Appeals court lets Pentagon keep Anthropic blacklist
A divided federal appeals court on 25 September allowed the Pentagon to keep Anthropic's supply-chain-risk designation, preserving its ability to remove Claude from Defense Department systems and bar its use in department contracts. The D.C. Circuit ruled 2-1 against Anthropic in a dispute over restrictions on using the company's models for mass surveillance and autonomous weapons. Anthropic says the designation has cost it billions in business and damaged its standing ahead of a potential IPO. The decision is a direct adverse development for a provider seeking public-sector revenue: it leaves a large customer closed to Claude while the litigation continues, even though a separate California court has blocked a parallel government designation under another law.
Judge Gregory Katsas wrote for the majority that the Pentagon reasonably feared Anthropic might encode limitations that prevent Claude from performing national-security functions the department regards as authorized. The opinion focused on supply-chain authority and the practical effect of Anthropic's built-in restrictions, rather than whether the company's safety motives were sincere. The judges said they had no reason to doubt those motives, but the legal test concerned what the supplier could do to the product. Judge Karen LeCraft Henderson dissented. Anthropic said it ‘respectfully disagrees’ and is considering further judicial review. The ruling gives the department a current legal basis to exclude Claude while the parties' broader disagreement over acceptable military applications remains unresolved.
The California case reached a different result under a different legal theory. A federal judge there found the administration had unlawfully retaliated against Anthropic for its views about AI safety in a parallel designation. The D.C. Circuit said its decision did not quarrel with that ruling; it assessed a separate statutory route for the Defense Department. These distinctions prevent a simple claim that every federal agency must stop using Anthropic or that all government restrictions have been judicially approved. The immediate operational effect is centered on Defense Department workflows and contractors doing its work. Other public-sector customers are not automatically barred from Claude under this ruling, according to the Associated Press.
The clash began after Anthropic declined to remove two restrictions from its models when the government sought contractual permission for all lawful military uses. The court's account recognizes that Claude has been adapted for national-security work, but the department objected to a supplier retaining the ability to block a category of future tasks. The company sees limits on autonomous weapons and mass surveillance as core safeguards; the government sees them as a possible interruption of contracted capability. This is a hard procurement problem for frontier AI. A product can be technically capable and commercially attractive, yet a buyer with mission-critical needs may reject a vendor's continuing policy control over uses after purchase.
The ruling arrived as Anthropic was courting public investors and expanding commercial offerings. The company can seek further review or negotiate with the government, but the decision remains in effect. The Pentagon's exclusion may also shape how other security-conscious buyers examine Anthropic's terms: some will value the safety commitment, while others will want certainty that approved workflows remain available. The court's opinion is important precisely because it turns an abstract argument about AI guardrails into access to a named, high-spending customer. Anthropic must decide how much business it is willing to forego to preserve product restrictions, and whether a contractual accommodation can satisfy both its policy and the buyer's operational requirements.
Analysis
The ruling creates an explicit opportunity cost for Anthropic's use restrictions: the Defense Department can continue to exclude Claude, and contractors may need alternatives for covered work. Anthropic's claimed billions in lost business are its litigation position, not a judicial calculation, but the customer category is material. Relaxing the controls might recover a large buyer while weakening the company's safety differentiation and internal mission bargain; holding them preserves that position while leaving a rival to serve the account. The separate California victory prevents a blanket federal ban from being inferred. The commercial issue is whether Anthropic can contractually define stable, acceptable military uses without surrendering the power to refuse applications it regards as unacceptable.