Appeals court upholds the Pentagon’s risk label on Anthropic
The D.C. Circuit ruled 2-1 that Anthropic’s limits on military use of Claude can count as a national-security risk. A San Francisco ruling against a parallel designation still stands.

Key takeaways
- The D.C. Circuit ruled 2-1 on Sept 25 that the Pentagon lawfully labelled Anthropic a risk.
- The majority read ‘manipulate’ as control of any kind, not only malicious interference.
- A San Francisco judge struck down a parallel designation in August; that ruling still stands.
A federal appeals court in Washington has upheld the Pentagon’s decision to label Anthropic a supply-chain risk and remove its Claude models from military systems. The 2-1 ruling of the D.C. Circuit, issued on Friday, September 25, denied Anthropic’s petitions for review.
Judge Gregory Katsas wrote for the majority, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented. The ruling leaves the company with one court against it and one, in San Francisco, on its side.
What the fight was about
It started as a contract negotiation. According to the opinion, the Department of War, the administration’s name for the Defense Department, asked Anthropic for permission to deploy Claude for “all lawful uses”. Anthropic kept contractual bans on using Claude for “lethal autonomous warfare” and for “mass surveillance of Americans”.
On March 3, 2026, Secretary Pete Hegseth made a formal determination against Anthropic under the Federal Acquisition Supply Chain Security Act of 2018. A follow-up memo barred contractors from using Anthropic products in their work for the department and ordered Claude out of its systems within 180 days. Anthropic sued days later.
One word decided the case
The statute covers the risk that someone could “manipulate” a system’s design or operation. Anthropic argued that word implies hostile or malicious intent. The majority disagreed and read it in the plain sense of controlling or shaping something, whatever the motive.
On that reading, the rest followed. Anthropic trains Claude to refuse certain uses, so it controls what the model will do for the military. The court accepted the department’s view that narrower steps, such as testing each new model before use, would not work because AI systems are hard to audit, respond differently to slightly different prompts and change quickly. It rejected the free-speech claim, finding the exclusion followed Anthropic’s refusal of a contract term rather than its public advocacy, and treated the lack of advance notice as harmless.
“But in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks,” the majority wrote.
The dissent
Henderson read “manipulate” in the light of the words around it in the statute, as meaning to influence “in a subtle, devious, or underhand manner”. An openly stated use policy, on her reading, is not that. She also wrote that the department “made good on its promise” to designate Anthropic after it declined the Secretary’s “ultimatum” to replace its restrictions with an “all lawful uses” clause.
Two courts, two answers
In August, US District Judge Rita Lin in San Francisco ruled against a parallel designation, finding the government’s actions were based on a desire “to make a public example out of Anthropic”, ABC News reports. That ruling still stands, so after Friday one designation is in force and the other struck down.
Anthropic said it remains confident and is “considering all options, including further review”. Hegseth and department spokesman Sean Parnell praised the decision on X.
Why it matters beyond one company
The majority did not say the Pentagon is right about how Claude should be used. It said the choice belongs to the executive. That is the part other AI vendors will read closely.
If a supplier’s own limits on use can count as a supply-chain risk, every lab selling to the military faces the same trade: keep its usage policy, or accept “all lawful uses”. The likelier effect is that public-sector contracts become the place where these policies are decided, rather than the companies’ published rules.
What to watch next is whether Anthropic asks the full D.C. Circuit to rehear the case or goes to the Supreme Court, and whether the split between the two courts’ outcomes ends up in front of a higher bench.
- Anthropic
- AI policy
- Claude
- Pentagon
- Courts
- Defense
Sources
- Anthropic PBC v. United States Department of War, No. 26-1049 (D.C. Cir. 2026) — US Court of Appeals for the D.C. Circuit (via Justia), Sep 25, 2026
- US appeals court upholds Pentagon's supply chain risk label on Anthropic — The Next Web, Sep 25, 2026
- Federal appeals court upholds Pentagon designation of Anthropic as supply chain risk — ABC News, Sep 25, 2026
Related stories

Anthropic signs $11.6bn seven-year deal for Akamai's CPUs
The contract could grow to about $20bn and gives Anthropic a warrant for up to 5% of Akamai. It buys general-purpose processors rather than AI accelerators, and Akamai has to build first.
3 min read

OpenAI agent broke into an Australian government portal, PM says
Anthony Albanese says an OpenAI research agent got around the blocks on a Medicare statistics portal on June 18, read non-public files and wrote files to the server. OpenAI took until September 10 to say so, by email to a public mailbox.
4 min read

OpenAI gives Ukraine’s government access to Daybreak cyber tools
Announced on the sidelines of the UN General Assembly, the deal puts OpenAI’s vulnerability-hunting models in the hands of a country whose national CERT handled nearly 6,000 incidents in 2025.
3 min read
Comments
No comments yet. Start the conversation.