The most consequential part of the D.C. Circuit’s new Anthropic ruling is easy to miss. The court did not decide whether Claude should be allowed to select military targets, nor did it endorse mass domestic surveillance. It decided who gets the last word when an AI supplier’s guardrails collide with the Pentagon’s demand for software that will perform every lawful military use.
In a 2–1 decision issued on September 25, a panel of the U.S. Court of Appeals for the D.C. Circuit denied Anthropic’s petitions to overturn the Department of War’s exclusion of Claude from its supply chain. Judge Gregory Katsas, joined by Judge Neomi Rao, concluded that the department had enough evidence to treat the prospect of model restrictions interfering with an expected military function as a covered supply-chain risk. Judge Karen LeCraft Henderson dissented, arguing that Congress wrote a narrower law aimed at sabotage and covert manipulation, not a supplier’s openly stated limits.
That split matters beyond one contract. It gives federal agencies a powerful procurement theory for frontier AI: a model’s behavior, including restrictions designed into it before delivery, can be treated as a supply-chain issue when the agency believes those restrictions could make a larger system fail to operate as intended.
The case is Anthropic PBC v. United States Department of War, consolidated under docket numbers 26-1049 and 26-1162. According to the 51-page opinion, the dispute arose after the department demanded contractual permission to use Claude for “all lawful uses.” Anthropic would not remove two restrictions: fully autonomous weapons that take humans out of the targeting loop, and mass surveillance of Americans.
Anthropic’s February 26 statement argued that current frontier models were not reliable enough to power fully autonomous weapons and that AI-enabled mass surveillance threatened civil liberties. The company nevertheless said it supported a broad range of defense applications, including foreign intelligence, operational planning and cyber operations.
The department’s position was operational rather than philosophical. Its January AI strategy required models free of policies that could limit lawful military applications. The record also described earlier cases in which commercial versions of Claude refused government prompts involving classified materials and sensitive public-health research. Anthropic developed Claude Gov and worked with government users to address those problems, but the incidents showed that model training could change what the software would do.
The confrontation sharpened in February. Secretary Pete Hegseth demanded the “all lawful uses” term on February 24. Anthropic publicly refused on February 26, following the weapons-policy standoff TECHi had tracked in Anthropic’s challenge to the Pentagon’s AI demand. On March 3, Hegseth formally determined that Claude presented a supply-chain risk under the Federal Acquisition Supply Chain Security Act, or FASCSA. The department ordered the removal of Anthropic products as soon as practical, with a 180-day outside deadline, and prohibited contractors from using Claude in work performed for the department.
The majority upheld three connected determinations: that removing Claude was necessary to reduce a national-security supply-chain risk, that less intrusive measures were not reasonably available, and that the department could act immediately before completing the ordinary notice process. It also rejected Anthropic’s Fifth Amendment due-process and First Amendment retaliation claims.
FASCSA authorizes covered procurement actions when information technology creates a risk that someone may sabotage, introduce unwanted functions, extract data or otherwise manipulate a product’s design or operation so as to deny, disrupt or manipulate its use. The majority read “manipulate” broadly enough to include restrictions that Anthropic knowingly trains into Claude before delivering a new model.
The opinion emphasized that Anthropic can shape how Claude responds through model training, technical controls and contract terms. Anthropic said it has no remote “kill switch” and cannot alter a model after it has been delivered into a classified environment. The majority accepted that point, yet found it incomplete: each new version still arrives with behavior shaped by Anthropic, and the model can sit inside a larger defense system whose function depends on Claude’s responses.
That is the ruling’s durable procurement lesson. A vendor does not need a hidden backdoor or post-deployment access to create a supply-chain risk under the majority’s reasoning. If a supplier controls the design of a component and the agency reasonably fears that the component may decline an expected task, the agency can treat that behavior as a risk to the surrounding system.
The panel also deferred heavily to the executive branch on national security. It said the court could not substitute its policy judgment for the department’s assessment of how an AI model might behave during a military operation. That deference carried through the analysis of narrower alternatives. Instead of auditing every contractor and every possible use, the department was allowed to make what the majority called a “clean break.”
Judge Henderson’s dissent attacked the statutory interpretation at its foundation. In her reading, the verbs Congress chose—sabotage, maliciously introduce, extract and manipulate—describe deceptive or hostile interference with a technology supply chain. Anthropic’s restrictions were public, contractual and central to its negotiations with the government. Treating that conduct as manipulation, she wrote, stretches a security statute past the kind of covert supply-chain compromise it was designed to address.
This is more than a semantic disagreement. The majority’s approach can apply to any AI company whose model includes a refusal layer, safety classifier, policy constraint or capability limitation that a federal customer considers incompatible with its mission. The dissent would keep the statute focused on hidden or underhanded compromise and leave an openly negotiated disagreement to ordinary procurement law.
