- The D.C. Circuit voted 2-1 on September 25 to uphold the Pentagon's March 3 order removing Claude from Defense Department systems and contractor work under the Federal Acquisition Supply Chain Security Act.
- The majority held that Anthropic's ability to make Claude refuse tasks through training, which the record shows blocked requests from the CDC and intelligence users, counts as a risk that "any person" may "manipulate" a covered system.
- A San Francisco court struck down a parallel order under a narrower law on August 27, so Claude's exclusion now rests on one statute and a split between courts that could reach the Supreme Court.
A federal appeals court has ruled that the feature Anthropic sells as safety, restrictions trained directly into Claude, is a legitimate reason for the Pentagon to treat the company as a national-security supply chain risk, and that reasoning now applies to every AI lab that enforces its usage policy inside the model.
The D.C. Circuit upheld the Claude ban on a 2-1 vote
Judge Gregory Katsas wrote the majority opinion in Anthropic PBC v. U.S. Department of War, joined by Judge Neomi Rao, and Judge Karen LeCraft Henderson dissented. The panel heard argument on May 19 and rejected all three of Anthropic's challenges, finding the exclusion authorized by the statute, adequately supported by the record and consistent with the First and Fifth Amendments. The order it upheld bars the Department and its contractors from using Claude in the Department's information systems.
The dispute began over two contract terms. Anthropic would not let Claude be used for fully autonomous weapons or mass domestic surveillance, and the Department wanted access for "all lawful uses." Secretary Pete Hegseth set a February 27 deadline, Anthropic refused on February 26, and the formal determination followed on March 3. Anthropic told reporters it "respectfully" disagrees, noted that "another federal court has already held the government's parallel designation unlawful," and said it is considering all options, "including further review."
The court treated trained-in refusals as the security risk
The heart of the opinion is how it reads one phrase. Under 41 U.S.C. section 4713, a supply chain risk is the risk that "any person" may sabotage a covered system "or otherwise manipulate" its design or operation. The majority read "manipulate" in its ordinary sense of controlling how something operates, and it pointed to Anthropic's own account of its product: the company "encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent."
The record gave the court concrete examples. When defense and intelligence agencies started running commercial Claude in classified systems in 2024, the model refused work such as summarizing threat assessments and translating intercepted material describing violence, which led Anthropic to release a separate Claude Gov model in March 2025. Claude also refused queries from the Centers for Disease Control and Prevention on infectious disease research. Most recently, the two sides disputed whether Anthropic's contract barred Claude's use in an ongoing overseas military operation.
“The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail. Anthropic raises the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force. Both possibilities present obvious national-security concerns. But in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks.”
Judge Gregory Katsas, majority opinion, Anthropic PBC v. U.S. Department of War, D.C. Circuit, September 25, 2026
Judge Henderson read the same words as aimed at covert sabotage by hostile actors, the threat Congress described when it passed the law in 2018. On her reading, the majority's version sweeps in "a contractor's honest and upfront enforcement of restrictions on a covered article's use disfavored by the government." The majority answered that the statute says "any person" and cannot be limited to foreign adversaries.
The ruling makes an AI lab's refusal policy a question of military reliability, and a lab that can switch a behavior off inside the model is, in the court's reading, a lab that controls the government's system.Santage analysis
Two statutes explain why two courts split on the same ban
Hegseth excluded Claude under two separate laws, which is why the case ran in two courts. The San Francisco ruling that found the Pentagon's action illegal in August dealt with the narrower one, and the D.C. Circuit said so directly.
| 10 U.S.C. section 3252 | 41 U.S.C. section 4713 (FASCSA) | |
|---|---|---|
| Court | N.D. California, Judge Rita Lin | D.C. Circuit, Katsas and Rao, Henderson dissenting |
| Who can pose the risk | "an adversary" | "any person" |
| Covered conduct | Sabotage or "otherwise subvert" | Sabotage, extract data or "otherwise manipulate" |
| Outcome | Designation set aside, August 27, 2026 | Designation upheld, September 25, 2026 |
Source: D.C. Circuit opinion, No. 26-1049, quoting both statutes, September 25, 2026.
The practical result is that Claude remains out of Defense Department work while Anthropic weighs a rehearing before the full D.C. Circuit or a petition to the Supreme Court. The official who wrote the memo behind the designation marked the ruling within hours.
Every lab's usage policy is now a procurement question
The opinion's reasoning reaches beyond Anthropic because every frontier lab shapes behavior through training, whether through reinforcement learning from human feedback or written model principles, and every lab ships refusals. What set Anthropic apart was a pair of contract terms it would not drop. OpenAI took the other path, announcing its own Pentagon agreement on February 28, a day after the Department broke with Anthropic. Under this ruling, a lab that keeps the ability to make a model decline lawful government tasks gives the Defense Department a statutory basis to exclude it, and defense contractors that build on that lab's models inherit the exposure.
The pressure also lands on the business case Anthropic has built for its planned public listing, where its safety positioning is a selling point to enterprises and a documented liability in the largest federal market. Buyers across the defense industrial base are likely to read the opinion as guidance on which model vendors are safe to standardize on.
Congress wrote the Supply Chain Security Act to keep compromised hardware and software from hostile suppliers out of federal networks, and the D.C. Circuit has now applied it to a domestic lab whose alleged manipulation consists of publicly stated safety rules. Unless the full court or the Supreme Court narrows that reading, the question for AI companies selling to the military is how much control over their own models they are willing to give up to keep the contract.
Santage is committed to independent, transparent journalism. This article is produced in accordance with Santage's Editorial Standards and aims to provide accurate and timely information. Readers are encouraged to verify information independently.