Appeals court lets the Pentagon exclude Claude, and says guardrails can count as a supply-chain risk
A split D.C. Circuit panel ruled that Anthropic's refusal-by-training is 'manipulation' under a 2018 procurement law, whatever the company's motive.
A federal appeals court on Friday upheld the Pentagon's decision to cut Claude out of its supply chain. In a 2-1 opinion issued on 25 September, the U.S. Court of Appeals for the D.C. Circuit denied Anthropic's petitions for review and held that the Department of War acted within its authority under the Federal Acquisition Supply Chain Security Act of 2018 when it excluded the company's models from its systems and from contractors' work for the department.
Judge Gregory Katsas wrote for the majority, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented. The case (Nos. 26-1049 and 26-1162, argued 19 May) is the first appellate ruling on the merits of the dispute, which began when Anthropic refused to drop two contractual limits on how the military could use Claude.
How the dispute got here
According to the court's account of the record, the department pushed from late 2025 for AI contracts that allow "all lawful uses". Anthropic agreed to loosen many earlier restrictions but kept two: no use of Claude for lethal autonomous warfare and no mass surveillance of Americans. After a 24 February meeting and a 27 February deadline, Anthropic publicly refused on 26 February. On 3 March, Secretary of War Pete Hegseth signed a formal determination under the supply chain act, a 6 March memo ordered Claude removed from department systems within 180 days, and Anthropic petitioned the D.C. Circuit on 9 March. The same court declined to pause the exclusion in April; the Secretary denied Anthropic's request for reconsideration on 3 June.
There are two separate designations in this fight. A federal district court in San Francisco set aside a designation under a different statute, 10 U.S.C. § 3252, on 27 August. Friday's ruling concerns the designation under 41 U.S.C. § 4713, whose review Congress sent exclusively to the D.C. Circuit. The majority said it had "no quarrel" with the California court's finding that Anthropic acted without bad motive, but held that § 4713 does not require one.
The core holding: guardrails can count as "manipulation"
The statute defines supply chain risk as the risk that someone may "sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate" an IT product so as to "deny" or "disrupt" its function. Anthropic argued that this language targets hostile actors. The majority read "manipulate" in its ordinary sense and concluded that training a model to refuse certain tasks fits the definition.
We have no reason to doubt that Anthropic manipulates Claude's function, use and operation with noble intentions, whether a principled commitment to personal privacy or a genuine concern about AI safety. But at least as applied here, the statutory definition of a "supply chain risk" turns on what Anthropic does, not why Anthropic does it.
The court leaned on points Anthropic itself put in the record: the company shapes Claude's behaviour through training on its constitution, can change those guardrails with every new model it delivers, and Claude had at times refused legitimate government work, including evaluating classified materials and CDC queries on infectious-disease research. It also cited a dispute over whether Claude's use in an overseas operation was permitted, which the department called alarming and Anthropic described as a misunderstanding.
Anthropic's main factual defence was that it has no kill switch: once a model is delivered for classified use, the company says it cannot access, alter or shut it down, so the department could test each new version and refuse it. The court was not persuaded. It noted that the contested restrictions are "hardly self-defining", that the department reasonably viewed the models as opaque to auditing, and that Anthropic acknowledged Claude "might respond differently to similar requests depending on their exact wording" — so a test with one phrasing does not guarantee the same answer later. It added that the department "cannot utilize AI systems that remain trapped in amber" by refusing every upgrade.
The court also rejected Anthropic's procedural and constitutional claims. It found any lack of advance notice harmless, because Anthropic later got to make its full case and the Secretary kept the exclusion anyway. On the First Amendment, it accepted that Anthropic's AI-safety advocacy is protected speech but found no causal link: in the court's reading, the department acted because Anthropic refused a contract term, not because of what the company said publicly.
The dissent
Judge Henderson argued that the surrounding words — sabotage, maliciously, surveil — show Congress was targeting intentionally hostile or deceptive acts, and that Congress wrote the law against hostile infiltration of government systems, not to pressure suppliers over their usage terms. Her warning is aimed at whoever replaces Anthropic: under the majority's view, she wrote, a contractor told to permit any functions the department deems necessary would have to "agree to the Secretary's demands or risk being designated a national security threat".
What changes, and for whom
For most developers using Claude through the API or consumer products, nothing changes on Friday: the exclusion covers the Department of War's systems and contractors' work for the department. Anthropic said in its March statement that the vast majority of its customers were unaffected; that statement addressed the § 3252 letter, and Friday's ruling concerns the separate § 4713 action, which covers department systems and contractors' work for the department.
The wider consequence is legal. The majority's reading means a vendor's usage policy, enforced through model training, can on its own count as a supply-chain risk under § 4713 — regardless of motive. Any AI provider selling to the U.S. military now has an appellate precedent saying that refusals built into a model are something the department may treat as a security risk. Teams building defence or defence-adjacent products on any commercial model should expect usage-policy terms and refusal behaviour to become explicit procurement questions.
The ruling is not necessarily final. Under normal appellate procedure Anthropic can seek rehearing by the panel or the full D.C. Circuit, or ask the Supreme Court to take the case. As of publication, Anthropic had not posted a statement about the decision on its newsroom, and Promptea could not confirm whether it plans to seek further review. Ars Technica reported the decision on Friday.
Why this matters
- It is the first appellate merits ruling in the Anthropic–Pentagon dispute, and it goes against Anthropic on every claim.
- The majority's reading means usage restrictions enforced through model training can by themselves justify a national-security exclusion, which affects every AI vendor selling to the U.S. military.
- The court cited prompt-wording variability as a reason pre-deployment testing cannot fully predict a model's refusals.
Key takeaways
- D.C. Circuit, 2-1, 25 September 2026: petitions denied (Katsas and Rao in the majority, Henderson dissenting).
- The case concerns the 41 U.S.C. § 4713 exclusion; a separate § 3252 designation was set aside in California on 27 August.
- Anthropic can still seek panel or en banc rehearing, or Supreme Court review.
Sources
- U.S. Court of Appeals for the D.C. Circuit (via CourtListener RECAP)PrimaryAnthropic PBC v. United States Department of War, Nos. 26-1049 & 26-1162 (D.C. Cir., decided Sept. 25, 2026)storage.courtlistener.com
- AnthropicPrimaryWhere things stand with the Department of Waranthropic.com
- Ars TechnicaCourt rules Trump can blacklist Anthropic for refusing to enable Claude featuresarstechnica.com
- policy
- national-security
- supply-chain
- ai-safety
- usage-policy
- courts
- defense
- claude
- procurement
- Anthropic
- U.S. Department of War
- Claude