Skip to content
nanoai

Appeals court upholds the Pentagon’s risk label on Anthropic

The D.C. Circuit ruled 2-1 that Anthropic’s limits on military use of Claude can count as a national-security risk. A San Francisco ruling against a parallel designation still stands.

By Siva Charakani3 min read

AI companies news graphic showing a federal appeals court ruling, Pentagon building, gavel, Anthropic branding, and a 2–1 decision allowing the Pentagon to label Anthropic a supply-chain risk.
Image: AI Generated

Key takeaways

  • The D.C. Circuit ruled 2-1 on Sept 25 that the Pentagon lawfully labelled Anthropic a risk.
  • The majority read ‘manipulate’ as control of any kind, not only malicious interference.
  • A San Francisco judge struck down a parallel designation in August; that ruling still stands.

A federal appeals court in Washington has upheld the Pentagon’s decision to label Anthropic a supply-chain risk and remove its Claude models from military systems. The 2-1 ruling of the D.C. Circuit, issued on Friday, September 25, denied Anthropic’s petitions for review.

Judge Gregory Katsas wrote for the majority, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented. The ruling leaves the company with one court against it and one, in San Francisco, on its side.

What the fight was about

It started as a contract negotiation. According to the opinion, the Department of War, the administration’s name for the Defense Department, asked Anthropic for permission to deploy Claude for “all lawful uses”. Anthropic kept contractual bans on using Claude for “lethal autonomous warfare” and for “mass surveillance of Americans”.

On March 3, 2026, Secretary Pete Hegseth made a formal determination against Anthropic under the Federal Acquisition Supply Chain Security Act of 2018. A follow-up memo barred contractors from using Anthropic products in their work for the department and ordered Claude out of its systems within 180 days. Anthropic sued days later.

One word decided the case

The statute covers the risk that someone could “manipulate” a system’s design or operation. Anthropic argued that word implies hostile or malicious intent. The majority disagreed and read it in the plain sense of controlling or shaping something, whatever the motive.

On that reading, the rest followed. Anthropic trains Claude to refuse certain uses, so it controls what the model will do for the military. The court accepted the department’s view that narrower steps, such as testing each new model before use, would not work because AI systems are hard to audit, respond differently to slightly different prompts and change quickly. It rejected the free-speech claim, finding the exclusion followed Anthropic’s refusal of a contract term rather than its public advocacy, and treated the lack of advance notice as harmless.

“But in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks,” the majority wrote.

The dissent

Henderson read “manipulate” in the light of the words around it in the statute, as meaning to influence “in a subtle, devious, or underhand manner”. An openly stated use policy, on her reading, is not that. She also wrote that the department “made good on its promise” to designate Anthropic after it declined the Secretary’s “ultimatum” to replace its restrictions with an “all lawful uses” clause.

Two courts, two answers

In August, US District Judge Rita Lin in San Francisco ruled against a parallel designation, finding the government’s actions were based on a desire “to make a public example out of Anthropic”, ABC News reports. That ruling still stands, so after Friday one designation is in force and the other struck down.

Anthropic said it remains confident and is “considering all options, including further review”. Hegseth and department spokesman Sean Parnell praised the decision on X.

Why it matters beyond one company

The majority did not say the Pentagon is right about how Claude should be used. It said the choice belongs to the executive. That is the part other AI vendors will read closely.

If a supplier’s own limits on use can count as a supply-chain risk, every lab selling to the military faces the same trade: keep its usage policy, or accept “all lawful uses”. The likelier effect is that public-sector contracts become the place where these policies are decided, rather than the companies’ published rules.

What to watch next is whether Anthropic asks the full D.C. Circuit to rehear the case or goes to the Supreme Court, and whether the split between the two courts’ outcomes ends up in front of a higher bench.

  • Anthropic
  • AI policy
  • Claude
  • Pentagon
  • Courts
  • Defense

Sources

  1. Anthropic PBC v. United States Department of War, No. 26-1049 (D.C. Cir. 2026) — US Court of Appeals for the D.C. Circuit (via Justia), Sep 25, 2026
  2. US appeals court upholds Pentagon's supply chain risk label on Anthropic — The Next Web, Sep 25, 2026
  3. Federal appeals court upholds Pentagon designation of Anthropic as supply chain risk — ABC News, Sep 25, 2026

Follow The Nano AI: Instagram · X · LinkedIn · YouTube

Was this article helpful?

Comments

No comments yet. Start the conversation.

Be respectful. Comments are moderated.

Related stories

The AI briefing, without the noise.

The stories that matter in AI, sourced and explained. Free, and you can unsubscribe at any time.