US Appeals Court Upholds Pentagon's Anthropic Blacklist: What the Ruling Means for Defense AI
Posted on 26th Sep 2026 06:06:46 in Artificial Intelligence, Machine Learning
Tagged as: Anthropic, Claude, Pentagon, AI Policy, Defense AI, AI Safety
A federal appeals court in Washington, D.C., ruled on Friday that the Pentagon may keep Anthropic on its supply-chain blacklist, upholding a designation that bars the U.S. military — and the defense contractors working with it — from using the company's Claude AI models. The 2-1 decision by the U.S. Court of Appeals for the D.C. Circuit is a heavy blow to one of the world's leading AI labs and a defining moment in the widening clash between national-security demands and AI safety commitments.
The ruling arrives at a delicate moment for Anthropic. The company is preparing for what could be a trillion-dollar initial public offering before the end of the year, and it has said the blacklist already cost it revenue as customers grew wary of doing business with a firm the government had branded a risk. Friday's decision keeps the Pentagon-specific ban in place indefinitely, even as a parallel ruling in California allows the rest of the federal government to keep working with Anthropic.
What the Court Decided
The three-judge panel split 2-1. Judge Gregory Katsas, writing for the majority and joined by Judge Neomi Rao — both appointed by President Donald Trump — found that the Department of Defense had "ample support" for concluding that keeping Claude inside its information systems presented "a statutorily covered national-security risk."
"As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent," the majority wrote, rejecting the company's arguments that the blacklist was arbitrary, unauthorized and unconstitutional.
The court also dismissed Anthropic's claims that its due-process and free-speech rights were violated, describing the dispute as a standard contract negotiation and concluding that the Pentagon "excluded Anthropic from its supply chain based on the company's refusal to assent to a contract term that the Department deemed essential." Judge Karen LeCraft Henderson, appointed by former President George H.W. Bush, dissented, arguing there was no legitimate concern that Anthropic could manipulate its technology to pose a security risk.
The panel delayed the ruling from taking immediate effect, giving Anthropic room to seek a rehearing, request an "en banc" hearing before all 11 judges of the D.C. Circuit, or petition the Supreme Court.
In practical terms, Friday's decision means:
- The U.S. military cannot use Anthropic's Claude models, and defense contractors are barred from using Claude in their work with the Pentagon.
- Other federal agencies and their contractors can continue working with Anthropic, under the separate California ruling that the government has not appealed.
- The Pentagon blacklist stays in force for as long as the appeals process continues, which could take years to fully resolve.
How the Standoff Began
Before the clash became public, Anthropic was one of the Pentagon's early AI partners, signing a $200 million contract with the department in July 2025 and serving agencies across the U.S. government. The relationship soured that September, when negotiations over deploying Claude on the Defense Department's GenAI.mil platform collapsed.
The Pentagon wanted unfettered access to Anthropic's models for "all lawful purposes." Anthropic wanted assurances that its technology would not be used for fully autonomous weapons or domestic mass surveillance. Neither side moved. Defense Secretary Pete Hegseth accused the company of trying to "seize veto power over the operational decisions of the United States military," and in March the department declared Anthropic a supply-chain risk — a label normally reserved for firms tied to foreign adversaries, and never before applied to an American company.
Katsas pointed to Hegseth's "deeply sobering" concern that "overly constrained" AI models could shut down unexpectedly during operations, or be subject to manipulation — but held that such judgments belong to the executive branch: "In our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks."
President Donald Trump has repeatedly attacked Anthropic chief executive Dario Amodei in the months since. On Monday, Trump wrote on Truth Social that his administration had "stopped AI 'people' from doing bad, or potentially bad, 'things,' like Dario (Anthropic!)", and pledged to continue doing so. Amodei, who recently called for an industry-wide slowdown in frontier AI development, was not invited to the White House state dinner for Chinese President Xi Jinping on Thursday.
Two Courts, Two Rulings
The Pentagon relied on two separate supply-chain designations to justify the blacklist, which forced Anthropic to fight the matter in two different courts. In August, Judge Rita Lin of the federal district court in San Francisco ruled the parallel designation "illegal and baseless," writing that "the empty invocation of national security is not a blank check to punish and retaliate against government critics."
Friday's D.C. Circuit decision upheld the second, Pentagon-specific designation. Because the two rulings rest on different statutory authorities, they can coexist: the California decision lets most of the federal government keep using Claude, while the D.C. ruling keeps the model out of the Pentagon. The government has not appealed the California ruling.
Why the Ruling Matters Beyond Washington
At its core, the case answers a question every AI vendor and government buyer is now wrestling with: can an AI company attach safety restrictions to defense contracts and still keep the business? Friday's answer, at least at the appellate level, is no — the government may treat a refusal to lift those restrictions as a national-security supply-chain risk, and the courts will defer to the executive branch's judgment.
The practical fallout is sweeping. Because the designation covers contractors, any company in the Pentagon's supply chain — from prime contractors to small subcontractors — risks running afoul of the rules by using Claude, including paid enterprise versions. Anthropic says the designations have already cost it revenue as customers grew skittish about working with a company the government had labeled a risk, even as it touts growing enterprise sales and prepares for a potential listing on public markets.
The Pentagon, meanwhile, has been replacing Claude with alternatives such as SpaceX's Grok, Google's Gemini and OpenAI's GPT models, though it has shared few details about its progress. Some Google and OpenAI employees have objected to taking on work that Anthropic rejected, citing ethical concerns, but the companies have pressed ahead, describing support for the U.S. government as essential.
The case also sends a signal far beyond the United States. Governments across Europe and Asia are writing their own rules for procuring frontier AI, and the D.C. Circuit's deference to the Pentagon offers an early template for how far states can go to compel access to models. For enterprises that sell into regulated or defense-adjacent supply chains anywhere in the world, contract terms and vendor risk policies are now as important as model performance.
And it lands in the middle of a widening debate over whether AI development should slow down. Anthropic has positioned itself as the safety-first lab, backing calls for stricter frontier-model oversight; the ruling shows the commercial cost of that posture when the customer is one of the largest buyers of technology on earth.
What Happens Next
The fight is far from over. "We respectfully disagree with the court's decision," an Anthropic spokesperson said in a statement. "Another federal court has already held the government's parallel designation unlawful. We remain confident in our position and are considering all options, including further review."
Those options include a rehearing by the same panel, an en banc review by the full D.C. Circuit, or an appeal to the Supreme Court — paths that, combined with the California litigation, point to years of further proceedings. The Pentagon, for its part, celebrated the outcome: Undersecretary Emil Michael wrote on X that "the hammer of justice has smashed" Anthropic's arguments, adding that warfighters "will sleep better knowing that no private company will insert their opinions in the chain of command."
What is already clear is that the ruling reshapes the ground rules for defense AI procurement in the United States, and likely beyond it. As AI labs, governments and contractors negotiate over what models can and cannot be used for, Friday's decision suggests that safety commitments written into a product will be read as business decisions — with consequences that follow the product through every supplier in the chain.
Sources
- WIRED — Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk
- CNBC — U.S. appeals court upholds Pentagon designation of Anthropic as supply chain risk
- CNN — Federal appeals court rules Pentagon's blacklist of Anthropic was legal
- The Guardian — Pentagon's blacklisting of Anthropic was unlawful, US judge rules