Articles

Anthropic Pentagon Blacklist Upheld by Appeals Court

A D.C. Circuit panel upheld the Pentagon's blacklisting of Anthropic in a 2-1 ruling, reversing a lower court and reviving a threat to its IPO.

Chisato Chisato · · 6 min read
A shield emblem representing national security and defense procurement

A federal appeals court has handed the Pentagon a win in its long-running fight with Anthropic, reversing a lower-court decision and reinstating the Defense Department’s move to blacklist the Claude maker as a national-security supply-chain risk. In a 2-1 decision issued Thursday, September 25, 2026, a three-judge panel of the U.S. Court of Appeals for the D.C. Circuit found that the Pentagon acted within its statutory authority when it designated Anthropic, throwing out the August ruling that had struck the designation down as unconstitutional retaliation.

The reversal reopens a wound the company had, for a few weeks, believed was closing. It also lands at the worst possible moment for Anthropic’s finances: the startup has told the court the blacklisting has cost it billions of dollars in lost business and damaged its reputation ahead of a highly anticipated initial public offering. What looked in late August like a clean legal victory — and a precedent other AI labs could lean on — is now a defeat the company says it will fight.

What the panel decided

Writing for the majority, Judge Gregory Katsas held that the Defense Department had adequately demonstrated that keeping Claude embedded in its information systems created a risk to national security of the kind the supply-chain statute is meant to address. Judge Neomi Rao joined the opinion. The majority concluded it was reasonable for the Pentagon to designate Anthropic after the company refused to allow its products to be used for fully autonomous weapons or mass domestic surveillance, and it rejected Anthropic’s central claim — that the designation was retaliation for the company’s public stance on AI safety and ethics.

That rejection is the heart of the ruling. The district court had found that officials punished Anthropic for taking a position the administration disliked, a First Amendment violation, and stripped it of protected interests without adequate process, a Fifth Amendment due-process violation. The appeals majority did not adopt that framing. In its telling, the government was not silencing a critic; it was making a procurement-risk judgment about a vendor whose product carried usage restrictions the military considered operationally disqualifying, and courts owe the executive branch deference when it does so.

Judge Karen LeCraft Henderson dissented. Her objection was narrower than the constitutional questions that animated the trial: she argued the government had interpreted the supply-chain-risk statute too broadly, stretching a tool built to guard against infiltration and sabotage by foreign adversaries to cover a domestic vendor whose only “risk” was declining to remove its own safety limits. On that reading, the majority hands the Pentagon a designation power with few boundaries — one that can reach any supplier who attaches conditions the department would rather not accept.

How the fight got here

The dispute traces back to February 2026, when Anthropic refused a demand from Defense Secretary Pete Hegseth to strip restrictions that prevent Claude from being deployed for two specific categories of work: autonomous lethal weapons and mass surveillance of Americans. Anthropic’s refusal rested on two arguments it has made repeatedly — a capability claim that current models are not reliable enough to be trusted inside systems where an error is measured in lives, and a rights claim that it opposes domestic mass surveillance outright.

When the company held its ground, Hegseth designated it a national-security supply-chain risk in March. That label is not a routine contracting dispute. It is the government’s most serious vendor sanction, the kind reserved for firms it believes could expose military systems to compromise, and it can cascade across the entire federal procurement apparatus. Anthropic sued, and in August it won: as we covered when a district judge blocked the Pentagon blacklist, the trial court called the designation “empty” invocation of national security and ordered the directives rescinded.

Thursday’s ruling erases that order. The formal barrier the district court lifted is back in place, and the legal precedent AI labs briefly held — a court decision they could cite the next time the government pressured them to loosen model constraints — has been vacated at the appellate level. The posture that made Anthropic a target is the same one it took in the open-weight release debate, where it broke from rivals over how much control to give up, and it is now the posture an appeals court has ruled the government may lawfully penalize.

What Anthropic says next

Anthropic said it respectfully disagrees with the decision but remains confident in its position and is weighing its options, including asking the full D.C. Circuit to rehear the case en banc. That path would put the question before the entire appeals court rather than the three-judge panel, and a further appeal to the Supreme Court remains available if the en banc bid fails or is declined. None of those routes is quick, and each keeps the designation live in the meantime.

The commercial clock is the harder problem. Anthropic filed confidentially for an IPO in June, and a “national security supply-chain risk” label sitting on its record — now with an appellate ruling affirming it — is exactly the kind of disclosed risk factor that public-market investors scrutinize. The company has spent 2026 arguing that its safety commitments are an asset; this ruling lets skeptics recast them as a liability that costs real federal revenue.

What it means

The immediate winner is the Pentagon, which not only reinstates its designation but secures an appellate endorsement of a broad reading of its supply-chain authority. That reading is the ruling’s most consequential export. If a department can brand a vendor a national-security risk for refusing to remove product-safety limits, every frontier developer now negotiates with the largest AI buyer in the world from a weaker position — the government can treat a “no” on any specific deployment as grounds for a sanction that reaches all of its business, not just the contract in dispute.

The clear loser is Anthropic, which loses both the money and the precedent. The billions it says the blacklist has cost are no longer offset by a favorable ruling it could show prospective investors, and the legal cover other labs might have taken from the August decision is gone. Rivals willing to ship models with fewer hard-coded restrictions stand to benefit: if Anthropic’s safety limits make it a harder sell to the Defense Department, the government workloads it won’t touch are workloads competitors can. That competitive dynamic — safety-constrained labs versus less-restricted ones chasing federal dollars — is the real contest this case keeps alive, and it runs alongside the broader Washington fight over who controls frontier systems that we tracked in the AI kill-switch legislation.

Three things will decide where this goes. First, whether the full D.C. Circuit agrees to rehear the case, and whether Judge Henderson’s narrower statutory objection picks up votes when more judges weigh in — a live possibility, since her dissent gives a future court a clean, non-constitutional path to rein the designation in. Second, whether the ruling emboldens the Pentagon to press other developers, including ones that have cooperated with the government on defense against AI misuse, as Anthropic did in publishing evaluations of real-world misuse of its models. And third, how the IPO market prices a frontier lab that has just been told, at the appellate level, that its safety stance can lawfully cost it its largest customer. For a company built on the premise that drawing lines is a feature, that is the most expensive sentence in the opinion.

Chisato Chisato · · 5 min read

Massachusetts AI Safety Bill: Anthropic vs OpenAI

Anthropic backs strict Massachusetts AI safety rules while OpenAI and Google push a narrower version. Here's what the bill requires and why it matters.

#AI #Policy #Anthropic
Chisato Chisato · · 6 min read

Anthropic Stands Alone in Open-Weight AI Fight

As Nvidia's open-weight letter doubled to 50 signatories, Anthropic refused to sign. Dario Amodei's rebuttal and a White House clash explain the standoff.

#AI #Anthropic #Policy