A panel of judges in Washington ruled on Friday that the Pentagon may go on calling Anthropic, an American company, a danger to its supply chain. The words the government uses are “supply chain risk,” a label built for firms suspected of working with foreign enemies. Anthropic is not accused of that. It is accused, on its own admission, of building restrictions into its Claude model so that the model will not do certain things. Those things are fully autonomous weapons and mass surveillance of American citizens. For this, the company has been cast out of the Defense Department, and the US Court of Appeals for the DC Circuit has now said, two judges to one, that the casting out may stand.
The quarrel is short to tell. According to Gizmodo’s reporting, Anthropic signed a $200 million deal with the Pentagon in July of last year to “prototype frontier AI capabilities that advance U.S. national security.” The Wall Street Journal reported in February that Claude was used by the US military in the operation to seize Venezuela’s president, Nicolás Maduro, and his wife from a palace in Caracas. Later that month, Anthropic’s chief executive, Dario Amodei, said the company would not consent to its technology being used for domestic surveillance or fully autonomous weapons — uses which, he said, “can undermine, rather than defend, democratic values.” The Pentagon wanted a contract covering “any lawful use” of the model. Anthropic would not sign it.
The answer came from the top. Secretary of War Pete Hegseth called Amodei’s position “a master class in arrogance and betrayal as well as a textbook case of how not to do business with the United States Government or the Pentagon.” President Trump wrote on Truth Social that “The Leftwing nut jobs at Anthropic have made a DISASTROUS MISTAKE trying to STRONG-ARM the Department of War,” and directed every federal agency to “IMMEDIATELY CEASE all use of Anthropic’s technology.” The designation followed. According to CNN, the label had never before been fixed on an American company.
Two laws, two courts, two answers
The government blacklisted Anthropic under two statutes at once, and that doubling has produced two opposite verdicts. Under one law, 10 U.S.C. § 3252, a supply-chain risk must involve an “adversary” bent on sabotage or subversion. A federal judge in San Francisco found that designation unlawful — Wired reports it was tossed out in March and that finding confirmed last month — because Anthropic has no such bad motive, and the government has not appealed. But the appeals court reviewed the second statute, 41 U.S.C. § 4713, over which Congress gave the DC Circuit exclusive jurisdiction, and that law defines the risk far more broadly: the risk that “any person” might sabotage, extract data or otherwise manipulate covered systems.
no such bad motive is required to support a designation under the much broader definition set forth in section 4713
The majority opinion, written by Judge Gregory Katsas, a Trump appointee, did not quarrel with the California court’s reading of the narrower law. It simply applied the wider one. “The Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk,” the judges wrote. “As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent.” One judge on the panel dissented, arguing there was no legitimate concern that Anthropic would manipulate its own technology to endanger security.
Anthropic had sued in March, arguing the blacklisting punished it for speech — an unprecedented and unlawful act, it said, in breach of the First Amendment. The majority was unmoved. The government, the judges wrote, “excluded Anthropic from its supply chain based on the company’s refusal to assent to a contract term that the Department deemed essential, not based on the company’s support for greater governmental regulation of AI technology.” Due process, in their view, had been observed. The same panel had declined in April to block the designation temporarily, finding Anthropic had failed to meet “stringent requirements” for an immediate reprieve.
What it costs, and what comes next
The practical result is a split world. Inside the Pentagon, Claude stays banned. Outside it, because the California ruling stands untouched, other agencies and contractors may still deal with the company. The Pentagon designation nonetheless reaches far: no contractor, supplier or partner working with the military may do business with Anthropic at all, down to buying a paid Claude subscription. Anthropic has said the label carries a “reputational stigma” and will cost it hundreds of millions of dollars in revenue. It said it lost business from the start, as customers shied away from a government pariah. The company is meanwhile talking up growing sales and preparing a stock-market flotation that could come before the end of the year and is said to be potentially valued in the trillions of dollars.
The company can ask the full DC Circuit — eleven judges rather than three — to rehear the case, or go straight to the Supreme Court. Both rulings face the prospect of years of appeals. “Another federal court has already held the government’s parallel designation unlawful,” a company spokesperson said. “We remain confident in our position and are considering all options, including further review.” The Pentagon’s undersecretary, Emil Michael, answered on X that “The hammer of justice has smashed @AnthropicAI arguments... Warfighters will sleep better knowing that no private company will insert their opinions in the chain of command.”
The bitterness has been accumulating for months. In June, Anthropic was forced to cut off access to its then-most powerful models after the government cited an obscure export law that some experts called legally dubious. Trump has mocked Amodei’s calls for a slowdown among frontier AI labs as a “hoax.” According to CNBC, no one from Anthropic attended Thursday’s White House dinner for Chinese President Xi Jinping, at which Mark Zuckerberg, Sam Altman, Sundar Pichai, Jensen Huang and Elon Musk were all guests.
Meanwhile the Pentagon says little about replacing Claude with alternatives such as SpaceX’s Grok, Google’s Gemini or OpenAI’s GPT models. Some employees at Google and OpenAI have objected, on ethical grounds, to their employers taking the deal Anthropic refused. Their employers have gone ahead anyway. A company wrote limits into its product and refused to remove them at the state’s command; the state called that a security risk, and a court has now agreed. The limits remain in the code.

