The United States Court of Appeals for the District of Columbia Circuit has delivered a significant blow to the artificial intelligence startup Anthropic, upholding a Department of Defense (DoD) designation that classifies the company as a supply-chain risk. In a 2-1 majority ruling issued on Friday, the federal panel refused to overturn the Trump administration’s restrictions, which effectively block the integration of Anthropic’s flagship Claude models into the military’s information systems. The decision underscores a growing friction between Silicon Valley’s ethical safety frameworks and the federal government’s demands for unrestricted technological utility in national defense operations.
The core of the dispute rests on Anthropic’s refusal to allow its AI models to be utilized for specific high-stakes military applications, including autonomous weaponry and domestic surveillance. While Anthropic has framed these restrictions as essential safety guardrails intended to prevent the misuse of powerful generative AI, the Department of Defense has characterized them as an unacceptable operational risk. According to the court’s majority opinion, the department maintained "ample support" for its conclusion that Anthropic’s self-imposed restrictions presented a statutorily covered national security risk, as the government cannot rely on critical infrastructure that a private vendor might choose to "throttle" or restrict during a conflict.
The Legal Conflict and the DC Circuit Ruling
The ruling from the DC Circuit Court of Appeals focused on the legality of the Pentagon’s use of supply-chain risk laws to exclude certain vendors. Anthropic had argued that the government exceeded its statutory authority and violated the company’s constitutional rights, including due process and free speech. However, the majority of the panel—comprising two of the three judges—rejected these claims. The court noted that Anthropic’s admission that it encodes specific restrictions into Claude to prevent it from performing certain tasks provided the Pentagon with a valid basis for its security concerns.
"As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent," the judges wrote. The court further clarified that the dispute was essentially a standard contract negotiation rather than a violation of rights. The Pentagon, the court reasoned, was not penalizing Anthropic for its support of AI regulation, but rather excluding it from the supply chain because the company refused to agree to a contract term the department deemed essential for national security.
This decision follows a preliminary ruling in April, where the same panel declined to issue an immediate reprieve for Anthropic, citing the company’s failure to meet the "stringent requirements" necessary for an emergency block of government policy. The final 2-1 decision highlights a narrow but firm consensus within the DC court that the executive branch maintains broad discretion in determining what constitutes a supply-chain vulnerability.
A Tale of Two Courts: The San Francisco Split
The legal battle over Anthropic’s status has been characterized by a rare and confusing split between federal jurisdictions. While the DC Circuit has sided with the Pentagon, a federal judge in San Francisco has taken a different view. Earlier this year, a judge in the Northern District of California tossed out one of the two supply-chain risk labels slapped on Anthropic, confirming that decision as recently as last month.
The San Francisco ruling provided Anthropic with a temporary victory, suggesting that at least some of the government’s justifications lacked sufficient evidence or failed to follow proper administrative procedures. However, because the Pentagon utilized two separate supply-chain laws to designate the company, Anthropic was forced to challenge each designation in different venues. Friday’s ruling in DC means that even if the San Francisco decision stands, the other risk label remains in place indefinitely. This creates a legal stalemate where the Pentagon can continue to block Anthropic’s technology based on the DC ruling, regardless of the outcome in California.
Chronology of the Dispute
The escalation between the Pentagon and Anthropic has moved rapidly over the last year, reflecting the high stakes of the "AI arms race" within the federal government.
- Early 2024: The Department of Defense, under the direction of Secretary of Defense Pete Hegseth, officially designates Anthropic as a supply-chain risk under two separate statutes. The designation requires the removal of Claude models from military and federal contractor systems.
- February 2024: Anthropic files dual lawsuits in San Francisco and Washington, D.C., arguing that the designations are arbitrary and based on the company’s ethical safety policies rather than actual security vulnerabilities.
- March 2024: A federal judge in San Francisco issues an initial ruling in favor of Anthropic, blocking one of the designations on the grounds that the government failed to provide adequate due process.
- April 2024: The DC Circuit Court of Appeals denies Anthropic’s request for a temporary injunction, signaling that the company faces a steeper uphill battle in the capital.
