AERIOXFLUX
← Frontier Labs
Frontier Labs · anthropic

A Court Just Ruled Claude's Refusals Are a Supply-Chain Risk

A split D.C. Circuit panel upheld the Pentagon's blacklisting of Anthropic, finding that a model built to say no can be treated as a national-security liability, while a California ruling against a parallel designation still stands.

Flux Desk·2026-09-26·5 min read

For most of the AI industry, a model that refuses certain requests is a safety feature. On September 25, two federal appellate judges ruled that it can also be a national-security risk. In a 2-1 decision, the U.S. Court of Appeals for the D.C. Circuit upheld the Pentagon's March designation of Anthropic as a supply-chain risk, the label that cancelled the company's military contracts and bars Defense Department contractors from using Claude.

Anthropic says the blacklisting has cost it billions of dollars in lost business and damaged its reputation ahead of a planned initial public offering, according to Reuters. The ruling leaves that damage in place, at least for now.

How it got here

The dispute is about two contract terms. Anthropic signed a $200 million Pentagon contract in July 2025. Talks broke down when the department wanted unrestricted use of the models and Anthropic insisted Claude not be used for fully autonomous lethal weapons or domestic mass surveillance. In February, Defense Secretary Pete Hegseth demanded those restrictions come out. Anthropic declined.

On March 3, Hegseth announced the designation, saying, per Courthouse News, that "Anthropic's stance is fundamentally incompatible with American principles." The exclusion was issued under the Federal Acquisition Supply Chain Security Act of 2018, a law most people associate with keeping hostile foreign hardware and software out of government systems.

Because the government relied on two separate designations under different authorities, Anthropic had to fight in two courts. In August, U.S. District Judge Rita Lin in San Francisco struck down the parallel designation, finding the administration had unlawfully retaliated against Anthropic for its views on AI safety. ABC News reports she wrote that the actions were driven by a desire to make a public example of the company for its "arrogance." That ruling remains in effect. The D.C. Circuit case concerned the other designation, and it went the other way.

What the majority said

Judge Gregory Katsas wrote the opinion, joined by Judge Neomi Rao. The core finding is that Anthropic's control over Claude's behavior is itself the risk. "The company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent," Katsas wrote, per excerpts published by the Volokh Conspiracy. "On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users."

Courthouse News reports the department pointed to a 2025 incident in which Claude refused CDC requests about infectious disease prevention, and to an executive who questioned whether Claude could be used for a sensitive military operation. From there, the court accepted the Pentagon's operational argument. "The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail," Katsas wrote, as quoted by Reuters.

The majority also rejected Anthropic's First Amendment claim. The department, it held, excluded the company "based on the company's refusal to assent to a contract term that the Department deemed essential, not based on the company's support for greater governmental regulation of AI technology." And it dismissed the argument that the statute only covers adversaries, noting the definition covers "any person," which "cannot refer only to foreign entities."

The dissent's warning

Judge Karen LeCraft Henderson read the same law as aimed at something very different: sabotage, subversion and covert interference. Per ABC News, she wrote that the law does not treat "a contractor's honest and upfront enforcement of restrictions" as the kind of risk that lets the government blacklist it.

Her larger point was about precedent. Courthouse News quotes her imagining a secretary telling a contractor to change its policies "or it will share the same fate as Anthropic." That is the scenario every AI vendor with an acceptable-use policy now has to consider. The majority's reasoning does not depend on Claude being malicious or compromised. It depends on Anthropic being able to decide what Claude will not do.

The split that makes this messy

The practical result is a legal contradiction. One federal court has found the government's action against Anthropic was unlawful retaliation. Another has found the procurement-based designation was lawful and well supported. Anthropic's statement leans on the first: "We respectfully disagree with the court's decision. Another federal court has already held the government's parallel designation unlawful." The company says it is "considering all options, including further review," which Military Times reports includes asking the full D.C. Circuit to rehear the case.

For customers, the distinction matters. The California ruling blocked the broader government-wide ban. The Pentagon exclusion, grounded in procurement law, stays. Any company that sells to the Defense Department, directly or as a subcontractor, still cannot build on Claude.

The IPO problem

Anthropic's filings put the stakes in writing. Its court papers said the government's adverse actions risk hundreds of millions, or even multiple billions, of dollars in lost revenue for 2026. The company now says the cost has already reached billions.

That is a disclosure problem as much as a revenue one. A company heading toward a public offering will have to describe this litigation, the contractor ban and the conflicting rulings as risk factors. Investors will be asked to price a business whose safety policy is, in the view of one appellate court, a legitimate reason for the largest buyer in the U.S. government to shut it out.

Why it matters

This ruling reframes what a safety policy is in procurement terms. Every frontier lab ships usage restrictions. Until now, those were treated as terms a customer could negotiate or walk away from. The D.C. Circuit majority treated them as a reliability defect that the government can act on under a supply-chain security law, without showing sabotage or foreign influence.

If that reading survives further review, government buyers gain leverage over how models behave, not just what they cost. Labs will face a choice between restrictions that hold for every customer and contracts that carve out exceptions for the military. Anthropic chose the first and has so far paid for it in billions. Whether that holds now depends on further review, and the rest of the industry will be reading every filing.

#anthropic#pentagon#supply-chain-risk#ai-policy#claude

The state of AI, in flux.

The directory + magazine for AI tools and the workflows people use to make money with them.

🔥 The Sauce Drop

The week's highest-earning AI workflows, in your inbox.

Some outbound links are affiliate links — Flux may earn a commission at no cost to you; this never affects rankings. Earnings figures are self-reported and not guarantees of income; most people earn less, some earn nothing.