Anthropic's Pentagon Ban Upheld: What the Appeals Ruling Means

A federal appeals court ruled 2-1 on September 25, 2026 that the Pentagon lawfully cut Anthropic's Claude out of its supply chain. The ruling means an American AI company can be treated as a "supply chain risk" for enforcing usage limits on its own models, even in good faith. A separate California ruling against the government still stands.
What Happened
The U.S. Court of Appeals for the D.C. Circuit denied Anthropic's petitions for review in Anthropic PBC v. U.S. Department of War (No. 26-1049, consolidated with No. 26-1162). Judge Gregory Katsas wrote the majority opinion, joined by Judge Neomi Rao. Judge Karen LeCraft Henderson dissented. The case was argued on May 19 and decided on September 25, according to the court's published opinion.
The action under review was a written determination Secretary of War Pete Hegseth (the Pentagon now calls itself the Department of War) signed on March 3, 2026, under the Federal Acquisition Supply Chain Security Act of 2018 (FASCSA). It found that using Claude in Department systems "presents a significant supply chain risk." Anthropic got the notice by email on March 4. On March 6 the Department's Chief Information Officer ordered Anthropic products removed from Department systems "as soon as practical," and within 180 days at the latest. The same memo barred contractors from using Anthropic products in their work for the Department. Anthropic filed its petition on March 9.
The opinion traces how the relationship broke down. The Department and intelligence agencies began using commercial versions of Claude on classified systems through contractors in 2024. The Department included the company in a $200 million AI contract in July 2025. In the fall of 2025, the Department asked for permission to use Claude for "all lawful uses." Anthropic relaxed many of its restrictions but kept two: no lethal autonomous warfare and no mass surveillance of Americans. On January 9, 2026, Hegseth issued an AI strategy that told the Department to put "any lawful use" language into its AI contracts. He met CEO Dario Amodei on February 24 and set a February 27 deadline. Anthropic refused on February 26.
The court denied a stay on April 8 but expedited the case. The Secretary turned down Anthropic's request for reconsideration on June 3. After the ruling, Anthropic said in a statement reported by CNBC: "We respectfully disagree with the court's decision." It added that it is "considering all options, including further review."
Why It Matters
The ruling covers more than one vendor. The majority held that the statute's definition of supply chain risk applies to "any person," not just foreign adversaries, and that motive is irrelevant. In Katsas's words, the test "turns on what Anthropic does, not why Anthropic does it."
This affects every AI company that sells to the military. Most frontier labs enforce acceptable-use policies partly by training their models to refuse certain requests. Under this reading, a Pentagon that wants unrestricted models can treat that training as a reason to exclude the vendor. Google has already agreed to terms allowing "any lawful government purpose." In dissent, Henderson warned that the next contractor will face the same choice: accept the Secretary's terms "or risk being designated a national security threat."
The ruling also leaves two federal courts on different tracks. On August 27, Judge Rita Lin of the Northern District of California set aside a separate designation the Pentagon had issued under a different statute, 10 U.S.C. § 3252. Nextgov reported that she wrote "the empty invocation of national security is not a blank check to punish and retaliate against government critics." The D.C. Circuit said it had "no quarrel" with that decision because the two laws define risk differently. So Anthropic has won one case and lost the other, and the Pentagon's own procurement ban remains in force.
How It Works
The FASCSA procedure
Under 41 U.S.C. § 4713, an agency head can exclude a supplier after making three written findings. The exclusion must be necessary to protect national security by reducing supply chain risk. Less intrusive measures must not be reasonably available. The determination must also specify which procurement actions it allows. The supplier normally gets notice and a chance to respond first. If the agency head finds an "urgent national security interest," that notice can come afterward instead. Any challenge goes straight to the D.C. Circuit within 60 days. The court reviews it under a deferential "arbitrary and capricious" standard.
The word that decided the case
FASCSA defines supply chain risk as the risk that any person may "sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate" a covered IT product "so as to surveil, deny, disrupt, or otherwise manipulate" its function. The case came down to the word "manipulate."
The majority used the plain dictionary meaning, to operate or control something skillfully. On that reading, the court said there is "not only a 'risk'—but a certainty" that Anthropic shapes Claude so it refuses lethal autonomous warfare and mass domestic surveillance. Henderson read "manipulate" in light of the words around it, such as sabotage, malice and surveillance. She concluded Congress meant covert, hostile interference by bad actors, not a contractor's "honest and upfront enforcement" of use restrictions the government dislikes.
The older 10 U.S.C. § 3252 is narrower. It covers the risk that "an adversary" may "sabotage, maliciously introduce unwanted function, or otherwise subvert" a system. The words "adversary" and "subvert" require a hostile motive, and Judge Lin found Anthropic had none. That difference is why the two courts reached opposite results.
Why Claude itself became the risk
The opinion describes three ways Anthropic limits misuse:
- Model training. Claude is trained to follow a written "constitution" of principles. Some tasks, such as helping build biological or chemical weapons, have been disabled entirely.
- Technical measures. Anthropic added monitoring systems on top of its models starting around mid-2025.
