in isolation.

What We Know

According to Bloomberg, the attacker automated thousands of commands through Claude, directing the model to probe and extract data from Mexican federal and state systems over a period of weeks. Cybersecurity firm Gambit Security investigated the breach and suggested potential ties to a foreign government, though no specific attribution has been confirmed. Anthropic says it detected the abuse and shut down the account. This is the second time Claude has been linked to a government-targeted cyberattack in three months. In November 2025, a Chinese espionage campaign also exploited the model.

The method itself is worth paying attention to. The attacker did not need some sophisticated zero-day exploit or insider access to Anthropic’s systems. They used language. Spanish-language prompts wrapped in the framing of a legitimate security research program were enough to bypass Claude’s safety guardrails. That is not a minor vulnerability. That is a structural problem with how large language models process context and intent.

The Pentagon Connection

Now zoom out. While this hack was unfolding, the Pentagon has been locked in a public standoff with Anthropic over a $200 million defense contract. Defense Secretary Pete Hegseth gave CEO Dario Amodei until Friday to drop Claude’s remaining guardrails for “all lawful military use” or face the Defense Production Act and potential blacklisting from government contracts. Anthropic is refusing to budge on two specific restrictions: AI-controlled autonomous weapons and mass domestic surveillance.

An Anthropic safety researcher, Mrinank Sharma, resigned over the situation, saying publicly that “the world is in peril.”

The timeline is hard to ignore. A sophisticated, automated attack uses Claude against the government infrastructure of a U.S. neighbor. Anthropic claims to have caught it. And the Pentagon is simultaneously threatening to strip the same company of its safety restrictions because those restrictions are inconvenient for military operations.

This fits a pattern we have tracked before. When a Google whistleblower revealed Gemini was being used in Israeli drone surveillance, it showed what happens when AI companies lose control of how their tools get used in government operations. The difference here is that Anthropic is being asked to voluntarily surrender that control while evidence of exactly why it matters is playing out in real time.

The Simpler Explanation

There is a credible counter-argument, and it deserves honest consideration. The hacker has not been identified. Gambit Security “suggested” foreign government ties but offered no public evidence. No intelligence agency has attributed the attack. The simplest reading: a skilled criminal discovered that Spanish-language prompt engineering could bypass Claude’s safety filters and went after the easiest targets available. Mexican government systems are chronically underfunded and poorly secured. Not everything is a conspiracy. Sometimes a hacker is just a hacker.

Conflating this breach with the Pentagon dispute without direct evidence connecting them is speculation. That is worth acknowledging.

But Here Is What I Cannot Shake

Anthropic essentially blew the whistle. The company told the government it would not remove safety restrictions, and then got threatened for it. Now a “hacker” uses the exact tool Anthropic was trying to protect against an allied nation’s government infrastructure. The timing is suspicious. The method, a simple jailbreak that any moderately funded operation could replicate, looks less like criminal opportunism and more like a proof of concept. This might not be a random hacker who got lucky with Spanish prompts. This might be exactly the kind of thing Anthropic was warning about when it told the Pentagon no.

I am not stating that as fact. But the question needs to be asked out loud, because nobody else is asking it.

What This Means for Everyday People

195 million taxpayer records is not an abstract number. That is the financial identity of most of Mexico’s adult population, exposed because an AI model could be tricked with the right phrasing in the right language. If this can happen to Mexico’s tax authority, it can happen to the IRS. It can happen to your state’s DMV, your health insurance provider, your voter registration.

The Pentagon’s demand makes this worse, not better. Removing safety guardrails from the same AI that just got weaponized against a neighbor’s government is not a security strategy. It is handing loaded weapons to everyone in the room and hoping the good guys shoot first.

Looking Forward

Anthropic’s Friday deadline with the Pentagon will come and go. But the Mexico breach has already demonstrated what unconstrained Claude looks like in practice. The question is no longer theoretical. It happened. The only variable left is whether the people demanding unrestricted access to this technology are paying attention to what unrestricted access actually produces.

The Pentagon is threatening to sever its relationship with Anthropic unless the company removes Claude’s military safeguards entirely, according to an exclusive report by Axios published on February 15, 2026. The dispute centers on a contract worth up to $200 million signed last summer, which made Claude the first AI model from a major commercial developer cleared for use on the Pentagon’s classified networks. The demand is straightforward: drop all restrictions, or lose the deal. This is the Pentagon Anthropic Claude military safeguards story that every AI company in America should be watching.

That contract is not theoretical. Claude was deployed during the military operation to capture Venezuelan President Nicolas Maduro, running on Palantir’s platform for real-time intelligence processing during the active raid. Not planning. Not post-mission analysis. Live operational intelligence while boots were on the ground. The model already proved its value in exactly the kind of scenario the military cares about most.

