Court upholds Pentagon exclusion of Anthropic over Claude use restrictions

Anthropic challenged a Department of War decision excluding the company and its Claude artificial intelligence models from the Department’s supply chain after Anthropic refused to permit Claude to be used for all lawful military purposes. The D.C. Circuit rejected the challenge and upheld the exclusion.
The dispute grew out of negotiations over how the Department could use Claude. Anthropic had agreed to relax many of its ordinary restrictions for government use, but continued to prohibit two categories of use: lethal autonomous warfare and mass surveillance of Americans. The Department, meanwhile, wanted contractual authority to use Claude for “all lawful uses.” When negotiations broke down, Secretary of War Pete Hegseth invoked the Federal Acquisition Supply Chain Security Act and determined that Claude presented a supply chain risk. The Department then ordered Anthropic products removed from its systems and prohibited contractors from using Anthropic products in work for the Department.
Anthropic did not begin with a conventional lawsuit in a district court. The statute gave the D.C. Circuit direct jurisdiction to review covered procurement actions, so Anthropic filed a petition for review in that court on March 9, 2026. It also asked the court to stay the exclusion while the challenge was pending. The court denied the stay on April 8 but expedited the case for a decision on the merits.
The procedural posture became more complicated after Anthropic asked the Department to rescind or reconsider the exclusion. Secretary Hegseth denied that request on June 3. Anthropic then filed a second petition for review challenging both the original March 3 action and the June 3 denial of reconsideration. The D.C. Circuit consolidated the two proceedings and concluded that, one way or another, it had jurisdiction to decide the merits.
What Anthropic asked the court to decide
On the merits, Anthropic attacked three parts of the Secretary’s statutory determination. It argued that removing Claude was not necessary to protect national security by reducing a statutory “supply chain risk,” that less intrusive alternatives were reasonably available, and that there was no urgent national security interest justifying immediate action without advance notice. The statute required the D.C. Circuit to set aside procurement actions that were arbitrary, capricious, an abuse of discretion, or otherwise contrary to law.
Anthropic also asserted constitutional claims. It argued that the Department had violated due process by imposing the exclusion before giving Anthropic a chance to respond, and that the government had retaliated against Anthropic in violation of the First Amendment because of the company’s public advocacy concerning AI safety and restrictions on military uses of artificial intelligence.
The D.C. Circuit rejected all of those arguments and denied both petitions for review.
Why Anthropic’s safeguards counted as a supply chain risk
The most interesting statutory issue concerned what it means to “manipulate” an information technology product under the supply chain statute.
Anthropic argued that the statutory language was directed at conduct resembling sabotage, malicious interference, or covert subversion. The majority read the provision more broadly. Anthropic intentionally trains Claude and configures successive versions of the model so that they will refuse certain tasks. Because the statute covers manipulation of a product’s design or operation that can deny or disrupt its use, the court held that Anthropic’s good-faith safety restrictions could fall within the definition even though Anthropic was not acting maliciously.
The court emphasized that this was not merely a disagreement over written contract terms. Anthropic’s use restrictions could become part of Claude’s actual behavior. Claude had previously refused government prompts, and Anthropic could impose new behavioral restrictions each time it delivered a new version of the model. The Department therefore could reasonably worry that a system incorporating Claude might fail to perform a function the Department considered authorized and operationally necessary.
Anthropic responded that it had no remote “kill switch” and could not alter a model after deployment on a classified government system. But the court found that point insufficient. Anthropic could still shape the behavior of later versions through model training, and the Department could not necessarily eliminate the risk merely by testing each new model before deployment because large language models can react differently to differently worded prompts and are difficult to audit comprehensively.
The majority also rejected Anthropic’s argument that “manipulate” should be read to require hostile or improper motive. The court acknowledged that Anthropic may have imposed its restrictions for “noble intentions,” including privacy protection and AI safety. But under the majority’s interpretation, the statute focused on what Anthropic did to Claude’s design and operation, not why it did it.
Judge Henderson dissented. She would have interpreted “manipulate” in light of surrounding statutory terms such as sabotage and malicious conduct, limiting the provision to intentionally subversive or deceptive interference. On that reading, Anthropic’s open enforcement of contractual and technical restrictions would not amount to the kind of supply chain threat Congress intended the statute to address.
The court rejected the remaining statutory and constitutional challenges
The court also upheld the Secretary’s conclusion that less intrusive measures were not reasonably available. Anthropic suggested that the Department could have limited its restrictions to systems involving lethal autonomous warfare or domestic surveillance, but the court reasoned that AI models can be integrated into larger systems and affect the functionality of those systems. It therefore deferred to the Department’s decision to make a clean break rather than examine Claude’s use system by system.
Anthropic also challenged the Secretary’s determination that urgent national security concerns justified acting before giving Anthropic an opportunity to respond. The court held that even assuming the Secretary had been wrong about the urgency, Anthropic could not show prejudice. The Department gave Anthropic detailed notice shortly after the exclusion, allowed it to submit arguments and evidence, and later considered those submissions when denying reconsideration. The court concluded that giving Anthropic the same opportunity earlier would not have changed the result.
That reasoning also defeated Anthropic’s due process claim. The court concluded that post-deprivation process could satisfy the Constitution in the national security circumstances presented and that Anthropic received a prompt opportunity to contest the exclusion.
The First Amendment claim failed for a different reason. The court agreed that Anthropic’s advocacy concerning AI safety was protected speech and that exclusion from the Department’s supply chain was materially adverse. But it found no causal connection between the two. In the court’s view, the Department acted because Anthropic refused to accept an “all lawful uses” contract term, not because Anthropic had publicly advocated for greater AI safeguards.
A different result from an earlier Anthropic decision
I wrote about this dispute earlier this year when the Northern District of California preliminarily blocked other federal actions against Anthropic. That court concluded, among other things, that Anthropic was likely to succeed in challenging a supply chain risk designation under a different federal statute.
The D.C. Circuit addressed that decision directly. It explained that the California case involved 10 U.S.C. § 3252, whose definition refers to the risk that an “adversary” may sabotage, maliciously introduce unwanted functionality, or otherwise subvert a system. The statute before the D.C. Circuit, 41 U.S.C. § 4713, instead applies to actions by “any person” and contains broader language concerning manipulation. The court therefore concluded that Anthropic could lose under one statute even though the California court had found its conduct outside the other.
The decision illustrates an important issue that will recur as AI systems become embedded in critical operations. Restrictions imposed by an AI developer may begin as contractual terms or safety policies, but model training can make those restrictions part of how the technology itself behaves. That means a disagreement over permitted use can become an operational question about whether the system will perform when the customer expects it to.
Anthropic PBC v. United States Department of War, Nos. 26-1049 & 26-1162 (D.C. Cir. Sept. 25, 2026).