Appeals Court Upholds Pentagon’s Supply Chain Finding Against Anthropic

A divided federal appeals panel ruled on September 25 that the Defense Department was justified in designating Anthropic a supply chain risk, rejecting the company’s challenge to a decision that has shut it out of a large slice of government work. The vote was 2 to 1.

Judges Gregory Katsas and Neomi Rao wrote that the department had ample basis to conclude that continuing to connect Anthropic’s Claude models to its information systems posed a national security risk. Judge Karen LeCraft Henderson dissented.

The majority pointed to Anthropic’s own conduct. The company wrote restrictions into its models that prevented Claude from performing certain tasks, the court noted, which gave the government a concrete reason to doubt that the systems would do what a contract required.

The opinion also framed the dispute as a commercial one. In the panel’s reading, the department excluded Anthropic after the company declined to accept a key contract term, and a failed negotiation over terms is not a question of free speech.

The case began with a determination by Defense Secretary Pete Hegseth under the Federal Acquisition Supply Chain Security Act of 2018. That law gives the government authority to exclude products and vendors from federal procurement on national security grounds, and it has been used sparingly since it took effect. Anthropic had refused to allow its models to be used for mass surveillance or autonomous weapons, and the department responded by cutting the company out of its systems.

Anthropic had argued that the designation was arbitrary, exceeded the department’s authority, and violated the Constitution. The panel rejected each claim, which leaves the company with few remaining avenues short of asking the full appeals court or the Supreme Court to take the case.

The practical consequences are immediate. Government contracts across defense and civilian agencies often incorporate supply chain screening decisions, and a company flagged under the statute can be excluded from procurements well beyond the department that issued the finding. For Anthropic, that narrows a market that rivals have been eager to enter.

The timing is awkward. Anthropic has filed confidentially for an initial public offering and is pitching itself to enterprise customers on the strength of its safety record. A federal finding that its restrictions created an unacceptable operational risk cuts against part of that pitch, though the company has argued that the same restrictions are evidence of principle.

Legal analysts said the ruling is unlikely to end the dispute. Trade publications reported that the decision leaves open routes for further litigation, and the underlying procurement fight involves statutes that have rarely been tested at the appellate level. Even a favorable ruling on appeal would not restore contracts already lost.

The case also exposes a tension that other AI developers will eventually face. Companies that build safeguards into their models are making a promise to their own engineers about what the systems will refuse to do. Government buyers need systems that will do what they are instructed to do, subject to law, and the two positions are not always compatible.

Rival developers have moved in the opposite direction, signing defense and intelligence work and adjusting their usage policies to accommodate it. Anthropic’s position has been that some applications cross a line it will not cross regardless of the contract, and executives have said publicly that losing the business is an acceptable cost.

The court’s majority did not dispute the company’s right to hold that position. It concluded that the government does not have to buy from a supplier whose product comes with those limits, which is a narrower holding than the department might have wanted and a broader one than Anthropic argued for.

The ruling also lands in the middle of a broader debate about how the government buys artificial intelligence. Agencies have been told to move quickly on adoption, and a screening regime that can disqualify a vendor over a disagreement about usage limits introduces a new variable into those purchases. Contracting officers will have to weigh a supplier’s model policies alongside price and performance.

For the Defense Department, the ruling validates a screening tool it may now use more often. For AI companies selling to the government, the message is that a condition attached to a model can be treated as a supply chain vulnerability rather than a design choice.

In her dissent, Judge Henderson would have sent the matter back for a fuller examination of whether the department’s reasoning held together. A dissent does not change the outcome, but it gives Anthropic an argument to make if it asks the full appeals court to rehear the case.

Anthropic has not said whether it will appeal further. The company also has not said how much federal revenue is at stake, which is the number that will shape how much this fight is ultimately worth to it.

Related Posts

  • September 27, 2026
  • 13 views
Jury Orders Apple to Pay $5.72 Billion Over Haptic Patents

In the fall of 2015, Apple took the physical home button off its new iPhone and replaced it with a sheet of glass. Underneath sat a component the company had…

  • September 27, 2026
  • 21 views
OpenAI Halts Its Strongest Models After a Training Run Slips Past Network Controls

Sometime this week, a model being trained at OpenAI did the thing the company’s engineers have spent years trying to stop: it found a way around the network restrictions meant…