Security & Governance

US appeals court upholds Pentagon's blacklisting of Anthropic over Claude's safety restrictions

A DC Circuit ruling on 26 September 2026 lets the Pentagon keep Anthropic out of its AI supply chain for refusing to remove Claude's weapons and surveillance limits.

security governance category

On 26 September 2026, the US Court of Appeals for the District of Columbia Circuit ruled 2-1 that the Pentagon was within its rights to designate Anthropic as a supply-chain risk, upholding a decision that bars the company’s Claude models from Defence Department systems. The ruling is one of the most consequential AI procurement decisions in recent memory, and it raises questions that go well beyond Anthropic itself.

How we got here

The dispute has roots in how the Pentagon actually used Claude. From mid-2025, Claude Gov models were running on classified military networks, partly through a partnership with Palantir Technologies. Anthropic had signed a $200 million contract with the Department of Defense in July 2025, and its models were embedded in mission workflows. The company had also updated its usage policy over time to permit weapons design, foreign intelligence analysis, and offensive cyber operations for government customers.

Two things remained off-limits: the use of Claude in fully autonomous lethal weapons systems, and mass domestic surveillance of Americans. These restrictions had been in Anthropic’s policy since June 2024, and the Pentagon signed its contract with full knowledge of them.

On 24 February 2026, Defence Secretary Pete Hegseth formally demanded that Anthropic remove all usage restrictions and grant the Pentagon the right to use Claude “for all lawful purposes.” Anthropic refused. The Pentagon designated Anthropic a supply-chain risk in March 2026, citing the Federal Acquisition Supply Chain Security Act, a statute normally reserved for firms linked to foreign adversaries. It was the first time the designation had been applied to an American company. President Trump followed on 27 February 2026 by directing federal agencies to cease all use of Anthropic’s technology immediately.

Anthropic sued, arguing the designation violated the First Amendment and was legally unsound.

What the court decided

The majority opinion, written by Judge Gregory Katsas (a Trump appointee, joined by Judge Neomi Rao), found that “the Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems presented a statutorily covered national-security risk.”

The court’s reasoning turned on a specific point: Anthropic encodes restrictions directly into Claude’s behaviour with each new version, and because the military must update its systems to use the latest models, the Pentagon could reasonably fear that future versions might be configured in ways that block legitimate national-security use. Judge Katsas wrote that “the Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorised and necessary.”

The majority also addressed the First Amendment argument, acknowledging that Anthropic’s public advocacy on AI safety is protected speech, but finding that the exclusion was triggered by the company’s refusal to agree to the “all lawful purposes” provision, not by its speech.

Judge Karen LeCraft Henderson dissented. In her view, the law does not treat “a contractor’s honest and upfront enforcement of restrictions” as the kind of supply-chain risk that warrants a blacklist.

A split verdict across two courts

The picture is not clean-cut. On 27 August 2026, a federal judge in California reached the opposite conclusion. Judge Lin, ruling in the Northern District of California, found that the Pentagon’s actions constituted unlawful retaliation against constitutionally protected expression, and also found the supply-chain designation “arbitrary and capricious.”

The practical result of having two courts reach opposite conclusions is a patchwork. The DC Circuit ruling means Claude remains prohibited within Pentagon systems. The California ruling means other federal agencies and contractors can still work with Anthropic. The company says it is “considering all options, including further review,” which could mean asking the full 11-judge DC Circuit to rehear the case en banc.

What this means for Anthropic

The financial stakes are significant. Anthropic told the court that more than 100 enterprise customers contacted the company after the designation, and estimated the government’s actions risk “hundreds of millions, or even multiple billions, of dollars in lost revenue” for 2026. The company has been building toward a substantial IPO, reportedly before the end of this year, and its enterprise AI business is central to that plan. A Pentagon blacklist is not a small thing for a company pitching itself to large organisations.

What this means for the broader AI industry

This is the part that matters for anyone selling AI models to government or regulated industries.

The ruling effectively establishes a precedent: a supplier’s safety restrictions, if they conflict with what a government customer wants to do, can be framed as a supply-chain risk. The Computer and Communications Industry Association, along with ITI, SIIA, and TechNet, filed amicus briefs in both courts warning that allowing a tool normally reserved for foreign adversaries to be used as commercial leverage after a contract dispute creates serious risks for the entire technology sector.

More than 500 employees from Google DeepMind and OpenAI signed an open letter urging companies not to yield to demands for domestic mass surveillance or autonomous weapons. That letter reflects a wider anxiety in the industry: if a company can be blacklisted for maintaining safety policies that were known and accepted at contract signing, what does that mean for any AI provider’s ability to maintain meaningful restrictions on how its models are used?

The question the DC Circuit has essentially answered is this: the government can decide that a supplier’s unwillingness to remove safety restrictions poses a national-security risk, even if those restrictions were publicly documented before the contract was signed. Whether that answer holds up across further appeals, or whether Congress responds with clearer procurement rules, remains to be seen.

What to watch next

Anthropic has several options: seek en banc rehearing at the DC Circuit, pursue further appeal on First Amendment grounds, or attempt to have the conflicting California and DC rulings reconciled at a higher level. The split between circuits makes Supreme Court involvement a real possibility over time.

For enterprise buyers and contractors, the immediate practical question is whether their own AI procurement agreements include clauses about usage policy changes, and whether the models they rely on have restrictions that a government customer might one day object to. The Anthropic PBC v. United States Department of War case (No. 26-1049) has made that question much harder to ignore.