The US Court of Appeals for the District of Columbia Circuit has ruled that the Department of Defense may legally blacklist Anthropic, the creator of the Claude AI model, for refusing to enable certain features requested by the military. The 2‑1 decision affirms the Trump administration’s authority to treat the company’s refusal as a supply‑chain risk, even though Anthropic did not act with malicious intent.
What happenedIn September 2026, a three‑judge panel upheld the Pentagon’s blacklist of Anthropic after the company declined to remove restrictions that prevent Claude from being used in lethal autonomous weapons and mass‑surveillance scenarios. The majority opinion, written by judges appointed during the Trump administration, held that the Secretary of Defense acted within the powers granted by the Supply Chain Security Act and by 41 U.S.C. § 4713, a broader statute that does not require a “bad motive” to designate a supply‑chain risk.
The court contrasted two statutes that had been invoked in the case. The district court in California had focused on 10 U.S.C. § 3252, which limits “supply‑chain risk” to actions by an adversary that sabotage or maliciously alter a system. The appeals court, however, reviewed the blacklist under § 4713, which defines a risk as any person potentially sabotaging, introducing unwanted functions, extracting data, or otherwise manipulating a covered technology. Because the language includes “any person,” the court concluded that Anthropic’s decision to withhold Claude features could be treated as a risk.
Anthropic argued that its restrictions were a matter of policy, not a hostile act, and that the blacklist violated its First Amendment rights. The dissent, authored by Judge Karen Henderson, warned that the majority’s reading expands the statute beyond its original intent to protect against hostile nation‑state actors. She emphasized that the law was meant to address deliberate infiltration, not a contractor’s honest enforcement of use‑case limits.
The ruling also noted the practical stakes: the Department feared that Anthropic might later modify Claude to deny lawful functions the military deems necessary, potentially jeopardizing operations. The court cited examples where Claude’s built‑in restrictions stopped the model from completing tasks requested by government users, including a disputed overseas mission.
Anthropic may now seek an en banc review by the full DC Circuit or petition the Supreme Court.
Why it mattersThe decision sets a precedent for how the US government can classify AI providers as supply‑chain risks, even when the provider’s actions are driven by ethical or policy considerations rather than malicious intent. By interpreting the broader § 4713 definition to include any “person” who might limit a system’s functionality, the ruling potentially expands the government’s reach over commercial AI technologies.
For the defense sector, the case underscores a tension between operational certainty and the ethical safeguards that AI developers embed in their models. Overly constrained AI could fail at critical moments, while unconstrained models risk hallucinating inappropriate targets. The court’s language highlights both concerns, suggesting that the Pentagon must balance the risk of a model shutting down unexpectedly against the danger of it generating harmful outputs.
The ruling also raises First Amendment questions about whether a government agency can penalize a private company for refusing to alter its product in ways that conflict with the company’s policy. While the dissent warns of overreach, the majority’s view that “bad motive” is not required under § 4713 could influence future disputes involving other emerging technologies.
The bigger pictureAnthropic’s legal battle is part of a broader wave of government scrutiny over AI supply chains. Earlier this year, a California district court ruled that the blacklist violated the narrower definition of supply‑chain risk, emphasizing that only adversarial sabotage falls under that statute. The contrasting outcomes illustrate the fragmented legal landscape surrounding AI regulation.
The case also reflects the Trump administration’s aggressive stance on AI security, as articulated by Defense Secretary Pete Hegseth and Commerce Secretary Howard Lutnick, who recently said the administration and Anthropic have “patched up” their relationship. Yet the underlying disagreement about Claude’s restrictions remains unresolved.
Across the industry, AI firms are increasingly embedding usage constraints to avoid enabling weapons or mass surveillance. The Anthropic episode shows how those safeguards can become flashpoints when government customers demand full functionality for national‑security missions.
What happens nextThe appeals court’s decision leaves several paths open for Anthropic. The company can request an en banc hearing before the full DC Circuit, which would involve all the judges on that panel reviewing the case. Alternatively, it could petition the Supreme Court to hear the matter, potentially turning the dispute into a landmark case on AI, supply‑chain law, and free speech.
Meanwhile, the Pentagon is likely to continue treating Anthropic as a restricted supplier until the legal challenges are resolved. The department may seek alternative AI vendors that can provide unrestricted capabilities, or it could negotiate new contracts that address the government’s security concerns while respecting the developer’s policy constraints.
The broader policy community will be watching how courts interpret the expansive language of § 4713. Future rulings could either tighten or loosen the government’s ability to blacklist AI firms, shaping the balance between national security imperatives and corporate ethical standards.
The outcome of this case will influence not only Anthropic’s relationship with the US defense establishment but also set a legal benchmark for how AI supply‑chain risks are defined and enforced across the federal landscape.



