TechArtificial Intelligence6 MIN READ

Appeals Court Upholds Pentagon's Supply-Chain Risk Label on Anthropic in a 2-1 Ruling on Who Sets Limits on Military AI

A divided US appeals court in Washington has upheld the Pentagon's designation of Anthropic as a national-security supply-chain risk. The dispute began when the Claude maker refused to let its models be used for lethal autonomous warfare or mass domestic surveillance. Anthropic says it is considering all options.

By Aravind Kumar · Author26 September 2026Breaking
Appeals Court Upholds Pentagon's Supply-Chain Risk Label on Anthropic in a 2-1 Ruling on Who Sets Limits on Military AI

A US federal appeals court has sided with the Pentagon in its unprecedented dispute with Anthropic, the developer of the Claude AI models, in a case that has become a test of how much control technology companies can keep over the use of their products by the military.

On Friday, September 25, the US Court of Appeals for the District of Columbia Circuit ruled 2-1 to uphold the Department of Defense's designation of Anthropic as a national-security supply-chain risk. The decision denies Anthropic's petitions to overturn the designation, which restricts the company's role in military contracts.

Judge Gregory Katsas wrote the majority opinion, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented.

The majority's reasoning

The majority found "ample support" for the Pentagon's conclusion that integrating Claude into Defense Department systems presented a national-security risk covered by the relevant statute, according to reporting by The Next Web.

"The Department reasonably feared that Anthropic might manipulate Claude's design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary," Katsas wrote, as quoted by the Associated Press.

The court rejected Anthropic's arguments that the designation was arbitrary, unlawful and unconstitutional. On the company's free-speech claim, the majority concluded that the Pentagon had acted because Anthropic refused to accept what it considered an essential contract term, not because of the company's public policy positions on AI safety.

The majority also noted that Anthropic had declined to relax contract terms barring the use of Claude for lethal autonomous warfare and domestic surveillance, and that Claude's built-in restrictions had previously blocked certain government requests.

The dissent

Judge Henderson disagreed on a central question of statutory interpretation. The 2018 federal law on supply-chain security, under which the designation was made, is aimed at risks that an adversary might sabotage or "manipulate" technology used in government systems.

In her view, "manipulate" requires deliberate, deceptive acts. It does not cover what she described as "honest and upfront enforcement of restrictions", in other words, a company openly stating the limits on how its product may be used.

The disagreement goes to the heart of the case. The supply-chain statute was designed with foreign adversaries in mind. Its use against a US company for enforcing publicly stated usage policies has been contested from the outset.

Anthropic's response

Anthropic said it would consider further legal action. "We respectfully disagree with the court's decision," the company said in a statement. "Another federal court has already held the government's parallel designation unlawful. We remain confident in our position and are considering all options, including further review."

Further review could include asking the full DC Circuit to rehear the case or petitioning the Supreme Court.

How the dispute began

The confrontation dates back to February. According to Reuters, Defense Secretary Pete Hegseth met Anthropic chief executive Dario Amodei and pressed the company to loosen restrictions on how the military could use its models. Anthropic had drawn two firm lines: Claude should not be used for lethal autonomous warfare without human oversight, or for mass surveillance of Americans. The company argued that its models had not been sufficiently tested for those uses.

When Anthropic refused to change its position, President Donald Trump directed federal agencies to stop using the company's technology, and Hegseth moved to designate Anthropic a supply-chain risk. Reuters reported that it was the first public use of the measure against a US company.

“We respectfully disagree with the court's decision... Another federal court has already held the government's parallel designation unlawful. We remain confident in our position and are considering all options, including further review.”
— Anthropic, statement following the ruling

The consequences were swift. Several federal agencies began cutting ties, and what had been a Pentagon relationship worth around $200 million turned into one of the sharpest confrontations yet between Washington and an American AI company.

A split legal picture

Anthropic has fought the government on more than one front, and the courts have not spoken with one voice.

In a separate case in San Francisco, US District Judge Rita Lin temporarily blocked a parallel government designation in March and issued a permanent ruling against it in August. According to Reuters, she described the government's action as "illegal and baseless" and wrote that "the empty invocation of national security is not a blank check to punish and retaliate against government critics."

Friday's appeals court ruling concerned a different designation made under the 2018 supply-chain statute, which is reviewed directly by the DC Circuit. The result is a split outcome: one designation has been found unlawful by a district court, while another has now been upheld on appeal. The contrasting decisions increase the likelihood that the dispute will continue through further appeals.

The wider industry context

The case has implications far beyond Anthropic. At its core is a question that will shape the relationship between governments and AI developers for years: who decides how commercial AI models may be used in military and intelligence settings?

The Pentagon's position is that it cannot rely on technology whose availability for lawful military missions could be restricted by a private supplier. Government lawyers argued that the dispute stemmed from Anthropic's refusal to accept contract terms, not from retaliation for its views.

Anthropic's position is that developers have a responsibility to set limits on uses they believe their systems are not ready for, particularly those involving lethal force or surveillance of citizens.

Other AI companies have taken different approaches. OpenAI announced its own agreement to deploy AI on Pentagon classified networks shortly after the Anthropic dispute erupted. OpenAI has said that its contract bars the use of its technology for mass domestic surveillance, directing autonomous weapons systems and certain high-stakes automated decisions. It also publicly opposed labelling Anthropic a supply-chain risk.

Business implications

For Anthropic, the ruling keeps a significant portion of potential government and defence-contractor business in question. It comes at a time when the company is expanding rapidly in the commercial market; on the same day, Akamai's shares surged after it announced an $11.6 billion cloud agreement with Anthropic.

Relations between Anthropic and parts of the US administration have reportedly improved in recent months, and some government agencies have continued to use its newer models. That creates an unusual situation in which the company is valued by parts of the government while being designated a risk by the Pentagon.

A question that will outlast the case

The DC Circuit's decision is a significant legal victory for the Pentagon and a setback for Anthropic. But with a dissenting opinion on the core statutory question, a contrary ruling from a district court and Anthropic weighing further review, the dispute is far from settled.

Whatever the final outcome, the case has already become a landmark in the debate over AI governance. It poses a question that companies, governments and courts around the world will have to answer: when an AI developer's safety limits conflict with a government's view of its national-security needs, whose judgement prevails?

TagsAnthropicPentagonDepartment of DefenseDC CircuitSupply Chain RiskAI PolicyMilitary AIClaudeAI SafetyNational SecurityDario AmodeiCourt Ruling

Reader reviews

Sign in to rate and review this article.
Loading reviews…