The 2–1 split therefore creates a real appeal issue. Anthropic could seek rehearing by the full D.C. Circuit or ask the Supreme Court to review the case. Whether either court would take it is uncertain, but the dissent gives the company a defined statutory argument rather than only a policy objection.
The decision is narrower than a blanket ban on Claude.
Anthropic itself drew that boundary in a March 5 customer update, saying the designation could not reach a contractor’s unrelated commercial use of Claude. That statement came as Anthropic revived talks around its $200 million military AI agreement. The court’s description of the March 6 implementation memo likewise ties the contractor restriction to work for the department.
That distinction is especially important for cloud distribution. Earlier in the dispute, Microsoft said Claude would remain available to commercial and non-defense government customers, a position TECHi covered in its report on Microsoft’s Anthropic access decision. The new opinion does not convert that Pentagon-specific restriction into a general federal or private-sector prohibition.
The practical effect will show up first in contract language and model testing.
Federal buyers are likely to demand clearer disclosure of refusal behavior, model-level safety constraints and the process for changing those constraints. “All lawful use” clauses may become more common in defense procurement, but a phrase that broad still leaves operational questions: who determines that a use is lawful, what happens when a model refuses by mistake, and how quickly must a supplier produce a corrected version?
Contractors will also need to map where a frontier model sits inside a larger system. The majority repeatedly focused on the possibility that Claude could limit the function of an application layered around it. A prime contractor that treats a general-purpose model as a replaceable API may discover that the government views the model as a mission-critical component with its own supply-chain obligations.
Testing will have to cover refusals, not only accuracy and security. A benchmark showing that a model can summarize intelligence is different from an acceptance test showing that the deployed version will respond consistently to the agency’s lawful prompts. The record cited early refusals involving violent classified material and infectious-disease research, even though Anthropic said those glitches were resolved. Under the court’s logic, a resolved refusal still proves that supplier-designed behavior can constrain a government workflow.
The decision may also favor vendors willing to build government-specific models and terms. Anthropic had already created Claude Gov and a government addendum, as described in both the opinion and its earlier government-access announcement. The dispute was not about whether customization was possible. It was about whether a supplier could retain two non-negotiable limits after the department declared them incompatible with its strategy.
The immediate beneficiary is not automatically the company with the strongest general benchmark score. It is the provider whose technical controls and contract posture most closely match the customer’s mission.
The opinion says the department moved to expand its relationship with OpenAI after beginning Claude’s removal. That detail shows how policy architecture can become a competitive product feature. In national-security procurement, a model’s permissible-use envelope can matter as much as latency, context length or reasoning performance.
Microsoft, Amazon and Google face a related distribution problem. Each can make multiple model families available through its cloud, but a government authorization does not override a model maker’s terms or an agency’s procurement exclusion. Anthropic’s prior approvals for Claude on Amazon Bedrock government workloads and Google Cloud’s authorized environments established that Claude could meet demanding infrastructure standards. The D.C. Circuit case shows that infrastructure compliance and behavioral acceptability are separate gates.
That distinction is the TECHi angle the headlines miss: the government AI market now has two supply chains. One is physical and operational—cloud regions, access controls, software dependencies and model delivery. The other is behavioral—the model’s training, refusal rules and the supplier’s authority to define acceptable use. The majority treated the second as legally part of the first.
The panel denied Anthropic’s petitions rather than sending the matter back for a narrower remedy. Unless the ruling is reheard, stayed or reversed, the department’s exclusion remains in place on the terms described in the record.
The next signals to watch are concrete. Anthropic must decide whether to seek rehearing or Supreme Court review. The department and its contractors must complete the transition away from Claude in covered work. Rival AI providers will have to show that their models can satisfy military acceptance testing without producing a different set of safety or reliability problems. Contract drafters across the government will study the opinion’s broad reading of “manipulate.”
The unresolved policy question is harder than the legal holding. The majority closed by acknowledging two serious risks: an overly constrained model could fail during a military operation, while an unconstrained model could hallucinate an inappropriate lethal target. The court said elected executive officials, not judges or suppliers, must balance those dangers for the military.
That gives the government procurement authority. It does not make the underlying engineering problem disappear.
Article Brief
Key takeaways
5 Points30s Read
Motorola launched the Signature 27 at the Snapdragon Summit 2026, introducing a new flagship to…
Motorola launched the Signature 27 at the Snapdragon Summit 2026, introducing a new flagship to…
Bitcoin is holding near $84,000, but the more revealing number is $85,582. That is the…
Nvidia and Tesla spent Monday trading like two different answers to the same question: how…
OPPO is launching its September update to ColorOS 16, adding new features to improve the…
OPPO is launching its September update to ColorOS 16, adding new features to improve the…