Appeals court lets Pentagon keep Anthropic blacklist
A Washington appeals panel has upheld the Pentagon’s designation of Anthropic as a supply-chain risk, preserving restrictions on Claude in military work while further appeals remain possible.

On September 25, 2026, the U.S. Court of Appeals for the District of Columbia Circuit upheld the Pentagon’s designation of Anthropic as a supply-chain risk. The 2-1 ruling allows the Defense Department to maintain its restrictions on the company’s Claude AI models, despite a separate federal court decision last month finding a parallel designation unlawful.
The practical effect is significant for a company that had previously worked with the U.S. government. The designation bars the U.S. military from using Anthropic’s models and prevents defense contractors from using them in work for the department. Anthropic said it respectfully disagrees with the decision and is considering further review.
A split ruling over two legal authorities
The appellate case turned on a distinction between two statutes used by the Pentagon in its March designation. Anthropic challenged both routes in separate courts because each statute assigned review to a different judicial forum. A federal district judge in Northern California reviewed one designation; the D.C. Circuit reviewed the other.
The California court concluded that the government’s action was unlawful under 10 U.S.C. § 3252. That provision concerns supply-chain risks involving an adversary and conduct such as sabotage, maliciously introduced functions or subversion. According to reporting on the decision, the district court found that Anthropic did not fit that definition and that the action violated the First Amendment.
- The Pentagon designated Anthropic a supply-chain risk in March.
- The designation blocks military use of Claude and limits contractors’ use in Defense Department work.
- A California federal court invalidated one parallel designation last month.
- The D.C. Circuit upheld the designation reviewed under a separate procurement statute.
- Anthropic can seek rehearing or ask the Supreme Court to take the case.
Why the appeals panel ruled for the Pentagon
Judges Gregory Katsas and Neomi Rao formed the majority. They held that the Defense Department had sufficient support for its conclusion that continued integration of Claude into department information systems, whether by the department itself or its contractors, presented a national-security risk covered by statute.
The majority focused on 41 U.S.C. § 4713, a broader provision governing procurement-related supply-chain risks. In its reading, that law does not require a malicious motive or a foreign adversary. The court said the word “deny” in the statute could encompass Anthropic restricting the government’s access to certain Claude capabilities or declining uses the department considered authorized and necessary.
Dispute over military safeguards
The conflict followed unsuccessful negotiations over deployment of Claude on the Pentagon’s GenAI.mil platform. Anthropic had signed a $200 million Pentagon contract in July 2025. But talks broke down after the department sought unfettered access to the models for all lawful purposes, while Anthropic sought assurances that its technology would not be used for fully autonomous weapons or domestic mass surveillance.
The government argued that restrictions encoded in Claude could cause the system to refuse tasks requested by military users. The appeals court referred to the possibility that overly constrained models could shut down unexpectedly and affect military operations. Anthropic, meanwhile, warned of the separate danger of unconstrained models hallucinating inappropriate targets for lethal force. The court did not resolve that policy conflict on technical grounds; it said the President and the Defense Secretary are responsible for balancing those risks.
A dissent challenges the statute’s reach
Judge Karen LeCraft Henderson dissented. She argued that, read in statutory context, the relevant terms address deliberate interference with or surveillance of technology already in the federal supply chain. In her view, Congress enacted the law in response to threats from hostile states and other bad actors, not to cover a contractor’s upfront enforcement of use restrictions that the government dislikes.
That disagreement matters beyond Anthropic. The majority’s interpretation permits the government to treat a provider’s refusal to enable certain functions as a supply-chain risk under the broader statute, even without evidence that the provider acted with malicious intent. The dissent would have drawn a narrower line around procurement security powers.
What comes next for Claude users
The panel delayed the immediate effect of its decision to give Anthropic time to seek rehearing before the same panel or an en banc review by the full D.C. Circuit. The company could also petition the Supreme Court. Until a court changes the result or the government revises its position, U.S. defense organizations and contractors face continued limits on deploying Claude in Pentagon-related work. For AI suppliers serving public institutions, the case highlights how contractual guardrails can become central to procurement, national-security and constitutional disputes.