- Contract terms. A Usage Policy prohibits specific uses, and a government addendum allows some uses it denies to private customers.
Anthropic argued that it has no back door or remote "kill switch." Once a model is delivered for use on classified systems, the company cannot access, alter or shut it down. The Department could test each new version before accepting it, and could keep using an older one, which the company said "does not degrade or change on its own."
The court did not find that enough. It said the disputed restrictions are "hardly self-defining," particularly when it comes to how much human involvement a targeting decision needs. It cited a Department declaration saying each Claude model has roughly 5 to 10 trillion parameters, which makes their outputs hard to audit. It noted that Claude can answer the same request differently depending on how it is worded. Finally, it said refusing upgrades is not realistic when models improve so quickly: the Department "cannot utilize AI systems that remain trapped in amber."
The constitutional claims
Both of Anthropic\'s constitutional claims failed. On due process, the court held that notice after the fact was enough, since the company had the full record within just over two weeks and a chance to contest it. On the First Amendment, it agreed that Anthropic\'s AI safety advocacy is protected speech but found no causal link to the exclusion. The Department had worked with Anthropic for two years despite that advocacy and acted only after the company refused a contract term.
What's Still Unknown
Whether Anthropic seeks further review. The company could ask the same panel or the full D.C. Circuit to rehear the case. Because the federal government is a party, the appellate rules allow 45 days to file. It could also petition the Supreme Court. Anthropic has not said which route it will take.
What happens to the California judgment. Reports on the August 27 ruling that we reviewed did not say whether the government will appeal it to the Ninth Circuit.
What happened during the overseas operation. The Department said an Anthropic executive questioned a contractor's use of Claude "for a sensitive military operation abroad." It did not identify the operation. Media reports Anthropic put into the record tie the dispute to the January 3 operation to capture Venezuela's Nicolás Maduro. Amodei has described the incident as a misunderstanding.
The commercial cost. No audited figure for lost defense business is public. The court even questioned whether Anthropic's reputation suffered, citing reports of investment offers valuing the company at more than $900 billion.
Frequently Asked Questions
What did the appeals court decide about Anthropic?
The D.C. Circuit ruled 2-1 on September 25, 2026 that the Department of War lawfully excluded Anthropic's Claude from its supply chain under the Federal Acquisition Supply Chain Security Act. It rejected Anthropic's claims that the decision was arbitrary, exceeded the statute, and violated due process and the First Amendment. The court denied both petitions for review, so the exclusion stays in force.
Can businesses and consumers still use Claude?
Yes. The ruling concerns what the Department of War buys. It covers removing Claude from Department systems and barring contractors from using Anthropic products in their Department work. It does not restrict commercial customers or individuals, and nothing in the opinion limits Anthropic's consumer apps or its sales to private businesses. Defense contractors are the group most directly affected.
Why did two courts reach different results?
They reviewed two different laws. Judge Rita Lin in California set aside a designation made under 10 U.S.C. § 3252, which covers risks from "an adversary" acting to subvert a system and therefore requires hostile intent. The D.C. Circuit reviewed a FASCSA action under 41 U.S.C. § 4713, which covers "any person" who may manipulate a product. The appeals court read that as requiring no bad motive.
What counts as a supply chain risk under FASCSA?
The statute defines it as the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate a covered IT product so as to surveil, deny, disrupt, or otherwise manipulate its function. The majority held that deliberately training an AI model to refuse certain government tasks fits that definition, whatever the vendor's reasons for doing it.
Did the court find that Anthropic acted in bad faith?
No. The majority wrote that it had no reason to doubt that Anthropic acted with noble intentions, whether out of concern for privacy or AI safety. It held that intent does not matter under this statute, because the definition turns on what a supplier does. The dissent argued that Congress meant the law to target covert, hostile interference, not a vendor's open enforcement of its contract terms.
What can Anthropic do next?
Anthropic can ask the three-judge panel to rehear the case, ask the full D.C. Circuit to rehear it en banc, or petition the Supreme Court. Because the federal government is a party, the appellate rules give 45 days to seek rehearing. The company has said it is considering all options, including further review, but has not announced a filing.
Does the ruling affect OpenAI, Google and other AI vendors?
Indirectly, yes. The decision tells every AI vendor that selling to the Pentagon while enforcing use restrictions through model training can justify exclusion under FASCSA. After Anthropic's exclusion, the Department expanded its work with OpenAI, and Google has accepted "any lawful government purpose" terms. Vendors with strict usage policies now have a court precedent to weigh before bidding.
Related Reading
This decision is the latest step in a dispute we have followed since March. Start with our report on how the Pentagon first labeled Anthropic a supply chain risk over the AI weapons dispute. Then read how Judge Rita Lin blocked the Pentagon blacklist in March, calling it First Amendment retaliation.
For how the rest of the industry responded, see why Google signed a Pentagon AI deal for any lawful government purpose despite an employee protest. Our breakdown of the Pentagon's $3.4 billion AI deals with Nvidia, Microsoft and AWS covers who replaced Anthropic on classified networks.