A court let the Pentagon blacklist Anthropic over the limits it puts on Claude

A US appeals court voted 2-1 to uphold the Pentagon's designation of Anthropic as a national-security supply-chain risk, after the company refused to let Claude be used for autonomous weapons or mass surveillance. It is a rare, concrete test of what an AI lab's safety red lines cost when the customer is the military.

By Yash Malviya

Published

Dario Amodei, portrait
TechCrunch / Wikimedia Commons (CC BY 2.0)

A safety stance with a price tag

Anthropic logo
Anthropic / Wikimedia Commons (public domain)

Anthropic has built its brand on being the careful AI lab, the one that draws lines about what its models may and may not do. This week a federal court showed what those lines can cost. On 25 September 2026, the US Court of Appeals for the D.C. Circuit voted 2 to 1 to uphold the Pentagon's decision to brand Anthropic a national-security supply-chain risk, a designation that effectively shuts the company out of a large swath of military work.

The ruling is a rare, concrete test of a question the industry usually debates in the abstract: what happens when a company's AI safety principles run headlong into what a powerful customer demands. For Anthropic, the answer this round was a loss in court and a real hit to its business.

Why Anthropic was blacklisted

The dispute is not about a security flaw in Claude. It is about restraint. The Pentagon made its supply-chain-risk designation in March after Anthropic refused to let its models be used for two things: fully autonomous weapons and domestic mass surveillance. Anthropic's position, which it reiterated after the ruling, is that AI is not yet reliable enough to be trusted in autonomous weapons, and that domestic surveillance crosses a line on fundamental rights.

The Defense Department saw the same restrictions differently. It wanted assurance that the models it integrates could be used across the full range of lawful military purposes, and it treated a vendor that builds in refusals as a dependency it cannot control. In the government's telling, an AI system that might decline a task mid-operation is not a principled partner but an operational liability.

Female engineer managing multiple screens during a technology simulation in a control room
The dispute is not about a flaw in Claude. It is about Anthropic's refusal to allow autonomous-weapons and mass-surveillance uses. Photo: ThisIsEngineering / Pexels

What the court decided

The majority sided with the Pentagon, and its reasoning is worth reading carefully because it is not the caricature either side might want. Writing for the court, Judge Gregory Katsas, joined by Judge Neomi Rao, found the designation a reasonable national-security judgment rather than an act of political payback. The majority noted that Anthropic "encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent," and that "on more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users." That, the court held, was enough to justify treating the integration of Claude as a covered national-security risk.

“The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail.”

Judge Gregory Katsas, majority opinion, US Court of Appeals for the D.C. Circuit, 25 Sep 2026

Katsas also gave voice to the military's underlying worry in a line that captures the whole clash. "The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail," he wrote. The court rejected Anthropic's claims that the blacklisting was unlawful retaliation for its views on AI safety and ethics, and its related First Amendment argument.

It was not unanimous. Judge Karen Henderson dissented, leaving Anthropic a thread to pull. The company said it "respectfully" disagrees with the decision, remains confident in its position, and is considering all options, which legal observers read as a possible request for review by the full D.C. Circuit or, eventually, the Supreme Court.

The stakes for Anthropic

This is not a symbolic defeat. Being labeled a supply-chain risk cuts Anthropic out of contracts and casts a shadow over its standing as a government vendor, and the company has said the designation has already cost it business and bruised its reputation at an awkward moment, with a closely watched initial public offering on the horizon. A lab that has spent years arguing its caution is a feature, not a bug, now has to explain to investors why that caution also carries a concrete revenue cost.

The awkwardness runs deeper than money. Anthropic's entire pitch, from its published safety framework to its founders' public warnings, is that responsible restraint is what separates it from rivals. A court has now effectively ruled that, at least for the Pentagon, that same restraint makes it less useful than a competitor willing to hand over unrestricted access.

The bigger question

Strip the case to its core and it poses a question every frontier lab will eventually face. AI companies increasingly advertise "red lines," uses they will refuse on ethical grounds. Those commitments look principled in a blog post. This ruling shows they are also commercial and legal positions with consequences, and that a determined government buyer can respond by simply routing around the company that holds them.

It also sharpens a tension inside the safety movement itself. The same pace-the-frontier caution that Anthropic's leadership urges on the whole industry is, in this instance, exactly what the Pentagon cited as the reason to exclude it. Safety as self-restraint and safety as reliability are not the same thing, and here they pulled in opposite directions: Anthropic restrained Claude on principle, and the government called an unpredictably restrained model a risk.

Our take

The tidy version of this story, that a brave safety-first lab was punished for its ethics, does not survive the opinion. A 2-1 majority looked at the retaliation claim and rejected it, resting instead on a plausible operational concern about models that refuse tasks in the field. The equally tidy opposite, that Anthropic was simply an unreliable vendor, ignores that the "unreliability" is a deliberate refusal to build autonomous weapons or surveillance tools, which many would call a virtue. What is left is genuinely hard, and more interesting than either headline: a company's ethical limits and a government's demands collided, a court had to weigh them, and the limits lost. Anthropic can appeal, and may. But every AI company now has a data point about what its red lines are worth when the customer is the most powerful military on earth, and the number is not zero.

Frequently asked questions

What did the court decide?

On 25 September 2026, the US Court of Appeals for the D.C. Circuit voted 2 to 1 to uphold the Pentagon's designation of Anthropic as a national-security supply-chain risk. The court treated the designation as a reasonable national-security judgment rather than political payback, and it rejected Anthropic's retaliation and First Amendment claims.

Why did the Pentagon blacklist Anthropic?

The Pentagon made the designation in March, after Anthropic refused to let Claude be used for two things: fully autonomous weapons and domestic mass surveillance. Anthropic's position is that AI is not yet reliable enough to be trusted in autonomous weapons and that domestic surveillance crosses a line on fundamental rights. The dispute was about that restraint, not about a security flaw in Claude.

What was the court's main reasoning?

Writing for the majority, Judge Gregory Katsas, joined by Judge Neomi Rao, noted that Anthropic encodes restrictions into Claude that prevent the model from performing certain tasks, and that on more than one occasion those restrictions had stopped Claude from performing tasks requested by government users. The court held that this was enough to justify treating the integration of Claude as a covered national-security risk.

Was the ruling unanimous, and can Anthropic appeal?

No, it was a 2-1 decision. Judge Karen Henderson dissented. Anthropic said it respectfully disagrees, remains confident in its position, and is considering all options, which observers read as a possible request for review by the full D.C. Circuit or, eventually, the Supreme Court.

What does the designation cost Anthropic?

Being labeled a supply-chain risk effectively shuts Anthropic out of a large swath of military work, cutting it out of contracts and casting a shadow over its standing as a government vendor. The company has said the designation has already cost it business and bruised its reputation, at an awkward moment with a closely watched initial public offering on the horizon.

Sources

What each one is, and whose it is.

  1. DocumentationIndependent of the vendor
  2. Press reportIndependent of the vendor
  3. Press reportIndependent of the vendor