A divided federal appeals court upheld the Pentagon’s decision to treat Anthropic as a supply-chain risk after the company refused to relax restrictions on Claude’s military use.
The US Court of Appeals for the District of Columbia Circuit denied Anthropic’s petitions on 25 September. The majority held that the Department of War had enough support to remove Claude from its supply chain under the Federal Acquisition Supply Chain Security Act.
The dispute began when Anthropic would not replace restrictions on lethal autonomous warfare and domestic surveillance with a term permitting all lawful uses. The department argued that Claude’s model, technical and contractual controls could stop the system from functioning as military users expected. Anthropic challenged that characterization, the process used to impose it and the government’s motives.
Why it matters
The decision treats a supplier’s disclosed ability to constrain its product as a possible national-security supply-chain risk. That is broader than the familiar image of compromised hardware, covert code or a hostile vendor. For frontier-model companies, it means safety policies can become procurement reliability questions when government customers need predictable access during operations.
The majority said the statute covers manipulation that can deny, disrupt or otherwise change a technology’s operation. It found that Anthropic was able and willing to enforce restrictions and that Claude had previously refused government-requested tasks. The judges deferred to the department’s assessment that a clean break was preferable to reviewing every system and use case separately.
Anthropic also argued that it should have received a chance to respond before the exclusion took effect. The majority concluded that any procedural problem was harmless because the company received notice soon afterward, submitted its objections and did not show that earlier timing would have changed the result.
On the First Amendment claim, the court accepted that Anthropic’s advocacy for AI safeguards was protected speech and that exclusion was materially adverse. It nevertheless found no causal connection. The majority read the record as a contract dispute: the government acted after Anthropic rejected the all-lawful-uses term, not because the company had publicly supported regulation.
The dissent draws a narrower boundary
Judge Karen Henderson dissented. She argued that Congress designed the law for hostile actors and covert compromise, not for an American supplier openly enforcing restrictions that a customer had previously accepted. In her view, the majority’s definition could let an agency brand a contractor a national-security threat whenever it dislikes disclosed technical or contractual limits.
That disagreement is the decision’s central policy fault line. A government buyer needs assurance that a critical system will work under pressure. A model supplier may believe some requested uses are unsafe, unlawful in practice or incompatible with its mission. If the buyer’s preferred term is the only acceptable boundary, procurement power can pressure vendors to remove safeguards without a legislature resolving the underlying AI policy.
The ruling does not establish that Claude is technically compromised or that Anthropic acted maliciously. It validates this agency action under a specific statute and record. It also does not erase every separate court proceeding involving the designation. Claims about the effect of rulings in other jurisdictions should be checked against those dockets rather than inferred from this opinion.
For contractors, the practical lesson is to define update authority, model behavior, refusal modes and emergency access before deployment. For agencies, the decision rewards a documented link between a supplier’s controls and operational risk. The next question is whether Anthropic seeks further review and how broadly other agencies apply the court’s interpretation.
Verification
- VERIFIED — The D.C. Circuit denied Anthropic’s petitions on 25 September 2026. Primary source: https://law.justia.com/cases/federal/appellate-courts/cadc/26-1049/26-1049-2026-09-25.html
- VERIFIED — The majority found the supply-chain determination reasonable and rejected the due-process and First Amendment claims. Primary source: the published opinion above.
- VERIFIED — The court tied the action to Anthropic’s refusal to accept an all-lawful-uses term. Primary source: the opinion above.
- VERIFIED — Judge Henderson dissented and argued the statute targeted malicious or covert manipulation rather than disclosed restrictions. Primary source: the dissent included with the opinion above.
- ANALYSIS — The implications for future procurement and vendor safeguards are editorial interpretation.
Glossary candidates
- Supply-chain risk: A risk that a supplier or component could impair a system’s integrity, operation or availability.
- Harmless error: A procedural mistake that does not justify relief because it did not prejudice the affected party.
- Petition for review: A request for an appellate court to examine an agency action.
Cold-reader sentence: The court let the Pentagon treat Anthropic’s safeguards as an operational supply-chain risk, over a dissent warning that the statute was stretched too far.