The D.C. Circuit Sided With the Pentagon. The Dissent Turns on One Word.
A 2-1 D.C. Circuit panel upheld the Pentagon's blacklisting of Anthropic, backing the government on military AI terms while the dissent turns on one word.

A three-judge panel of the U.S. Court of Appeals for the D.C. Circuit ruled 2-1 on Friday that the Pentagon may keep Anthropic on its list of supply chain risks, ending one round of a fight the company opened after the Department of War cut its Claude models out of military and contractor work. The decision does more than settle a procurement dispute. It answers a question the AI industry has been circling since the first defense contracts were signed: when a model maker attaches conditions to how its software may be used, who decides whether those conditions are a deal term or a security threat? The court said the buyer does.
What the panel actually decided
The case, Anthropic PBC v. U.S. Department of War, was argued in May and decided Friday. It was a three-part attack: Anthropic contended the exclusion was arbitrary, that the statute did not authorize it, and that it violated the First Amendment and due process. The panel rejected all three, as CNBC reported. Judge Gregory Katsas, writing for himself and Judge Neomi Rao — both Trump appointees — found the record sufficient:
"The Department had ample support for its conclusion that the continued integration of Claude into the Department's information systems, by the Department or its contractors, presented a statutorily covered national-security risk."
The court's own account of the facts is blunter than most of the coverage. The Department acted, it says, "after Anthropic refused to relax contractual prohibitions on the use of Claude for lethal autonomous warfare or domestic surveillance." The constitutional claims failed separately: due process because the company was told why it was excluded and given a chance to contest it, and free speech because, on the majority's reading, the exclusion rested on a refusal to accept a contract term rather than on Anthropic's advocacy about AI regulation. The excerpts published by the Volokh Conspiracy carry the reasoning at length.
The dissent rests on a single word
Judge Karen LeCraft Henderson, appointed by George H. W. Bush, did not dispute the national-security framing. She dissented on the statute. Under FASCSA, the Secretary may exclude a source only after concluding it poses a significant risk that it will "sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate" a covered article — and the whole case, as she noted, turned on that last clause, because the two sides read "manipulate" differently. Anthropic read it as deliberately subversive acts carried out by deceptive means. The government read it as control, the way a hand turns a doorknob.
Henderson accepted the narrower reading. Under the majority's, she wrote, a contractor's honest and upfront enforcement of restrictions the government dislikes would itself be a supply chain risk — a result she said sits badly with a statute enacted to answer hostile states and other bad actors compromising federal supply chains. The majority declined to narrow the definition that way, because it covers "any person" and not only adversaries: whatever examples Congress had in mind, the words reach further.
Two designations, two courts, one label left standing
The March blacklisting was never a single act. The Department leaned on two separate designations to support it, which is why the dispute has run through two courthouses at once. A San Francisco judge granted Anthropic an injunction in March, the ruling we covered at the time, and in August a judge there held one of the two designations illegal outright. Friday upheld the other. Anthropic's statement to CNBC leans on exactly that asymmetry:
"We respectfully disagree with the court's decision. Another federal court has already held the government's parallel designation unlawful. We remain confident in our position and are considering all options, including further review."
So how much government business Anthropic has actually lost is still an open question. One label stands, one has been struck down elsewhere, and the panel delayed the immediate effect of its ruling so the company can seek rehearing.
The contract that collapsed, and the terms at issue
The argument has a documented prehistory. Anthropic signed a $200 million Pentagon contract in July 2025. Talks about deploying Claude on the Department's GenAI.mil platform collapsed that September over a version of the same disagreement. The Department wanted access for all lawful purposes; Anthropic wanted written assurance its models would not be used for fully autonomous weapons or mass domestic surveillance. Defense Secretary Pete Hegseth framed it as a question of command, accusing Anthropic of trying to "seize veto power over the operational decisions of the United States military."
The majority treats the same facts as a procurement problem rather than a speech problem. Claude carries restrictions Anthropic encodes itself, the opinion notes, and "on more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users." It also recounts a dispute over whether those prohibitions covered an ongoing overseas military operation, leaving the Department unsure how the model would behave. Katsas raised the prospect of "overly constrained" models shutting down mid-operation, and of Claude being "subject to manipulation." Anthropic has contested both characterizations.
What readers argued
The Hacker News thread under the CNBC report ran to hundreds of comments, and the two loudest positions map onto the panel's split. The punitive reading held that the designation was retaliation for a company exercising a contract right. "It's clearly a punitive measure and has nothing to do with national security," one commenter wrote, asking how a vendor's terms for its own product could threaten the Department's supply chain. The other camp treated the case as ordinary procurement:
"Anthropic wanted to have rules on how the military used AI, the military said no and therefore doesn't want anthropic used anywhere in their supply line."
Those commenters quoted FASCSA's own text back at the thread, and one said OpenAI's government agreement carries comparable limits on surveillance and autonomous weapons without a designation following — a comparison others disputed on the details. These are reader arguments, not findings, and the court resolved the statutory question the other way.
The politics wrapped around the docket
The ruling lands inside an unusually personal fight. Trump has attacked Anthropic chief executive Dario Amodei on social media repeatedly, including a post this month that named him as an example of AI "people" doing bad "things." Amodei was not invited to the White House state dinner for Xi Jinping this week, and he recently called for an industry-wide slowdown, a position the summit readout showed the administration is not taking up. None of it appears in the opinion. It is the backdrop against which Henderson's dissent will be read.
What the ruling settles, and what it leaves undecided
Two conclusions follow. The limits on military AI use are, for now, set by the buyer: Anthropic can write restrictions into Claude, but it cannot make the Department accept them as a condition of a contract. And the law is less settled than the headline "court upholds blacklist" suggests. One of two designations stands, the other has been held unlawful by a different court, and the panel delayed its ruling's effect so Anthropic can petition for rehearing — by the same panel or en banc — before the Supreme Court becomes relevant.
The most balanced passage in the file belongs to the majority, and it concedes what a court can and cannot weigh:
"The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail. Anthropic raises the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force. Both possibilities present obvious national-security concerns."
Ranking those two risks, the court held, is the President's and the Secretary's job. Whether that division of labour still holds for a technology this new is now a question for Congress, for the procurement officers who write the next contract, and for whoever decides whether Anthropic's terms were a negotiation or a punishment.


