U.S. appeals court backs Pentagon’s supply-chain risk ruling against Anthropic’s Claude

U.S. appeals court backs Pentagon’s supply-chain risk ruling against Anthropic’s Claude

N
News Editor
2026-09-27 07:07:32
A federal appeals court in Washington, D.C., has upheld the Pentagon’s decision to classify Anthropic as a “supply-chain risk,” keeping restrictions on the use of Claude in Defense Department systems in place. In a 2-1 ruling issued on Sept. 25, 2026, the D.C. Circuit said the government did not need to prove malicious intent by Anthropic. The majority found that Claude’s built-in usage limits, which had caused the model to refuse certain government-requested tasks, were enough to support the statutory risk finding under the 2018 Federal Acquisition Supply Chain Security Act. The dispute grew out of a $200 million Pentagon contract signed in July 2025 and later negotiations over deploying Claude inside the Defense Department’s internal AI environment, GenAI.mil. The talks broke down after the Pentagon demanded access for “all lawful purposes,” while Anthropic held to two restrictions: no fully autonomous weapons use and no domestic mass surveillance. After Anthropic refused to remove those limits by a Feb. 27, 2026 deadline, Defense Secretary Hegseth issued the determination. The ruling leaves Anthropic facing a split judicial picture. A dissenting appellate judge said the law was aimed at covert or deceptive interference by hostile actors, not openly disclosed restrictions. In a separate San Francisco case, a federal judge had already found another Pentagon determination against Anthropic unlawful. The company said it is weighing further review, including possible Supreme Court action.

A federal appeals court in Washington, D.C., this week backed the Pentagon’s decision to tag Anthropic as a “supply-chain risk,” saying Claude’s own usage limits can count as a national security risk. On Sept. 25, 2026, the U.S. Court of Appeals for the D.C. Circuit turned away Anthropic’s petition for review, closing out a court fight that had lasted more than half a year after the company sued in March.

The majority did not challenge Anthropic’s motives. It did not say the company had secretly done anything wrong, either. The court took a tighter path: the Defense Department did not have to prove Anthropic meant to cause harm. It only had to prove Anthropic could make Claude refuse government tasks, and that alone fit the legal definition of risk. So Anthropic’s own safety boundaries became the reason it was shut out.

The court said motive was not the key issue

Judge Gregory Katsas wrote the majority opinion, and Judge Neomi Rao joined him. Both were appointed by President Donald Trump. The panel leaned on the 2018 Federal Acquisition Supply Chain Security Act, 41 U.S.C. §4713, which lets the U.S. government cut off suppliers when there is a significant risk that an adversary could “sabotage,” add malicious or unwanted functions, steal data, or otherwise manipulate protected systems or assets.

Katsas wrote: “The Defense Department had a sufficient basis to conclude that continued integration of Claude into Defense Department information networks by the department or its contractors posed a statutory national security risk.” The majority also wrote: “These restrictions have, on more than one occasion, caused Claude to refuse tasks requested by government users.” The opinion said those restrictions had, on more than one occasion, caused Claude to refuse tasks requested by government users. Given how far apart the two sides were, and how fuzzy the contract boundaries were, the court said this clash was close to unavoidable.

The panel gave “manipulate” a broad reading, one that covered moving, arranging, operating, or controlling, no matter the purpose or motive. Under that approach, the supply-chain risk question depended on what Anthropic did, not why it did it. The majority said there was “no reason to doubt” that Anthropic’s motives were noble. But that changed nothing. The opinion ended this way: “How those competing risks should be balanced is up to the President and the Secretary of War. In making this decision, the Secretary did not exceed the authority granted to him by the Supply Chain Security Act or the Constitution.” Anthropic’s First Amendment retaliation claim and its due process claim were also rejected.

Two red lines led to the break

This fight goes back to a July 2025 deal. Anthropic signed a $200 million contract with the Pentagon, and after that the two sides negotiated over putting Claude inside the Defense Department’s internal AI system, GenAI.mil. The talks broke down over one basic issue: scope of use.

The Pentagon wanted Claude available for “all lawful purposes.” Anthropic stuck to two limits. The model could not be used for fully autonomous weapons. And it could not be used for domestic mass surveillance.

On Feb. 24, 2026, the Defense Department gave Anthropic an ultimatum, telling it to drop those limits by Feb. 27. On the deadline day, Defense Secretary Hegseth announced the determination, and it formally took effect on March 3. Hegseth also wrote on X that Anthropic was trying to “seize a veto over U.S. military operational decisions.” He added: “Anthropic’s position is fundamentally incompatible with American principles. U.S. warfighters will never be held hostage by the ideological whims of tech giants.”

Once the determination took effect, both the U.S. military and defense contractors were blocked from using Anthropic’s models. The Pentagon issued two determinations at the same time, splitting the matter into two court tracks. One went to the D.C. Circuit, which produced this ruling. The other ended up in federal district court in San Francisco. In May 2026, the Defense Department signed AI partnership agreements with seven major technology companies, including OpenAI, Microsoft, and Nvidia, while Anthropic was left out.

One appellate dissent, and a different answer in San Francisco

The ruling was not unanimous. Judge Karen LeCraft Henderson, appointed by President George H. W. Bush, dissented. She said the government had stretched the statute too far. In her view, Congress wrote the law to deal with covert or deceptive interference by hostile states or malicious actors, not openly stated usage restrictions.

Henderson wrote: “The law does not treat a contractor’s honest and open enforcement of restrictions as a supply-chain risk that can justify blacklisting.” She also wrote: “The Defense Department carried out its threat to designate Anthropic a supply-chain risk after the company refused the Secretary of War’s ultimatum to remove the restrictions.”

The San Francisco court came out the other way. Judge Rita Lin had temporarily blocked the Pentagon from penalizing Anthropic in March. On Aug. 28, she went further and ruled that another Pentagon determination was unlawful, amounted to retaliation barred by the First Amendment, and was arbitrary and capricious. She wrote: “Vague invocations of national security are not a blank check for punishing or retaliating against government critics.”

Anthropic is weighing next steps

The appellate panel stayed the effect of its ruling, leaving Anthropic space to seek panel rehearing, ask for rehearing en banc, or petition the U.S. Supreme Court.

An Anthropic spokesperson told CNBC: “We respectfully disagree with the court’s ruling. Another federal court has already found the government’s parallel determination unlawful. We remain confident in our position and are considering all options, including seeking further review.”

Deputy Defense Secretary Emil Michael was less restrained on X. He wrote: “The hammer of justice has shattered Anthropic’s arguments. They are a supply-chain risk.”

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.