US appeals court upholds Pentagon designation 2-1: Anthropic remains a supply chain risk
The ruling is blunt. Per the Associated Press: a federal appeals court on Friday rejected Anthropic's challenge to the government's labeling of it as a supply chain risk, with judges ruling 2-1 in the Pentagon's favour, which allows the Pentagon to continue removing Anthropic's Claude models from its systems and to bar Defense Department contractors from using Anthropic products in their work for the department. The majority's reasoning: the Pentagon had "ample support" for its action, and that support comes from Anthropic's own admission that "the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent."
Draw the boundary of this story first, because it involves three distinct legal moves and mixing them up leads to misreading. One: this ruling concerns the Pentagon's supply chain risk designation under public procurement regulations, and the court upheld it, so the designation remains in effect. Two: it is not the same case as the one in California, where on August 28 a federal judge found a broader ban imposed by the Trump administration against Anthropic illegal, which per Al Jazeera created a potential conflict between two federal courts. Three: the majority said explicitly that it had "no quarrel" with the conclusions in the California case, holding only that proving a supply chain risk designation does not require showing a "bad motive" on Anthropic's part.
The second thread is the language of the opinion itself, because this reasoning explains the outcome better than any summary. Per the AP, Judge Gregory G. Katsas, writing for the majority, said: "The Department reasonably feared that Anthropic might manipulate Claude's design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary." The opinion also credits good faith: the judges said they have "no reason to doubt" that Anthropic acts with "noble intentions" in restricting Claude, particularly regarding privacy and AI safety. But it then makes a decisive technical point: in this context, the definition of a supply chain risk hinges "on what Anthropic does, not why Anthropic does it." That sentence is the fulcrum of the ruling. Motive is not a defence; conduct is.
The third thread is how the dispute got here, and the dates are clear. Per the AP and Al Jazeera, the conflict broke out in February 2026, when President Donald Trump and Defense Secretary Pete Hegseth accused Anthropic of endangering national security and designated the company a supply chain risk. Al Jazeera puts it more concretely: the conflict began when Anthropic refused Hegseth's demand to remove restrictions on the use of Claude for fully autonomous lethal weapons and mass domestic surveillance of Americans. The designation, made in March, cancelled Anthropic's military contracts and barred other Defense Department contractors from using its technology. The Pentagon began removing Claude from its workflows earlier this year, and this ruling upholds its ability to do so. Note the scope: Al Jazeera states that Anthropic's products are not barred from the federal government as a whole under this ruling.
The fourth thread is both sides' reactions and the checkable consequences. The Pentagon's top spokesman, Sean Parnell, wrote in a social media post: "Today's DC Circuit Court ruling completely validates the Department's position." Anthropic said in a written statement that it "respectfully disagrees" with the decision, adding that "another federal court has already held the government's parallel designation unlawful," and that "we remain confident in our position and are considering all options, including further review." On consequences, two figures need separating: Al Jazeera reports that Anthropic has said the blacklisting has cost it billions of dollars in lost business and damaged its reputation ahead of a highly anticipated initial public offering, and the same piece says that IPO is expected in the coming weeks. As for the dollar value of the litigation or contract numbers, public reporting does not provide them, and this article does not fill those gaps.
To keep opinion and reporting separate, the composition of the majority and dissent matters. The AP states that the majority consisted of Judges Gregory G. Katsas and Neomi Rao, both nominated by Trump, and the sole dissenter was Judge Karen LeCraft Henderson, nominated by Republican President George H. W. Bush. That composition is a fact and carries no inference about the ruling's leanings. One more item has to be labelled by its source: Al Jazeera reports that "the military had reportedly been using Claude across a range of classified and sensitive systems, including during the January operation that captured and deposed Venezuelan leader Nicolas Maduro." The wording is "reportedly," and the piece cites no official document, so this article flags it as unconfirmed reporting rather than verified fact.
The final thread is what this means for enterprise buyers, and here facts must be separated from advice. The fact is that a US AI company was excluded from a US Defence Department procurement pathway because it encoded behaviour restrictions into its model that the customer could not remove, and that step has now been upheld by a federal appeals court. For any team with an AI model inside a production workflow, the checkable takeaways are three, all at the behavioural level: first, a vendor's built-in model restrictions may be a contractual risk to you rather than a safety asset; second, measure switching cost in advance, because once you are excluded the migration runs in days, not quarters; third, keep request logs, because when a dispute happens what proves what you did and did not use is the log, not your memory. Those three are advice, not the contents of this ruling.
