AI News

Anthropic Loses Pentagon Supply-Chain Case in Split Appeals Court Ruling

The Pentagon can exclude Anthropic’s Claude from its supply chain under a federal procurement law, a divided appeals court ruled on September 25, 2026. The decision gives the government a significant victory in its fight over military access to AI and raises a difficult question for every company selling models to national-security agencies: when can a supplier’s safety restrictions become grounds for excluding its technology?

In a 2–1 decision, the U.S. Court of Appeals for the District of Columbia Circuit denied Anthropic’s petitions challenging the exclusion. Judge Gregory Katsas wrote the majority opinion, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented. The case is Anthropic PBC v. United States Department of War, No. 26-1049, consolidated with No. 26-1162. Read the opinion, pp. 1–5 and 43.

The ruling concerns the Pentagon’s procurement authority. It does not prohibit ordinary consumers from using Claude, order Anthropic to remove its safeguards, or establish that the company secretly sabotaged military systems.

Its broader significance lies in the majority’s conclusion that a company can act from sincere safety convictions and still present a supply-chain risk under this particular statute. Henderson’s dissent argues that this interpretation gives the government a power Congress did not intend.

What the court decided

Question September 25 decision
Can the Pentagon exclude Claude under the Federal Acquisition Supply Chain Security Act of 2018? Yes. The majority upheld the challenged procurement actions under 41 U.S.C. § 4713.
Did the government have to prove malicious intent? No, under the majority’s interpretation of this statute. Henderson disagreed with that reading.
Did the court find a remote kill switch in classified deployments? No. Its reasoning rested on model training and future versions, without requiring post-deployment control.
Did Anthropic win its constitutional challenges? No. The majority rejected its due-process and First Amendment retaliation claims.
Does this ban Claude for the public? No. The decision addresses the Department’s supply chain and related contract work.
Did this reverse Anthropic’s separate August district-court victory? No. The majority distinguished that decision, which involved a different statutory definition.

Assistant Attorney General Brett Shumate highlighted the government’s victory in the X post linking to the decision. His description focused on the national-security grounds for excluding Claude. The opinion supplies the qualifications needed to understand what that means. Majority opinion, pp. 18–32 and 38–43.

How two restrictions became a procurement fight

Anthropic and the Pentagon had worked together before this dispute. According to the court’s account, government users began accessing commercially available Claude models through contractors in classified systems in 2024. Some versions refused requests involving classified material or violent content that government users considered appropriate for national-security work. Anthropic subsequently developed specialized Claude Gov models and adapted its contractual terms. Opinion, pp. 8–9.

The relationship broke down over the Pentagon’s demand for contractual permission to use Claude for all lawful purposes. Anthropic retained two exclusions: mass domestic surveillance of Americans and lethal autonomous warfare.

In his February 26 statement, CEO Dario Amodei argued that frontier models were insufficiently reliable for fully autonomous weapons and that AI could enable domestic surveillance at a scale existing law did not adequately address. That was a defense of specific restrictions within an existing national-security business, rather than a withdrawal from military work altogether.

The court describes an additional dispute over a sensitive overseas operation. The Department said an Anthropic executive’s questions about the use of Claude created uncertainty about whether the technology would perform as expected. Anthropic suggested there had been a misunderstanding. The majority expressly acknowledged that it did not know exactly what happened. That account supports reporting a disputed incident; it does not support claiming that Claude shut down during combat. Opinion, pp. 10 and 19–20.

The principal steps, as recorded in the opinion, were:

Date Development
February 24, 2026 Secretary Pete Hegseth demanded that Anthropic accept the proposed usage terms by February 27.
February 26 Amodei publicly maintained the two restrictions.
March 3 Hegseth made the formal supply-chain determination under the 2018 law.
March 6 A Department memorandum ordered removal as soon as practical, with a 180-day outer limit, and prohibited contractor use on Department work.
April 8 The D.C. Circuit denied an interim stay and expedited merits review.
June 3 Hegseth denied reconsideration and clarified that the determination did not depend on Anthropic having real-time control over deployed classified models.
September 25 The panel denied Anthropic’s petitions on the merits, 2–1.

Timeline source: opinion, pp. 10–15 and 43. The September decision did not start a new 180-day transition period. The timetable above describes the Department’s March memorandum, not a verified inventory of what its systems use today.

Why the majority sided with the Pentagon

The majority accepted the Department’s concern that restrictions embedded in Claude could prevent it from performing tasks the Department regarded as lawful, contractually permitted and operationally necessary.

Three features of the record mattered. Anthropic trains models to follow its safety principles. Previous models had refused government requests. And future versions could carry restrictions that would produce further disagreements about military use. The judges treated those facts as sufficient support for the Department’s assessment of risk. They also emphasized the deference courts give factual national-security judgments. Opinion, pp. 16–20.

The legal dispute then turned on the wording of 41 U.S.C. § 4713. Its supply-chain definition covers specified interference with technology, including manipulation of its design or operation that denies or disrupts its use. Anthropic argued that the surrounding references to sabotage and malicious conduct limited the provision to hostile or deceptive behavior.

The majority rejected that limitation. It read the statute as broad enough to cover deliberate restrictions on functionality even when the supplier’s motives are legitimate. The opinion explicitly allowed that Anthropic could be acting from principled commitments to privacy and safety. In the majority’s view, the effects on the government’s systems were decisive. Opinion, pp. 23–31.

This is the ruling’s most consequential point for AI vendors. Publishing a restriction openly, and defending it in good faith, does not by itself put that restriction outside the law as this panel interpreted it. The government must still satisfy the statute’s other requirements; the opinion does not automatically classify every model with safeguards as a national-security risk.

