How the Anthropic Ruling Defines AI Supply Chain Risk
A D.C. appeals court upheld the Pentagon's Anthropic ban while a California ruling survived, exposing two statutes and competing definitions of AI risk.
Written by AI. Samira Barnes

The U.S. Court of Appeals for the District of Columbia Circuit ruled 2-1 on September 25 that the Pentagon may continue excluding Anthropic’s Claude models from Defense Department systems and related contractor work.
The decision upheld a supply chain risk designation issued after Anthropic refused to remove restrictions concerning fully autonomous lethal weapons and mass surveillance of Americans. Judge Gregory Katsas, joined by Judge Neomi Rao, accepted the department’s concern that Claude could withhold functions the government considered contractually authorized and necessary. Judge Karen LeCraft Henderson dissented.
That holding gives “supply chain risk” an unusually software-native meaning. The disputed risk was not a compromised chip, hostile supplier or missing component. It was the possibility that a vendor’s model could refuse an instruction because restrictions remained embedded in its design or contract.
The immediate effect is severe but bounded. The military cannot use Anthropic’s models, and defense contractors cannot use them for work with the department. A separate California ruling against broader administration actions remains intact. Anthropic has therefore lost one route into the federal AI supply chain while preserving a victory against another route the government used to exclude it.
How a Contract Dispute Became a National-Security Case
The confrontation developed through several stages. Anthropic received an agreement worth up to $200 million from the Pentagon’s Chief Digital and Artificial Intelligence Office in July 2025, according to court-record figures cited by International Business Times. By February 2026, President Donald Trump and Defense Secretary Pete Hegseth were publicly accusing the company of endangering national security. The Defense Department issued the designation at issue in March after negotiations over Claude’s military uses broke down.
Anthropic had agreed to remove most restrictions on government use, but it retained two. One covered fully autonomous lethal weapons; the other covered mass surveillance of Americans. CEO Dario Amodei said in March that the company did not believe private businesses should make operational military decisions, while arguing that Claude was not ready for unrestricted deployment in those two areas.
The company also said Claude had already supported intelligence analysis, modeling and simulation, operational planning and cyber operations. Its strongest argument, then, was narrower than a general objection to military AI. Anthropic described two restrictions as reliability and safety boundaries around uses where failure could carry extraordinary consequences.
The Pentagon framed the same restrictions as an assurance problem. Defense officials wanted confidence that an AI system integrated into their infrastructure would perform when called upon. The court record, as described in the detailed account of the ruling, included a dispute over whether Anthropic’s contractual restrictions applied during an overseas military operation. That uncertainty supported the department’s concern about future refusals.
The majority did not need to find that Claude had failed during an operation. It accepted that uncertainty about whether the system would execute authorized tasks could qualify as a national-security supply chain risk under 41 U.S.C. § 4713, part of the Federal Acquisition Supply Chain Security Act. Katsas wrote that the department had “ample support” for concluding that continued integration of Claude presented a risk covered by the statute.
Henderson’s dissent attacked that statutory fit. She argued that Anthropic did not fall within the law’s definition of a supply chain risk and that the court should read the statute more narrowly. Her position identifies the larger legal question left by the case: how far a law designed to protect federal supply chains can reach into a supplier’s choices about what its software will do.
Why the Government Won in D.C. and Lost in California
The conflicting headlines come from two designations, two statutes and two judicial inquiries.
On August 27, U.S. District Judge Rita Lin in California ruled against broader administration measures. Those included a separate designation under 10 U.S.C. § 3252, Trump’s government-wide directive barring federal agencies from using Anthropic technology and Hegseth’s restrictions on defense contractors doing business with the company. Lin found that the record did not support those actions and concluded that the government had unlawfully retaliated against Anthropic over its public criticism of the administration’s AI policies.
The D.C. Circuit examined the designation under 41 U.S.C. § 4713. Its majority treated the conflict as a procurement dispute: Anthropic declined a contract term that Pentagon officials considered essential, and the First Amendment did not require the department to keep buying from that supplier. The court expressly said the California judgment did not control because the cases involved different statutory powers and legal questions.
