D.C. Circuit backs Pentagon blacklisting of Anthropic as supply chain risk
A D.C. appeals court sided with the Pentagon in a 2-1 ruling that upholds Anthropic’s supply-chain risk label, rejecting the AI firm’s bid to block national-security limits on Claude.
The U.S. Court of Appeals for the D.C. Circuit ruled Friday that the Department of Defense had legal authority to designate Anthropic a supply chain risk and keep the company’s Claude models out of defense work. The 2-1 decision backs the Trump administration in a high-stakes fight over who controls how advanced AI is used in national security settings.
The Hill reported that Circuit Judge Gregory Kastas wrote for the majority, joined by Judge Neomi Rao, while Judge Karen LeCraft Henderson dissented. The panel found the Pentagon had “ample support” under the Federal Acquisition Supply Chain Security Act for treating continued use of Claude by the department or its contractors as a national security risk.
At the core of the dispute is a simple clash. Anthropic wanted hard limits on military use of its models. The Pentagon insisted it could use Claude for all lawful purposes. When talks over safety guardrails collapsed earlier this year, the designation followed, and President Trump directed civilian agencies to stop using Anthropic’s products.
Judges say Claude’s own limits posed a defense risk
Kastas framed the problem as operational, not political. The majority said the department reasonably feared Anthropic could shape Claude so the model would refuse national-security tasks the Pentagon considers contractually authorized and necessary.
In the opinion, Kastas wrote that the department “reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary.”
He went further on how those limits work in practice. Because Anthropic could enforce contractual restrictions through model training, the court said, officials reasonably worried that a critical defense system backed by Claude might “fail to engage” when the department expected it to act. The opinion also noted that, on more than one occasion, those restrictions already stopped Claude from performing tasks requested by government users.
One disclosed example came from 2025, when CDC staff used a commercial Claude model and some prompts were refused. Anthropic’s own usage policy bars normal models from disinformation campaigns, malicious cyber operations, censorship, and domestic surveillance, though the company also offers Claude Gov models with fewer refusals on classified work. The Pentagon’s demand was broader: authority for all lawful uses, not a private firm’s veto inside the chain of command.
Breitbart noted that the majority rested on Anthropic’s own model restrictions and did not need to find bad motive to uphold the designation. That reading treats supply-chain security as a readiness question first, whether warfighters can count on a tool when it matters.
Constitutional claims fell short on notice and motive
Anthropic had argued the blacklisting violated the First and Fifth Amendments. The majority rejected both theories.
On due process, Kastas wrote that the claim fails because the department promptly notified the company of the exclusion and its supporting rationale, then gave Anthropic a fair chance to contest it. On the First Amendment, the court held the exclusion turned on Anthropic’s refusal to accept a contract term the department deemed essential, not on the company’s support for heavier government regulation of AI.
Henderson dissented, arguing the government read the supply-chain risk statute too broadly. Designations of this kind have often been associated with foreign adversaries, a point Anthropic stressed when it sued the Trump administration in March over both the Pentagon label and the civilian stop-use directive. The majority still found the statute covered the risk the department described.
Court fights over executive power rarely travel in a straight line, as seen when a federal judge ordered notice rules before certain administration actions elsewhere. Here, the D.C. Circuit put national-security contracting back in the department’s hands.
California ruling points the other way
The appeals decision collides with a separate track in California. Last month, federal Judge Rita Lin found the government violated the First Amendment when it issued the supply-chain risk designation and sided with Anthropic’s argument that the move retaliated against constitutionally protected activity and raised Fifth Amendment due-process problems.
That split matters. Contradicting rulings can tee up a Supreme Court fight, the same kind of appellate pressure that appears when the Trump administration returns to the Supreme Court to defend contested policies. Anthropic’s spokesperson said the firm “respectfully disagrees” with the D.C. Circuit outcome and pointed straight at the California decision.
"Another federal court has already held the government’s parallel designation unlawful."
The spokesperson added that Anthropic remains confident in its position and is considering all options, including further review.
Earlier rounds in the same dispute already showed how fast the emergency docket can move. Fox News reported that a D.C. Circuit order denying Anthropic a stay weighed a contained risk of financial harm to one company against judicial management of how the department secures vital AI during active military conflict, and found the balance favored the government. Acting Attorney General Todd Blanche called that stay result a resounding victory for military readiness.
The Washington Examiner reported that a three-judge D.C. Circuit panel also refused Anthropic a preliminary injunction while agreeing a speedy final decision was needed after the company’s California win. Reuters reported Blanche’s broader point in that phase: military authority and operational control belong to the commander-in-chief and the department, not a tech company.
Pentagon officials call the ruling a win for warfighters
Emil Michael, the Pentagon under secretary for research and engineering and a central figure in the talks with Anthropic, celebrated Friday’s merits ruling on X. He wrote that the hammer of justice had smashed Anthropic’s arguments and that the company is a supply chain risk to the defense industrial base. He added that warfighters will sleep better knowing no private company will insert its opinions in the chain of command, and that Secretary Pete Hegseth was right.
Breitbart also carried praise from Pentagon spokesman Sean Parnell, who said the D.C. Circuit ruling completely validates the department’s position. The message from the building is consistent: contractors do not get to revise lawful mission requirements through model training and refusal policies.
Trump-nominated judges on the majority drew a bright line between corporate safety branding and defense procurement control. That posture fits a wider pattern in which Trump-appointed judges shape major rules when statutes and national interests collide with institutional resistance. It also stands apart from cases where a Trump-appointed judge rejects a DOJ theory on different facts, the through-line is textual authority, not a rubber stamp.
Guardrails, lethal autonomy, and “all lawful uses”
Anthropic’s red lines were not vague. The company asked that its technology not be used in fully autonomous lethal weapons or for mass surveillance of Americans. The Pentagon’s counter was categorical: Claude should be available for all lawful uses. Once negotiations failed, the supply-chain designation and the civilian-agency directive followed.
Supporters of the administration’s approach see a basic accountability problem. If a model can be trained to refuse orders the government believes are lawful and necessary, then the vendor, not the elected commander-in-chief or Senate-confirmed secretary, holds a quiet veto inside sensitive systems. The D.C. Circuit majority treated that veto risk as enough to sustain the FASCA designation.
Critics, including Anthropic and the California court, cast the same facts as punishment for protected advocacy on AI limits. The D.C. Circuit majority rejected that story. It said the exclusion tracked a refused contract term, not a crackdown on the company’s regulatory politics. Henderson’s dissent keeps the statutory-breadth fight alive, and Anthropic’s promise of further review means the conflict is not finished.
Large technology fights increasingly land in the same courts that handle other hard power questions for the administration, from procurement to sanctions policy like tariffs reaching 100 percent on Russia. The Anthropic case is about whether private AI labs can hard-code their policy preferences into tools the Pentagon may need under fire.
For now, the D.C. Circuit has answered in the government’s favor. The designation stands. Claude’s path into defense systems runs through terms the department calls essential, not through a vendor’s unilateral refusals. Anthropic can seek further review. The California judgment still points the other way. A Supreme Court clash remains possible.
National security software is not a seminar on corporate ethics. If a contractor can train a model to freeze at the moment of command, the chain of command is already broken, and Friday’s ruling put that risk back where it belongs, under lawful military authority.




