Anthropic lost its bid to overturn the Pentagon’s national security “supply chain risk” designation Friday after a federal appeals court upheld the government’s decision to exclude the artificial intelligence company’s Claude models from military systems and contracts.
In a 2-1 decision, the U.S. Court of Appeals for the District of Columbia Circuit rejected Anthropic’s claims that the designation exceeded the Pentagon’s authority, was arbitrary and violated the company’s constitutional rights. The ruling leaves one of the Trump administration’s restrictions on Anthropic intact even after the company won a separate case in California last month over broader federal restrictions.
Writing for the majority, U.S. Circuit Judge Gregory Katsas said the Pentagon had sufficient grounds to conclude that Claude could pose a supply chain risk because Anthropic designs the model to refuse certain uses, including some involving lethal autonomous weapons and mass domestic surveillance. U.S. Circuit Judge Neomi Rao joined the opinion. U.S. Circuit Judge Karen LeCraft Henderson dissented.
Under the Federal Acquisition Supply Chain Security Act of 2018, agencies may exclude technology when its design or operation could deny, disrupt, or otherwise affect the functioning of a government system. The D.C. Circuit held that the law covers risks created by how a product operates regardless of whether the supplier intended harm.
A separate California ruling in August struck down a Pentagon designation issued under a different defense procurement law. U.S. District Judge Rita Lin found that the statute required malicious interference, a showing the government had not established. The D.C. Circuit said Friday that the 2018 supply chain law independently authorized Claude’s exclusion, allowing the two rulings to apply under different statutory standards.
The dispute began after the Pentagon sought permission to use Claude for “all lawful uses” as the military expanded its reliance on artificial intelligence. Anthropic agreed to loosen many of its restrictions but continued to prohibit the use of Claude for fully autonomous lethal weapons and mass surveillance of Americans.
CEO Dario Amodei has argued that current AI systems are not reliable enough to independently select and engage targets and that mass domestic surveillance creates serious civil liberties concerns.
Pentagon officials viewed the restrictions as an operational risk. The government argued that an AI system embedded in military operations must remain available when needed and cited previous instances in which Claude refused government requests. Officials also pointed to a dispute involving a sensitive overseas military operation as evidence that Anthropic’s safeguards could interfere with uses the department considered authorized.
Defense Secretary Pete Hegseth issued the supply chain determination on March 3, finding that continued use of Claude presented a significant national security risk and that less restrictive measures were inadequate.
Anthropic challenged the determination directly in the D.C. Circuit, arguing that the Pentagon had stretched a law designed to secure federal technology supply chains beyond what Congress intended.
Katsas wrote that Anthropic’s ability to build restrictions into Claude created uncertainty over whether the model would perform functions the Pentagon considered necessary. The court also deferred to the department’s conclusion that evaluating every potential military deployment would create greater delay, cost and uncertainty than removing the system from its supply chain.
The court also rejected Anthropic’s First Amendment retaliation claim. The majority recognized the company’s public advocacy over AI safety as protected speech and its exclusion from Pentagon contracts as adverse government action. It found that the Pentagon acted because Anthropic rejected an “all lawful uses” condition rather than because of the company’s public criticism of military AI policy.
Henderson rejected the majority’s reading of the supply chain statute. Her dissent argued that Congress designed the law to address hostile or deceptive interference with government technology, including threats involving foreign governments and malicious actors. Applying the same authority to openly disclosed safety restrictions, she wrote, gives federal agencies substantially broader power than Congress intended.
The California ruling continues to block the administration’s broader restrictions on Anthropic, while Friday’s decision preserves the Pentagon’s separate designation under the 2018 supply chain law. The ruling leaves Anthropic restricted from certain Pentagon work while its broader challenge to the administration’s actions continues.
Anthropic said it “respectfully disagrees” with the decision and pointed to its California victory involving the parallel designation. The company said it remains confident in its legal position and is considering further judicial review.