The U.S. Court of Appeals for the D.C. Circuit ruled 2-1 on Friday that the Pentagon may keep Anthropic on its list of national-security supply-chain risks, upholding a designation that has barred the AI lab's Claude models from Defense Department systems and from the work of its contractors.
The dispute began in February, when President Donald Trump and Defense Secretary Pete Hegseth accused Anthropic of endangering national security after the company refused to allow its products to be used for fully autonomous lethal weapons or for mass domestic surveillance. Hegseth designated the company under two separate legal authorities; the case decided Friday turned on the Federal Acquisition Supply Chain Security Act.
Writing for the majority, Circuit Judge Gregory Katsas found the department had "ample support" for its action. He noted that by Anthropic's own admission, "the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent." Because those restrictions are enforced through model training, Katsas wrote, the department "reasonably feared that Anthropic might manipulate Claude's design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary."
The opinion also credited the government's broader concern, quoting the Secretary's warning about "the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail." The court pointed to a disclosed incident in which staff at the Centers for Disease Control and Prevention used a commercial Claude model in 2025 and found some prompts refused. Anthropic's First and Fifth Amendment claims were rejected: the panel found the department had promptly notified the company and given it a fair chance to contest the exclusion, and that the exclusion rested on Anthropic's refusal to accept a contract term rather than on its advocacy for AI regulation.
Judge Neomi Rao joined the majority. Judge Karen LeCraft Henderson dissented, arguing the government had read the supply-chain-risk statute too broadly. Both Katsas and Rao were nominated by Trump; Henderson by George H. W. Bush.
The ruling is a victory for the administration but not a settled legal picture. A federal judge in San Francisco ruled last month that a parallel Pentagon designation was unlawful retaliation in violation of the First Amendment, and blocked both a government-wide ban on Anthropic and Hegseth's order barring military contractors from doing business with the startup. The D.C. Circuit said it had "no quarrel" with that conclusion, holding only that a bad motive is not required to support a supply-chain designation. Anthropic said it "respectfully disagrees" and is weighing all options, including asking the full appeals court to rehear the case. Hegseth and Pentagon officials celebrated on social media.
For Anthropic, the practical damage is significant. The company says the designation has cost it billions in lost business and damaged its reputation just as it prepares a closely watched public listing. Longer term, the more consequential effect may be the signal it sends to the rest of the industry. If drawing an ethical line around autonomous weapons is enough to be branded a national-security risk, then restraint becomes a competitive liability at precisely the moment when restraint may matter most — and the rational move for every other AI company is to draw fewer lines.
Comments (0)
Log in to join the discussion
Log InNo comments yet