US appeals court upholds blacklisting of Anthropic over military AI restrictions

A DC Circuit Court upheld the Pentagon's blacklisting of Anthropic as a supply chain risk in a 2-1 ruling, letting the ban on defense contractors stand.

Published on: Sep 26, 2026
US appeals court upholds blacklisting of Anthropic over military AI restrictions

A US appeals court upheld the Defense Department's blacklisting of Anthropic technology today, ruling that the Trump administration acted within its authority to designate the AI company as a supply chain risk. The 2-1 decision from the DC Circuit Court of Appeals allows the Pentagon to continue barring defense contractors from doing business with Anthropic, a move that stems from the company's refusal to remove safety restrictions on its Claude AI model for certain military uses.

The ruling creates a direct split with a California district court, which last month found the same blacklisting illegal under a different statute. Anthropic said it is considering further appeals, including a potential Supreme Court challenge.

The legal reasoning behind the decision

Judges Gregory Katsas and Neomi Rao, both Trump appointees, formed the majority. They focused on a procurement law - 41 U.S.C. ยง 4713 - that defines supply chain risk more broadly than the statute the California court examined. Under Section 4713, a supply chain risk includes "the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate" the design or operation of covered technology. The court said the phrase "any person" shows the definition is not limited to adversaries or foreign entities.

The majority also pointed to the word "deny" in the statute, arguing it covers Anthropic's practice of encoding restrictions into Claude that prevent the model from performing tasks the company wants to block. "The Department reasonably feared that Anthropic might manipulate Claude's design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary," the ruling said.

The court acknowledged the stakes on both sides. The US raises "the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail," while "Anthropic raises the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force."

A dissenting view and the California ruling

Judge Karen Henderson, a George H.W. Bush appointee, dissented. She argued that Congress passed the statute in response to threats from "hostile nation state and other bad actors" infiltrating federal supply chains. The definition, she wrote, should not cover "a contractor's honest and upfront enforcement of restrictions on a covered article's use disfavored by the government."

The California case, presided over by Biden appointee Judge Rita Lin, found the blacklisting violated the First Amendment. "The empty invocation of national security is not a blank check to punish and retaliate against government critics," Lin wrote. Her ruling determined that Anthropic does not meet the definition of a supply-chain risk under 10 U.S.C. ยง 3252, which is limited to malicious actions by adversaries.

Today's DC Circuit ruling did not dispute that finding. Instead, it said the appeals court has exclusive jurisdiction to review the designation under Section 4713, which lacks the bad-motive requirement.

What comes next

Anthropic sued in March after federal agencies were ordered to stop using its products and defense contractors were banned from doing business with the company. An Anthropic spokesperson told CNBC: "We respectfully disagree with the court's decision. Another federal court has already held the government's parallel designation unlawful. We remain confident in our position and are considering all options, including further review."

The company can ask for an en banc review by all DC Circuit judges or petition the Supreme Court. Commerce Secretary Howard Lutnick recently said the Trump administration and Anthropic have patched up their relationship and are "in tune," despite the ongoing litigation.

The dispute centers on restrictions Anthropic builds into Claude that prevent the model from performing tasks related to lethal autonomous warfare and mass surveillance. The appeals court noted that these restrictions "have stopped Claude from performing tasks requested by government users" and created uncertainty about whether the model would function as needed during an overseas military operation.

Why this matters for AI policy and legal professionals

This ruling establishes that a company's product safety restrictions can qualify as a supply chain risk under federal procurement law, even absent malicious intent. For government contractors working with AI systems, the decision signals that built-in model constraints - however transparently disclosed - may not shield a vendor from exclusion if those constraints interfere with agency missions. The circuit split also makes Supreme Court review more likely, which could produce the first high-court ruling on how the government may regulate AI tools through its purchasing power. Professionals tracking AI governance should watch whether Congress clarifies the statutory definitions at issue, as the current tension between Section 3252 and Section 4713 leaves room for conflicting interpretations across jurisdictions.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)