Anthropic is hiring a Head of National Security Sales, according to a job posting reviewed by The American Prospect, an opening that has not previously been reported. The listing asks the incoming leader to build out the company’s sales organization for the Department of War and the intelligence community, with total compensation reaching $700,000 a year.
The hire matters because of what came before it. Earlier this year the Pentagon labeled Anthropic a “supply chain risk,” a designation that blocked the company from federal contracting work. Anthropic said the move was retaliation for red lines it had drawn against using its technology for “mass domestic surveillance or fully autonomous weapons.” A federal judge ruled on August 28 that the designation was unlawful, a decision covered separately in this issue. What matters here is the timing: Anthropic is staffing up to sell into defense before that legal fight had even resolved.
That timing exposes a tension the company has spent two years managing in public. Anthropic markets itself as the AI lab most willing to say no to governments and militaries, the one that built a public constitution around avoiding harm. A national security sales function, led by someone tasked to scale adoption across intelligence agencies, reads as a company trying to hold two positions at once: publicly principled, commercially ambitious. Reasonable people can land on either side of whether that combination is coherent. The job posting itself does not resolve it, and Anthropic did not answer the Prospect’s questions about how it would enforce its stated limits once contracts start flowing again.
The competitive backdrop sharpens the stakes. When the Pentagon froze Anthropic out, it turned to rival OpenAI instead, on assurances that the NSA would not be a customer and that the tools would not be turned on people at home inside the U.S. citizens. Those promises did not satisfy everyone inside OpenAI. The company’s head of robotics, Caitlin Kalinowski, resigned over the deal, saying questions about surveillance and lethal autonomy deserved more scrutiny than they got. OpenAI has kept building out its own national security sales operation since then, recruiting representatives who hold top secret clearance to walk agencies through adoption.
Anthropic’s models have already touched real military operations, including the raid that captured Venezuelan President Nicolás Maduro and, according to earlier reporting, an American drone strike that hit a school for girls inside Iran. Those episodes are the backdrop against which the company’s safety commitments will be tested if its new sales team succeeds at the job description.
At the Brennan Center, Amos Toh is senior counsel on its Liberty and National Security Program. He has separately cautioned that AI-generated targeting recommendations in warfare “can sound extremely convincing” while being wrong, and that autonomous agents risk leaking classified data without an operator’s knowledge. Those are the exact failure modes any national security sales pitch will need an answer for.
For Anthropic, the open question is no longer whether it wants back into defense contracting. The job posting settles that. The open question is what its stated red lines will actually cost it once negotiations start with agencies that, in the OpenAI deal, showed a preference for writing assurances into a contract rather than changing how they operate. Buyers and competitors evaluating Anthropic’s enterprise roadmap over the next quarter should watch whether the hire closes before or after the legal fight over its blacklisting is fully settled, since that sequencing will shape how much leverage Anthropic has to negotiate its own terms.
The American Prospect (Zachary Groz) first reported the job posting on August 27, 2026.