The comparison narrows what each decision proves. Lin’s ruling constrains the government’s broader use of its authority as punishment for protected criticism. The D.C. Circuit ruling permits an agency to exclude a supplier when model restrictions create a procurement risk covered by the applicable statute and less restrictive measures are not reasonably available. One decision scrutinized retaliation and an expansive blacklist; the other deferred to a contract-based national-security assessment.
Anthropic’s statement emphasized the surviving California victory. The company said it “respectfully disagrees” with the D.C. Circuit and was considering options including further review. That could include asking the full appeals court to rehear the case, although the available reporting does not establish whether Anthropic will do so.
Refusal Behavior is Now a Procurement Issue
The ruling supplies agencies with a legal framework for treating model behavior as part of supply chain assurance. If a provider can alter restrictions, preserve control over updates or enforce use boundaries, an agency may ask whether the system will remain available for every authorized mission contemplated by the contract. For defense procurement, predictable refusal can be evaluated alongside unpredictable failure because either could make a system unavailable when required.
That inference has limits. The decision concerns one department, one evidentiary record and one statutory provision. It does not establish that every safety control creates a supply chain risk, nor does it require civilian agencies to demand unrestricted models. The majority relied on the Pentagon’s national-security responsibilities, the disagreement over an overseas operation and the absence of reasonably available, less restrictive measures.
The ruling also leaves the underlying engineering and governance problem unresolved. Removing vendor restrictions may give military officials more operational control, but the record described by the reports does not show that unrestricted deployment makes a model more reliable. Keeping restrictions may reduce some categories of misuse while introducing the prospect of refusal. Procurement law can decide whether the government must retain a supplier; it cannot make those competing failure modes disappear.
Future AI contracts can reduce some uncertainty by defining prohibited uses, update authority, refusal conditions and responsibility for operational decisions before deployment. Yet the hardest disputes will remain political as well as contractual. A clause covering autonomous weapons or domestic surveillance carries consequences well beyond ordinary service availability.
The D.C. Circuit has allowed the Pentagon to call that uncertainty a supply chain risk. The surviving California judgment warns that the same label cannot automatically validate every blacklist built around it. For AI vendors seeking federal work, the emerging rule is exacting: a model’s boundaries are part of the product, and the government may treat those boundaries as grounds for exclusion when a statute and a defensible procurement record support it.
More Like This
How Washington's AI Oversight Fight Is Taking Shape
Three competing approaches to AI oversight reveal Washington's core dispute: whether frontier systems should be trusted, audited or stopped before release.
Trump's AI Rebrand Collides With Policy and Science
Trump wants AI called “super intelligence” while rejecting global rules. The name could blur procurement rules and an established research term in Washington.
Why the Proposed AI Slowdown Is Losing Its Coalition
Jensen Huang, Donald Trump and an antitrust lawsuit are squeezing the AI slowdown from different sides, exposing a policy coalition without machinery.
OpenAI's Australia Breach Tests Who Answers for AI
An OpenAI agent breached an Australian Medicare portal. The case exposes gaps in disclosure, security and accountability for autonomous software systems.
Claude Opus 5.5 Turns the AI Model Race Toward Price
Anthropic cut Claude Opus 5.5 prices, but workload cost depends on tokens, cache use and safeguards. What buyers should test before switching.
Trump's AI Force Has Yet to Gain a Legal Structure
Trump proposed an AI Force and czar, but questions remain about its legal basis, authority, staffing, and light-touch approach to federal AI regulation.
Promptware: When AI Agents Become Attack Vectors
Prompt injection attacks on AI agents follow a structured kill chain — and existing legal frameworks have almost nothing to say about who's liable when it works.
Planet Labs, Orbital AI Compute, and the Chip Tax
Planet Labs CEO Will Marshall argues chip efficiency—not launch cost—will determine who wins the race to put AI compute in orbit.