Anthropic's tug-of-war with the Pentagon reached a critical ruling against the AI lab on September 25 (U.S. time). According to Reuters and the Associated Press, the U.S. Court of Appeals for the District of Columbia Circuit voted 2-1 to uphold the Department of Defense's designation of Anthropic as a "supply chain risk," declining to lift orders barring Anthropic from military contracts and removing Claude models from Pentagon systems.
What the 2-1 ruling said
Judge Gregory Katsas, writing for the majority, put it this way: "The Department had ample support for its conclusion that the continued integration of Claude into the Department's information systems — by the Department or its contractors — presented a statutorily covered national-security risk." That sentence captures the ruling's core logic: the Pentagon did not need to show that Claude had caused any security incident; deeming the "continued integration" itself a risk was enough legal basis for the blacklist. The majority also rejected Anthropic's three claims — that the Department acted arbitrarily, exceeded its statutory authority, and violated the Constitution. Judge Neomi Rao joined Katsas in the majority; dissenting Judge Karen LeCraft Henderson filed an eight-page dissent.
The conflict traces back to February, when President Trump and Defense Secretary Hegseth accused Anthropic of endangering national security and designated it a supply chain risk. The trigger was the collapse of contract talks over military use: Anthropic CEO Dario Amodei refused to budge over concerns the company's products could be used for mass surveillance or autonomous armed drones. According to the majority opinion, the Pentagon in turn "reasonably feared that Anthropic might manipulate Claude's design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary."
It won in California — why did it lose here?
The confusing part: didn't a federal court in California rule for Anthropic just last month? The two cases rest on different laws. On August 27, Judge Lin of the Northern District of California ruled in a parallel suit that a designation under a different statutory provision was unlawful, amounting to unconstitutional retaliation against Anthropic; the D.C. Circuit case, by contrast, concerned a designation under the 2018 Federal Acquisition Supply Chain Security Act (Anthropic PBC v. United States Department of War, argued May 19), and concluded the Department had a factual basis, followed proper procedure, and did not retaliate against speech — because the designation was based on "the company's refusal to revise a contract term," not on Anthropic's public statements. The California injunction remains in effect, but it cannot block this ruling.
The impact is direct. Anthropic said it "respectfully disagrees" with the decision and is considering all options, including further judicial review, adding that the blacklist has already cost it billions of dollars in lost business and damaged its reputation ahead of its IPO. The tech industry is on edge: the Computer & Communications Industry Association (CCIA), together with ITI, SIIA and TechNet, filed amicus briefs in both courts, warning that if a government agency can wield a supply-chain tool designed for foreign adversaries as retaliation in a commercial dispute, every U.S. company is worse off. This is not an isolated episode — the White House has already halted U.S.-U.K. AI model sharing, requiring new models from OpenAI and Anthropic to clear U.S. review first, as Washington systematically tightens control over frontier AI models.
A new boundary is being drawn
What truly deserves attention here is the new boundary being drawn: an AI safety stance itself is becoming a "risk factor" in government procurement. Anthropic was blacklisted for refusing to alter its product terms for military use, and a court has now blessed that as lawful — meaning any AI company in the future may be forced to choose between "holding its safety line" and "winning government contracts." For Anthropic, about to face public shareholders in its IPO, the cost of this legal fight is not just billions of dollars; it is a public stress test of its "responsible AI" narrative.