A federal appeals court has upheld the Pentagon’s decision to exclude Anthropic’s Claude AI systems from the department’s supply chain after the company refused to accept a contractual term permitting “all lawful uses” of the technology. The U.S. Court of Appeals for the D.C. Circuit denied Anthropic’s petitions for review in a September 25, 2026, decision, finding that the department acted within its authority under the Federal Acquisition Supply Chain Security Act. (media.cadc.uscourts.gov)

A procurement ruling for frontier AI vendors

The 2-1 decision is a consequential procurement ruling for frontier-model companies, whose commercial and government contracts increasingly include questions about who has the final say over a model’s permitted uses. Anthropic had agreed to relax many prior restrictions during negotiations, but retained prohibitions on using Claude for lethal autonomous warfare and mass surveillance of Americans. The Pentagon sought broader authorization, and the negotiations ultimately broke down. (media.cadc.uscourts.gov)

Judge Gregory Katsas wrote for the court, with Judge Neomi Rao on the panel majority; Judge Karen LeCraft Henderson dissented. The majority held that the department had sufficient support for concluding that continued integration of Claude in department systems, including through contractors, created a covered national-security risk. It rejected Anthropic’s claims that the action was arbitrary, beyond the governing statute, or unconstitutional. (media.cadc.uscourts.gov)

How the court defined supply-chain risk

At the center of the case was the statute’s definition of “supply chain risk.” The majority concluded that the provision can encompass an AI supplier’s ability to control or limit how its product functions, even absent an allegation that the supplier acted with malicious intent. In the court’s view, Anthropic’s acknowledged willingness and ability to enforce use restrictions through model training gave the department a reasonable basis to worry that a Claude-supported system might not perform as officials expected in a military setting. (media.cadc.uscourts.gov)

That conclusion does not mean the court found that Anthropic had remotely disabled Claude, deployed a so-called kill switch, or caused a confirmed operational failure. The opinion explicitly said it did not know exactly what happened in a disputed incident cited in the administrative record. Rather, the majority treated the disagreement over the scope and enforceability of the company’s use restrictions as relevant to the Pentagon’s need for confidence in the availability and behavior of systems used for defense work. (media.cadc.uscourts.gov)

The ruling also left intact the Pentagon’s finding that less restrictive measures were not reasonably available. The department reasoned that a narrower, system-by-system approach would involve delay, expense, and uncertainty because a model embedded in a larger application can affect that application’s functionality. The court said it would not override that fact-based national-security assessment. (media.cadc.uscourts.gov)

Scope of the exclusion

The direct scope of the decision is procurement-related, not a general prohibition on Claude. The court described the relevant authority as allowing the government to bar agency contracts with a supplier and subcontracts using that supplier for agency work. A March 6 department memorandum, described in the opinion, directed removal of Anthropic products from department systems and prohibited contractors from using those products in work for the department. (law.justia.com)

Anthropic’s position was that the two remaining restrictions reflected safety and civil-liberties concerns, not an attempt to interfere with lawful government operations. In a statement summarized in the court record, CEO Dario Amodei said mass domestic surveillance was incompatible with democratic values and argued that AI was not yet reliable enough to power weapons that select and engage targets without humans in the loop. The company had said the department could select another provider if it chose to offboard Anthropic. (media.cadc.uscourts.gov)

The panel rejected Anthropic’s First Amendment argument, concluding that the record showed the Pentagon acted because Anthropic would not agree to a contractual term that officials considered essential to national security, rather than because of the company’s public advocacy. The majority acknowledged that Anthropic’s speech about safe AI use is constitutionally protected, but found no causal connection sufficient to establish retaliation. (media.cadc.uscourts.gov)

The dissent and related California litigation

Henderson’s dissent illustrates why the ruling may resonate beyond this particular dispute. She argued that the supply-chain-risk definition should be read more narrowly in context, alongside terms such as sabotage and malicious introduction of unwanted functionality. Under that interpretation, a vendor’s openly stated and contractually negotiated safety restrictions would not fit the statutory category. (law.justia.com)

The D.C. Circuit decision also sits alongside a separate California federal-court case involving different legal authorities and a different route for judicial review. That court ruled for Anthropic on several claims, including First Amendment and due-process grounds, while the related appeal was stayed pending the D.C. Circuit’s decision. Ars Technica reported that the two courts were assessing the government action under different statutes, a distinction that helps explain why the D.C. Circuit did not treat the California decision as dispositive. (caselaw.findlaw.com)

What the decision means for AI suppliers

For AI suppliers, the practical implication is not that vendor safety policies are unlawful or that defense agencies can compel a company to redesign its models. The decision instead shows how a government customer may use supply-chain and procurement authority when it believes a supplier’s retained controls create an unacceptable operational risk. That could sharpen negotiations over deployment boundaries, contract language, auditability, model behavior, and contingency planning for AI systems used in sensitive government environments.

Industry groups said the decision raises broader concerns for technology vendors that want to sell to government while maintaining lawful limits on product use. The Software & Information Industry Association argued that procurement authority should not become a means of punishing companies over policy disagreements, while the Computer & Communications Industry Association said the ruling should concern government contractors. Those are advocacy positions, not findings of the court, but they reflect the commercial stakes of a decision that places contractual control of frontier AI closer to the center of national-security procurement. (siia.net)

Anthropic said it respectfully disagreed with the decision and was considering further review, according to reporting cited by Ars Technica. For now, the ruling leaves the Pentagon’s supply-chain exclusion in place and establishes a pointed legal test for AI developers: safety-based constraints can remain central to a company’s product policy, but in defense procurement they may also be evaluated as a potential constraint on mission availability. (arstechnica.com)