- October 2024: The San Francisco judge confirms the permanent block of the first designation.
- Current Ruling: The DC Circuit Court of Appeals issues its 2-1 decision upholding the second designation, ensuring the Pentagon’s blacklist remains functional.
National Security vs. AI Safety Guardrails
At the heart of the Pentagon’s objection is a fundamental disagreement over the "dual-use" nature of artificial intelligence. Anthropic, founded by former OpenAI executives with a focus on "Constitutional AI," has built its brand on the idea that AI must be steerable and restricted by a set of human-defined values. Anthropic’s leadership has been vocal about their refusal to allow Claude to assist in the development of lethal autonomous weapons systems (LAWS) or to be used in domestic surveillance programs that could infringe on civil liberties.
Secretary of Defense Pete Hegseth has framed this stance as a "significant national security risk." From the Pentagon’s perspective, if a private company can hard-code "redlines" into a model, it introduces a point of failure. If the U.S. military were to integrate such a model into its decision-making chain, and the vendor decided to expand those redlines or "turn off" the AI during a geopolitical crisis, the military’s operational capacity would be compromised. The government argues that it requires "unfiltered" access to the underlying capabilities of the technology it purchases.
Market Implications and the Road to IPO
The financial fallout for Anthropic has been tangible. In the immediate wake of the Pentagon’s designations, Anthropic reported a loss in projected revenue as federal contractors and private sector partners became wary of doing business with a company labeled a "national security risk" by the DoD. The "pariah" status in Washington is particularly ill-timed for Anthropic, which is reportedly moving toward an initial public offering (IPO) later this year.
Despite the legal setbacks, Anthropic has touted growing sales in the enterprise sector, where its safety-first approach is often seen as a benefit rather than a liability. However, the loss of the massive federal market—and the potential for these designations to influence allied nations’ procurement policies—remains a shadow over the company’s valuation. Industry analysts suggest that Anthropic’s ability to successfully appeal this ruling to the Supreme Court or a broader panel of the DC Circuit will be a critical factor in its pre-IPO narrative.
The Competitive Landscape: OpenAI, Google, and SpaceX
While Anthropic remains locked in a legal struggle with the Pentagon, its primary competitors have moved to fill the vacuum. The Department of Defense has reportedly explored or expanded its use of alternatives, including:
- OpenAI’s GPT Models: Despite historical internal debates about military use, OpenAI recently updated its policies to allow for certain "national security" applications, leading to increased collaboration with the DoD.
- Google’s Gemini: Google has continued to pursue government contracts, despite past employee protests regarding "Project Maven."
- SpaceX’s Grok: Elon Musk’s xAI has positioned itself as a "pro-West" and "anti-woke" alternative, explicitly seeking to support U.S. government and military interests without the "safety filters" that define Anthropic’s approach.
The Pentagon has not provided a detailed timeline for replacing Claude, but the ruling ensures that these competitors will have an easier path to securing long-term, high-value defense contracts. This has sparked ethical concerns among employees at Google and OpenAI, some of whom have objected to their companies striking the very deals that Anthropic rejected on moral grounds.
Broader Implications for the AI Industry
The DC Circuit’s ruling sets a powerful precedent for how the U.S. government interacts with the burgeoning AI industry. It signals that the executive branch’s power to define supply-chain risks is broad and can be used to compel tech companies to remove safety restrictions if those restrictions interfere with government objectives.
For the wider tech industry, the decision poses a difficult question: Can a company remain a leader in "Ethical AI" while also serving as a primary contractor for the world’s most powerful military? If the court’s logic holds, future AI developers may be forced to choose between maintaining their ethical guardrails and accessing the lucrative federal marketplace.
Anthropic spokesperson Danielle Cohen stated that the company is "considering all options," which may include an en banc review by the full DC Circuit or a petition to the U.S. Supreme Court. As the legal process continues, the case will likely remain a landmark in the ongoing debate over who controls the "brain" of artificial intelligence: the engineers who build it or the government that buys it.
