Court Upholds Pentagon's Ban on Anthropic's Claude

Court Upholds Pentagon's Ban on Anthropic's Claude
⚖️ A $200M defense contract, one "no," and a six-month AI phase-out. Anthropic refused to let the Pentagon use Claude for "any lawful purpose"—no autonomous lethal targeting, no mass surveillance. So on Sept 25, a divided D.C. Circuit panel upheld the Pentagon's supply chain risk designation, keeping Claude banned from DoD systems. The twist? A San Francisco court struck the other designation down. Same conduct, opposite outcome—under two different laws. OpenAI and Google signed comparable contracts without the hard limits. The one that refused is in regulatory time-out. 🤖 Should writing down safety limits make you a compliance hero—or a supply chain risk? The market hasn't decided. What do you think?

Let's get the timeline straight, because this saga is less a story than a game of regulatory whack-a-mole with a very sophisticated mole.

Back in July 2025, the Department of War happily slipped Anthropic's Claude into a $200 million AI contract. By February 2026, that warm embrace had curdled. Defense Secretary Pete Hegseth demanded a contract tweak: Claude should be available for "any lawful purpose," no carve-outs. Anthropic CEO Dario Amodei, having spent January publicly urging limits on AI-powered weapons, declined to sign away his red lines—specifically, no fully autonomous lethal targeting and no mass domestic surveillance.

The Pentagon's response was swift. On March 3, Hegseth issued a formal supply chain determination under the Federal Acquisition Supply Chain Security Act of 2018, designating Anthropic a "supply chain risk" and ordering a six-month phase-out of Claude across Department systems and contractor workflows. Yes, the first time that particular hammer has hit a domestic U.S. company rather than a hostile foreign entity.

Two Laws, Two Courts, One Headache

Here's where it gets delightfully messy. The Pentagon didn't rely on one statute—it used two. And they're faring very differently in court.

Under 10 U.S.C. § 3252, the designation got struck down in August 2026 by a San Francisco federal judge who found the blacklisting unlawful. That ruling lets other federal agencies keep doing business with Anthropic.

Under 41 U.S.C. § 4713 (the 2018 supply chain security law), the story is different. On September 25, a divided D.C. Circuit panel upheld the designation 2–1. Judge Gregory Katsas, joined by Judge Neomi Rao, ruled the Department had ample basis to conclude that Claude's continued integration presented a statutorily covered national-security risk—including the uncomfortable prospect that Anthropic, having built restrictions into the model, could "manipulate" its behavior. Judge Karen LeCraft Henderson dissented.

Anthropic's due process and First Amendment retaliation claims? Tossed. The court found no causal connection between Amodei's speech and the exclusion—the Department just didn't like the model's constraints.

The Operational Fallout

The practical scoreboard reads:

  • Pentagon use of Claude: Banned, and staying banned for now.
  • Six-month phase-out: Already underway across DoD systems and defense contractor workflows.
  • Contractor scramble: Any vendor doing military work must now purge Claude from DoD-facing pipelines—a compliance headache with a hard deadline.
  • Civilian access: Untouched. Open the app, ask your mundane questions, no men in black appear.
  • The safeguards: Still in place. The ruling does not compel Anthropic to remove its restrictions.

Notably, OpenAI and Google signed comparable Pentagon contracts without the hard contractual limits Anthropic insisted on. Observable consequence: the company that baked in the safety language is the one sitting in regulatory time-out. Whether that's a cautionary tale or a badge of honor depends on your seat.

What to Watch

Two open questions dominate the horizon:

  1. En banc or the Supremes. Anthropic says it's weighing further review. The split with the California ruling—same conduct, opposite outcome under different statutes—gives the justices plenty to chew on.
  2. The contract-language precedent. Defense contractors now face a real question: does writing down your safety limits make you a supply chain risk, or a compliance hero? The market is voting, and no one's quite sure which box it's checking.

The near-term read: the Pentagon version of the ban holds; the broader federal ban doesn't. Long-term, the designation list just grew its first domestic, safety-conscious AI member—and everyone selling models to national-security agencies is now reading the fine print twice.

That's the reporting. Whether the next model learns to say "yes" or says "sorry" more tactfully is its own future headline.