The ruling did not establish a Claude kill switch

Anthropic told the court that once a model was delivered for use on the Department’s classified systems, the company could not access, alter or shut it down. It argued that the government could test new versions, reject an unsuitable upgrade and continue running an accepted older model.

The majority did not need to reject Anthropic’s account of that deployment architecture to rule against it. Instead, it focused on restrictions already learned during training and those Anthropic could put into later releases. Hegseth’s June reconsideration decision had expressly disclaimed reliance on real-time technical control after deployment. Opinion, pp. 18 and 20–23.

The court also accepted the Department’s concern that testing could not resolve every future refusal scenario, including differently worded prompts and uncertain boundaries around human involvement in targeting. It considered indefinite reliance on older models an inadequate answer in a fast-moving field.

That distinction changes the technical meaning of the case. The dispute reaches into how an AI system is built and updated, even where the supplier lacks access to a deployed copy. Reporting it as proof of remote sabotage would obscure the actual reasoning.

Henderson’s dissent challenges the reach of the statute

Henderson read the same statutory language differently. In her view, the references to sabotage, malicious interference and related acts give the broader language a hostile or deceptive meaning. Openly enforcing agreed restrictions on a product therefore should not fall within the definition merely because the government dislikes those restrictions.

Her concern extends beyond Anthropic. If the government can use this designation when a supplier declines to change its usage policies, a contract negotiation can become a choice between accepting new demands and risking a national-security label. She warned that the majority’s reasoning could reach restrictions already accepted by the Department, even when the supplier applies them honestly. Henderson dissent, pp. 1–8; PDF pp. 44–51.

This is a dispute over the limits of a particular legal power. The majority stressed the statute’s role in protecting government systems and the operational consequences of refusals. Henderson stressed the statutory context and Congress’s concern with hostile infiltration of technology supply chains. Her dissent does not change the judgment, but it explains why the decision has consequences beyond choosing one AI contractor over another.

Why Anthropic’s earlier court victory did not settle this case

Readers who remember Anthropic winning a related case are remembering a different legal route. The September opinion discusses an August 27, 2026 Northern District of California decision setting aside a designation under 10 U.S.C. § 3252. The D.C. Circuit case concerns 41 U.S.C. § 4713.

The difference is substantive:

Statute Distinction emphasized by the majority
10 U.S.C. § 3252 Refers to an adversary and to subversion. The panel accepted that this language requires bad motive.
41 U.S.C. § 4713 Refers to any person and to manipulation. The panel interpreted this definition more broadly.

The majority said it had no quarrel with the district court’s conclusion that Anthropic had acted without bad motive. It nevertheless held that the broader definition in § 4713 supported the procurement actions before it. Opinion, pp. 30–31 and footnote 1.

Describing Friday’s ruling as an appellate reversal of the California decision would therefore misstate the relationship between the two cases. The D.C. Circuit distinguished the other statute and exercised its own assigned review authority.

The constitutional claims also failed

On free speech, the majority recognized that Anthropic’s advocacy about AI safety was protected and that exclusion from the supply chain was an adverse government action. It found the necessary causal connection missing: in its reading of the record, the Department acted because Anthropic refused a contractual term, rather than because it publicly advocated safety regulation. Opinion, pp. 41–43.

On due process, the majority accepted the government’s need to act quickly and found that the notice and opportunity to respond shortly afterward were sufficient in the circumstances. Separately, it rejected the statutory challenge to delayed notice because Anthropic had not demonstrated prejudice from the timing. These are related but distinct reasons, and neither amounts to a general rule that procurement decisions require no process. Opinion, pp. 33–41.

What this means for Claude users and AI suppliers

For ordinary Claude users, the decision creates no general prohibition on using the chatbot or API. Its direct subject is exclusion from the Department’s supply chain, including contractor use in performing Department work. It should not be read as a blanket order forbidding every defense contractor from using Claude for every unrelated purpose. The contractual setting and the scope of the procurement action matter. Opinion, pp. 5–6 and 12–13.

For suppliers, our reading is that the ruling puts more pressure on the relationship between a model’s promised uses and its trained behavior. Agreeing to broad contractual terms will not, by itself, demonstrate that a model will reliably carry out every task covered by them. Conversely, a supplier’s transparent safety policy does not prevent the government from treating resulting refusals as a procurement risk under this decision.

The opinion also exposes two different reliability problems. A model can fail by refusing an appropriate request. It can fail by complying with a request it cannot safely or accurately execute. The majority acknowledged both risks in its closing discussion, including Anthropic’s concern about erroneous targeting. It placed the balance between them with the President and Secretary under the law at issue. That allocation of authority is a legal conclusion; it is not an engineering finding that unrestricted models are safe for autonomous weapons. Opinion, p. 43.

For background, Kingy previously covered the Pentagon’s original action against Anthropic and Anthropic’s efforts to prevent misuse of Claude. Those earlier stories describe the wider dispute; the September 25 opinion is the source for the ruling reported here.

The next concrete developments to watch are any request for further judicial review, a change to the procurement restrictions, or a revised agreement between the parties. Friday’s decision resolves these petitions. It leaves the technical challenge of making military AI dependable under real operating conditions to the agencies and suppliers deploying it.

Source note: This analysis is based on the full 51-page September 25 opinion, including Henderson’s dissent, Shumate’s linked post, and Anthropic’s earlier published explanation of its restrictions. Page references identify the majority’s printed pages unless the dissent is specified. The earlier Anthropic statement is background, not a response to Friday’s judgment. This article does not independently verify classified deployments or the disputed overseas incident.