The D.C. Circuit’s 2-1 Ruling Turns Anthropic’s Own Guardrails Into a Supply-Chain Risk
A federal appeals court sided with the Pentagon in a case separate from the one Anthropic already won in California, ruling that Claude's own safety restrictions can count as evidence of a...
A federal appeals court ruled Friday that the Pentagon was within its rights to label Anthropic a “supply chain risk,” handing the Department of Defense a win in a legal fight that, a month earlier, had gone the opposite way in a different courtroom entirely. Judges on the U.S. Court of Appeals for the District of Columbia Circuit split 2-1 in the government’s favor, rejecting Anthropic’s challenge and leaving the Pentagon free to keep Claude off its own systems and bar the Defense Department from using Anthropic’s products.
Table Of Content
The ruling does not disturb the case Anthropic has already won. It is a separate lawsuit, filed the same month in a different court, built around what the Associated Press describes as “a different rule the Pentagon was using to try to declare Anthropic a supply chain risk.” Two federal courts looked at the same underlying dispute between an AI lab and its would-be biggest customer and reached opposite conclusions, and the reason why says less about who is right than about how narrow a legal needle a “supply chain risk” designation asks judges to thread when the thing being restricted is a piece of software’s own safety design.
Two Lawsuits, One Fight, Two Outcomes
The dispute traces back to February 2026, when Defense Secretary Pete Hegseth gave Anthropic three days to agree to “all lawful uses” of its technology, or be designated a supply chain risk. Anthropic refused to drop the restrictions it had built into Claude against fully autonomous weapons and mass domestic surveillance. President Donald Trump and Hegseth followed through, ordering every federal agency to stop using Anthropic’s products and barring defense contractors from doing any business with the company at all, even work with nothing to do with the Pentagon.
Anthropic responded by filing two separate complaints that same March, one in the Northern District of California and one in Washington, D.C., according to TechCrunch‘s reporting at the time. The California case reached a verdict first. On the night of August 27, U.S. District Judge Rita Lin ruled that the designation amounted to “unlawful retaliation in violation of the First Amendment” against Anthropic for publicly criticizing the Pentagon’s approach to military AI, a ruling sxz.io covered in depth at the time. TechCrunch noted at the time that the D.C. suit “is still ongoing.”
It has now concluded, and not in Anthropic’s favor. Judges Gregory G. Katsas and Neomi Rao, both nominated to the D.C. Circuit by Trump, formed the majority. Judge Karen LeCraft Henderson, nominated by President George H.W. Bush in 1990, dissented. The panel’s makeup meant the same underlying grievance produced opposite outcomes in front of two different courts, weighing two different legal theories against the same designation.
What ‘What, Not Why’ Means for a Safety Feature
The D.C. Circuit’s majority did not dispute the facts Judge Lin relied on. According to the Associated Press wire report carried by KSAT, the judges said they had “no reason to doubt” that Anthropic acts with “noble intentions” in restricting what Claude will do, and they had “no quarrel” with the conclusions the California court reached in the separate case. Where they parted ways was on what the law actually requires for a supply chain risk finding to stand: not a bad motive on Anthropic’s part, but simply “on what Anthropic does, not why Anthropic does it.”
That standard turned Anthropic’s own engineering choices into the government’s exhibit. The majority opinion, written by Katsas, noted that “by Anthropic’s own admission, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent.” From there, the reasoning followed a straight line: “The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary,” Katsas wrote, concluding the Pentagon had “ample support” for its position. The same safety guardrails Anthropic built specifically to keep Claude from being weaponized against domestic surveillance or autonomous lethal use became, in the majority’s reading, proof that the company might one day withhold a capability the Pentagon considered its own to command.
It is a distinction with real teeth for any AI vendor doing business with the federal government. A company cannot simply avoid the “why” question by having good intentions; under this reading, the mere technical capacity to restrict a model’s behavior, regardless of the reason it was built, can itself support a national-security risk finding if a customer decides it does not like being told no.
A Dissent, and an Unsettled Next Move
Judge Henderson’s dissent was not detailed in the AP’s account beyond her vote, but her presence as the lone holdout, and the one judge on the panel not appointed by Trump, underscores how contested the “what, not why” framework is even among judges who agree on the underlying facts. Pentagon spokesman Sean Parnell called the outcome a full vindication, writing that “today’s DC Circuit Court ruling completely validates the Department’s position,” according to the AP.
Anthropic was less conciliatory. A company spokesperson said in a written statement that Anthropic “respectfully disagrees” with the court’s decision. “Another federal court has already held the government’s parallel designation unlawful,” the statement continued. “We remain confident in our position and are considering all options, including further review.” That leaves open the possibility of a petition for rehearing en banc before the full D.C. Circuit, or an eventual appeal to the Supreme Court, either of which could take months to resolve while the practical restrictions imposed by Friday’s ruling stay in effect.
For now, the two rulings coexist uneasily. The California decision, which sxz.io covered when it came down in August, blocks the Pentagon from punishing Anthropic for its public criticism. The D.C. ruling lets the Pentagon’s underlying supply chain risk label stand on entirely separate grounds, meaning the restrictions on Claude that took effect in March remain in force for now, regardless of which theory a future court finds more persuasive. Any AI company weighing whether to hold firm on safety commitments in a high-stakes government contract now has a live example of how that choice can be read in court: not as evidence of good faith, but as evidence of exactly the kind of control a national-security customer says it cannot accept.








No Comment! Be the first one.