Policy

US appeals court upholds Pentagon blacklisting of Anthropic over Claude safety limits

The D.C. Circuit ruled 2-1 on September 25, 2026 that the Pentagon may keep Anthropic's Claude models out of its systems, deepening a split with a California court.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 26, 2026 / 7 min read

A federal appeals court in Washington handed the Pentagon a major victory on September 25, 2026, ruling 2-1 that the Department of Defense acted within its authority when it designated the artificial intelligence company Anthropic a national-security supply chain risk. The decision from the U.S. Court of Appeals for the District of Columbia Circuit allows the Pentagon to keep stripping Anthropic's Claude models out of its systems and to bar its contractors from using the products for government work.

The dispute has been building since February 2026, when President Donald Trump and Defense Secretary Pete Hegseth accused Anthropic of endangering national security. At the center of the fight is Anthropic chief executive Dario Amodei, who refused to back down over concerns that the company's products could be used for mass surveillance or autonomous armed drones.

Anthropic has argued that the supply chain risk label was retaliatory and exceeded the government's statutory authority. The company says it cannot modify its models once they are delivered to the military, though it does determine the behavior of each new version, meaning the Pentagon must keep pace with the latest offerings. The military had been using Claude across a range of classified and sensitive systems.

The ruling immediately split the federal judiciary. A separate California federal judge had ruled in August 2026 that a related designation was unlawful, and the D.C. Circuit's decision now conflicts directly with that finding. Anthropic said it respectfully disagrees and is weighing its options, including a request for en banc review by the full appeals court or a further appeal.

Key Facts

The Associated Press reported on September 25 that the D.C. Circuit rejected Anthropic's challenge to the government's labeling of it as a supply chain risk, clearing the way for the Pentagon to continue removing Claude from its systems and barring the use of its products for Defense Department work. Judges Gregory G. Katsas and Neomi Rao, both Trump nominees, formed the majority, while Judge Karen LeCraft Henderson, nominated by George H. W. Bush, was the sole dissenter.

The conflict traces to February 2026, when Hegseth demanded that Anthropic drop its contractual restrictions on using Claude for fully autonomous lethal weapons and mass surveillance of Americans. The supply chain risk designation was formally signed by Hegseth on February 27, 2026, and announced by the Pentagon on March 3, canceling Anthropic's military contracts and barring other Pentagon contractors from using its technology.

AFP reported on September 26 that the military had been using Claude across a range of classified and sensitive systems before the designation. According to the decision, an Anthropic executive had questioned the use of Claude by a Pentagon contractor, Palantir, during the military operation that captured Venezuelan President Nicolas Maduro on January 3. Under Secretary of Defense Emil Michael is quoted in the opinion saying the objection led to alarm and raised material doubts about whether Anthropic would cause its software to stop working or cause some other disastrous action that would put warfighters' lives in danger.

The Hill reported on September 25 that in the case Anthropic PBC v. Department of War, the three-judge panel denied Anthropic's challenges and found the Department of Defense had ample support for its belief that continued use of Claude by the agency or its contractors presented a national security risk. The designation bars the military and its contractors from using the models and cut the company off from government contracts.

Judge Katsas wrote that the Department reasonably feared that Anthropic might manipulate Claude's design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary. He added that the Pentagon raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail.

Analysis

What this really means is that a vendor's own safety guardrails can now be treated as a national-security liability by the United States government. The majority found that the Pentagon had ample support to conclude that Claude's built-in restrictions, combined with the unresolved contract dispute, created a genuine national security risk. For any AI company that sells to the defense establishment, that is a striking precedent to absorb.

Pondero Newsdesk reported on September 26 that the ruling gives the Pentagon a court-tested precedent for treating an AI vendor's own safety guardrails as grounds for a supply chain risk label. The designation marked a highly unusual use of that authority against a U.S. company, and the precedent now rests on a split appellate panel rather than a unanimous court.

The dissent matters a great deal. Henderson argued that enforcing a model's own safety restrictions should not count as the kind of supply chain risk the statute was written to police. Her reading suggests that the majority stretched a security statute to cover a commercial disagreement about how a product should behave, a question that may eventually need the full D.C. Circuit or the Supreme Court to settle.

The bigger picture here is about market power as much as national security. The Pentagon immediately turned to Anthropic's competitors after the designation. OpenAI signed an agreement on the same day as Anthropic's ban, Elon Musk's xAI signed in February, and Google and Microsoft signed a few months later. Anthropic, valued at nearly $1 trillion, is heading toward an IPO expected in weeks. Legal uncertainty over its biggest government relationships lands at an awkward moment for the company.

Why It Matters

The decision creates two conflicting federal rulings on substantially the same government action. In August 2026, U.S. District Judge Rita Lin in the Northern District of California ruled that Anthropic prevailed on one of two statutory justifications the government used for a related designation, finding the stated rationale was in part an attempt to make a public example of the company rather than a legitimate security response. The D.C. Circuit's ruling now stands alongside it.

For Anthropic, the practical effect is continued exclusion from military work at a time when it is preparing to go public. The designation canceled its military contracts and bars other Pentagon contractors from using its technology. Even a company valued at nearly $1 trillion cannot easily replace a customer as large as the Defense Department, and the loss of a court-tested seal of approval may weigh on how quickly it can rebuild those ties.

For the broader industry, the ruling signals that refusing to loosen safety limits on a deployed model can carry real commercial consequences. The Pentagon's top spokesman, Sean Parnell, wrote in a social media post that the ruling completely validates the Department's position, language that leaves little room for the softer approach Anthropic had sought.

Next Up

Anthropic said it respectfully disagrees and is considering all options, including further review. That could mean asking the full D.C. Circuit for en banc review or taking the fight to a higher court, and the company has pointed to the earlier California ruling as evidence that its position has judicial support.

Meanwhile, the Pentagon can continue removing Claude from its systems and enforcing the contractor ban. With Anthropic's IPO expected in weeks and its rivals already signed up for defense work, the legal and commercial clock is running at the same time.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.

Sponsored