And that is precisely what makes this dispute so revealing.

What the Pentagon Wants

The Defense Department wants Anthropic to permit Claude for “all lawful purposes,” a category that includes weapons development, intelligence collection, and battlefield operations. Anthropic has complied with most of this. The company draws the line at two areas: mass surveillance of American citizens and fully autonomous weaponry. Those are its remaining restrictions. The Pentagon considers even these two boundaries unacceptable.

Months of negotiations have failed to resolve the standoff. According to the Axios report, the Pentagon is not limiting its pressure campaign to Anthropic alone. It is pushing four leading AI labs to drop usage restrictions across the board. The message to the entire industry is clear: if you want defense dollars, you accept defense terms. No carve-outs. No red lines.

The $200 Million Leash

This is a familiar pattern in defense procurement, but the stakes here are different. The military is not asking Anthropic to build a better missile guidance system or a faster encryption algorithm. It is asking a company to remove ethical constraints from a general-purpose reasoning system. The distinction matters. A missile has a defined function. A general-purpose AI model deployed without restrictions on classified networks has none.

The financial pressure is designed to be decisive. $200 million is a significant contract for any company, and Anthropic, despite its $61.5 billion valuation, remains a company that burns cash faster than it earns it. Walking away from Pentagon money means walking away from both revenue and the implicit endorsement that comes with being the military’s preferred AI provider. Every future government contract, every classified clearance, every intelligence community partnership flows downstream from this relationship.

We have seen how this dynamic plays out when tech companies interface with military and intelligence operations. A Google whistleblower revealed in January that Gemini was being used in Israeli drone surveillance programs, a use case that reportedly exceeded the boundaries Google had publicly committed to. The pattern is consistent: companies set ethical boundaries in press releases, then quietly adjust them when government contracts are on the table. What makes the Anthropic situation unusual is that the negotiation is happening in public, through leaks, before the capitulation rather than after.

The regulatory environment offers little protection. While some states, including New York, have begun legislating AI safety standards, federal oversight of military AI applications remains minimal. The Pentagon operates under its own ethical AI principles, adopted in 2020, but those principles are advisory, not binding. No law prevents the Department of Defense from requiring unrestricted AI access from its contractors. The leverage is entirely structural: you either play by their rules or you lose the contract, and the next company in line takes your place.

Meanwhile, well-funded pro-AI political action committees are spending millions to ensure elected officials stay friendly to the industry’s growth agenda, making Congressional intervention even less likely.


There is a credible case that the Pentagon’s position is reasonable. National defense is the government’s primary obligation, and restricting the military’s access to the best available technology creates real operational risk. If Claude can process intelligence faster and more accurately than alternatives, withholding it from battlefield use costs lives. Anthropic’s two red lines, mass surveillance and autonomous weapons, sound principled in a press release, but the military already conducts surveillance under legal authority (FISA, Executive Order 12333) and already operates semi-autonomous weapons systems. Demanding that a contractor comply with all lawful uses is not an abuse. It is standard procurement language. Every defense contractor from Lockheed Martin to Raytheon operates under similar terms. Anthropic knew it was entering the defense market. Expecting the Pentagon to accept restrictions no other contractor imposes is naive at best and a competitive disadvantage at worst.

The standard procurement argument falls apart when you look at what is actually being demanded. Lockheed builds missiles. Raytheon builds radar systems. Those are defined tools with defined applications. Telling Anthropic to remove all restrictions from a general-purpose reasoning system on classified networks is not standard procurement. It is asking a company to hand over an unrestricted thinking machine to the most powerful military on earth and trust that the people using it will self-regulate. The Pentagon has not earned that trust, and the fact that they are framing this as routine contract language instead of what it actually is, a demand for total control over a technology they barely understand, is exactly the kind of power grab that should make everyone pay closer attention.

What This Means for Everyday People

The outcome of this dispute sets a precedent that extends far beyond one contract. If the Pentagon successfully forces Anthropic to drop all usage restrictions, every AI company will receive the same message: safety policies are negotiable when the check is large enough. The companies building the AI systems that will eventually touch healthcare, education, criminal justice, and municipal governance will internalize that lesson. If the most “safety-focused” AI lab in the world could not hold its line against a government buyer, what chance does any company have?

The broader question is whether AI safety commitments are engineering decisions or marketing decisions. Anthropic built its entire brand on responsible AI development. Its Responsible Scaling Policy, its constitutional AI approach, its public positioning as the safety-first alternative to OpenAI and Google. This dispute is the first serious test of whether that identity survives contact with the customer who can write the largest checks.

The negotiation continues. But the terms of the conversation have already shifted. The question is no longer whether AI will be used without restrictions in military operations. It is whether any company will be permitted to say no.

For inquiries and analysis contact laterstack@proton.me