Pentagon Can Keep Anthropic Out Of Its AI Supply Chain, Appeals Court Rules As It Rejects Claude Maker’s Challenge
A federal appeals court ruled Friday that the Pentagon can exclude Anthropic’s Claude artificial intelligence models from its supply chain, rejecting the company’s challenge to a national security designation imposed after a dispute over restrictions on autonomous weapons and domestic surveillance.
The U.S. Court of Appeals for the District of Columbia Circuit denied Anthropic’s petitions for review in a 2-1 decision, finding that the Department of War had sufficient grounds to conclude that Claude presented a supply chain risk under the Federal Acquisition Supply Chain Security Act.
Judge Gregory Katsas, writing for the majority, said the department had evidence that restrictions built into Claude could prevent the model from carrying out tasks requested by government users. The court also cited a dispute over whether Anthropic’s contractual restrictions applied during an overseas military operation, which left defense officials uncertain about whether Claude would perform as expected.
The court said Anthropic had acknowledged that its models are designed to enforce some safety restrictions and found that the Pentagon could reasonably treat the possibility of Claude refusing certain instructions as a national security concern.
Anthropic had argued that the designation exceeded the government’s statutory authority, was arbitrary and violated its constitutional rights.
The majority rejected those claims. It found that the department had not punished Anthropic for advocating stronger AI safeguards but had instead acted because the company would not agree to a contractual term that Pentagon officials considered necessary. The court also held that Anthropic had received sufficient notice and an opportunity to challenge the designation after it was imposed.
Circuit Judge Karen LeCraft Henderson dissented, arguing that Anthropic did not fall within the law’s definition of a supply chain risk and that the statute should be read more narrowly.
The dispute grew out of negotiations over how the Pentagon could use Claude in military and national security systems.
Anthropic agreed to remove most restrictions on the government’s use of the model but declined to eliminate two: a prohibition on using Claude for fully autonomous lethal weapons and another covering mass surveillance of Americans.
The company said those limits reflected concerns about the reliability and safety of current AI systems rather than an attempt to control military operations.
Anthropic CEO Dario Amodei said in a March statement that the company did not believe private companies should make operational military decisions but maintained that its two restrictions addressed areas where it believed Claude was not ready for unrestricted deployment.
“Our only concerns have been our exceptions on fully autonomous weapons and mass domestic surveillance,” Amodei said at the time. Anthropic also said Claude had already been used for intelligence analysis, modeling and simulation, operational planning and cyber operations.
The Pentagon took a different view, arguing that military officials needed confidence that an AI system integrated into defense systems would function when required.
The D.C. Circuit said Friday that the disagreement was fundamentally contractual. The majority concluded that the First Amendment did not require the Pentagon to continue working with a company after it declined a contract term the department considered essential to national security.
Friday’s decision does not overturn a separate ruling issued last month by a federal judge in California.
U.S. District Judge Rita Lin ruled Aug. 27 that broader administration actions against Anthropic were unlawful, including a separate supply chain designation issued under 10 U.S.C. § 3252, President Donald Trump’s government-wide directive barring federal agencies from using Anthropic technology and Defense Secretary Pete Hegseth’s order restricting defense contractors from doing business with the company.
Lin found that the record did not support those broader actions and concluded that the government had unlawfully retaliated against Anthropic over its public criticism of the administration’s approach to AI safety.
The D.C. Circuit addressed a different designation under 41 U.S.C. § 4713, part of the Federal Acquisition Supply Chain Security Act. The appeals court explicitly said the California ruling did not control its review because the two cases involved different statutory authorities and different legal questions.
The appeals court’s majority said the federal statute allows agencies to bar suppliers or subcontractors when the use of their technology presents a supply chain risk to national security and less restrictive measures are not reasonably available.
Anthropic said it disagreed with Friday’s decision and was considering further review, including possible consideration by the full appeals court, according to a statement provided to Reuters. The company said another federal court had already ruled that the government’s parallel designation was unlawful.
The company had previously said the Pentagon designation threatened billions of dollars in federal contracts and subcontracts and harmed its reputation. Court records show Anthropic had been awarded an agreement worth up to $200 million by the Pentagon’s Chief Digital and Artificial Intelligence Office in July 2025.