Court Upholds Pentagon Blacklisting of Anthropic — What a Supply-Chain Designation Means for Model Deployments

On 25 September 2026, a panel of the US Court of Appeals for the D.C. Circuit ruled 2-1 to uphold the Pentagon’s designation of Anthropic as a supply-chain risk — keeping Claude models out of US military systems and barring defense contractors from using them in Pentagon work. The majority found the Department of Defense had “ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk.” It is the first appellate ruling to treat a frontier AI lab’s usage policies as a cognizable supply-chain threat — and it directly contradicts a federal judge in San Francisco, who ruled last month that the government’s parallel designation was illegal.

For security teams, the case matters less as politics than as precedent: supply-chain risk law now reaches the model layer, and a vendor’s refusal to grant unrestricted use can itself be framed as the risk.

How a contract dispute became a blacklist

Anthropic started as an early Pentagon AI partner, signing a $200 million contract in July 2025. Talks collapsed that September over deployment on the DOD’s GenAI.mil platform: the military wanted unfettered access to Claude across all lawful purposes, while Anthropic sought assurance its technology would not be used for fully autonomous weapons or domestic mass surveillance. Defense Secretary Pete Hegseth accused the company of trying to “seize veto power over the operational decisions of the United States military.” In March 2026 the DOD labeled Anthropic a supply-chain risk — purportedly a threat to national security — and Anthropic sued in both San Francisco district court and the D.C. Circuit, because the department relied on two distinct designations that had to be litigated in two courts.

That procedural split is now producing a split-brain outcome: one designation unlawful (San Francisco, August), the other upheld (D.C. Circuit, September). The appellate panel delayed its decision from taking immediate effect so Anthropic can seek panel rehearing, en banc review, or Supreme Court review. “We respectfully disagree with the court’s decision,” an Anthropic spokesperson said. “Another federal court has already held the government’s parallel designation unlawful. We remain confident in our position and are considering all options, including further review.”

The opinion’s security logic is worth reading carefully

Judge Gregory Katsas, joined by Judge Neomi Rao, rejected Anthropic’s argument that the ban was arbitrary, unauthorized and unconstitutional. Two passages carry the weight:

  • Availability as a security property. Katsas credited Hegseth’s “deeply sobering” concern that “overly constrained” AI models could shut down unexpectedly — plus the potential that Claude might be “subject to manipulation.” Read plainly, the court accepted refusal-behavior and steerability limits as operational risks to military systems, not just product choices. That is a remarkable framing for anyone who builds usage policies: the safeguard itself was entered into evidence as the hazard.
  • Deference on the balance. “In our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks,” Katsas wrote, finding the Secretary did not transgress the Supply Chain Security Act or the Constitution. Judge Karen LeCraft Henderson dissented.

Anthropic disputes both premises, and the San Francisco ruling shows a court can look at the same facts and find the designation unlawful. Expect this tension — vendor usage constraints as customer supply-chain risk — to recur wherever regulated buyers meet labs with acceptable-use policies.

What to do

  • Dual-source frontier models in regulated environments now. A single designation removed Claude from an entire buyer class overnight. If your deployment or your customers’ deployments touch defense, critical infrastructure or government work, no single lab should be a single point of failure.
  • Track designations like you track CVEs. Supply-chain-risk listings, entity lists and procurement bans now move at the speed of model releases. Assign ownership for monitoring them and map each model in your stack to the jurisdictions that could restrict it.
  • Negotiate usage-policy carve-outs in writing, early. The GenAI.mil collapse shows acceptable-use terms are no longer click-through boilerplate — they are the contested surface. Get red lines on autonomous-weapons, surveillance and refusal-behavior expectations into enterprise agreements before integration deepens.
  • Model the “constrained model shuts down” scenario. Whatever you think of the court’s reasoning, the availability question is real: behavior changes, safeguard updates and verification-gated capabilities (Anthropic’s own Cyber Verification Program model) can alter what your deployment can do without notice. Pin versions, changelog-gate upgrades, and keep a fallback model warm.
  • Watch the rehearing window. The decision is stayed pending further review petitions. Contractor guidance could change again within weeks — don’t hard-code today’s blacklist state into long-term architecture.

Sources: