Appeals Court Backs Pentagon’s Power to Label Anthropic a Supply Chain Risk

Image: Ars Technica AI
Main Takeaway
A divided federal appeals court upheld the Pentagon’s authority to designate Anthropic a supply chain risk over restrictions built into its Claude AI models.
Jump to Key PointsSummary
The ruling’s immediate effect
A divided federal appeals court in Washington has upheld the Pentagon’s authority to designate Anthropic a supply chain risk, allowing the Defense Department to restrict the company’s role in military systems. The ruling gives the Trump administration a major victory in its dispute with the AI company over Claude’s built-in limits on certain uses.
The appeals court did not directly reject a California district judge’s conclusion that Anthropic did not fit the statutory definition of a supply chain risk. Instead, the panel said the lower court was reviewing the decision under one legal framework while the appeals court had exclusive jurisdiction over another. That distinction allowed the designation to stand while separate litigation continues.
Why Anthropic was designated
The Pentagon argued that Claude’s restrictions created a national-security risk because the department and its contractors rely on the model inside information systems. The majority said the government had ample support for concluding that continued integration presented a covered risk, pointing to Anthropic’s ability to encode limits that prevent Claude from performing tasks the company rejects.
The dispute centers on Anthropic’s refusal to permit some military applications, including uses the company considered unacceptable. The administration treated those limits as a control over a system used by the government, while Anthropic argued that the designation punished the company for exercising its rights and for setting safety boundaries around its technology. The legal fight therefore reaches beyond one procurement decision: it tests how much control an AI developer retains after its models enter national-security infrastructure.
Two courts, different legal questions
The appellate decision does not erase the separate ruling from the Northern District of California, where a judge found the blacklisting unlawful. That court held that the statutory meaning of supply chain risk is limited to threats such as adversarial sabotage, malicious introduction of unwanted functions, or other subversion of a covered system.
The DC Circuit focused on jurisdiction and the scope of its review rather than adopting the district court’s core interpretation. That procedural split has produced two important results at once: Anthropic has a favorable finding from one federal court, while the Pentagon retains an operative designation backed by the appeals court. The conflicting rulings leave the legal boundary unsettled and create a path for further appeals or additional challenges.
A test for AI safety controls
The case puts model safeguards at the center of a government contracting dispute. Anthropic’s position treats restrictions on Claude as part of the company’s safety design and corporate judgment. The Pentagon’s position treats those same restrictions as a source of operational uncertainty when the model is embedded in systems that support military work.
That conflict gives the ruling significance beyond Anthropic. AI developers selling to public agencies will face closer scrutiny over who controls model behavior after deployment, especially when providers refuse particular uses. Government buyers, meanwhile, gain a stronger argument for treating provider-imposed limits as procurement and security concerns rather than ordinary product features. The decision does not establish that every restriction creates a supply chain risk, but it validates the Pentagon’s authority to make that determination in this case.
Consequences for federal AI procurement
The designation can affect Anthropic’s access to Defense Department work and to contractors operating within military information systems. It also raises the cost of adopting Claude across agencies that require stable capabilities, predictable controls, and continuity of service. Competitors stand to benefit if procurement officials shift contracts toward models whose providers accept broader government requirements.
The case also gives AI companies a sharper strategic choice. Firms can preserve strict limits on military applications and risk losing government business, or negotiate more flexible deployment terms and face pressure from employees, customers, and safety advocates. Microsoft, Google, OpenAI, and other providers compete in the same public-sector market, so the court’s treatment of provider restrictions will shape contract negotiations well beyond Anthropic.
What happens next
Anthropic’s legal challenge remains active because the California ruling and the DC Circuit decision address different aspects of the government’s action. The company can seek further review, while the administration can continue enforcing the designation under the appeals court’s ruling. The Supreme Court’s involvement would depend on future petitions and the courts’ treatment of the jurisdictional conflict.
For now, the Pentagon has judicial backing to classify Anthropic as a supply chain risk, while the definition of that risk remains contested. The outcome leaves federal agencies with greater leverage over AI vendors and leaves developers facing a basic question about deployment: whether model behavior is a safety feature, a contractual term, or a national-security vulnerability.
Key Points
Anthropic faces a Pentagon supply chain risk designation upheld by a divided federal appeals court.
Claude’s built-in restrictions on military tasks formed the core of the national-security dispute.
A California judge separately ruled the administration’s blacklisting action was illegal.
The DC Circuit emphasized jurisdiction while leaving the statutory definition dispute unresolved.
The decision strengthens federal leverage over AI vendors serving defense agencies and contractors.
Questions Answered
The Pentagon designated Anthropic a supply chain risk because Claude includes restrictions that prevent some military uses. The department argued those limits create operational and national-security concerns when the model is integrated into defense information systems.
The appeals court upheld the Pentagon’s authority to make the designation, but it did not directly resolve the California court’s narrower interpretation of supply chain risk. The DC Circuit focused on jurisdiction and the scope of review.
Anthropic objected to being blacklisted after refusing to enable certain military applications of Claude. The company argued that its model restrictions are safety controls and that the government’s action violated its rights.
The ruling allows the Pentagon to keep treating Anthropic as a supply chain risk and can limit Claude’s use in Defense Department systems and contractor networks. It also gives federal procurement officials stronger grounds to scrutinize Anthropic’s government work.
Anthropic can pursue further legal review while the Pentagon continues enforcing the designation. Future proceedings could address the conflict between the DC Circuit’s jurisdictional ruling and the California court’s interpretation of supply chain risk law.
Source Reliability
57% of sources are highly trusted · Avg reliability: 85
Go deeper with Organic Intel
Simple AI systems for your life, work, and business. Each one includes copyable prompts, guides, and downloadable resources.
Explore Systems