What happened
The U.S. Court of Appeals for the District of Columbia Circuit upheld the Pentagon’s authority to exclude Anthropic’s Claude model from its supply chain. In a 2‑1 vote, Judges Gregory Katsas and Neomi Rao wrote the majority opinion, while Judge Karen LeCraft Henderson dissented. The court interpreted 41 U.S.C. § 4713 broadly, allowing the government to treat safety‑related restrictions embedded in the model as a supply‑chain risk. The ruling does not affect ordinary consumers or require Anthropic to remove its safeguards, but it affirms the government’s right to reject models that refuse certain requests deemed lawful and operationally necessary for defense work.
On September 25, 2026, the D.C. Circuit issued a split decision (2‑1) in Anthropic PBC v. United States Department of War, rejecting Anthropic’s petitions that challenged its exclusion from the Pentagon’s supply chain.
The majority, authored by Judge Gregory Katsas and joined by Judge Neomi Rao, interpreted the procurement statute (41 U.S.C. § 4713) to cover deliberate functional restrictions, even when motivated by safety or privacy concerns, deeming Claude a supply‑chain risk.
Judge Karen LeCraft Henderson dissented, arguing that the statute should be limited to hostile or deceptive interference and that the government’s reading expands congressional intent.
The court’s opinion clarifies that the exclusion applies only to the Department’s procurement and contractor use of Claude in classified systems, not to ordinary commercial users or the broader public API.
Anthropic’s prior cooperation with the Pentagon, including the development of Claude Gov models, ended over disagreements about contractual permission to use Claude for all lawful purposes, with Anthropic retaining exclusions for mass domestic surveillance and lethal autonomous warfare.
Why it matters
The decision sets a precedent that a supplier’s principled safety restrictions can trigger a national‑security label, potentially reshaping how AI vendors negotiate contracts with the military. It signals that the Pentagon can invoke procurement statutes to bar models that do not meet its functional demands, even when the vendor’s motives are safety‑focused. This could pressure AI companies to relax safeguards or risk exclusion from lucrative defense contracts, influencing the broader balance between and national‑security priorities. The ruling also clarifies the legal scope of supply‑chain risk definitions, affecting future procurement disputes across the AI industry.
The ruling creates a legal that safety‑driven model restrictions can be treated as a procurement risk, potentially forcing AI vendors to choose between maintaining safety safeguards and retaining defense contracts.
By affirming the Pentagon’s authority under a broad statutory definition, the decision may encourage the government to apply similar exclusions to other AI providers that embed safety constraints, influencing industry standards for model behavior in high‑stakes environments.
The case highlights the tension between advocacy and national‑security imperatives, raising questions about how future legislation might balance these competing interests and whether Congress will revisit the statutory language.
For defense agencies, the decision underscores the need to develop robust testing and verification processes for AI systems that may refuse certain requests, as reliance on older model versions may be deemed insufficient.
The dissent warns of possible overreach, suggesting that future legal challenges could arise if the government uses the supply‑chain risk label to penalize vendors for policy‑driven restrictions rather than genuine security threats.
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
crm_get_transaction(id='4092').Impossibility results in algorithmic fairness (e.g. Kleinberg et al., Chouldechova) show what?
What to watch next
Future judicial actions, such as any petition for rehearing or appeal to the Supreme Court, and any renegotiated procurement terms between Anthropic and the Department of Defense. Watch for Pentagon policy updates that may tighten or relax contractual language for AI models, and for industry responses—whether other AI firms adjust safety features to remain eligible for defense contracts. Additionally, monitor congressional hearings that may address the balance between commitments and national‑security requirements.
Any filing for rehearing or appeal by Anthropic, which could alter the legal landscape or prompt a Supreme Court review.
Potential revisions to the Department of Defense’s procurement contracts that may explicitly address model safety restrictions, influencing how future AI contracts are structured.
Congressional scrutiny or hearings on the use of AI in defense, especially regarding the balance between safety safeguards and operational requirements.
Responses from other AI firms—whether they adjust safety features, seek exemptions, or lobby for clearer statutory guidance—to remain eligible for defense contracts.
Implementation details from the Pentagon on how the exclusion will be enforced, including any transition plans for existing Claude deployments in classified systems.