Skip to main content

Appeals Court Lets the Pentagon Keep Anthropic on Its AI Blacklist

A divided US appeals court ruled on 25 September that the Pentagon may keep Anthropic on a supply-chain risk list. The decision applies a broader defence-procurement law and does not overturn a California order blocking a separate government-wide contractor ban. Anthropic can still seek review by the full court or the Supreme Court.

On this page

The Pentagon won under a broader procurement law

A divided federal appeals court ruled on 25 September that the Pentagon may keep Anthropic on its supply-chain risk list. The US Court of Appeals for the District of Columbia Circuit said the governing defence-procurement law does not require proof that a supplier acted maliciously or deliberately created a vulnerability.

The dispute began after Anthropic refused to remove restrictions on certain military uses of Claude. The Pentagon concluded that the company could restrict functions that it considered important to defence operations and designated Anthropic as a supply-chain risk. Anthropic argued that the designation punished it for maintaining safety limits and rested on a statute aimed at hostile or compromised suppliers.

The two-judge majority read Section 4713 more broadly. In its view, a risk can arise from the possibility that a supplier will withhold or limit a capability, even without malicious intent. That interpretation was enough for the court to leave the Pentagon's designation in force while the underlying case continues.

The ruling does not revive the wider contractor ban

This decision is narrower than a government-wide prohibition on using Anthropic. A federal court in California previously blocked a separate measure that would have prevented agencies and contractors across the government from doing business with the company. That order was based on a different statute, Section 3252, and remains in place.

The DC Circuit expressly said it had no quarrel with the California court's conclusion that Anthropic had not acted maliciously under that law. It reached a different result because Section 4713 uses different language and gives the DC Circuit exclusive jurisdiction over the Pentagon designation.

The result is an awkward split rather than a clean victory for either side. The Pentagon can continue treating Anthropic as a supply-chain risk for its own procurement decisions. The broader effort to exclude Anthropic from government and contractor work is still blocked. Agencies and companies will need to identify which measure governs a particular contract instead of treating the two cases as interchangeable.

A dissent warned that safety limits became the alleged risk

The dissent argued that the majority stretched a supply-chain security law beyond its intended purpose. On that reading, Anthropic's refusal to provide every requested capability is a commercial and policy dispute, not evidence that its software or supply chain has been compromised.

That disagreement reaches beyond Claude. AI vendors increasingly place contractual and technical limits on surveillance, autonomous weapons, cyber operations, and other sensitive uses. If the government can classify those limits themselves as a supply-chain risk, procurement law becomes leverage over the conditions under which a model may be used.

The majority did not hold that every vendor restriction qualifies. Its decision turns on the Pentagon's assessment of defence needs and the specific wording of Section 4713. Reuters reported that the 2-1 ruling preserves the designation while litigation continues. It does not decide whether Anthropic's safety policies are technically effective or whether the restricted uses would be lawful.

The next appeal could define the practical boundary

Anthropic can ask the full DC Circuit to rehear the case or petition the Supreme Court. The company may also continue challenging how the Pentagon applied the statute on the fuller record. Until then, the designation can affect defence procurement even though the California injunction limits the broader ban.

For AI customers, the immediate lesson is contractual. A model's acceptable-use policy becomes a delivery constraint when a government customer expects capabilities the vendor will not provide. Buyers should check whether critical functions depend on terms that can change, whether another provider can meet the same requirement, and which legal authority controls an exclusion decision.

For policymakers, the two cases leave an unresolved line between genuine supply-chain protection and pressure on a vendor to relax its safeguards. That question will matter as governments rely on commercial models for military planning, intelligence analysis, and software operations while vendors retain control over model access and updates.

CuriousLM runs supported AI models locally on your device. Try CuriousLM.