Key Points
- The D.C. Circuit held that the Supply Chain Security Act's definition of 'supply chain risk' does not require bad motive, allowing the Pentagon to exclude Anthropic for refusing to remove AI safety restrictions.
- The court found that Anthropic's ability to encode safety restrictions into Claude through model training constitutes 'manipulating' the product's design and operation under the statute.
- Judge Henderson dissented, arguing that the statute's hostile verbs like 'sabotage' and the adverb 'maliciously' indicate Congress meant to cover only deliberately subversive conduct.
- The court rejected Anthropic's due process and First Amendment claims, finding the dispute was contractual rather than retaliatory.
- The ruling permits the Pentagon to complete removing Claude from defense systems within the 180-day period ordered in March 2026.
The D.C. Circuit on Friday denied Anthropic's challenge to its exclusion from the Pentagon's supply chain, holding that the AI company's refusal to remove contractual safety restrictions from its Claude product gave the Department of War adequate grounds to treat it as a national security risk.
Judge Gregory Katsas wrote for a 2-1 panel that the Department's determination was reasonable under the Federal Acquisition Supply Chain Security Act of 2018, rejecting Anthropic's arguments that the statute required evidence of malicious intent. Judge Neomi Rao joined the majority. Judge Karen LeCraft Henderson dissented, arguing that the statute's definition of "supply chain risk" demands some showing of deliberately subversive conduct.
The ruling clears the way for the military to complete its removal of Claude from defense systems and shifts the AI landscape for government contracts. Anthropic may seek further review, and the statutory construction fight between the majority and dissent positions the case as a potential vehicle for Supreme Court review of procurement-statute canons.
The dispute arose in early 2026 after negotiations between Anthropic and the Department broke down. The Department had used Claude through contractors since 2024, and Anthropic had agreed to permit uses including weapon system design and offensive cyber operations. But the company maintained restrictions on lethal autonomous warfare and mass surveillance of Americans. In February 2026, Secretary of War Pete Hegseth demanded Anthropic accept an "all lawful uses" contractual term. CEO Dario Amodei publicly refused.
On March 3, the Secretary formally invoked the Supply Chain Security Act to exclude Claude, finding that an "urgent national security interest" required immediate action. The determination cited Anthropic's ability to "alter system guardrails and model weights" governing Claude's responses and an incident in which an Anthropic executive "questioned the propriety" of a contractor's use of Claude "for a sensitive military operation abroad."
The central legal question was whether Anthropic's conduct fell within the statute's definition of "supply chain risk," which covers the risk that any person may "sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate" covered products. Anthropic argued the hostile verbs indicated Congress meant to cover only deliberately subversive acts, and that its open, contractually disclosed safety restrictions could not qualify as surreptitious manipulation.
Judge Katsas rejected that reading. "Based on undisputed record evidence, there is not only a 'risk'—but a certainty—that Anthropic will so manipulate the 'design' or 'operation' of Claude to deny it the 'function' of conducting lethal autonomous warfare or mass domestic surveillance," he wrote.
The majority found that while "sabotage" connotes hostile intent, other verbs in the list do not uniformly require bad motive. Unlike criminal statutes where courts impose narrow readings, the Supply Chain Security Act is a procurement statute enabling the Executive Branch to mitigate national security risks. "At least as applied here, the statutory definition of a 'supply chain risk' turns on what Anthropic does, not why Anthropic does it," Judge Katsas wrote.
On Anthropic's argument that the Department could refuse model upgrades rather than exclude the company entirely, Judge Katsas was unpersuaded. "Quite obviously," he wrote, "the Department cannot utilize AI systems that remain trapped in amber."
The panel rejected Anthropic's constitutional claims. Post-deprivation process satisfied due process where the government needed to act quickly, and the First Amendment retaliation claim failed because Anthropic could not show the Department acted because of its AI safety advocacy rather than its contractual refusal.
Judge Henderson dissented on statutory construction. She would have applied the canon of noscitur a sociis—that a word is known by the company it keeps—to read "manipulate" as limited to intentionally subversive conduct suggested by "sabotage" and "maliciously introduce."
The dissent warned that the majority's reading would let the Department designate any contractor a supply chain risk for enforcing disfavored contractual restrictions. "Suppose the Secretary tells Anthropic's presumed replacement to change its AI-use policies to permit any 'functions that the Department deems necessary' or it will share the same fate as Anthropic," Henderson wrote. "According to today's decision, that contractor will have a choice: Agree to the Secretary's demands or risk being designated a national security threat under FASCSA."
The ruling does not affect a separate challenge Anthropic brought in the Northern District of California under 10 U.S.C. § 3252, which uses the word "adversary" and has a narrower definition of supply chain risk. That court set aside the Department's designation in August 2026, finding that statute's hostile language requires bad motive.
Kelly P. Dunbar argued for Anthropic. Sharon Swingle argued for the government.