U.S. Appeals Court Upholds Pentagon's Designation of Anthropic as Supply Chain Risk

Verdict: The appeals court upheld the Pentagon’s blacklist of Anthropic, confirming the AI firm as a supply‑chain risk for the U.S. military.

The U.S. Court of Appeals for the District of Columbia, in a 2‑1 decision, rejected Anthropic’s claim that the Department of Defense’s (DoD) ban on its Claude models was arbitrary, unauthorized, and unconstitutional. The majority opinion, written by Judge Gregory Katsas and joined by Judge Neomi Rao—both Trump appointees—found that the DoD had sufficient statutory authority under the Supply Chain Security Act to label Anthropic a national‑security risk.


Legal Reasoning: The court affirmed the DoD’s statutory authority and national‑security rationale.

  • Statutory basis – The judges held that the DoD’s decision fell squarely within the Supply Chain Security Act, which empowers the department to block products that pose a “statutorily covered national‑security risk.”
  • Risk assessment – The majority cited the Pentagon’s concerns that Claude could be manipulated, could shut down unexpectedly, or could be used for autonomous weapons or mass surveillance, all of which constitute legitimate security worries.
  • Dissent – Judge Karen LeCraft Henderson (appointed by George H.W. Bush) dissented, arguing that the designation overreached the department’s authority and effectively punished Anthropic for insisting on usage safeguards.

Immediate Impact: Anthropic’s models are barred from all DoD contracts and from defense contractors working with the Pentagon.

  • Contractual fallout – The designation nullifies Anthropic’s $200 million contract signed in July 2025 for responsible AI development in defense operations.
  • Operational restrictions – U.S. military and its contractors cannot integrate Claude into any system, and any existing integrations must be removed.
  • Future legal avenues – Anthropic may petition the same panel for a rehearing, seek an en banc rehearing, or appeal to the Supreme Court.

Context: The dispute stems from a clash over model access and usage safeguards.

  • DoD’s demand – The Pentagon wanted unrestricted access to Claude for all lawful purposes, including potential weaponization.
  • Anthropic’s stance – The company insisted on guarantees that its models would not be used for fully autonomous weapons or domestic mass‑surveillance, and that it could retain control over model deployment.
  • Negotiation breakdown – Talks collapsed in September 2025, leading Defense Secretary Pete Hegseth to accuse Anthropic of trying to “seize veto power” over military decisions.

Reactions from the community and commentators

"It seems like a textbook designation: Anthropic wanted rules on military use, the military said no, so the Pentagon blacklisted them." – ApolloFortyNine (HN comment)

"This smells like corruption; OpenAI faces no comparable punishment while Anthropic is being singled out." – prometheus1992 (HN comment)

"Supply‑chain risk is a massive over‑reaction, but understandable if the government can’t rely on a vendor’s willingness to comply with unrestricted use." – HarHarVeryFunny (HN comment)

"The decision shows how courts defer to the executive on national‑security matters, even when the underlying dispute is a contract disagreement." – gip (HN comment)


Broader Implications for AI in Defense

  • Precedent for future blacklists – This ruling may empower the DoD to label other AI providers as supply‑chain risks if they impose usage constraints, potentially limiting the ability of companies to enforce ethical safeguards.
  • Dual‑use technology tension – The case highlights the clash between commercial AI firms that seek to limit weaponization and a military that demands unrestricted access to cutting‑edge models.
  • Impact on open‑source and third‑party components – Legal scholars note that if contractual guardrails can trigger a supply‑chain risk designation, it could chill the development of open‑source AI tools used in defense software.

What’s next?

  • Potential rehearing – Anthropic has a limited window to request a rehearing from the same panel.
  • En banc review – The full D.C. Circuit could be asked to reconsider the case en banc, which would involve all active judges on the court.
  • Supreme Court – If lower‑court remedies fail, Anthropic may petition the U.S. Supreme Court, though the Court historically grants deference to the executive on national‑security classifications.

Takeaway

The appellate court’s affirmation of the Pentagon’s blacklist solidifies the government’s authority to treat AI providers that refuse unrestricted military access as supply‑chain risks, setting a significant legal precedent that could shape the future relationship between commercial AI firms and U.S. defense procurement.

Sources

Related