
Image: METAL
Summary
- On September 25, the U.S. Court of Appeals for the D.C. Circuit upheld, 2-1, the Department of Defense's (now the Department of War) exclusion of Claude from its supply chain and denied Anthropic's petition.
- The majority found ample support for the national-security risk determination, citing instances in which Claude's use restrictions led it to refuse government requests and a dispute over its use in an overseas military operation.
- Judge Henderson argued in dissent that the statute's notion of manipulation should be read narrowly, and Anthropic said it is considering all options, including further review.
On September 25, the U.S. Court of Appeals for the D.C. Circuit upheld, by a 2-1 vote, the decision of the U.S. Department of Defense (now called the Department of War) to exclude Anthropic's Claude from its supply chain. The court rejected all of Anthropic's claims that the action was arbitrary, unauthorized by statute and unconstitutional. The ruling keeps in place a situation in which the U.S. military cannot use Anthropic's models and defense contractors cannot use Claude in their work for the department.
"The Department had ample support for its conclusion that the continued integration of Claude into the Department's information systems, by the Department or its contractors, presented a statutorily covered national-security risk," wrote Circuit Judge Gregory Katsas for the majority. Judge Neomi Rao joined the majority, and Judge Karen LeCraft Henderson dissented. The opinion METAL reviewed runs 51 pages; the case was argued on May 19 and decided on September 25.
The dispute is rooted in a contract term. According to the opinion, Anthropic was included in a $200 million Department AI contract awarded in July 2025, and from that fall it negotiated a direct contract with the department. The department asked for permission to use Claude for all lawful uses, and Anthropic substantially relaxed its existing use restrictions while insisting to the end on two exceptions: lethal autonomous warfare and mass surveillance of Americans.
The timeline laid out in the opinion moves quickly. Secretary Pete Hegseth issued an AI strategy on January 9 directing that "any lawful use" language be written into AI contracts, and on February 24 he met Chief Executive Dario Amodei and demanded that Anthropic accept the term by February 27. In a February 26 statement, Amodei refused, saying mass domestic surveillance was "incompatible with democratic values." Hegseth made a formal determination under the Federal Acquisition Supply Chain Security Act (FASCSA) on March 3, and on March 6 the department's chief information officer ordered Anthropic products removed from all systems within 180 days at the latest.
The majority rested its risk finding on three strands of fact. As Anthropic admits, Claude has restrictions encoded into it that prevent tasks the company wishes to prevent, and on more than one occasion these restrictions stopped Claude from performing tasks requested by government users. The opinion says that in 2024, Claude refused tasks in classified systems such as summarizing threat assessments or translating intercepted materials, and that it also declined to respond to queries from the Centers for Disease Control and Prevention (CDC) about research on preventing the spread of infectious disease. On top of that, the court said, a dispute over whether contract terms permitted Claude's use in an overseas military operation left the department uncertain whether Claude would perform when needed.
On the constitutional questions, the court also sided with the department. Judge Katsas found no due-process violation because the department promptly notified Anthropic of the exclusion and its rationale and gave it a fair opportunity to contest it. On the First Amendment claim, he wrote that the department excluded Anthropic not because of the company's support for greater regulation of AI, but because it refused to agree to a contract term the department deemed essential. The court concluded that even Hegseth's February 27 social media post denouncing Anthropic's sanctimonious rhetoric was ultimately aimed at the refusal to accept the contract term.
Judge Henderson's dissent turns on a single word in the statute. FASCSA defines supply chain risk as the risk that someone may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate a product, and the majority read manipulate in a broad sense, like turning a doorknob. Judge Henderson countered that every word in the preceding list describes intentionally covert, hostile acts, so the term should be read narrowly. She wrote that the law was enacted to stop hostile actors such as companies beholden to foreign governments from infiltrating federal systems, and that a contractor's honest and upfront enforcement of use restrictions the government dislikes is far from what Congress had in mind.
The legal fight is not over. Because the department relied on two separate designations, the litigation proceeded in two courts, and a federal court in San Francisco ruled last month that the other designation was unlawful. METAL previously reported on Anthropic's first court win in this fight. "Another federal court has already held the government's parallel designation unlawful," an Anthropic spokesperson said. "We remain confident in our position and are considering all options, including further review." According to reports, the panel delayed the decision from taking effect so that Anthropic can seek rehearing or rehearing en banc, and a Supreme Court appeal also remains possible.
Seen through a tech lawyer's lens, the weight of this ruling lies in how statutory interpretation turns into contract leverage. As Judge Henderson noted, if this reading holds, the next AI supplier will face the same two paths: accept the usage policy the Secretary wants, or risk being designated a national-security threat. In its conclusion, the majority acknowledged both the risk of overly constrained AI shutting down mid-operation and the risk of unconstrained AI hallucinating inappropriate targets as deeply sobering concerns, but it held firmly that striking the balance between them is for the President and the Secretary. The safety principles an AI company writes into its terms can become grounds for a supply chain risk finding in government procurement, and that is the question this ruling leaves on the AI industry's contracts.





Comments