A US federal appeals court has sided with the Pentagon in its unprecedented dispute with Anthropic, the developer of the Claude AI models, in a case that has become a test of how much control technology companies can keep over the use of their products by the military.
On Friday, September 25, the US Court of Appeals for the District of Columbia Circuit ruled 2-1 to uphold the Department of Defense's designation of Anthropic as a national-security supply-chain risk. The decision denies Anthropic's petitions to overturn the designation, which restricts the company's role in military contracts.
Judge Gregory Katsas wrote the majority opinion, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented.
The majority's reasoning
The majority found "ample support" for the Pentagon's conclusion that integrating Claude into Defense Department systems presented a national-security risk covered by the relevant statute, according to reporting by The Next Web.
"The Department reasonably feared that Anthropic might manipulate Claude's design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary," Katsas wrote, as quoted by the Associated Press.
The court rejected Anthropic's arguments that the designation was arbitrary, unlawful and unconstitutional. On the company's free-speech claim, the majority concluded that the Pentagon had acted because Anthropic refused to accept what it considered an essential contract term, not because of the company's public policy positions on AI safety.
The majority also noted that Anthropic had declined to relax contract terms barring the use of Claude for lethal autonomous warfare and domestic surveillance, and that Claude's built-in restrictions had previously blocked certain government requests.
The dissent
Judge Henderson disagreed on a central question of statutory interpretation. The 2018 federal law on supply-chain security, under which the designation was made, is aimed at risks that an adversary might sabotage or "manipulate" technology used in government systems.
In her view, "manipulate" requires deliberate, deceptive acts. It does not cover what she described as "honest and upfront enforcement of restrictions", in other words, a company openly stating the limits on how its product may be used.
The disagreement goes to the heart of the case. The supply-chain statute was designed with foreign adversaries in mind. Its use against a US company for enforcing publicly stated usage policies has been contested from the outset.
Anthropic's response
Anthropic said it would consider further legal action. "We respectfully disagree with the court's decision," the company said in a statement. "Another federal court has already held the government's parallel designation unlawful. We remain confident in our position and are considering all options, including further review."
Further review could include asking the full DC Circuit to rehear the case or petitioning the Supreme Court.
How the dispute began
The confrontation dates back to February. According to Reuters, Defense Secretary Pete Hegseth met Anthropic chief executive Dario Amodei and pressed the company to loosen restrictions on how the military could use its models. Anthropic had drawn two firm lines: Claude should not be used for lethal autonomous warfare without human oversight, or for mass surveillance of Americans. The company argued that its models had not been sufficiently tested for those uses.
When Anthropic refused to change its position, President Donald Trump directed federal agencies to stop using the company's technology, and Hegseth moved to designate Anthropic a supply-chain risk. Reuters reported that it was the first public use of the measure against a US company.



