News

The court said the refusal was the risk. The Pentagon keeps Claude out.

A 2-1 D.C. Circuit panel on Friday upheld the Pentagon’s designation of Anthropic as a national-security supply-chain risk. Katsas and Rao said the refusal to relax Claude on autonomous weapons and mass surveillance was enough. Henderson dissented. Rita Lin’s California order still stands on a different statute. Claude stays off Defense work.

The Pentagon looking northeast, with the Potomac River and the Washington Monument in the distance. Department of Defense photograph by Master Sgt. Ken Hammond, U.S. Air Force, public domain, via Wikimedia Commons.
Photo: Master Sgt. Ken Hammond, U.S. Air Force / Wikimedia Commons (Public Domain / PD-USGov-DoD)

Friday’s order is a merits loss, not a pause. A 2-1 panel of the U.S. Court of Appeals for the D.C. Circuit denied both petitions in Anthropic PBC v. U.S. Department of War, Nos. 26-1049 and 26-1162, and left the Pentagon’s label in place: Anthropic is a national-security supply-chain risk under the Federal Acquisition Supply Chain Security Act, 41 U.S.C. § 4713. Judge Gregory Katsas wrote for himself and Judge Neomi Rao. Judge Karen LeCraft Henderson dissented. The first American frontier lab to wear this designation in this fight still wears it tonight. Claude stays off Defense systems, and off the contractors who work them.

The court did not find a foreign implant. It found a refusal the Secretary called essential, and it called the refusal the risk.

This is not Saturday’s OpenAI file. It is a contract term that a court just treated as a security event.

What the majority counted as the risk

CNBC, WIRED, and Reason all carry the holding. The Department had “ample support” that continued integration of Claude — by the Department or its contractors — presented a statutorily covered national-security risk. The trigger was not a leak and not a backdoor. Anthropic would not relax Claude’s prohibitions on lethal autonomous warfare and mass domestic surveillance. It encodes those refusals into the model. Government users have already watched Claude stop mid-task. A dispute over an overseas military operation left the Department uncertain whether Claude would perform as needed.

Katsas put the Secretary’s fear in a sentence that will travel. “The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail.” He also wrote the line that Anthropic cannot appeal as a misunderstanding: the statutory definition, as applied here, turns “on what Anthropic does, not why Anthropic does it.” The majority said it had no reason to doubt “noble intentions” — privacy, safety. Motive is not the test. Effects are. The Associated Press has the same cut.

The company lost the rest of the docket in the same opinion. Arbitrary action: no. Statutory overreach: no. Due process: the Department notified it and gave it a chance to contest. First Amendment and retaliation for AI-safety views: no. The exclusion, Katsas wrote, rested on refusal of a contract term the Department deemed essential, not on Anthropic’s advocacy for regulation. Reason quotes the closer: in this republic it is the President and the Secretary of War who balance the competing risks, and the Secretary did not transgress the Act or the Constitution.

Henderson would not go there. She read “or otherwise manipulate” in the 2018 Act the way a statute written for hostile supply-chain sabotage is supposed to be read: with an intentionally hostile or clandestine purpose. Congress, she wrote, was answering intelligence warnings about foreign actors, not a U.S. company that says in public it will not drop two red lines. Breaking Defense has her sentence: this is not the scenario FASCSA was written to catch. A 2-1 panel can call a safety refusal a manipulation. A dissent can call that a rewrite.

Two statutes, two courts, one exclusion that still bites

Do not flatten Friday into a government-wide ban. The Pentagon used two designations. Challenges had to be filed in two courts. Last month, Judge Rita Lin in the Northern District of California struck down the parallel designation under a different statute, vacated the government-wide contractor order that rode with it, and wrote that an empty invocation of national security is not a blank check. Ars Technica still has that line. The D.C. Circuit said it had “no quarrel” with her conclusion that bad motive is required under that statute. It also said no such motive is required under § 4713. Friday keeps the Defense Department exclusion in place. California’s fight continues. Anthropic is not barred from the rest of the federal government by this ruling. It is barred from the building that wanted “all lawful uses.”

CNBC has the commercial history that makes the exclusion a procurement fact and not a press release. Anthropic had a $200 million Pentagon contract in 2025. Talks on GenAI.mil collapsed when the Department asked for unfettered lawful use and the company kept the two exceptions. Defense Secretary Pete Hegseth accused the lab of trying to seize veto power over operational decisions. The panel delayed the mandate so Anthropic can seek a rehearing from the same three judges or en banc review by the full D.C. Circuit. It can also try the Supreme Court. None of those paths is automatic.

Anthropic’s Friday statement, given to CNBC, WIRED, and the AP, is the one a company writes when the next court is the plan: it respectfully disagrees; another federal court has already held the government’s parallel designation unlawful; it remains confident and is considering all options, including further review. Pentagon spokesman Sean Parnell, in a post the AP quotes, said Friday’s ruling “completely validates the Department’s position.” Breaking Defense has chief technology officer Emil Michael going further: warfighters, he said, will sleep better knowing no private company will insert its opinions into the chain of command. That is the official read of a safety refusal: an opinion in the chain.

A safety line that a court just treated as a defect

The same week this newsroom filed Amodei at the Security Council asking for a narrow ban on AI bioweapons, the court that sits over the Pentagon told him the refusals he encodes are, for Defense procurement, a covered risk. Those two sentences can share a Saturday. They cannot share a definition of “safe.” A model that stops mid-task is, to Anthropic, the product working. To Katsas, it is the Secretary’s sobering prospect. To Henderson, it is not sabotage. The majority chose the Secretary.

A label written for hostile supply chains now sits on a U.S. lab that would not drop two prohibitions. Contractors who want Pentagon work will not run Claude on that work. The California order still says the other statute cannot do the same thing for the rest of government. En banc is a request, not a date. Until a larger court takes the case, the refusal is the risk, and the Pentagon keeps Claude out.