🤔 Frequently Asked Questions
What exactly did the court decide?
The US Court of Appeals for the DC Circuit rejected Anthropic's challenge to the Pentagon's supply chain risk designation 2-1, so the designation stands. The practical effect is that the Pentagon can continue removing Claude from its systems and bar Defense Department contractors from using Anthropic products in department work. Per Al Jazeera, Anthropic's products are not barred from the federal government as a whole by this ruling.
Does this conflict with the California case?
The two cases address different designations. In the California case, a federal judge on August 28 found a broader ban imposed by the Trump administration against Anthropic illegal, which Al Jazeera describes as a potential inter-court conflict. The majority in this case said explicitly it had "no quarrel" with the California conclusions; the split is over whether supporting this supply chain risk designation requires showing a "bad motive" by Anthropic.
Will Anthropic keep appealing?
The company said in a written statement that it is "considering all options, including further review." As of publication, public reporting carries no more specific next step, and this article does not speculate on its appellate path or odds.
If I buy AI for an enterprise, what should I do?
At the factual level the case points to three self-checks: which models on your procurement list encode behaviour restrictions the customer cannot remove; if a vendor became unavailable tomorrow, would your replacement take days or quarters; and do you retain request logs sufficient to prove what you used and did not use. These are suggestions, not the ruling's contents, and specific terms still depend on your contract with the vendor.
🛠️ Recommended Tools
- Markdown EditorThe real landing spot for a ruling like this is a clause in a procurement document, not a headline. Maintain a vendor risk register with three lines per AI provider: what restrictions are built into the model, whether the customer can remove them, and what the fallback is if the vendor is excluded. Keep it in Markdown under version control, and the next time something like this happens you can check it in ten minutes instead of reconvening a meeting.
- API TesterThe problem a ruling like this creates is not that a model got worse, it is that a supplier suddenly became unavailable. Extract your critical calls into a replayable test set and fire them at your fallback endpoints on a schedule, so you know whether the replacement actually works or only works on paper. The drill costs nothing now, and there is no time for it on the day it matters.
- JSON FormatterWhat counts as evidence when a dispute happens is a structured record of your calls. Store and format the raw request and response JSON so you can answer quickly what data you sent and what the model returned, rather than relying on recall. In compliance inquiries and data-boundary reviews this is usually the first thing asked for.
Summary
On September 25, 2026, the US Court of Appeals for the District of Columbia Circuit rejected Anthropic's challenge to the Pentagon's supply chain risk designation 2-1, leaving the designation in effect: the Pentagon can continue removing Claude from its systems and bar Defense Department contractors from using Anthropic products in department work (per Al Jazeera, Anthropic's products are not barred from the federal government as a whole by this ruling). The majority opinion, written by Judge Gregory G. Katsas, found the Pentagon had "ample support," grounded in Anthropic's own admission that it encodes restrictions into Claude. The ruling credits Anthropic with "noble intentions" it has no reason to doubt, but holds that the definition hinges on what Anthropic does, not why it does it. The conflict began in February 2026, when Anthropic refused to remove restrictions on Claude (per Al Jazeera, concerning fully autonomous lethal weapons and mass domestic surveillance), with the designation made in March. Pentagon spokesman Sean Parnell said the ruling "completely validates the Department's position," while Anthropic said it "respectfully disagrees" and is considering options including further review. A separate California case on August 28, 2026 found a broader ban illegal; the majority here said it has "no quarrel" with those conclusions, and the two cases address different designations, creating a potential conflict. Al Jazeera's account of military use of Claude across classified systems, including a January operation in Venezuela, uses the word "reportedly" and is flagged here as unconfirmed.
Sources: Associated Press (via KSAT): Federal court says Pentagon can label Anthropic a supply chain risk
AP: Anthropic supply chain risk designation (related coverage)
Al Jazeera (AFP and Reuters): US court upholds Pentagon's blacklisting of Anthropic
AP: separate California ruling on the Pentagon's action against Anthropic