AI Affairs, home

Wednesday 30 September 2026

Government

US appeals court upholds Pentagon’s supply chain risk designation of Anthropic

The 2-1 ruling keeps Claude out of Pentagon systems and defence contractors’ work with the department, despite a separate August judgment against another designation.

An aerial view of the Pentagon building with surrounding parking lots and highways.
Photo: David B. Gleason from Chicago, IL, CC BY-SA 2.0, via Wikimedia Commons (cropped)

28 September 2026 — The US Court of Appeals for the District of Columbia Circuit upheld the Pentagon’s designation of Anthropic as a national security supply chain risk in a 2-1 decision on 25 September, CNBC reported. The designation prevents the military from using Anthropic’s Claude models and bars defence contractors from using them in work with the department. Anthropic had challenged the designation as arbitrary, unauthorised and unconstitutional.

Key points

  • The D.C. Circuit rejected Anthropic’s challenge to one of two Pentagon designations made under different laws.
  • Claude remains prohibited within the Pentagon and in defence contractors’ work with it.
  • An August ruling in San Francisco struck down the separate designation and allowed other government agencies and contractors to continue working with Anthropic.
  • The appeals panel delayed its decision taking immediate effect to give Anthropic time to seek a rehearing.

Katsas and Rao back the Pentagon

Judge Gregory Katsas wrote for the majority, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented. Katsas and Rao were appointed by President Donald Trump; Henderson was appointed by former President George H.W. Bush. The majority accepted the department’s assessment that continuing to integrate Claude into its systems, whether directly or through contractors, presented a national security risk covered by the law used for the designation.

The Pentagon’s case rested in part on the prospect that restrictions built into Claude could interfere with military operations. Katsas described Defense Secretary Pete Hegseth’s concern that a constrained model might stop working during an operation, and raised the possibility of manipulation of Claude, according to CNBC. Anthropic disputed those concerns. Katsas wrote that decisions about how to balance the competing risks belonged to Trump and Hegseth.

Anthropic argued that the government had retaliated against it for opposing the use of its AI in lethal autonomous warfare or mass surveillance of Americans. It also alleged violations of its First Amendment rights and of due process, and challenged the use of the national security law to exclude it. The majority rejected those arguments, ABC News reported.

Henderson disagreed with the majority’s reading of the law authorising the exclusion. In her dissent, she argued that a contractor openly enforcing restrictions on its product did not present the kind of supply chain risk for which that law permits blacklisting, according to ABC News. Her objection concerned the reach of the Pentagon’s designation power, even where the department objects to limits on a product it wants to use.

Claude restrictions followed a $200 million contract

The dispute grew out of negotiations over military access to Claude. Anthropic signed a $200 million Pentagon contract in July 2025, then entered talks about deploying Claude on the department’s GenAI.mil platform that September, CNBC reported. The department wanted access across all lawful purposes. Anthropic sought assurances against deploying Claude for weapons operating without human control or for mass surveillance inside the United States. The talks ended without an agreement.

Hegseth accused Anthropic of trying to obtain a veto over military operational decisions. Anthropic has rejected the administration’s characterisation of its position, saying AI is not yet reliable enough for safe use in autonomous weapons and that domestic mass surveillance violates fundamental rights, Reuters reported in Defense News. The Pentagon designated the company a supply chain risk in March 2026.

Anthropic says the designation has cost it billions of dollars in lost business and harmed its reputation ahead of an anticipated initial public offering, Reuters reported in Defense News. Those are the company’s estimates of its losses. For organisations subject to the D.C. designation, the operative restriction concerns use of Anthropic’s models by the military and by contractors in their work with the department.

San Francisco ruling governs a different designation

The Pentagon used two different legal authorities to designate Anthropic a supply chain risk, leading to lawsuits in separate courts. In August, US District Judge Rita Lin in San Francisco invalidated the parallel designation, ruling that the administration’s action was illegal retaliation for Anthropic’s views on AI safety. Lin also halted a prohibition on Anthropic across the federal administration and a Hegseth directive preventing military contractors from conducting any business with the company, Reuters reported in Defense News.

The D.C. Circuit’s decision concerned the other designation and did not reverse Lin’s ruling. Claude therefore remains prohibited within the Pentagon, while other government agencies and contractors can continue working with Anthropic under the San Francisco ruling, CNN reported. The government has not appealed that ruling, according to CNN.

The appeals panel delayed its decision taking immediate effect to allow Anthropic to petition the panel for a rehearing or ask all the D.C. Circuit judges to rehear the case. Anthropic could also ask the Supreme Court to hear it. The company said it respectfully disagreed with the decision and was considering its options, including further judicial review.

Topics: Foundation models, Regulation